{
  "schema": "libkungfu.agent-output-comparison/v1",
  "status": "observed-public-github-data",
  "collectedAt": "2026-08-12T13:00:17.837Z",
  "window": {
    "id": "operating",
    "label": "Buildchain operating window",
    "startInclusive": "2026-07-02T00:00:00.000Z",
    "endExclusive": "2026-08-01T00:00:00.000Z",
    "githubQualifier": "merged:2026-07-02T00:00:00Z..2026-07-31T23:59:59Z",
    "duration": "P30D"
  },
  "subjects": {
    "ax": {
      "label": "Google AX",
      "scope": "one public repository",
      "query": "repo:google/ax is:pr is:merged merged:2026-07-02T00:00:00Z..2026-07-31T23:59:59Z",
      "organizationForm": "multiple public contributor accounts working in one repository",
      "summary": {
        "mergedPullRequests": 52,
        "activeRepositories": 1,
        "authorAccounts": 4,
        "activeMergeDays": 15,
        "totalAdditions": 6821,
        "totalDeletions": 1563,
        "totalChangedFiles": 194,
        "changeSize": {
          "median": 92,
          "p25": 19,
          "p75": 184,
          "p90": 383
        },
        "authors": [
          {
            "name": "joycel-github",
            "count": 19
          },
          {
            "name": "rakyll",
            "count": 16
          },
          {
            "name": "wjjclaud",
            "count": 10
          },
          {
            "name": "zbl94",
            "count": 7
          }
        ],
        "repositories": [
          {
            "name": "google/ax",
            "count": 52
          }
        ],
        "daily": [
          {
            "name": "2026-07-06",
            "count": 6
          },
          {
            "name": "2026-07-07",
            "count": 6
          },
          {
            "name": "2026-07-08",
            "count": 2
          },
          {
            "name": "2026-07-09",
            "count": 8
          },
          {
            "name": "2026-07-10",
            "count": 4
          },
          {
            "name": "2026-07-11",
            "count": 1
          },
          {
            "name": "2026-07-13",
            "count": 3
          },
          {
            "name": "2026-07-14",
            "count": 3
          },
          {
            "name": "2026-07-15",
            "count": 5
          },
          {
            "name": "2026-07-16",
            "count": 6
          },
          {
            "name": "2026-07-17",
            "count": 3
          },
          {
            "name": "2026-07-18",
            "count": 2
          },
          {
            "name": "2026-07-20",
            "count": 1
          },
          {
            "name": "2026-07-21",
            "count": 1
          },
          {
            "name": "2026-07-28",
            "count": 1
          }
        ],
        "workTypes": [
          {
            "name": "unclassified",
            "count": 37
          },
          {
            "name": "antigravity",
            "count": 6
          },
          {
            "name": "docs",
            "count": 3
          },
          {
            "name": "interactions",
            "count": 2
          },
          {
            "name": "chore",
            "count": 1
          },
          {
            "name": "ci",
            "count": 1
          },
          {
            "name": "fix",
            "count": 1
          },
          {
            "name": "skills",
            "count": 1
          }
        ]
      },
      "defaultBranchActivity": {
        "repository": "google/ax",
        "branch": "main",
        "commits": 69,
        "activeDays": 14,
        "authorAccounts": 4,
        "rolling7": {
          "minimumCommits": 1,
          "maximumCommits": 30,
          "minimumActiveDays": 1,
          "maximumActiveDays": 6,
          "observations": [
            {
              "endDay": "2026-07-08",
              "commits": 14,
              "activeDays": 3
            },
            {
              "endDay": "2026-07-09",
              "commits": 22,
              "activeDays": 4
            },
            {
              "endDay": "2026-07-10",
              "commits": 26,
              "activeDays": 5
            },
            {
              "endDay": "2026-07-11",
              "commits": 27,
              "activeDays": 6
            },
            {
              "endDay": "2026-07-12",
              "commits": 27,
              "activeDays": 6
            },
            {
              "endDay": "2026-07-13",
              "commits": 24,
              "activeDays": 6
            },
            {
              "endDay": "2026-07-14",
              "commits": 21,
              "activeDays": 6
            },
            {
              "endDay": "2026-07-15",
              "commits": 23,
              "activeDays": 6
            },
            {
              "endDay": "2026-07-16",
              "commits": 21,
              "activeDays": 6
            },
            {
              "endDay": "2026-07-17",
              "commits": 17,
              "activeDays": 5
            },
            {
              "endDay": "2026-07-18",
              "commits": 16,
              "activeDays": 4
            },
            {
              "endDay": "2026-07-19",
              "commits": 16,
              "activeDays": 4
            },
            {
              "endDay": "2026-07-20",
              "commits": 13,
              "activeDays": 3
            },
            {
              "endDay": "2026-07-21",
              "commits": 11,
              "activeDays": 3
            },
            {
              "endDay": "2026-07-22",
              "commits": 30,
              "activeDays": 3
            },
            {
              "endDay": "2026-07-23",
              "commits": 25,
              "activeDays": 3
            },
            {
              "endDay": "2026-07-24",
              "commits": 25,
              "activeDays": 3
            },
            {
              "endDay": "2026-07-25",
              "commits": 25,
              "activeDays": 3
            },
            {
              "endDay": "2026-07-26",
              "commits": 25,
              "activeDays": 3
            },
            {
              "endDay": "2026-07-27",
              "commits": 25,
              "activeDays": 3
            },
            {
              "endDay": "2026-07-28",
              "commits": 25,
              "activeDays": 3
            },
            {
              "endDay": "2026-07-29",
              "commits": 2,
              "activeDays": 2
            },
            {
              "endDay": "2026-07-30",
              "commits": 1,
              "activeDays": 1
            },
            {
              "endDay": "2026-07-31",
              "commits": 1,
              "activeDays": 1
            }
          ]
        },
        "daily": [
          {
            "name": "2026-07-06",
            "count": 6
          },
          {
            "name": "2026-07-07",
            "count": 6
          },
          {
            "name": "2026-07-08",
            "count": 2
          },
          {
            "name": "2026-07-09",
            "count": 8
          },
          {
            "name": "2026-07-10",
            "count": 4
          },
          {
            "name": "2026-07-11",
            "count": 1
          },
          {
            "name": "2026-07-13",
            "count": 3
          },
          {
            "name": "2026-07-14",
            "count": 3
          },
          {
            "name": "2026-07-15",
            "count": 4
          },
          {
            "name": "2026-07-16",
            "count": 6
          },
          {
            "name": "2026-07-21",
            "count": 1
          },
          {
            "name": "2026-07-22",
            "count": 23
          },
          {
            "name": "2026-07-23",
            "count": 1
          },
          {
            "name": "2026-07-28",
            "count": 1
          }
        ],
        "records": [
          {
            "sha": "701777e498ea53f5131b4fc789441f43d77407bb",
            "url": "https://github.com/google/ax/commit/701777e498ea53f5131b4fc789441f43d77407bb",
            "committedAt": "2026-07-06T05:47:49Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Regenerate proto files (#241)",
            "message": "Regenerate proto files (#241)\n\n* Regenerate proto files\n\nFixes #240.\n\n* chore: add Apache 2.0 license headers to generated Python protobuf files"
          },
          {
            "sha": "cec995b72f1c9199663cea5190df13d45630b8bf",
            "url": "https://github.com/google/ax/commit/cec995b72f1c9199663cea5190df13d45630b8bf",
            "committedAt": "2026-07-06T05:48:05Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Fix spacing between AGY harness responses (#239)",
            "message": "Fix spacing between AGY harness responses (#239)\n\nThe AGY harness streams each contiguous block of assistant text as a separate TextContent message, with tool calls in between. The CLI display (cmd/ax/internal/display.go) tracks a state field to decide when to insert separating newlines  but the Content_ToolCall case was a pure no-op that left state == stateText.\n\nFixes #233."
          },
          {
            "sha": "a02465de3384fb7673b0369b9b58cd560bf708c6",
            "url": "https://github.com/google/ax/commit/a02465de3384fb7673b0369b9b58cd560bf708c6",
            "committedAt": "2026-07-06T17:13:18Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Make Postgres optional on substrate deployments (#236)",
            "message": "Make Postgres optional on substrate deployments (#236)\n\n* Make postgres optional.\n\n* Default requires postgres DSN from user."
          },
          {
            "sha": "72b51a4893f342eeb5857da21bc11ab5e4acc930",
            "url": "https://github.com/google/ax/commit/72b51a4893f342eeb5857da21bc11ab5e4acc930",
            "committedAt": "2026-07-06T17:30:46Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Rename ControllerService to ExecutionService (#242)",
            "message": "Rename ControllerService to ExecutionService (#242)"
          },
          {
            "sha": "e39b1232b2c90e09341b5d9366dd3762287312cf",
            "url": "https://github.com/google/ax/commit/e39b1232b2c90e09341b5d9366dd3762287312cf",
            "committedAt": "2026-07-06T21:00:57Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Move Harness implementations to their own packages (#243)",
            "message": "Move Harness implementations to their own packages (#243)\n\n* Move Harness implementations to their own packages\n\nFixes #232.\n\n* Shorten the constructor names"
          },
          {
            "sha": "b2cfc9bc0b9415910d6935801c38170058762564",
            "url": "https://github.com/google/ax/commit/b2cfc9bc0b9415910d6935801c38170058762564",
            "committedAt": "2026-07-06T22:18:42Z",
            "author": "joycel-github",
            "authorName": "JoyceLiu",
            "committerName": "GitHub",
            "title": "harness/python: normalize thought summary whitespace (#244)",
            "message": "harness/python: normalize thought summary whitespace (#244)\n\nModel thought summaries often contain runs of blank lines between\nsection headers (**Section A**\\n\\n\\n**Section B**) and trailing\nnewlines.\n\nPreviously, the Python AGY harness streamed these verbatim over gRPC.\nThis placed the burden of whitespace cleanup on downstream clients (like\ndisplay.go and the Web Dashboard), and caused visible 3+ newline runs\nand compounding newlines at the thought->text transition boundary.\n\nCollapse runs of 3+ newlines to a single blank line and strip\ntrailing newlines inside the Python adapter before sending over the wire.\nAppend exactly one trailing newline to ensure clients generate clean\nseparators when transitioning to text blocks.\n\nFixes #191."
          },
          {
            "sha": "948ca05b5233dcf8b5e4d48e598a332186ab46a8",
            "url": "https://github.com/google/ax/commit/948ca05b5233dcf8b5e4d48e598a332186ab46a8",
            "committedAt": "2026-07-07T01:04:28Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Serve /readyz from ax harness server. (#254)",
            "message": "Serve /readyz from ax harness server. (#254)\n\n* Serve readyz from ax harness.\n\n* Surface the correct error message from server."
          },
          {
            "sha": "ab717703a1165949ffea2eaea29e5dd1ea5b5aa1",
            "url": "https://github.com/google/ax/commit/ab717703a1165949ffea2eaea29e5dd1ea5b5aa1",
            "committedAt": "2026-07-07T01:12:23Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Remove examples/skills/ from the Dockerfile (#256)",
            "message": "Remove examples/skills/ from the Dockerfile (#256)\n\nFixes #253."
          },
          {
            "sha": "cca34eaa7676f7db3b89806a064f7ced3bb54b1d",
            "url": "https://github.com/google/ax/commit/cca34eaa7676f7db3b89806a064f7ced3bb54b1d",
            "committedAt": "2026-07-07T01:12:38Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Use /axharness folder in the snapshots bucket (#255)",
            "message": "Use /axharness folder in the snapshots bucket (#255)\n\nThe ax harness server will provide more than Antigravity."
          },
          {
            "sha": "ad6a89ebaad32ffdb5543d6e602bdfdc41fc3c82",
            "url": "https://github.com/google/ax/commit/ad6a89ebaad32ffdb5543d6e602bdfdc41fc3c82",
            "committedAt": "2026-07-07T01:13:46Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Rename KO_DOCKER_REPO to AX_IMAGE_REPO (#257)",
            "message": "Rename KO_DOCKER_REPO to AX_IMAGE_REPO (#257)\n\nFixes #247."
          },
          {
            "sha": "2ce514f6d61c62046cbd7da786081f8d4332f7d2",
            "url": "https://github.com/google/ax/commit/2ce514f6d61c62046cbd7da786081f8d4332f7d2",
            "committedAt": "2026-07-07T02:43:02Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Make /workspace the default working directory on Substrate (#259)",
            "message": "Make /workspace the default working directory on Substrate (#259)\n\nFixes #258."
          },
          {
            "sha": "c507098025f6619ce611bcf0f2b14386eb846fc4",
            "url": "https://github.com/google/ax/commit/c507098025f6619ce611bcf0f2b14386eb846fc4",
            "committedAt": "2026-07-07T23:50:17Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Introduce pythonsidecar package (#273)",
            "message": "Introduce pythonsidecar package (#273)\n\n* Introduce pythonsidecar package\n\n* chore: add Apache 2.0 license headers to pythonsidecar files\n\n* chore: add development todo notes to sidecar configuration struct"
          },
          {
            "sha": "e764d366a5c660315a6827f065ae1c13cd4a97a3",
            "url": "https://github.com/google/ax/commit/e764d366a5c660315a6827f065ae1c13cd4a97a3",
            "committedAt": "2026-07-08T16:42:27Z",
            "author": "zbl94",
            "authorName": "zbl94",
            "committerName": "GitHub",
            "title": "Serve the Antigravity Interactions harness over HarnessService (#274)",
            "message": "Serve the Antigravity Interactions harness over HarnessService (#274)\n\n* Serve the Antigravity Interactions harness over HarnessService\n\nAdd a Go HarnessService server for the Antigravity Interactions harness so\nit can run as a substrate actor, alongside the existing Python sidecar path.\n\n- internal/harness/antigravityinteractions/server.go: Serve(...) stands up\n  the gRPC HarnessService (plus gRPC health) and an HTTP /readyz endpoint\n  reflecting this server's own serving state, with graceful shutdown on\n  ctx-cancel or SIGINT/SIGTERM. Connect adapts the harness onto the wire\n  contract: a start frame drives one turn (Start -> Queue -> Run), each agent\n  message is streamed as a HarnessResponse{outputs} frame, and the stream\n  terminates with exactly one HarnessResponse{end} (COMPLETED/FAILED/\n  CANCELED); a mid-stream cancel frame cancels the run.\n- cmd/ax/harness.go: add a thin runAntigravityInteractionsHarness(ctx,\n  systemInstructions) entrypoint that builds the config and calls Serve; the\n  dispatch layer decides when to invoke it.\n- server_test.go: bufconn tests for the start->end contract and rejection of\n  a non-start first frame.\n\n* Persist resume cursors under .ax/cursors in the work dir\n\nPlace the Antigravity Interactions harness resume-cursor StateDir in a\ndedicated \".ax/cursors\" subdirectory under the actor working directory,\nrather than the work dir root. This keeps AX internal state out of the\nagent-visible workspace (so it isn't surfaced by list_dir and can't collide\nwith the agent's files) while staying within the snapshotted filesystem so\nit survives snapshot/restore.\n\n* Document why steering is not supported over Connect\n\nAdd a comment in the HarnessService Connect loop explaining that mid-run\nsteering is intentionally unsupported: the execution can accept steering via\nQueue, but the HarnessRequest oneof only defines {start, cancel}, so there is\nno wire frame to deliver input after start. Multi-turn conversation is\nexpressed as separate Connect executions that resume via the persisted cursor.\n\n* Persist resume cursors under ~/.ax/cursors\n\nMove the resume-cursor StateDir out of the agent's working directory to a\ndedicated ~/.ax/cursors under the user's home directory. The working directory\nis the agent's operating surface (it reads and edits files there, including\nhidden ones), so keeping AX internal state separate avoids the agent seeing or\nclobbering it. If the home directory cannot be resolved, the harness now fails\nwith an error rather than silently falling back to the current directory."
          },
          {
            "sha": "e1400ea634880eec0ed10fcbf7bd407abef65382",
            "url": "https://github.com/google/ax/commit/e1400ea634880eec0ed10fcbf7bd407abef65382",
            "committedAt": "2026-07-08T19:37:59Z",
            "author": "joycel-github",
            "authorName": "JoyceLiu",
            "committerName": "GitHub",
            "title": "Auto-start Antigravity Python sidecar from ax exec (#275)",
            "message": "Auto-start Antigravity Python sidecar from ax exec (#275)\n\nLocal mode (the default for ax exec) now forks the Antigravity Python\nsidecar via the pythonsidecar package (introduced in #273) so users\ndon't need to launch the harness server out of band. Modeled after\ncmd/ax/harness.go.\n\nAntigravityHarness.New takes an autoStart bool:\n- true  (cliutil, local mode): fork the sidecar, wait for TCPReady,\n  and install a signal handler that stops the sidecar on\n  ctrl-C / SIGTERM. Full lifecycle stays inside antigravity.go so\n  callers don't need a registry -> controller -> antigravity\n  teardown chain.\n- false (e2e demo, unit tests against harnesstest.MockHarnessServer):\n  pure gRPC-client constructor, no fork.\n\nClose stops the forked sidecar; the signal-handler goroutine is the\nprimary caller today.\n\nTests:\n- internal/harness/antigravity/antigravity_test.go covers both\n  autoStart paths via TestNew_AutoStartTrue_StubServer_ForksSidecar\n  (drives the real fork against a minimal stub Python module on\n  PYTHONPATH) and TestNew_AutoStartFalse_NilSidecar.\n- cmd/ax/internal/cliutil/cliutil_test.go's DefaultHarness test uses\n  the same stub-Python trick to exercise the end-to-end wiring\n  through NewControllerFromConfig.\n\ne2e demo (internal/cmd/e2e/main.go) still uses autoStart=false; TODO\nnotes a companion autoStart=true demo as follow-up."
          },
          {
            "sha": "3ed25c7ec5f315748683ddca9bd209a0ad777b8d",
            "url": "https://github.com/google/ax/commit/3ed25c7ec5f315748683ddca9bd209a0ad777b8d",
            "committedAt": "2026-07-09T00:43:48Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Antigravity interactions harness registry and config (#277)",
            "message": "Antigravity interactions harness registry and config (#277)"
          },
          {
            "sha": "81c84f77b2b205b921aa2a287b1a8f54547ffd85",
            "url": "https://github.com/google/ax/commit/81c84f77b2b205b921aa2a287b1a8f54547ffd85",
            "committedAt": "2026-07-09T02:28:18Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Embed python artifacts into ax (#276)",
            "message": "Embed python artifacts into ax (#276)\n\n* Embed python artifacts into ax\n\nAnd setup the AGY harness service at runtime.\n\n* refactor: remove directory and file filtering logic from setup walk function\n\n* refactor: rename installRequirements to install in python sidecar setup\n\n* refactor: simplify Sidecar configuration by passing PYTHONPATH directly to Start method and removing unnecessary environment and binary options\n\n* feat: configure pip install to use local site-packages and filter unwanted files during setup\n\n* feat: support appending to PYTHONPATH and update Python setup path resolution\n\n* refactor: remove redundant file filtering in sidecar setup directory traversal\n\n* refactor: simplify python package installation and add PyPI index URL to pip command\n\n* fix: remove extra index URL from pip install command\n\n* refactor: remove Sidecar.Setup method and move asset extraction logic to external standalone function\n\n* refactor: remove PythonPath configuration field from sidecar.Config in favor of direct global pythonPath usage\n\n* test: remove integration test for antigravity sidecar auto-start logic\n\n* fix: add pypi.org extra-index-url to python package installation command\n\n* refactor: remove Stdin support from pythonsidecar configuration and cleanup redundant harness definitions"
          },
          {
            "sha": "74731320788e8f21b3167b37ae52f48e3972190f",
            "url": "https://github.com/google/ax/commit/74731320788e8f21b3167b37ae52f48e3972190f",
            "committedAt": "2026-07-09T05:08:09Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Setup ~/.ax/antigravity once until a new update arrives (#278)",
            "message": "Setup ~/.ax/antigravity once until a new update arrives (#278)\n\n* Consolidate .ax directory path resolution into a centralized config helper\n\n* refactor: remove unused TargetDir field from SetupOptions in python sidecar tests\n\n* test: update setup test to use HOME directory and verify .ax subdirectory extraction\n\n* refactor: simplify directory path resolution and variable naming in python sidecar setup\n\n* perf: skip redundant file copying and pip installations when dependencies are up to date\n\n* fix: remove redundant check for non-existent requirements file in setup\n\n* refactor: track file updates during extraction to skip unnecessary pip installs\n\n* feat: add progress notification when installing Antigravity SDK\n\n* fix: ensure site-packages directory exists before returning path in setup\n\n* feat: add pypi simple index to pip install command for environment compatibility"
          },
          {
            "sha": "e1950e035ef48b7a8615575442d04115593bd922",
            "url": "https://github.com/google/ax/commit/e1950e035ef48b7a8615575442d04115593bd922",
            "committedAt": "2026-07-09T06:18:25Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Add instructions for accessing ax server via port-forwarding in install script (#280)",
            "message": "Add instructions for accessing ax server via port-forwarding in install script (#280)"
          },
          {
            "sha": "e84907da7936aabc1d89b10c3b828e67fde66c9f",
            "url": "https://github.com/google/ax/commit/e84907da7936aabc1d89b10c3b828e67fde66c9f",
            "committedAt": "2026-07-09T06:18:44Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "ax command should start without an ax.yaml (#279)",
            "message": "ax command should start without an ax.yaml (#279)\n\nFixes #260."
          },
          {
            "sha": "fef750f9065219139a7fdaa506e903fb51a889e5",
            "url": "https://github.com/google/ax/commit/fef750f9065219139a7fdaa506e903fb51a889e5",
            "committedAt": "2026-07-09T21:08:05Z",
            "author": "zbl94",
            "authorName": "zbl94",
            "committerName": "GitHub",
            "title": "Harden Antigravity Interactions harness HTTP client (#285)",
            "message": "Harden Antigravity Interactions harness HTTP client (#285)\n\n* Harden Antigravity Interactions harness HTTP client\n\nFix a substrate suspend/resume failure and tighten the config surface:\n\n- Disable HTTP keep-alives on the harness's default client. On substrate the\n  actor is suspended after a turn and resumed for the next (with a new routable\n  IP), which leaves any pooled keep-alive connection stale; reusing it made the\n  next turn's request fail. Opening a fresh connection per request avoids that\n  at the cost of an extra handshake.\n- Remove the public HTTPClient override from AntigravityInteractionsConfig.\n  External callers don't configure the harness's transport, and exposing it\n  risked silently reintroducing the keep-alive bug. New now always owns its\n  (keep-alive-disabled) client; tests inject a fake transport via an unexported\n  newWithHTTPClient seam.\n- Reorder AntigravityInteractionsConfig fields to list required (Agent,\n  StateDir) before optional, with clearer doc comments.\n\nBuild and package tests pass.\n\n* Explain why the HTTP transport is cloned, not newly created\n\nAddress review feedback: document that cloning DefaultTransport (rather than a\nbare &http.Transport{}) is intentional -- it inherits the production defaults\n(env proxy, dial/TLS/handshake timeouts, HTTP/2) and only overrides keep-alives.\nA fresh empty transport would silently drop those."
          },
          {
            "sha": "3f39ca3f917b01b10c39fe788e69ace363449360",
            "url": "https://github.com/google/ax/commit/3f39ca3f917b01b10c39fe788e69ace363449360",
            "committedAt": "2026-07-09T21:44:57Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Delete obsolete Makefile targets (#284)",
            "message": "Delete obsolete Makefile targets (#284)"
          },
          {
            "sha": "70a2581d4914d2481b3df0f4d7d76347b088df6e",
            "url": "https://github.com/google/ax/commit/70a2581d4914d2481b3df0f4d7d76347b088df6e",
            "committedAt": "2026-07-09T23:24:27Z",
            "author": "zbl94",
            "authorName": "zbl94",
            "committerName": "GitHub",
            "title": "Surface server error events in Antigravity Interactions harness (#288)",
            "message": "Surface server error events in Antigravity Interactions harness (#288)\n\nparseStreamedTurn only handled interaction.* and step.* SSE events; a\nserver-emitted \"error\" event fell through the switch and was silently\ndropped. The turn then returned as completed-but-empty, which:\n\n  - made a failure (e.g. INVALID_ARGUMENT for a malformed client tool\n    result) look like a blank \"no response\" turn, and\n  - persisted the failing interaction's id as a poisoned resume cursor.\n\nAdd an \"error\" case that returns a real error, plus a serverErrorMessage\nhelper that extracts message/status from the error payload. Now a\nturn-level server failure aborts the turn with a descriptive error\ninstead of being hidden.\n\nAdds tests for the error-event path and serverErrorMessage formatting."
          },
          {
            "sha": "fea5d230db6d6ef8cea3cf5fa19b69179f205d09",
            "url": "https://github.com/google/ax/commit/fea5d230db6d6ef8cea3cf5fa19b69179f205d09",
            "committedAt": "2026-07-10T00:44:00Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Run Antigravity Interactions as substrate actors (#287)",
            "message": "Run Antigravity Interactions as substrate actors (#287)\n\n* Run antigravity interactions as actor.\n\n* Add instructions for users.\n\n* Remove a comment.\n\n* Fix readme format."
          },
          {
            "sha": "65f0478ea1b0f503464d6aaf9ce5839105e7a01b",
            "url": "https://github.com/google/ax/commit/65f0478ea1b0f503464d6aaf9ce5839105e7a01b",
            "committedAt": "2026-07-10T03:45:26Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "Replace Antigravity sidecar in-memory Agent cache with SDK-native resume (#289)",
            "message": "Replace Antigravity sidecar in-memory Agent cache with SDK-native resume (#289)\n\nThe Python sidecar previously kept a per-conversation Agent instance in\nan in-process dict (self._agents) with a lock, and relied on that cache\nto preserve conversation history across turns. This tied conversation\nstate to a single sidecar process lifetime: any restart, crash, or\nmulti-replica scaling would silently drop history.\n\nDelete the cache and use the Antigravity SDK's own per-conversation\npersistence instead. LocalAgentConfig accepts (conversation_id, save_dir);\nthe SDK's localharness persists trajectory state to\n{save_dir}/{sdk_conv_id}.db. Each turn now:\n\n1. Constructs a fresh Agent scoped to a per-AX-conversation save_dir\n   (~/.ax/antigravity/conversations/{ax_conv_id}/), so each AX\n   conversation gets its own directory with at most one .db file.\n2. If a .db exists there (from a prior turn), passes its stem as the\n   SDK's conversation_id to trigger resume. The SDK's conversation_id\n   is resume-only -- passing a non-existent id errors out -- hence\n   the discover-then-pass pattern.\n3. Runs the turn inside an async-with Agent(...) block, disposing at\n   the end. No process-level state.\n\nMirrors internal/harness/antigravityinteractions/DefaultStateDir()\nconvention (state under ~/.ax/, out of the agent's cwd/operating\nsurface). A TODO references issues #269 and #203 for the eventual\ncontroller-injected save_dir via harness_config.\n\nTest replaces test_grpc_connect_agent_reused (which asserted cache\nbehavior) with test_grpc_connect_agent_per_turn_with_save_dir, which\nasserts per-turn Agent construction and deterministic per-conv save_dir\nnaming.\n\nVerified end-to-end with ax exec --conversation <id>: turn 2 correctly\nrecalls a name introduced in turn 1 across a fresh sidecar process,\nwith only one .db file per conversation on disk. Different --conversation\nids remain isolated."
          },
          {
            "sha": "b71ba523cc08e69980b497e67887f6b54bf23fab",
            "url": "https://github.com/google/ax/commit/b71ba523cc08e69980b497e67887f6b54bf23fab",
            "committedAt": "2026-07-10T21:23:47Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Use GOOGLE_CLOUD_PROJECT variable and remove PROJECT_ID usage (#293)",
            "message": "Use GOOGLE_CLOUD_PROJECT variable and remove PROJECT_ID usage (#293)\n\n* Update install script to use GOOGLE_CLOUD_PROJECT instead of PROJECT_ID\n\nFixes #290.\n\n* Use GOOGLE_CLOUD_PROJECT variable and remove PROJECT_ID usage\n\nFixes #290."
          },
          {
            "sha": "c48baf33a0e9ba1fbad97c3439f3f46b3732c248",
            "url": "https://github.com/google/ax/commit/c48baf33a0e9ba1fbad97c3439f3f46b3732c248",
            "committedAt": "2026-07-10T21:34:17Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Update GOOGLE_CLOUD_PROJECT for interactions path. (#294)",
            "message": "Update GOOGLE_CLOUD_PROJECT for interactions path. (#294)"
          },
          {
            "sha": "4846d9090b8748cf7fd4c9a85c4a604a7ce56793",
            "url": "https://github.com/google/ax/commit/4846d9090b8748cf7fd4c9a85c4a604a7ce56793",
            "committedAt": "2026-07-11T00:30:26Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "harness/python: fix stale thought summary test assertions (#291)",
            "message": "harness/python: fix stale thought summary test assertions (#291)\n\nPR #244 normalized thought summary text with a trailing '\\n' in\nharness_server.py but harness_server_test.py wasn't updated.\ntest_grpc_connect_success and test_grpc_connect_buffering assert\nagainst the pre-normalization strings and fail.\n\nThe drift went unnoticed because the Python tests aren't wired\ninto CI (.github/workflows/go.yml only runs go test ./...).\nWiring pytest into CI is the follow-up."
          },
          {
            "sha": "1b58b0943e5e1a4aab33e7d74edc083f1281cc1d",
            "url": "https://github.com/google/ax/commit/1b58b0943e5e1a4aab33e7d74edc083f1281cc1d",
            "committedAt": "2026-07-13T16:55:02Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "Antigravity sidecar state dir from config (#292)",
            "message": "Antigravity sidecar state dir from config (#292)\n\n* antigravity: plumb sidecar state_dir from ax.yaml\n\nSidecar's trajectory storage directory was hardcoded in Python. This\nplumbs it through as a yaml config that users can override, matching\nthe pattern already used for the Interactions harness's state_dir.\n\nFlow:\n- ax.yaml: harnesses.antigravity.state_dir (optional; empty = default)\n- config.go: AntigravityHarnessConfig.StateDir field (yaml surface only,\n  no default logic on the Go side)\n- cliutil.go: passes yaml value as-is (empty string when unset)\n- antigravity Go client: appends --state-dir arg only when non-empty\n- Python sidecar: argparse --state-dir with default\n  ~/.ax/antigravity/conversations. Default is a transitional fallback\n  for substrate mode (where ActorTemplate doesn't inject the flag yet).\n  Removable once substrate can set the field via ActorTemplate.\n\nServicer's state_dir is required (no fallback) -- production path always\nreceives it from argparse; tests pass tmp_path.\n\nVerified end-to-end with ax exec:\n- No yaml state_dir  -> ~/.ax/antigravity/conversations/{conv_id}/\n- yaml state_dir: X  -> X/{conv_id}/\n- Different conversations remain isolated across both paths.\n\nCloses part of the local-mode gap in issue #269 (harness_config\ncontract design); a follow-up will do the same for substrate via\nActorTemplate.\n\n* antigravity: address PR review comments (P1/P2/P3)\n\n- P1: two Python tests referenced tmp_path without declaring the fixture;\n  add tmp_path to their signatures.\n- P2: state_dir CLI arg was not tilde-expanded, so ~/.ax/... became a\n  literal ~ dir. Add .expanduser().\n- P3: no Go-side test asserted --state-dir forwarding. Extract\n  buildSidecarArgs() as a small pure helper and add table test for the\n  empty/non-empty cases, plus a yaml parse test for\n  AntigravityHarnessConfig.StateDir.\n\n* antigravity: inline sidecar args build instead of separate helper\n\nFollow-up to review feedback: buildSidecarArgs was overkill for a 3-line\nconditional. Move it back into New() inline. Also drops the associated\nTestBuildSidecarArgs (the arg-forwarding rule is now covered only by\nend-to-end verification)."
          },
          {
            "sha": "7437b2f63389bf2ad633fe3eb6b0bb2be81d7296",
            "url": "https://github.com/google/ax/commit/7437b2f63389bf2ad633fe3eb6b0bb2be81d7296",
            "committedAt": "2026-07-13T16:55:24Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "ci: run Python tests for the antigravity harness sidecar (#296)",
            "message": "ci: run Python tests for the antigravity harness sidecar (#296)\n\nThe 17 tests in python/antigravity/harness_server_test.py have never\nrun in CI. .github/workflows/go.yml only runs 'go test ./...' and the\nMakefile 'test' target likewise only runs Go. That let PR #244 land\nwith 2 stale assertions unnoticed (fixed in #291).\n\nAdds:\n- .github/workflows/python.yml -- dedicated Python workflow (kept\n  separate from the Go-only go.yml so each can evolve independently).\n- Makefile 'test-python' target for local parity.\n\nTest deps are inlined in the workflow rather than added as a separate\nrequirements-test.txt -- the diff is 2 packages ('pytest>=7.0',\n'pytest-timeout>=2.0'), not worth its own file. Version floors match\nthe upstream google-antigravity SDK's dev extras so this doesn't\ndrift as pytest evolves.\n\n--timeout=30 --timeout-method=thread guards against hung gRPC servers\nso a stuck test can't eat the whole workflow budget."
          },
          {
            "sha": "c7e9f295e392c7ae5f7336eb1fc0efbcc745bbfc",
            "url": "https://github.com/google/ax/commit/c7e9f295e392c7ae5f7336eb1fc0efbcc745bbfc",
            "committedAt": "2026-07-13T21:55:05Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "parse harness config from request (#295)",
            "message": "parse harness config from request (#295)\n\n* antigravity: parse and validate request harness_config\n\nParse HarnessStart.harness_config (JSON-in-bytes) and overlay it onto\nthe server's default LocalAgentConfig before each turn.\n\n- Blocks a request from overriding AX-owned persistence fields\n  (save_dir, conversation_id) via _AX_MANAGED_CONFIG_FIELDS; these are\n  injected last so a request can't redirect trajectory storage.\n- Reconstructs the config (not model_copy) so the SDK re-validates the\n  overlaid values and surfaces its own error; invalid config fails the\n  turn with INVALID_ARGUMENT instead of crashing.\n- save_dir derives from the injected state_dir (#292) as\n  state_dir / conversation_id.\n\n* antigravity: address harness_config review comments\n\n- Inline _parse_harness_config into _build_config_for so the parsed\n  dict stays a local intermediate; the method's only boundary type is\n  the validated LocalAgentConfig (no dict[str, object] across a helper\n  boundary). Addresses the \"introduce a type for the config\" comment.\n- Make per-conv save_dir test assertions portable: compare against\n  str(tmp_path / conversation_id) instead of hardcoding \"/conv-1\", and\n  drop the now-vestigial Path.home monkeypatch (save_dir derives from\n  the injected state_dir since #292). Addresses the Windows path\n  separator comment.\n\n_AX_MANAGED_CONFIG_FIELDS keeps guarding both conversation_id and\nsave_dir on purpose: harness_config is a separate client-controlled\nsurface from the request's conversation_id, so blocking it prevents a\nrequest from redirecting another conversation's trajectory storage."
          },
          {
            "sha": "a953396b6d2fb5e9740b3c7718ce4ca2ac1e6781",
            "url": "https://github.com/google/ax/commit/a953396b6d2fb5e9740b3c7718ce4ca2ac1e6781",
            "committedAt": "2026-07-14T00:04:49Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "antigravity: reject unknown harness_config fields (#301)",
            "message": "antigravity: reject unknown harness_config fields (#301)\n\nLocalAgentConfig uses pydantic's default extra=\"ignore\", so an\nunrecognized field in a request's harness_config -- e.g. a typo like\n\"system_instruction\" for \"system_instructions\" -- was silently dropped\nand the caller believed the override took effect when it did not.\n\nAdd _reject_disallowed_fields(overrides), which factors two key checks\ninto one helper and raises HarnessConfigError (mapped to\nINVALID_ARGUMENT) naming the offending field(s):\n  - fields that come from outside harness_config (_NON_HARNESS_CONFIG_\n    FIELDS: conversation_id from the runtime request, save_dir from the\n    server's state_dir), and\n  - unknown top-level fields.\n\nValidation is best-effort and top-level only: nested-key and value/type\nvalidation is delegated to the SDK's own LocalAgentConfig validation at\nconstruction time."
          },
          {
            "sha": "8eff724ca6833c507a5d8178bdbc9f13e5d9c280",
            "url": "https://github.com/google/ax/commit/8eff724ca6833c507a5d8178bdbc9f13e5d9c280",
            "committedAt": "2026-07-14T20:03:01Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Interactions actor reads config from yaml. (#302)",
            "message": "Interactions actor reads config from yaml. (#302)"
          },
          {
            "sha": "9873c8747553031a1df660964b688c73fc74254d",
            "url": "https://github.com/google/ax/commit/9873c8747553031a1df660964b688c73fc74254d",
            "committedAt": "2026-07-14T20:28:49Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "antigravity: stop exposing harness state_dir in ax.yaml (#304)",
            "message": "antigravity: stop exposing harness state_dir in ax.yaml (#304)\n\nstate_dir is an AGY SDK implementation detail (where trajectory /\nresume-cursor storage lives), not something AX users should configure.\nRemove the yaml surface for both built-in harnesses and derive the path\ninternally from config.AXAssetsDir().\n\n- config: drop StateDir from AntigravityHarnessConfig and\n  AntigravityInteractionsHarnessConfig.\n- antigravity: add DefaultStateDir() -> ~/.ax/antigravity/conversations,\n  mirroring antigravityinteractions.DefaultStateDir(). cliutil now passes\n  this into antigravity.New instead of the yaml value.\n- cliutil: interactions harness always uses DefaultStateDir(); drop the\n  yaml read + fallback.\n\nThe internal APIs (antigravity.New's stateDir arg, the required\nAntigravityInteractionsConfig.StateDir field, and the Python sidecar's\n--state-dir default) are unchanged -- only the user-facing ax.yaml knob\nis removed.\n\nAddresses rakyll's follow-up on #292."
          },
          {
            "sha": "37718e20bf2ee578eaa007e2a7709b71b19f6e87",
            "url": "https://github.com/google/ax/commit/37718e20bf2ee578eaa007e2a7709b71b19f6e87",
            "committedAt": "2026-07-15T00:40:31Z",
            "author": "zbl94",
            "authorName": "zbl94",
            "committerName": "GitHub",
            "title": "Add Gemini Enterprise Skill Registry integration for local harnesses (#300)",
            "message": "Add Gemini Enterprise Skill Registry integration for local harnesses (#300)\n\nMaterialize agentskills.io skills from the Gemini Enterprise Skill Registry\n(Vertex AI v1beta1) into on-disk folders before the harness starts, so the\nbuilt-in harnesses can use registry-hosted skills on the local `ax exec` /\n`ax serve` path.\n\n- internal/skills/geminienterprise: harness-agnostic package that reads\n  config.SkillsConfig, drives the registry client (ListSkills / GetSkill /\n  GetSkillRevision / skills:retrieve), safe-unzips payloads to\n  <target_dir>/<skill-id>/, and reports what it wrote. First-wins on\n  duplicate ids with a warning; fail-safe (a registry error never blocks\n  harness startup).\n- config: top-level `skills.registries[]` (harness-agnostic -- each actor\n  runs a single harness that consumes the materialized folder). Per-registry\n  selection (skills / query / all), required target_dir, and a validated\n  \"exactly one selection mode\" rule. Also wires the interactions harness's\n  system_instruction from ax.yaml.\n- cliutil: materializes skills once, up front, at controller construction;\n  for the interactions harness (no SKILLS_DIR concept) it appends a discovery\n  pointer to the system instruction.\n\nScope: local path only; the substrate/pod path does not yet read ax.yaml.\nVerified end-to-end against a live registry (by-id and by-query)."
          },
          {
            "sha": "4d38084e773bbdaf62072bde3b58976450dac570",
            "url": "https://github.com/google/ax/commit/4d38084e773bbdaf62072bde3b58976450dac570",
            "committedAt": "2026-07-15T17:27:16Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "antigravity: format harness_server.py with black (#311)",
            "message": "antigravity: format harness_server.py with black (#311)"
          },
          {
            "sha": "f14e57d896b2838b383821346f405d7f363a91cf",
            "url": "https://github.com/google/ax/commit/f14e57d896b2838b383821346f405d7f363a91cf",
            "committedAt": "2026-07-15T17:28:01Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "docs(readme): fix invalid harness in exec example (#309)",
            "message": "docs(readme): fix invalid harness in exec example (#309)\n\nThe exec example used `--harness coding`, but no \"coding\" harness\nexists; runHarness only accepts \"antigravity\" and\n\"antigravity-interactions\" and errors otherwise, so the command as\nwritten fails. Point the example at the real \"antigravity\" harness."
          },
          {
            "sha": "968348aea14492243d20837474d976fc1f714a98",
            "url": "https://github.com/google/ax/commit/968348aea14492243d20837474d976fc1f714a98",
            "committedAt": "2026-07-15T17:34:14Z",
            "author": "zbl94",
            "authorName": "zbl94",
            "committerName": "GitHub",
            "title": "Honor view_file line range and cap result size (#303)",
            "message": "Honor view_file line range and cap result size (#303)\n\n* Honor view_file line range and cap result size\n\nexecViewFile read the whole file and ignored the agent's StartLine/EndLine,\nso viewing a large file returned its entire content as the tool result --\na ~900KB blob for a 3k-line CSV stalled the following turn.\n\nImplement the Antigravity view_file contract (1-indexed inclusive line range\nwith slice-notation windowing) plus defensive caps:\n- StartLine/EndLine window (neither=first N lines; start-only=next N forward;\n  end-only=previous N backward; both=precise range, capped to N).\n- viewFileMaxLines / viewFileMaxBytes caps so a large file can never blob.\n- ContentOffset honored as the read position within the windowed content.\n\nThe result payload is just {\"content\": ...}; the view_file result schema is\ndefined server-side, so no extra fields are added.\n\nAdds intArg/intArgOK helpers and tests for windowing, byte cap, offset read,\nand range honoring.\n\n* view_file: UTF-8-safe byte cap + pagination metadata\n\nAddress review feedback on the byte cap:\n\n- applyByteWindow backs the cut off to the last complete UTF-8 rune so a\n  multi-byte character straddling viewFileMaxBytes is never split (raw byte\n  slicing could produce invalid UTF-8, corrupting the last char and JSON\n  serialization).\n- execViewFile returns the metadata the server needs to distinguish a\n  complete read from a paginated/byte-truncated one: content, start_line/\n  end_line (0-indexed inclusive served range), content_offset,\n  line_range_bytes (total bytes of the line range pre-byte-cap), and\n  num_lines/num_bytes. The server detects truncation via\n  content_offset+len(content) < line_range_bytes and prompts the model to\n  resume from that offset.\n\nA paired server change reads these fields instead of hardcoding\nstart_line=0/end_line=last.\n\nAdds tests for UTF-8 boundary capping, pagination metadata, and resume."
          },
          {
            "sha": "2db183311358abb3fc2c2d9f18b6913123c78656",
            "url": "https://github.com/google/ax/commit/2db183311358abb3fc2c2d9f18b6913123c78656",
            "committedAt": "2026-07-16T03:24:21Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Handle default harness correctly. (#308)",
            "message": "Handle default harness correctly. (#308)"
          },
          {
            "sha": "7aa53e719af2bda2e9b3357c92ec78f768642e62",
            "url": "https://github.com/google/ax/commit/7aa53e719af2bda2e9b3357c92ec78f768642e62",
            "committedAt": "2026-07-16T16:19:08Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "docs(readme): refresh Antigravity setup, auth, and CLI usage (#317)",
            "message": "docs(readme): refresh Antigravity setup, auth, and CLI usage (#317)\n\n* docs(readme): refresh Antigravity setup, auth, and CLI usage\n\nRe-land the README refresh that was approved as #310 but never reached\nmain (it merged into #309's branch, which was then squash-merged, orphaning\nthis content).\n\n- Document the built-in Antigravity harness: local execution needs python3\n  and pip on PATH; AX auto-starts the Python sidecar and installs the pinned\n  SDK dependencies on first use.\n- Promote Authentication to its own top-level section (Google AI Studio and\n  Vertex AI / ADC).\n- Refresh Quick Start / Usage examples, document the --harness-config and\n  --harness-config-json flags, and add a per-request configuration example.\n\n* docs(readme): use gemini-3.5-flash in per-request config example\n\nUpdate the per-request harness config example from gemini-2.5-pro to a\ncurrent model, matching the model naming used in examples/skills."
          },
          {
            "sha": "de4792aed4dc1777bcb18a9367c6de6851b2849a",
            "url": "https://github.com/google/ax/commit/de4792aed4dc1777bcb18a9367c6de6851b2849a",
            "committedAt": "2026-07-16T17:03:30Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Separate container for python. (#305)",
            "message": "Separate container for python. (#305)"
          },
          {
            "sha": "6afbf90a8f3cbe057370278bfb02894a618a09a2",
            "url": "https://github.com/google/ax/commit/6afbf90a8f3cbe057370278bfb02894a618a09a2",
            "committedAt": "2026-07-16T20:25:39Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Set workdir for interactions execution. (#324)",
            "message": "Set workdir for interactions execution. (#324)"
          },
          {
            "sha": "35958b273b62790504915653c59883c69cf458d8",
            "url": "https://github.com/google/ax/commit/35958b273b62790504915653c59883c69cf458d8",
            "committedAt": "2026-07-16T21:29:02Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "fix(harness): wire --state-dir for the Antigravity SDK harness on substrate (#322)",
            "message": "fix(harness): wire --state-dir for the Antigravity SDK harness on substrate (#322)\n\nrunAntigravityHarness (the `ax harness antigravity` path used by the\nsubstrate ActorTemplate) forked the Python sidecar with only --host/--port.\nThe sidecar then fell back to its own default state dir, so on a substrate\nactor per-conversation save_dir landed on a path AX does not control, which\nbreaks SDK-native resume across actor Run/Restore and snapshotting.\n\nDerive the trajectory dir via antigravity.DefaultStateDir() and pass it as\n--state-dir, mirroring the local path in antigravity.New and the interactions\nharness in runAntigravityInteractionsHarness (both own the path internally\nrather than taking it from ax.yaml/ActorTemplate).\n\nFixes #321"
          },
          {
            "sha": "d1e95fc2983f51b174ac3f5e8ccd5a250912eb8d",
            "url": "https://github.com/google/ax/commit/d1e95fc2983f51b174ac3f5e8ccd5a250912eb8d",
            "committedAt": "2026-07-16T23:28:13Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "antigravity: bump google-antigravity 0.1.5 -> 0.1.7 (#326)",
            "message": "antigravity: bump google-antigravity 0.1.5 -> 0.1.7 (#326)\n\n0.1.7 reads GenAI credential env vars natively. Bump first; the\nsidecar override is removed in a follow-up (#325). Behavior unchanged\nhere since explicit override kwargs still take precedence.\n\nRef #325"
          },
          {
            "sha": "a34bbebf2de12c77bc6b45236c1fe2902baeea4a",
            "url": "https://github.com/google/ax/commit/a34bbebf2de12c77bc6b45236c1fe2902baeea4a",
            "committedAt": "2026-07-21T01:22:45Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "Jaana Dogan",
            "title": "antigravity: remove _resolve_localhost /etc/hosts hack (#328)",
            "message": "antigravity: remove _resolve_localhost /etc/hosts hack (#328)\n\ngoogle-antigravity 0.1.7's _connect_websocket retries both \"localhost\"\nand \"127.0.0.1\" when dialing localharness (local_connection.py:993), so\nthe sidecar no longer needs to patch /etc/hosts for substrate/gVisor\nenvironments where localhost may not resolve.\n\nRef #325\n\nantigravity: guard conversation_id for safe save_dir use (#312)\n\nharness_server uses the caller-supplied conversation_id directly as a\nper-conversation storage directory name (save_dir = state_dir /\nconversation_id) before the Antigravity harness ever sees it, so a value\nlike \"../escape\" could traverse outside state_dir. Reject an empty id or\none containing a path separator or a \".\" / \"..\" component at the boundary\nin _run_turn, returning an INVALID_ARGUMENT end frame.\n\nThis is intentionally only a path-safety guard, not the id-format\ncontract. The Antigravity harness owns that: it validates the forwarded\ncascade_id (length and character set) per cl/948016352. Keeping the\nformat rule in one place avoids the two layers drifting.\n\nchore: remove stale docs, gitignore, and Makefile entries (#329)\n\n- CONTRIBUTING.md: drop 'make run-remote' (no such Makefile target)\n- .gitignore: remove orphaned entries (local/remote_agent, sandbox-router,\n  tasklog, axepp, google-cloud-sdk, test-sandbox-config.yaml)\n- Makefile: add missing deps, clean-logs to .PHONY\n\nantigravity: remove vertex env-var override (superseded by AGY 0.1.7) (#331)\n\n* antigravity: remove vertex env-var override (superseded by AGY 0.1.7)\n\ngoogle-antigravity 0.1.7 reads GOOGLE_GENAI_USE_VERTEXAI /\nGOOGLE_GENAI_USE_ENTERPRISE + GOOGLE_CLOUD_{PROJECT,LOCATION} natively,\nso the sidecar no longer needs _vertex_kwargs_from_env to thread them\ninto LocalAgentConfig.\n\n- Delete _vertex_kwargs_from_env + VertexKwargs.\n- _build_default_config: bare LocalAgentConfig(system_instructions=...).\n- _has_credentials: read project/location from env (SDK hydrates them\n  onto VertexEndpoint, not LocalAgentConfig).\n- Update tests accordingly.\n\nRequires the 0.1.7 bump. Credential resolution is startup-only and\ndoes not touch the save_dir/state_dir resume path.\n\nRef #325\n\n* antigravity: drop stale _has_credentials docstring note about vertex env override\n\nInteractions: persist interactions harness with durable dir and resume from it (#327)\n\ninteractions: make WorkDir authoritative for run_command (#335)\n\nThe interactions harness executed run_command relative to the process's\nambient working directory, which is not reliably the agent's workspace: with\nno Cwd argument the command ran wherever the process cwd happened to be, and a\nmodel-supplied Cwd (including \"/\") was honored blindly. As a result tool calls\noften ran from \"/\" instead of the configured workspace (#332).\n\nMake the workspace directory authoritative in the executor rather than relying\non ambient process state:\n\n- Add AntigravityInteractionsConfig.WorkDir (defaults from AX_HARNESS_WORKDIR).\n- run_command now resolves its directory via resolveRunDir: no Cwd -> WorkDir;\n  relative Cwd -> joined under WorkDir; absolute Cwd -> honored as-is. Empty\n  WorkDir preserves the previous process-cwd behavior.\n- Add WorkspaceSystemInstruction to orient the agent about its working\n  directory so it emits workspace-relative paths, and wire it in cmd/ax.\n\nFixes #332\n\nRemove the binary (#334)\n\n* Remove the binary\n\n* chore: add e2e directory to .gitignore\n\n* refactor: migrate binary file check to a dedicated workflow file\n\n* fix: restrict binary file check to added, copied, or modified files"
          },
          {
            "sha": "10588c52ac413f499795389a7a65ffa50701ed94",
            "url": "https://github.com/google/ax/commit/10588c52ac413f499795389a7a65ffa50701ed94",
            "committedAt": "2026-07-22T15:43:07Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "fix(docs): update HarnessService description to clarify terminology",
            "message": "fix(docs): update HarnessService description to clarify terminology"
          },
          {
            "sha": "5ac275e373303d10c0e9723af5201c483e98ab00",
            "url": "https://github.com/google/ax/commit/5ac275e373303d10c0e9723af5201c483e98ab00",
            "committedAt": "2026-07-22T15:44:24Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "fix(docs): update Control API label to Actor Controller in README",
            "message": "fix(docs): update Control API label to Actor Controller in README"
          },
          {
            "sha": "bff324b7dbcf8579854388396a07e712ecd5d3d3",
            "url": "https://github.com/google/ax/commit/bff324b7dbcf8579854388396a07e712ecd5d3d3",
            "committedAt": "2026-07-22T17:02:05Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "docs: remove obsolete Antigravity harness documentation from README",
            "message": "docs: remove obsolete Antigravity harness documentation from README"
          },
          {
            "sha": "6806eb99d7b976294cad2f3daeccee0d99096cbf",
            "url": "https://github.com/google/ax/commit/6806eb99d7b976294cad2f3daeccee0d99096cbf",
            "committedAt": "2026-07-22T17:02:24Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "docs: remove deprecated BYOH and integrations items from roadmap",
            "message": "docs: remove deprecated BYOH and integrations items from roadmap"
          },
          {
            "sha": "e4c2fbda0015d34b33fdfff32a17244a43bc7161",
            "url": "https://github.com/google/ax/commit/e4c2fbda0015d34b33fdfff32a17244a43bc7161",
            "committedAt": "2026-07-22T17:04:03Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "docs: remove temporary external contribution pause and contact email from README",
            "message": "docs: remove temporary external contribution pause and contact email from README"
          },
          {
            "sha": "1abc003dca8833fba084be6f67fe999487eaf8fb",
            "url": "https://github.com/google/ax/commit/1abc003dca8833fba084be6f67fe999487eaf8fb",
            "committedAt": "2026-07-22T17:09:23Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "feat: prevent sidecar startup when ReadyFunc indicates the endpoint is already in use",
            "message": "feat: prevent sidecar startup when ReadyFunc indicates the endpoint is already in use"
          },
          {
            "sha": "a0bfb5fb74dfe94f96d8feebf7755c6248856734",
            "url": "https://github.com/google/ax/commit/a0bfb5fb74dfe94f96d8feebf7755c6248856734",
            "committedAt": "2026-07-22T18:56:37Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "feat: add support for terminating existing orphan processes before starting the Python sidecar",
            "message": "feat: add support for terminating existing orphan processes before starting the Python sidecar"
          },
          {
            "sha": "701feadd055b872edd02c040531551e532e1b797",
            "url": "https://github.com/google/ax/commit/701feadd055b872edd02c040531551e532e1b797",
            "committedAt": "2026-07-22T19:01:27Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "refactor: rename CLI flags to --config and --ax-config for improved command naming consistency",
            "message": "refactor: rename CLI flags to --config and --ax-config for improved command naming consistency"
          },
          {
            "sha": "2fd20cd431259aa2bb3340d7c1e080cdcba2c630",
            "url": "https://github.com/google/ax/commit/2fd20cd431259aa2bb3340d7c1e080cdcba2c630",
            "committedAt": "2026-07-22T19:04:50Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "refactor: rename harness configuration flags to --config for inline JSON and --config-file for paths",
            "message": "refactor: rename harness configuration flags to --config for inline JSON and --config-file for paths"
          },
          {
            "sha": "24b2f399fa17572b9ffb64dd3e2ee1049a15aa7b",
            "url": "https://github.com/google/ax/commit/24b2f399fa17572b9ffb64dd3e2ee1049a15aa7b",
            "committedAt": "2026-07-22T19:05:48Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "docs: update README features list to highlight MCP tools and custom environment support",
            "message": "docs: update README features list to highlight MCP tools and custom environment support"
          },
          {
            "sha": "bab973e877a32444af8283e4f850912ef7345a98",
            "url": "https://github.com/google/ax/commit/bab973e877a32444af8283e4f850912ef7345a98",
            "committedAt": "2026-07-22T19:13:19Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "refactor: rename seq to step across protocol and internal controller logic",
            "message": "refactor: rename seq to step across protocol and internal controller logic"
          },
          {
            "sha": "c0d8e5bf10c2ae0ecfefa93bc9c727b7eeed9714",
            "url": "https://github.com/google/ax/commit/c0d8e5bf10c2ae0ecfefa93bc9c727b7eeed9714",
            "committedAt": "2026-07-22T19:15:28Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "refactor: remove dashboard implementation and web assets",
            "message": "refactor: remove dashboard implementation and web assets"
          },
          {
            "sha": "5ec51983e13d18d8e7ead94972113f19942dad50",
            "url": "https://github.com/google/ax/commit/5ec51983e13d18d8e7ead94972113f19942dad50",
            "committedAt": "2026-07-22T19:19:30Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "refactor: move antigravity configuration to top-level and rename HarnessesConfig to RegistryConfig",
            "message": "refactor: move antigravity configuration to top-level and rename HarnessesConfig to RegistryConfig"
          },
          {
            "sha": "16db0d7a0fc3a3a96c44b2a7545754f5dfdb48ae",
            "url": "https://github.com/google/ax/commit/16db0d7a0fc3a3a96c44b2a7545754f5dfdb48ae",
            "committedAt": "2026-07-22T19:24:07Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "refactor: simplify CLI by removing the exec subcommand and moving its flags to the root command",
            "message": "refactor: simplify CLI by removing the exec subcommand and moving its flags to the root command"
          },
          {
            "sha": "d1a3da114281ec9438da0c3c98772433e392938e",
            "url": "https://github.com/google/ax/commit/d1a3da114281ec9438da0c3c98772433e392938e",
            "committedAt": "2026-07-22T19:25:38Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "docs: format bash command examples for better readability in README.md",
            "message": "docs: format bash command examples for better readability in README.md"
          },
          {
            "sha": "b019d135ce1917c6e7defaf7653cca928384c3ea",
            "url": "https://github.com/google/ax/commit/b019d135ce1917c6e7defaf7653cca928384c3ea",
            "committedAt": "2026-07-22T19:27:26Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "chore: add Google LLC copyright headers to generated protocol buffer files",
            "message": "chore: add Google LLC copyright headers to generated protocol buffer files"
          },
          {
            "sha": "d4c5c352e034547fa7c5d2006d12e3a2c2ce2503",
            "url": "https://github.com/google/ax/commit/d4c5c352e034547fa7c5d2006d12e3a2c2ce2503",
            "committedAt": "2026-07-22T19:28:28Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "chore: rename --config flag to --ax-config for consistency",
            "message": "chore: rename --config flag to --ax-config for consistency"
          },
          {
            "sha": "f4ad177adbb697d8ff9458f23eca03e64c280719",
            "url": "https://github.com/google/ax/commit/f4ad177adbb697d8ff9458f23eca03e64c280719",
            "committedAt": "2026-07-22T19:30:30Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "docs: rename --config flag to --ax-config in README examples",
            "message": "docs: rename --config flag to --ax-config in README examples"
          },
          {
            "sha": "19be3958f3dec9e0a7175ae85e053b323217ded9",
            "url": "https://github.com/google/ax/commit/19be3958f3dec9e0a7175ae85e053b323217ded9",
            "committedAt": "2026-07-22T19:31:28Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "docs: remove specific harness and model controller descriptions from README",
            "message": "docs: remove specific harness and model controller descriptions from README"
          },
          {
            "sha": "0f8f36c8d5a7299099cfc8e6b9bec31be06fbde6",
            "url": "https://github.com/google/ax/commit/0f8f36c8d5a7299099cfc8e6b9bec31be06fbde6",
            "committedAt": "2026-07-22T19:32:24Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "docs: simplify quickstart section and fix formatting in README.md",
            "message": "docs: simplify quickstart section and fix formatting in README.md"
          },
          {
            "sha": "d9a0f75ed243547c2df6c6e7fb68d888f27d92e8",
            "url": "https://github.com/google/ax/commit/d9a0f75ed243547c2df6c6e7fb68d888f27d92e8",
            "committedAt": "2026-07-22T19:38:41Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "docs: update usage documentation for ax execute and serve commands",
            "message": "docs: update usage documentation for ax execute and serve commands"
          },
          {
            "sha": "0f8d4c62ed00b6b2531fae1c14728d0a232d669c",
            "url": "https://github.com/google/ax/commit/0f8d4c62ed00b6b2531fae1c14728d0a232d669c",
            "committedAt": "2026-07-22T19:57:49Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "refactor: remove unused history confirmation utility functions",
            "message": "refactor: remove unused history confirmation utility functions"
          },
          {
            "sha": "4474dff3cd54303b442ec6eff4adf605e09a9273",
            "url": "https://github.com/google/ax/commit/4474dff3cd54303b442ec6eff4adf605e09a9273",
            "committedAt": "2026-07-22T19:59:02Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "refactor: move ate package from internal/k8s to internal/ to decouple from Kubernetes dependencies",
            "message": "refactor: move ate package from internal/k8s to internal/ to decouple from Kubernetes dependencies"
          },
          {
            "sha": "cbd2c564376d2e487ac0623d6e54650d929e17a7",
            "url": "https://github.com/google/ax/commit/cbd2c564376d2e487ac0623d6e54650d929e17a7",
            "committedAt": "2026-07-23T05:30:04Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "Jaana Dogan",
            "title": "refactor: update install script paths in documentation and manifest comments",
            "message": "refactor: update install script paths in documentation and manifest comments"
          },
          {
            "sha": "f327e23b5b842e9b700675ded9a6cdb79c505856",
            "url": "https://github.com/google/ax/commit/f327e23b5b842e9b700675ded9a6cdb79c505856",
            "committedAt": "2026-07-28T20:04:19Z",
            "author": "zbl94",
            "authorName": "Zhengbo Li",
            "committerName": "GitHub",
            "title": "skills: add local directory source alongside the registry (#316)",
            "message": "skills: add local directory source alongside the registry (#316)\n\nIntroduce a local skills source parallel to the Gemini Enterprise Skill\nRegistry integration. A local source points at a directory already on disk\n(a parent dir holding <skill-id>/SKILL.md subfolders, the same layout as\nexamples/skills and a registry's target_dir); nothing is fetched and the\ndirectory is used as-is.\n\n- New mode-agnostic result shape (internal/skills: Available/Group/Skill) so\n  both sources feed the same consumers without either depending on the other.\n- internal/skills/local.Discover enumerates enabled local paths, treating\n  immediate subfolders with a SKILL.md as skills (subfolder name = id). It is\n  fail-safe like registry materialization: a missing/unreadable/empty path is\n  logged and skipped, never blocking harness creation.\n- config.SkillsConfig gains Local []LocalSkillsConfig (enabled + path) with\n  validation; geminienterprise.Materialize now returns skills.Available.\n- cliutil combines registry and local groups into one system-instruction\n  pointer for the Antigravity Interactions harness. The Antigravity SDK\n  harness (SKILLS_DIR-based) is left as a TODO.\n\nOnly the interactions harness is wired; tests cover discovery, fail-safe\ndegradation, config validation, and the examples/skills fixture."
          }
        ]
      },
      "records": [
        {
          "repository": "google/ax",
          "number": 241,
          "url": "https://github.com/google/ax/pull/241",
          "title": "Regenerate proto files",
          "body": "Fixes #240.",
          "author": "rakyll",
          "createdAt": "2026-07-03T22:05:10Z",
          "mergedAt": "2026-07-06T05:47:50Z",
          "additions": 134,
          "deletions": 41,
          "changedFiles": 7
        },
        {
          "repository": "google/ax",
          "number": 239,
          "url": "https://github.com/google/ax/pull/239",
          "title": "Fix spacing between AGY harness responses",
          "body": "The AGY harness streams each contiguous block of assistant text as a separate TextContent message, with tool calls in between. The CLI display (cmd/ax/internal/display.go) tracks a state field to decide when to insert separating newlines  but the Content_ToolCall case was a pure no-op that left state == stateText.\r\n\r\nFixes #233.",
          "author": "rakyll",
          "createdAt": "2026-07-03T21:42:42Z",
          "mergedAt": "2026-07-06T05:48:06Z",
          "additions": 44,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 236,
          "url": "https://github.com/google/ax/pull/236",
          "title": "Make Postgres optional on substrate deployments",
          "body": "### Changes\r\nAdds a `--no-postgres` flag to `hack/install-ax.sh` so a substrate deployment can\r\nskip the Postgres StatefulSet and run with an ephemeral **SQLite** event log\r\ninstead. Fix #168.\r\n- manifests/ax-postgres.yaml (new): Moved out from ax-deployment.yaml. The Postgres Service + Secret +\r\n  StatefulSet, applied only in the default (Postgres) mode.\r\n- hack/install-ax.sh:\r\n  - New `--no-postgres` flag.\r\n  - Default mode: applies ax-deployment.yaml + ax-postgres.yaml with\r\n    AX_SERVER_REPLICAS=3, resolves/generates the Postgres password, and waits\r\n    for the Postgres StatefulSet.\r\n  - `--no-postgres`: applies only ax-deployment.yaml with\r\n    AX_SERVER_REPLICAS=1, rewriting the ConfigMap's eventlog block to\r\n    sqlite: filename: \"/tmp/ax-eventlog/log.sqlite\".\r\n\r\n### Tested\r\n```\r\n./hack/install-ax.sh --deploy-ax-server               # Postgres (default, unchanged)\r\n./hack/install-ax.sh --deploy-ax-server --no-postgres # ephemeral SQLite\r\n```",
          "author": "wjjclaud",
          "createdAt": "2026-07-01T19:42:40Z",
          "mergedAt": "2026-07-06T17:13:19Z",
          "additions": 164,
          "deletions": 102,
          "changedFiles": 4
        },
        {
          "repository": "google/ax",
          "number": 242,
          "url": "https://github.com/google/ax/pull/242",
          "title": "Rename ControllerService to ExecutionService",
          "body": "",
          "author": "rakyll",
          "createdAt": "2026-07-06T05:58:12Z",
          "mergedAt": "2026-07-06T17:30:47Z",
          "additions": 98,
          "deletions": 191,
          "changedFiles": 11
        },
        {
          "repository": "google/ax",
          "number": 243,
          "url": "https://github.com/google/ax/pull/243",
          "title": "Move Harness implementations to their own packages",
          "body": "Fixes #232.",
          "author": "rakyll",
          "createdAt": "2026-07-06T20:47:26Z",
          "mergedAt": "2026-07-06T21:00:58Z",
          "additions": 149,
          "deletions": 133,
          "changedFiles": 13
        },
        {
          "repository": "google/ax",
          "number": 244,
          "url": "https://github.com/google/ax/pull/244",
          "title": "harness/python: normalize thought summary whitespace (#191)",
          "body": "Fixes #191.\n\n## Context\n\nGemini's thinking summaries contain runs of `\\n\\n\\n` between reasoning\nsections and often trailing `\\n\\n`. Previously, the Python AGY harness\nstreamed these payloads verbatim over gRPC to the AX controller. This\nmeant every downstream client (`cmd/ax/internal/display.go`, the Web\nDashboard, and any future one) would need to know to scrub Gemini's\nparticular whitespace quirks.\n\n## Fix\n\nNormalize the payload in the Python harness adapter — the same layer\nalready responsible for shielding downstream clients from\nmodel/SDK-specific representations. In `flush_thought()`:\n\n1. Collapse runs of 3+ newlines to a single blank line (`\\n{3,}` → `\\n\\n`).\n2. `rstrip()` trailing whitespace so the payload doesn't leak trailing\n   newlines into downstream renderers.\n3. Append exactly one trailing newline so downstream displays render\n   a blank line between the thinking block and whatever follows (next\n   thought, tool call, or answer text). Without this, `display.go`'s\n   single-newline transition would glue blocks together.\n\n## End-to-end validation\n\nVerified against a live `ax exec --harness antigravity` with a real\nVertex AI Gemini backend. Sample output:\n\n```\n⏺ what's the weather in New York City\n\nThinking: **Searching Web for Data**\n\nI'm currently focusing on acquiring the necessary weather data for New York City. Since I lack a direct tool, I'm preparing to utilize the `search_web` function to locate this information.\n\n**Exploring Web Search Options**\n\nI'm focusing on how to best retrieve New York City weather data. As I don't have a dedicated weather tool, I'll be employing the `search_web` function. My initial query will be \"weather in New York City.\"\n\nThinking: **Finding Weather Forecasts**\n\nI've successfully retrieved the New York City weather forecast using my search capabilities. I can now present these details to you.\n\n**Presenting Weather Data**\n\nI've successfully gathered the New York City weather forecast and am now ready to share the detailed information with you.\n\nIt is currently raining in New York City with a temperature of 69°F (21°C)...\n```\n\n- Single blank line between reasoning sections within a `Thinking:` block ✓\n- Single blank line between consecutive `Thinking:` blocks ✓\n- Single blank line between the last `Thinking:` block and the answer text ✓\n- No runs of 2+ blank lines anywhere ✓\n\nCompare to the buggy output in the issue where blank-line runs appeared\nin all three positions.\n\n## Alternatives considered\n\n* **Do the normalization in `cmd/ax/internal/display.go`.** Rejected\n  per Jaana's review: it would put model/SDK-specific whitespace\n  quirks into a generic renderer, and would need to be duplicated in\n  every other client (Web Dashboard, etc.). PR #239 handles\n  *structural* boundary spacing (between different `Content` types)\n  in the display, which is appropriate; but payload cleanup belongs\n  in the adapter.\n* **Rely on the AGY SDK to normalize.** The SDK documents\n  `thinking_delta` as a raw incremental substring, so a lossy\n  normalization there would break the SDK's contract for other\n  consumers.\n* **Skip the trailing `+ '\\n'` and let display handle separation.**\n  Live testing revealed this glues consecutive thinking blocks\n  together (no blank line between them) because `display.go`'s\n  thought-transition logic emits only one `\\n`. The trailing newline\n  produces the correct rendering with today's display code; if\n  display ownership of the transition changes later, the harness\n  contract can be revised.",
          "author": "joycel-github",
          "createdAt": "2026-07-06T20:48:31Z",
          "mergedAt": "2026-07-06T22:18:43Z",
          "additions": 13,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 254,
          "url": "https://github.com/google/ax/pull/254",
          "title": "Serve /readyz from ax harness server.",
          "body": "Fix #252.\r\n- ax harness now serves an HTTP /readyz endpoint (port 8081), gated on the Python harness's gRPC health. Substrate polls this endpoint during golden snapshotting and per-actor Run/Restore.\r\n- The ActorTemplate declares the matching readyz probe.\r\n- Bumps the pinned substrate version.\r\n- Fix an indeterministic/flaky error message in the RPC stream. It should return the actual server error.\r\n\r\nTested: Deploy and run on substrate.",
          "author": "wjjclaud",
          "createdAt": "2026-07-07T00:11:03Z",
          "mergedAt": "2026-07-07T01:04:29Z",
          "additions": 128,
          "deletions": 7,
          "changedFiles": 7
        },
        {
          "repository": "google/ax",
          "number": 256,
          "url": "https://github.com/google/ax/pull/256",
          "title": "Remove examples/skills/ from the Dockerfile",
          "body": "Fixes #253.",
          "author": "rakyll",
          "createdAt": "2026-07-07T01:07:34Z",
          "mergedAt": "2026-07-07T01:12:24Z",
          "additions": 5,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 255,
          "url": "https://github.com/google/ax/pull/255",
          "title": "Use /axharness folder in the snapshots bucket",
          "body": "The ax harness server will provide more than Antigravity.\r\n\r\nDepends on https://github.com/google/ax/pull/254.",
          "author": "rakyll",
          "createdAt": "2026-07-07T01:03:09Z",
          "mergedAt": "2026-07-07T01:12:38Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 257,
          "url": "https://github.com/google/ax/pull/257",
          "title": "Rename KO_DOCKER_REPO to AX_IMAGE_REPO",
          "body": "Fixes #247.",
          "author": "rakyll",
          "createdAt": "2026-07-07T01:12:00Z",
          "mergedAt": "2026-07-07T01:13:46Z",
          "additions": 10,
          "deletions": 10,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 259,
          "url": "https://github.com/google/ax/pull/259",
          "title": "Make /workspace the default working directory on Substrate",
          "body": "Fixes #258.",
          "author": "rakyll",
          "createdAt": "2026-07-07T01:39:15Z",
          "mergedAt": "2026-07-07T02:43:03Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 273,
          "url": "https://github.com/google/ax/pull/273",
          "title": "Introduce pythonsidecar package",
          "body": "We need an optional step to extract embedded python/ directory and install the Python modules for the local experience.",
          "author": "rakyll",
          "createdAt": "2026-07-07T21:38:37Z",
          "mergedAt": "2026-07-07T23:50:18Z",
          "additions": 433,
          "deletions": 15,
          "changedFiles": 3
        },
        {
          "repository": "google/ax",
          "number": 274,
          "url": "https://github.com/google/ax/pull/274",
          "title": "Serve the Antigravity Interactions harness over HarnessService",
          "body": "Add a Go HarnessService server for the Antigravity Interactions harness so it can run as a substrate actor, alongside the existing Python sidecar path.\r\n\r\n- internal/harness/antigravityinteractions/server.go: Serve(...) stands up the gRPC HarnessService (plus gRPC health) and an HTTP /readyz endpoint reflecting this server's own serving state, with graceful shutdown on ctx-cancel or SIGINT/SIGTERM. Connect adapts the harness onto the wire contract: a start frame drives one turn (Start -> Queue -> Run), each agent message is streamed as a HarnessResponse{outputs} frame, and the stream terminates with exactly one HarnessResponse{end} (COMPLETED/FAILED/ CANCELED); a mid-stream cancel frame cancels the run.\r\n- cmd/ax/harness.go: add a thin runAntigravityInteractionsHarness(ctx, systemInstructions) entrypoint that builds the config and calls Serve; the dispatch layer decides when to invoke it.\r\n- server_test.go: bufconn tests for the start->end contract and rejection of a non-start first frame.",
          "author": "zbl94",
          "createdAt": "2026-07-07T23:00:02Z",
          "mergedAt": "2026-07-08T16:42:28Z",
          "additions": 397,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "google/ax",
          "number": 275,
          "url": "https://github.com/google/ax/pull/275",
          "title": "Auto-start Antigravity Python sidecar from ax exec",
          "body": "Progresses #249 (autofork done; PYTHONPATH & pip install still user responsibility — see Scope + Known limitation)\n\n## Scope\n\nThis PR only wires the sidecar startup via `pythonsidecar`. It does **not** install the Python runtime dependencies of `python/antigravity/harness_server.py`. Users are expected to have them installed before running `ax exec`:\n\n```\npip install -r python/antigravity/requirements.txt\n```\n\n## Known limitation: set `PYTHONPATH` before `ax exec`\nLocal users need to manually prepend the repo root and `python/` to `PYTHONPATH`:\n```bash\nexport PYTHONPATH=\"$PWD:$PWD/python:$PYTHONPATH\"\n```\nWithout this, the sidecar fork fails with:\n```\nImportError: cannot import name 'content_pb2' from 'proto' (unknown location)\n```\n**Root cause.** `harness_server.py` uses `from python.proto import ax_pb2` (needs repo root on `sys.path`) while generated `ax_pb2.py` uses `from proto import content_pb2` (needs `python/` on `sys.path`). Python's default `sys.path` satisfies only one. This has been the case since PR #34 introduced the streaming harness.\n**Substrate is unaffected.** `cmd/ax/Dockerfile:64` sets `ENV PYTHONPATH=/ax-app:/ax-app/python`, so pods inherit it via the container image.\n**Follow-up.** `go:embed`-ing `python/` into the ax binary and pointing `PYTHONPATH` at the extracted cache dir. Out of scope for this PR.\n\n## Summary\n\n`ax exec` now forks the Antigravity Python sidecar automatically via `pythonsidecar` (#273). Users no longer need to run `ax harness` in a separate terminal.\n\n## Design rationale\n\nThis PR is intentionally minimal. An earlier attempt (#251, 1122 lines) shipped the full CUJ end-to-end — identity probe to distinguish AGY vs foreign sidecars, `Pdeathsig` for parent-crash cleanup, a shared autostart package for future harnesses, and an `AX_ANTIGRAVITY_NO_AUTOSTART` escape hatch. Post-review discussion converged on stacking the work as smaller PRs: land the minimum autofork here, add each capability as its own reviewable follow-up. This PR is that minimum. Known follow-ups (all `TODO`'d in code or tracked as issues):\n\n- Reuse an existing AGY sidecar via a named gRPC health service identity probe (currently: any port-in-use fails the fork)\n- Parent-crash cleanup (`Pdeathsig` on Linux)\n- Auto PYTHONPATH via `go:embed` (#270 / addressed by #276)\n- Auto `pip install` at first run\n\n## API\n\n- `antigravity.New(ctx, address, autoStart)` — when `autoStart=true`, forks the sidecar, waits for `TCPReady`, installs a signal handler that stops it on SIGINT/SIGTERM.\n- `cliutil.NewControllerFromConfig` passes `autoStart=true` in local mode.\n\nSubstrate mode and the e2e demo pass `autoStart=false` (unchanged behavior).\n\n## Tests\n1. unit test \n2. manual run \n\n(.venv) lhuan@lhuan:~/ax-test$ ./ax exec --input \"hi\"\nStarting gRPC harness server on 127.0.0.1:50053...\nConversation: 7b7974ff-0b58-445b-a836-ca41e3500f43\n\n⏺ hi\n\n[gRPC] Connect turn requested. conv_id=7b7974ff-0b58-445b-a836-ca41e3500f43\n[gRPC] Creating new Agent instance for conv_id=7b7974ff-0b58-445b-a836-ca41e3500f43\n[gRPC] Running chat query: hi\n[gRPC] Turn completed successfully.\nHello! How can I help you today?\nseq=2\n",
          "author": "joycel-github",
          "createdAt": "2026-07-08T00:56:53Z",
          "mergedAt": "2026-07-08T19:37:59Z",
          "additions": 137,
          "deletions": 41,
          "changedFiles": 5
        },
        {
          "repository": "google/ax",
          "number": 277,
          "url": "https://github.com/google/ax/pull/277",
          "title": "Antigravity interactions harness registry and config",
          "body": "Wires the built-in Antigravity Interactions harness into the controller for #271.\r\n- Config (internal/config): new antigravity interactions harness config.\r\n- Registry wiring (cmd/ax/internal/cliutil): registers for both local mode and substrate mode.\r\n- Default state dir: move the default state dir helper to the shared package.\r\n- Example yaml commented out for enabling in followups.\r\n\r\n### Tested\r\nOn local mode, uncomment config in `ax.yaml`\r\n`export GOOGLE_CLOUD_PROJECT=<project_ID>`\r\n`go run ./cmd/ax exec --harness antigravity-interactions --input \"hello\"`\r\n\r\n### Follow up\r\nRouting in `ax harness` for substrate mode.",
          "author": "wjjclaud",
          "createdAt": "2026-07-08T23:14:06Z",
          "mergedAt": "2026-07-09T00:43:49Z",
          "additions": 159,
          "deletions": 44,
          "changedFiles": 9
        },
        {
          "repository": "google/ax",
          "number": 276,
          "url": "https://github.com/google/ax/pull/276",
          "title": "Embed python artifacts into ax",
          "body": "This change embeds the python/ directory into the ax binary.\r\n\r\n- At runtime, it extracts the python/ directory to `~/.ax/python`.\r\n- It runs, `pip install -r requirements.txt`\r\n- And starts the AGY harness service.\r\n\r\nThis is a hack until `antigravityinteractions` package is ready to replace `antigravity`.\r\n\r\nTested:\r\n\r\n- [x]  Locally\r\n- [x]  On Substrate",
          "author": "rakyll",
          "createdAt": "2026-07-08T22:52:59Z",
          "mergedAt": "2026-07-09T02:28:19Z",
          "additions": 308,
          "deletions": 82,
          "changedFiles": 8
        },
        {
          "repository": "google/ax",
          "number": 278,
          "url": "https://github.com/google/ax/pull/278",
          "title": "Setup ~/.ax/antigravity once until a new update arrives",
          "body": "- Check if any files in the embed.FS has changed. If not, skip pip install.\r\n- Consolidate .ax directory path resolution into a centralized config helper\r\n",
          "author": "rakyll",
          "createdAt": "2026-07-09T02:45:58Z",
          "mergedAt": "2026-07-09T05:08:10Z",
          "additions": 64,
          "deletions": 46,
          "changedFiles": 4
        },
        {
          "repository": "google/ax",
          "number": 280,
          "url": "https://github.com/google/ax/pull/280",
          "title": "Add instructions for accessing ax server via port-forwarding in ax-install.sh",
          "body": "",
          "author": "rakyll",
          "createdAt": "2026-07-09T05:18:02Z",
          "mergedAt": "2026-07-09T06:18:26Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 279,
          "url": "https://github.com/google/ax/pull/279",
          "title": "ax command should start without an ax.yaml",
          "body": "Fixes #260.",
          "author": "rakyll",
          "createdAt": "2026-07-09T05:07:50Z",
          "mergedAt": "2026-07-09T06:18:45Z",
          "additions": 7,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 285,
          "url": "https://github.com/google/ax/pull/285",
          "title": "Harden Antigravity Interactions harness HTTP client",
          "body": "Fix a substrate suspend/resume failure and tighten the config surface:\r\n\r\n- Disable HTTP keep-alives on the harness's default client. On substrate the actor is suspended after a turn and resumed for the next (with a new routable IP), which leaves any pooled keep-alive connection stale; reusing it made the next turn's request fail. Opening a fresh connection per request avoids that at the cost of an extra handshake.\r\n- Remove the public HTTPClient override from AntigravityInteractionsConfig. External callers don't configure the harness's transport, and exposing it risked silently reintroducing the keep-alive bug. New now always owns its (keep-alive-disabled) client; tests inject a fake transport via an unexported newWithHTTPClient seam.\r\n- Reorder AntigravityInteractionsConfig fields to list required (Agent, StateDir) before optional, with clearer doc comments.\r\n\r\nBuild and package tests pass.",
          "author": "zbl94",
          "createdAt": "2026-07-09T19:41:28Z",
          "mergedAt": "2026-07-09T21:08:06Z",
          "additions": 44,
          "deletions": 27,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 284,
          "url": "https://github.com/google/ax/pull/284",
          "title": "Delete obsolete Makefile targets",
          "body": "- Container image is built from a Dockerfile and the existing targets in the Makefile are not used.\r\n- Remote agents is removed a part of the unified harness refactor.",
          "author": "rakyll",
          "createdAt": "2026-07-09T19:38:48Z",
          "mergedAt": "2026-07-09T21:44:58Z",
          "additions": 1,
          "deletions": 25,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 288,
          "url": "https://github.com/google/ax/pull/288",
          "title": "Surface server error events in Antigravity Interactions harness",
          "body": "parseStreamedTurn only handled interaction.* and step.* SSE events; a server-emitted \"error\" event fell through the switch and was silently dropped. The turn then returned as completed-but-empty, which:\r\n\r\n  - made a failure (e.g. INVALID_ARGUMENT for a malformed client tool result) look like a blank \"no response\" turn, and\r\n  - persisted the failing interaction's id as a poisoned resume cursor.\r\n\r\nAdd an \"error\" case that returns a real error, plus a serverErrorMessage helper that extracts message/status from the error payload. Now a turn-level server failure aborts the turn with a descriptive error instead of being hidden.\r\n\r\nAdds tests for the error-event path and serverErrorMessage formatting.",
          "author": "zbl94",
          "createdAt": "2026-07-09T22:26:34Z",
          "mergedAt": "2026-07-09T23:24:28Z",
          "additions": 101,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 287,
          "url": "https://github.com/google/ax/pull/287",
          "title": "Run Antigravity Interactions as substrate actors",
          "body": "A simple working version that serves both antigravity and interactions harness on substrate. Fix #271. \r\n- Add ax harness [harness-id] positional selection so the ax harness binary can serve either built-in harness based on the harness id in the execution request.\r\n- ActorTemplate\r\n  - Antigravity: `ax-harness-antigravity-template`\r\n  - Antigravity Interactions: `ax-harness-interactions-template`\r\n- Document the Vertex AI (Workload Identity) IAM prerequisite the interactions harness needs.\r\n\r\n### Tested\r\nDeploy: `./hack/install-ax.sh --deploy-ax-server --deploy-postgres`\r\nRun both harnesses:\r\n- `ax exec --server=localhost:8494 --harness=antigravity-interactions`\r\n- `ax exec --server=localhost:8494 --harness=antigravity`",
          "author": "wjjclaud",
          "createdAt": "2026-07-09T22:25:10Z",
          "mergedAt": "2026-07-10T00:44:00Z",
          "additions": 119,
          "deletions": 27,
          "changedFiles": 8
        },
        {
          "repository": "google/ax",
          "number": 289,
          "url": "https://github.com/google/ax/pull/289",
          "title": "Replace Antigravity sidecar in-memory Agent cache with SDK-native resume",
          "body": "## Problem\r\n\r\nAntigravity harness caches Agent per conversation in memory. Substrate snapshot won't include memory, and local server restarts when a conversation resumes. This setup doesn't work for conversation\r\nresumption.\r\n\r\n## Assumption \r\n\r\n1. Single writer so no lock needed \r\n\r\n## Fix\r\n\r\n1. Delete the cache. \r\n3. Use `LocalAgentConfig`'s native `(conversation_id,save_dir)` — SDK persists trajectory state to\r\n`{save_dir}/{sdk_conv_id}.db`. \r\n4. **Note:** Each AX conversation gets its own directory under `~/.ax/antigravity/conversations/{ax_conv_id}/`; on\r\nsubsequent turns we discover the SDK's hash-id from the `.db` filename\r\nand pass it back to resume.\r\n\r\n**This is because SDK's `conversation_id` is resume-only — passing a non-existent id errors.** Hence discover-then-pass, not pass-always. \r\n\r\nAlternatively we can store the {AX convs_id : AGY convs_id} separately but this simplify the overall logic and setup \r\n\r\n## Next\r\n\r\n`save_dir` is hardcoded here. Should be injected by controller via `harness_config` — see #269, #203. TODO in code.\r\n\r\n## Tasks\r\n\r\n- [x] Test local (`ax exec --conversation <id>` across fresh sidecar\r\n      processes → resume works, isolation works)\r\n- [x] Test substrate",
          "author": "joycel-github",
          "createdAt": "2026-07-09T23:30:48Z",
          "mergedAt": "2026-07-10T03:45:27Z",
          "additions": 149,
          "deletions": 175,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 293,
          "url": "https://github.com/google/ax/pull/293",
          "title": "Use GOOGLE_CLOUD_PROJECT variable and remove PROJECT_ID usage",
          "body": "Fixes https://github.com/google/ax/issues/290.",
          "author": "rakyll",
          "createdAt": "2026-07-10T17:26:16Z",
          "mergedAt": "2026-07-10T21:23:48Z",
          "additions": 10,
          "deletions": 10,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 294,
          "url": "https://github.com/google/ax/pull/294",
          "title": "Update GOOGLE_CLOUD_PROJECT for interactions path.",
          "body": "",
          "author": "wjjclaud",
          "createdAt": "2026-07-10T21:30:53Z",
          "mergedAt": "2026-07-10T21:34:18Z",
          "additions": 5,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 291,
          "url": "https://github.com/google/ax/pull/291",
          "title": "harness/python: fix stale thought summary test assertions",
          "body": "Fix 2 stale test assertions in `python/antigravity/harness_server_test.py`.\r\n\r\nformer PR changed the format but this test didn't get auto triggered  \r\n\r\nNext: make python test auto triggered ",
          "author": "joycel-github",
          "createdAt": "2026-07-10T08:10:37Z",
          "mergedAt": "2026-07-11T00:30:27Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 292,
          "url": "https://github.com/google/ax/pull/292",
          "title": "Antigravity sidecar state dir from config",
          "body": "Follow-up to #289.\r\n## Problem\r\nSidecar's trajectory storage directory was hardcoded in Python. No way\r\nfor users to relocate it.\r\n## Fix\r\nPlumb `state_dir` through: `ax.yaml` → `AntigravityHarnessConfig` → Go\r\nclient → sidecar `--state-dir` arg. Mirrors the existing\r\n`antigravity-interactions.state_dir` pattern.\r\nPython default (`~/.ax/antigravity/conversations`) kept as transitional\r\nfallback for substrate mode (ActorTemplate doesn't inject the flag\r\nyet); removable once it does.\r\n## Tasks\r\n- [x] Test local\r\n- [ ] Test substrate",
          "author": "joycel-github",
          "createdAt": "2026-07-10T09:46:37Z",
          "mergedAt": "2026-07-13T16:55:03Z",
          "additions": 56,
          "deletions": 35,
          "changedFiles": 8
        },
        {
          "repository": "google/ax",
          "number": 296,
          "url": "https://github.com/google/ax/pull/296",
          "title": "ci: run Python tests for the antigravity harness sidecar",
          "body": "\r\n- Wires the 17 antigravity harness sidecar tests (`python/antigravity/harness_server_test.py`) into CI. They have never run automatically — `.github/workflows/go.yml` only runs `go test ./...`, which is how the stale assertions fixed in #291 slipped through.\r\n- Adds `.github/workflows/python.yml`, a dedicated Python workflow kept separate from the Go-only `go.yml` so each can evolve independently.\r\n- Adds a `test-python` Makefile target for local parity.\r\n\r\n",
          "author": "joycel-github",
          "createdAt": "2026-07-11T00:40:30Z",
          "mergedAt": "2026-07-13T16:55:25Z",
          "additions": 63,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 295,
          "url": "https://github.com/google/ax/pull/295",
          "title": "parse harness config from request",
          "body": "Parse `HarnessStart.harness_config` (delivered to the sidecar as json in bytes )\r\ninto a JSON object and overlay it onto the server's `LocalAgentConfig` before each turn.\r\n\r\nMinimum parsing and validation logic in the adapter as intended  \r\n- Only blocks a request from overriding AX-owned setup (`save_dir`,\r\n  `conversation_id`); these are injected last so a request can't redirect\r\n  trajectory storage.\r\n- No distinction between request-time vs conversation-creation overrides\r\n  -- intentionally left to the harness behind the adapter.\r\n- No validation yet for fields only meaningful to a runtime request, not\r\n  harness_config (e.g. confirmation). Rejected today since\r\n  `LocalAgentConfig` doesn't accept them.\r\n\r\nConfig is reconstructed (not `model_copy`'d) so the SDK re-validates and\r\nsurfaces its own error; invalid config fails the turn with\r\n`INVALID_ARGUMENT` instead of crashing.\r\n\r\n## Next\r\n- Error on `LocalAgentConfig` unknown fields (pydantic silently drops\r\n  them today; TODO in code).\r\n- Merge the `state_dir` change from #292.\r\n\r\n## Verification\r\nLocal `ax exec --harness-config-json`: valid override applied, AX-owned\r\nfield rejected, SDK validation error surfaced, malformed JSON rejected,\r\nresume intact across a per-turn override.",
          "author": "joycel-github",
          "createdAt": "2026-07-11T00:24:12Z",
          "mergedAt": "2026-07-13T21:55:05Z",
          "additions": 165,
          "deletions": 17,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 301,
          "url": "https://github.com/google/ax/pull/301",
          "title": "antigravity: reject unknown harness_config fields",
          "body": "Add validation for unknown fields against `LocalAgentConfig`.\r\n\r\nclean up the TODO for validate and reject LocalAgentConfig unknown fields. \r\nLocalAgentConfig currently silently ignore the unknown fields. \r\n\r\n## Tested via `ax exec`\r\n\r\nUnknown field → rejected:\r\n```\r\n$ ax exec --harness-config-json '{\"system_instruction\":\"typo\"}' --input \"hi\"\r\nError: ... [3] Invalid harness_config: unknown config field(s): system_instruction\r\n``\r\n\r\nValid override → applied:\r\n```\r\n$ ax exec --harness-config-json '{\"system_instructions\":\"You are a pirate. One short sentence.\"}' --input \"What is 2+2?\"\r\nAhoy, 2+2 be makin' 4, ye scurvy dog!\r\n```\r\n",
          "author": "joycel-github",
          "createdAt": "2026-07-13T23:37:22Z",
          "mergedAt": "2026-07-14T00:04:50Z",
          "additions": 48,
          "deletions": 16,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 302,
          "url": "https://github.com/google/ax/pull/302",
          "title": "[substrate] Interactions actor reads harness config from ax.yaml",
          "body": "Previously, the Antigravity Interactions harness always use default value on substrate deployment. Its config in ax.yaml is only used by local path.\r\n\r\n#### Changes\r\n- Through an env var `AX_CONFIG_CONTENT`, Antigravity Interactions harness reads its deploy config (agent, state_dir) from ax.yaml on the substrate/actor path, with fallback to built-in defaults.\r\n- Split the configMap into a separate file `manifests/ax.yaml`. It's used by both the controller ConfigMap and the actor's env var.\r\n- The config plumbing will be used by Antigravity Interactions harness skills registry on substrate mode.\r\n\r\n#### Tested\r\nDeployed and run on substrate. Both SDK and Interactions work.",
          "author": "wjjclaud",
          "createdAt": "2026-07-14T00:39:19Z",
          "mergedAt": "2026-07-14T20:03:02Z",
          "additions": 109,
          "deletions": 22,
          "changedFiles": 6
        },
        {
          "repository": "google/ax",
          "number": 304,
          "url": "https://github.com/google/ax/pull/304",
          "title": "antigravity: stop exposing harness state_dir in ax.yaml",
          "body": "remove state_dir from ax.yaml for both antigravity and interaction harness. \r\n\r\nthis is to resolve the follow-up from https://github.com/google/ax/pull/292#discussion_r3562628246",
          "author": "joycel-github",
          "createdAt": "2026-07-14T19:49:51Z",
          "mergedAt": "2026-07-14T20:28:49Z",
          "additions": 54,
          "deletions": 39,
          "changedFiles": 6
        },
        {
          "repository": "google/ax",
          "number": 300,
          "url": "https://github.com/google/ax/pull/300",
          "title": "Add GEAP Skill Registry integration for local harnesses",
          "body": "Materialize agentskills.io skills from the GEAP Skill Registry (Vertex AI v1beta1) into an on-disk skills directory before a harness starts, so the Antigravity and Antigravity Interactions harnesses can use registry-hosted skills on the local `ax exec` / `ax serve` path.\r\n\r\n- internal/skills/materialize: harness-agnostic package that reads config.SkillsConfig, drives the registry client (ListSkills / GetSkill / GetSkillRevision / skills:retrieve), safe-unzips payloads to <target_dir>/<skill-id>/, and reports what it wrote. First-wins on duplicate ids with a warning; fail-safe (a registry error never blocks harness startup).\r\n- config: harnesses.<id>.skills.registries[] with per-registry selection (skills / query / all), required target_dir, and a validated \"exactly one selection mode\" rule. Also wires the interactions harness's system_instruction from ax.yaml.\r\n- cliutil: materializes skills at controller construction; for the interactions harness (no SKILLS_DIR concept) it appends a discovery pointer to the system instruction.\r\n\r\nScope: local path only; the substrate/pod path does not yet read ax.yaml. Verified end-to-end against a live registry (by-id and by-query).",
          "author": "zbl94",
          "createdAt": "2026-07-13T20:20:50Z",
          "mergedAt": "2026-07-15T00:40:32Z",
          "additions": 1723,
          "deletions": 3,
          "changedFiles": 10
        },
        {
          "repository": "google/ax",
          "number": 311,
          "url": "https://github.com/google/ax/pull/311",
          "title": "antigravity format clean up - harness_server.py ",
          "body": "harness_server.py  is not formatted. When adding logical change, we only get irrelevant format delta and need to prompt to remove. Format this once. There is no real delta ",
          "author": "joycel-github",
          "createdAt": "2026-07-15T05:32:04Z",
          "mergedAt": "2026-07-15T17:27:16Z",
          "additions": 94,
          "deletions": 60,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 309,
          "url": "https://github.com/google/ax/pull/309",
          "title": "docs(readme): fix invalid harness in exec example",
          "body": "one line fix on ax harness sample command \n\nPart of #299",
          "author": "joycel-github",
          "createdAt": "2026-07-15T03:44:36Z",
          "mergedAt": "2026-07-15T17:28:02Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 310,
          "url": "https://github.com/google/ax/pull/310",
          "title": "docs(readme): refresh Antigravity setup, auth, and CLI usage",
          "body": "- Document the built-in Antigravity harness: local execution needs Python 3 + pip; AX auto-starts the Python sidecar and installs pinned SDK deps on first use.\n- Promote Authentication to its own section (Google AI Studio and Vertex AI/ADC) and earlier on ReadMe\n- Refresh Quick Start / Usage examples - document `--harness-config` / `--harness-config-json`, and add a per-request config example. Fix the example that referenced a nonexistent `coding` harness or wrong wordings \n\nStacked on #309. Part of #299",
          "author": "joycel-github",
          "createdAt": "2026-07-15T05:07:13Z",
          "mergedAt": "2026-07-15T17:28:16Z",
          "additions": 45,
          "deletions": 22,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 303,
          "url": "https://github.com/google/ax/pull/303",
          "title": "Honor view_file line range and cap result size",
          "body": "execViewFile read the whole file and ignored the agent's StartLine/EndLine, so viewing a large file returned its entire content as the tool result -- a ~900KB blob for a 3k-line CSV stalled the following turn.\r\n\r\nImplement the Antigravity view_file contract (1-indexed inclusive line range with slice-notation windowing) plus defensive caps:\r\n- StartLine/EndLine window (neither=first N lines; start-only=next N forward; end-only=previous N backward; both=precise range, capped to N).\r\n- viewFileMaxLines / viewFileMaxBytes caps so a large file can never blob.\r\n\r\nAdds intArg/intArgOK helpers and tests for windowing, byte cap + offset resume, and range honoring.",
          "author": "zbl94",
          "createdAt": "2026-07-14T18:26:42Z",
          "mergedAt": "2026-07-15T17:34:14Z",
          "additions": 511,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 308,
          "url": "https://github.com/google/ax/pull/308",
          "title": "Handle default harness correctly when resume a conversation.",
          "body": "Fix #306 \r\n\r\n- Resume a conversation should use the same harness stored in its log. Resume doesn't need to explicitly specify the harness via `--harness` flag.\r\n- Reject only an explicit harness ID is passed on resume.\r\n- In the conversation log, record the actual harness ID instead of empty string \"\" when starting a conversation with default harness.\r\n\r\n#### Tested\r\nRerun the sequence in #306 without error.",
          "author": "wjjclaud",
          "createdAt": "2026-07-15T03:11:12Z",
          "mergedAt": "2026-07-16T03:24:22Z",
          "additions": 221,
          "deletions": 29,
          "changedFiles": 5
        },
        {
          "repository": "google/ax",
          "number": 317,
          "url": "https://github.com/google/ax/pull/317",
          "title": "docs(readme): refresh Antigravity setup, auth, and CLI usage",
          "body": "## Summary\n- Document the built-in Antigravity harness: local execution needs `python3` and `pip` on `PATH`; AX auto-starts the Python sidecar and installs pinned SDK deps on first use.\n- Promote Authentication to its own top-level section (Google AI Studio and Vertex AI / ADC).\n- Refresh Quick Start / Usage examples, document `--harness-config` / `--harness-config-json`, and add a per-request config example.\n\n## Note\nRe-lands the content approved in #310, which was marked merged but never reached `main`: #310 was stacked on #309's branch, and #309 was squash-merged, orphaning this content. This PR targets `main` directly.\n\nPart of #299",
          "author": "joycel-github",
          "createdAt": "2026-07-16T07:39:45Z",
          "mergedAt": "2026-07-16T16:19:08Z",
          "additions": 45,
          "deletions": 22,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 305,
          "url": "https://github.com/google/ax/pull/305",
          "title": "Build separate python image for antigravity harness",
          "body": "Split the single combined `ax` image into two images:\r\n- **`ax`** — Used by the ax-server and the Go interactions harness.\r\n- **`ax-antigravity`** —  Used by the antigravity harness built with python SDK.\r\n\r\nThe resumption time of interactions actor reduce from ~800ms to ~500ms with the removed python dependencies. The resumption time of the antigravity python actor doesn't change much.\r\n\r\n#### Tested\r\nDeployed on substrate and run with both antigravity and antigravity-interactions.\r\nAntigravity actor resume: ~1.6s\r\nInteractions actor resume: ~500ms",
          "author": "wjjclaud",
          "createdAt": "2026-07-14T19:53:10Z",
          "mergedAt": "2026-07-16T17:03:31Z",
          "additions": 75,
          "deletions": 26,
          "changedFiles": 4
        },
        {
          "repository": "google/ax",
          "number": 324,
          "url": "https://github.com/google/ax/pull/324",
          "title": "Set workdir for interactions execution.",
          "body": "When running on substrate, the workdir is reset to root `/` after each resume actor call. We need to explicitly set the workdir for each execution. Fix #323.",
          "author": "wjjclaud",
          "createdAt": "2026-07-16T20:17:33Z",
          "mergedAt": "2026-07-16T20:25:40Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 322,
          "url": "https://github.com/google/ax/pull/322",
          "title": "fix(harness): wire --state-dir for the Antigravity SDK harness on substrate",
          "body": "## Summary\r\n\r\n- Derive the trajectory dir via `antigravity.DefaultStateDir()` and pass it to the sidecar as `--state-dir`, mirroring the local path (`antigravity.New`) and the interactions harness  \r\n- \r\n## Testing\r\n- `go build`, `go vet`, `go test ./...` pass.\r\n- No new unit test: the resolved path comes from `antigravity.DefaultStateDir()`, which is already covered by `TestDefaultStateDir` in `internal/harness/antigravity/antigravity_test.go`. This change only wires that existing, tested value into the sidecar args.\r\n\r\nFixes #321",
          "author": "joycel-github",
          "createdAt": "2026-07-16T18:04:56Z",
          "mergedAt": "2026-07-16T21:29:03Z",
          "additions": 7,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 326,
          "url": "https://github.com/google/ax/pull/326",
          "title": "antigravity: bump google-antigravity 0.1.5 -> 0.1.7",
          "body": "## Summary\r\n- Bump `google-antigravity` 0.1.5 → 0.1.7 in the sidecar requirements.\r\n- 0.1.7 reads GenAI credential env vars natively; this is the prerequisite for removing the sidecar's `_vertex_kwargs_from_env` override (follow-up PR).\r\n- Behavior unchanged here: with the override still present, its explicit kwargs take precedence, so the result is identical.\r\n\r\n## Validation\r\n- Sidecar test suite: 32/32 pass against 0.1.7.\r\n- Exercised real 0.1.7 locally: bare `LocalAgentConfig()` + env vars routes to Vertex with project/location hydrated (also via `USE_ENTERPRISE`); AI Studio path unchanged.\r\n- Reviewed the 0.1.5→0.1.7 SDK diff scoped to ax's surface (`Agent`, `LocalAgentConfig`, `types.{Text,Thought,ToolCall}`, `conversation.chat`) — no breaking changes; new `LocalAgentConfig` params are additive.\r\n\r\nPart of #325.\r\n\r\nNext:\r\n- clean up overrides that no longer needed with 0.1.7 ",
          "author": "joycel-github",
          "createdAt": "2026-07-16T21:56:01Z",
          "mergedAt": "2026-07-16T23:28:14Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 328,
          "url": "https://github.com/google/ax/pull/328",
          "title": "antigravity: remove _resolve_localhost /etc/hosts hack",
          "body": "## Summary\n- Remove the `_resolve_localhost()` hack that patched `/etc/hosts` so `localhost` resolved under substrate/gVisor.\n- Obsolete as of `google-antigravity` 0.1.7: the SDK's `_connect_websocket` now retries both `localhost` and `127.0.0.1` when dialing localharness (`local_connection.py:993`), so the fallback is handled upstream.\n\n## Testing\n- [x] Local: sidecar suite 32/32; booted the real gRPC server and confirmed it serves health without the hack.\n- [x] Substrate: verified on Agent Substrate (GKE `lhuan-substrate`, gVisor, no injected `/etc/hosts`). Deployed the antigravity harness image built from this branch with Vertex via Workload Identity (no API key in image). Real end-to-end turn returned a model response (`PR328_OK`); suspend/restore (`RESTORE_OK`) and cold restore after deleting all worker pods (`COLD_OK`) both succeeded. Zero `Failed to connect/initialize WebSocket` or localhost-resolution errors across the run. Confirmed SDK 0.1.7 fallback in the image: `local_connection.py` `for host in (\"localhost\", \"127.0.0.1\")`. SDK 0.1.7, substrate `v0.0.0-20260706222328-3cb7433bd8a8`.\n\nPart of #325.\n",
          "author": "joycel-github",
          "createdAt": "2026-07-16T23:31:14Z",
          "mergedAt": "2026-07-17T02:08:45Z",
          "additions": 0,
          "deletions": 26,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 312,
          "url": "https://github.com/google/ax/pull/312",
          "title": "antigravity: guard conversation_id for safe save_dir use",
          "body": "conversation_id is used as part of save_dir. add a validation to make sure it's safe ",
          "author": "joycel-github",
          "createdAt": "2026-07-15T05:44:16Z",
          "mergedAt": "2026-07-17T02:21:26Z",
          "additions": 117,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 329,
          "url": "https://github.com/google/ax/pull/329",
          "title": "chore: remove stale docs, gitignore, and Makefile entries",
          "body": "## Summary\nHousekeeping for references to code/targets that no longer exist.\n\n- **CONTRIBUTING.md**: drop the `make run-remote` section — no such Makefile target.\n- **.gitignore**: remove orphaned entries with no matching files (`local_agent`, `remote_agent`, `sandbox-router`, `examples/sandbox_agent/cloudbuild.yaml`, `tasklog/*`, `/axepp`, `google-cloud-sdk/`, `google-cloud-cli-darwin-arm.tar.gz`, `test-sandbox-config.yaml`).\n- **Makefile**: add missing `deps` and `clean-logs` to `.PHONY`.\n\nNo functional/build changes; `go build ./...` passes.",
          "author": "joycel-github",
          "createdAt": "2026-07-17T03:16:47Z",
          "mergedAt": "2026-07-17T03:54:26Z",
          "additions": 1,
          "deletions": 16,
          "changedFiles": 4
        },
        {
          "repository": "google/ax",
          "number": 331,
          "url": "https://github.com/google/ax/pull/331",
          "title": "antigravity: remove vertex env-var override (superseded by AGY 0.1.7)",
          "body": "## Summary\r\n- Remove the `_vertex_kwargs_from_env` sidecar override (and `VertexKwargs`) now that `google-antigravity` reads `GOOGLE_GENAI_USE_VERTEXAI` / `GOOGLE_GENAI_USE_ENTERPRISE` + `GOOGLE_CLOUD_{PROJECT,LOCATION}` natively. \r\n\r\n## Testing\r\n* unit test \r\n* manual test \r\n\r\nPart of #325.",
          "author": "joycel-github",
          "createdAt": "2026-07-18T00:02:01Z",
          "mergedAt": "2026-07-18T00:45:54Z",
          "additions": 41,
          "deletions": 137,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 327,
          "url": "https://github.com/google/ax/pull/327",
          "title": "Interactions: persist interactions harness with durable dir and resume from it",
          "body": "The Antigravity interactions harness is built upon a thin Go server, which is fast in terms of start up time. Instead of taking a snapshot of the whole rootfs + memory, we can take snapshot of one durable directory only, and resume from the state under that durable dir. Related issue: #268\r\n\r\n#### Changes\r\n- The interactions harness write artifacts to `workspace` by default.\r\n- Mount durable dir at `/workspace`, which contains all the artifacts the interactions harness has created, as well as the internal state `.ax/antigravityinteractions/cursor`\r\n- Add MkdirAlls in setHarnessWorkDir before chdir call.\r\n\r\n#### Tested\r\n- Deploy on substrate.\r\n- Test with interactions harness: write files, update files, execute files across turns.",
          "author": "wjjclaud",
          "createdAt": "2026-07-16T23:23:36Z",
          "mergedAt": "2026-07-18T01:03:28Z",
          "additions": 62,
          "deletions": 11,
          "changedFiles": 6
        },
        {
          "repository": "google/ax",
          "number": 335,
          "url": "https://github.com/google/ax/pull/335",
          "title": "interactions: make WorkDir authoritative for run_command",
          "body": "The interactions harness executed run_command relative to the process's ambient working directory, which is not reliably the agent's workspace: with no Cwd argument the command ran wherever the process cwd happened to be, and a model-supplied Cwd (including \"/\") was honored blindly. As a result tool calls often ran from \"/\" instead of the configured workspace (#332).\r\n\r\nMake the workspace directory authoritative in the executor rather than relying on ambient process state:\r\n\r\n- Add AntigravityInteractionsConfig.WorkDir (defaults from AX_HARNESS_WORKDIR).\r\n- run_command now resolves its directory via resolveRunDir: no Cwd -> WorkDir; relative Cwd -> joined under WorkDir; absolute Cwd -> honored as-is. Empty WorkDir preserves the previous process-cwd behavior.\r\n- Add WorkspaceSystemInstruction to orient the agent about its working directory so it emits workspace-relative paths, and wire it in cmd/ax.\r\n\r\nFixes #332",
          "author": "zbl94",
          "createdAt": "2026-07-20T21:49:08Z",
          "mergedAt": "2026-07-20T22:26:58Z",
          "additions": 180,
          "deletions": 9,
          "changedFiles": 6
        },
        {
          "repository": "google/ax",
          "number": 334,
          "url": "https://github.com/google/ax/pull/334",
          "title": "Remove the binary",
          "body": "",
          "author": "rakyll",
          "createdAt": "2026-07-18T19:55:10Z",
          "mergedAt": "2026-07-21T01:11:58Z",
          "additions": 40,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "google/ax",
          "number": 316,
          "url": "https://github.com/google/ax/pull/316",
          "title": "skills: add local directory source alongside the registry",
          "body": "Introduce a local skills source parallel to the Gemini Enterprise Skill Registry integration. A local source points at a directory already on disk (a parent dir holding <skill-id>/SKILL.md subfolders, the same layout as examples/skills and a registry's target_dir); nothing is fetched and the directory is used as-is.\r\n\r\n- New mode-agnostic result shape (internal/skills: Available/Group/Skill) so both sources feed the same consumers without either depending on the other.\r\n- internal/skills/local.Discover enumerates enabled local paths, treating immediate subfolders with a SKILL.md as skills (subfolder name = id). It is fail-safe like registry materialization: a missing/unreadable/empty path is logged and skipped, never blocking harness creation.\r\n- config.SkillsConfig gains Local []LocalSkillsConfig (enabled + path) with validation; geminienterprise.Materialize now returns skills.Available.\r\n- cliutil combines registry and local groups into one system-instruction pointer for the Antigravity Interactions harness. The Antigravity SDK harness (SKILLS_DIR-based) is left as a TODO.\r\n\r\nOnly the interactions harness is wired; tests cover discovery, fail-safe degradation, config validation, and the examples/skills fixture.",
          "author": "zbl94",
          "createdAt": "2026-07-15T18:46:04Z",
          "mergedAt": "2026-07-28T20:04:19Z",
          "additions": 465,
          "deletions": 62,
          "changedFiles": 10
        }
      ],
      "developmentAttribution": {
        "repository": "google/ax",
        "branch": "main",
        "window": {
          "id": "ax-history-before-cutoff",
          "label": "AX public default-branch history before the comparison cutoff",
          "startInclusive": "2026-01-01T00:00:00.000Z",
          "endExclusive": "2026-08-01T00:00:00.000Z",
          "duration": "P212D"
        },
        "windowRelation": "repository-history-outside-measured-windows",
        "totalCommitsScanned": 608,
        "explicitlyAttributedCommits": 7,
        "byAgent": [
          {
            "agent": "Gemini",
            "commits": 7,
            "markerTypes": [
              {
                "name": "co-author-trailer",
                "count": 7
              }
            ]
          }
        ],
        "records": [
          {
            "agent": "Gemini",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: gemini-code-assist[bot]",
            "repository": "google/ax",
            "branch": "main",
            "sha": "5e030de39700fbfaabbcfafa9e9b7481bec5de4e",
            "url": "https://github.com/google/ax/commit/5e030de39700fbfaabbcfafa9e9b7481bec5de4e",
            "title": "Add a warning saying the project is in active development (#73)",
            "observedAt": "2026-02-27T19:14:42Z"
          },
          {
            "agent": "Gemini",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: gemini-code-assist[bot]",
            "repository": "google/ax",
            "branch": "main",
            "sha": "423549a5409b2dee1f5c45ea10b0c6facce62dd1",
            "url": "https://github.com/google/ax/commit/423549a5409b2dee1f5c45ea10b0c6facce62dd1",
            "title": "Fix the README section about the Python agent (#104)",
            "observedAt": "2026-03-17T02:12:40Z"
          },
          {
            "agent": "Gemini",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: gemini-code-assist[bot]",
            "repository": "google/ax",
            "branch": "main",
            "sha": "a5c1aff3a297808ae639d0bfdf37eb421aafdd4d",
            "url": "https://github.com/google/ax/commit/a5c1aff3a297808ae639d0bfdf37eb421aafdd4d",
            "title": "Small improvements in the exec loop. (#128)",
            "observedAt": "2026-03-24T01:30:19Z"
          },
          {
            "agent": "Gemini",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: gemini-code-assist[bot]",
            "repository": "google/ax",
            "branch": "main",
            "sha": "d694866ec5dba1c5010a277da3a3f4ccb10c2bdb",
            "url": "https://github.com/google/ax/commit/d694866ec5dba1c5010a277da3a3f4ccb10c2bdb",
            "title": "Move experimental docs to experimental (#264)",
            "observedAt": "2026-04-30T15:48:52Z"
          },
          {
            "agent": "Gemini",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: gemini-code-assist[bot]",
            "repository": "google/ax",
            "branch": "main",
            "sha": "a29c6e742e9c676baf47fd25ac2a0ffd6015e2f4",
            "url": "https://github.com/google/ax/commit/a29c6e742e9c676baf47fd25ac2a0ffd6015e2f4",
            "title": "Some more updates to the NOT section (#271)",
            "observedAt": "2026-04-30T18:42:30Z"
          },
          {
            "agent": "Gemini",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: gemini-code-assist[bot]",
            "repository": "google/ax",
            "branch": "main",
            "sha": "b42d530c8e5aca8ddd3f2d3da4a550366a3b01af",
            "url": "https://github.com/google/ax/commit/b42d530c8e5aca8ddd3f2d3da4a550366a3b01af",
            "title": "Update wording in Substrate instructructions (#278)",
            "observedAt": "2026-05-04T19:04:10Z"
          },
          {
            "agent": "Gemini",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: gemini-code-assist[bot]",
            "repository": "google/ax",
            "branch": "main",
            "sha": "f220cec527f394a31a2c14578a9b2d039dd41c9e",
            "url": "https://github.com/google/ax/commit/f220cec527f394a31a2c14578a9b2d039dd41c9e",
            "title": "sync code with latest substrate API changes (#348)",
            "observedAt": "2026-05-15T23:42:28Z"
          }
        ]
      }
    },
    "kungfu": {
      "label": "Kungfu Systems",
      "scope": "all public repositories in kungfu-systems with merged work in the window",
      "query": "org:kungfu-systems is:pr is:merged merged:2026-07-02T00:00:00Z..2026-07-31T23:59:59Z is:public",
      "organizationForm": "one human product owner directing Agent-mediated work across a public multi-repository system",
      "summary": {
        "mergedPullRequests": 4065,
        "activeRepositories": 16,
        "authorAccounts": 4,
        "activeMergeDays": 30,
        "totalAdditions": 3130526,
        "totalDeletions": 567805,
        "totalChangedFiles": 53052,
        "changeSize": {
          "median": 106,
          "p25": 17,
          "p75": 542,
          "p90": 1640
        },
        "authors": [
          {
            "name": "dongkeren",
            "count": 3913
          },
          {
            "name": "app/kungfu-systems-release-bot",
            "count": 85
          },
          {
            "name": "kungfu-origin",
            "count": 65
          },
          {
            "name": "app/kungfu-paper-release-bot",
            "count": 2
          }
        ],
        "repositories": [
          {
            "name": "kungfu-systems/buildchain",
            "count": 1451
          },
          {
            "name": "kungfu-systems/kungfu",
            "count": 1333
          },
          {
            "name": "kungfu-systems/build-images",
            "count": 246
          },
          {
            "name": "kungfu-systems/kfd",
            "count": 232
          },
          {
            "name": "kungfu-systems/site-libkungfu-dev",
            "count": 171
          },
          {
            "name": "kungfu-systems/site-kungfu-tech",
            "count": 142
          },
          {
            "name": "kungfu-systems/libnode",
            "count": 94
          },
          {
            "name": "kungfu-systems/paper-kungfu-product-white-paper",
            "count": 87
          },
          {
            "name": "kungfu-systems/paper-observer-declared-timelines",
            "count": 65
          },
          {
            "name": "kungfu-systems/runtime-images",
            "count": 61
          },
          {
            "name": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
            "count": 60
          },
          {
            "name": "kungfu-systems/agent-hub-demo",
            "count": 54
          },
          {
            "name": "kungfu-systems/paper-kfd-machine-life-roadmap",
            "count": 47
          },
          {
            "name": "kungfu-systems/homebrew-tap",
            "count": 11
          },
          {
            "name": "kungfu-systems/paper-episodes-to-primitives",
            "count": 10
          },
          {
            "name": "kungfu-systems/.github",
            "count": 1
          }
        ],
        "daily": [
          {
            "name": "2026-07-02",
            "count": 118
          },
          {
            "name": "2026-07-03",
            "count": 98
          },
          {
            "name": "2026-07-04",
            "count": 139
          },
          {
            "name": "2026-07-05",
            "count": 125
          },
          {
            "name": "2026-07-06",
            "count": 202
          },
          {
            "name": "2026-07-07",
            "count": 189
          },
          {
            "name": "2026-07-08",
            "count": 129
          },
          {
            "name": "2026-07-09",
            "count": 140
          },
          {
            "name": "2026-07-10",
            "count": 195
          },
          {
            "name": "2026-07-11",
            "count": 112
          },
          {
            "name": "2026-07-12",
            "count": 92
          },
          {
            "name": "2026-07-13",
            "count": 123
          },
          {
            "name": "2026-07-14",
            "count": 163
          },
          {
            "name": "2026-07-15",
            "count": 226
          },
          {
            "name": "2026-07-16",
            "count": 98
          },
          {
            "name": "2026-07-17",
            "count": 77
          },
          {
            "name": "2026-07-18",
            "count": 91
          },
          {
            "name": "2026-07-19",
            "count": 92
          },
          {
            "name": "2026-07-20",
            "count": 64
          },
          {
            "name": "2026-07-21",
            "count": 130
          },
          {
            "name": "2026-07-22",
            "count": 161
          },
          {
            "name": "2026-07-23",
            "count": 144
          },
          {
            "name": "2026-07-24",
            "count": 205
          },
          {
            "name": "2026-07-25",
            "count": 153
          },
          {
            "name": "2026-07-26",
            "count": 134
          },
          {
            "name": "2026-07-27",
            "count": 119
          },
          {
            "name": "2026-07-28",
            "count": 150
          },
          {
            "name": "2026-07-29",
            "count": 119
          },
          {
            "name": "2026-07-30",
            "count": 115
          },
          {
            "name": "2026-07-31",
            "count": 162
          }
        ],
        "workTypes": [
          {
            "name": "fix",
            "count": 1195
          },
          {
            "name": "feat",
            "count": 834
          },
          {
            "name": "chore",
            "count": 746
          },
          {
            "name": "unclassified",
            "count": 450
          },
          {
            "name": "release",
            "count": 308
          },
          {
            "name": "docs",
            "count": 228
          },
          {
            "name": "ci",
            "count": 131
          },
          {
            "name": "refactor",
            "count": 82
          },
          {
            "name": "test",
            "count": 32
          },
          {
            "name": "build",
            "count": 21
          },
          {
            "name": "alpha",
            "count": 8
          },
          {
            "name": "promote",
            "count": 8
          },
          {
            "name": "perf",
            "count": 7
          },
          {
            "name": "shifu",
            "count": 6
          },
          {
            "name": "storage",
            "count": 4
          },
          {
            "name": "check",
            "count": 1
          },
          {
            "name": "diag",
            "count": 1
          },
          {
            "name": "merge",
            "count": 1
          },
          {
            "name": "rewind",
            "count": 1
          },
          {
            "name": "style",
            "count": 1
          }
        ]
      },
      "records": [
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 6,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/6",
          "title": "ci: enable reusable web-surface apply flow",
          "body": "## Summary\n\n- enable Buildchain reusable web-surface preview apply, preview cleanup, and staging apply\n- replace placeholder CloudFront distribution ids with the live preview and staging distributions\n- keep production apply disabled behind the existing explicit gate\n\n## Validation\n\n- npm run build\n- npm run check\n- Buildchain validate / preview plan / cleanup plan / staging plan with concrete CloudFront distributions\n\n## Notes\n\nThis PR is intended to prove the shared Buildchain reusable workflow can own the real preview apply path without site-local AWS glue.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T23:12:38Z",
          "mergedAt": "2026-07-02T00:52:27Z",
          "additions": 12,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 31,
          "url": "https://github.com/kungfu-systems/build-images/pull/31",
          "title": "ci: pin buildchain 2.0.16",
          "body": "## Summary\n- pin Buildchain workflow actions to stable v2.0.16\n- pick up finalization recovery fixes from Buildchain PRs #220/#222/#226/#227\n\n## Validation\n- npm view @kungfu-tech/buildchain@2.0.16\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T01:01:22Z",
          "mergedAt": "2026-07-02T01:03:29Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 238,
          "url": "https://github.com/kungfu-systems/buildchain/pull/238",
          "title": "fix(web-surface): honor explicit root deploy prefix",
          "body": "## Summary\n- Treat an explicitly configured deploy prefix, including an empty string, as authoritative.\n- Normalize root-prefix CloudFront invalidations to `/*` instead of `//*`.\n- Add coverage for bucket-root staging deploys.\n\n## Verification\n- `pnpm run check`\n\n## Context\n`site-kungfu-tech` staging uses a dedicated domain at `https://staging.kungfu.tech/`. Without explicit root prefix support, a staging apply writes to `staging/index.html` while the domain root serves `index.html`.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T00:56:24Z",
          "mergedAt": "2026-07-02T01:04:41Z",
          "additions": 41,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 32,
          "url": "https://github.com/kungfu-systems/build-images/pull/32",
          "title": "Promote dev/v1/v1.1 to alpha",
          "body": "## Summary\n- promote the Buildchain v2.0.16 workflow pin to alpha/v1/v1.1\n\n## Validation\n- PR #31 checks passed\n- dev/v1/v1.1 workflows now use v2.0.16",
          "author": "dongkeren",
          "createdAt": "2026-07-02T01:04:03Z",
          "mergedAt": "2026-07-02T01:05:18Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 239,
          "url": "https://github.com/kungfu-systems/buildchain/pull/239",
          "title": "Promote dev/v2/v2.0 to alpha",
          "body": "## Summary\n\nPromote the Buildchain web-surface root deploy prefix fix from dev to alpha.\n\n## Verification\n\n- PR #238 checks passed before merge into dev/v2/v2.0\n- Local `pnpm run check` passed on PR #238\n- dev/v2/v2.0 Verify passed after merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T01:06:12Z",
          "mergedAt": "2026-07-02T01:07:51Z",
          "additions": 41,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 24,
          "url": "https://github.com/kungfu-systems/libnode/pull/24",
          "title": "ci: publish libnode alpha through buildchain final-version mode",
          "body": "## Summary\n- declare libnode's Buildchain publish contract as publish-final-version/trusted-publishing\n- publish platform packages before the main package and include artifact roles for Buildchain ordering\n- allow anchored libnode npm versions to use alpha prerelease form and bump to 22.22.3-kf.3-alpha.0\n\n## Validation\n- corepack pnpm verify-release\n- node --check .gyp/npm-publish-tarballs.js\n- node --check .gyp/libnode-release-verify.js\n- git diff --check\n- buildchain validate --require-version-state\n- dry-run against existing package tarballs confirmed publish-final-version does not run npm dist-tag add",
          "author": "dongkeren",
          "createdAt": "2026-07-02T00:56:44Z",
          "mergedAt": "2026-07-02T01:19:10Z",
          "additions": 47,
          "deletions": 25,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 7,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/7",
          "title": "fix: deploy staging and production at domain roots",
          "body": "## Summary\n- Declare bucket-root deploy prefixes for staging and production.\n- Keep preview prefixes unchanged.\n\n## Verification\n- `npm run check`\n- `npm run build`\n- Local Buildchain dry-run using the root-prefix fix confirms staging sync target is `s3://kungfu-tech-staging-727884401362-us-east-1` and CloudFront invalidation is `/*`.\n\n## Dependency\nRequires Buildchain PR #238 to be promoted to `v2.0-alpha`; current released Buildchain ignores empty prefixes.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T00:58:33Z",
          "mergedAt": "2026-07-02T01:22:54Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 240,
          "url": "https://github.com/kungfu-systems/buildchain/pull/240",
          "title": "fix(web-surface): preserve metadata on root deploys",
          "body": "## Summary\n- Keep `.buildchain/*` metadata when syncing a web-surface artifact to a bucket root with `--delete`.\n- Preserve existing non-root prefix behavior.\n- Extend root-prefix deploy coverage to assert the metadata exclude.\n\n## Verification\n- `pnpm run check`\n\n## Context\nAfter site-kungfu-tech PR #7, staging root deploys correctly updated `https://staging.kungfu.tech/`, but root sync deleted older `.buildchain/deployments/staging/*` records before writing the current manifest. This keeps Buildchain deployment metadata outside static artifact deletion.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T01:25:50Z",
          "mergedAt": "2026-07-02T01:39:08Z",
          "additions": 18,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 25,
          "url": "https://github.com/kungfu-systems/libnode/pull/25",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.0",
          "body": "## Summary\n- promote dev/v22/v22.22 to alpha/v22/v22.22\n- publish libnode package set version 22.22.3-kf.3-alpha.0 with npm dist-tag alpha\n- exercise Buildchain publish-final-version + trusted-publishing release path\n\n## Expected Buildchain behavior\n- build Linux x64, macOS ARM64, and Windows x64 platform packages\n- publish platform packages before @kungfu-tech/libnode\n- use npm Trusted Publishing, not npm token-backed dist-tag promotion",
          "author": "dongkeren",
          "createdAt": "2026-07-02T01:19:41Z",
          "mergedAt": "2026-07-02T01:40:34Z",
          "additions": 47,
          "deletions": 25,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 241,
          "url": "https://github.com/kungfu-systems/buildchain/pull/241",
          "title": "Promote dev/v2/v2.0 to alpha",
          "body": "## Summary\n\nPromote the Buildchain web-surface root metadata preservation fix from dev to alpha.\n\n## Verification\n\n- PR #240 checks passed before merge into dev/v2/v2.0\n- dev/v2/v2.0 Verify passed after merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T01:40:24Z",
          "mergedAt": "2026-07-02T01:42:12Z",
          "additions": 18,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 242,
          "url": "https://github.com/kungfu-systems/buildchain/pull/242",
          "title": "Promote alpha/v2/v2.0 to release",
          "body": "## Summary\n\nPromote the current Buildchain alpha line to stable release after merging PRs #240 and #241.\n\n## Expected release\n\n- v2.0.17\n\n## Verification\n\n- PR #240 checks passed and merged into dev/v2/v2.0\n- PR #241 checks passed and merged into alpha/v2/v2.0\n- Buildchain Ref Promotion updated v2.0-alpha to 0b086146e8defd47bcd62bf11a8c5e99625f6e30\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T01:49:24Z",
          "mergedAt": "2026-07-02T01:52:22Z",
          "additions": 59,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 243,
          "url": "https://github.com/kungfu-systems/buildchain/pull/243",
          "title": "Release v2.0.17",
          "body": "Create the generated version-state commit for v2.0.17.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:00:34Z",
          "mergedAt": "2026-07-02T02:02:24Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 244,
          "url": "https://github.com/kungfu-systems/buildchain/pull/244",
          "title": "Prepare v2.0.18-alpha.0",
          "body": "Create the generated version-state commit for v2.0.18-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:03:44Z",
          "mergedAt": "2026-07-02T02:05:42Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 245,
          "url": "https://github.com/kungfu-systems/buildchain/pull/245",
          "title": "Add Buildchain observability toolkit",
          "body": "## Summary\n- add @kungfu-tech/buildchain/logging JSONL event and summary SDK\n- add CLI log/mark/span/doctor/release explain/transaction inspect surfaces\n- emit lifecycle framework/user observability into artifact manifest and summary\n\n## Validation\n- pnpm run check\n- node bin/buildchain.mjs lifecycle run verify --artifact-name buildchain-dogfood --artifact-path package.json",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:33:41Z",
          "mergedAt": "2026-07-02T02:35:05Z",
          "additions": 810,
          "deletions": 35,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 246,
          "url": "https://github.com/kungfu-systems/buildchain/pull/246",
          "title": "Promote v2.1 observability toolkit to alpha",
          "body": "## Summary\nPromote Buildchain v2.1 observability toolkit from dev to alpha.\n\n## Expected Buildchain semantics\n- source: dev/v2/v2.1\n- target: alpha/v2/v2.1\n- expected exact tag: first v2.1 alpha\n- npm dist-tag: alpha through publish transaction",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:36:25Z",
          "mergedAt": "2026-07-02T02:38:23Z",
          "additions": 810,
          "deletions": 35,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 247,
          "url": "https://github.com/kungfu-systems/buildchain/pull/247",
          "title": "Prepare v2.1.0-alpha.0",
          "body": "Create the generated version-state commit for v2.1.0-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:41:32Z",
          "mergedAt": "2026-07-02T02:43:36Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 248,
          "url": "https://github.com/kungfu-systems/buildchain/pull/248",
          "title": "Promote v2.1 observability toolkit to release",
          "body": "## Summary\nPromote Buildchain v2.1.0 from alpha to release.\n\n## Expected Buildchain semantics\n- source: alpha/v2/v2.1\n- target: release/v2/v2.1\n- exact release tag: v2.1.0\n- floating tags: v2.1 and v2 if this is the newest production minor\n- npm dist-tag: latest through publish transaction",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:45:35Z",
          "mergedAt": "2026-07-02T02:47:14Z",
          "additions": 811,
          "deletions": 36,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 136,
          "url": "https://github.com/kungfu-systems/kungfu/pull/136",
          "title": "feat(core): extract yijinjing journal core into standalone static library",
          "body": "Extract the yijinjing journal core into a standalone static library (src/libyijinjing, target yijinjing -> libyijinjing.a): schema leaf gains PageEnd/AssembleMode, the god-header common.h sheds rx/nng into yijinjing/rx.h, typed frame dump and master-kv verification become runtime-installed seams, core sources compile once and libkungfu links the target. The fact-ledger slice now links only the core (no shared-library deps beyond libc++/libSystem) and src/libyijinjing/check-deps.sh guards the dependency direction. libkungfu + slice build green; run_slice.sh verifies end to end.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:44:22Z",
          "mergedAt": "2026-07-02T02:50:11Z",
          "additions": 720,
          "deletions": 460,
          "changedFiles": 54
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 249,
          "url": "https://github.com/kungfu-systems/buildchain/pull/249",
          "title": "Release v2.1.0",
          "body": "Create the generated version-state commit for v2.1.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:48:36Z",
          "mergedAt": "2026-07-02T02:51:21Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 250,
          "url": "https://github.com/kungfu-systems/buildchain/pull/250",
          "title": "Prepare v2.1.1-alpha.0",
          "body": "Create the generated version-state commit for v2.1.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:52:44Z",
          "mergedAt": "2026-07-02T02:54:05Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 1,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/1",
          "title": "feat(site): add libkungfu developer substrate hub",
          "body": "## Summary\n\n- add a generated static site for the libkungfu.dev developer substrate hub\n- render hub, core, and Buildchain surfaces from fixture manifests\n- switch the repository to the shared Buildchain web-surface workflow\n- update deployment docs for libkungfu.dev, core.libkungfu.dev, and buildchain.libkungfu.dev\n\n## Verification\n\n- npm run build\n- npm run check\n- node /Users/dkr/Code/kungfu-systems/buildchain/scripts/web-surface.mjs --mode validate --cwd .\n- Buildchain deploy-plan for preview, staging, and production channels\n- Playwright browser render check for the generated homepage\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T03:03:50Z",
          "mergedAt": "2026-07-02T03:07:59Z",
          "additions": 952,
          "deletions": 223,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 137,
          "url": "https://github.com/kungfu-systems/kungfu/pull/137",
          "title": "refactor(core): narrow the yijinjing namespace to the journal core",
          "body": "Move the runtime components practice, cache and index out of kungfu::yijinjing into top-level namespaces (kungfu::practice / kungfu::cache / kungfu::index) so the namespace boundary matches the physical boundary drawn by the libyijinjing extraction. References that had been resolving through the old enclosing namespace are explicitly qualified with yijinjing::, matching the existing wingchun convention. Include paths unchanged, no compatibility aliases, pure rename (83 files, symmetric replacement). libkungfu + fact-ledger slice build green; run_slice.sh verifies end to end; check-deps.sh passes.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T03:11:45Z",
          "mergedAt": "2026-07-02T03:14:10Z",
          "additions": 334,
          "deletions": 334,
          "changedFiles": 83
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 26,
          "url": "https://github.com/kungfu-systems/libnode/pull/26",
          "title": "release: finalize libnode 22.22.3-kf.3",
          "body": "## Summary\n- advance the release channel from the latest alpha source to final npm version 22.22.3-kf.3\n- keep the Node anchor at v22.22.3 and libnode revision 3\n- rely on Buildchain v2 publish-final-version + Trusted Publishing for latest publication\n\n## Validation\n- corepack pnpm verify-release\n- git diff --check\n- node --check .gyp/libnode-release-verify.js\n- node --check .gyp/npm-publish-tarballs.js\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs validate --require-version-state\n\n## Release intent\nMerging this PR into release/v22/v22.22 should publish @kungfu-tech/libnode and platform packages as 22.22.3-kf.3 with npm dist-tag latest.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:50:32Z",
          "mergedAt": "2026-07-02T03:29:12Z",
          "additions": 47,
          "deletions": 25,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 138,
          "url": "https://github.com/kungfu-systems/kungfu/pull/138",
          "title": "refactor(core): move nanomsg and webserver out of the yijinjing namespace",
          "body": "Second half of the namespace narrowing: nanomsg and webserver are runtime transport components, moved to kungfu::nanomsg / kungfu::webserver so the namespace boundary matches the physical core boundary. References in moved files explicitly qualified with yijinjing:: per the established convention; include paths unchanged; no aliases. The orphaned socket/ headers are deliberately left untouched (nothing includes or references them; removal is a separate decision). Pure rename, 9 files, symmetric replacement; all targets build green, run_slice.sh and check-deps.sh pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T03:49:10Z",
          "mergedAt": "2026-07-02T03:53:52Z",
          "additions": 33,
          "deletions": 430,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 139,
          "url": "https://github.com/kungfu-systems/kungfu/pull/139",
          "title": "docs(adr): adopt KFD-1 release versioning via ADR-0010 with welded-surface register",
          "body": "Merge docs/kfd-adoption into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T03:50:11Z",
          "mergedAt": "2026-07-02T03:57:29Z",
          "additions": 88,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 251,
          "url": "https://github.com/kungfu-systems/buildchain/pull/251",
          "title": "docs: adopt KFD-1 release versioning with a welded-surface register",
          "body": "Adds docs/versioning.md (welded-surface register + decision log) and a MAP row. Documentation only; no registered surface is touched (patch per KFD-1).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:04:32Z",
          "mergedAt": "2026-07-02T04:05:13Z",
          "additions": 40,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 33,
          "url": "https://github.com/kungfu-systems/build-images/pull/33",
          "title": "docs: adopt KFD-1 with welded surfaces and a decision log",
          "body": "Appends Welded Surfaces and Decision Log sections to docs/release-and-tags.md. Documentation only; no registered surface is touched (patch per KFD-1).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:06:05Z",
          "mergedAt": "2026-07-02T04:06:32Z",
          "additions": 33,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 2,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/2",
          "title": "ci(site): enable Buildchain web-surface apply",
          "body": "## Summary\n- point web-surface deploy config at the provisioned libkungfu.dev CloudFront distributions\n- enable Buildchain preview apply, preview cleanup apply, and staging apply through GitHub OIDC roles\n- keep production apply disabled\n\n## Validation\n- npm run build\n- npm run check\n- Buildchain web-surface validate\n- Buildchain preview and staging deploy-plan\n- Buildchain preview and staging deploy-apply dry-run",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:07:21Z",
          "mergedAt": "2026-07-02T04:09:16Z",
          "additions": 9,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 252,
          "url": "https://github.com/kungfu-systems/buildchain/pull/252",
          "title": "Add release passport binary distribution",
          "body": "## Summary\n- add Buildchain v2.2 release passport, artifact evidence, impact ledger, agent index, and release check contracts\n- add GitHub-hosted binary distribution workflow with self-hosted compatibility fixture\n- dogfood Buildchain observability through standalone builder API logs and workflow mark/span/log summary events\n- document v2.2 versioning semantics and release passport usage\n\n## Verification\n- pnpm run check\n- standalone SEA smoke: build, version, help, mark/log summary\n- release passport dogfood over generated binary/log assets\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:15:33Z",
          "mergedAt": "2026-07-02T04:17:18Z",
          "additions": 1705,
          "deletions": 0,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 140,
          "url": "https://github.com/kungfu-systems/kungfu/pull/140",
          "title": "feat(core): make the yijinjing core embeddable standalone",
          "body": "Makes src/libyijinjing/CMakeLists.txt self-sufficient so a third-party project can consume the journal core via add_subdirectory alone: dependency targets resolved only when no enclosing build provides them, C++20 declared at target level (std::atomic_ref carries the ADR-0001 publication protocol), vendored hana fallback, parent output/optimization variables optional. EMBEDDING.md pins the contract: source embedding of the static target is the single supported distribution form; .so/ABI stability and standalone package artifacts are deliberately not offered, with three concrete escalation criteria. Verified both ways: an external scratch project builds and re-reads a causally chained journal via add_subdirectory alone; the in-tree build (libkungfu, slice, run_slice.sh, check-deps.sh) is unchanged and green.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:20:00Z",
          "mergedAt": "2026-07-02T04:23:37Z",
          "additions": 124,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 253,
          "url": "https://github.com/kungfu-systems/buildchain/pull/253",
          "title": "Promote v2.2 release passport binary distribution to alpha",
          "body": "## Summary\nPromote Buildchain v2.2 release passport and binary distribution surface from dev to alpha.\n\n## Expected Buildchain behavior\n- create exact alpha version tag v2.2.0-alpha.0\n- move v2.2-alpha to the alpha release material\n- prepare the next dev/alpha source state for v2.2\n- publish npm alpha and trigger binary release passport assets on the exact tag\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:18:09Z",
          "mergedAt": "2026-07-02T04:26:50Z",
          "additions": 1909,
          "deletions": 10,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 254,
          "url": "https://github.com/kungfu-systems/buildchain/pull/254",
          "title": "Fix v2.2 binary distribution on Windows",
          "body": "## Summary\n- resolve Windows package manager command shims when building the standalone binary\n- add a regression test for pnpm/npx .cmd resolution\n\n## Verification\n- node --check scripts/build-standalone-binary.mjs && node --test tests/cli.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:34:42Z",
          "mergedAt": "2026-07-02T04:36:11Z",
          "additions": 23,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 27,
          "url": "https://github.com/kungfu-systems/libnode/pull/27",
          "title": "ci: declare libnode release manifest version state",
          "body": "## Summary\n- declare libnode.release.json#npmVersion as a Buildchain version-state file\n- advance the alpha package version to 22.22.3-kf.3-alpha.1 so release final can differ from alpha only by version-state files\n\n## Why\nBuildchain rejected the final release because release source differed from v22.22.0-alpha.1 in libnode.release.json, while only package.json was declared as version state.\n\n## Validation\n- corepack pnpm verify-release\n- git diff --check\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs validate --require-version-state",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:05:53Z",
          "mergedAt": "2026-07-02T04:36:51Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 255,
          "url": "https://github.com/kungfu-systems/buildchain/pull/255",
          "title": "Fix alpha exact tag reuse after completed transactions",
          "body": "## Summary\n- do not reuse a completed alpha transaction's exact tag for new alpha material\n- keep partial finalization recovery intact for published/finalizing transactions\n- add regression coverage for completed transaction exact-tag reuse\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:43:28Z",
          "mergedAt": "2026-07-02T04:44:59Z",
          "additions": 186,
          "deletions": 53,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 256,
          "url": "https://github.com/kungfu-systems/buildchain/pull/256",
          "title": "Prepare v2.2.0-alpha.1",
          "body": "Create the generated version-state commit for v2.2.0-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:46:25Z",
          "mergedAt": "2026-07-02T04:47:52Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 257,
          "url": "https://github.com/kungfu-systems/buildchain/pull/257",
          "title": "Fix Windows standalone binary shell execution",
          "body": "## Summary\n- run Windows package-manager .cmd shims through shell when building standalone binaries\n- keep command resolution explicit and covered by CLI tests\n\n## Verification\n- node --check scripts/build-standalone-binary.mjs && node --test tests/cli.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:51:41Z",
          "mergedAt": "2026-07-02T04:53:20Z",
          "additions": 11,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 258,
          "url": "https://github.com/kungfu-systems/buildchain/pull/258",
          "title": "Prepare v2.2.0-alpha.2",
          "body": "Create the generated version-state commit for v2.2.0-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:54:50Z",
          "mergedAt": "2026-07-02T04:57:43Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 259,
          "url": "https://github.com/kungfu-systems/buildchain/pull/259",
          "title": "Release Buildchain v2.2.0",
          "body": "Promotes the verified v2.2 alpha line to the v2.2 release line.\\n\\nEvidence before release promotion:\\n- v2.2.0-alpha.2 exact tag and v2.2-alpha floating tag both point to 9276eb0f6fab5ca7b50af5c27cfb4a246a7d4a55.\\n- npm alpha is @kungfu-tech/buildchain@2.2.0-alpha.2.\\n- Binary Distribution run 28566553311 passed for linux-x64, darwin-arm64, and windows-x64.\\n- Release passport, checksums, binary assets, and Buildchain observability log events/summaries were uploaded to the GitHub Release.\\n\\nRelease target: v2.2.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:01:24Z",
          "mergedAt": "2026-07-02T05:02:57Z",
          "additions": 2126,
          "deletions": 63,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 260,
          "url": "https://github.com/kungfu-systems/buildchain/pull/260",
          "title": "Release v2.2.0",
          "body": "Create the generated version-state commit for v2.2.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:04:25Z",
          "mergedAt": "2026-07-02T05:06:09Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 28,
          "url": "https://github.com/kungfu-systems/libnode/pull/28",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.1",
          "body": "## Summary\n- promote the version-state manifest fix from dev to alpha\n- publish alpha package set 22.22.3-kf.3-alpha.1 as the release baseline\n\n## Why\nThe final release gate requires release source to differ from the latest alpha source only by declared version-state files. This alpha establishes libnode.release.json#npmVersion as declared version state before retrying final release.\n\n## Expected result\nMerging into alpha/v22/v22.22 should run Release - New Version and publish the package set with npm dist-tag alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:37:14Z",
          "mergedAt": "2026-07-02T05:06:23Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 261,
          "url": "https://github.com/kungfu-systems/buildchain/pull/261",
          "title": "Prepare v2.2.1-alpha.0",
          "body": "Create the generated version-state commit for v2.2.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:07:45Z",
          "mergedAt": "2026-07-02T05:10:13Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 141,
          "url": "https://github.com/kungfu-systems/kungfu/pull/141",
          "title": "refactor(core): converge on target-scoped source layout",
          "body": "Every library owns its headers: src/include splits into src/libkungfu/include and src/libwingchun/include, matching src/libyijinjing; dormant wingchun sources move out of the libkungfu tree; include propagation becomes target-scoped throughout. Validated: full build green on macOS arm64, yijinjing dependency guard passes, fact-ledger slice end-to-end green with zero extra dynamic deps, freeze staging covered. Also syncs the pnpm lockfile with the spec package's rimraf dependency.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:40:31Z",
          "mergedAt": "2026-07-02T05:40:37Z",
          "additions": 93,
          "deletions": 46,
          "changedFiles": 139
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 262,
          "url": "https://github.com/kungfu-systems/buildchain/pull/262",
          "title": "feat(release): publish release passport site bundle",
          "body": "## Summary\n- reposition README around Buildchain Release Passport consumption, verification, npm, toolkit, and site facts\n- add release evidence bundle generation and prevent loose binary asset collisions\n- publish generated dist/site facts inside @kungfu-tech/buildchain\n- document binary distribution, toolkit observability, product mechanism, install, and site bundle contracts\n\n## Verification\n- pnpm run check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:45:14Z",
          "mergedAt": "2026-07-02T05:46:45Z",
          "additions": 1577,
          "deletions": 264,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 263,
          "url": "https://github.com/kungfu-systems/buildchain/pull/263",
          "title": "promote: dev v2.2 to alpha",
          "body": "## Summary\nPromote dev/v2/v2.2 to alpha/v2/v2.2 for the next Buildchain v2.2 alpha.\n\n## Verification\n- Source PR #262 checks passed before merge\n- Buildchain Ref Promotion will create the version-state alpha PR if required",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:47:17Z",
          "mergedAt": "2026-07-02T05:48:48Z",
          "additions": 1577,
          "deletions": 264,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 264,
          "url": "https://github.com/kungfu-systems/buildchain/pull/264",
          "title": "fix(site): keep generated facts version agnostic",
          "body": "## Summary\n- stop copying package.json version into generated dist/site facts\n- keep package version as package.json#version so version-state commits do not stale the site bundle\n\n## Verification\n- pnpm run check\n- simulated package.json version bump followed by node scripts/generate-site-bundle.mjs --check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:51:10Z",
          "mergedAt": "2026-07-02T05:52:40Z",
          "additions": 8,
          "deletions": 5,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 265,
          "url": "https://github.com/kungfu-systems/buildchain/pull/265",
          "title": "promote: dev v2.2 to alpha after site bundle fix",
          "body": "## Summary\nPromote the site bundle version-state fix and release passport bundle changes to alpha/v2/v2.2.\n\n## Verification\n- PR #264 checks passed\n- Buildchain Ref Promotion should prepare v2.2.1-alpha.1",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:53:00Z",
          "mergedAt": "2026-07-02T05:54:31Z",
          "additions": 8,
          "deletions": 5,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 29,
          "url": "https://github.com/kungfu-systems/libnode/pull/29",
          "title": "release: publish libnode 22.22.3-kf.3",
          "body": "## Summary\n- finalize libnode 22.22.3-kf.3 from the published alpha baseline\n- carry buildchain.toml version-state declaration for libnode.release.json so strict release tree comparison accepts both version files\n\n## Verification\n- corepack pnpm verify-release\n- git diff --check\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs validate --require-version-state",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:36:36Z",
          "mergedAt": "2026-07-02T05:55:15Z",
          "additions": 5,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 266,
          "url": "https://github.com/kungfu-systems/buildchain/pull/266",
          "title": "Prepare v2.2.1-alpha.1",
          "body": "Create the generated version-state commit for v2.2.1-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:55:59Z",
          "mergedAt": "2026-07-02T05:57:19Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 267,
          "url": "https://github.com/kungfu-systems/buildchain/pull/267",
          "title": "release: Buildchain v2.2.1",
          "body": "## Summary\nPromote alpha/v2/v2.2 to release/v2/v2.2 for Buildchain v2.2.1.\n\n## Evidence\n- v2.2.1-alpha.1 exact tag exists\n- npm alpha dist-tag points to 2.2.1-alpha.1\n- Binary Distribution for v2.2.1-alpha.1 passed and published release passport bundle assets\n\n## Expected\n- Buildchain Ref Promotion creates v2.2.1 release version-state PR\n- npm stable publishes 2.2.1 with latest dist-tag\n- Binary Distribution publishes v2.2.1 assets without loose raw binaries",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:01:01Z",
          "mergedAt": "2026-07-02T06:02:31Z",
          "additions": 1581,
          "deletions": 265,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 268,
          "url": "https://github.com/kungfu-systems/buildchain/pull/268",
          "title": "Release v2.2.1",
          "body": "Create the generated version-state commit for v2.2.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:03:54Z",
          "mergedAt": "2026-07-02T06:05:20Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 269,
          "url": "https://github.com/kungfu-systems/buildchain/pull/269",
          "title": "Prepare v2.2.2-alpha.0",
          "body": "Create the generated version-state commit for v2.2.2-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:06:54Z",
          "mergedAt": "2026-07-02T06:09:08Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 270,
          "url": "https://github.com/kungfu-systems/buildchain/pull/270",
          "title": "fix(release): allow anchored version material in release gate",
          "body": "## Summary\n- allow strict release tree gate to accept anchored/manual release material changes limited to declared version.files plus the configured anchor manifest\n- require a valid alpha-to-release promotion PR plus lifecycle.verify or verification-command before applying that anchored/manual exception\n- update release docs, dry-run wording, tests, and the committed promote action bundle\n\n## Verification\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:28:42Z",
          "mergedAt": "2026-07-02T06:30:20Z",
          "additions": 261,
          "deletions": 48,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 271,
          "url": "https://github.com/kungfu-systems/buildchain/pull/271",
          "title": "release: promote v2.2 anchored release gate fix to alpha",
          "body": "## Summary\n- Promote the anchored/manual release tree gate fix from dev to alpha.\n- This should produce the next v2.2.2 alpha version-state after merge.\n\n## Verification\n- PR #270 checks passed.\n- Local pnpm run check passed on the source fix branch.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:31:01Z",
          "mergedAt": "2026-07-02T06:32:33Z",
          "additions": 261,
          "deletions": 48,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 272,
          "url": "https://github.com/kungfu-systems/buildchain/pull/272",
          "title": "Prepare v2.2.2-alpha.1",
          "body": "Create the generated version-state commit for v2.2.2-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:34:07Z",
          "mergedAt": "2026-07-02T06:35:51Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 273,
          "url": "https://github.com/kungfu-systems/buildchain/pull/273",
          "title": "release: promote anchored release gate fix to v2.2.2",
          "body": "## Summary\n- Promote the anchored/manual release tree gate fix from alpha to release.\n- Expected stable release: v2.2.2.\n\n## Verification\n- v2.2.2-alpha.1 promotion completed.\n- Binary Distribution for v2.2.2-alpha.1 completed successfully.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:39:25Z",
          "mergedAt": "2026-07-02T06:41:00Z",
          "additions": 262,
          "deletions": 49,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 274,
          "url": "https://github.com/kungfu-systems/buildchain/pull/274",
          "title": "Release v2.2.2",
          "body": "Create the generated version-state commit for v2.2.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:42:28Z",
          "mergedAt": "2026-07-02T06:43:57Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 275,
          "url": "https://github.com/kungfu-systems/buildchain/pull/275",
          "title": "Prepare v2.2.3-alpha.0",
          "body": "Create the generated version-state commit for v2.2.3-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:45:22Z",
          "mergedAt": "2026-07-02T06:47:21Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 276,
          "url": "https://github.com/kungfu-systems/buildchain/pull/276",
          "title": "fix(release): keep active dev branch current",
          "body": "## Summary\n\n- update release promotion so the latest minor line moves the repository default branch to its dev branch\n- refresh manual workflow defaults from v2.0 to v2.2\n- clarify that the npm package exposes importable toolkit APIs for JavaScript build code, while the CLI and binary are workflow/shell surfaces\n\n## Verification\n\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:06:51Z",
          "mergedAt": "2026-07-02T07:08:26Z",
          "additions": 230,
          "deletions": 87,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 142,
          "url": "https://github.com/kungfu-systems/kungfu/pull/142",
          "title": "refactor(core): home capability slices and gate them in verify --full",
          "body": "Capability slices get a home and a convention: framework/core/slices/<name>/ with a probe statement, sources and a one-command run script; the fact-ledger slice moves in as the first resident and its run script now asserts the zero-extra-dylib cut-proof itself. verify --full builds and runs all slices plus the yijinjing dependency-direction guard, so a core capability regression fails the repository gate instead of relying on manual scripts. Quick verify keeps its seconds-level semantics.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:12:02Z",
          "mergedAt": "2026-07-02T07:12:07Z",
          "additions": 161,
          "deletions": 22,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 278,
          "url": "https://github.com/kungfu-systems/buildchain/pull/278",
          "title": "release: promote current dev v2.2 to alpha",
          "body": "Promote the current dev/v2/v2.2 head into alpha before publishing the next stable buildchain release. This brings the active dev branch current with the anchored/manual release tree and toolkit observability updates.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:12:37Z",
          "mergedAt": "2026-07-02T07:14:28Z",
          "additions": 230,
          "deletions": 87,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 277,
          "url": "https://github.com/kungfu-systems/buildchain/pull/277",
          "title": "release: publish buildchain v2.2.3",
          "body": "Promote alpha/v2/v2.2 to release/v2/v2.2 so the stable v2 tag includes anchored/manual release tree handling needed by libnode publish gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:09:57Z",
          "mergedAt": "2026-07-02T07:16:11Z",
          "additions": 231,
          "deletions": 88,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 279,
          "url": "https://github.com/kungfu-systems/buildchain/pull/279",
          "title": "Prepare v2.2.3-alpha.1",
          "body": "Create the generated version-state commit for v2.2.3-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:15:59Z",
          "mergedAt": "2026-07-02T07:18:48Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 280,
          "url": "https://github.com/kungfu-systems/buildchain/pull/280",
          "title": "release: publish buildchain v2.2.3 after alpha refresh",
          "body": "Promote the refreshed alpha/v2/v2.2 line to release/v2/v2.2 after dev/v2/v2.2 was merged and v2.2.3-alpha.1 was fixed as the exact alpha material.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:20:55Z",
          "mergedAt": "2026-07-02T07:22:39Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 281,
          "url": "https://github.com/kungfu-systems/buildchain/pull/281",
          "title": "Release v2.2.3",
          "body": "Create the generated version-state commit for v2.2.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:24:10Z",
          "mergedAt": "2026-07-02T07:25:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 283,
          "url": "https://github.com/kungfu-systems/buildchain/pull/283",
          "title": "fix(release): allow anchored target PR version material",
          "body": "Allow anchored/manual release promotion to accept a reviewed same-repository PR merged into the target release branch when the diff from the exact alpha tag is limited to declared version-state and anchor manifest paths. This covers libnode's final release PR shape while keeping code changes after alpha rejected.\\n\\nValidation:\\n- node --test --test-name-pattern \"strict anchored release promotion accepts reviewed target PR\" tests/promote-buildchain-ref.test.mjs\\n- node --test --test-name-pattern \"strict release promotion|strict anchored release promotion|anchored manual release verifies\" tests/promote-buildchain-ref.test.mjs\\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:33:42Z",
          "mergedAt": "2026-07-02T07:35:23Z",
          "additions": 229,
          "deletions": 52,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 284,
          "url": "https://github.com/kungfu-systems/buildchain/pull/284",
          "title": "release: promote anchored target PR fix to alpha",
          "body": "Promote the anchored/manual target PR release gate fix from dev/v2/v2.2 into alpha before preparing the next stable buildchain release for libnode publishing.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:35:55Z",
          "mergedAt": "2026-07-02T07:37:36Z",
          "additions": 229,
          "deletions": 52,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 285,
          "url": "https://github.com/kungfu-systems/buildchain/pull/285",
          "title": "Prepare v2.2.4-alpha.0",
          "body": "Create the generated version-state commit for v2.2.4-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:39:07Z",
          "mergedAt": "2026-07-02T07:40:52Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 282,
          "url": "https://github.com/kungfu-systems/buildchain/pull/282",
          "title": "Prepare v2.2.4-alpha.0",
          "body": "Create the generated version-state commit for v2.2.4-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:27:22Z",
          "mergedAt": "2026-07-02T07:51:49Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 286,
          "url": "https://github.com/kungfu-systems/buildchain/pull/286",
          "title": "release: publish buildchain v2.2.4",
          "body": "Promote v2.2.4-alpha.0 to stable so libnode release publishing can use the anchored/manual target PR release gate fix.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:42:53Z",
          "mergedAt": "2026-07-02T07:53:45Z",
          "additions": 230,
          "deletions": 53,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 288,
          "url": "https://github.com/kungfu-systems/buildchain/pull/288",
          "title": "Release v2.2.4",
          "body": "Create the generated version-state commit for v2.2.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:55:19Z",
          "mergedAt": "2026-07-02T07:57:09Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 289,
          "url": "https://github.com/kungfu-systems/buildchain/pull/289",
          "title": "Prepare v2.2.5-alpha.0",
          "body": "Create the generated version-state commit for v2.2.5-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:58:47Z",
          "mergedAt": "2026-07-02T08:00:49Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 143,
          "url": "https://github.com/kungfu-systems/kungfu/pull/143",
          "title": "test(core): pin the embedding contract with a standalone consumer slice",
          "body": "The source/static embedding contract of the yijinjing core (EMBEDDING.md, adopted with the distribution-form decision) previously had no machine guard: it was validated once with a scratch project outside the repository. This adds slices/embedding — a standalone CMake project that consumes src/libyijinjing via add_subdirectory without the kungfu parent build, builds from scratch in a throwaway directory, writes a causal chain and asserts the assemble round trip. verify --full picks it up through the regular slice discovery.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:10:20Z",
          "mergedAt": "2026-07-02T08:10:25Z",
          "additions": 225,
          "deletions": 0,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 290,
          "url": "https://github.com/kungfu-systems/buildchain/pull/290",
          "title": "fix(release): key anchored transactions by package version",
          "body": "## Summary\n- key anchored/manual publish transactions by the declared package version instead of the anchor line tag\n- keep verification using the anchor release version while publish lifecycle receives the package version\n- add a libnode-shaped regression test and rebuild the promote action bundle\n\n## Verification\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:13:28Z",
          "mergedAt": "2026-07-02T08:15:22Z",
          "additions": 213,
          "deletions": 58,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 291,
          "url": "https://github.com/kungfu-systems/buildchain/pull/291",
          "title": "release: promote buildchain dev to alpha",
          "body": "## Summary\n- promote the current dev/v2/v2.2 line into alpha after the anchored transaction version fix\n\n## Verification\n- dev push Verify run 28575627774 succeeded\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:16:24Z",
          "mergedAt": "2026-07-02T08:18:27Z",
          "additions": 213,
          "deletions": 58,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 292,
          "url": "https://github.com/kungfu-systems/buildchain/pull/292",
          "title": "Prepare v2.2.5-alpha.1",
          "body": "Create the generated version-state commit for v2.2.5-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:20:12Z",
          "mergedAt": "2026-07-02T08:21:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 293,
          "url": "https://github.com/kungfu-systems/buildchain/pull/293",
          "title": "release: publish buildchain v2.2.5",
          "body": "## Summary\n- promote alpha/v2/v2.2 to release/v2/v2.2 after publishing 2.2.5-alpha.1\n- includes anchored/manual transaction identity fix for libnode\n\n## Verification\n- alpha version-state PR #292 merged\n- Buildchain Ref Promotion run 28576013639 succeeded\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:23:44Z",
          "mergedAt": "2026-07-02T08:25:20Z",
          "additions": 214,
          "deletions": 59,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 294,
          "url": "https://github.com/kungfu-systems/buildchain/pull/294",
          "title": "Release v2.2.5",
          "body": "Create the generated version-state commit for v2.2.5.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:26:48Z",
          "mergedAt": "2026-07-02T08:28:22Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 295,
          "url": "https://github.com/kungfu-systems/buildchain/pull/295",
          "title": "Prepare v2.2.6-alpha.0",
          "body": "Create the generated version-state commit for v2.2.6-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:29:47Z",
          "mergedAt": "2026-07-02T08:31:36Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 144,
          "url": "https://github.com/kungfu-systems/kungfu/pull/144",
          "title": "feat(core): prove bundle-only decoding with a schema-registry slice",
          "body": "Events carry only an opaque msg_type on the wire; this adds the schema-registry capability slice pinning the self-describing-format promise. The producer emits content-addressed .bfbs blobs plus per-run manifest schema bindings; the decoder links no generated code and no compiled type registry, decoding named typed fields through FlatBuffers runtime reflection, across two coexisting schema versions. Also stakes out the msg_type allocation ranges (docs/msg-type-ranges.md), moves the fact-ledger probe types into the slice range, and shares the sha256 helper under slices/common. All three slices plus the yijinjing dependency guard pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:37:40Z",
          "mergedAt": "2026-07-02T08:37:45Z",
          "additions": 521,
          "deletions": 11,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 296,
          "url": "https://github.com/kungfu-systems/buildchain/pull/296",
          "title": "fix(release): recover stale alpha transactions",
          "body": "## Summary\n- replace stale unfinished alpha publish transactions when version-state finalization is resuming the same declared version\n- keep completed transactions immutable and preserve exact-tag safety\n- cover same-version stale alpha recovery with durable state/evidence assertions\n\n## Tests\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:45:26Z",
          "mergedAt": "2026-07-02T08:47:05Z",
          "additions": 104,
          "deletions": 57,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 297,
          "url": "https://github.com/kungfu-systems/buildchain/pull/297",
          "title": "release: promote dev to alpha v2.2.6 recovery",
          "body": "## Summary\n- promote dev/v2/v2.2 to alpha/v2/v2.2 after stale alpha transaction recovery fix\n- keep the declared 2.2.6-alpha.0 version state on the alpha line\n\n## Tests\n- verified in PR #296: pnpm run check\n- this PR should let Buildchain finalization recreate the unfinished alpha transaction for v2.2.6-alpha.0",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:47:35Z",
          "mergedAt": "2026-07-02T08:49:57Z",
          "additions": 104,
          "deletions": 57,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 298,
          "url": "https://github.com/kungfu-systems/buildchain/pull/298",
          "title": "fix(release): ignore local stale transaction residue",
          "body": "## Summary\n- treat local-only release transaction files as non-authoritative cache when durable state is absent\n- replace stale local residue before publishing current alpha material\n- add coverage for self-hosted/dirty runner residue blocking alpha finalization\n\n## Tests\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:59:38Z",
          "mergedAt": "2026-07-02T09:01:50Z",
          "additions": 150,
          "deletions": 23,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 299,
          "url": "https://github.com/kungfu-systems/buildchain/pull/299",
          "title": "release: promote dev to alpha v2.2.6 transaction recovery",
          "body": "## Summary\n- promote dev/v2/v2.2 to alpha/v2/v2.2 with local-only stale transaction recovery\n- recover the unfinished v2.2.6-alpha.0 finalization without bumping to a new alpha\n\n## Tests\n- verified in PR #298: pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:02:22Z",
          "mergedAt": "2026-07-02T09:04:58Z",
          "additions": 150,
          "deletions": 23,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 300,
          "url": "https://github.com/kungfu-systems/buildchain/pull/300",
          "title": "fix(release): prefer declared alpha version state",
          "body": "## Summary\n- treat configured alpha version state as current even before its durable transaction branch exists\n- prevent older open durable alpha transactions from outranking the package-declared alpha version\n- add regression coverage for stale durable state selection\n\n## Tests\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:10:20Z",
          "mergedAt": "2026-07-02T09:12:59Z",
          "additions": 151,
          "deletions": 44,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 31,
          "url": "https://github.com/kungfu-systems/libnode/pull/31",
          "title": "ci(buildchain): add libnode build diagnostics",
          "body": "## Summary\n- add buildchain toolkit validation through the package JS API\n- capture libnode build diagnostics and timing snapshots across install, build, verify, package, and source preparation\n- pin @kungfu-tech/buildchain 2.2.5 for the diagnostics integration\n\n## Verification\n- corepack pnpm install --frozen-lockfile\n- corepack pnpm run buildchain:validate\n- node .gyp/libnode-release-verify.js\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n- node -c .gyp/buildchain-diagnostics.js\n- node -c .gyp/buildchain-validate.js\n- corepack pnpm exec prettier --check .gyp/*.js src/js/*.js\n- git diff --check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:43:52Z",
          "mergedAt": "2026-07-02T09:12:59Z",
          "additions": 582,
          "deletions": 33,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 301,
          "url": "https://github.com/kungfu-systems/buildchain/pull/301",
          "title": "release: promote dev to alpha v2.2.6 declared state recovery",
          "body": "Promote the declared-alpha transaction recovery fix from dev to alpha.\n\nThis includes the fix that makes a declared alpha version state outrank older resumable durable alpha transactions, so the next alpha promotion should create v2.2.6-alpha.0 instead of resuming stale v2.2.5-alpha.0 state.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:14:40Z",
          "mergedAt": "2026-07-02T09:16:12Z",
          "additions": 151,
          "deletions": 44,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 145,
          "url": "https://github.com/kungfu-systems/kungfu/pull/145",
          "title": "feat(gui): read live journal events and join a running master",
          "body": "Merge feature/v4-capability-sdk into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:20:44Z",
          "mergedAt": "2026-07-02T09:20:49Z",
          "additions": 694,
          "deletions": 133,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 34,
          "url": "https://github.com/kungfu-systems/build-images/pull/34",
          "title": "ci: follow buildchain v2 toolkit",
          "body": "## Summary\n- switch build-images Buildchain action refs from exact v2.0.16 to floating v2\n- add a Buildchain toolkit wrapper for v2 stable CLI observability\n- wrap image-family builds with Buildchain observability spans and verify the generated log\n\n## Validation\n- pnpm run check\n- git diff --check\n- shellcheck scripts/buildchain-toolkit.sh scripts/publish-image-family.sh\n- Buildchain toolkit smoke: version 2.2.5, span + verify observability-log passed",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:36:33Z",
          "mergedAt": "2026-07-02T09:37:33Z",
          "additions": 62,
          "deletions": 6,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 302,
          "url": "https://github.com/kungfu-systems/buildchain/pull/302",
          "title": "feat(web-surface): support first-class host mappings",
          "body": "## Summary\n- add named web-surface host mappings with per-channel preview/staging/production URLs\n- emit per-surface URL/binding outputs from the reusable web-surface workflow\n- support per-surface AWS deploy overrides, live concrete target checks, docs, and the libkungfu.dev-shaped fixture\n\n## Validation\n- pnpm run check\n\n## Release line\n- This is recorded as the v2.3 minor surface in docs/versioning.md.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:35:59Z",
          "mergedAt": "2026-07-02T09:37:33Z",
          "additions": 1089,
          "deletions": 260,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 35,
          "url": "https://github.com/kungfu-systems/build-images/pull/35",
          "title": "Promote dev/v1/v1.1 to alpha",
          "body": "## Summary\n- promote Buildchain v2 floating action refs and image build observability to alpha/v1/v1.1\n\n## Validation\n- PR #34 checks passed\n- dev/v1/v1.1 now uses Buildchain action refs @v2 and Buildchain toolkit observability wrapper",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:38:03Z",
          "mergedAt": "2026-07-02T09:38:56Z",
          "additions": 95,
          "deletions": 6,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 303,
          "url": "https://github.com/kungfu-systems/buildchain/pull/303",
          "title": "Prepare v2.3.0-alpha.0",
          "body": "## Summary\n- open the v2.3 minor line for the web-surface host mapping surface\n- carry the merged first-class host mapping implementation from dev/v2/v2.2\n- seed version state at 2.3.0-alpha.0 via buildchain.toml version.files\n\n## Validation\n- node bin/buildchain.mjs validate --require-version-state\n- implementation PR #302 passed pnpm run check and libnode-shaped reusable workflow checks",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:40:25Z",
          "mergedAt": "2026-07-02T09:41:58Z",
          "additions": 1394,
          "deletions": 284,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 304,
          "url": "https://github.com/kungfu-systems/buildchain/pull/304",
          "title": "Release v2.3.0",
          "body": "## Summary\n- release the v2.3 web-surface host mapping surface\n- promote the tested v2.3.0-alpha.0 alpha material to production\n\n## Evidence\n- alpha exact tag: v2.3.0-alpha.0\n- alpha promotion run: https://github.com/kungfu-systems/buildchain/actions/runs/28580737392\n- npm alpha package: @kungfu-tech/buildchain@2.3.0-alpha.0\n\n## Expected Buildchain behavior\n- create exact release tag v2.3.0\n- move floating tags v2.3 and v2 as appropriate\n- publish @kungfu-tech/buildchain@2.3.0 to npm latest\n- prepare next alpha v2.3.1-alpha.0",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:45:25Z",
          "mergedAt": "2026-07-02T09:47:00Z",
          "additions": 1394,
          "deletions": 284,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 36,
          "url": "https://github.com/kungfu-systems/build-images/pull/36",
          "title": "Prepare v1.1.1-alpha.10",
          "body": "Create the generated version-state commit for v1.1.1-alpha.10.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:46:54Z",
          "mergedAt": "2026-07-02T09:47:58Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 305,
          "url": "https://github.com/kungfu-systems/buildchain/pull/305",
          "title": "Release v2.3.0",
          "body": "Create the generated version-state commit for v2.3.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:48:35Z",
          "mergedAt": "2026-07-02T09:50:30Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 306,
          "url": "https://github.com/kungfu-systems/buildchain/pull/306",
          "title": "Prepare v2.3.1-alpha.0",
          "body": "Create the generated version-state commit for v2.3.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:51:56Z",
          "mergedAt": "2026-07-02T09:53:34Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 3,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/3",
          "title": "ci(site): adopt Buildchain v2.3 surface hosts",
          "body": "## Summary\n- declare hub/core/buildchain as first-class Buildchain web surfaces\n- switch the reusable web-surface workflow to Buildchain v2.3\n- update deploy and rollback docs for host-level preview/staging\n\n## Verification\n- npm run build\n- npm run check\n- git diff --check\n- Buildchain v2.3 web-surface validate\n- Buildchain v2.3 preview/staging deploy-plan\n- Buildchain v2.3 preview/staging deploy-apply dry-run\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T10:18:00Z",
          "mergedAt": "2026-07-02T10:23:00Z",
          "additions": 47,
          "deletions": 13,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 146,
          "url": "https://github.com/kungfu-systems/kungfu/pull/146",
          "title": "build(api): declare typescript so the type gate is self-contained",
          "body": "Merge feature/v4-default-kfx into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T10:24:09Z",
          "mergedAt": "2026-07-02T10:24:14Z",
          "additions": 2533,
          "deletions": 33345,
          "changedFiles": 209
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 147,
          "url": "https://github.com/kungfu-systems/kungfu/pull/147",
          "title": "feat(cli): promote kungfu to the canonical CLI command",
          "body": "## What\n\n- `@kungfu-tech/core` now installs both `kungfu` and `kfc` bins pointing at the same entry (`lib/kfc.js`): `kungfu` is the canonical end-user command, `kfc` stays a short alias and remains the runtime binary name.\n- Docs switch command examples to `kungfu` where they teach what to type (CLI handbook, debugging, adapters, spec overview) and keep `kfc` where they describe the runtime (architecture, design-philosophy, buildchain).\n- `concepts.md` / `known-limits.md` / `CONTRIBUTING.md` updated: the reserved `kungfu` name is now realized as the CLI facade; the richer end-user shell remains planned under the same name.\n- Welded-surface register: `kfc-cli` → `kungfu-cli` with an additive decision-log entry (pre-release, no line open, nothing removed).\n\n## Why\n\nThe `kungfu` name was reserved for the end-user CLI. Realizing it now, before any release line opens, is the only free window: after release the command name is a welded surface and a rename would be a major break. The freeze pipeline and `dist/kfc` internals are untouched — the bin map is the only mechanical change.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T11:16:39Z",
          "mergedAt": "2026-07-02T12:06:32Z",
          "additions": 46,
          "deletions": 38,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 4,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/4",
          "title": "Render Buildchain npm site facts",
          "body": "## Summary\n- replace the Buildchain surface fixture with the pinned @kungfu-tech/buildchain@2.3.0 npm package dist/site bundle\n- render package provenance, docs, CLI, workflow, release model, product mechanism, and machine artifact facts from the package\n- run npm ci from the official npm registry before the Buildchain web-surface build\n\n## Validation\n- npm ci --ignore-scripts --registry=https://registry.npmjs.org/\n- npm run build\n- npm run check\n- git diff --check\n- node node_modules/@kungfu-tech/buildchain/scripts/web-surface.mjs --mode validate --cwd .\n- preview/staging deploy-plan dry-runs",
          "author": "dongkeren",
          "createdAt": "2026-07-02T12:25:13Z",
          "mergedAt": "2026-07-02T12:26:41Z",
          "additions": 279,
          "deletions": 104,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 148,
          "url": "https://github.com/kungfu-systems/kungfu/pull/148",
          "title": "build: finish the pnpm migration for the workspace-level build chain",
          "body": "## What\n\nRunning the workspace build end to end (`./kungfu-code build` → freeze → verify → app) surfaced three yarn-era leftovers that break the root build chain under pnpm:\n\n1. **wsrun runs package scripts with yarn** — corepack rejects yarn under the pinned `packageManager`, so root `build`/`format` (the `foreach`/`format` runners) never worked post-migration. Fix: `--bin pnpm`.\n2. **patch-package cannot find pm2** — the root postinstall looked for `node_modules/pm2` at the workspace root, but pnpm nests it under `framework/api`, so every fresh install failed. Fix: move the pm2 named-pipe patch to pnpm-native `patchedDependencies` and retire patch-package (script, devDependency, and patch file format).\n3. **electron missing from `allowBuilds`** — its install script never ran, no Electron binary was fetched, and the reference GUI could not start from a fresh install.\n\nAlso records PR #147 in the versioning decision log (kungfu-cli register update).\n\n## Validation\n\nOn this branch, end to end on macOS arm64: `CI=1 ./kungfu-code build` compiles core and freezes `dist/kfc` (nuitka), `./kungfu-code verify` passes 5/5 including the runtime smoke (`kungfu --version` → 4.0.0-alpha.0, `kfc` alias likewise), pm2 patch verified applied in `framework/api/node_modules/pm2/paths.js`, and the reference GUI starts (electron-vite preview; main process loads all 20 native exports).\n\n## Known limits (out of scope, pre-existing)\n\n- `kfs craft dev` (artifact app path) still fails on webpack-era phantom deps in `framework/api/toolkit/utils.js` (`html-webpack-plugin`) — the known frontend-foundation follow-up; the sdk `build` script has the same class of issue (`webpack` undeclared).\n- `format:js` is broken workspace-wide: prettier is declared nowhere after the toolchain dependency-container retirement.\n- `prebuilt.libkungfu.cc` serves an expired certificate, so prebuilt fetch falls back to source builds (slower, not incorrect).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T12:40:16Z",
          "mergedAt": "2026-07-02T14:08:38Z",
          "additions": 16,
          "deletions": 155,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 149,
          "url": "https://github.com/kungfu-systems/kungfu/pull/149",
          "title": "fix(gui): home the packaged runtime under userData",
          "body": "Merge feature/v4-default-kfx into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T14:17:12Z",
          "mergedAt": "2026-07-02T14:17:18Z",
          "additions": 6,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 150,
          "url": "https://github.com/kungfu-systems/kungfu/pull/150",
          "title": "docs(adr): ADR-0011, first cut of the v4 capability SDK contract",
          "body": "Merge feature/v4-adr-0011-capability-sdk into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T14:27:47Z",
          "mergedAt": "2026-07-02T14:27:53Z",
          "additions": 78,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 151,
          "url": "https://github.com/kungfu-systems/kungfu/pull/151",
          "title": "feat(rewind): define the capture event schema as open-layer types",
          "body": "## What\n\nThe event contract for the `kungfu trace` capture layer, as the first Rewind component:\n\n- `framework/core/src/python/kungfu/rewind/rewind_events.fbs` — `RunBegin`/`RunEnd`, `ModelRequest`/`ModelResponse`, `ToolCall`/`ToolResult`, `RetryMarker` under `kungfu.rewind.fb`, following the longfist fb evolution discipline (tail-append only, no id reuse, no `required`).\n- **Open-layer placement, not kernel**: msg_types `30001–30099`. The capture skeleton (nanosecond timing via `gen_time`, frame-level causality via `trigger_frame_uid`) rides the existing frame header; tables add run identity, cross-layer span correlation (`span_id`/`parent_span_id`/`CaptureLayer`), payload bodies, and status/retry facts. Payloads are JSON strings — full local fidelity at capture, redaction only at export.\n- Trace bundles bind these msg_types to the schema's content-addressed `.bfbs` per run and decode by reflection alone — the exact mechanism `slices/schema-registry` pins.\n- `msg-type-ranges.md`: adds an informative first-party open-layer allocation table (binding authority stays with each run's manifest).\n- `docs/versioning.md`: registers welded surface `rewind-event-schema` (integration + cross-time; additive decision-log entry).\n\n## Why open layer\n\nRewind is a product on top of the substrate, not part of it. Welding its event types into the longfist closed set would couple the kernel registry to application churn; the open layer exists precisely for self-describing application schemas, and using it here dogfoods the schema-registry mechanism on the first real product.\n\n## Validation\n\nSchema compiles clean with the conan-provided flatc 25.9.23 (`--cpp --scoped-enums`, `-b --schema`, `--python`). Build wiring (`.bfbs` generation/packaging) intentionally lands with its consumer — the capture supervisor — in the next change.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T15:03:16Z",
          "mergedAt": "2026-07-02T15:05:53Z",
          "additions": 184,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 152,
          "url": "https://github.com/kungfu-systems/kungfu/pull/152",
          "title": "docs(adr): accept ADR-0011, the capability SDK is implemented and consumed",
          "body": "Merge feature/v4-sdk-reborn into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T15:12:12Z",
          "mergedAt": "2026-07-02T15:12:18Z",
          "additions": 1150,
          "deletions": 2633,
          "changedFiles": 81
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 153,
          "url": "https://github.com/kungfu-systems/kungfu/pull/153",
          "title": "feat(rewind): kungfu trace wraps a run and produces the local store",
          "body": "## What\n\nThe capture supervisor's L0 slice — the first runnable piece of Kungfu Rewind:\n\n- **`kungfu trace [--run-id] -- <command>`** (new console command): assigns a run id, injects the capture environment (`KUNGFU_REWIND_RUN_ID`) into an unmodified child process tree, brackets the run with `RunBegin`/`RunEnd` journal frames, and emits the trace bundle's format pieces — a content-addressed `.bfbs` blob plus a manifest binding every rewind msg_type to it — so the run decodes without this runtime (the mechanism `slices/schema-registry` pins).\n- **Standalone single-writer journal from python**, same shape as the C++ slices: no master, no-op publisher, private bus. One binding addition exposes `noop_publisher` to python.\n- `kungfu.rewind` grows `events.py` (FlatBuffers serializers for the 7 event tables), `bundle.py` (blob + manifest emission), `supervisor.py` (L0); `flatbuffers` (pure python) joins the console dependencies; the flatc-generated accessors are checked in next to the schema together with the `.bfbs`.\n- **Fixture** `tests/fixtures/rewind-demo-happy/`: the demo agent sees only injected environment — traced code needs no modification (the release red line, self-enforced) — and `check_capture.py` asserts the frames round-trip, all msg_types are bound, and the schema blob is content-addressed.\n\n## Validation\n\n- Fixture end to end: 11/11 assertions pass (RunBegin/RunEnd round-trip via `assemble.read_bytes` + reflection-free accessors, manifest bindings complete, blob hash verified).\n- `./kungfu-code verify`: 5/5 including the runtime smoke.\n- `ruff format` clean on all new python.\n\n## Scope\n\nModel wire capture (L1 proxy) and in-process tool hooks (L2, over the announced ingest endpoint) land next; this change is deliberately the smallest end-to-end loop.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T15:45:03Z",
          "mergedAt": "2026-07-02T15:47:11Z",
          "additions": 1450,
          "deletions": 0,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 154,
          "url": "https://github.com/kungfu-systems/kungfu/pull/154",
          "title": "feat(rewind): capture model calls at the wire",
          "body": "## What\n\nCapture layer L1 — the model-wire proxy, completing the G2 capture evidence:\n\n- The supervisor runs a local proxy (ephemeral localhost port) and points the child's model SDKs at it through the base-url environment variables (`OPENAI_BASE_URL`, `OPENAI_API_BASE`, `ANTHROPIC_BASE_URL`). No code change in the traced program — env injection only.\n- Every request forwards to the upstream the run would have used untraced (the parent environment's own base urls, falling back to provider defaults; anthropic paths route to the anthropic upstream, everything else openai-compatible). Each call lands as a `ModelRequest`/`ModelResponse` pair: provider, model, bodies as sent/received, finish reason, token usage, wire latency, span-id correlation, provenance `ModelWire`.\n- **Headers are never captured** — that is where API keys live; capture takes JSON bodies only. Redaction remains an export-time concern by design.\n- **Single-writer discipline by construction**: capture layers enqueue serialized events; one writer thread drains in arrival order. The journal writer is never touched from handler threads.\n- Fixture upgraded to a real model call: the demo agent posts a chat completion the way an SDK would, a deterministic local mock serves as upstream, and `check_capture` asserts the full round-trip — **24 assertions green**.\n\n## Validation\n\n- Fixture end to end 24/24 (run bracketing + model request/response facts + span correlation + bundle manifest/blob).\n- `ruff format` clean; python-only change, no build-chain surface touched.\n\n## Scope\n\nL2 in-process hooks (tool/framework semantics over the announced ingest endpoint) and the G3 completeness assertions land next.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T15:52:43Z",
          "mergedAt": "2026-07-02T15:56:03Z",
          "additions": 367,
          "deletions": 13,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 155,
          "url": "https://github.com/kungfu-systems/kungfu/pull/155",
          "title": "feat(rewind): capture tool semantics in-process, gate the fixtures in verify",
          "body": "## What\n\nCapture layer L2, completing the G3 (event completeness) evidence, plus the fixtures becoming a release gate:\n\n- **In-process hooks over an announced endpoint**: the supervisor starts a local ingest listener and prepends a hook directory to the child's `PYTHONPATH`; python's site machinery pulls in `sitecustomize`, which installs a meta-path finder that patches known frameworks **after** they import, at their natural seams (user-facing call + per-attempt boundary). No eager imports, no user code changes.\n- **Child-side hook is pure stdlib and best-effort by hard rule** — the traced environment owes us nothing, and a traced program must behave exactly like an untraced one (every hook operation degrades silently; a user `sitecustomize` shadowed by ours is chained through). Events travel as line-delimited JSON to the announced endpoint; the framing is swappable behind the endpoint without touching the hook protocol.\n- **Single-writer discipline holds**: ingest validates, serializes, enqueues; the one writer thread stays the only journal writer.\n- `ToolCall`/`ToolResult`/`RetryMarker` land with provenance `InProcessHook`: per-attempt calls, error detail on the failed attempt, output on the retried one, and the retry edge linking both spans.\n- **Fixture**: a stand-in tool framework (capability probe, not a product — it knows nothing about kungfu) plus a flaky tool failing once then succeeding; `check_capture` asserts **43 facts** end to end.\n- **`verify --full` gains stage 6**: every `tests/fixtures/rewind-demo-*/run.sh` is now a build-chain gate — a red fixture means the capture contract regressed (build dogfoods the product, per ADR-0009).\n\n## Validation\n\n- Fixture 43/43 green (run bracketing, model wire facts, tool per-attempt facts, retry linkage, result-to-call correlation, bundle manifest/blob).\n- `ruff format` clean (flatc-generated `fb/` deliberately left as emitted); `node --check verify.js` clean; python-only.\n\n## Known limits (recorded)\n\n- Cross-layer parent linking (tool span → wire model span) is timeline-ordered, not span-linked yet; frame-level `trigger_frame_uid` chaining and the cross-runtime fixture belong to the G7/G-Moat line.\n- Streaming (SSE) responses are captured verbatim, not parsed into usage facts.\n- Adapter table ships with the demo-toolkit entry; real framework adapters (LangChain et al.) grow in the adapter table by the same pattern.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T16:04:38Z",
          "mergedAt": "2026-07-02T16:11:10Z",
          "additions": 508,
          "deletions": 3,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 8,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/8",
          "title": "ci(infra): verify site infrastructure outputs",
          "body": "## Summary\\n- mirror the private infra output contract into infra/outputs.json\\n- verify buildchain.toml deployment targets and GitHub Actions role ARNs against the infra contract\\n- document that AWS resource lifecycle changes belong in infra-kungfu-sites\\n\\n## Verification\\n- npm run build\\n- npm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T16:42:19Z",
          "mergedAt": "2026-07-02T16:44:19Z",
          "additions": 111,
          "deletions": 1,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 5,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/5",
          "title": "ci(infra): verify site infrastructure outputs",
          "body": "## Summary\\n- mirror the private infra output contract into infra/outputs.json\\n- verify buildchain.toml deployment targets and GitHub Actions role ARNs against the infra contract\\n- document that AWS resource lifecycle changes belong in infra-kungfu-sites\\n\\n## Verification\\n- npm ci --ignore-scripts --registry=https://registry.npmjs.org/\\n- npm run build\\n- npm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T16:42:19Z",
          "mergedAt": "2026-07-02T16:44:19Z",
          "additions": 116,
          "deletions": 0,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 156,
          "url": "https://github.com/kungfu-systems/kungfu/pull/156",
          "title": "fix(core): arm every sqlite connection against cross-process contention",
          "body": "Merge feature/v4-config-db-lock-fix into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T17:11:05Z",
          "mergedAt": "2026-07-02T17:11:10Z",
          "additions": 94,
          "deletions": 21,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 32,
          "url": "https://github.com/kungfu-systems/libnode/pull/32",
          "title": "ci: authorize buildchain diagnostics alpha publish",
          "body": "Authorize the Buildchain diagnostics dogfood alpha source for 22.22.3-kf.3-alpha.2.\\n\\nEvidence before alpha authorization:\\n- Release - New Version run 28604378358 completed all native platform build/verify jobs.\\n- Windows x64, Linux x64, and macOS ARM64 uploaded deterministic artifacts, artifact manifests, and diagnostics artifacts.\\n- Buildchain aggregate summary and aggregate diagnostics summary jobs completed.\\n- npm publish did not run because alpha/v22/v22.22 was still locked to the previous alpha source SHA.\\n\\nThis PR targets only the alpha line; it is not a release/latest publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T16:35:23Z",
          "mergedAt": "2026-07-02T17:12:24Z",
          "additions": 36,
          "deletions": 17,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 33,
          "url": "https://github.com/kungfu-systems/libnode/pull/33",
          "title": "ci: stage Buildchain diagnostics alpha channel",
          "body": "Stages the Buildchain diagnostics dogfood changes on dev/v22/v22.22 so alpha publication can flow through the required dev -> alpha channel PR.\\n\\n- keeps publication on alpha only\\n- advances the attempted unpublished alpha.2 to 22.22.3-kf.3-alpha.3\\n- preserves Buildchain publish-gate/source-lock publication semantics\\n\\nAfter this lands on dev, the next step is a dev/v22/v22.22 -> alpha/v22/v22.22 channel PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T17:41:25Z",
          "mergedAt": "2026-07-02T18:02:18Z",
          "additions": 69,
          "deletions": 599,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 34,
          "url": "https://github.com/kungfu-systems/libnode/pull/34",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.3",
          "body": "Channel PR for alpha publication through Buildchain governance.\\n\\n- source: dev/v22/v22.22\\n- target: alpha/v22/v22.22\\n- npm version: 22.22.3-kf.3-alpha.3\\n- alpha only; no release/latest publication\\n- supersedes the unpublished alpha.2 publish-gate attempt that failed governance because it came from a feature -> alpha PR instead of dev -> alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T18:02:43Z",
          "mergedAt": "2026-07-02T18:25:18Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 307,
          "url": "https://github.com/kungfu-systems/buildchain/pull/307",
          "title": "feat(diagnostics): merge toolkit diagnostics into v2.3",
          "body": "## Summary\n- port the diagnostics toolkit, workflow diagnostics artifacts, and source-lock publish gate from the validated feature branch onto current v2.3\n- keep v2.3 version state at 2.3.1-alpha.0\n\n## Validation\n- pnpm run check\n- libnode dogfood alpha: @kungfu-tech/libnode@22.22.3-kf.3-alpha.3 and platform packages published under alpha\n- libnode publish-gate validated dev -> alpha source-lock via PR #33/#34\n\n## Notes\n- This PR is the v2.3 integration branch for feature/toolkit-diagnostics-feedback.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T18:51:30Z",
          "mergedAt": "2026-07-02T18:53:14Z",
          "additions": 4379,
          "deletions": 164,
          "changedFiles": 38
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 157,
          "url": "https://github.com/kungfu-systems/kungfu/pull/157",
          "title": "feat(rewind): one causal chain across python and node in one journal",
          "body": "## What\n\nGate **G7 (cross-runtime single journal)** — the machine-checkable half of G-Moat, and the attribution load-bearing wall: without this, Rewind's success would only prove a generic local tracer.\n\n- **Node hook** (`hook/rewind_hook.js`): injected via `NODE_OPTIONS --require` (the node counterpart of sitecustomize), pure node built-ins, same hard rules as the python hook — best-effort everywhere, socket `unref()` so tracing never keeps the traced process alive, frameworks patched after require at the same natural seams via a minimal require interceptor.\n- **Cross-runtime span propagation**: the python hook maintains the active span in `KUNGFU_REWIND_PARENT_SPAN` around each tool invocation (restored after, exception-safe); child processes inherit their causal parent through the environment, and the other runtime's spans root under it. One causal chain, two runtimes, one journal.\n- **Fixture** `tests/fixtures/rewind-demo-cross-runtime/` (auto-gated by `verify --full` stage 6): python agent → model call (wire) → tool delegated to a node process (node twin of the stand-in framework). **12 assertions**, the decisive ones:\n  - cross-runtime causal edge: node ToolCall's `parent_span_id` **equals** the python delegate's `span_id`;\n  - shared `run_id` across runtimes; single nanosecond timeline ordering the boundary; results correlate to calls across runtimes; the entire chain lives in one journal location.\n- A generic baseline (per-runtime logs joined offline / OTLP viewer) cannot satisfy these facts — that is the point of the assertion design.\n\n## Validation\n\n- Cross-runtime fixture 12/12 green; happy-path fixture regression 43/43 green; `ruff format` + `node --check` clean.\n\n## Scope\n\nNext change adds the forensic-replay surface (`kungfu rewind show/verify`: native journal walk vs bundle reflection decode, consistency diff) — v1 is forensic replay; deterministic rerun stays a next-stage differentiator gate.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T23:32:03Z",
          "mergedAt": "2026-07-02T23:34:47Z",
          "additions": 528,
          "deletions": 2,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 158,
          "url": "https://github.com/kungfu-systems/kungfu/pull/158",
          "title": "docs(deps): register local modifications to vendored dependencies",
          "body": "Merge docs/v4-vendored-deps-register into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T23:36:17Z",
          "mergedAt": "2026-07-02T23:36:21Z",
          "additions": 27,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 159,
          "url": "https://github.com/kungfu-systems/kungfu/pull/159",
          "title": "feat(rewind): forensic replay — the record proves it self-describes",
          "body": "## What\n\nThe forensic-replay surface (the second half of the G-Moat machine gate):\n\n- **`kungfu rewind show --run <id>`** — reconstructs the run's causal tree from the journal alone through the native path (runtime reader + generated accessors): model spans, tool spans with their **cross-runtime nesting**, retry edges, per-span timing.\n- **`kungfu rewind verify --run <id> [--bundle <dir>]`** — re-decodes every frame a second, independent way: the bundle's manifest bindings + content-addressed `.bfbs` blob, walked through **FlatBuffers reflection with no generated event code**, then diffs the two paths fact by fact. Identical output proves the trace bundle decodes without the runtime that wrote it; schema drift, blob tampering, or binding gaps surface as concrete per-frame diffs. `reflection_fb.py` is flatc-generated from `reflection.fbs` (the schema of schemas) — checked in like the rest of the generated code.\n- **Fixture** `tests/fixtures/rewind-demo-forensic-replay/` (auto-gated by `verify --full`): records a cross-runtime run, asserts the tree renders with the node tool nested under the python delegate, asserts both decode paths agree over all frames, and asserts a **tampered schema blob makes verify fail** — the falsification that keeps the check honest.\n\nSample tree from the fixture:\n\n```\nrun fixturereplay…  command: python3 …/demo_agent.py\n  status: exit_code=0\n    - model openai/demo-model  [ok, 11.5ms]\n    - tool delegate  [ok, 38.9ms]\n      - tool node-lookup  [ok, 0.0ms]\n```\n\n## Disclosure (per the validation discipline)\n\nv1 replay scope is **forensic** — re-open, walk, verify. Deterministic re-execution is a next-stage differentiator gate by design, stated in the module header.\n\n## Validation\n\nForensic fixture green end to end (tree + verify + tamper rejection); happy-path 43/43 and cross-runtime 12/12 regressions green; `ruff format` clean; python-only.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T23:43:05Z",
          "mergedAt": "2026-07-02T23:48:09Z",
          "additions": 1923,
          "deletions": 0,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 160,
          "url": "https://github.com/kungfu-systems/kungfu/pull/160",
          "title": "fix(core): route terminate diagnostics through the stackwalker",
          "body": "Merge docs/v4-vendored-deps-register into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T23:58:51Z",
          "mergedAt": "2026-07-02T23:58:55Z",
          "additions": 36,
          "deletions": 11,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 161,
          "url": "https://github.com/kungfu-systems/kungfu/pull/161",
          "title": "docs(core): pin down why holdon is not publish",
          "body": "Merge docs/v4-rx-holdon-semantics into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T00:26:11Z",
          "mergedAt": "2026-07-03T00:26:16Z",
          "additions": 11,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 162,
          "url": "https://github.com/kungfu-systems/kungfu/pull/162",
          "title": "fix(core): stop the event loop structurally on subscriber errors",
          "body": "Merge fix/v4-rx-structured-interrupt into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T00:55:53Z",
          "mergedAt": "2026-07-03T00:55:57Z",
          "additions": 21,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 163,
          "url": "https://github.com/kungfu-systems/kungfu/pull/163",
          "title": "fix(rewind): fixture mocks must not outlive their run",
          "body": "## What\n\nTwo harness bugs that `verify --full` stage 6 itself surfaced the first time it ran the rewind fixtures under `spawnSync` — the gate catching its own probes:\n\n1. **Disarmed cleanup trap**: ending `run.sh` with `exec` replaced the shell, so the `EXIT` trap never fired and the background mock model leaked (several multi-hour mock processes accumulated across manual runs).\n2. **Pipe-EOF deadlock**: the leaked mock inherited the captured stdout pipe; a harness waiting for pipe EOF (`spawnSync`) waited forever — stage 6 hung on a fixture that had actually passed.\n\nFix: the mock detaches from stdio at spawn (`>/dev/null 2>&1`) and the final check runs without `exec` so the trap actually fires. The reasoning is recorded as a comment at the spawn site in all three fixtures.\n\n## Validation\n\n`./kungfu-code verify --full`: **14/14 passed** — full rebuild + freeze + runtime smoke + 3 capability slices + yijinjing dependency guard + all 3 rewind fixtures green under the gated (spawnSync) environment, no leftover processes.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T01:18:28Z",
          "mergedAt": "2026-07-03T01:20:05Z",
          "additions": 20,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 308,
          "url": "https://github.com/kungfu-systems/buildchain/pull/308",
          "title": "feat(diagnostics): infer process-tree parallelism",
          "body": "## Summary\n- capture redacted process command lines in process-tree samples\n- infer requested parallelism from sampled build-tool descendants when wrapper commands hide the real build command\n- include process-tree evidence and candidates in process summaries\n\n## Validation\n- pnpm exec node --test tests/cli.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T01:36:22Z",
          "mergedAt": "2026-07-03T01:38:06Z",
          "additions": 195,
          "deletions": 30,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 164,
          "url": "https://github.com/kungfu-systems/kungfu/pull/164",
          "title": "build(artifact): revive the app assembly on the platform stack",
          "body": "## What\n\nThe frontend-foundation surgery that unblocks the GUI line — net **-752 lines**:\n\n- **artifact revived as a thin delegation layer** (its scripts still called the retired webpack-era `kfs craft` verbs, so every root app verb was dead): `dev`/`app`/`build` forward to the reference GUI's electron-vite verbs, `package`/`dist` to its electron-builder `pack`/`dist`, `cli` to the TUI. The dogfood identity stays — the runnable/packageable product surface is the reference app with its default kfx — without duplicating an app shell.\n- **The Electron binary becomes a precondition the verbs enforce**, not an install side effect: pnpm's build-script scheduling has been observed to leave `electron` without its `dist/` on fresh worktrees (package present, install script never ran, `pnpm ignored-builds` reports none — mechanism unclear, recorded as observation). `ensure-electron.mjs` no-ops in milliseconds when the binary is present and runs electron's own `install.js` in place when it is not; wired explicitly into `dev`/`start`/`pack`/`dist`.\n- **Last webpack remnants removed**: `framework/api/toolkit/` was dead wood poisoned by a top-level `html-webpack-plugin` require — its only consumer was a try/catch in core's `lib/kfc.js` that always fell back (now simplified to the byte-identical fallback behavior). `codeEditor/` inside it referenced a package that no longer exists.\n- **Root `rebuild` script renamed to `rebuild:all`**: the name shadowed pnpm's built-in `rebuild` command workspace-wide, which blocked the natural repair lever for the electron case above.\n\n## Validation\n\n- `./kungfu-code app` launches the Electron app end to end (process alive, main process loads all 20 native exports).\n- `./kungfu-code --filter @kungfu-tech/artifact-kungfu run package` produces `Kungfu.app` (darwin-arm64, electron-builder).\n- `ensure-electron` verified on both paths (present → fast no-op; missing → fetches once and validates).\n- `./kungfu-code verify` 5/5; no dangling `kfs craft` / `api/toolkit` references repo-wide.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T01:56:28Z",
          "mergedAt": "2026-07-03T02:00:40Z",
          "additions": 59,
          "deletions": 811,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 309,
          "url": "https://github.com/kungfu-systems/buildchain/pull/309",
          "title": "feat(workflows): gate buildchain runtime overrides",
          "body": "## Summary\n- keep Buildchain reusable workflow runtime refs stable by default with empty buildchain-ref inputs\n- allow trusted workflow_dispatch runs to validate train refs or exact runtime SHAs after resolving them to immutable commits\n- record runtime ref, SHA, stability class, trust decision, and rollback evidence in summaries and web-surface manifests\n\n## Validation\n- pnpm exec node --test tests/build-surface.test.mjs tests/cli.test.mjs\n- pnpm run check:workflows\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T02:22:45Z",
          "mergedAt": "2026-07-03T02:24:45Z",
          "additions": 697,
          "deletions": 24,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 165,
          "url": "https://github.com/kungfu-systems/kungfu/pull/165",
          "title": "feat(core): add event-dispatch latency probe and baseline bench",
          "body": "Merge feature/event-dispatch-baseline into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T02:45:25Z",
          "mergedAt": "2026-07-03T02:45:30Z",
          "additions": 512,
          "deletions": 3,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 166,
          "url": "https://github.com/kungfu-systems/kungfu/pull/166",
          "title": "feat(gui): the Rewind inspector — recorded runs become a diagnosable face",
          "body": "## What\n\nRewind grows its first user-visible face — the reference app's third default kfx, carrying gates G5 (find the failing step fast) and G6 (demo carrier), and the stage for the G-Moat agent-QA half:\n\n- **Rewind inspector kfx** (three panes, house style — dark/dense/monospace):\n  - *run list*: status dot, event/error counts, start time; empty state points at `kungfu trace -- …`;\n  - *causal trace tree*: model/tool/retry spans with their **cross-runtime nesting** (the node tool renders under the python delegate), failed nodes marked ✗, per-span latency;\n  - *node detail*: status/latency/tokens/finish-reason/error facts plus pretty-printed input/output bodies — the G5 questions (which step failed, what went in, what came back) answered in two clicks.\n- **Capability SDK grows the rewind domain** beside the ADR-0011 five handles, same factory style: `openRewind → runs()/loadRun()/refresh()`, decoding open-layer events via flatc-generated TS accessors (checked in like the python side) and rebuilding **the same causal tree the CLI's forensic replay walks** — one fact model, two surfaces. `flatbuffers` (TS runtime) joins api dependencies.\n- **Native frame gains `dataBytes()`** (~5 lines): the raw-payload path for open-layer frames whose schemas live outside the compiled longfist registry (`data()`/`dataAsString()` only speak the closed set).\n\n## Validation\n\n- Headless capability smoke over a captured two-run home: run list with error counts; retry (attempt=2) and error facts present; cross-runtime child correctly nested under its python parent.\n- App boots against the same home (binding loaded, 20 exports); `tsc --noEmit` (api), `electron-vite build`, `biome check` all clean.\n\n## Scope notes\n\n- No new UI dependencies — hand-rolled compact components consistent with the existing kfx; the richer component stack (virtualized tables, flow graph, editors) grows later per the design reserve.\n- G5/G6 formal gate runs (agent-QA + full demo three-pack) are the next line; this change delivers the diagnosable surface they run on.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T02:45:46Z",
          "mergedAt": "2026-07-03T02:58:26Z",
          "additions": 1572,
          "deletions": 5,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 167,
          "url": "https://github.com/kungfu-systems/kungfu/pull/167",
          "title": "docs(adr): record the v4 freeze decision for the reactive event layer",
          "body": "Merge docs/adr0005-event-freeze into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T03:27:54Z",
          "mergedAt": "2026-07-03T03:27:59Z",
          "additions": 29,
          "deletions": 7,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 310,
          "url": "https://github.com/kungfu-systems/buildchain/pull/310",
          "title": "docs(workflows): document runtime train handoff",
          "body": "## Summary\n- document runtime train validation handoff\n- clarify trains are temporary fast-use and rollback channels, not pending merge targets\n- require normal dev mainline and alpha/release closeout after validation\n\n## Validation\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T03:48:05Z",
          "mergedAt": "2026-07-03T03:48:18Z",
          "additions": 174,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 168,
          "url": "https://github.com/kungfu-systems/kungfu/pull/168",
          "title": "fix(yijinjing): fix Windows crash stack traces — rewrite walker and ship PDBs",
          "body": "## What\n\nWindows crash reports carried no usable native stack. Two parts:\n\n1. **Rewrite the stackwalker** (`fix(yijinjing)`): the hand-rolled StackWalk64 walk, seeded from a manual STACKFRAME with DbgHelp `fInvadeProcess=FALSE` and no registered unwind tables, produced garbage frames and no symbols on x64. Replaced with the OS unwinder (`RtlCaptureStackBackTrace` for the current thread, `StackWalk64` from the exception `CONTEXT` for SEH) symbolized via `SymFromAddr` / `SymGetLineFromAddr64`. Architecture-neutral (x64 + ARM64), DbgHelp serialized behind one process-wide mutex. Collapses the file from ~2000 lines to ~350 and removes the dead vendored walker and VC5/6 compatibility code.\n\n2. **Ship PDBs** (`build(windows)`): the MSVC build emitted no debug info, so even with a correct walker kungfu frames would resolve only to `module+offset` in the field. Build with `/Z7` + `/DEBUG /OPT:REF /OPT:ICF`, copy each native's PDB into `dist/kfc` at freeze, and fail the freeze if a shipped kungfu native lacks its PDB. See `docs/windows-crash-symbols.md`.\n\n## Validation\n\nThe walker was validated with a standalone harness compiling the real `StackWalker.cpp` + `stacktrace.cpp` under VS2022: before → garbage frames / no symbols; after → fully symbolized stacks for both the SEH crash path and the capture path, including exact `file:line` at the fault site. The full in-tree Windows `.node` build is currently blocked by unrelated toolchain issues (cmake-js/Ninja resource-compiler, rocksdb MSVC mismatch), so these changes are not yet exercised end-to-end there; the freeze-time PDB check fails safe when symbols are missing.\n\n## Version impact\n\nPatch — internal bug fix plus build hardening, no public interface change.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T03:40:32Z",
          "mergedAt": "2026-07-03T03:54:36Z",
          "additions": 474,
          "deletions": 2103,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 169,
          "url": "https://github.com/kungfu-systems/kungfu/pull/169",
          "title": "docs(rewind): the onboarding page, hardened by a stranger walking it",
          "body": "## What\n\nThe Rewind onboarding surface plus the completed demo three-pack — the substance behind gates G9 (docs onboarding), G6 (demo three-pack) and the fresh-reader validation loop:\n\n- **`docs/rewind.md`** — the complete stranger path: install → capture → diagnose (CLI + app) → forensic replay → delete/privacy → demos → honest known limits. Routed from `MAP.md`.\n- **Hardened by an actual fresh walk-through**: a reader following only this page (no source access) captured a failing agent run, diagnosed it in **one command**, correctly articulated the cross-runtime causal chain of a second run, ran `verify` and interpreted it — and reported eight friction points, all fixed here: the capture command spelling that survives shell re-exec (macOS dyld quirk documented in known limits), run-id assignment stated, the show-vs-app split for input/output bodies made honest, the two on-disk directories explained, exit-code propagation and upstream discovery documented, the missing per-node runtime tag acknowledged as a schema addition on the list.\n- **Demo three-pack completed** (each 12-assertion gated, auto-run by `verify --full`):\n  - `rewind-demo-tool-failure/` — a tool failing for real: single call, errored result carrying the actual contract violation, failed run status, ✗ in the rendered tree;\n  - `rewind-demo-model-drift/` — the model picks a tool that does not exist: the drift is visible in the model node's recorded output, the consequence in the routing step right after it, ordered on the timeline.\n- **Two small product improvements the walk-through motivated**: the CLI tree renders failed nodes as `✗ error — <detail>` (was a bare status code), and the app accepts `KFE_INITIAL_VIEW` to open straight onto a chosen view (deep-linking for demos and drills).\n\n## Validation\n\n- All five fixtures green standalone (tool-failure and model-drift 12/12 each; happy 43, cross-runtime 12, forensic full regression).\n- gui lint/build clean; ruff clean; the fresh-reader walk-through itself is the G9 evidence (transcript recorded in the control-plane records).\n\n## Notes\n\nThe reader's attribution answer is worth quoting in spirit: for a single-process failure a generic per-process log diagnoses equally well — the differentiated value shows exactly where the plan said it would: the cross-runtime causal edge, the two-path `verify`, and wire capture with zero agent modification.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T03:57:43Z",
          "mergedAt": "2026-07-03T04:02:29Z",
          "additions": 685,
          "deletions": 2,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 311,
          "url": "https://github.com/kungfu-systems/buildchain/pull/311",
          "title": "feat(infra): add infra contract evidence surface",
          "body": "## Summary\n- add provider-neutral infra-contract config, CLI, plan/artifact/propagation contracts\n- add manual-observed and Terraform-shaped fixtures with fail-closed apply semantics\n- document infra-contract lifecycle and expose docs/CLI metadata in generated site bundle\n\n## Validation\n- node --check scripts/infra-contract-core.mjs scripts/infra-contract.mjs bin/buildchain.mjs scripts/init-repo.mjs\n- node --test tests/cli.test.mjs tests/infra-contract.test.mjs tests/buildchain-config.test.mjs\n- pnpm run generate:site && pnpm run check:site\n- pnpm run check\n\nTrain ref for consumer validation: train/v2/v2.4/infra-contract",
          "author": "dongkeren",
          "createdAt": "2026-07-03T04:16:42Z",
          "mergedAt": "2026-07-03T04:19:19Z",
          "additions": 1277,
          "deletions": 124,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 312,
          "url": "https://github.com/kungfu-systems/buildchain/pull/312",
          "title": "fix(infra): require saved plans for apply gates",
          "body": "## Summary\n- require `infra-contract apply` to consume a saved infra-contract plan\n- reject missing, stale, source-mismatched, or input-drifted plans before any adapter mutation can run\n- document the saved-plan apply gate and cover it from core and CLI tests\n\n## Validation\n- `node --check scripts/infra-contract-core.mjs scripts/infra-contract.mjs bin/buildchain.mjs`\n- `node --test tests/cli.test.mjs tests/infra-contract.test.mjs tests/buildchain-config.test.mjs`\n- `corepack pnpm run generate:site && corepack pnpm run check:site`\n- `corepack pnpm run check`\n\nNo package release or live infrastructure mutation is included in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T04:45:34Z",
          "mergedAt": "2026-07-03T04:47:20Z",
          "additions": 237,
          "deletions": 8,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 170,
          "url": "https://github.com/kungfu-systems/kungfu/pull/170",
          "title": "feat(rewind): export a run as one portable file; ship the app as an installer",
          "body": "## What\n\nThe distribution face — gates **G8 (export bundle)** and **G1 (installers, macOS arm64 first)**:\n\n- **`rewind export --run <id>`** → one portable `.rewind.zip` (journal pages + the self-describing bundle, layout-preserving). **`rewind open <file>`** extracts anywhere, runs the same two-path verification as a local run before showing anything, prints the causal tree, and leaves a fully functional home behind. Offline, no services.\n- **`rewind-demo-export` fixture** proves it the hard way: capture → export → **delete the original home** → open in a fresh location → verify green + full tree (retry annotation included). Auto-discovered by `verify --full`.\n- **Installable app**: electron-builder targets grow `dmg` + `zip` (pack verb unchanged). Validated end to end: `dist` produced the dmg, it was mounted, `Kungfu.app` copied out (simulated install) and launched from the installed copy against a captured home — binding loads (20 exports), Rewind inspector renders identically to the workspace build. Unsigned pre-release; quarantine note documented. Linux/Windows + signing stay with the release pipeline (documented as the next gate).\n- **Tree-builder bug fixed in both surfaces**: a RetryMarker shares its span_id with the attempt that follows it; both the CLI and GUI tree builders opened a span for it, which the ToolCall then overwrote in place — node rendered twice, retry edge lost. Retries are now annotations on the attempt's span: `(retry #2)` in the CLI, retry-tinted label + detail facts in the app.\n- Docs: install section covers the dmg path; export/open section added; the on-disk journal path corrected to the real layout (`journal/system/rewind/<run-id>`).\n\n## Validation\n\n- All six rewind fixtures green (new export fixture: verify-after-delete + tree assertions).\n- api tsc clean, gui lint/build clean, ruff format clean.\n- dmg install → standalone launch → inspector renders: verified on darwin-arm64.\n\n## Notes\n\nInstaller size is hefty (~1.25GB dmg) — the frozen kfc runtime ships inside. Size optimization is real follow-up work but not a gate for the pre-release window.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T04:46:29Z",
          "mergedAt": "2026-07-03T04:49:01Z",
          "additions": 421,
          "deletions": 35,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 313,
          "url": "https://github.com/kungfu-systems/buildchain/pull/313",
          "title": "feat(infra): add dry-run-first contract propagation",
          "body": "## Summary\n- add `infra-contract --mode propagation-apply` as the execution layer for downstream contract PR propagation\n- keep propagation dry-run by default with machine-readable planned operations\n- require `--dry-run false`, `--approval-id`, and explicit consumer workspaces before creating branches, commits, pushes, or GitHub PRs\n\n## Validation\n- `node --check scripts/infra-contract-core.mjs scripts/infra-contract.mjs bin/buildchain.mjs`\n- `node --test tests/cli.test.mjs tests/infra-contract.test.mjs tests/buildchain-config.test.mjs`\n- `corepack pnpm run generate:site && corepack pnpm run check:site`\n- `corepack pnpm run check`\n\nNo package release, live infrastructure mutation, or real consumer PR creation is included in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T04:54:51Z",
          "mergedAt": "2026-07-03T04:56:28Z",
          "additions": 371,
          "deletions": 6,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 314,
          "url": "https://github.com/kungfu-systems/buildchain/pull/314",
          "title": "feat(infra): capture custom command adapter evidence",
          "body": "## Summary\n- record custom-command validate/plan/observe hooks as adapter evidence by default without executing them\n- support explicit `--execute-adapter-commands true` for non-mutating validate/plan/observe evidence capture\n- fail closed when adapter evidence commands fail and preserve JSON stdout as machine-readable evidence\n\n## Validation\n- `node --check scripts/infra-contract-core.mjs scripts/infra-contract.mjs bin/buildchain.mjs`\n- `node --test tests/cli.test.mjs tests/infra-contract.test.mjs tests/buildchain-config.test.mjs`\n- `corepack pnpm run generate:site && corepack pnpm run check:site`\n- `corepack pnpm run check`\n\nNo package release, live infrastructure mutation, or real consumer PR creation is included in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T05:04:36Z",
          "mergedAt": "2026-07-03T05:06:27Z",
          "additions": 273,
          "deletions": 3,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 315,
          "url": "https://github.com/kungfu-systems/buildchain/pull/315",
          "title": "feat(infra): execute approved custom command apply",
          "body": "## Summary\n- add an input hash to infra-contract plans so apply freshness checks ignore dynamic adapter evidence while still detecting desired/contract/consumer drift\n- execute custom-command apply hooks only after saved plan freshness, approval id, `--dry-run false`, and `--execute-adapter-commands true`\n- keep non-custom infrastructure adapters fail-closed before mutation execution\n\n## Validation\n- `node --check scripts/infra-contract-core.mjs scripts/infra-contract.mjs bin/buildchain.mjs`\n- `node --test tests/infra-contract.test.mjs tests/cli.test.mjs tests/buildchain-config.test.mjs`\n- `corepack pnpm run generate:site && corepack pnpm run check:site`\n- `corepack pnpm run check`\n\nNo package release, live cloud/IaC mutation, or real consumer PR creation is included in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T05:16:48Z",
          "mergedAt": "2026-07-03T05:18:27Z",
          "additions": 303,
          "deletions": 14,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 316,
          "url": "https://github.com/kungfu-systems/buildchain/pull/316",
          "title": "test(infra): add static provider contract fixtures",
          "body": "## Summary\n- add static aws-cloudformation and pulumi infra-contract fixtures with desired and observed output shapes\n- cover both fixtures through validate, plan, contract, and propagation-plan tests without provider credentials or live calls\n- document the safe provider fixture set for infra-contract adapters\n\n## Validation\n- `node --test tests/infra-contract.test.mjs tests/buildchain-config.test.mjs`\n- `corepack pnpm run generate:site && corepack pnpm run check:site && corepack pnpm run check`\n\nNo package release, live cloud/IaC mutation, or real consumer PR creation is included in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T05:25:37Z",
          "mergedAt": "2026-07-03T05:27:14Z",
          "additions": 161,
          "deletions": 0,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 317,
          "url": "https://github.com/kungfu-systems/buildchain/pull/317",
          "title": "feat(infra): bundle infra contract lifecycle evidence",
          "body": "## Summary\n- add an infra-contract evidence-bundle contract that binds desired, plan, approval, apply, observe, contract, and propagation evidence to a verified artifact hash\n- expose buildchain infra-contract --mode evidence-bundle with apply/propgation result inputs\n- document the lifecycle bundle and cover artifact/apply/propagation mismatch failures\n\n## Tests\n- node --check scripts/infra-contract-core.mjs && node --check scripts/infra-contract.mjs && node --check bin/buildchain.mjs\n- node --test tests/infra-contract.test.mjs tests/cli.test.mjs tests/buildchain-config.test.mjs\n- corepack pnpm run generate:site\n- corepack pnpm run check:site\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T05:38:48Z",
          "mergedAt": "2026-07-03T05:40:30Z",
          "additions": 341,
          "deletions": 0,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 318,
          "url": "https://github.com/kungfu-systems/buildchain/pull/318",
          "title": "feat(infra): plan provider adapter commands",
          "body": "## Summary\n- record planned command evidence for built-in infra adapters across validate/plan/apply/observe stages\n- keep built-in provider commands planned-only until concrete executors exist; only custom-command hooks execute through the existing explicit switch\n- update infra-contract docs and site CLI registry\n\n## Tests\n- node --check scripts/infra-contract-core.mjs && node --check scripts/infra-contract.mjs && node --check scripts/generate-site-bundle.mjs && node --check bin/buildchain.mjs\n- node --test tests/infra-contract.test.mjs tests/cli.test.mjs tests/buildchain-config.test.mjs\n- corepack pnpm run generate:site && corepack pnpm run check:site\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T05:51:30Z",
          "mergedAt": "2026-07-03T05:53:04Z",
          "additions": 116,
          "deletions": 18,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 319,
          "url": "https://github.com/kungfu-systems/buildchain/pull/319",
          "title": "feat(infra): execute configured provider commands",
          "body": "## Summary\n- allow `[infra.commands]` hooks to execute for any infra adapter, not just `custom-command`\n- keep built-in provider command templates planned-only unless a repository declares concrete commands\n- preserve apply gates: saved fresh plan, approval id, `--dry-run false`, and `--execute-adapter-commands true`\n\n## Validation\n- `node --check scripts/infra-contract-core.mjs && node --check scripts/infra-contract.mjs && node --check scripts/generate-site-bundle.mjs && node --check bin/buildchain.mjs`\n- `node --test tests/infra-contract.test.mjs tests/cli.test.mjs tests/buildchain-config.test.mjs`\n- `corepack pnpm run generate:site`\n- `corepack pnpm run check:site`\n- `corepack pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T06:04:33Z",
          "mergedAt": "2026-07-03T06:06:13Z",
          "additions": 141,
          "deletions": 27,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 320,
          "url": "https://github.com/kungfu-systems/buildchain/pull/320",
          "title": "feat(infra): verify lifecycle evidence bundles",
          "body": "## Summary\n- add `buildchain verify infra-contract-evidence-bundle <file>` as a read-only fail-closed verifier\n- verify bundle hash, contract artifact hash, lifecycle stage presence, and desired/plan/approval/observe/propagation bindings\n- document the verifier and add it to the generated CLI registry\n\n## Validation\n- `node --check scripts/infra-contract-core.mjs && node --check scripts/infra-contract.mjs && node --check scripts/generate-site-bundle.mjs && node --check bin/buildchain.mjs`\n- `node --test tests/infra-contract.test.mjs tests/cli.test.mjs tests/buildchain-config.test.mjs`\n- `corepack pnpm run generate:site && corepack pnpm run check:site`\n- `corepack pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T06:19:59Z",
          "mergedAt": "2026-07-03T06:21:47Z",
          "additions": 252,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 171,
          "url": "https://github.com/kungfu-systems/kungfu/pull/171",
          "title": "fix(yijinjing): make POSIX crash dump async-signal-safe",
          "body": "## Summary\n\nThe crash signal handler produced its stack dump using calls that are not\nasync-signal-safe: `std::ofstream`, `localtime`/`strftime`, spdlog logging, and\nmalloc-backed `backtrace_symbols`/`__cxa_demangle`. When a fatal signal is\nraised after heap corruption — precisely the case where a stack trace matters\nmost — those calls could deadlock or double-fault, so no report was written.\nThis rewrites the POSIX crash dump path to use only async-signal-safe\nprimitives.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- Rewrite the POSIX `print_stack_trace()` to use only async-signal-safe building\n  blocks: preallocated buffers, `open`/`write`, hand-rolled integer formatting,\n  and `backtrace_symbols_fd` (which does not allocate).\n- Symbol names are intentionally left mangled to avoid `__cxa_demangle` (which\n  allocates and is not async-signal-safe); demangle offline with `c++filt`.\n- Add `prepare_stack_trace()`, called once when handlers are installed, to force\n  the lazy dynamic-linker resolution behind `backtrace()` out of the handler.\n- Drop the `KF_LOG_*` (spdlog) calls on the fatal signal branches so logging can\n  no longer allocate or block before the dump is written.\n- The POSIX `print_stack_trace` signature gains an optional `int signum`\n  (defaulted), source-compatible with all existing callers.\n\nBehavior note: `print_stack_trace()` is also used by non-signal catch blocks\n(`rx.h` and the node bindings). Those now also emit mangled names and use a\n`hs_err_pid<pid>_<epoch>.log` filename. Reliability improves; symbol\ndemangling moves offline to `c++filt`.\n\nWindows is intentionally out of scope for this PR; the SEH / dbghelp path is\ntracked separately.\n\n## Verification\n\n- The rewritten POSIX routine compiles cleanly under\n  `clang++ -std=c++17 -Wall -Wextra` with no warnings.\n- A standalone harness reproducing the primitives produces a complete stack\n  trace for a plain SIGSEGV, an `abort()`, and — critically — a SIGSEGV raised\n  after deliberate heap corruption. A control that mimics the previous\n  malloc/stdio approach writes no report at all under the same heap corruption.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (behavior note above)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T05:30:15Z",
          "mergedAt": "2026-07-03T06:34:54Z",
          "additions": 128,
          "deletions": 132,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 321,
          "url": "https://github.com/kungfu-systems/buildchain/pull/321",
          "title": "fix(infra): verify evidence bundle validation summary",
          "body": "## Summary\n- Recompute infra-contract evidence bundle validation summary booleans during verification\n- Fail closed when validation summary fields are stale or misleading, even if bundleHash was refreshed\n- Document the stronger verifier contract and refresh the site CLI registry\n\n## Verification\n- node --check scripts/infra-contract-core.mjs scripts/infra-contract.mjs scripts/generate-site-bundle.mjs bin/buildchain.mjs\n- node --test tests/infra-contract.test.mjs tests/cli.test.mjs tests/buildchain-config.test.mjs\n- corepack pnpm run generate:site && corepack pnpm run check:site\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T06:33:29Z",
          "mergedAt": "2026-07-03T06:34:58Z",
          "additions": 125,
          "deletions": 6,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 172,
          "url": "https://github.com/kungfu-systems/kungfu/pull/172",
          "title": "feat(gui): the work dashboard becomes the first screen",
          "body": "Merge feature/default-profile-work-dashboard into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T06:35:51Z",
          "mergedAt": "2026-07-03T06:43:11Z",
          "additions": 2802,
          "deletions": 13,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 322,
          "url": "https://github.com/kungfu-systems/buildchain/pull/322",
          "title": "feat(infra): add mutation-free ci evidence mode",
          "body": "## Summary\n- Add `buildchain infra-contract --mode ci` as a single mutation-free evidence-chain entrypoint\n- Make `init --type infra-contract` wire lifecycle.verify to the CI mode and upload specific infra-contract JSON artifacts\n- Document the standard CI evidence chain and refresh the site CLI registry\n\n## Verification\n- node --check scripts/infra-contract.mjs scripts/infra-contract-core.mjs scripts/init-repo.mjs scripts/generate-site-bundle.mjs bin/buildchain.mjs\n- node --test tests/infra-contract.test.mjs tests/cli.test.mjs tests/buildchain-config.test.mjs\n- corepack pnpm run generate:site && corepack pnpm run check:site\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T06:45:38Z",
          "mergedAt": "2026-07-03T06:48:35Z",
          "additions": 189,
          "deletions": 10,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 323,
          "url": "https://github.com/kungfu-systems/buildchain/pull/323",
          "title": "docs(release): record infra contract v2.4 surface",
          "body": "## Summary\n- Record infra-contract lifecycle as the Buildchain v2.4 minor surface in docs/versioning.md\n- Align the release decision log with the already-merged infra-contract CLI, project type, evidence, propagation, and CI mode surfaces\n\n## Verification\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T06:56:45Z",
          "mergedAt": "2026-07-03T06:58:22Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 324,
          "url": "https://github.com/kungfu-systems/buildchain/pull/324",
          "title": "Release passport evidence for v2.3.1",
          "body": "## Summary\n- add the unified release passport evidence chain\n- generate and persist buildchain-release-passport from publish transactions\n- preserve caller-provided passport product.name instead of hardcoding Buildchain\n\n## Validation\n- node --test tests/release-passport.test.mjs tests/cli.test.mjs tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:00:10Z",
          "mergedAt": "2026-07-03T07:02:28Z",
          "additions": 1693,
          "deletions": 98,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 325,
          "url": "https://github.com/kungfu-systems/buildchain/pull/325",
          "title": "Release passport evidence for v2.4",
          "body": "## Summary\n- add the unified release passport evidence chain on the v2.4 line\n- generate and persist buildchain-release-passport from publish transactions\n- preserve caller-provided passport product.name instead of hardcoding Buildchain\n\n## Validation\n- node --test tests/release-passport.test.mjs tests/cli.test.mjs tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:00:36Z",
          "mergedAt": "2026-07-03T07:02:33Z",
          "additions": 1693,
          "deletions": 98,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 326,
          "url": "https://github.com/kungfu-systems/buildchain/pull/326",
          "title": "Promote v2.3 passport changes to alpha",
          "body": "## Summary\n- promote the v2.3 release passport and publish transaction passport changes to alpha\n- includes product.name propagation fix for release passports\n\n## Source\n- dev/v2/v2.3 @ a8d0c6282797d56a52e4aebb7afc870fdd5f42bb\n\n## Validation\n- branch PR checks will run Verify and Build Surface Fixture",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:03:05Z",
          "mergedAt": "2026-07-03T07:04:49Z",
          "additions": 7044,
          "deletions": 229,
          "changedFiles": 55
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 327,
          "url": "https://github.com/kungfu-systems/buildchain/pull/327",
          "title": "test(infra): cover remaining infra contract adapters",
          "body": "## Summary\n- add static infra-contract fixtures for OpenTofu, AWS CDK, and AWS CLI shapes\n- extend provider fixture coverage to assert built-in command plans and observe evidence\n- update infra-contract docs so the safe fixture set matches supported built-in adapters\n\n## Validation\n- node --test tests/infra-contract.test.mjs tests/buildchain-config.test.mjs tests/cli.test.mjs\n- pnpm run check\n\nTrain note: this PR targets dev/v2/v2.4; train/v2/v2.4/infra-contract remains a validation pointer and should be resynced after merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:14:12Z",
          "mergedAt": "2026-07-03T07:16:04Z",
          "additions": 211,
          "deletions": 4,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 328,
          "url": "https://github.com/kungfu-systems/buildchain/pull/328",
          "title": "fix(release): retry transient GitHub commit reads",
          "body": "## Summary\n- retry transient GitHub Git Data API getCommit failures in promotion\n- cover runner-style 500 other side closed reads in promote action tests\n- rebuild the committed promote action bundle\n\n## Verification\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:15:37Z",
          "mergedAt": "2026-07-03T07:17:46Z",
          "additions": 111,
          "deletions": 86,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 329,
          "url": "https://github.com/kungfu-systems/buildchain/pull/329",
          "title": "fix(release): retry transient GitHub commit reads",
          "body": "## Summary\n- retry transient GitHub Git Data API getCommit failures in promotion\n- carry the v2.3 release retry fix into the v2.4 development line\n- rebuild the committed promote action bundle\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs tests/release-passport.test.mjs tests/cli.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:19:24Z",
          "mergedAt": "2026-07-03T07:21:07Z",
          "additions": 109,
          "deletions": 84,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 330,
          "url": "https://github.com/kungfu-systems/buildchain/pull/330",
          "title": "release(v2.3): promote retry-capable 2.3 alpha",
          "body": "## Summary\n- promote the v2.3 release passport changes plus the promotion getCommit retry fix to alpha\n- re-run the protected alpha promotion after the previous runner-side GitHub API 500 failure\n\n## Verification\n- dev/v2/v2.3 PR checks passed in #324 and #328\n- promotion will run from the protected Verify workflow path after merge",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:21:33Z",
          "mergedAt": "2026-07-03T07:23:17Z",
          "additions": 111,
          "deletions": 86,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 173,
          "url": "https://github.com/kungfu-systems/kungfu/pull/173",
          "title": "test(atlas): import fixture proves the read-only projection end to end",
          "body": "Merge feature/atlas-import-projection into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:25:20Z",
          "mergedAt": "2026-07-03T07:25:25Z",
          "additions": 1917,
          "deletions": 3,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 331,
          "url": "https://github.com/kungfu-systems/buildchain/pull/331",
          "title": "Prepare v2.3.1-alpha.1",
          "body": "Create the generated version-state commit for v2.3.1-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:25:17Z",
          "mergedAt": "2026-07-03T07:27:00Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 174,
          "url": "https://github.com/kungfu-systems/kungfu/pull/174",
          "title": "fix(yijinjing): harden Windows crash dump against handler deadlock",
          "body": "## Summary\n\nHarden the Windows crash-dump path so it can no longer deadlock or double-fault\ninside the crash handler. This is the Windows follow-up to the POSIX\nasync-signal-safe rewrite (#171) and the stackwalker rewrite (#168), whose scope\nnote explicitly deferred crash-handler safety.\n\n`print_stack_trace` is reached from `hero.cpp`'s SEH `__except` filter, the CRT\nsignal handler, and ~30 non-fatal `catch` blocks in the node bindings / `rx.h`.\nIt previously used `KF_LOG_CRITICAL` (spdlog), `std::ofstream`, `std::localtime`\nand heap `std::string` building. The faulting thread may already hold the spdlog\nor CRT lock, so the dump could hang or re-fault — precisely in the\nheap-corruption access-violation case where the stack is most needed.\n\n## Changes\n\n- `stacktrace.cpp` (Windows): rewrite the dump to avoid the lock-taking calls —\n  preallocated path buffer, `GetLocalTime` + hand-rolled integer formatting,\n  `CreateFileA`/`WriteFile` through a small `std::streambuf` instead of\n  `std::ofstream`, and a statically-allocated SEH exception-code description.\n  Add a Windows `prepare_stack_trace()` that warms up DbgHelp once at\n  handler-install time so the crash path only does symbol lookups.\n- `signal.cpp`: drop `KF_LOG_CRITICAL` from the fatal signal branch and install\n  `SetUnhandledExceptionFilter` as a process-wide backstop for crashes raised\n  outside `hero::produce`'s SEH frame (real `EXCEPTION_POINTERS`, unlike the\n  contextless CRT signal path).\n- `StackWalker.cpp`: remove the per-frame `std::ostringstream` and the\n  `KF_LOG_CRITICAL` echo from the native-stack loop; emit the native stack first\n  in the report so a heap-corruption-truncated dump still contains it.\n\nReport format changes; module + symbol + line are preserved. DbgHelp's own heap\nuse and `std::ostream` locale facets remain (documented residual); out-of-process\n/ minidump capture is future work.\n\n## Validation\n\nStandalone MSVC harness (VS 2026 / MSVC 19.51) compiling the real\n`stacktrace.cpp` + `StackWalker.cpp`, mirroring the handler install, triggering\neach scenario in its own process (20s watchdog):\n\n| scenario | via SEUF | via SEH `__except` |\n| --- | --- | --- |\n| access violation | full symbolized stack (module+symbol+line) | full symbolized stack |\n| heap corruption then AV | no hang; stack captured (module+offset), degrades under corruption | no hang; degrades under corruption |\n| stack overflow | no hang; system info captured, native frames limited by exhaustion | no hang |\n| non-fatal `catch` path | full symbolized stack, returns normally | — |\n\nNo scenario hung or double-faulted (the previous spdlog path would deadlock on\nthe held lock under heap corruption). Stack overflow defeating the native walk\nis a known limitation, documented in the code.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:29:16Z",
          "mergedAt": "2026-07-03T07:30:46Z",
          "additions": 240,
          "deletions": 92,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 332,
          "url": "https://github.com/kungfu-systems/buildchain/pull/332",
          "title": "release(v2.3): publish 2.3.1",
          "body": "## Summary\n- promote v2.3.1-alpha.1 from alpha to stable release\n- publish the unified release passport / publish transaction passport release material\n- include the promotion getCommit retry fix used to complete alpha finalization\n\n## Verification\n- alpha promotion completed successfully at e9ab3a5\n- v2.3.1-alpha.1 and v2.3-alpha point at e9ab3a5\n- protected release promotion will run after this PR merges",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:29:46Z",
          "mergedAt": "2026-07-03T07:31:28Z",
          "additions": 7103,
          "deletions": 263,
          "changedFiles": 55
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 333,
          "url": "https://github.com/kungfu-systems/buildchain/pull/333",
          "title": "Release v2.3.1",
          "body": "Create the generated version-state commit for v2.3.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:33:37Z",
          "mergedAt": "2026-07-03T07:35:14Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 334,
          "url": "https://github.com/kungfu-systems/buildchain/pull/334",
          "title": "Prepare v2.3.2-alpha.0",
          "body": "Create the generated version-state commit for v2.3.2-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:37:23Z",
          "mergedAt": "2026-07-03T07:39:32Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 335,
          "url": "https://github.com/kungfu-systems/buildchain/pull/335",
          "title": "fix(infra): require apply identity gates",
          "body": "## Summary\n- require target environment and provider-neutral identity_ref for non-disabled infra-contract apply\n- bind identity_ref into plan, artifact, and apply evidence\n- document managed apply target/identity gates and cover missing environment/identity before mutation\n\n## Verification\n- node --test tests/infra-contract.test.mjs tests/buildchain-config.test.mjs tests/cli.test.mjs\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:37:36Z",
          "mergedAt": "2026-07-03T07:39:34Z",
          "additions": 204,
          "deletions": 34,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 336,
          "url": "https://github.com/kungfu-systems/buildchain/pull/336",
          "title": "fix(release): preserve finalization passport evidence",
          "body": "## Summary\n- carry persisted publish transaction evidence and publish contract through version-state finalization\n- generate release passports from the transaction source SHA instead of the finalization merge SHA\n- extend promotion tests to assert persisted passport and check-report remain trusted\n\n## Validation\n- pnpm --filter \"./actions/promote-buildchain-ref\" build\n- node --test tests/promote-buildchain-ref.test.mjs tests/release-passport.test.mjs tests/cli.test.mjs\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:55:04Z",
          "mergedAt": "2026-07-03T07:56:36Z",
          "additions": 157,
          "deletions": 47,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 175,
          "url": "https://github.com/kungfu-systems/kungfu/pull/175",
          "title": "feat(rewind): capture an unmodified LangChain agent via the adapter table",
          "body": "Add a LangChain adapter to the in-process capture hook's adapter table: patch BaseTool.run once langchain_core.tools imports, so a real create_agent (langgraph) run's tool calls land in the journal with zero code change. Model turns are already captured at the wire proxy. A new rewind-demo-langchain fixture runs a genuine langchain agent against a deterministic mock model and asserts the full fact set in one journal (both model turns, the tool call from the real seam, causal bracketing); verify's double-path decode holds on the real run and verify --full picks the fixture up automatically.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:56:59Z",
          "mergedAt": "2026-07-03T07:57:05Z",
          "additions": 470,
          "deletions": 3,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 337,
          "url": "https://github.com/kungfu-systems/buildchain/pull/337",
          "title": "fix(release): preserve finalization passport evidence",
          "body": "## Summary\n- port the finalization passport evidence fix from v2.3 to v2.4\n- carry persisted publish transaction evidence and publish contract through version-state finalization\n- keep release passport source SHA and trusted publishing checks tied to the original publish transaction\n\n## Validation\n- pnpm --filter \"./actions/promote-buildchain-ref\" build\n- node --test tests/promote-buildchain-ref.test.mjs tests/release-passport.test.mjs\n- pnpm run check\n- git diff --check\n\nCherry-picked-from: 56db41a",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:58:23Z",
          "mergedAt": "2026-07-03T08:00:48Z",
          "additions": 157,
          "deletions": 47,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 338,
          "url": "https://github.com/kungfu-systems/buildchain/pull/338",
          "title": "chore(release): promote 2.4 alpha",
          "body": "Promote the Buildchain 2.4 development line into the alpha channel.\\n\\nThis starts the governed 2.4 release flow after the infra-contract lifecycle work landed on dev/v2/v2.4.\\n\\nExpected follow-up: Buildchain Ref Promotion publishes the 2.4 alpha version state and npm evidence before production release promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:59:46Z",
          "mergedAt": "2026-07-03T08:01:57Z",
          "additions": 5896,
          "deletions": 218,
          "changedFiles": 61
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 339,
          "url": "https://github.com/kungfu-systems/buildchain/pull/339",
          "title": "Prepare v2.4.0-alpha.0",
          "body": "Create the generated version-state commit for v2.4.0-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:07:04Z",
          "mergedAt": "2026-07-03T08:08:17Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 340,
          "url": "https://github.com/kungfu-systems/buildchain/pull/340",
          "title": "fix(release): ignore invalid optional build summaries",
          "body": "## Summary\n- ignore missing or invalid optional build summary inputs when collecting release passports\n- keep release passport validation strict for explicitly accepted JSON inputs\n- add regression coverage for path-like non-JSON build-summary artifacts\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:15:38Z",
          "mergedAt": "2026-07-03T08:16:45Z",
          "additions": 58,
          "deletions": 44,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 341,
          "url": "https://github.com/kungfu-systems/buildchain/pull/341",
          "title": "chore(release): promote 2.4 alpha",
          "body": "Promote dev/v2/v2.4 to alpha/v2/v2.4 after the release-passport optional build-summary fix.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:17:14Z",
          "mergedAt": "2026-07-03T08:18:48Z",
          "additions": 58,
          "deletions": 44,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 342,
          "url": "https://github.com/kungfu-systems/buildchain/pull/342",
          "title": "Prepare v2.4.0-alpha.1",
          "body": "Create the generated version-state commit for v2.4.0-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:20:51Z",
          "mergedAt": "2026-07-03T08:22:22Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 343,
          "url": "https://github.com/kungfu-systems/buildchain/pull/343",
          "title": "fix(release): ignore missing optional dist-tag evidence",
          "body": "## Summary\n- guard optional dist-tag evidence paths before release passport collection\n- keep missing stale evidence paths from being parsed as JSON strings\n- update finalization regression coverage for missing optional dist-tag evidence\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:26:47Z",
          "mergedAt": "2026-07-03T08:28:11Z",
          "additions": 42,
          "deletions": 62,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 344,
          "url": "https://github.com/kungfu-systems/buildchain/pull/344",
          "title": "chore(release): promote 2.4 alpha",
          "body": "Promote dev/v2/v2.4 to alpha/v2/v2.4 after the optional dist-tag evidence passport fix.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:28:46Z",
          "mergedAt": "2026-07-03T08:30:16Z",
          "additions": 42,
          "deletions": 62,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 345,
          "url": "https://github.com/kungfu-systems/buildchain/pull/345",
          "title": "Prepare v2.4.0-alpha.2",
          "body": "Create the generated version-state commit for v2.4.0-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:32:18Z",
          "mergedAt": "2026-07-03T08:33:37Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 346,
          "url": "https://github.com/kungfu-systems/buildchain/pull/346",
          "title": "chore(release): release 2.4",
          "body": "Promote alpha/v2/v2.4 to release/v2/v2.4 for Buildchain 2.4 production release. Alpha v2.4.0-alpha.2 is finalized with release passport evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:36:29Z",
          "mergedAt": "2026-07-03T08:37:59Z",
          "additions": 5891,
          "deletions": 219,
          "changedFiles": 61
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 347,
          "url": "https://github.com/kungfu-systems/buildchain/pull/347",
          "title": "Release v2.4.0",
          "body": "Create the generated version-state commit for v2.4.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:40:06Z",
          "mergedAt": "2026-07-03T08:41:28Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 348,
          "url": "https://github.com/kungfu-systems/buildchain/pull/348",
          "title": "Prepare v2.4.1-alpha.0",
          "body": "Create the generated version-state commit for v2.4.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:43:49Z",
          "mergedAt": "2026-07-03T08:44:48Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 176,
          "url": "https://github.com/kungfu-systems/kungfu/pull/176",
          "title": "refactor(gui): built-in kfx migrate to the v2 contract",
          "body": "Merge feature/shell-foundation into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:48:13Z",
          "mergedAt": "2026-07-03T08:48:17Z",
          "additions": 812,
          "deletions": 168,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 349,
          "url": "https://github.com/kungfu-systems/buildchain/pull/349",
          "title": "feat(release): enrich release passports",
          "body": "## Summary\n- add release-passport-product-name to promote-buildchain-ref\n- backfill the durable release-state SHA into buildchain.release.json after the first passport upload and persist the updated passport\n- document the consumer passport audit entrypoint and cover product-name/SHA backfill in tests\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs tests/release-passport.test.mjs\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T09:33:37Z",
          "mergedAt": "2026-07-03T09:35:20Z",
          "additions": 114,
          "deletions": 66,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 350,
          "url": "https://github.com/kungfu-systems/buildchain/pull/350",
          "title": "Promote v2.4 dev to alpha",
          "body": "Promote dev/v2/v2.4 to alpha/v2/v2.4 for release passport product-name and durable state SHA backfill validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T09:35:44Z",
          "mergedAt": "2026-07-03T09:37:38Z",
          "additions": 114,
          "deletions": 66,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 351,
          "url": "https://github.com/kungfu-systems/buildchain/pull/351",
          "title": "Prepare v2.4.1-alpha.1",
          "body": "Create the generated version-state commit for v2.4.1-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T09:39:38Z",
          "mergedAt": "2026-07-03T09:41:19Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 352,
          "url": "https://github.com/kungfu-systems/buildchain/pull/352",
          "title": "Promote v2.4 alpha to release",
          "body": "Promote alpha/v2/v2.4 to release/v2/v2.4 for stable 2.4.1 after validating release passport product-name and durable state SHA backfill.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T09:43:48Z",
          "mergedAt": "2026-07-03T09:45:32Z",
          "additions": 115,
          "deletions": 67,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 353,
          "url": "https://github.com/kungfu-systems/buildchain/pull/353",
          "title": "Release v2.4.1",
          "body": "Create the generated version-state commit for v2.4.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T09:47:21Z",
          "mergedAt": "2026-07-03T09:49:06Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 354,
          "url": "https://github.com/kungfu-systems/buildchain/pull/354",
          "title": "Prepare v2.4.2-alpha.0",
          "body": "Create the generated version-state commit for v2.4.2-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T09:51:22Z",
          "mergedAt": "2026-07-03T09:53:00Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 177,
          "url": "https://github.com/kungfu-systems/kungfu/pull/177",
          "title": "feat(core): native FlatBuffers schema compilation and the kfx open layer",
          "body": "Let a kfx author define a FlatBuffers event schema and insert it into a run dynamically — the point of the hana->FB migration. libkungfu compiles a .fbs to a .bfbs in-process via the FlatBuffers library it already links (Parser::Parse + Serialize), with no flatc binary and no subprocess; compilation is tiered by trust (sandboxed third-party schemas get hard bounds). Exposed as pykungfu.yijinjing.compile_schema and a 'kungfu schema compile' CLI verb. A compiled schema is content-addressed and bound to a msg_type in the run manifest (third-party kfx band 40000-49999), and events of that type decode by reflection over the .bfbs in every runtime: the Python BundleDecoder (extended to the full scalar set plus float/double/vectors) and a new TS ReflectionDecoder capability for the Electron inspector. A rewind-demo-kfx-schema fixture runs the whole loop under 'kungfu trace' and is auto-gated by verify --full; the same in-run event decodes identically through C++/Python and TS.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T09:59:29Z",
          "mergedAt": "2026-07-03T09:59:34Z",
          "additions": 2141,
          "deletions": 14,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 178,
          "url": "https://github.com/kungfu-systems/kungfu/pull/178",
          "title": "test(kfx): distribution fixture proves the tgz lifecycle",
          "body": "Merge feature/kfx-distribution into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T10:00:51Z",
          "mergedAt": "2026-07-03T10:00:57Z",
          "additions": 1733,
          "deletions": 459,
          "changedFiles": 36
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 179,
          "url": "https://github.com/kungfu-systems/kungfu/pull/179",
          "title": "Extension devkit: scaffold, docs and fixture for view kfx",
          "body": "## What\n\nCloses the developer-facing gap in the kfx distribution chain: a newcomer can go from an empty directory to an installed view extension without reading platform sources.\n\n- `kfs create extension <dir>` scaffolds a view kfx (same token mechanism as `create app`): manifest with `kungfuConfig.config.view`, a minimal `View` component on the contract tokens, build/clean scripts, README. `--workspace` wires `workspace:*` deps.\n- `docs/extensions.md` fills the MAP's `to write` slot: facet/package/suite vocabulary, scaffold-to-install quickstart, `kungfuConfig` field reference tied to `framework/kfx` types, the build externals contract, discovery roots, install lifecycle, and the honest status of runtime facets (mid-migration, per `known-limits.md`). MAP row goes `stable`.\n- `tests/fixtures/kfx-demo-scaffold/` proves the chain end to end: scaffold → build → load-contract assertion (named `View` export, only shell-provided modules required) → `npm pack` → `kungfu kfx install`/`list`/`remove` in a clean home. Picked up automatically by `verify --full` via the `kfx-demo-` prefix.\n\n## Validation\n\n- Scaffold → build → contract assertion → pack ran green offline from a clean directory; the tgz contains exactly `dist/`, `package.json`, `README.md`.\n- `create app` regression-smoked (workspace token, non-empty-dir refusal); `node --check` and biome on `kfs.js` (the one formatter finding predates this change).\n- The fixture's install stage requires a built `dist/kfc` (same precondition as `kfx-demo-install`); first full run lands with the next `verify --full` on a built tree.\n\n## Not in scope\n\nLoader/CLI/contract semantics are only consumed, never changed; the runtime facet build chain stays as documented status.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T10:35:48Z",
          "mergedAt": "2026-07-03T10:36:02Z",
          "additions": 367,
          "deletions": 10,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 9,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/9",
          "title": "ci(site): run web surface on Buildchain 2.4",
          "body": "## Summary\n- run the web surface workflow on Buildchain v2.4\n- consume checked infra output evidence without applying cloud changes by default\n- keep preview, cleanup, staging, and production apply switches disabled\n\n## Validation\n- bash -n scripts/check-site.sh\n- node --check scripts/check-infra-outputs.mjs\n- bash scripts/build-site.sh && bash scripts/check-site.sh\n- git diff --check\n- shellcheck scripts/check-site.sh\n\n## Safety\n- No live cloud apply is enabled by this PR.\n- Preview, cleanup, staging, and production apply switches remain false by default.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T10:14:58Z",
          "mergedAt": "2026-07-03T10:38:11Z",
          "additions": 30,
          "deletions": 9,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 6,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/6",
          "title": "feat(site): consume Buildchain 2.4 bundle",
          "body": "## Summary\n- pin the site runtime to the Buildchain v2.4 package\n- consume checked infra output evidence without applying cloud changes by default\n- keep preview, cleanup, staging, and production apply switches disabled\n\n## Validation\n- npm ci --ignore-scripts --registry=https://registry.npmjs.org/\n- npm run build\n- npm run check\n- bash -n scripts/check-site.sh\n- node --check scripts/check-infra-outputs.mjs\n- node --check scripts/render-site.mjs\n- git diff --check\n- shellcheck scripts/check-site.sh\n\n## Safety\n- No live cloud apply is enabled by this PR.\n- Preview, cleanup, staging, and production apply switches remain false by default.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T10:14:58Z",
          "mergedAt": "2026-07-03T10:38:15Z",
          "additions": 47,
          "deletions": 32,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 180,
          "url": "https://github.com/kungfu-systems/kungfu/pull/180",
          "title": "feat(rewind): framework adapters become a kfx runtime facet",
          "body": "Make framework capture adapters a kfx extension form (config.adapter) instead of kernel code — the first v4 runtime facet. The trace supervisor scans the same extension roots the GUI shell does, finds packages declaring a python or node adapter, and injects the adapter source into the traced child, where the dependency-free capture hook loads it and it registers its patcher (register_adapter in python; globalThis.__kungfuRewind in node). Discovery lives in the supervisor so the hooks stay dependency-free. LangChain support moves out of core into extensions/langchain-adapter; the kernel's built-in table keeps only the demo toolkit probe. @kungfu-tech/kfx gains the KfxAdapterDecl contract type, kfs kfx build tolerates an adapter-only package (an adapter ships source, nothing to bundle), and docs/extensions.md plus shell-and-kfx.md grow the adapter facet and its per-runtime registration recipe. Verified: external python and node adapters found on the extension root capture a toy framework under kungfu trace; the langchain fixture captures an unmodified real agent from the package with no adapter code in core; cross-runtime and happy fixtures still pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T11:26:29Z",
          "mergedAt": "2026-07-03T11:26:34Z",
          "additions": 342,
          "deletions": 57,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 181,
          "url": "https://github.com/kungfu-systems/kungfu/pull/181",
          "title": "fix(yijinjing): write a minidump alongside the Windows crash report",
          "body": "## What\n\nOn a fatal native crash, write a `MiniDumpNormal` `.dmp` next to the existing\ntext `hs_err_*.log`, sharing the same `pid_timestamp` stem. Builds on #174\n(crash-handler deadlock hardening).\n\n## Why\n\nThe text report resolves symbols in-process via DbgHelp, which allocates on the\ncrashing heap. Under heap corruption -- the case most worth diagnosing -- that\ntruncates or degrades to `module+offset`. A minidump snapshots memory and the\nmodule list and defers symbolization to offline analysis with the matching PDB,\nso it usually survives heap-corruption crashes that truncate the text stack.\n\n## Behavior\n\n- The dump is written only on real faults carrying an exception context (the SEH\n  `__except` in `hero::produce` and the `SetUnhandledExceptionFilter` backstop).\n  The non-fatal `print_stack_trace()` diagnostic path (node/rx catch blocks)\n  stays text-only.\n- Ordering (settled by on-hardware validation): exception line first, then the\n  minidump, then the fragile DbgHelp stack walk -- so the fault is recorded even\n  if a later step faults, and the robust dump runs before the risky symbol walk.\n- Stack overflow: the dump is skipped (too little stack is left to run\n  `MiniDumpWriteDump`; it would only fault). The text report still records the\n  exception.\n- The dump is written to a `.part` sibling and renamed on success, so a `.dmp`\n  file always means a complete minidump.\n- `MiniDumpNormal` (thread stacks + module list + handles, no full working set)\n  keeps the footprint and privacy surface small.\n\n## Limitations (accepted)\n\nStill in-process: extreme heap corruption or a stack overflow can defeat the dump\ntoo. Out-of-process capture would remove that but adds a permanent\nresident-process + IPC maintenance surface, which is not justified here; it was\nevaluated and declined. Residual tiers are documented in\n`framework/core/docs/windows-crash-symbols.md`.\n\n## Validation\n\nStandalone MSVC harness compiling the real `stacktrace.cpp` + `StackWalker.cpp`,\none process per scenario with a 20s watchdog, across AV / heap-corruption AV /\nstack overflow / non-fatal catch, on both the SEUF and SEH paths:\n\n- No deadlock or double-fault in any scenario (the process always exits).\n- Common AVs: full symbolized log + valid ~48KB minidump every run.\n- Recoverable heap corruption: full log + valid minidump; total corruption: a\n  text stub with the exception line, no dump, no stray file.\n- Stack overflow: dump skipped, text-only. Non-fatal catch: text-only.\n- No 0-byte `.dmp` and no `.part` leftovers.\n\nNo public header or ABI change (`print_stack_trace` signature is unchanged; the\nhelper is file-local). `dbghelp.lib` was already linked, so there is no build\nchange.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T11:29:54Z",
          "mergedAt": "2026-07-03T11:31:05Z",
          "additions": 159,
          "deletions": 7,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 35,
          "url": "https://github.com/kungfu-systems/libnode/pull/35",
          "title": "ci: adopt buildchain 2.4.1 diagnostics",
          "body": "## Summary\n- switch libnode workflows to the published buildchain 2.4.1 refs\n- declare native diagnostics/cache directories in buildchain.toml\n- split libnode make/build/package lifecycle so buildchain observes the real native build\n- fail fast when libnode build outputs are missing\n\n## Validation\n- Build workflow 28655688895 succeeded on Linux x64, macOS ARM64, and Windows x64\n- npm 22.22.3-kf.3-alpha.4 is intentionally not published from this PR\n\n## Notes\nThis PR prepares the release/passport path without pushing publish-gate. Actual npm publishing remains gated by publish-gate.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T11:16:16Z",
          "mergedAt": "2026-07-03T11:39:14Z",
          "additions": 67,
          "deletions": 14,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 7,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/7",
          "title": "chore(site): refresh Buildchain site bundle to 2.4.1",
          "body": "## Summary\n- bump the pinned @kungfu-tech/buildchain package from 2.4.0 to 2.4.1\n- refresh generated source metadata and local assertions for the Buildchain site bundle\n- update repository docs that name the pinned Buildchain artifact\n\n## Validation\n- npm view @kungfu-tech/buildchain@2.4.1 version dist.integrity dist.tarball --registry=https://registry.npmjs.org/\n- npm ci --ignore-scripts --registry=https://registry.npmjs.org/ && npm run build && npm run check\n- git diff --check\n- bash -n scripts/build-site.sh scripts/check-site.sh\n- node --check scripts/render-site.mjs\n- node --check scripts/check-infra-outputs.mjs\n- shellcheck scripts/build-site.sh scripts/check-site.sh\n\n## Safety\n- Live apply remains disabled by default.\n- No AWS, DNS, CloudFront, WAF, IAM, GitHub environment, or deployment mutation was run.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T13:32:37Z",
          "mergedAt": "2026-07-03T13:33:22Z",
          "additions": 23,
          "deletions": 21,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 182,
          "url": "https://github.com/kungfu-systems/kungfu/pull/182",
          "title": "chore(extensions): retire trading-specific reference extensions",
          "body": "## What\n\nRetire four trading-specific reference extensions inherited from the\nframework's quantitative-trading origins:\n\n- `extensions/sim` — simulated broker (Python)\n- `extensions/xtp` — XTP broker gateway demo (C++)\n- `extensions/bar` — bar/candle operator (C++)\n- `extensions/matcher-101` — order matcher (C++)\n\nAlso drops the four packages from the `artifact` dogfood assembly and refreshes\nthe lockfile (30 → 26 workspace projects).\n\n## Why\n\nThese are leftovers from the trading-execution era, not part of the v4\njournal-first platform surface. `xtp` in particular is a real broker-counter\nadapter that is not usable outside that context.\n\n## Coverage note\n\nThe reference extensions double as build-time coverage probes. This change is\nmid-transition:\n\n- **Python path** — still covered by the neutral `indexer-live` extension.\n- **C++ path** — its neutral probe is being introduced separately, so the C++\n  extension path is temporarily without a dedicated build-time probe. This is\n  documented in `docs/architecture.md` rather than left silent.\n\n## Validation\n\nPure removal + lockfile refresh; `pnpm install --frozen-lockfile` is consistent\nand no workspace package references the removed extensions. Relying on the\n`buildchain-validate` CI gate for the full build/assembly check.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T13:54:10Z",
          "mergedAt": "2026-07-03T13:55:05Z",
          "additions": 6,
          "deletions": 4598,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 10,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/10",
          "title": "feat(site): enable gated production release workflow",
          "body": "## Summary\\n- add a repository AGENTS.md router\\n- wire the production OIDC role from infra outputs\\n- gate production apply on manual workflow_dispatch approval\\n- document the production Buildchain release command shape\\n\\n## Validation\\n- bash scripts/build-site.sh && bash scripts/check-site.sh\\n- actionlint .github/workflows/buildchain-web-surface.yml\\n- node /Users/dkr/Code/kungfu-systems/buildchain/scripts/web-surface.mjs --mode validate --cwd .\\n- node /Users/dkr/Code/kungfu-systems/buildchain/scripts/web-surface.mjs --mode deploy-plan --cwd . --channel production --source-sha <branch-head> --artifact-path dist\\n\\n## Release note\\nProduction apply remains manual and disabled by default until production_approved=true is supplied.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T14:03:42Z",
          "mergedAt": "2026-07-03T14:05:25Z",
          "additions": 99,
          "deletions": 22,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 8,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/8",
          "title": "feat(site): wire production release contract",
          "body": "## Summary\\n- wire the planned production role reference from infra outputs\\n- keep production apply disabled while production remains pending\\n- document readiness checks for libkungfu.dev production surfaces\\n- add manual Buildchain runtime validation pass-through\\n\\n## Validation\\n- npm ci --ignore-scripts --registry=https://registry.npmjs.org/ && npm run build && npm run check\\n- actionlint .github/workflows/buildchain-web-surface.yml\\n- node /Users/dkr/Code/kungfu-systems/buildchain/scripts/web-surface.mjs --mode validate --cwd .\\n- node /Users/dkr/Code/kungfu-systems/buildchain/scripts/web-surface.mjs --mode deploy-plan --cwd . --channel production --source-sha <branch-head> --artifact-path dist\\n\\n## Release note\\nThis PR does not enable production apply for libkungfu.dev.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T14:03:43Z",
          "mergedAt": "2026-07-03T14:05:31Z",
          "additions": 39,
          "deletions": 10,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 183,
          "url": "https://github.com/kungfu-systems/kungfu/pull/183",
          "title": "feat(kfx): the sandboxed-ipc trust tier — capabilities become a real boundary",
          "body": "Land the sandboxed-ipc kfx trust tier so installing a third-party view stops being blind trust. Today every kfx runs node-integrated in the shared renderer and can reach anything via window.require; a sandboxed view now runs in an isolated renderer (nodeIntegration:false, contextIsolation:true, sandbox:true) with no node, reaching only the capabilities its manifest declared, over IPC to a trusted host that rejects anything undeclared. Proven live in real Electron: window.require/process/Buffer are absent, a declared call round-trips, an undeclared one is rejected. resolveRuntimeTier is the single source of the trust decision (installed third-party is sandboxed, and a manifest may not elevate); createSandboxedView adds a network-denied session partition and a memory cap. A headless verify --full gate (kfx-demo-sandbox-boundary) asserts the enforcement. The adapter facet stays node-integrated (it runs inside the traced program's own process; its schema compilation is bounded separately). docs/extensions.md and shell-and-kfx.md document the tier as landed. The trusted path is unchanged; wiring the shell's loader to route sandboxed views is a tracked follow-up.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T14:06:31Z",
          "mergedAt": "2026-07-03T14:11:32Z",
          "additions": 475,
          "deletions": 11,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 36,
          "url": "https://github.com/kungfu-systems/libnode/pull/36",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.4",
          "body": "## Summary\n- merge dev/v22/v22.22 buildchain 2.4.1 diagnostics changes into alpha/v22/v22.22\n- advance anchored libnode alpha version to 22.22.3-kf.3-alpha.4\n- prepare alpha channel ref so publish-gate source SHA and target alpha ref match buildchain 2.4.1 release passport semantics\n\n## Validation\n- dev PR #35 Build and Buildchain Preflight passed\n- publish-gate run 28662820381 built all three platform artifacts successfully but failed before npm publish because alpha/v22/v22.22 still pointed at the previous alpha SHA\n- this PR updates alpha via branch protection instead of direct protected-branch push",
          "author": "dongkeren",
          "createdAt": "2026-07-03T13:47:37Z",
          "mergedAt": "2026-07-03T14:27:37Z",
          "additions": 67,
          "deletions": 14,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 355,
          "url": "https://github.com/kungfu-systems/buildchain/pull/355",
          "title": "fix(publish): fail fast on stale channel refs",
          "body": "## Summary\n- verify publish-gate source locks against their target channel refs before heavy build matrices\n- expose `buildchain publish-source verify-channel-ref` for reusable and custom publish jobs\n- move adjacent web-surface apply input and binary release upload checks before high-cost work\n\n## Validation\n- `node --test tests/build-surface.test.mjs tests/cli.test.mjs`\n- `bash scripts/check-workflows.sh`\n- `git diff --check`\n- `pnpm run check`\n\n## Safety\n- No publish, GitHub Release upload, cloud deploy, or release promotion was run.\n- The new gate fails before source checkout/build matrices when alpha/release channel refs do not match `publish-source-sha`.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T14:32:46Z",
          "mergedAt": "2026-07-03T14:34:52Z",
          "additions": 402,
          "deletions": 4,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 356,
          "url": "https://github.com/kungfu-systems/buildchain/pull/356",
          "title": "fix(publish): preflight channel PR lineage",
          "body": "## Summary\\n- verify publish source channel PR lineage in the reusable build trust gate before heavy matrices\\n- require alpha source-locks to come from merged same-repository dev-to-alpha PRs and release source-locks from alpha-to-release PRs\\n- document the earlier fail-fast behavior and cover CLI/workflow tests\\n\\n## Verification\\n- corepack pnpm@11.7.0 install --frozen-lockfile\\n- node --test tests/build-surface.test.mjs tests/cli.test.mjs\\n- bash scripts/check-workflows.sh\\n- node scripts/check-inventory.mjs\\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:14:32Z",
          "mergedAt": "2026-07-03T15:18:13Z",
          "additions": 304,
          "deletions": 16,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 357,
          "url": "https://github.com/kungfu-systems/buildchain/pull/357",
          "title": "feat(web-surface): support release PR production publishes",
          "body": "## Summary\n- add Buildchain-owned release PR intent resolution for web-surface production publishes\n- allow opt-in main-push production when the associated merged PR matches the release label and source branch prefix\n- document the release-PR publish contract and update workflow coverage\n\n## Validation\n- pnpm run check\n\n## Release note\nThis is a Buildchain v2.4 web-surface runtime change required before site-kungfu-tech can switch production publishing to release PR merge semantics.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:20:32Z",
          "mergedAt": "2026-07-03T15:22:03Z",
          "additions": 194,
          "deletions": 16,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 358,
          "url": "https://github.com/kungfu-systems/buildchain/pull/358",
          "title": "chore(release): promote v2.4 alpha",
          "body": "Promote dev/v2/v2.4 to alpha/v2/v2.4 so Buildchain can publish the next v2.4 alpha through the governed channel path.\n\nIncludes the reusable build preflight/source-lock lineage validation change from #356.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:21:07Z",
          "mergedAt": "2026-07-03T15:23:40Z",
          "additions": 884,
          "deletions": 20,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 359,
          "url": "https://github.com/kungfu-systems/buildchain/pull/359",
          "title": "chore(actions): sync run-lifecycle dist",
          "body": "Synchronize the generated run-lifecycle action bundle with the source after #357.\n\nThe alpha promotion run failed because version verification rebuilt action dist and detected a dirty actions/run-lifecycle/dist/index.js outside version state. This PR contains only the generated dist sync.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:26:58Z",
          "mergedAt": "2026-07-03T15:28:44Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 360,
          "url": "https://github.com/kungfu-systems/buildchain/pull/360",
          "title": "chore(release): retry v2.4 alpha promotion",
          "body": "Retry the governed dev/v2/v2.4 -> alpha/v2/v2.4 promotion after syncing the run-lifecycle dist bundle in #359.\n\nThe previous alpha promotion PR #358 merged correctly, but the promotion transaction failed because generated action dist drifted during version-state verification.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:29:05Z",
          "mergedAt": "2026-07-03T15:30:44Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 361,
          "url": "https://github.com/kungfu-systems/buildchain/pull/361",
          "title": "Prepare v2.4.2-alpha.1",
          "body": "Create the generated version-state commit for v2.4.2-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:32:47Z",
          "mergedAt": "2026-07-03T15:34:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 184,
          "url": "https://github.com/kungfu-systems/kungfu/pull/184",
          "title": "feat(sdk): build C++ kfx extensions via kfs, add a libkungfu FlatBuffers probe",
          "body": "## What\n\nAdds first-class C++ kfx extension support to the v4 SDK, plus a neutral\nreference probe that reinstates the C++ dogfood coverage lane.\n\nBefore this, `kfs` only built view extensions (esbuild) and adapter facets\n(ship source); a package with C++ sources had no working v4 build path (the old\n`build/kungfu.cmake` and the v2/v3 `*-cpp-101` examples are dead). This wires\nC++ back in cleanly, libkungfu-only.\n\n## Changes\n\n- **`kfs kfx build`** detects a `CMakeLists.txt` at the package root and drives\n  CMake with the core's conan toolchain, pinned to the core's Python, compiling\n  `src/cpp/` into a native pybind11 module under `dist/`.\n- **`extensions/probe-cpp`** — a neutral C++ kfx:\n  - `src/cpp/probe.cpp`: round-trips a value through libkungfu's generated\n    FlatBuffers `Order` table and calls a real libkungfu symbol\n    (`yijinjing::time::now_in_nano`), so it genuinely links libkungfu.\n  - `cmake/kungfu.cmake`: a fresh, libkungfu-only build helper — no libwingchun,\n    no separate `flatc` binary (it consumes libkungfu's generated FB headers),\n    `find_package(pybind11/flatbuffers)` via the conan configs.\n- **`verify`** builds the probe under `--full` (after `rebuild:core`) and\n  asserts the native module exists, so a core capability regression surfaces as\n  a C++ build failure.\n- **`docs/architecture.md`**: the C++ coverage path is now covered by\n  `probe-cpp`; the Python and JS/TS paths are noted as still being reinstated.\n\n## Validation\n\nLocal macOS arm64: `./kungfu-code rebuild:core` then `kfs kfx build` in\n`extensions/probe-cpp` produces `probe_cpp.cpython-313-darwin.so`, `otool -L`\nshows it links `@rpath/libkungfu.dylib`, and loading it under the core Python\nruns `fb_roundtrip(7) == 7` and `now_in_nano() > 0`. Relying on the\n`buildchain-validate` CI gate for the full cross-platform build.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:32:02Z",
          "mergedAt": "2026-07-03T15:35:25Z",
          "additions": 243,
          "deletions": 5,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 362,
          "url": "https://github.com/kungfu-systems/buildchain/pull/362",
          "title": "Promote v2.4 alpha to release",
          "body": "Promote Buildchain v2.4 alpha state to the stable release line after the release-PR publish semantics and run-lifecycle dist sync passed alpha promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:36:59Z",
          "mergedAt": "2026-07-03T15:38:45Z",
          "additions": 886,
          "deletions": 22,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 363,
          "url": "https://github.com/kungfu-systems/buildchain/pull/363",
          "title": "Release v2.4.2",
          "body": "Create the generated version-state commit for v2.4.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:40:44Z",
          "mergedAt": "2026-07-03T15:42:18Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 11,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/11",
          "title": "ci: publish production from Buildchain release PR merges",
          "body": "## Summary\n\n- enable Buildchain v2.4 release-PR production publish semantics for kungfu.tech\n- keep manual production dispatch as an explicit fallback\n- document the release PR shape and update the infra output guard\n\n## Verification\n\n- bash scripts/build-site.sh && bash scripts/check-site.sh\n- actionlint .github/workflows/buildchain-web-surface.yml\n\nMerging this release PR is the production approval event. Buildchain should publish production from the resulting main push only after verifying the same-repository merged PR, the buildchain-release label, and the feature/release- branch prefix.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:45:41Z",
          "mergedAt": "2026-07-03T15:46:52Z",
          "additions": 47,
          "deletions": 23,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 364,
          "url": "https://github.com/kungfu-systems/buildchain/pull/364",
          "title": "Prepare v2.4.3-alpha.0",
          "body": "Create the generated version-state commit for v2.4.3-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:44:21Z",
          "mergedAt": "2026-07-03T15:46:56Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 185,
          "url": "https://github.com/kungfu-systems/kungfu/pull/185",
          "title": "feat(sdk): build Python AOT kfx extensions via kfs, repair the engage bridges",
          "body": "## What\n\nAdds first-class **Python AOT** kfx extension support to the v4 SDK, a neutral\nreference probe that reinstates the Python dogfood coverage lane, and repairs\nthe two `engage` bridges it depends on (both were stale against the currently\nbundled tool versions).\n\nFollows the C++ path added earlier; together they restore two of the three\nextension coverage lanes described in `docs/architecture.md`.\n\n## Changes\n\n- **`kfs kfx build`** detects `kungfuBuild.python` and: installs the extension's\n  declared dependencies via `kungfu engage pdm`, then Nuitka-compiles\n  `src/python/<Pkg>` into a native module via `kungfu engage nuitka --module`\n  under `dist/`.\n- **`extensions/probe-python`** — a neutral Python AOT kfx: declares `pydantic`,\n  imports it plus the `kungfu` runtime binding, and compiles to a native module.\n- **`bridging/nuitka`** — delegate to Nuitka's own entry point\n  (`nuitka.__main__.main`) instead of re-implementing option parsing / plugin\n  loading, which crashed on Nuitka 4.1 (`from nuitka import Options` — gone).\n  The engaged scons / data-composer / binding-LIBPATH injection is preserved.\n- **`bridging/pdm`** — forward the subcommand args explicitly\n  (`Core().main(sys.argv[1:])`) so `engage pdm install` runs instead of printing\n  the bare help screen.\n- **`framework/core` deps** — pin `hishel<1.0`: pdm 2.21 imports\n  `hishel._serializers` (the 0.0.x API); the loose transitive bound otherwise\n  resolved to hishel 1.x which dropped it, breaking `engage pdm`.\n- **`verify`** builds and asserts the python probe module under `--full`.\n- **`docs/architecture.md`** — the Python AOT path is now covered by\n  `probe-python`.\n\n## Validation\n\nLocal macOS arm64: `kfs kfx build` in `extensions/probe-python` runs\n`engage pdm install` (installs pydantic 2.14) and `engage nuitka --module`,\nproducing `ProbePython.cpython-313-darwin.so`; loading the compiled module with\nits installed dependency runs `probe(11) == 11`. Relying on `buildchain-validate`\nCI for the full cross-platform build.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T16:20:53Z",
          "mergedAt": "2026-07-03T16:28:40Z",
          "additions": 351,
          "deletions": 170,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 186,
          "url": "https://github.com/kungfu-systems/kungfu/pull/186",
          "title": "feat(gui): embed sandboxed views in an isolated WebContentsView over a capability relay",
          "body": "Completes the runtime integration the loader tier seam left open. The shell now routes a `sandboxed-ipc` view to an isolated renderer instead of blank-rendering it.\n\n## What\n- **`main/sandbox-manager`** — embeds a sandboxed view as a child `WebContentsView` (node stripped, network denied, its own session), positioned over the shell's content area, and relays its capability invokes. Main reads the view bundle (trusted) and injects it into the isolated harness, so the sandbox never gets `fs`/`require`.\n- **`renderer/sandbox-view-harness`** — the isolated page: builds `caps` from the bridge with the api guest, CommonJS-wraps the injected bundle over the shell's externals contract (one React + the capability surface), and mounts `<View caps shell/>` in a real React root.\n- **`renderer/sandbox-host-service`** + **`sandbox-client`** + **`main.tsx`** — the shell registers a view's trusted capability host, asks main to embed it, and keeps the overlay synced to its content rect.\n- **`sandbox-view`** — the isolation posture (webPreferences, locked-down partition, resource guard) is factored into shared helpers; the guard now reads the pid each sample so an embedded view (no OS process at construction) is covered.\n- **`electron.vite.config`** — builds the sandbox preload and the harness page.\n\n## Why this shape\nThe real capabilities live in the trusted node-integrated renderer (they hold the native binding), so the capability path is three hops:\n\n```\nsandboxed view --IPC--> main (SandboxManager, a pure relay)\n  --IPC--> trusted renderer's capability host (the real caps)\n```\n\nMain is a pure relay: it never sees the real capabilities and never interprets the `{cap,method,args}` payload — the declared-only enforcement stays in the trusted renderer's `createCapabilityHost`, co-located with the caps it guards. This keeps the guest↔host callback/subscription protocol intact end to end.\n\n## Validation\n`tsc` clean · `biome check` clean · `electron-vite build` green (preload + harness page emitted) · a headless Electron harness driving these production modules asserts, all passing: tier routing; isolation (no `require`/`process`); bridge exposes declared keys only; a declared capability round-trips through the relay; an undeclared capability is rejected host-side; a third-party bundle mounts live in the isolated renderer; `setBounds` positions the overlay; an over-limit view is killed by the resource guard.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-03T16:30:30Z",
          "mergedAt": "2026-07-03T16:30:58Z",
          "additions": 874,
          "deletions": 49,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 187,
          "url": "https://github.com/kungfu-systems/kungfu/pull/187",
          "title": "docs(architecture): JS/TS coverage is the existing view extensions",
          "body": "The JS/TS extension coverage lane was never missing — the reference view extensions (rewind-inspector, work-dashboard, config-manager, journal-manager) build with esbuild via `kfs kfx build`. Corrects the wording introduced alongside the python-AOT probe that called it 'still being reinstated'. With the cpp (probe-cpp) and python-AOT (probe-python) probes, all three extension coverage lanes are now accurately documented.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T16:35:30Z",
          "mergedAt": "2026-07-03T16:36:04Z",
          "additions": 4,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 37,
          "url": "https://github.com/kungfu-systems/libnode/pull/37",
          "title": "ci: use buildchain v2 for libnode alpha",
          "body": "## Summary\n- switch libnode workflows/actions from pinned buildchain v2.4.1 to floating stable v2\n- bump the anchored alpha package version to 22.22.3-kf.3-alpha.5\n\n## Validation\n- corepack pnpm verify-release\n- git diff --check\n\nThis prepares the next alpha for the strict buildchain publish-gate flow.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T16:09:51Z",
          "mergedAt": "2026-07-03T16:41:37Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 38,
          "url": "https://github.com/kungfu-systems/libnode/pull/38",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.5",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 for @kungfu-tech/libnode 22.22.3-kf.3-alpha.5.\\n\\nThis channel PR carries the alpha.5 semver bump and switches libnode workflows to the floating stable buildchain @v2 tag so future stable buildchain upgrades do not require routine libnode workflow edits.\\n\\nExpected publish path after merge:\\n- merge this reviewed PR into alpha/v22/v22.22\\n- push publish-gate/alpha/v22/v22.22/22.22.3-kf.3-alpha.5 to the resulting alpha HEAD\\n- let Buildchain trusted publishing publish the root and platform npm packages\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T16:42:01Z",
          "mergedAt": "2026-07-03T17:18:19Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 39,
          "url": "https://github.com/kungfu-systems/libnode/pull/39",
          "title": "build: preserve libnode package aliases",
          "body": "## Summary\\n- package Unix libnode aliases as hardlinks so npm tarballs keep libnode.dylib/libnode.so without duplicating the binary\\n- require platform tarballs to contain the alias entry during Buildchain publish evidence preparation\\n- bump alpha package version to 22.22.3-kf.3-alpha.6\\n\\n## Verification\\n- corepack pnpm verify-release\\n- corepack pnpm verify-package-source\\n- node --check .gyp/node-platform-package.js && node --check .gyp/npm-publish-tarballs.js\\n- git diff --check\\n- local fake package-set validation through .gyp/npm-publish-tarballs.js",
          "author": "dongkeren",
          "createdAt": "2026-07-03T18:03:33Z",
          "mergedAt": "2026-07-03T18:24:58Z",
          "additions": 19,
          "deletions": 7,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 40,
          "url": "https://github.com/kungfu-systems/libnode/pull/40",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.6",
          "body": "## Summary\\n- promote libnode alpha.6 from dev to alpha\\n- includes hardlink alias packaging fix for darwin/linux platform tarballs\\n\\n## Verification\\n- PR #39 Build passed on Linux x64, macOS ARM64, Windows x64\\n- release path will run Buildchain strict channel verification before publish",
          "author": "dongkeren",
          "createdAt": "2026-07-03T18:25:22Z",
          "mergedAt": "2026-07-03T18:47:51Z",
          "additions": 19,
          "deletions": 7,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 41,
          "url": "https://github.com/kungfu-systems/libnode/pull/41",
          "title": "build: materialize libnode aliases after install",
          "body": "## Summary\n- switch platform alias handling from hardlinks to install-time materialization\n- keep darwin/linux tarballs free of alias copies while requiring helper + postinstall\n- bump alpha package version to 22.22.3-kf.3-alpha.7\n\n## Validation\n- corepack pnpm verify-release\n- corepack pnpm verify-package-source\n- node --check .gyp/node-platform-package.js\n- node --check .gyp/npm-publish-tarballs.js\n- git diff --check\n- fake npm package-set validation via .gyp/npm-publish-tarballs.js",
          "author": "dongkeren",
          "createdAt": "2026-07-03T19:12:09Z",
          "mergedAt": "2026-07-03T19:36:57Z",
          "additions": 15,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 42,
          "url": "https://github.com/kungfu-systems/libnode/pull/42",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.7",
          "body": "## Summary\n- promote libnode alpha.7 alias materialization fix into the alpha channel\n- keep buildchain workflow on floating stable v2\n- publish through buildchain publish-gate after channel merge\n\n## Validation\n- PR #41 buildchain checks passed after rerunning transient Linux configure SIGSEGV\n- Windows x64 and macOS ARM64 passed on the initial run\n- Linux x64 passed on failed-job rerun",
          "author": "dongkeren",
          "createdAt": "2026-07-03T19:37:28Z",
          "mergedAt": "2026-07-03T19:56:37Z",
          "additions": 15,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 188,
          "url": "https://github.com/kungfu-systems/kungfu/pull/188",
          "title": "Rename the runtime command from kfc to kungfu",
          "body": "Rename the runtime command and its packaged artifacts from `kfc` to `kungfu`, so the product exposes a single canonical name end to end.\n\n## What changed\n\n- **core** freezes the standalone runtime as `kungfu` under `dist/kungfu` (nuitka entry output + `binary.module_path`); the launcher and `kfs` resolve the executable and shared runtime dir there.\n- **packaging** ships `core/dist/kungfu` to `Resources/kungfu`, and the binding install rpath points at `Resources/kungfu`; the gui/tui/api and the SDK app template resolve the runtime and the `kungfu` executable there.\n- **install to PATH** — the reference app gains a VS Code–style \"Install 'kungfu' Command in PATH\" menu action: it ships a small wrapper that locates the bundled runtime and execs it, and symlinks `/usr/local/bin/kungfu` (elevating only when that directory is not user-writable).\n- **runtime identifiers** — the runtime env contract (`KFC_*` → `KUNGFU_*`) is renamed in sync across the writers (api/gui/tui/sdk) and readers (core binding loader, Python variants/cli); TS/JS helpers, the freeze/spec internals, the binding variant suffix, the Windows delay-load hook, and the CLI group all take the `kungfu` name.\n- **public surface** — the `kfc` bin alias is dropped (`kungfu` is the sole command), the prebuilt package name becomes `kungfu-v*`, examples/fixtures invoke `kungfu`, and the docs describe a single `kungfu` runtime and CLI.\n\n## Deliberately kept\n\n- Invisible internal build filenames (`kfc.py`, `kfc.spec`, the `kfc.dist`/`kfc-nuitka` intermediates, the `lib/kfc.js` launcher, `.devtools/kfc.py`) — never user-visible, so renaming them buys nothing.\n- The `Kf*` domain model (`KfConfig`/`KfCategory`/`KfLocation`/…) is a separate namespace and is untouched.\n- Dated ADR / versioning-ledger records that mention the former alias are left as accurate history.\n\n## Verification\n\nA from-scratch core build produces a runnable `dist/kungfu/kungfu` that presents as `kungfu` in `--help`; the packed app carries `Resources/kungfu/kungfu` (rpath resolves in the packaged layout) and the bundled CLI wrapper runs `kungfu` from PATH end to end.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T23:55:00Z",
          "mergedAt": "2026-07-04T00:06:20Z",
          "additions": 500,
          "deletions": 319,
          "changedFiles": 86
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 12,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/12",
          "title": "feat(homepage): add cost state proof first screen",
          "body": "## Summary\n- Replaces the initial kungfu.tech screen with the Cost / State / Proof product promise.\n- Adds a realistic local control pane preview for cost waste, work state, and evidence.\n- Keeps the open-source trust layer visible below the first screen.\n\n## Checks\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- Browser smoke at desktop and mobile widths: no horizontal overflow, console clean.\n\n## Deployment\n- Source-only change. No production apply or release action is included in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T16:11:04Z",
          "mergedAt": "2026-07-04T00:34:05Z",
          "additions": 429,
          "deletions": 71,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 365,
          "url": "https://github.com/kungfu-systems/buildchain/pull/365",
          "title": "fix(release): retry durable state finalization",
          "body": "## Summary\n- Retry transient GitHub API failures for durable release-state reads and writes.\n- Clear stale transaction failure values when finalization reaches complete.\n- Improve native diagnostics: ccache text fallback, full process commands, Windows sampling, requested parallelism detection, and first-class native cache/compiler-cache fields.\n\n## Verification\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-04T00:46:52Z",
          "mergedAt": "2026-07-04T00:48:28Z",
          "additions": 736,
          "deletions": 231,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 366,
          "url": "https://github.com/kungfu-systems/buildchain/pull/366",
          "title": "chore(release): promote v2.4 dev to alpha",
          "body": "## Summary\n- Promote dev/v2/v2.4 into alpha/v2/v2.4 for Buildchain 2.4.3-alpha validation.\n- Includes durable release-state retry/finalization reliability and native diagnostics improvements.\n\n## Verification\n- PR checks must pass before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T00:49:47Z",
          "mergedAt": "2026-07-04T00:51:36Z",
          "additions": 736,
          "deletions": 231,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 189,
          "url": "https://github.com/kungfu-systems/kungfu/pull/189",
          "title": "Rename the internal freeze-entry files to kungfu",
          "body": "Follow-up to the kfc→kungfu rename: rename the remaining internal freeze-entry files so the source tree reads as kungfu throughout, with no user-visible surface change.\n\n- `src/python/kfc.py` → `kungfu_cli.py` (the nuitka/pyinstaller entry — it cannot be `kungfu.py` without shadowing the sibling `kungfu` package)\n- `.devtools/kfc.py` → `.devtools/kungfu_cli.py`\n- `kfc.spec` → `kungfu.spec`\n- `lib/kfc.js` → `lib/kungfu-cli.js` (`lib/kungfu.js` is the binding loader)\n- `.gyp/freeze-kfc.sh` → `freeze-kungfu.sh`\n\nThe nuitka intermediates follow the entry basename (`kungfu_cli.dist` / `kungfu_cli.bin`, `build/kungfu-nuitka`); the freeze script, conanfile, `package.json` bin/scripts, spec, and the tests/bench references are updated to match.\n\nVerified by a re-freeze: `src/python/kungfu_cli.py` compiles into `kungfu_cli.dist` and produces a runnable `dist/kungfu/kungfu`; the renamed launcher `lib/kungfu-cli.js` runs it too.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T00:53:42Z",
          "mergedAt": "2026-07-04T00:54:36Z",
          "additions": 45,
          "deletions": 45,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 367,
          "url": "https://github.com/kungfu-systems/buildchain/pull/367",
          "title": "Prepare v2.4.3-alpha.1",
          "body": "Create the generated version-state commit for v2.4.3-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T00:53:46Z",
          "mergedAt": "2026-07-04T00:55:31Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 190,
          "url": "https://github.com/kungfu-systems/kungfu/pull/190",
          "title": "refactor(examples): retire legacy trading examples, move the build probes here",
          "body": "The examples/ tree held v3 trading samples (strategy / operator / report / slicetool) whose build scripts call `kfs` commands that no longer exist under v4 — they don't build. Removes them.\n\nMoves the two dogfood build probes from `extensions/` to `examples/` and renames them `@kungfu-tech/examples-probe-{cpp,python}`: they exist to exercise the C++ and python-AOT extension build paths, not to be installed as products, so `examples/` is their proper home and the name no longer implies a shipped kfx.\n\nverify still builds and asserts both probes (paths + package names updated); docs/architecture.md points at the new locations. Locally both probes build from examples/ (probe-cpp -> probe_cpp .so; probe-python -> engage pdm pydantic + engage nuitka -> ProbePython .so, probe(21)==21).",
          "author": "dongkeren",
          "createdAt": "2026-07-04T00:55:41Z",
          "mergedAt": "2026-07-04T00:56:15Z",
          "additions": 19,
          "deletions": 1218,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 368,
          "url": "https://github.com/kungfu-systems/buildchain/pull/368",
          "title": "chore(release): promote v2.4 alpha to release",
          "body": "## Summary\n- Promote alpha/v2/v2.4 into release/v2/v2.4 for Buildchain 2.4.3 stable.\n- Includes durable release-state retry/finalization reliability and native diagnostics improvements already validated in alpha.\n\n## Verification\n- Alpha v2.4.3-alpha.1 release and Binary Distribution completed successfully.\n- PR checks must pass before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T00:59:16Z",
          "mergedAt": "2026-07-04T01:01:11Z",
          "additions": 737,
          "deletions": 232,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 369,
          "url": "https://github.com/kungfu-systems/buildchain/pull/369",
          "title": "Release v2.4.3",
          "body": "Create the generated version-state commit for v2.4.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:03:21Z",
          "mergedAt": "2026-07-04T01:05:00Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 371,
          "url": "https://github.com/kungfu-systems/buildchain/pull/371",
          "title": "Prepare v2.4.4-alpha.0",
          "body": "Create the generated version-state commit for v2.4.4-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:07:22Z",
          "mergedAt": "2026-07-04T01:09:12Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 13,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/13",
          "title": "ci: enable standard Buildchain release flow",
          "body": "## Summary\n\n- enable Buildchain preview apply, preview cleanup apply, and staging apply for site-kungfu-tech\n- document the standard flow: feature PR preview, normal merge to staging, release PR merge to production\n- update infra output checks so the workflow must keep preview/staging apply enabled while preserving production release PR gates\n\n## Verification\n\n- bash -n scripts/build-site.sh scripts/check-site.sh\n- node --check scripts/check-infra-outputs.mjs\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- actionlint .github/workflows/buildchain-web-surface.yml\n- git diff --check\n\n## Dependency\n\nThe preview/staging apply jobs are already supported by Buildchain v2.4. The release PR page staging-review comment depends on the companion Buildchain PR landing and being promoted to the v2.4 workflow ref.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:05:06Z",
          "mergedAt": "2026-07-04T01:15:36Z",
          "additions": 24,
          "deletions": 18,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 370,
          "url": "https://github.com/kungfu-systems/buildchain/pull/370",
          "title": "feat(web-surface): comment staging URL on release PRs",
          "body": "## Summary\n\n- add a Buildchain web-surface release PR review comment with the staging review URL and production target\n- keep the comment scoped to same-repository release PRs that match `production-release-on-main`, `production-release-label`, and `production-release-head-prefix`\n- document the operator flow: verify staging from the release PR page, then merge as the production approval\n\n## Verification\n\n- node --check scripts/web-surface-release-pr-review.mjs\n- node --test tests/build-surface.test.mjs\n- pnpm run check:workflows\n- actionlint .github/workflows/.web-surface.yml\n- pnpm run check:site\n- pnpm run check\n- git diff --check\n\n## Notes\n\nThis makes the standard web-surface flow visible in GitHub: feature PRs publish preview, normal main merges publish staging, and release PR pages point operators at staging before merge publishes production.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:05:05Z",
          "mergedAt": "2026-07-04T01:41:51Z",
          "additions": 260,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 191,
          "url": "https://github.com/kungfu-systems/kungfu/pull/191",
          "title": "refactor(api): retire pm2 and the dead trading process-management layer",
          "body": "v4 does not start trading processes (td/md/strategy/ledger/master); the runtime loads in-process and kfx views are isolated by the Electron sandbox (`WebContentsView` + declared-capability IPC relay), so the pm2-based process supervisor in `framework/api` is dead — nothing in gui/tui/developer/extensions calls it.\n\nRemoves the pm2 dependency + `patches/[email-redacted]` + the patchedDependencies entry; deletes `processUtils.ts`, `pm2Custom.ts`, `hooks/preStartProcessHook.ts`, `actions/tradingTask.ts` (pm2-only, zero external consumers); excises the dead pm2 functions from `busiUtils.ts` and their references in `actions/index.ts` / `hooks/index.ts` / `typings/global.d.ts`; decouples `resolveStartProcessOptionsHook` from the pm2 `StartOptions` type. Documents the in-process / Electron-sandbox process model in `docs/architecture.md`.\n\nNet -3132 lines. `framework/api` type-checks clean (`tsc --noEmit`, 0 errors); no pm2 references remain, and no external package imports the removed exports.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:43:30Z",
          "mergedAt": "2026-07-04T01:45:04Z",
          "additions": 15,
          "deletions": 3132,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 43,
          "url": "https://github.com/kungfu-systems/libnode/pull/43",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.8",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 for libnode 22.22.3-kf.3-alpha.8.\n\n- Publish channel: alpha\n- Expected npm version: 22.22.3-kf.3-alpha.8\n- Buildchain runtime: @v2 stable\n\nThis should trigger the publish-gate source lock flow with one alpha build after merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:22:38Z",
          "mergedAt": "2026-07-04T01:47:34Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 372,
          "url": "https://github.com/kungfu-systems/buildchain/pull/372",
          "title": "feat(web-surface): persist release feedback passports",
          "body": "## Summary\n- add web-surface staging/production release feedback comments and passport artifacts after apply\n- record responsibility actors, gate evidence, source event, run, target, rollback, and failure context\n- separate anchored/manual internal tags from published version labels in release passports\n\n## Validation\n- node --check scripts/web-surface-release-feedback.mjs\n- node --test tests/build-surface.test.mjs\n- node --test tests/release-passport.test.mjs\n- pnpm run build\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:52:53Z",
          "mergedAt": "2026-07-04T01:54:37Z",
          "additions": 589,
          "deletions": 48,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 373,
          "url": "https://github.com/kungfu-systems/buildchain/pull/373",
          "title": "chore(release): promote v2.4 dev to alpha",
          "body": "Promote Buildchain dev/v2/v2.4 to alpha/v2/v2.4 for the release feedback/passport changes and PR #370.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:55:14Z",
          "mergedAt": "2026-07-04T01:56:57Z",
          "additions": 849,
          "deletions": 48,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 374,
          "url": "https://github.com/kungfu-systems/buildchain/pull/374",
          "title": "Prepare v2.4.4-alpha.1",
          "body": "Create the generated version-state commit for v2.4.4-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:58:59Z",
          "mergedAt": "2026-07-04T02:00:42Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 375,
          "url": "https://github.com/kungfu-systems/buildchain/pull/375",
          "title": "chore(release): promote v2.4 alpha to release",
          "body": "Promote Buildchain v2.4.4 alpha to release after release feedback/passport changes and alpha validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:04:48Z",
          "mergedAt": "2026-07-04T02:06:31Z",
          "additions": 850,
          "deletions": 49,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 192,
          "url": "https://github.com/kungfu-systems/kungfu/pull/192",
          "title": "docs(architecture): document the repository layout and a placement rule",
          "body": "Gives new packages a standard home so placement doesn't drift. Completes the repository-layout block (adds `framework/kfx` and `framework/spec`, lists `kungfu-code`), drops the retired `developer/toolchain`, adds a short **Contracts** layer entry for kfx/spec, and adds a **Where a new package goes** rule.\n\nThe rule: `framework/` = a runtime component or a publishable contract/library others build **on** (imported as a dependency — core/api/kfx/spec/gui/tui); `developer/` = a build-time **tool** others build **with** (invoked, a devDependency — sdk/kfs); `extensions/` = kfx plugins; `examples/` = samples and build-coverage probes; `artifact` = the installer. By this rule a format spec is a contract (framework) and the kfs CLI is a tool (developer), even with a single package there.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:04:26Z",
          "mergedAt": "2026-07-04T02:10:09Z",
          "additions": 44,
          "deletions": 13,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 376,
          "url": "https://github.com/kungfu-systems/buildchain/pull/376",
          "title": "Release v2.4.4",
          "body": "Create the generated version-state commit for v2.4.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:08:30Z",
          "mergedAt": "2026-07-04T02:10:15Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 377,
          "url": "https://github.com/kungfu-systems/buildchain/pull/377",
          "title": "Prepare v2.4.5-alpha.0",
          "body": "Create the generated version-state commit for v2.4.5-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:12:34Z",
          "mergedAt": "2026-07-04T02:15:22Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 194,
          "url": "https://github.com/kungfu-systems/kungfu/pull/194",
          "title": "Ship the fact-ledger schemas and the Ink TUI in the packaged app",
          "body": "The installed app now exercises the full runtime: the fact-ledger features work frozen, and the Ink reference TUI ships and runs.\n\n## Fact-ledger schema blobs (`kungfu trace` / rewind / work / atlas)\n\nThe `*_events.bfbs` reflection schemas were never bundled into the frozen runtime, and were read via `dirname(__file__)` — not a real directory inside the standalone binary — so `kungfu trace` failed with `NotADirectoryError`. Ship the blobs flat next to the binding (the `kungfubuildinfo.json` pattern) and resolve them through a `schema_data_path` helper that tries the source layout first, then the binding directory.\n\n## Reference TUI in the dmg\n\nThe Ink TUI was not shipped at all. Bundle it to a single self-contained ES module (esbuild; ESM is required for Ink 5 / yoga-layout top-level await), stub Ink's optional `react-devtools-core`, add a `require` shim for bundled CJS deps, ship it under `Resources/tui`, and add a `kungfu tui` command that runs it through kungfu's embedded Node runtime (`libnode`) — the same bridge `kungfu cli` uses — with `KUNGFU_DIR` pointed at the shipped runtime so it loads `kungfu_node.node` in-process.\n\n## Verification\n\nFrom the packaged app: `kungfu trace -- echo ...` captures a run and writes its bundle; `kungfu tui` loads the in-process binding and renders the ledger view.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:18:03Z",
          "mergedAt": "2026-07-04T02:19:05Z",
          "additions": 140,
          "deletions": 6,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 193,
          "url": "https://github.com/kungfu-systems/kungfu/pull/193",
          "title": "fix(gui): boot the sandboxed-view app and surface installed views",
          "body": "Running the full reference app end to end — not just the headless capability harness — surfaced three defects on the embedded sandboxed-view path. Each is fixed here; the production isolation posture is unchanged.\n\n## Fixes\n\n1. **App fails to start.** The electron main/preload externalized the pure-TS workspace packages `@kungfu-tech/api` and `@kungfu-tech/kfx`, so at runtime node's ESM loader tried to resolve their extensionless `src` imports (`export * from './types'`) and threw `ERR_MODULE_NOT_FOUND`. Bundle them into main/preload instead; the native `@kungfu-tech/core` stays external and is `require()`d at runtime.\n\n2. **Installed third-party view invisible.** An installed (sandboxed-ipc) view loaded into the registry but never appeared in the shell nav, because the nav only listed `system` views or views in the active profile's built-in `kfx` list. Surface installed sandboxed views independently of the profile.\n\n3. **Sandboxed view blank in development.** A sandboxed view's locked-down partition denies all non-`file:`/`devtools:` requests. In development the harness page is served over the renderer dev-server origin (`ELECTRON_RENDERER_URL`, an http origin), so it was blocked (`ERR_BLOCKED_BY_CLIENT`) and the view rendered blank. Allow that origin through in development only; production has no such env and still passes only `file:`/`devtools:`.\n\n## Verification\n\nRan the reference app against a real native-backed runtime with a third-party view installed into `<home>/extensions`, and verified in the live app:\n\n- the third-party view is classified `sandboxed-ipc` and renders in an isolated renderer with no node (`window.require`/`process` absent);\n- its declared `ledger` capability round-trips over IPC to the real runtime and returns live health/anchors/records;\n- an undeclared capability is absent on the guest and a forged call is rejected at the host;\n- the view is killed when it breaches the working-set cap, while the shell survives;\n- the embedded view tracks the window on resize.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:07:50Z",
          "mergedAt": "2026-07-04T02:22:43Z",
          "additions": 14,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 378,
          "url": "https://github.com/kungfu-systems/buildchain/pull/378",
          "title": "Add consumer issue reporting action",
          "body": "## Summary\n- add first-class `actions/report-buildchain-issue` for consumer workflows to create or update Buildchain issues\n- add `@kungfu-tech/buildchain/issue-reporting` toolkit API with fingerprint dedupe, redaction, GitHub API retry/backoff, and label fallback\n- document the GitHub App token trust model and register the action in Buildchain inventory/site facts\n\n## Verification\n- `pnpm run test:unit`\n- `pnpm -r --filter \"./actions/**\" build`\n- `pnpm run check`\n- bundled action dry-run smoke via `node actions/report-buildchain-issue/dist/index.js`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:53:53Z",
          "mergedAt": "2026-07-04T02:55:38Z",
          "additions": 1019,
          "deletions": 1,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 379,
          "url": "https://github.com/kungfu-systems/buildchain/pull/379",
          "title": "Promote dev/v2/v2.4 to alpha",
          "body": "## Summary\n- promote Buildchain consumer issue reporting surface into the alpha channel\n\n## Source\n- dev/v2/v2.4 @ bf3e1eaf2b5bda720391b32805be2665f7e31720\n- includes PR #378\n\n## Verification\n- PR #378 Verify and Build Surface Fixture checks passed before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:56:04Z",
          "mergedAt": "2026-07-04T02:58:20Z",
          "additions": 1019,
          "deletions": 1,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 380,
          "url": "https://github.com/kungfu-systems/buildchain/pull/380",
          "title": "Prepare v2.4.5-alpha.1",
          "body": "Create the generated version-state commit for v2.4.5-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T03:00:33Z",
          "mergedAt": "2026-07-04T03:02:03Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 381,
          "url": "https://github.com/kungfu-systems/buildchain/pull/381",
          "title": "Promote v2.4 alpha to release",
          "body": "## Summary\n- promote Buildchain 2.4.5 alpha into the release channel\n- includes first-class consumer issue reporting action/API from PR #378\n\n## Source\n- alpha/v2/v2.4 @ 92bc8bacb95dbf9208084d92aae1259217255867\n- alpha npm: @kungfu-tech/buildchain@2.4.5-alpha.1\n- alpha release passport: v2.4.5-alpha.1\n\n## Verification\n- PR #379 checks passed before alpha merge\n- PR #380 checks passed before alpha version-state merge\n- Buildchain Ref Promotion runs 28692842200 and 28692935004 succeeded\n- Binary Distribution run 28692958103 succeeded\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T03:05:51Z",
          "mergedAt": "2026-07-04T03:07:37Z",
          "additions": 1020,
          "deletions": 2,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 382,
          "url": "https://github.com/kungfu-systems/buildchain/pull/382",
          "title": "Release v2.4.5",
          "body": "Create the generated version-state commit for v2.4.5.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T03:09:45Z",
          "mergedAt": "2026-07-04T03:11:32Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 383,
          "url": "https://github.com/kungfu-systems/buildchain/pull/383",
          "title": "Prepare v2.4.6-alpha.0",
          "body": "Create the generated version-state commit for v2.4.6-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T03:14:07Z",
          "mergedAt": "2026-07-04T03:16:01Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 386,
          "url": "https://github.com/kungfu-systems/buildchain/pull/386",
          "title": "feat(release): add RC passport promotion evidence",
          "body": "## Summary\n- add reusable build release-candidate passport generation and artifacts\n- add promote-only RC passport validation before promotion side effects\n- extend Buildchain issue reporting with workflow-friction mode and cooldown dedupe\n- dogfood RC passport output in the build-surface fixture workflow\n\n## Verification\n- pnpm run check\n- node --test tests/issue-reporting.test.mjs tests/release-candidate.test.mjs tests/build-surface.test.mjs\n- node --test tests/promote-buildchain-ref.test.mjs\n- git diff --check\n\n## Notes\n- No consumer repository PRs were opened.\n- Buildchain self feedback is fail-soft and requires issues:write on the reporting workflow.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:21:30Z",
          "mergedAt": "2026-07-04T04:23:26Z",
          "additions": 1241,
          "deletions": 125,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 196,
          "url": "https://github.com/kungfu-systems/kungfu/pull/196",
          "title": "Make kungfu tui cwd-independent and let trace run -c commands",
          "body": "Two robustness fixes surfaced by dogfooding the packaged app.\n\n- **`kungfu tui` was cwd-dependent and could crash.** It derived its runtime home from `cwd/demo-runtime`, so it showed a different (usually empty) ledger per directory and crashed with a native exception when the cwd was not writable. Default `KF_RUNTIME_DIR` to the same `<home>/runtime` the rest of the CLI uses (`ctx.runtime_dir`), so the TUI opens the real runtime regardless of where it is launched.\n\n- **`kungfu trace -- sh -c '...'` tripped Nuitka's self-execution guard.** Tracing a child command whose arguments include `-c` was mistaken by Nuitka's deployment mode for the frozen binary being asked to self-execute. The runtime never re-executes itself, so the freeze now passes `--no-deployment-flag=self-execution`.\n\nVerified on a fresh build: `kungfu trace -- sh -c 'echo a; echo b'` captures the run; `kungfu tui` launched from a read-only directory renders against the home runtime instead of crashing.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:24:46Z",
          "mergedAt": "2026-07-04T04:25:25Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 387,
          "url": "https://github.com/kungfu-systems/buildchain/pull/387",
          "title": "chore(release): promote v2.4 dev to alpha",
          "body": "## Summary\nPromote the verified dev/v2/v2.4 head into alpha/v2/v2.4 for Buildchain release publication.\n\nIncludes #386: RC passport promotion evidence and workflow-friction feedback.\n\n## Verification\n- dev/v2/v2.4 Verify run 28694793859 passed\n- PR #386 Verify and Build Surface Fixture passed; RC artifact was generated.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:24:55Z",
          "mergedAt": "2026-07-04T04:26:26Z",
          "additions": 1241,
          "deletions": 125,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 388,
          "url": "https://github.com/kungfu-systems/buildchain/pull/388",
          "title": "Prepare v2.4.6-alpha.1",
          "body": "Create the generated version-state commit for v2.4.6-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:28:31Z",
          "mergedAt": "2026-07-04T04:30:21Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 389,
          "url": "https://github.com/kungfu-systems/buildchain/pull/389",
          "title": "chore(release): promote v2.4 alpha to release",
          "body": "## Summary\nPromote the verified alpha/v2/v2.4 line into release/v2/v2.4 for Buildchain production publication.\n\nIncludes #386 and alpha publication v2.4.6-alpha.1.\n\n## Verification\n- alpha Verify run 28694950698 passed\n- alpha promotion finalization run 28694970815 passed\n- npm alpha dist-tag is 2.4.6-alpha.1\n- v2.4.6-alpha.1 and v2.4-alpha point at alpha/v2/v2.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:32:54Z",
          "mergedAt": "2026-07-04T04:34:27Z",
          "additions": 1242,
          "deletions": 126,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 390,
          "url": "https://github.com/kungfu-systems/buildchain/pull/390",
          "title": "Release v2.4.6",
          "body": "Create the generated version-state commit for v2.4.6.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:36:18Z",
          "mergedAt": "2026-07-04T04:37:53Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 391,
          "url": "https://github.com/kungfu-systems/buildchain/pull/391",
          "title": "Prepare v2.4.7-alpha.0",
          "body": "Create the generated version-state commit for v2.4.7-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:40:13Z",
          "mergedAt": "2026-07-04T04:42:52Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 197,
          "url": "https://github.com/kungfu-systems/kungfu/pull/197",
          "title": "build(core): pin clang-format via uv for reproducible C++ formatting",
          "body": "Pin clang-format==20.1.8 as a uv-managed dependency (PyPI wheel, same lane as ruff) so C++ formatting is byte-identical across machines. run-format-cpp.js and the pre-commit hook use the uv-provided binary; the C++ tree is reformatted to the pinned version.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:10:26Z",
          "mergedAt": "2026-07-04T05:10:31Z",
          "additions": 179,
          "deletions": 139,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 195,
          "url": "https://github.com/kungfu-systems/kungfu/pull/195",
          "title": "docs(adr): ADR-0013 — extension isolation and the trusted channel on the runtime plane",
          "body": "Extends ADR-0011's tier model from the GUI view plane to the runtime plane (adapters loaded by the trace supervisor, and future runtime facets).\n\n**Decision (proposed):**\n- Resolve the tier on two axes — trust (source-verified first-party vs third-party) × co-residence (in-process instrumentation vs isolatable independent compute) — instead of one conflated tier.\n- **Default tier:** an untrusted independent-compute facet runs default-deny in an OS-sandboxed child process (macOS Seatbelt; Linux Landlock + seccomp + namespaces), with the capability relay as its sole egress (the same transport-agnostic capability proxy ADR-0011 uses, over child-process IPC).\n- **Trusted channel:** a source-verified first-party facet keeps in-process zero-copy access to the journal.\n- **Instrumentation is gated, not contained:** a capture-side adapter must co-reside in the traced process, so an untrusted adapter is refused rather than sandboxed.\n- **Trust by verifiable origin, never by path:** replace the extension-root-derived trust with a build-time frozen first-party set (key + content hash), as a pluggable source-authority verdict; signature verification can be added later without rewriting the tier decision.\n\nDocs-only; `proposed` status; implementation deferred to a follow-up. Residual risk (OS-sandbox escape, Seatbelt coarseness, capability surface as the real boundary, supply-chain trust root) is recorded in the ADR.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:16:09Z",
          "mergedAt": "2026-07-04T05:22:31Z",
          "additions": 131,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 392,
          "url": "https://github.com/kungfu-systems/buildchain/pull/392",
          "title": "fix(release): require PR-stage RC evidence for promotion",
          "body": "## Summary\n- make buildchain-ref-promotion resolve and consume PR-stage RC passport/build-summary artifacts before promotion\n- record locked source Git tree SHA in build summary and RC passport, and accept channel merge commits only by exact head/merge SHA or tree equivalence\n- classify workflow friction for duplicate PRs, duplicate heavy builds, and late fail-fast; write full copyable issue body to summary when issue reporting fails\n\n## Validation\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:26:37Z",
          "mergedAt": "2026-07-04T05:28:26Z",
          "additions": 946,
          "deletions": 94,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 393,
          "url": "https://github.com/kungfu-systems/buildchain/pull/393",
          "title": "release: promote v2.4.7 alpha",
          "body": "## Summary\n- promote dev/v2/v2.4 into alpha/v2/v2.4 for v2.4.7 validation\n- PR-stage Build Surface Fixture must produce the RC passport consumed by buildchain-ref-promotion after merge\n\n## Validation\n- dev branch includes PR #392 with local `pnpm run check` and green PR checks\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:29:09Z",
          "mergedAt": "2026-07-04T05:31:23Z",
          "additions": 946,
          "deletions": 94,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 198,
          "url": "https://github.com/kungfu-systems/kungfu/pull/198",
          "title": "build: extend format coverage to the whole tree via root biome.json",
          "body": "Add a root biome.json covering all JS/TS outside framework/core (ignoring generated, fixtures, build, JSON). framework/api, framework/spec, extension views, the SDK template and repo-root scripts are now formatted to the biome baseline, and the pre-commit dispatch is widened repo-wide. Pure formatting + tooling; no behavior change.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:41:21Z",
          "mergedAt": "2026-07-04T05:41:26Z",
          "additions": 695,
          "deletions": 321,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 395,
          "url": "https://github.com/kungfu-systems/buildchain/pull/395",
          "title": "fix(release): wire RC promotion workflow on default branch",
          "body": "## Summary\n- update default-branch Buildchain Ref Promotion workflow so workflow_run promotions can consume target-commit PR-stage RC evidence\n- add workflow-friction reporter action/core to the default branch so failure reporting can create/dedupe Buildchain issues or write summary fallback\n- keep old target commits compatible by disabling promote-only RC only when the checked-out target commit lacks the resolver script\n\n## Validation\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:40:24Z",
          "mergedAt": "2026-07-04T05:42:29Z",
          "additions": 1163,
          "deletions": 0,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 394,
          "url": "https://github.com/kungfu-systems/buildchain/pull/394",
          "title": "Prepare v2.4.7-alpha.1",
          "body": "Create the generated version-state commit for v2.4.7-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:33:17Z",
          "mergedAt": "2026-07-04T05:42:56Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 397,
          "url": "https://github.com/kungfu-systems/buildchain/pull/397",
          "title": "fix(release): match RC workflow runs by PR",
          "body": "## Summary\n- match PR-stage release candidate runs by pull request instead of display title\n- keep workflow-name filtering optional and avoid confusing PR titles with workflow names\n- emit absolute artifact paths when the resolver downloads RC evidence outside the workspace\n\n## Validation\n- node --check scripts/release-candidate-resolver.mjs\n- node --test tests/release-candidate.test.mjs\n- pnpm run check\n\n## Release note\nThis fixes alpha/release promotion resolving PR-stage RC passports for version-state PRs whose workflow run title is the PR title rather than the workflow name.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:49:48Z",
          "mergedAt": "2026-07-04T05:53:07Z",
          "additions": 18,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 398,
          "url": "https://github.com/kungfu-systems/buildchain/pull/398",
          "title": "fix(release): run promotion guards from default branch",
          "body": "## Summary\n- checkout the default-branch promotion runtime before checking out the target commit\n- resolve RC passport evidence from the default workflow runtime, before target checkout and before publish side effects\n- run workflow-friction classification/reporting from the default workflow runtime so failed promotions get copyable evidence even when the target commit is stale\n\n## Validation\n- bash scripts/check-workflows.sh\n- node --check scripts/release-candidate-resolver.mjs\n- node --check scripts/workflow-friction-report.mjs\n- pnpm run check\n\n## Context\nGitHub workflow_run evaluates the workflow file from the repository default branch. This makes the default-branch promotion entry the strict gate for v2.4 alpha/release promotion reruns.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:52:20Z",
          "mergedAt": "2026-07-04T05:53:59Z",
          "additions": 606,
          "deletions": 44,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 399,
          "url": "https://github.com/kungfu-systems/buildchain/pull/399",
          "title": "fix(release): match RC runs by head ref fallback",
          "body": "## Summary\n- fall back from empty workflow run pull_requests arrays to PR head SHA / same-repo head branch matching\n- cover GitHub pull_request runs where the Actions API returns pull_requests: []\n\n## Validation\n- node --check scripts/release-candidate-resolver.mjs\n- node --test tests/release-candidate.test.mjs\n- pnpm run check\n\n## Context\nGitHub returned pull_requests: [] for the PR-stage Build Surface Fixture run on #394, while head_sha/head_branch still identified the version-state PR run.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:58:05Z",
          "mergedAt": "2026-07-04T06:00:06Z",
          "additions": 39,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 400,
          "url": "https://github.com/kungfu-systems/buildchain/pull/400",
          "title": "fix(release): match RC runs when PR links are empty",
          "body": "## Summary\n- update the default-branch promotion runtime resolver to match PR-stage runs by PR head SHA / same-repo head branch when GitHub returns pull_requests: []\n\n## Validation\n- node --check scripts/release-candidate-resolver.mjs\n- bash scripts/check-workflows.sh\n- pnpm run check\n\n## Context\nThe #394 Build Surface Fixture run has the correct head_sha/head_branch and artifacts, but the Actions API returns an empty pull_requests array.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:59:10Z",
          "mergedAt": "2026-07-04T06:00:51Z",
          "additions": 12,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 401,
          "url": "https://github.com/kungfu-systems/buildchain/pull/401",
          "title": "fix(release): bind RC passport channel from PR base",
          "body": "## Summary\n- normalize RC target channels so publish-channel none is not treated as a real channel\n- derive PR-stage RC channel from the PR base ref, e.g. alpha/v2/v2.4 -> alpha\n- tolerate legacy RC passports that recorded target.channel as none when source identity still matches\n- rebuild the promote-buildchain-ref action bundle\n\n## Validation\n- node --test tests/release-candidate.test.mjs tests/promote-buildchain-ref.test.mjs\n- pnpm run check\n\n## Context\nThe strict default promotion entry successfully resolved #394 PR-stage RC evidence and enabled promote-only-release-candidate, but the old RC passport contained target.channel: none because publish-channel defaulted to none during PR-stage builds.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:05:21Z",
          "mergedAt": "2026-07-04T06:07:34Z",
          "additions": 108,
          "deletions": 42,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 402,
          "url": "https://github.com/kungfu-systems/buildchain/pull/402",
          "title": "fix(release): preserve promotion runtime for reports",
          "body": "## Summary\n- restore the default-branch promotion runtime after target checkout and install\n- keep workflow-friction classifier/report action available when promotion fails after target checkout\n\n## Validation\n- bash scripts/check-workflows.sh\n- pnpm run check\n\n## Context\nThe target checkout deletes the earlier promotion-runtime checkout. Without restoring it, post-promote failure classification and issue summary fallback can lose the runtime scripts/action.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:06:38Z",
          "mergedAt": "2026-07-04T06:08:49Z",
          "additions": 7,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 403,
          "url": "https://github.com/kungfu-systems/buildchain/pull/403",
          "title": "release: promote v2.4.7 alpha",
          "body": "## Summary\n- promote latest v2.4 release governance fixes to alpha\n- includes strict RC passport consumption, PR-stage run matching fallbacks, RC channel binding, and workflow-friction reporting runtime fixes\n\n## Validation\n- dev PR checks passed on #397, #399, #401\n- default promotion entry checks passed on #398, #400, #402\n\n## Release intent\nThis alpha promotion should publish the next v2.4 alpha candidate through promote-only release-candidate evidence before release promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:09:19Z",
          "mergedAt": "2026-07-04T06:17:57Z",
          "additions": 165,
          "deletions": 48,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 199,
          "url": "https://github.com/kungfu-systems/kungfu/pull/199",
          "title": "build: converge on a single biome config and remove prettier",
          "body": "Collapse the JS/TS toolchain onto one root biome.json (delete duplicate per-package configs/scripts, declare biome once at root), remove prettier entirely (core build scripts now use biome), drop dead eslintrc. Pure tooling + formatting.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:23:46Z",
          "mergedAt": "2026-07-04T06:23:51Z",
          "additions": 40,
          "deletions": 241,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 406,
          "url": "https://github.com/kungfu-systems/buildchain/pull/406",
          "title": "fix(release): retry promotion PR lineage API reads",
          "body": "## Summary\n- wrap promotion PR lineage lookups in the existing transient GitHub API retry helper\n- cover `GET /commits/{sha}/pulls` 500/other-side-closed retry behavior\n- rebuild the promote-buildchain-ref action bundle\n\n## Validation\n- node --test --test-name-pattern=\"channel promotion PR lineage retries|publish transaction retries transient durable release-state reads\" tests/promote-buildchain-ref.test.mjs\n- pnpm --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- pnpm run check\n\n## Release note\nThis fixes the transient GitHub API 500 observed in Buildchain Ref Promotion run 28697487524 after RC passport resolution had already succeeded.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:23:23Z",
          "mergedAt": "2026-07-04T06:25:28Z",
          "additions": 122,
          "deletions": 58,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 407,
          "url": "https://github.com/kungfu-systems/buildchain/pull/407",
          "title": "release: promote v2.4.7 alpha retry fix",
          "body": "## Summary\n- promote dev/v2/v2.4 to alpha/v2/v2.4 after adding transient GitHub API retry coverage for promotion PR lineage reads\n- keeps the legal dev -> alpha promotion lineage for RC passport promote-only validation\n\n## Context\n- Buildchain Ref Promotion run 28697487524 resolved PR-stage RC evidence and set promote-only-release-candidate=true, then failed on transient GitHub API 500 from `GET /commits/{sha}/pulls`.\n- PR #406 fixes that API read path.\n\n## Validation\n- PR #406: pnpm run check\n- this PR should produce fresh PR-stage RC passport artifacts for promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:26:03Z",
          "mergedAt": "2026-07-04T06:28:15Z",
          "additions": 122,
          "deletions": 58,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 200,
          "url": "https://github.com/kungfu-systems/kungfu/pull/200",
          "title": "feat(rewind): add provider cost adapters — discovery + Codex/Claude parse layer",
          "body": "Provider cost adapters (parse layer): discover Codex/Claude CLIs (incl. macOS Codex App bundle) and parse their structured output into a normalized, honestly-attributed CostSnapshot. Codex exec --json (tokens only, no pricing) and Claude --print json (total_cost_usd + session + cache-split usage). Parse-only, pure stdlib, no journal/wire/credentials; new fixture asserts the contract under verify.js stage 6.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:32:33Z",
          "mergedAt": "2026-07-04T06:32:37Z",
          "additions": 1062,
          "deletions": 0,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 408,
          "url": "https://github.com/kungfu-systems/buildchain/pull/408",
          "title": "release: promote v2.4.7",
          "body": "## Summary\n- promote Buildchain v2.4.7 from alpha/v2/v2.4 to release/v2/v2.4\n- carries RC passport strict promotion, workflow-friction reporter integration, and transient GitHub API retry fixes\n\n## Alpha evidence\n- PR #407 merged to alpha/v2/v2.4\n- Verify run: 28697715023\n- Buildchain Ref Promotion run: 28697736411\n- Promotion consumed PR-stage RC evidence with promote-only-release-candidate=true\n- Alpha tag: v2.4.7-alpha.1\n\n## Validation\n- PR #406: pnpm run check\n- PR #407: Verify, Release - Verify, and Build Surface Fixture checks passed",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:31:19Z",
          "mergedAt": "2026-07-04T06:34:39Z",
          "additions": 1156,
          "deletions": 123,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 409,
          "url": "https://github.com/kungfu-systems/buildchain/pull/409",
          "title": "Release v2.4.7",
          "body": "Create the generated version-state commit for v2.4.7.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:36:41Z",
          "mergedAt": "2026-07-04T06:38:41Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 410,
          "url": "https://github.com/kungfu-systems/buildchain/pull/410",
          "title": "Prepare v2.4.8-alpha.0",
          "body": "Create the generated version-state commit for v2.4.8-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:41:00Z",
          "mergedAt": "2026-07-04T06:42:39Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 201,
          "url": "https://github.com/kungfu-systems/kungfu/pull/201",
          "title": "chore: add opt-in @ts-check type safety to the JS tooling layer",
          "body": "Add // @ts-check + JSDoc across the bootstrap/tooling/entry JS (zero compilation), plus a tsconfig.tools.json + check:types script. Type-checking surfaced and fixed real defects (a socket null-race and an undefined-key lookup in rewind_hook.js, an unknown-catch in verify.js). No runtime behavior change.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T07:06:06Z",
          "mergedAt": "2026-07-04T07:06:11Z",
          "additions": 644,
          "deletions": 140,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 202,
          "url": "https://github.com/kungfu-systems/kungfu/pull/202",
          "title": "fix(core): report signal-killed subprocesses as failures, not success",
          "body": "Merge fix/shell-signal-kill-exit-code into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-04T07:24:22Z",
          "mergedAt": "2026-07-04T07:24:29Z",
          "additions": 140,
          "deletions": 6,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 44,
          "url": "https://github.com/kungfu-systems/libnode/pull/44",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.9",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 for libnode 22.22.3-kf.3-alpha.9.\n\n- Publish channel: alpha\n- Expected npm version: 22.22.3-kf.3-alpha.9\n- Buildchain runtime: @v2 stable\n\nThis should trigger the publish-gate source lock flow with one alpha build after merge.\n\nVerification before PR:\n- node .gyp/libnode-release-verify.js\n- git diff --check\n- corepack pnpm verify-package-source\n- corepack pnpm pack --dry-run",
          "author": "dongkeren",
          "createdAt": "2026-07-04T07:14:20Z",
          "mergedAt": "2026-07-04T07:33:30Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 203,
          "url": "https://github.com/kungfu-systems/kungfu/pull/203",
          "title": "feat(gui): managed terminal — PTY-backed terminal capability + view",
          "body": "Managed terminal: PTY-backed terminal capability (trusted-renderer PTY host) + sandboxed-ipc xterm view + node-pty (Electron 42 ABI). Verified: typecheck, gui build, kfs bundle, 26-assert capability behavior test, and an Electron render smoke (PTY output renders into the DOM). Full kungfu-shell end-to-end deferred to a native build.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T07:52:44Z",
          "mergedAt": "2026-07-04T07:52:49Z",
          "additions": 572,
          "deletions": 1,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 204,
          "url": "https://github.com/kungfu-systems/kungfu/pull/204",
          "title": "feat(kfx): grant view trust by source-authority verdict, not by path (ADR-0013 Phase 0)",
          "body": "First implementation slice of ADR-0013: grant a view the node-integrated tier by a **source-authority verdict**, never by which extension root it loaded from.\n\n**The hole:** `resolveRuntimeTier` trusted a view whenever it loaded from any root other than the install root — so a `KF_EXTENSION_PATH` entry (or any writable built-in root) conferred full `node-integrated` trust.\n\n**The change:**\n- **kfx** — `FirstPartyManifest` + `authorizeFirstParty(manifest, key, contentHash)`: a view is trusted only if its key is in the frozen first-party set and, when pinned, its bundle content hash matches. This is the pluggable verdict — a signature check can be a second implementation without touching `resolveRuntimeTier`, which now takes a `trusted` boolean.\n- **gui loader** — resolve the tier from the manifest (`KF_FIRST_PARTY_MANIFEST`) + bundle hash; path no longer confers trust. A missing manifest trusts nothing but the shell's own `system` views (safe default, never a path fallback).\n- **manifest generation** — derived from a *fixed* first-party root (never `KF_EXTENSION_PATH`). Dev generates it at startup, keys only (bundles rebuild constantly → trusted by key). Packaged points at a build-baked resource with pinned hashes.\n\n**Design note (surfaced during grounding):** content-hash trust conflicts with dev source builds (hashes change every rebuild). Resolved by making the verdict identity-based — packaged pins `key+hash`, dev trusts first-party `key` unpinned — so both modes close the `KF_EXTENSION_PATH` hole.\n\n**Gate:** `tests/fixtures/kfx-demo-trust-authority` (verify --full stage 6, 10 assertions) — a third-party key on another root is sandboxed, a first-party key is node-integrated only with matching content, a tampered bundle is rejected, no manifest trusts nothing but system views.\n\n**Follow-up (out of scope here):** the packaged pinned-manifest bake rides with built-in-extension shipping (a separate pre-existing gap); until then packaged apps trust only system views. Untrusted capture-side adapters (the runtime plane) are a later slice.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T07:54:21Z",
          "mergedAt": "2026-07-04T07:59:05Z",
          "additions": 296,
          "deletions": 21,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 205,
          "url": "https://github.com/kungfu-systems/kungfu/pull/205",
          "title": "build(core): build the native addon from source on install",
          "body": "The self-hosted prebuilt host (prebuilt.libkungfu.cc) has an expired cert and publishes no 4.0 binary, so the node-pre-gyp download on install always failed. 4.0 now builds the native addon from source on install (skips when already built). Removes vestigial binary/install config from api and indexer-live. Verified end to end: a clean install compiles kungfu_node.node in ~10min. Follow-up: retire the node-pre-gyp/node-gyp/binding.gyp orchestration (it only circles back to run-conan.js) and distribute via npm platform packages.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:15:00Z",
          "mergedAt": "2026-07-04T08:15:04Z",
          "additions": 19,
          "deletions": 25,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 411,
          "url": "https://github.com/kungfu-systems/buildchain/pull/411",
          "title": "feat(release): add release-candidate promote-only flow",
          "body": "## Summary\n- emit PR-stage release-candidate bundles from the reusable build summary job\n- add a promote-only reusable workflow that resolves one merged PR RC, downloads it, validates tree-equivalent source locks, locks publish-gate, and then publishes without rerunning the heavy matrix\n- teach promote-buildchain-ref and release passports to record built-source vs promotion-channel SHA/tree evidence\n- add workflow friction issue fallback helper and docs for native package promote-only semantics\n\n## Validation\n- pnpm install --frozen-lockfile\n- pnpm -r --filter \"./actions/**\" build\n- pnpm run check\n\n## Dogfood boundary\n- Verified through Buildchain fixture/unit coverage only. No consumer repo PRs were opened and no consumer three-platform heavy build was triggered.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:02:52Z",
          "mergedAt": "2026-07-04T08:15:30Z",
          "additions": 555,
          "deletions": 53,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 206,
          "url": "https://github.com/kungfu-systems/kungfu/pull/206",
          "title": "feat(rewind): refuse untrusted adapters at the trace supervisor (ADR-0013 Phase 1)",
          "body": "Extends the ADR-0013 source-authority verdict from the GUI view plane (Phase 0, #204) to the **runtime/capture plane**.\n\n**The hole:** a capture-side `adapter` facet is injected by the trace supervisor into the traced program **in-process**, and the supervisor injected *every* discovered adapter with no trust check. Installing a third-party adapter, or pointing `KF_EXTENSION_PATH` at one, gave it full in-process reach over the run.\n\n**Why refuse, not sandbox:** an adapter runs inside the traced program's own process by construction (it patches the framework's tool seam) — isolating it would defeat the instrumentation. So an untrusted adapter is **refused, not contained**; injecting third-party code into a run requires the trusted channel (source verification).\n\n**The change:**\n- `first_party.py` — the first-party key set, read from the shared manifest (`KF_FIRST_PARTY_MANIFEST`, the same one the GUI loader uses) or, in a source checkout, derived from the product's own `extensions/` tree. A frozen build with no baked manifest trusts none.\n- `discover_adapters` now returns `(entries, dirs, refused)`; only a package whose key is in the first-party set is injected. The supervisor logs each refusal on stderr.\n- `test_adapter_trust` — an untrusted adapter is refused whether it sits on `KF_EXTENSION_PATH` or the install root; a first-party adapter is injected. Trust is by set membership, never by root.\n\n**No regression:** the `rewind-demo-langchain` fixture runs from source (`uv run python .devtools/kungfu_cli.py`), so the first-party set is derived from the real `extensions/` tree and `langchain-adapter` stays trusted.\n\n**Follow-up (shared with Phase 0):** the packaged/frozen path needs the baked first-party manifest (rides with built-in-extension shipping); until then a frozen build refuses adapters.\n\nBuilds on #204.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:15:25Z",
          "mergedAt": "2026-07-04T08:17:04Z",
          "additions": 193,
          "deletions": 9,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 412,
          "url": "https://github.com/kungfu-systems/buildchain/pull/412",
          "title": "release: promote v2.4 native promote-only flow to alpha",
          "body": "Promote Buildchain v2.4 native promote-only release-candidate flow to alpha.\\n\\nIncludes PR-stage release-candidate artifacts, post-merge promote-only reuse, tree-equivalent source lock validation, publish-gate wrapper semantics, and workflow friction reporting coverage.\\n\\nValidation before channel PR:\\n- pnpm run check\\n- PR #411 checks: Verify/check and Build Surface Fixture all passed",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:16:58Z",
          "mergedAt": "2026-07-04T08:19:07Z",
          "additions": 555,
          "deletions": 53,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 413,
          "url": "https://github.com/kungfu-systems/buildchain/pull/413",
          "title": "Prepare v2.4.8-alpha.1",
          "body": "Create the generated version-state commit for v2.4.8-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:21:16Z",
          "mergedAt": "2026-07-04T08:23:05Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 414,
          "url": "https://github.com/kungfu-systems/buildchain/pull/414",
          "title": "release: promote v2.4.8",
          "body": "Promote Buildchain v2.4.8 from alpha to release.\\n\\nAlpha evidence:\\n- v2.4.8-alpha.1 tag: 374ef2699e0ae850213bb58835881cc410209870\\n- npm alpha: @kungfu-tech/buildchain@2.4.8-alpha.1\\n- Buildchain Ref Promotion runs 28700335036 and 28700431091 completed successfully\\n\\nThis promotes the native promote-only release-candidate flow implemented through PR #411.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-04T08:25:36Z",
          "mergedAt": "2026-07-04T08:27:13Z",
          "additions": 556,
          "deletions": 54,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 415,
          "url": "https://github.com/kungfu-systems/buildchain/pull/415",
          "title": "Release v2.4.8",
          "body": "Create the generated version-state commit for v2.4.8.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:29:10Z",
          "mergedAt": "2026-07-04T08:31:03Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 416,
          "url": "https://github.com/kungfu-systems/buildchain/pull/416",
          "title": "Prepare v2.4.9-alpha.0",
          "body": "Create the generated version-state commit for v2.4.9-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:33:36Z",
          "mergedAt": "2026-07-04T08:35:31Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 207,
          "url": "https://github.com/kungfu-systems/kungfu/pull/207",
          "title": "feat(capability): subprocess transport + Python guest for the relay (ADR-0013 Phase 2)",
          "body": "The capability relay (`sandbox.ts`) was transport-agnostic but shipped only the Electron IPC channel (GUI plane). This adds the **CLI-plane channel**: a sandboxed guest can run in a child process, reaching only its declared capabilities over the child's stdio.\n\n- `api/capability/subprocess.ts` — pure newline-delimited-JSON stdio framing, **decoupled from the host** (the caller composes it with `createCapabilityHost`), so it serves any host and is testable without a capability instance. The host holds the real caps; an undeclared capability is rejected there, never reachable.\n- `kungfu/capability` (`guest.py`) — the **Python port** of `createCapabilityGuest`: a child builds its capability object from the declared set alone, marshals callback args as `{\"__sandboxCallback\"}` markers, and receives bridged events on a background reader thread.\n- fixture `kfx-demo-subprocess-caps` (verify --full stage 6) — a Node host + a **Python guest over a real subprocess** prove a declared call round-trips, an undeclared capability is absent, and a subscription bridges host→guest.\n\nValidated: fixture passes end-to-end (Node ↔ Python), `subprocess.ts` typechecks, `guest.py` ruff-clean.\n\nBuilds on the two-tier trust work (#204 Phase 0, #206 Phase 1). This is the default-tier *transport*; the OS-sandbox launcher that isolates the child is Phase 3.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:43:57Z",
          "mergedAt": "2026-07-04T08:44:48Z",
          "additions": 314,
          "deletions": 0,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 417,
          "url": "https://github.com/kungfu-systems/buildchain/pull/417",
          "title": "fix(release): expose RC workflow selection",
          "body": "## Summary\n- add release-candidate workflow file/name inputs to the promote-only wrapper, defaulting consumers to build.yml / Build\n- pass artifact-name and workflow selectors into release-candidate-resolver\n- filter RC passport/summary artifact selection by artifact-name to avoid same-run ambiguity\n- document the consumer defaults\n\n## Verification\n- node --check scripts/release-candidate-resolver.mjs\n- node --test tests/release-candidate.test.mjs tests/build-surface.test.mjs\n- bash scripts/check-workflows.sh\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:46:54Z",
          "mergedAt": "2026-07-04T08:48:48Z",
          "additions": 69,
          "deletions": 8,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 418,
          "url": "https://github.com/kungfu-systems/buildchain/pull/418",
          "title": "chore(release): promote v2.4 alpha",
          "body": "## Summary\n- Promote dev/v2/v2.4 to alpha/v2/v2.4 after PR #417.\n- This exercises the release-candidate build and post-merge promote-only release path.\n\n## Release intent\n- Channel: alpha\n- Source: dev/v2/v2.4\n- Target: alpha/v2/v2.4\n\n## Verification\n- PR #417 passed Verify and Build Surface Fixture before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:49:16Z",
          "mergedAt": "2026-07-04T08:51:00Z",
          "additions": 69,
          "deletions": 8,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 419,
          "url": "https://github.com/kungfu-systems/buildchain/pull/419",
          "title": "Prepare v2.4.9-alpha.1",
          "body": "Create the generated version-state commit for v2.4.9-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:53:13Z",
          "mergedAt": "2026-07-04T08:54:42Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 208,
          "url": "https://github.com/kungfu-systems/kungfu/pull/208",
          "title": "feat(rewind): add CostSnapshot open-layer event (msg_type 30008)",
          "body": "Mint the wire form of the parsed cost contract: rewind open-layer CostSnapshot (msg_type 30008), SCHEMA_VERSION 1->2, tail-only additive. Fixture rewind-demo-cost-wire proves round-trip + honesty bits + schema-only reflection decode + bundle binding.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:55:55Z",
          "mergedAt": "2026-07-04T08:56:00Z",
          "additions": 729,
          "deletions": 5,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 209,
          "url": "https://github.com/kungfu-systems/kungfu/pull/209",
          "title": "feat(capability): OS sandbox launcher for the default tier — macOS (ADR-0013 Phase 3)",
          "body": "The isolation base for the default tier: launch an untrusted guest inside an OS default-deny sandbox so its **only egress is the capability relay** (Phase 2) on its stdio. Filesystem writes and the network are denied; reads are allowed (an interpreter must read its own runtime — a coarse boundary the ADR records as residual risk).\n\n- `sandbox-launcher.ts` — wrap a command in a Seatbelt profile via `sandbox-exec` on macOS. **Linux (Landlock + seccomp + namespaces) is not implemented yet and is refused, not run unconfined** — a silent no-op sandbox is worse than a visible gap.\n- fixture `kfx-demo-sandbox-launch` (verify --full stage 6, macOS only) — composes launcher + transport + host: a guest under the sandbox relays a capability call through its stdio, while a filesystem write and a network connection are **both denied**.\n\n**Validated on macOS arm64** (this machine): relay works through the sandbox, `/tmp` write → PermissionError, socket connect → PermissionError, no leak file created.\n\nCompletes the default-tier isolation: Phase 1 refuses untrusted in-process adapters, Phase 2 gave the relay a subprocess channel, Phase 3 confines that subprocess. Builds on #204/#206/#207. Remaining: Phase 4 (install-time trust consent), the Linux launcher, and the packaged first-party-manifest bake.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:58:13Z",
          "mergedAt": "2026-07-04T08:58:30Z",
          "additions": 159,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 210,
          "url": "https://github.com/kungfu-systems/kungfu/pull/210",
          "title": "docs(governance): define provider-risk boundaries",
          "body": "Merge docs/open-source-provider-governance into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:58:22Z",
          "mergedAt": "2026-07-04T08:59:02Z",
          "additions": 281,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 420,
          "url": "https://github.com/kungfu-systems/buildchain/pull/420",
          "title": "chore(release): promote v2.4.9",
          "body": "## Summary\n- Promote alpha/v2/v2.4 to release/v2/v2.4 after Buildchain RC wrapper fix.\n- Stable release should publish Buildchain 2.4.9 and move v2/v2.4 refs.\n\n## Release intent\n- Channel: release\n- Source: alpha/v2/v2.4\n- Target: release/v2/v2.4\n- Alpha verified: 2.4.9-alpha.1\n\n## Verification\n- PR #417 merged after Verify and Build Surface Fixture passed.\n- PR #418 produced PR-stage RC artifacts and alpha promote-only resolved RC evidence.\n- Alpha finalization published npm alpha dist-tag 2.4.9-alpha.1 and moved v2.4-alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:57:22Z",
          "mergedAt": "2026-07-04T08:59:48Z",
          "additions": 70,
          "deletions": 9,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 421,
          "url": "https://github.com/kungfu-systems/buildchain/pull/421",
          "title": "docs(governance): define provider-risk boundaries",
          "body": "Add public governance boundaries for trademarks, official services, and upstream provider compliance.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:00:50Z",
          "mergedAt": "2026-07-04T09:00:56Z",
          "additions": 281,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 422,
          "url": "https://github.com/kungfu-systems/buildchain/pull/422",
          "title": "Release v2.4.9",
          "body": "Create the generated version-state commit for v2.4.9.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:01:54Z",
          "mergedAt": "2026-07-04T09:03:52Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 423,
          "url": "https://github.com/kungfu-systems/buildchain/pull/423",
          "title": "Prepare v2.4.10-alpha.0",
          "body": "Create the generated version-state commit for v2.4.10-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:06:26Z",
          "mergedAt": "2026-07-04T09:08:00Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 211,
          "url": "https://github.com/kungfu-systems/kungfu/pull/211",
          "title": "feat(kfx): disclose the trust verdict at install time (ADR-0013 Phase 4)",
          "body": "`kungfu kfx install` extracted a package with no word about the trust it would run at — the install-time trust prompt ADR-0013 and `docs/extensions.md` called for. This discloses it, so the trust grant is informed.\n\n- A package is **first-party (trusted)** or **third-party (untrusted)** by source, never by the install path.\n- Each declared facet's consequence is stated at install:\n  - a **view** runs `node-integrated` (trusted) or `sandboxed-ipc` (untrusted, isolated + declared capabilities only);\n  - an **untrusted adapter will be REFUSED** at trace time — it runs in-process in the traced program and cannot be sandboxed, so only a source-verified first-party adapter may inject.\n- `kfx list` gains the same first-party/third-party marker (and a `trusted` field in `--json`).\n\n`first_party.is_first_party(key)` is the shared membership check; `test_kfx_trust_notice` covers trusted/untrusted × view/adapter. Reuses the frozen first-party set from #206.\n\nCompletes the ADR-0013 implementation surface (Phases 0-4): trust by verifiable origin, refuse untrusted in-process adapters, sandboxed transport, OS isolation, and now the install-time consent surface. Remaining follow-ups: the Linux launcher and the packaged first-party-manifest bake.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:08:42Z",
          "mergedAt": "2026-07-04T09:08:45Z",
          "additions": 89,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 425,
          "url": "https://github.com/kungfu-systems/buildchain/pull/425",
          "title": "fix(release): update default branch before pending version PR",
          "body": "## Summary\n- update release promotion so the active dev line becomes the GitHub default branch before returning a pending next-alpha version-state PR\n- add regression coverage for protected alpha branches that require a generated version-state PR\n- rebuild the promote-buildchain-ref action bundle\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check\n\nNo alpha promotion is requested for this change.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:28:12Z",
          "mergedAt": "2026-07-04T09:29:50Z",
          "additions": 119,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 213,
          "url": "https://github.com/kungfu-systems/kungfu/pull/213",
          "title": "feat(rewind): managed provider run emits a CostSnapshot event",
          "body": "run_managed launches codex/claude in structured-output mode, parses usage via the cost adapters, and emits a CostSnapshot journal event (msg_type 30008) bound to the run. Process runner + emit sink injected; fixture rewind-demo-managed-run proves the wiring flatbuffers-only.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:31:35Z",
          "mergedAt": "2026-07-04T09:31:41Z",
          "additions": 398,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 214,
          "url": "https://github.com/kungfu-systems/kungfu/pull/214",
          "title": "feat(capability): Linux OS sandbox launcher via bubblewrap (ADR-0013)",
          "body": "Implements the default-tier OS sandbox on **Linux**, so the isolation base is no longer macOS-only (Phase 3 shipped Seatbelt; Linux was explicitly refused).\n\n- `sandbox-launcher.ts` — on Linux, wrap the guest in **bubblewrap** (`bwrap --unshare-all --ro-bind / / --proc /proc --dev /dev --die-with-parent`): a read-only root (every write denied), an unshared empty network namespace (no network), its own user/pid/mount namespaces, dies with the parent. Inherited stdio is untouched, so the capability relay still flows. This is the practical unprivileged sandbox where raw namespaces are blocked (Ubuntu's AppArmor unprivileged-userns restriction) but bwrap is permitted; **if bwrap is absent the launch is refused, never run unconfined**.\n- `isOsSandboxSupported()` now reports Linux support by bwrap presence; the `kfx-demo-sandbox-launch` fixture runs on Linux too (skip logic moved into `parent.mjs`), and its denial assertions accept `OSError` (EPERM on Seatbelt, EROFS / no-route on bwrap).\n\n**Validated on real hardware (both platforms):**\n- macOS arm64: relay works, `/tmp` write → PermissionError, socket → PermissionError.\n- Linux (Ubuntu 24.04, kernel 6.8, bwrap): relay works through the sandbox, `/tmp` write denied, network denied, no leak file — the fixture's 3 assertions pass end-to-end.\n\nFollow-up remaining: the packaged first-party-manifest bake. Landlock (available on the kernel) could later add finer-grained read confinement; bwrap's read-only root is the coarse boundary the ADR records as residual risk.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:32:30Z",
          "mergedAt": "2026-07-04T09:34:12Z",
          "additions": 66,
          "deletions": 23,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 212,
          "url": "https://github.com/kungfu-systems/kungfu/pull/212",
          "title": "docs(governance): add PR risk checklist",
          "body": "## Summary\n\nAdd a lightweight governance risk checklist to the pull request template.\n\n## Verification\n\n- git diff --check\n- public leakage scan for Atlas/Codex/Claude/AI-maintenance/local paths\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR only updates the PR template so future changes surface these boundaries explicitly.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-04T09:22:35Z",
          "mergedAt": "2026-07-04T09:38:36Z",
          "additions": 14,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 424,
          "url": "https://github.com/kungfu-systems/buildchain/pull/424",
          "title": "docs(governance): add PR risk checklist",
          "body": "## Summary\n\nAdd a lightweight governance risk checklist to the pull request template.\n\n## Verification\n\n- git diff --check\n- public leakage scan for Atlas/Codex/Claude/AI-maintenance/local paths\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR only updates the PR template so future changes surface these boundaries explicitly.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-04T09:22:35Z",
          "mergedAt": "2026-07-04T09:38:40Z",
          "additions": 14,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 14,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/14",
          "title": "feat(trust): add public trust entrypoint",
          "body": "## Summary\n\nAdd a public trust page and homepage entrypoint for Kungfu's trust posture.\n\n## Changes\n\n- Add `/trust/index.html` with open source, local-first, release evidence, provider compliance, branding, and acceptable-use boundaries.\n- Link the trust page from the homepage.\n- Add a PR template with the governance risk checklist.\n- Extend build/check scripts to verify the trust page.\n\n## Verification\n\n- bash -n scripts/build-site.sh scripts/check-site.sh\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- git diff --check\n- public leakage scan for Atlas/AI-maintenance/local paths\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above",
          "author": "kungfu-origin",
          "createdAt": "2026-07-04T09:22:35Z",
          "mergedAt": "2026-07-04T09:38:43Z",
          "additions": 213,
          "deletions": 0,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 426,
          "url": "https://github.com/kungfu-systems/buildchain/pull/426",
          "title": "feat(release): complete promote-only native wrapper",
          "body": "## Summary\n- make release-candidate-promote.yml a complete promote-only native package wrapper\n- resolve, download, and validate PR-stage payload artifacts before promotion\n- generate or pass publish-required-artifacts-json and forward package set, dist-tag, trusted publishing, required status check, and release passport inputs\n- preserve build-free promotion semantics so channel merge reuses the PR-stage native matrix output\n\n## Validation\n- node --test tests/release-candidate.test.mjs tests/build-surface.test.mjs\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:42:26Z",
          "mergedAt": "2026-07-04T09:44:03Z",
          "additions": 309,
          "deletions": 8,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 215,
          "url": "https://github.com/kungfu-systems/kungfu/pull/215",
          "title": "feat(first-party): bake the frozen manifest for packaged/frozen builds (ADR-0013)",
          "body": "Closes the last ADR-0013 gap: a frozen CLI and a packaged app have no source `extensions/` tree, so the first-party set was empty and they trusted **only** system views (adapters all refused). Bake the manifest at build time and read it at runtime, so both grant trust by verifiable source.\n\n- **generation** — `gen-first-party-manifest.mjs` + an electron-builder `beforePack` hook write `first-party.json` into `dist/kungfu` (which ships to `Resources/kungfu`). The **pinned** build records each built view bundle's content hash; a key whose bundle is not built is **omitted** (stays untrusted) rather than trusted by key alone — an unpinned entry in a shipped manifest would be forgeable.\n- **frozen CLI read-path** — `first_party.py` resolves the set as `KF_FIRST_PARTY_MANIFEST`, then the manifest baked next to the executable, then a source scan (dev).\n- **packaged GUI** — main points the packaged manifest at `Resources/kungfu/first-party.json`.\n\n**Validated (units):** the generator pins built bundles and omits unbuilt ones; the beforePack hook bakes the manifest; the supervisor reads the baked manifest next to a (simulated) executable, with the env manifest taking precedence; TS typechecks, Python ruff-clean, pytest added. The full electron-builder package run is not exercised in CI here — the hook is proven in isolation.\n\nThis completes the ADR-0013 implementation surface end to end (design → decision C → Phases 0-4 → dual-platform OS isolation → packaged bake). Follow-up beyond trust: shipping built-in extensions to a read-only packaged location, and Landlock read-confinement on Linux.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:53:14Z",
          "mergedAt": "2026-07-04T09:53:17Z",
          "additions": 134,
          "deletions": 11,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 428,
          "url": "https://github.com/kungfu-systems/buildchain/pull/428",
          "title": "feat(release): derive npm RC required artifacts",
          "body": "## Summary\n- derive default npm publish-required-artifacts-json from downloaded PR-stage .tgz payloads\n- read package/package.json for real scoped package name/version and compute npm sha512 integrity from tarball bytes\n- mark publish-package-main as role=main and other npm tarballs as role=platform\n- keep release-candidate-promote.yml build-free and declarative for consumers\n\n## Validation\n- node --test tests/release-candidate.test.mjs tests/build-surface.test.mjs\n- corepack pnpm run check\n- bash scripts/check-workflows.sh\n\n## Release\n- dev-only per instruction; do not promote alpha/release yet",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:56:13Z",
          "mergedAt": "2026-07-04T09:57:53Z",
          "additions": 191,
          "deletions": 11,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 427,
          "url": "https://github.com/kungfu-systems/buildchain/pull/427",
          "title": "chore(release): promote v2.4 alpha",
          "body": "## Summary\n- promote dev/v2/v2.4 to alpha/v2/v2.4 after PR #426\n- publishes the Buildchain release-candidate promote wrapper changes through the alpha channel\n\n## Validation\n- dev/v2/v2.4 Verify succeeded on 012cdcde47b96e1d45715722e1988fe2434d08fc",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:45:36Z",
          "mergedAt": "2026-07-04T10:02:37Z",
          "additions": 904,
          "deletions": 14,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 216,
          "url": "https://github.com/kungfu-systems/kungfu/pull/216",
          "title": "fix(core): include <queue> in yijinjing journal.h",
          "body": "journal.h declares std::priority_queue has_data_journals_heap_ but only included <mutex>; it failed to compile on gcc/libstdc++ (priority_queue does not name a template type). Caught by a native core build on Linux. One-line include fix.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:03:20Z",
          "mergedAt": "2026-07-04T10:03:25Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 429,
          "url": "https://github.com/kungfu-systems/buildchain/pull/429",
          "title": "Prepare v2.4.10-alpha.1",
          "body": "Create the generated version-state commit for v2.4.10-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:04:48Z",
          "mergedAt": "2026-07-04T10:06:34Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 430,
          "url": "https://github.com/kungfu-systems/buildchain/pull/430",
          "title": "feat(release): dogfood RC promote wrapper",
          "body": "## Summary\n- route Buildchain self-promotion through the declarative release-candidate-promote reusable workflow\n- derive channel and target SHA in the wrapper so callers only pass release intent inputs\n- move workflow-friction reporting into the wrapper and update tests/inventory docs to forbid hand-wired resolver/promote steps\n\n## Verification\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:17:00Z",
          "mergedAt": "2026-07-04T10:18:48Z",
          "additions": 130,
          "deletions": 139,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 431,
          "url": "https://github.com/kungfu-systems/buildchain/pull/431",
          "title": "chore(release): promote v2.4 alpha",
          "body": "## Summary\n- promote dev/v2/v2.4 into alpha/v2/v2.4 after the dogfood RC promote wrapper change\n- this validates Buildchain self-promotion through declarative release-candidate-promote inputs\n\n## Verification\n- dev branch checks are green on PR #430\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:19:16Z",
          "mergedAt": "2026-07-04T10:21:23Z",
          "additions": 130,
          "deletions": 139,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 432,
          "url": "https://github.com/kungfu-systems/buildchain/pull/432",
          "title": "fix(release): allow self-promotion artifact reads",
          "body": "## Summary\n- grant actions: read to the Buildchain self-promotion caller so the declarative RC promote wrapper can resolve PR-stage artifacts\n- add inventory and unit coverage for that permission contract\n\n## Verification\n- bash scripts/check-workflows.sh\n- node scripts/check-inventory.mjs\n- node --test tests/build-surface.test.mjs\n- corepack pnpm run check\n\n## Notes\n- fixes the startup failure observed in Buildchain Ref Promotion run 28703197341 after PR #431 merged to alpha\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:25:31Z",
          "mergedAt": "2026-07-04T10:27:20Z",
          "additions": 3,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 433,
          "url": "https://github.com/kungfu-systems/buildchain/pull/433",
          "title": "chore(release): promote v2.4 alpha",
          "body": "## Summary\n- promote the self-promotion artifact-read permission fix into alpha/v2/v2.4\n- rerun Buildchain dogfood promotion through the declarative RC promote wrapper\n\n## Verification\n- dev branch PR #432 is green\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:27:41Z",
          "mergedAt": "2026-07-04T10:29:14Z",
          "additions": 3,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 435,
          "url": "https://github.com/kungfu-systems/buildchain/pull/435",
          "title": "fix(release): prepare package manager in promote wrapper",
          "body": "## Summary\n- install promotion dependencies inside release-candidate-promote.yml according to the declarative package-manager input\n- set Buildchain self dogfood to package-manager: pnpm without adding hand-wired setup or resolver steps\n- cover the wrapper setup and self dogfood declaration in build-surface tests\n\n## Verification\n- bash scripts/check-workflows.sh\n- node scripts/check-inventory.mjs\n- node --test tests/build-surface.test.mjs\n- corepack pnpm run check\n\n## Notes\n- follows up Buildchain Ref Promotion run 28703376291, where the wrapper resolved the PR-stage RC but failed because pnpm was not available for lifecycle.verify\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:33:23Z",
          "mergedAt": "2026-07-04T10:34:57Z",
          "additions": 40,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 436,
          "url": "https://github.com/kungfu-systems/buildchain/pull/436",
          "title": "chore(release): promote v2.4 alpha",
          "body": "## Summary\n- promote the package-manager preparation fix into alpha/v2/v2.4\n- rerun Buildchain self dogfood through release-candidate-promote.yml without hand-wired setup steps\n\n## Verification\n- dev branch PR #435 is green\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:35:18Z",
          "mergedAt": "2026-07-04T10:36:53Z",
          "additions": 40,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 437,
          "url": "https://github.com/kungfu-systems/buildchain/pull/437",
          "title": "Prepare v2.4.10-alpha.2",
          "body": "Create the generated version-state commit for v2.4.10-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:39:12Z",
          "mergedAt": "2026-07-04T10:40:59Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 217,
          "url": "https://github.com/kungfu-systems/kungfu/pull/217",
          "title": "feat(rewind): record human control decisions (ApprovalDecision, msg_type 30009)",
          "body": "ApprovalDecision open-layer event (30009): approve/deny/interrupt/resume recorded as a run fact; approvals.apply_decision returns the ControlAction a session driver applies (SIGINT / input). Provider approval-prompt detection is out of scope; interrupt/resume ride the terminal capability's kill/write. Fixture rewind-demo-approval + native-validatable.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:42:20Z",
          "mergedAt": "2026-07-04T10:42:24Z",
          "additions": 540,
          "deletions": 7,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 438,
          "url": "https://github.com/kungfu-systems/buildchain/pull/438",
          "title": "chore(release): promote v2.4.10",
          "body": "## Summary\n- promote alpha/v2/v2.4 to release/v2/v2.4 for Buildchain v2.4.10\n- includes declarative release-candidate-promote wrapper dogfood, npm artifact evidence generation, and self-promotion package-manager preparation\n\n## Verification\n- alpha promotion completed successfully through release-candidate-promote.yml\n- npm alpha dist-tag is 2.4.10-alpha.2\n- v2.4.10-alpha.2 and v2.4-alpha point at adba091\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:44:03Z",
          "mergedAt": "2026-07-04T10:45:55Z",
          "additions": 1078,
          "deletions": 154,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 218,
          "url": "https://github.com/kungfu-systems/kungfu/pull/218",
          "title": "build(core): prebuilt platform-package distribution + self-contained dist/kungfu",
          "body": "Ship @kungfu-tech/core prebuilt native binaries as npm platform packages: install becomes a no-op, build stages a self-contained dist/kungfu (bundling libnode), and the platform package packs it. Also decouples build from node-pre-gyp, fixes a Windows node-path space bug, stages versioned ELF sonames on linux, and de-vendors pybind11 (conan-provided). Validated on macOS arm64 and linux x64.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:48:25Z",
          "mergedAt": "2026-07-04T10:48:30Z",
          "additions": 528,
          "deletions": 18897,
          "changedFiles": 67
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 439,
          "url": "https://github.com/kungfu-systems/buildchain/pull/439",
          "title": "Release v2.4.10",
          "body": "Create the generated version-state commit for v2.4.10.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:47:50Z",
          "mergedAt": "2026-07-04T10:49:33Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 440,
          "url": "https://github.com/kungfu-systems/buildchain/pull/440",
          "title": "Prepare v2.4.11-alpha.0",
          "body": "Create the generated version-state commit for v2.4.11-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:52:04Z",
          "mergedAt": "2026-07-04T10:53:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 441,
          "url": "https://github.com/kungfu-systems/buildchain/pull/441",
          "title": "fix(release): use buildchain issue token for friction reports",
          "body": "## Summary\n- add an optional `buildchain-issue-token` reusable workflow secret for Buildchain-owned workflow-friction issue reporting\n- fallback issue reporting token through `BUILDCHAIN_PROMOTION_TOKEN` before `github.token`\n- document consumer mapping and add regression coverage so the report step cannot regress to fixed consumer `github.token`\n\n## Verification\n- corepack pnpm@11.7.0 run check:workflows\n- node --test tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:25:35Z",
          "mergedAt": "2026-07-04T11:27:15Z",
          "additions": 24,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 442,
          "url": "https://github.com/kungfu-systems/buildchain/pull/442",
          "title": "release: promote Buildchain 2.4 issue-token fix to alpha",
          "body": "## Summary\n- promote the workflow-friction issue-token fix from dev to alpha\n- keeps release-candidate-promote issue reporting cross-repository capable\n\n## Verification\n- PR #441 checks passed\n- local `corepack pnpm@11.7.0 run check` passed before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:27:43Z",
          "mergedAt": "2026-07-04T11:30:02Z",
          "additions": 24,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 444,
          "url": "https://github.com/kungfu-systems/buildchain/pull/444",
          "title": "fix(release): mint buildchain issue token from app credentials",
          "body": "## Summary\n- let `release-candidate-promote.yml` mint a Buildchain issue-report token from GitHub App credentials\n- keep explicit issue token / promotion token / `github.token` fallbacks for existing consumers\n- update wrapper docs so consumers pass declarative App credentials instead of hand-wiring token creation\n\n## Verification\n- corepack pnpm@11.7.0 run check:workflows\n- node --test tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:34:36Z",
          "mergedAt": "2026-07-04T11:36:09Z",
          "additions": 71,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 443,
          "url": "https://github.com/kungfu-systems/buildchain/pull/443",
          "title": "Prepare v2.4.11-alpha.1",
          "body": "Create the generated version-state commit for v2.4.11-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:32:32Z",
          "mergedAt": "2026-07-04T11:36:53Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 219,
          "url": "https://github.com/kungfu-systems/kungfu/pull/219",
          "title": "fix(core): stage dist/kungfu completely on Windows",
          "body": "On Windows, run-build.js stage() staged nothing usable into dist/kungfu: single-config Ninja emits the addons into build/ (not build/<buildType>), glob.sync received a backslash path it treats as an escape, and *.pyd was missing from the pattern list. Search both build dirs on Windows, use glob's cwd option, and add *.pyd. Verified on a Windows self-hosted build: dist/kungfu now bundles kungfu_node.node, pykungfu.pyd, drone.node, link_node.node and libnode.dll. No behavior change on macOS/Linux.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:37:07Z",
          "mergedAt": "2026-07-04T11:37:12Z",
          "additions": 27,
          "deletions": 7,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 220,
          "url": "https://github.com/kungfu-systems/kungfu/pull/220",
          "title": "feat(rewind): managed-run CLI — run a provider and report its cost",
          "body": "One command joins the chain: discover the provider, run it under management (managed_run), bracket the run on a real journal (RunBegin/CostSnapshot/RunEnd), finalize a trace bundle, and print the cost with attribution + a proof path. Verified end to end against a real claude --print run.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:37:41Z",
          "mergedAt": "2026-07-04T11:37:45Z",
          "additions": 149,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 445,
          "url": "https://github.com/kungfu-systems/buildchain/pull/445",
          "title": "release: promote Buildchain issue app token support to alpha",
          "body": "## Summary\n- promote GitHub App-backed Buildchain issue token support into alpha\n- includes prior issue-token fallback fix plus wrapper-level App installation token creation\n\n## Verification\n- PR #444 checks passed\n- local `corepack pnpm@11.7.0 run check` passed",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:37:17Z",
          "mergedAt": "2026-07-04T11:40:58Z",
          "additions": 71,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 446,
          "url": "https://github.com/kungfu-systems/buildchain/pull/446",
          "title": "Prepare v2.4.11-alpha.2",
          "body": "Create the generated version-state commit for v2.4.11-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:43:34Z",
          "mergedAt": "2026-07-04T11:45:27Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 447,
          "url": "https://github.com/kungfu-systems/buildchain/pull/447",
          "title": "release: promote Buildchain 2.4.11",
          "body": "## Summary\n- promote Buildchain 2.4.11 to the stable release channel\n- includes `release-candidate-promote.yml` GitHub App-backed workflow-friction issue reporting\n- includes issue-token fallback support and docs/tests\n\n## Verification\n- PR #441 checks passed and merged\n- PR #444 checks passed and merged\n- PR #445 alpha promotion succeeded\n- alpha dist-tag is 2.4.11-alpha.2",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:47:22Z",
          "mergedAt": "2026-07-04T11:49:15Z",
          "additions": 86,
          "deletions": 4,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 448,
          "url": "https://github.com/kungfu-systems/buildchain/pull/448",
          "title": "Release v2.4.11",
          "body": "Create the generated version-state commit for v2.4.11.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:51:24Z",
          "mergedAt": "2026-07-04T11:53:05Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 449,
          "url": "https://github.com/kungfu-systems/buildchain/pull/449",
          "title": "Prepare v2.4.12-alpha.0",
          "body": "Create the generated version-state commit for v2.4.12-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:55:24Z",
          "mergedAt": "2026-07-04T11:57:03Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 221,
          "url": "https://github.com/kungfu-systems/kungfu/pull/221",
          "title": "docs(adr): ADR-0014 extension execution contract — uniform capability surface",
          "body": "Record the developer-facing execution contract on top of ADR-0013's trust boundary: one uniform asynchronous capability surface across trust tiers (one source runs unchanged in either tier), zero-copy preserved for the trusted tier via an in-process short-circuit, and restriction expressed as transparent interception rather than API removal so later confinement does not force extensions to be rewritten. Status proposed; implementation deferred to a follow-up.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:58:30Z",
          "mergedAt": "2026-07-04T11:58:35Z",
          "additions": 189,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 15,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/15",
          "title": "feat(layout): generate shared header and footer",
          "body": "## Summary\n\nGenerate the site header and footer from one shared layout source so the home and trust pages cannot drift independently.\n\n## Changes\n\n- Add `site/shared-layout.json` as the single source for brand, navigation, and footer content.\n- Add `scripts/render-shared-layout.mjs` to rewrite marked header/footer regions in each page.\n- Run the renderer from `scripts/build-site.sh` and validate drift from `scripts/check-site.sh`.\n- Update the home and trust pages to use shared header/footer markers and matching `site-*` layout classes.\n- Document the shared layout workflow in `README.md`.\n\n## Verification\n\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `bash -n scripts/build-site.sh scripts/check-site.sh`\n- `git diff --check`\n- Playwright DOM smoke on desktop home and mobile trust pages: one header, one footer, matching nav links, matching footer text, no horizontal overflow.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis touches official site branding/navigation/footer presentation only. The shared source keeps the visible Kungfu brand, repository, feedback, trust, security, and footer text consistent across pages.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:45:48Z",
          "mergedAt": "2026-07-04T13:16:06Z",
          "additions": 237,
          "deletions": 26,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 222,
          "url": "https://github.com/kungfu-systems/kungfu/pull/222",
          "title": "feat(gui): managed-run inbox in the terminal + kungfu managed-run command",
          "body": "The GUI terminal opens on an inbox of managed-run profiles; picking one runs a provider under management and reports its cost. Adds the 'kungfu managed-run' console subcommand and reworks the terminal view into an inbox + run terminal. Verified end to end in the GUI against a real claude run.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T13:28:47Z",
          "mergedAt": "2026-07-04T13:28:52Z",
          "additions": 277,
          "deletions": 47,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 45,
          "url": "https://github.com/kungfu-systems/libnode/pull/45",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.9",
          "body": "Publish @kungfu-tech/libnode 22.22.3-kf.3-alpha.9 through the Buildchain v2 release-candidate promotion flow.\\n\\nThis PR includes the libnode-side migration to the stable Buildchain v2 release-candidate promote wrapper so the PR build produces the reusable release-candidate evidence and the alpha branch push promotes that evidence to npm without a second heavy build.\\n\\nExpected flow:\\n- one alpha channel PR: dev/v22/v22.22 -> alpha/v22/v22.22\\n- one three-platform Build workflow run\\n- Release - New Version promote-only publish after merge\\n\\nVerified before opening:\\n- corepack pnpm verify-package-source\\n- git diff --check\\n- npm official registry returns 404 for 22.22.3-kf.3-alpha.9 before publish\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T13:21:26Z",
          "mergedAt": "2026-07-04T13:40:24Z",
          "additions": 37,
          "deletions": 136,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 46,
          "url": "https://github.com/kungfu-systems/libnode/pull/46",
          "title": "ci: align release candidate artifact patterns",
          "body": "Fix the libnode-side Release - New Version declaration so Buildchain v2 release-candidate-promote can resolve the PR-stage payload artifacts produced by the Build workflow.\\n\\nProblem observed in Release - New Version run 28708019670 after PR #45 merged:\\n- Buildchain resolver expected at least 4 PR-stage payload artifacts but found 1.\\n- The PR Build run 28707537788 actually produced platform payload artifacts named libnode-macos-arm64-*, libnode-linux-x64-*, and libnode-windows-x64-*.\\n- The libnode wrapper had declared npm/os names libnode-darwin-arm64-* and libnode-win32-x64-* and required 4 payload containers.\\n\\nThis PR aligns the wrapper with the Buildchain artifact names and the three-platform payload count.\\n\\nThis is an extra PR caused by the previous libnode declaration bug; the prior three-platform Build run was already successful but the old alpha-side workflow could not promote it.\\n\\nVerified locally:\\n- actionlint .github/workflows/release-new-version.yml\\n- YAML parse\\n- git diff --check\\n- offline pattern check against PR #45 artifact names matched 3 payload artifacts\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T13:47:13Z",
          "mergedAt": "2026-07-04T14:10:12Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 223,
          "url": "https://github.com/kungfu-systems/kungfu/pull/223",
          "title": "feat(capability): uniform capability surface across trust tiers (ADR-0014 first delivery)",
          "body": "Assemble the binding-less guest host into one uniform asynchronous capability surface across trust tiers: the trusted co-resident tier short-circuits in-process and keeps zero-copy by reference, the default tier runs in an OS sandbox and reaches the host over the stdio relay (serialized copies). Adds the missing Node child-side guest proxy, a permissive first-delivery profile with independent write/network restriction knobs, and serializes relay frames with the bigint rule. Verified on macOS (Seatbelt) and Linux (bubblewrap): a JavaScript and a Python facet run unchanged in both tiers, and the restriction knobs narrow what a facet reaches without re-adapting it. ADR-0014 accepted.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T14:22:28Z",
          "mergedAt": "2026-07-04T14:22:33Z",
          "additions": 1132,
          "deletions": 67,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 47,
          "url": "https://github.com/kungfu-systems/libnode/pull/47",
          "title": "ci: test buildchain rc promote allow repository",
          "body": "Temporarily route Release - New Version through Buildchain train ref train/v2/v2.5/rc-promote-allow-repository so we can verify the release-candidate-promote allow-repository fix against libnode.\\n\\nContext:\\n- PR #46 fixed libnode artifact-pattern/count declaration.\\n- Release - New Version run 28708787668 resolved PR-stage RC evidence successfully but failed in promote-buildchain-ref with: Ref promotion is limited to kungfu-systems/buildchain; got kungfu-systems/libnode.\\n- The provided Buildchain train ref exposes allow-repository and defaults it to the caller repository.\\n\\nVerified locally:\\n- actionlint .github/workflows/release-new-version.yml\\n- YAML parse\\n- git diff --check\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T14:27:46Z",
          "mergedAt": "2026-07-04T14:54:31Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 224,
          "url": "https://github.com/kungfu-systems/kungfu/pull/224",
          "title": "refactor(core,api): remove legacy CLI commands and reduce api to the capability SDK",
          "body": "Remove the old quant-trading legacy: the login/backtest/run/assemble/tool/slicetool CLI commands and the serverless account module; the dead `cli` command (superseded by tui). Reduce @kungfu-tech/api to the capability SDK — the entire non-capability tree (trading config/data/stores, old-app config/utils/language/typings) is unused by v4 (gui/tui consume only /capability). Also fixes the guest-harness capability modules to build clean under the reference surfaces. @kungfu-tech/api, gui and tui all build clean.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T14:57:30Z",
          "mergedAt": "2026-07-04T14:57:35Z",
          "additions": 56,
          "deletions": 17374,
          "changedFiles": 86
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 453,
          "url": "https://github.com/kungfu-systems/buildchain/pull/453",
          "title": "feat(governance): add dev PR auto-merge workflow",
          "body": "## Summary\n- add a reusable dev PR auto-merge workflow for protected semver dev branches\n- add a Buildchain-owned policy engine for ready labels, block labels, approvals, required checks, same-repository heads, branch prefixes, max merges, dry-run, and sequential merge revalidation\n- document protected dev branch semantics and register the workflow in package-owned site facts\n\n## Verification\n- pnpm run check\n\n## Release line\n- target: dev/v2/v2.5\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T15:09:34Z",
          "mergedAt": "2026-07-04T15:11:34Z",
          "additions": 862,
          "deletions": 0,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 454,
          "url": "https://github.com/kungfu-systems/buildchain/pull/454",
          "title": "release: promote Buildchain 2.5 to alpha",
          "body": "Promote the reviewed Buildchain 2.5 development line into the alpha channel.\\n\\nRelease path:\\n- dev/v2/v2.5 -> alpha/v2/v2.5\\n- follow-up alpha/v2/v2.5 -> release/v2/v2.5 after alpha promotion completes\\n\\nValidation already completed on the dev PR and Buildchain fixture matrix; this PR intentionally uses the protected release-governance path so Buildchain Ref Promotion owns version-state, tags, passport, and npm trusted publishing evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T15:25:30Z",
          "mergedAt": "2026-07-04T15:27:31Z",
          "additions": 1076,
          "deletions": 60,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 457,
          "url": "https://github.com/kungfu-systems/buildchain/pull/457",
          "title": "release: promote Buildchain 2.5.0",
          "body": "Promote the tested Buildchain 2.5 alpha channel to the production release channel.\\n\\nRelease path:\\n- alpha/v2/v2.5 -> release/v2/v2.5\\n- tested alpha tag: v2.5.0-alpha.0\\n\\nBuildchain Ref Promotion owns the final version-state commit, exact v2.5.0 tag, floating v2.5/v2 refs, release passport, and next alpha preparation.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T15:30:37Z",
          "mergedAt": "2026-07-04T15:32:33Z",
          "additions": 1076,
          "deletions": 60,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 458,
          "url": "https://github.com/kungfu-systems/buildchain/pull/458",
          "title": "Release v2.5.0",
          "body": "Create the generated version-state commit for v2.5.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T15:34:52Z",
          "mergedAt": "2026-07-04T15:36:35Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 459,
          "url": "https://github.com/kungfu-systems/buildchain/pull/459",
          "title": "Prepare v2.5.1-alpha.0",
          "body": "Create the generated version-state commit for v2.5.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T15:39:12Z",
          "mergedAt": "2026-07-04T15:41:04Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 225,
          "url": "https://github.com/kungfu-systems/kungfu/pull/225",
          "title": "refactor: retire the dormant wingchun module",
          "body": "Remove the wingchun trading-semantics module end to end: the dead node-side instrument methods on Watcher, the entire pykungfu.wingchun binding surface, the headers-only src/libwingchun tree and its packaging manifest entries, and the disabled kungfu.wingchun python strategy framework with its unreferenced practice leaves. Core builds clean (configure/compile, 19/19 linked). Net 115 files, -32460.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T15:48:45Z",
          "mergedAt": "2026-07-04T15:48:50Z",
          "additions": 6,
          "deletions": 32460,
          "changedFiles": 115
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 460,
          "url": "https://github.com/kungfu-systems/buildchain/pull/460",
          "title": "fix: preserve Windows lifecycle sampler evidence",
          "body": "## Summary\n- make Windows process-tree sampling distinguish sampler unavailable from an empty process tree\n- capture wrapped lifecycle command stdout/stderr tails and exit evidence in process-summary and lifecycle error events\n- add regressions for Windows sampler fallback/unavailable state and sampled lifecycle failure evidence\n\n## Validation\n- pnpm run check\n\nNo consumer/libnode build was triggered.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T16:06:36Z",
          "mergedAt": "2026-07-04T16:15:35Z",
          "additions": 246,
          "deletions": 40,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 461,
          "url": "https://github.com/kungfu-systems/buildchain/pull/461",
          "title": "promote: dev to alpha v2.5",
          "body": "## Summary\nPromote the Windows lifecycle sampler evidence fix from dev/v2/v2.5 to alpha/v2/v2.5.\n\nIncludes PR #460: Windows process-tree sampler availability, wrapped command exit evidence, and Buildchain fixture dogfood for Windows descendants.\n\n## Validation\n- PR #460 check passed\n- PR #460 Build Surface Fixture passed on Linux/macOS/Windows\n- Windows diagnostics artifact: sampler unavailable=false, sampleCount=2, root cmd.exe with node descendant\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T16:16:07Z",
          "mergedAt": "2026-07-04T16:20:27Z",
          "additions": 246,
          "deletions": 40,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 462,
          "url": "https://github.com/kungfu-systems/buildchain/pull/462",
          "title": "Prepare v2.5.1-alpha.1",
          "body": "Create the generated version-state commit for v2.5.1-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T16:22:37Z",
          "mergedAt": "2026-07-04T16:24:27Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 463,
          "url": "https://github.com/kungfu-systems/buildchain/pull/463",
          "title": "release: promote Buildchain 2.5.1",
          "body": "## Summary\nPromote Buildchain v2.5.1 from alpha/v2/v2.5 to release/v2/v2.5.\n\nIncludes Windows lifecycle sampler fix from PR #460 and alpha version-state PR #462.\n\n## Validation\n- PR #460 Build Surface Fixture passed on Linux/macOS/Windows\n- Latest Windows diagnostics artifact: sampler unavailable=false, sampleCount=2, root cmd.exe with node descendant\n- Alpha promote-only publish completed: @kungfu-tech/buildchain alpha=2.5.1-alpha.1\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T16:24:51Z",
          "mergedAt": "2026-07-04T16:28:51Z",
          "additions": 247,
          "deletions": 41,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 464,
          "url": "https://github.com/kungfu-systems/buildchain/pull/464",
          "title": "Release v2.5.1",
          "body": "Create the generated version-state commit for v2.5.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T16:30:56Z",
          "mergedAt": "2026-07-04T16:32:56Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 465,
          "url": "https://github.com/kungfu-systems/buildchain/pull/465",
          "title": "Prepare v2.5.2-alpha.0",
          "body": "Create the generated version-state commit for v2.5.2-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T16:35:38Z",
          "mergedAt": "2026-07-04T16:37:24Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 226,
          "url": "https://github.com/kungfu-systems/kungfu/pull/226",
          "title": "feat: Windows AppContainer support for the sandbox membrane (ADR-0014)",
          "body": "Extend the uniform capability surface's default tier to Windows: the launcher applies an AppContainer via a native CreateProcess (libyijinjing spawn_app_container, exposed through the node binding), the host owns two named pipes as the relay, and the guest reaches the host over them. The full guest-host matrix runs green on Windows — a JavaScript and a Python facet, both trust tiers, over the AppContainer + named-pipe relay — alongside the existing macOS (Seatbelt) and Linux (bubblewrap) support. Includes the window-station grant a USER32-linked guest needs to initialize, link deps (userenv/advapi32/user32), and DeriveCapabilitySidsFromName resolved dynamically for SDK portability. Restriction knobs on Windows (network capability / write confinement) are a follow-up: AppContainer confines by capability and ACL rather than by syscall, which needs a further-restricted token to demonstrate write denial.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T22:36:28Z",
          "mergedAt": "2026-07-04T22:36:33Z",
          "additions": 844,
          "deletions": 26,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 227,
          "url": "https://github.com/kungfu-systems/kungfu/pull/227",
          "title": "refactor: fold the kfs SDK into the 'kungfu sdk' subcommand",
          "body": "Retire the standalone kfs command and reach the application-assembly toolkit as 'kungfu sdk': rename developer/sdk to sdk.js, add the sdk console subcommand (runs the SDK through embedded libnode like 'kungfu tui'), migrate every extension/example build to 'kungfu sdk kfx build', remove the kfs launcher/freeze chain (kungfu.spec/conanfile/run-freeze), and update docs, ADR-0009 and the welded-surface register. Net 44 files, +156 -221.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T23:54:26Z",
          "mergedAt": "2026-07-04T23:54:30Z",
          "additions": 156,
          "deletions": 221,
          "changedFiles": 44
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 228,
          "url": "https://github.com/kungfu-systems/kungfu/pull/228",
          "title": "refactor: rename the 'tui' command to 'cockpit'",
          "body": "Name the terminal reference surface by its experience: kungfu tui -> kungfu cockpit (an operator surface — monitor + config + mission ops). The Ink renderer stays the tui substrate (framework/tui, @kungfu-tech/tui, tui.mjs, Resources/tui); only the command/experience name changes. ~6 files, no package/dir/packaging changes.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T00:41:47Z",
          "mergedAt": "2026-07-05T00:41:52Z",
          "additions": 10,
          "deletions": 8,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 48,
          "url": "https://github.com/kungfu-systems/libnode/pull/48",
          "title": "ci: use stable buildchain v2 for release promotion",
          "body": "## Summary\n- remove the temporary Buildchain train runtime override\n- return release promotion to the stable floating Buildchain v2 wrapper\n\n## Validation\n- git diff --check\n- verified release-new-version.yml no longer contains buildchain-ref/train override\n\n## Release note\nThis PR is expected to trigger one Build PR-stage native matrix before alpha promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T15:43:35Z",
          "mergedAt": "2026-07-05T00:48:49Z",
          "additions": 0,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 229,
          "url": "https://github.com/kungfu-systems/kungfu/pull/229",
          "title": "refactor: retire the legacy indexer-live extension",
          "body": "indexer-live never migrated to v4: defunct 'kungfu sdk strategy/project' build verbs, no runtime caller for its slice-location hooks, unread useFor:replay manifest field, and a vestigial import of the removed pykungfu.wingchun binding. The rewind/replay path does not route through it. Remove the extension + its artifact dependency; no live capability affected.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T00:58:42Z",
          "mergedAt": "2026-07-05T00:58:46Z",
          "additions": 0,
          "deletions": 115,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 231,
          "url": "https://github.com/kungfu-systems/kungfu/pull/231",
          "title": "refactor: rename the kungfu.console package to kungfu.cli",
          "body": "The internal package is the CLI command-dispatch framework (commands/variants/bridging); 'console' reads ambiguously beside the cockpit operator surface. Rename kungfu.console -> kungfu.cli, updating every absolute import, the bridging run_module string, and two doc links. find_packages auto-discovers the package (packaging untouched); the runtime 'console' service location and PyInstaller's console flag are left alone. 34 files.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T01:21:54Z",
          "mergedAt": "2026-07-05T01:21:59Z",
          "additions": 23,
          "deletions": 23,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 230,
          "url": "https://github.com/kungfu-systems/kungfu/pull/230",
          "title": "fix(gui): ship a single core runtime in app bundle",
          "body": "## Summary\n- stop production packaging from copying workspace @kungfu-tech/core trees into the Electron app node_modules\n- ship the frozen runtime only from Contents/Resources/kungfu\n- add an afterPack bundle audit/prune hook and a manual audit:bundle command\n\n## Validation\n- ./kungfu-code build:core\n- ./kungfu-code freeze\n- ./kungfu-code package:app\n- ./kungfu-code verify\n- pnpm --filter @kungfu-tech/gui run audit:bundle -- framework/gui/dist/mac-arm64/Kungfu.app\n- packaged CLI entries returned 4.0.0-alpha.0\n- bounded GUI smoke loaded KFE_MAIN_OK\n\n## Bundle Result\n- Kungfu.app: 1.1G\n- Contents/Resources/kungfu: 744M\n- Contents/Resources/app: 32M\n- duplicate @kungfu-tech/core package trees: 0\n- .venv directories in app resources: 0\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T01:21:47Z",
          "mergedAt": "2026-07-05T01:22:43Z",
          "additions": 224,
          "deletions": 8,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 466,
          "url": "https://github.com/kungfu-systems/buildchain/pull/466",
          "title": "feat(patrol): add cadence patrol workflows",
          "body": "## Summary\n- add Buildchain patrol protocol workflow plus daily, weekly, and monthly reusable wrappers\n- dogfood the three cadence wrappers in Buildchain with scheduled/manual callers\n- add patrol engine tests, workflow contract tests, inventory coverage, and release governance docs\n\n## Verification\n- pnpm run check\n- daily/weekly/monthly local patrol dry-runs against dev/v2/v2.5\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:08:11Z",
          "mergedAt": "2026-07-05T02:09:59Z",
          "additions": 1014,
          "deletions": 2,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 467,
          "url": "https://github.com/kungfu-systems/buildchain/pull/467",
          "title": "chore(release): promote v2.5 patrol cadence to alpha",
          "body": "## Summary\n- Promote the patrol cadence workflow implementation from dev to alpha.\n\n## Release intent\n- Source: dev/v2/v2.5\n- Target: alpha/v2/v2.5\n- Expected promotion: next alpha for v2.5\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:10:47Z",
          "mergedAt": "2026-07-05T02:13:31Z",
          "additions": 1014,
          "deletions": 2,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 468,
          "url": "https://github.com/kungfu-systems/buildchain/pull/468",
          "title": "Prepare v2.5.2-alpha.1",
          "body": "Create the generated version-state commit for v2.5.2-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:15:57Z",
          "mergedAt": "2026-07-05T02:18:01Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 469,
          "url": "https://github.com/kungfu-systems/buildchain/pull/469",
          "title": "chore(release): promote v2.5.2 patrol cadence to stable",
          "body": "## Summary\n- Promote v2.5.2-alpha.1 to the stable v2.5 release line.\n\n## Release intent\n- Source: alpha/v2/v2.5\n- Target: release/v2/v2.5\n- Tested alpha: v2.5.2-alpha.1\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:20:36Z",
          "mergedAt": "2026-07-05T02:22:19Z",
          "additions": 1015,
          "deletions": 3,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 232,
          "url": "https://github.com/kungfu-systems/kungfu/pull/232",
          "title": "docs(skill): define Kungfu Skill architecture",
          "body": "## Summary\n- add ADR-0015 for Kungfu Skill as the agent context layer above kfx\n- add docs/skills.md covering SKILL.md minimal source, catalog/envelope injection, Node/Python manage modes, and kfx dependency composition\n- link the new design from README, docs/MAP.md, and ADR index\n\n## Validation\n- git diff --check\n\n## Risk\n- documentation only; implementation is explicitly marked as not yet landed",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:24:38Z",
          "mergedAt": "2026-07-05T02:25:40Z",
          "additions": 575,
          "deletions": 0,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 470,
          "url": "https://github.com/kungfu-systems/buildchain/pull/470",
          "title": "Release v2.5.2",
          "body": "Create the generated version-state commit for v2.5.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:24:09Z",
          "mergedAt": "2026-07-05T02:25:44Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 471,
          "url": "https://github.com/kungfu-systems/buildchain/pull/471",
          "title": "Prepare v2.5.3-alpha.0",
          "body": "Create the generated version-state commit for v2.5.3-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:28:12Z",
          "mergedAt": "2026-07-05T02:31:07Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 472,
          "url": "https://github.com/kungfu-systems/buildchain/pull/472",
          "title": "fix(patrol): allow weekly monthly reusable startup",
          "body": "## Summary\\n- grant weekly/monthly patrol wrappers the write-scoped permissions required by the shared patrol reusable core\\n- grant Buildchain weekly/monthly dogfood callers matching permissions so workflow_dispatch starts successfully\\n- add build-surface regression assertions for patrol wrapper and dogfood permissions\\n\\n## Verification\\n- node --test tests/build-surface.test.mjs tests/buildchain-patrol.test.mjs tests/dev-pr-auto-merge.test.mjs\\n- node scripts/check-inventory.mjs\\n- bash scripts/check-workflows.sh\\n- pnpm run check\\n\\n## Dogfood context\\n- daily dogfood dry-run passed on v2.5.2: run 28727207108\\n- weekly/monthly v2.5.2 dry-runs failed at startup because callers had read-only permissions while the nested reusable core requires write scopes",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:43:57Z",
          "mergedAt": "2026-07-05T02:45:47Z",
          "additions": 20,
          "deletions": 8,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 233,
          "url": "https://github.com/kungfu-systems/kungfu/pull/233",
          "title": "docs(skill): anchor skills in accountable agent work",
          "body": "## Summary\n- Anchor Kungfu Skills in accountable delegated agent work, not generic action-first agent skills.\n- Clarify that skill audit events belong to the responsibility trail / journal-backed proof model.\n- Keep the existing Skill -> catalog -> context envelope -> KFX trust gate architecture unchanged.\n\n## Verification\n- git diff --check\n- git show --check HEAD\n\n## Risk\n- Documentation-only change.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:44:54Z",
          "mergedAt": "2026-07-05T02:45:54Z",
          "additions": 29,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 473,
          "url": "https://github.com/kungfu-systems/buildchain/pull/473",
          "title": "Promote v2.5 patrol permission fix to alpha",
          "body": "## Summary\\n- promote the weekly/monthly patrol startup permission fix from dev to alpha\\n- required for Buildchain weekly/monthly dogfood workflow_dispatch to start successfully\\n\\n## Verification\\n- PR #472 checks passed\\n- dev/v2/v2.5 Verify run 28727318863 passed\\n- local pnpm run check passed before #472",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:46:57Z",
          "mergedAt": "2026-07-05T02:48:50Z",
          "additions": 20,
          "deletions": 8,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 474,
          "url": "https://github.com/kungfu-systems/buildchain/pull/474",
          "title": "Prepare v2.5.3-alpha.1",
          "body": "Create the generated version-state commit for v2.5.3-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:50:54Z",
          "mergedAt": "2026-07-05T02:52:47Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 475,
          "url": "https://github.com/kungfu-systems/buildchain/pull/475",
          "title": "Release v2.5.3 patrol permission fix",
          "body": "## Summary\\n- release Buildchain v2.5.3 with weekly/monthly patrol startup permission fix\\n- keeps daily/weekly/monthly dogfood wrappers startable when using the shared patrol core\\n\\n## Verification\\n- PR #472 checks passed\\n- local pnpm run check passed\\n- alpha promotion finalized as v2.5.3-alpha.1\\n- alpha/dev/v2.5 refs point at 10c00402f1e5500db3ed887881b6809ebdc3c635",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:55:26Z",
          "mergedAt": "2026-07-05T02:57:15Z",
          "additions": 21,
          "deletions": 9,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 476,
          "url": "https://github.com/kungfu-systems/buildchain/pull/476",
          "title": "Release v2.5.3",
          "body": "Create the generated version-state commit for v2.5.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:59:17Z",
          "mergedAt": "2026-07-05T03:01:15Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 477,
          "url": "https://github.com/kungfu-systems/buildchain/pull/477",
          "title": "Prepare v2.5.4-alpha.0",
          "body": "Create the generated version-state commit for v2.5.4-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T03:03:35Z",
          "mergedAt": "2026-07-05T03:05:35Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 234,
          "url": "https://github.com/kungfu-systems/kungfu/pull/234",
          "title": "feat(skill): add first Kungfu Skill CLI slice",
          "body": "## Summary\n- add framework/skill schemas, fixtures, and TypeScript helpers for SKILL.md-based Kungfu Skills\n- add Python skill parser/catalog/context registry plus kungfu skill validate/install/list/catalog/context/read/explain\n- add SDK skill scaffolding and update skill docs/ADR to first-slice implementation status\n\n## Verification\n- ./kungfu-code build:core\n- pnpm --filter @kungfu-tech/core run freeze\n- framework/core/dist/kungfu/kungfu --version\n- framework/core/dist/kungfu/kungfu -H /tmp/kungfu-skill-home skill validate framework/skill/fixtures/minimal --json\n- framework/core/dist/kungfu/kungfu -H /tmp/kungfu-skill-home skill context --path framework/skill/fixtures --source cli --manager python --json\n- framework/core/dist/kungfu/kungfu -H /tmp/kungfu-skill-home skill explain trace-failure-investigator --path framework/skill/fixtures --json\n- PYTHONPATH=framework/core/src/python uv run --frozen --project framework/core pytest framework/core/tests/python/test_skill.py\n- pnpm --filter @kungfu-tech/skill run build\n- uv run --frozen --project framework/core ruff check framework/core/src/python/kungfu/skill framework/core/src/python/kungfu/cli/commands/skill.py framework/core/tests/python/test_skill.py\n- node developer/sdk/src/sdk.js create skill /tmp/kungfu-skill-sdk-smoke --name \"Smoke Skill\"\n- ./kungfu-code verify\n\n## Follow-up scope\n- Node/Electron GUI manager injection\n- persistent audit events for advertised/read skills\n- kfx dependency install/dedup binding through the kfx registry\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T03:05:00Z",
          "mergedAt": "2026-07-05T03:05:37Z",
          "additions": 1108,
          "deletions": 44,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 478,
          "url": "https://github.com/kungfu-systems/buildchain/pull/478",
          "title": "fix(release): protect managed dev channel branches",
          "body": "## Summary\n- protect managed dev/alpha/release channel branches after Buildchain creates or advances them\n- require one approving review on managed channel branch protection\n- add promote-buildchain-ref coverage for created dev branch protection\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check\n- verified all current kungfu-systems dev branches require one approving review\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T04:05:28Z",
          "mergedAt": "2026-07-05T04:07:20Z",
          "additions": 218,
          "deletions": 47,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 235,
          "url": "https://github.com/kungfu-systems/kungfu/pull/235",
          "title": "feat(kfx-sandbox): Windows AppContainer restriction knobs — external-egress network observable + container-SID write-ACE deny-write",
          "body": "Windows AppContainer restriction knobs for the kfx sandbox (ADR-0014):\n\n- deny-network: an external-egress observable (short-timeout connect to TEST-NET 192.0.2.1) — the internetClient capability gates external egress only, so loopback and interface-presence both miss it; run-knobs uses this observable on win32.\n- deny-write: governed by the container SID's own write ACE (a lowbox token does not honour the user's own ACEs). The launcher passes the guest a scratch dir and grants the container SID write on it only under a permissive profile; deny-write leaves it ungranted so the write is refused. The runtime's TEMP is redirected to the AppContainer's own folder so it starts under every profile.\n- read-path ACLs codified into the launcher (grant the container SID read+execute on the interpreter/guest dirs + ancestor traverse), removing the need for manual icacls.\n- host fail-fast: the Windows host no longer deadlocks if a guest exits before connecting its relay pipes.\n\nFollow-up (tracked separately): named-pipe relay handshake robustness and deny-network guest startup under empty capabilities.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T05:06:03Z",
          "mergedAt": "2026-07-05T05:06:08Z",
          "additions": 393,
          "deletions": 27,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 236,
          "url": "https://github.com/kungfu-systems/kungfu/pull/236",
          "title": "docs: add facts before trust philosophy",
          "body": "## Summary\n- add docs/facts-before-trust.md as a public, engineering-facing philosophy article\n- link it from README, docs/MAP.md, and docs/design-philosophy.md\n- keep the public framing focused on facts before trust and local proof before control\n\n## Validation\n- git diff --check\n- verified facts-before-trust links resolve from README, docs/MAP.md, and docs/design-philosophy.md\n- checked public docs for Atlas / AI-maintenance leakage terms",
          "author": "dongkeren",
          "createdAt": "2026-07-05T05:35:07Z",
          "mergedAt": "2026-07-05T05:35:45Z",
          "additions": 167,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 237,
          "url": "https://github.com/kungfu-systems/kungfu/pull/237",
          "title": "feat(skill): inject context into managed runs",
          "body": "## Summary\n- add shared Python and TypeScript Skill context providers with on-demand prompt injection\n- let CLI managed-run build Python contexts and accept Node-generated context files\n- let Electron main write a GUI-managed Skill context envelope for child managed runs\n- add golden fixtures that keep Python and Node catalog/context envelopes schema-equivalent\n\n## Verification\n- PYTHONPATH=framework/core/src/python uv --project framework/core run python -m pytest framework/core/tests/python/test_skill.py -q\n- pnpm --filter @kungfu-tech/skill run test:golden\n- pnpm --filter @kungfu-tech/gui run build\n- pnpm --filter @kungfu-tech/tui run build\n- ./kungfu-code build:core\n- ./kungfu-code freeze\n- framework/core/dist/kungfu/kungfu --version\n- framework/core/dist/kungfu/kungfu --home /tmp/kf-skill-smoke skill context --path framework/skill/fixtures/minimal --json\n- framework/core/dist/kungfu/kungfu managed-run --help\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T05:55:58Z",
          "mergedAt": "2026-07-05T05:57:19Z",
          "additions": 625,
          "deletions": 16,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 479,
          "url": "https://github.com/kungfu-systems/buildchain/pull/479",
          "title": "feat(build): add S3 artifact relay transfer mode",
          "body": "## Summary\n\n- add opt-in `artifact-transfer-mode: s3-to-github-artifacts` to the reusable Buildchain build workflow\n- upload heavy platform payloads from build runners to S3, then rehydrate and verify them on a GitHub-hosted relay job before uploading standard GitHub artifacts\n- keep default `github-artifacts` behavior unchanged for forks and ordinary consumers\n- add Buildchain dogfood dispatch support for the relay mode through declarative workflow inputs\n- document org/repo variable and OIDC role configuration without hard-coding Kungfu private values\n\n## AWS/organization setup\n\n- Created AWS China bucket `kungfu-buildchain-artifact-relay` in `cn-north-1`.\n- Enabled public access block, SSE-S3 encryption, and 7-day lifecycle cleanup for `buildchain-artifacts/`.\n- Added GitHub OIDC China audience `sts.amazonaws.com.cn` to the existing provider.\n- Created OIDC roles `BuildchainArtifactRelayUpload` and `BuildchainArtifactRelayDownload` scoped to `repo:kungfu-systems/*:*` and the relay bucket prefix.\n- Set `kungfu-systems` org variables for bucket, region, prefix, role ARNs, and OIDC audience.\n\n## Validation\n\n- `node --check scripts/artifact-relay-s3.mjs`\n- `node --test tests/build-surface.test.mjs`\n- `bash scripts/check-workflows.sh`\n- `pnpm run check`\n- AWS read-only verification of OIDC audience, S3 public access block, bucket encryption, and lifecycle configuration\n\n## Risk\n\n- Relay mode is opt-in and fails before heavy matrix scheduling if bucket/region/role configuration is missing.\n- S3 objects are deleted only after GitHub artifact upload succeeds; failed relay runs retain objects for investigation and lifecycle cleanup removes stale payloads later.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T05:58:44Z",
          "mergedAt": "2026-07-05T06:12:51Z",
          "additions": 1096,
          "deletions": 7,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 480,
          "url": "https://github.com/kungfu-systems/buildchain/pull/480",
          "title": "release: promote dev v2.5 to alpha",
          "body": "Promote dev/v2/v2.5 to alpha/v2/v2.5 for the S3 artifact relay release.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:13:30Z",
          "mergedAt": "2026-07-05T06:15:24Z",
          "additions": 1314,
          "deletions": 54,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 482,
          "url": "https://github.com/kungfu-systems/buildchain/pull/482",
          "title": "fix: derive release candidate channel from PR base",
          "body": "Fix release-candidate generation for channel PR builds by deriving alpha/release/major from the PR base ref when publish-channel remains none.\\n\\nValidation:\\n- bash scripts/check-workflows.sh\\n- node --test tests/build-surface.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:18:16Z",
          "mergedAt": "2026-07-05T06:20:03Z",
          "additions": 24,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 484,
          "url": "https://github.com/kungfu-systems/buildchain/pull/484",
          "title": "chore: record alpha channel merge in dev topology",
          "body": "No file content changes. This records the already-merged alpha channel commit as a dev parent so the next dev/v2/v2.5 -> alpha/v2/v2.5 promotion PR is mergeable after the failed RC-passport promotion attempt.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:23:21Z",
          "mergedAt": "2026-07-05T06:26:24Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 483,
          "url": "https://github.com/kungfu-systems/buildchain/pull/483",
          "title": "release: promote dev v2.5 to alpha",
          "body": "Promote dev/v2/v2.5 to alpha/v2/v2.5 after the artifact relay and release-candidate channel derivation fixes.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:20:16Z",
          "mergedAt": "2026-07-05T06:28:14Z",
          "additions": 24,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 485,
          "url": "https://github.com/kungfu-systems/buildchain/pull/485",
          "title": "Prepare v2.5.4-alpha.1",
          "body": "Create the generated version-state commit for v2.5.4-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:30:19Z",
          "mergedAt": "2026-07-05T06:32:09Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 486,
          "url": "https://github.com/kungfu-systems/buildchain/pull/486",
          "title": "Release v2.5.4 artifact relay",
          "body": "Promote alpha/v2/v2.5 to release/v2/v2.5 after alpha publish of @kungfu-tech/buildchain@2.5.4-alpha.1.\\n\\nIncludes S3 artifact relay transfer mode, RC channel derivation, and the dev/alpha topology repair needed for the stable release path.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:33:09Z",
          "mergedAt": "2026-07-05T06:36:19Z",
          "additions": 1338,
          "deletions": 56,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 487,
          "url": "https://github.com/kungfu-systems/buildchain/pull/487",
          "title": "Release v2.5.4",
          "body": "Create the generated version-state commit for v2.5.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:38:26Z",
          "mergedAt": "2026-07-05T06:40:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 489,
          "url": "https://github.com/kungfu-systems/buildchain/pull/489",
          "title": "Fix release finalization non-fast-forward recovery",
          "body": "Fix Buildchain release finalization when the generated next-alpha commit cannot fast-forward the alpha channel ref.\\n\\nThe action now routes protected channel non-fast-forward updates through a generated version-state PR instead of failing after npm publish. This addresses workflow friction issue #488.\\n\\nValidation:\\n- node --test tests/promote-buildchain-ref.test.mjs\\n- bash scripts/check-workflows.sh\\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:47:41Z",
          "mergedAt": "2026-07-05T06:51:04Z",
          "additions": 156,
          "deletions": 44,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 490,
          "url": "https://github.com/kungfu-systems/buildchain/pull/490",
          "title": "chore(release): restore v2.5 channel topology",
          "body": "Restore v2.5 channel ancestry after the release channel had diverged from dev/alpha.\\n\\nThis PR intentionally keeps dev content unchanged while making alpha/v2/v2.5 and release/v2/v2.5 ancestors of dev again so future alpha/release promotions can finalize with normal fast-forward semantics.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:52:01Z",
          "mergedAt": "2026-07-05T06:53:43Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 491,
          "url": "https://github.com/kungfu-systems/buildchain/pull/491",
          "title": "release: promote v2.5.5 alpha",
          "body": "Promote the v2.5 line from dev to alpha with the release finalization recovery fix and S3 artifact relay support.\\n\\nThis keeps the release candidate path on the standard Buildchain channel workflow before stable promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:54:28Z",
          "mergedAt": "2026-07-05T06:56:18Z",
          "additions": 157,
          "deletions": 45,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 492,
          "url": "https://github.com/kungfu-systems/buildchain/pull/492",
          "title": "Prepare v2.5.5-alpha.0",
          "body": "Create the generated version-state commit for v2.5.5-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:58:25Z",
          "mergedAt": "2026-07-05T07:00:22Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 495,
          "url": "https://github.com/kungfu-systems/buildchain/pull/495",
          "title": "chore(release): make release ancestry visible to alpha",
          "body": "Repair the v2.5 channel graph after earlier squash-based channel promotion.\\n\\nThis PR keeps alpha content unchanged while making release/v2/v2.5 an ancestor of alpha/v2/v2.5 so the real alpha -> release promotion PR can merge cleanly and still satisfy Buildchain lineage rules.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:07:56Z",
          "mergedAt": "2026-07-05T07:09:43Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 493,
          "url": "https://github.com/kungfu-systems/buildchain/pull/493",
          "title": "release: promote v2.5.5 to stable",
          "body": "Promote Buildchain v2.5.5 from alpha to release.\\n\\nThis release includes first-class S3 artifact relay support and release finalization recovery for non-fast-forward next-alpha updates. The channel merge must use a merge commit to preserve alpha lineage.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:01:29Z",
          "mergedAt": "2026-07-05T07:11:38Z",
          "additions": 157,
          "deletions": 45,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 496,
          "url": "https://github.com/kungfu-systems/buildchain/pull/496",
          "title": "Prepare v2.5.5-alpha.1",
          "body": "Create the generated version-state commit for v2.5.5-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:11:53Z",
          "mergedAt": "2026-07-05T07:14:31Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 498,
          "url": "https://github.com/kungfu-systems/buildchain/pull/498",
          "title": "Release v2.5.5",
          "body": "Create the generated version-state commit for v2.5.5.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:13:36Z",
          "mergedAt": "2026-07-05T07:15:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 239,
          "url": "https://github.com/kungfu-systems/kungfu/pull/239",
          "title": "docs: state fact-first product goal",
          "body": "## Summary\n- state the product goal in README: make fact-first responsibility the path of least resistance\n- add a Product Goal section to docs/facts-before-trust.md\n- connect the goal from docs/design-philosophy.md\n\n## Validation\n- git diff --check\n- checked the public docs patch for Atlas or AI-maintenance leakage terms",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:16:27Z",
          "mergedAt": "2026-07-05T07:17:18Z",
          "additions": 34,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 238,
          "url": "https://github.com/kungfu-systems/kungfu/pull/238",
          "title": "feat(gui,terminal): managed session workspace with main-process host (ADR-0016 stage 1)",
          "body": "Multi-pane managed session workspace in the GUI: run and watch several PTY-backed agent sessions on one screen. Adds the tmux durability backend to the terminal capability (detach/discover/reattach), runs the session host in the main process behind KF_TERMINAL_HOST=main (ADR-0016 stage 1), persists and restores the workspace layout, and fixes real-app blockers found on device (renderer node: bundling, discover race, sizing, and loading each kfx view's sibling stylesheet).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:51:27Z",
          "mergedAt": "2026-07-05T07:19:45Z",
          "additions": 1955,
          "deletions": 225,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 500,
          "url": "https://github.com/kungfu-systems/buildchain/pull/500",
          "title": "fix(release): bind finalization to transaction alpha source",
          "body": "## Summary\n- bind release finalization to the alpha source recorded by the durable release transaction\n- avoid selecting a later next-alpha tag when stable release-state finalization resumes after next-alpha has advanced\n- add a regression test for the 2.5.5 finalization failure mode\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- bash scripts/check-workflows.sh\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:26:06Z",
          "mergedAt": "2026-07-05T07:27:53Z",
          "additions": 245,
          "deletions": 50,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 501,
          "url": "https://github.com/kungfu-systems/buildchain/pull/501",
          "title": "chore(release): restore v2.5 channel topology after v2.5.5",
          "body": "## Summary\n- restore dev channel ancestry after v2.5.5 alpha/release promotions\n- keep dev tree content unchanged with an ours merge so subsequent promotions satisfy lineage checks\n\n## Validation\n- git merge-base ancestry checks before/after topology merge",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:29:16Z",
          "mergedAt": "2026-07-05T07:31:03Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 502,
          "url": "https://github.com/kungfu-systems/buildchain/pull/502",
          "title": "release: promote dev v2.5 to alpha",
          "body": "## Summary\n- promote current dev/v2/v2.5 to alpha after S3 artifact relay and release-finalization fixes\n\n## Notes\n- uses the protected dev-to-alpha channel PR path\n- no consumer repository build is triggered",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:31:27Z",
          "mergedAt": "2026-07-05T07:33:09Z",
          "additions": 246,
          "deletions": 51,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 503,
          "url": "https://github.com/kungfu-systems/buildchain/pull/503",
          "title": "Prepare v2.5.5-alpha.2",
          "body": "Create the generated version-state commit for v2.5.5-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:35:24Z",
          "mergedAt": "2026-07-05T07:37:15Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 240,
          "url": "https://github.com/kungfu-systems/kungfu/pull/240",
          "title": "fix(deps): update vulnerable toolchain packages",
          "body": "## Summary\n- update Python dependency floors for current advisory fixes in framework/core\n- upgrade GUI build tooling to Vite 6 and electron-vite 5\n- move vulnerable tar/js-yaml transitive edges to patched versions through pnpm workspace overrides\n- refresh uv and pnpm lockfiles\n\n## Validation\n- `uv lock --check`\n- `./kungfu-code audit --audit-level low` reports no known vulnerabilities\n- `git diff --check`\n- package JSON parse check for root, framework/core, and framework/gui manifests\n\n## Known blocker\n- `./kungfu-code install --frozen-lockfile --lockfile-only` still fails because `framework/core/package.json` references unpublished optional packages: `@kungfu-tech/core-darwin-arm64`, `@kungfu-tech/core-linux-x64`, and `@kungfu-tech/core-win32-x64` at `4.0.0-alpha.0`. This is separate from the vulnerability updates and blocks full `build:app` validation in the current local mirror/registry state.\n\n## Risk\n- Vite/electron-vite and Python packaging tools move across major versions; follow-up GUI/core build validation is needed after the optional platform package issue is resolved.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:36:57Z",
          "mergedAt": "2026-07-05T07:37:54Z",
          "additions": 1092,
          "deletions": 987,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 504,
          "url": "https://github.com/kungfu-systems/buildchain/pull/504",
          "title": "release: promote v2.5.5 to stable",
          "body": "## Summary\n- promote current alpha/v2/v2.5 to release/v2/v2.5\n- includes S3 artifact relay support and release finalization alpha-source fix\n\n## Notes\n- merge via protected alpha-to-release channel PR\n- promote-only path should reuse PR-stage release candidate evidence",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:37:42Z",
          "mergedAt": "2026-07-05T07:39:25Z",
          "additions": 246,
          "deletions": 51,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 1,
          "url": "https://github.com/kungfu-systems/kfd/pull/1",
          "title": "docs: add fact-first accountability KFD",
          "body": "## What\n\nAdds KFD-2 as the organization-level principle for fact-first product accountability: responsibility should be the path of least resistance.\n\nAlso extends the KFD registry model with `kind` so entries can distinguish principles from procedures. KFD-1 is marked as a procedure; KFD-2 is marked as a principle and explicitly does not supersede KFD-1.\n\n## Registry agreement\n\n- [x] `node scripts/check.mjs` passes\n- [x] `npm run check` passes\n- [x] Decision texts remain append-only; supersession over rewrite\n\n## Version impact (per KFD-1)\n\n- [x] minor-impact registry schema additive (`kind`)\n- [ ] patch-only content operation\n- [ ] major machine surface breakage\n\n## Notes\n\nNewer KFD numbers do not implicitly override older decisions. Supersession or override must be explicit in the later KFD and recorded in `registry.json`; otherwise conflicting active KFDs are a registry defect.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:39:04Z",
          "mergedAt": "2026-07-05T07:40:02Z",
          "additions": 162,
          "deletions": 9,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 507,
          "url": "https://github.com/kungfu-systems/buildchain/pull/507",
          "title": "fix(release): title generated version-state PRs",
          "body": "## Summary\n- default generated version-state fallback PR title/body before GitHub API creation\n- pass explicit protected-update PR metadata for alpha, release, and major finalization branch updates\n- cover protected dev finalization with a unit test\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:48:27Z",
          "mergedAt": "2026-07-05T07:50:16Z",
          "additions": 72,
          "deletions": 40,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 508,
          "url": "https://github.com/kungfu-systems/buildchain/pull/508",
          "title": "chore(release): restore v2.5 channel topology",
          "body": "## Summary\n- restore dev/v2/v2.5 ancestry over the current alpha and release channel heads\n- keep the tree exactly on current dev; this is a topology-only merge before the next alpha/release promotion\n\n## Validation\n- topology-only merge using -s ours\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:51:09Z",
          "mergedAt": "2026-07-05T07:52:51Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 509,
          "url": "https://github.com/kungfu-systems/buildchain/pull/509",
          "title": "release: promote v2.5 dev to alpha",
          "body": "## Summary\n- promote current dev/v2/v2.5 to alpha/v2/v2.5\n- includes S3 artifact relay support and release finalization fixes\n\n## Validation\n- PR checks\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:53:02Z",
          "mergedAt": "2026-07-05T07:54:44Z",
          "additions": 73,
          "deletions": 41,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 242,
          "url": "https://github.com/kungfu-systems/kungfu/pull/242",
          "title": "feat(rewind): capture managed-run responses",
          "body": "## Summary\n\n- Capture provider response text for `kungfu managed-run` and emit a Supervisor-layer `ModelResponse` (`msg_type 30004`) next to the existing `CostSnapshot`.\n- Write a hash-bound `response.json` sidecar into the Rewind bundle manifest and expose `--print-response` for provider smoke tests.\n- Cover both `codex exec --json` and `claude --print --output-format json` response extraction paths in the managed-run fixture.\n- Allow the newly introduced `electron-winstaller` install script in pnpm `allowBuilds`; inspected script only selects the host-arch 7z vendor binary, which preserves GUI/Windows packaging behavior.\n\n## Verification\n\n- `uv --project framework/core run ruff check framework/core/src/python/kungfu/rewind/managed_run.py framework/core/src/python/kungfu/rewind/managed_cli.py framework/core/src/python/kungfu/cli/commands/managed_run.py tests/fixtures/rewind-demo-managed-run/check_managed_run.py`\n- `uv --project framework/core run python tests/fixtures/rewind-demo-managed-run/check_managed_run.py tests/fixtures/rewind-demo-managed-run`\n- `PYTHONPATH=framework/core/src/python uv --project framework/core run pytest framework/core/tests/python/test_skill.py`\n- `git diff --check`\n- `./kungfu-code build:core`\n- `./kungfu-code freeze`\n- `./kungfu-code verify`\n- `framework/core/dist/kungfu/kungfu managed-run --help | rg -- '--print-response|--skill-path|--provider'`\n- Real Claude managed-run with `framework/skill/fixtures/minimal`: response sidecar and journal `ModelResponse` contain `kungfu.skill-context/v1` and the advertised skill hash.\n- Real Codex managed-run with `framework/skill/fixtures/minimal`: response sidecar and journal `ModelResponse` contain `kungfu.skill-context/v1` and the advertised skill hash.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:01:37Z",
          "mergedAt": "2026-07-05T08:02:58Z",
          "additions": 273,
          "deletions": 6,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 511,
          "url": "https://github.com/kungfu-systems/buildchain/pull/511",
          "title": "fix(release): skip stale published alpha state",
          "body": "## Summary\n- treat stale alpha durable state with published material as occupied\n- let alpha promotion choose the next prerelease instead of reusing an already-published npm version\n- cover stale published alpha state with a unit test\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --filter \"./actions/promote-buildchain-ref\" build\n- pnpm run check\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:02:13Z",
          "mergedAt": "2026-07-05T08:03:57Z",
          "additions": 211,
          "deletions": 62,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 512,
          "url": "https://github.com/kungfu-systems/buildchain/pull/512",
          "title": "chore(release): restore v2.5 topology after alpha retry",
          "body": "## Summary\n- restore dev/v2/v2.5 ancestry over the current alpha and release channel heads after the failed alpha retry\n- keep the tree exactly on current dev before re-promoting alpha\n\n## Validation\n- topology-only merge using -s ours\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:04:25Z",
          "mergedAt": "2026-07-05T08:06:07Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 513,
          "url": "https://github.com/kungfu-systems/buildchain/pull/513",
          "title": "release: promote v2.5 dev to alpha",
          "body": "## Summary\n- retry v2.5 dev to alpha promotion after stale published alpha-state fix\n- includes S3 artifact relay support and release finalization recovery fixes\n\n## Validation\n- PR checks\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:06:20Z",
          "mergedAt": "2026-07-05T08:08:04Z",
          "additions": 211,
          "deletions": 62,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 243,
          "url": "https://github.com/kungfu-systems/kungfu/pull/243",
          "title": "fix(kfx-sandbox): fix the Windows AppContainer relay spawn hang",
          "body": "Root-cause and fix the intermittent Windows AppContainer relay spawn hang: ancestor traverse ACL grants on large user-profile directories (C:\\Users\\<user>, AppData) triggered NTFS inheritance re-propagation and blocked spawn synchronously. Skip ancestor grants where ALL APPLICATION PACKAGES already has traverse. Also harden the host relay handshake (listen-readiness, timeout, retry). Verified on a real Windows machine: the knob matrix (permissive/denyWrite/denyNetwork) runs green in one pass and the js/py x trusted/sandbox matrix is 4/4 green, both without manual icacls.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:08:01Z",
          "mergedAt": "2026-07-05T08:08:05Z",
          "additions": 266,
          "deletions": 101,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 515,
          "url": "https://github.com/kungfu-systems/buildchain/pull/515",
          "title": "feat(release): add surface-aware impact classification",
          "body": "## Summary\n- add surface-aware release impact fields to release passports (`versionImpact` and `surfaceImpacts`)\n- verify that the final version impact matches the highest declared surface impact\n- expose surface impact rationale through release explanation output\n- document the KFD registry schema case where content remains patch but an additive machine registry schema change requires minor-impact review\n\n## Validation\n- `node --test tests/release-passport.test.mjs`\n- `pnpm run check`\n\n## Release impact\nMinor-impact release governance surface: this adds additive release passport / impact ledger fields and validation while preserving existing passport consumers.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:10:52Z",
          "mergedAt": "2026-07-05T08:12:57Z",
          "additions": 315,
          "deletions": 80,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 516,
          "url": "https://github.com/kungfu-systems/buildchain/pull/516",
          "title": "fix(release): ignore published alpha history states",
          "body": "## Summary\n\n- prevent published alpha durable states from being resumed only because their transaction commit is in channel history\n- keep ancestry-based recovery for unpublished material, but require exact source/material matches once artifacts or evidence exist\n- add regression coverage for stale published alpha state selection\n\n## Validation\n\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --filter \"./actions/promote-buildchain-ref\" build\n- pnpm run check\n- git diff --check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:16:34Z",
          "mergedAt": "2026-07-05T08:18:26Z",
          "additions": 64,
          "deletions": 62,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 517,
          "url": "https://github.com/kungfu-systems/buildchain/pull/517",
          "title": "chore(release): restore v2.5 topology after alpha history",
          "body": "## Summary\n\n- merge the current alpha/v2/v2.5 channel history back into dev/v2/v2.5 using the ours strategy\n- preserve release topology after a failed alpha promotion attempt without changing files\n\n## Validation\n\n- git merge -s ours --no-ff origin/alpha/v2/v2.5\n- git status --short\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:19:16Z",
          "mergedAt": "2026-07-05T08:21:02Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 518,
          "url": "https://github.com/kungfu-systems/buildchain/pull/518",
          "title": "release: promote v2.5 dev to alpha",
          "body": "## Summary\n\n- promote dev/v2/v2.5 to alpha/v2/v2.5 after S3 artifact relay and release-state fixes\n- expected path is promote-only, reusing PR-stage evidence and avoiding an extra heavy native matrix after merge\n\n## Validation\n\n- dev channel PR checks and Buildchain dogfood passed before merge\n- topology restored via #517\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:21:26Z",
          "mergedAt": "2026-07-05T08:23:09Z",
          "additions": 339,
          "deletions": 102,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 519,
          "url": "https://github.com/kungfu-systems/buildchain/pull/519",
          "title": "Prepare v2.5.5-alpha.3",
          "body": "Create the generated version-state commit for v2.5.5-alpha.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:25:18Z",
          "mergedAt": "2026-07-05T08:27:09Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 520,
          "url": "https://github.com/kungfu-systems/buildchain/pull/520",
          "title": "release: promote v2.5.5 to stable",
          "body": "## Summary\n\n- promote alpha/v2/v2.5 to release/v2/v2.5 after v2.5.5-alpha.3 validation\n- publish stable Buildchain release with S3 artifact relay and release-state fixes\n\n## Validation\n\n- alpha promotion completed successfully in Buildchain Ref Promotion run 28734672617\n- alpha version-state PR #519 merged\n- npm alpha dist-tag is 2.5.5-alpha.3\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:27:35Z",
          "mergedAt": "2026-07-05T08:31:07Z",
          "additions": 526,
          "deletions": 108,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 524,
          "url": "https://github.com/kungfu-systems/buildchain/pull/524",
          "title": "fix(release): scan candidate runs for RC artifacts",
          "body": "## Summary\n\n- scan all matching successful PR-stage Build Surface Fixture runs until one contains release-candidate passport artifacts\n- keep the newest-run ordering but skip successful reruns that lack RC passport/summary artifacts\n- add regression coverage for the release-channel failure seen after #520\n\n## Validation\n\n- node --test tests/release-candidate.test.mjs\n- pnpm run check\n- git diff --check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:36:57Z",
          "mergedAt": "2026-07-05T08:38:44Z",
          "additions": 156,
          "deletions": 14,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 525,
          "url": "https://github.com/kungfu-systems/buildchain/pull/525",
          "title": "chore(release): restore v2.5 topology after release RC fix",
          "body": "## Summary\n\n- merge the current release/v2/v2.5 channel history back into dev/v2/v2.5 using the ours strategy\n- preserve topology after the release RC resolver fix without changing files\n\n## Validation\n\n- git merge -s ours --no-ff origin/release/v2/v2.5\n- git diff --stat origin/dev/v2/v2.5..HEAD\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:39:41Z",
          "mergedAt": "2026-07-05T08:41:17Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 521,
          "url": "https://github.com/kungfu-systems/buildchain/pull/521",
          "title": "Prepare v2.5.5-alpha.3",
          "body": "Create the generated version-state commit for v2.5.5-alpha.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:29:06Z",
          "mergedAt": "2026-07-05T08:41:19Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 526,
          "url": "https://github.com/kungfu-systems/buildchain/pull/526",
          "title": "release: promote v2.5 dev to alpha",
          "body": "## Summary\n\n- promote dev/v2/v2.5 to alpha/v2/v2.5 after RC resolver fallback fix\n- expected path remains promote-only; PR verify build jobs should skip heavy release build\n\n## Validation\n\n- resolver fix merged in #524\n- topology restored in #525\n- npm alpha dist-tag currently 2.5.5-alpha.3\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:41:40Z",
          "mergedAt": "2026-07-05T08:43:25Z",
          "additions": 157,
          "deletions": 15,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 527,
          "url": "https://github.com/kungfu-systems/buildchain/pull/527",
          "title": "Prepare v2.5.5-alpha.4",
          "body": "Create the generated version-state commit for v2.5.5-alpha.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:45:46Z",
          "mergedAt": "2026-07-05T08:47:35Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 244,
          "url": "https://github.com/kungfu-systems/kungfu/pull/244",
          "title": "feat(skill): verify managed context envelopes",
          "body": "## Summary\n- add `kungfu skill verify` to run real managed providers against Skill context envelopes and validate Rewind response evidence\n- add Node manager context file writer/CLI and wire Electron GUI context generation through the shared Node skill package\n- document Python/Node manager verification paths and extend golden fixture coverage\n\n## Validation\n- `./kungfu-code build:core`\n- `./kungfu-code freeze`\n- `./kungfu-code verify`\n- `uv --project framework/core run ruff check framework/core/src/python/kungfu/cli/commands/skill.py framework/core/src/python/kungfu/rewind/managed_cli.py`\n- `PYTHONPATH=framework/core/src/python uv --project framework/core run pytest framework/core/tests/python/test_skill.py`\n- `./kungfu-code --filter @kungfu-tech/skill run build`\n- `./kungfu-code --filter @kungfu-tech/skill run test:golden`\n- `./kungfu-code --filter @kungfu-tech/gui run build`\n- frozen `kungfu skill verify --provider codex --manager python --json` -> ok\n- frozen Node-generated context + `kungfu skill verify --provider claude --skill-context-file ... --manager node --json` -> ok\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:49:24Z",
          "mergedAt": "2026-07-05T08:50:11Z",
          "additions": 426,
          "deletions": 31,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 529,
          "url": "https://github.com/kungfu-systems/buildchain/pull/529",
          "title": "feat(release): require surface impact gates",
          "body": "## Summary\n- require surfaceImpacts[] for production release passports and major publish gates\n- expose release-passport-impact-json in promote-buildchain-ref so generated production passports can satisfy the gate\n- document the new requirement and cover production versus alpha behavior in tests\n\n## Validation\n- node --check packages/core/release-passport.js actions/promote-buildchain-ref/lib.js actions/promote-buildchain-ref/index.js bin/buildchain.mjs\n- node --test tests/release-passport.test.mjs\n- node --test tests/cli.test.mjs\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:49:24Z",
          "mergedAt": "2026-07-05T08:51:09Z",
          "additions": 291,
          "deletions": 88,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 528,
          "url": "https://github.com/kungfu-systems/buildchain/pull/528",
          "title": "release: promote v2.5.5 to stable",
          "body": "## Summary\n\n- promote alpha/v2/v2.5 to release/v2/v2.5 after v2.5.5-alpha.4 validation\n- includes S3 artifact relay and release-candidate resolver fallback fix\n\n## Validation\n\n- alpha promotion completed successfully in Buildchain Ref Promotion run 28735175401\n- alpha version-state PR #527 merged\n- npm alpha dist-tag is 2.5.5-alpha.4\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:48:06Z",
          "mergedAt": "2026-07-05T08:51:36Z",
          "additions": 157,
          "deletions": 15,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 533,
          "url": "https://github.com/kungfu-systems/buildchain/pull/533",
          "title": "fix(release): treat occupied release-state versions as published",
          "body": "## Summary\n- treat stable release-state refs as occupied patch versions when selecting the next release tag\n- prevent version-state stale replacement from deleting transactions that already have published material\n- require published finalization transactions to cover the current required artifacts before reuse\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --filter \"./actions/promote-buildchain-ref\" build\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:01:09Z",
          "mergedAt": "2026-07-05T09:03:52Z",
          "additions": 103,
          "deletions": 53,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 534,
          "url": "https://github.com/kungfu-systems/buildchain/pull/534",
          "title": "chore(release): restore v2.5 topology after state fix",
          "body": "## Summary\n- merge release/v2/v2.5 topology back into dev/v2/v2.5 with ours strategy\n- preserve dev content after the release-state version selection fix\n\n## Validation\n- topology-only merge commit",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:05:02Z",
          "mergedAt": "2026-07-05T09:06:46Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 530,
          "url": "https://github.com/kungfu-systems/buildchain/pull/530",
          "title": "Prepare v2.5.5-alpha.4",
          "body": "Create the generated version-state commit for v2.5.5-alpha.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:49:28Z",
          "mergedAt": "2026-07-05T09:06:48Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 535,
          "url": "https://github.com/kungfu-systems/buildchain/pull/535",
          "title": "release: promote v2.5 dev to alpha",
          "body": "Promote dev/v2/v2.5 to alpha/v2/v2.5 after release-state version selection fix and topology restore.\n\nExpected behavior:\n- Buildchain selects the next available alpha version after occupied release-state versions.\n- Promotion uses publish-gate alpha semantics.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:07:08Z",
          "mergedAt": "2026-07-05T09:10:33Z",
          "additions": 345,
          "deletions": 92,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 537,
          "url": "https://github.com/kungfu-systems/buildchain/pull/537",
          "title": "fix(release): skip occupied release-state for next alpha",
          "body": "## Summary\n- include stable release-state refs when selecting the next alpha patch\n- prevents alpha from continuing on a patch whose final version already has durable published state\n\n## Validation\n- pnpm --filter \"./actions/promote-buildchain-ref\" build\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:14:44Z",
          "mergedAt": "2026-07-05T09:16:43Z",
          "additions": 56,
          "deletions": 47,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 538,
          "url": "https://github.com/kungfu-systems/buildchain/pull/538",
          "title": "chore(release): restore v2.5 alpha topology after alpha skip fix",
          "body": "## Summary\n- merge alpha/v2/v2.5 topology back into dev/v2/v2.5 with ours strategy\n- preserve dev content after next-alpha release-state occupancy fix\n\n## Validation\n- topology-only merge commit",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:17:27Z",
          "mergedAt": "2026-07-05T09:19:17Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 539,
          "url": "https://github.com/kungfu-systems/buildchain/pull/539",
          "title": "release: promote v2.5 dev to alpha",
          "body": "Promote dev/v2/v2.5 to alpha/v2/v2.5 after next-alpha release-state occupancy fix.\n\nExpected behavior:\n- Buildchain skips occupied stable release-state patch 2.5.5.\n- Alpha promotion prepares the next patch alpha instead of continuing v2.5.5-alpha.N.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:19:42Z",
          "mergedAt": "2026-07-05T09:21:38Z",
          "additions": 56,
          "deletions": 47,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 540,
          "url": "https://github.com/kungfu-systems/buildchain/pull/540",
          "title": "Prepare v2.5.6-alpha.0",
          "body": "Create the generated version-state commit for v2.5.6-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:24:05Z",
          "mergedAt": "2026-07-05T09:25:54Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 245,
          "url": "https://github.com/kungfu-systems/kungfu/pull/245",
          "title": "feat(skill): audit context usage",
          "body": "## Summary\n- record `SkillAdvertised` audit sidecars in managed-run bundles and reference them from `manifest.json`\n- record `SkillLoaded` events when `kungfu skill read` loads full `SKILL.md` content\n- add `kungfu skill audit` to inspect run bundle evidence or standalone audit files\n\n## Validation\n- `uv --project framework/core run ruff check framework/core/src/python/kungfu/skill/audit.py framework/core/src/python/kungfu/skill/__init__.py framework/core/src/python/kungfu/cli/commands/skill.py framework/core/src/python/kungfu/rewind/managed_cli.py framework/core/tests/python/test_skill.py`\n- `PYTHONPATH=framework/core/src/python uv --project framework/core run pytest framework/core/tests/python/test_skill.py`\n- `./kungfu-code build:core`\n- `./kungfu-code --filter @kungfu-tech/skill run build`\n- `./kungfu-code --filter @kungfu-tech/skill run test:golden`\n- `./kungfu-code freeze`\n- `./kungfu-code verify`\n- frozen `kungfu skill verify --provider codex --manager python --json` + `kungfu skill audit --run-id ...` -> `SkillAdvertised`\n- frozen `kungfu skill read ... --audit-file ... --json` + `kungfu skill audit --audit-file ...` -> `SkillLoaded`\n- frozen Node-generated GUI context + `kungfu skill verify --skill-context-file ... --manager node --json` + `skill audit --run-id ...` -> `manager=node`, `source=gui`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:26:43Z",
          "mergedAt": "2026-07-05T09:27:32Z",
          "additions": 367,
          "deletions": 16,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 541,
          "url": "https://github.com/kungfu-systems/buildchain/pull/541",
          "title": "release: promote v2.5.6 to stable",
          "body": "Promote alpha/v2/v2.5 to release/v2/v2.5 for stable v2.5.6.\n\nExpected behavior:\n- publish-gate release locks the channel merge commit\n- release promotion reuses the PR-stage RC artifacts\n- no heavy build is rerun after merge",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:27:06Z",
          "mergedAt": "2026-07-05T09:31:21Z",
          "additions": 358,
          "deletions": 96,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 544,
          "url": "https://github.com/kungfu-systems/buildchain/pull/544",
          "title": "test(release): cover major surface impact gate",
          "body": "## Summary\n- add a release passport regression test for publish-gate/major without surfaceImpacts[]\n- assert the verifier fails closed with the major-gate requirement\n\n## Validation\n- node --test tests/release-passport.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:30:55Z",
          "mergedAt": "2026-07-05T09:32:52Z",
          "additions": 17,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 545,
          "url": "https://github.com/kungfu-systems/buildchain/pull/545",
          "title": "Release v2.5.6",
          "body": "Create the generated version-state commit for v2.5.6.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:33:30Z",
          "mergedAt": "2026-07-05T09:35:17Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 542,
          "url": "https://github.com/kungfu-systems/buildchain/pull/542",
          "title": "Prepare v2.5.6-alpha.0",
          "body": "Create the generated version-state commit for v2.5.6-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:28:14Z",
          "mergedAt": "2026-07-05T09:38:08Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 246,
          "url": "https://github.com/kungfu-systems/kungfu/pull/246",
          "title": "per-session OS windows behind a flag (ADR-0016 stage 2)",
          "body": "Add the per-session OS window (ADR-0016 stage 2): pop a managed session out of the in-shell grid into its own restorable window, placed on the display it was last on. Pure F7 placement + a main-process window registry + a windows[] layer on WorkspaceLayout; pop-out is a shell service so the view stays electron-free. Behind KF_SESSION_WINDOWS (default off); window content is a stage-2 placeholder. Includes a fix so app quit does not wipe the persisted layout. Validated on a real machine (pop out / cross-display move / quit / restore with clamp).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:38:16Z",
          "mergedAt": "2026-07-05T09:38:22Z",
          "additions": 755,
          "deletions": 14,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 546,
          "url": "https://github.com/kungfu-systems/buildchain/pull/546",
          "title": "Prepare v2.5.7-alpha.0",
          "body": "Create the generated version-state commit for v2.5.7-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:37:45Z",
          "mergedAt": "2026-07-05T09:39:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 247,
          "url": "https://github.com/kungfu-systems/kungfu/pull/247",
          "title": "perf(kfx-sandbox): skip ancestor traverse grant the container SID already holds",
          "body": "Merge fix/kfx-win-roaming-traverse-skip into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:54:58Z",
          "mergedAt": "2026-07-05T09:55:03Z",
          "additions": 40,
          "deletions": 21,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 248,
          "url": "https://github.com/kungfu-systems/kungfu/pull/248",
          "title": "feat(skill): bind kfx dependencies",
          "body": "## Summary\n- add Skill kfx dependency binding documents under the Kungfu home\n- resolve declared kfx dependencies against the shared kfx registry without copying kfx payloads per skill\n- expose `kungfu skill deps` plus Python and Node binding helpers\n- record `SkillDependenciesBound` audit events and support multi-event JSONL audit reads\n\n## Verification\n- `uv --project framework/core run ruff check framework/core/src/python/kungfu/skill framework/core/src/python/kungfu/cli/commands/skill.py framework/core/tests/python/test_skill.py`\n- `PYTHONPATH=framework/core/src/python uv --project framework/core run pytest framework/core/tests/python/test_skill.py`\n- `./kungfu-code --filter @kungfu-tech/skill run build`\n- `./kungfu-code --filter @kungfu-tech/skill run test:golden`\n- `./kungfu-code build:core`\n- `./kungfu-code freeze`\n- frozen `framework/core/dist/kungfu/kungfu` install/deps smoke with two skills sharing one kfx registry entry\n- `./kungfu-code verify`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T10:08:07Z",
          "mergedAt": "2026-07-05T10:08:41Z",
          "additions": 711,
          "deletions": 21,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 249,
          "url": "https://github.com/kungfu-systems/kungfu/pull/249",
          "title": "test: port the verification gate's shell scripts to Node (cross-platform)",
          "body": "Port all 24 bash run.sh drivers (20 fixtures + 3 capability slices + the yijinjing dependency guard) to pure-Node run.mjs so verify --full runs on every platform pnpm runs on, Windows included. Adds two shared harnesses, a verify.js stage 0a guard against reintroducing .sh, and a CONTRIBUTING convention. Also fixes verify --full's build order (freeze before the dogfood probes, which now build via 'kungfu sdk kfx build' and need the frozen runtime). Behavior-preserving: run.sh-passing fixtures pass as run.mjs; the 3 kfx failures are pre-existing (identical on the original run.sh) and tracked separately.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T10:59:12Z",
          "mergedAt": "2026-07-05T10:59:17Z",
          "additions": 1640,
          "deletions": 1015,
          "changedFiles": 52
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 547,
          "url": "https://github.com/kungfu-systems/buildchain/pull/547",
          "title": "fix(release): gate promotion on push verifies",
          "body": "## Summary\n- prevent Buildchain Ref Promotion from running for pull_request Verify workflow_run events\n- keep manual dry-run promotion available\n- add inventory and test coverage for the push-only promotion gate\n\n## Issue coverage\n- Covers repeated workflow-friction issues where PR Verify or version-state PR Verify triggered promote-only publication attempts before a channel push.\n- Leaves existing libnode workflow-file fallback issues as already fixed by the current workflow-friction classifier tests.\n\n## Verification\n- node --test tests/build-surface.test.mjs tests/release-candidate.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T11:47:06Z",
          "mergedAt": "2026-07-05T11:48:54Z",
          "additions": 6,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 549,
          "url": "https://github.com/kungfu-systems/buildchain/pull/549",
          "title": "chore(release): restore v2.5 topology after friction fix",
          "body": "## Summary\n- merge alpha/v2/v2.5 version-state history back into dev/v2/v2.5 after the workflow-friction fix\n- preserve the push-only promotion gate from #547 while restoring the channel topology required for alpha promotion\n\n## Validation\n- pnpm run check\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-05T11:53:38Z",
          "mergedAt": "2026-07-05T11:55:31Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 548,
          "url": "https://github.com/kungfu-systems/buildchain/pull/548",
          "title": "release: promote workflow-friction fix to alpha",
          "body": "## Summary\n- promote the push-only Buildchain Ref Promotion gate to alpha\n- prevents pull_request Verify workflow_run events from starting promote-only publication attempts\n\n## Verification\n- PR #547 checks passed\n- dev/v2/v2.5 Verify passed after merge\n\n## Expected release behavior\n- PR-stage checks should build/verify only.\n- Buildchain Ref Promotion should only run after the alpha branch push Verify succeeds.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T11:50:02Z",
          "mergedAt": "2026-07-05T11:57:22Z",
          "additions": 23,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 2,
          "url": "https://github.com/kungfu-systems/kfd/pull/2",
          "title": "docs(release): add production impact ledger",
          "body": "## Summary\n- add `release-impact.json` as the Buildchain surface-aware ledger for KFD production passports\n- make `node scripts/check.mjs` validate the ledger alongside registry/document agreement\n- document the `release-passport-impact-json: release-impact.json` release input\n\n## Validation\n- node --check scripts/check.mjs\n- node scripts/check.mjs\n- jq . release-impact.json\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs validate --cwd .",
          "author": "dongkeren",
          "createdAt": "2026-07-05T11:59:27Z",
          "mergedAt": "2026-07-05T12:00:10Z",
          "additions": 99,
          "deletions": 4,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 550,
          "url": "https://github.com/kungfu-systems/buildchain/pull/550",
          "title": "Prepare v2.5.7-alpha.1",
          "body": "Create the generated version-state commit for v2.5.7-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T11:59:36Z",
          "mergedAt": "2026-07-05T12:01:27Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 250,
          "url": "https://github.com/kungfu-systems/kungfu/pull/250",
          "title": "feat(skill): expose dependency state to managers",
          "body": "## Summary\n- add a `kungfu.skill-manager/v1` Node manager view that joins installed skills with kfx dependency binding state\n- write `KF_SKILL_MANAGER_FILE` from Electron main and expose it through `shell.info.skillManager`\n- add the first-party `skill-manager` system view to show resolved/unresolved kfx dependencies before agent launch\n\n## Validation\n- `./kungfu-code --filter @kungfu-tech/skill run build`\n- `./kungfu-code --filter @kungfu-tech/skill run test:golden`\n- `./kungfu-code --filter @kungfu-tech/kfx run build`\n- `./kungfu-code --filter @kungfu-tech/gui run build`\n- `./kungfu-code exec biome check framework/skill/src/index.ts framework/skill/scripts/golden.mjs framework/skill/scripts/manager.mjs framework/gui/src/main/index.ts framework/gui/src/main/skill-context.ts framework/gui/src/renderer/src/runtime.ts framework/gui/src/renderer/src/shell-state.ts framework/kfx/src/index.ts extensions/system/package.json extensions/system/skill-manager/package.json extensions/system/skill-manager/src/view/index.tsx`\n- `node --experimental-transform-types framework/skill/scripts/manager.mjs --home <tmp> --path framework/skill/fixtures/minimal --path framework/skill/fixtures/with-frontmatter`\n- `node ../../../developer/sdk/src/sdk.js kfx build` from `extensions/system/skill-manager`\n\n## Notes\n- Full `./kungfu-code lint` is not a clean signal on this branch because existing unrelated files currently fail Biome import/style rules; changed-file Biome check passes.\n- The package script `kungfu sdk kfx build` resolves to the local global `/usr/local/bin/kungfu` on this machine, which lacks `sdk`; the view bundle was verified through the repo SDK entrypoint directly.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:04:08Z",
          "mergedAt": "2026-07-05T12:04:41Z",
          "additions": 617,
          "deletions": 9,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 551,
          "url": "https://github.com/kungfu-systems/buildchain/pull/551",
          "title": "Prepare v2.5.7-alpha.1",
          "body": "Create the generated version-state commit for v2.5.7-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:03:34Z",
          "mergedAt": "2026-07-05T12:05:40Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 251,
          "url": "https://github.com/kungfu-systems/kungfu/pull/251",
          "title": "refactor(core): finish the .sh→node migration (benches + tree-wide guard)",
          "body": "Ports the two ADR-0005 dispatch benches to .mjs (shared _bench.mjs), removes the orphaned freeze-kungfu.sh (superseded by run-freeze.js), and hardens verify stage 0a to guard the whole tree against reintroduced .sh (was 3 whitelisted dirs). Repo is now zero .sh.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:06:34Z",
          "mergedAt": "2026-07-05T12:06:39Z",
          "additions": 370,
          "deletions": 244,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 552,
          "url": "https://github.com/kungfu-systems/buildchain/pull/552",
          "title": "release: promote workflow-friction fix to stable",
          "body": "## Summary\n- promote Buildchain v2.5.7-alpha.1 to the stable v2.5 release line\n- includes #547 push-only promotion gate for Buildchain Ref Promotion so PR-stage Verify no longer triggers publishing\n- carries alpha-tested version-state and binary distribution evidence\n\n## Validation\n- #547 CI passed and merged to dev/v2/v2.5\n- #548 dev -> alpha checks passed and alpha promote-only completed\n- #550 version-state PR passed and binary distribution completed for v2.5.7-alpha.1\n- #551 dev version-state sync passed and merged\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:06:58Z",
          "mergedAt": "2026-07-05T12:08:36Z",
          "additions": 24,
          "deletions": 2,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 553,
          "url": "https://github.com/kungfu-systems/buildchain/pull/553",
          "title": "Release v2.5.7",
          "body": "Create the generated version-state commit for v2.5.7.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:10:45Z",
          "mergedAt": "2026-07-05T12:12:33Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 554,
          "url": "https://github.com/kungfu-systems/buildchain/pull/554",
          "title": "Prepare v2.5.8-alpha.0",
          "body": "Create the generated version-state commit for v2.5.8-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:15:11Z",
          "mergedAt": "2026-07-05T12:17:03Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 50,
          "url": "https://github.com/kungfu-systems/libnode/pull/50",
          "title": "ci: enable buildchain s3 relay for alpha publishing",
          "body": "## Summary\n- enable Buildchain S3 artifact relay for Build, Release - Verify, and Release - New Version\n- bump alpha version to 22.22.3-kf.3-alpha.10 for the validation publish\n\n## Validation\n- ruby YAML parse for modified workflows\n- jq parse for package.json and libnode.release.json\n- corepack pnpm verify-release\n- corepack pnpm verify-package-source\n- git diff --check\n\nAfter this PR build validates relay mode, publish-gate/alpha will publish the alpha package set through the same Buildchain S3 relay path.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:02:14Z",
          "mergedAt": "2026-07-05T12:24:43Z",
          "additions": 6,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 555,
          "url": "https://github.com/kungfu-systems/buildchain/pull/555",
          "title": "chore(release): sync dev after v2.5.7 release",
          "body": "## Summary\n- sync dev/v2/v2.5 to the prepared v2.5.8-alpha.0 state after the v2.5.7 release\n- closes the post-release topology gap where alpha advanced but dev remained at v2.5.7-alpha.1\n\n## Validation\n- v2.5.7 stable release completed\n- v2.5.8-alpha.0 next-alpha binary distribution completed\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:24:57Z",
          "mergedAt": "2026-07-05T12:26:46Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 252,
          "url": "https://github.com/kungfu-systems/kungfu/pull/252",
          "title": "build(repo): move the pre-commit hook to node (cross-platform format + lint guard)",
          "body": "JS-ify the pre-commit hook so it works on Windows: all logic moves to precommit.mjs (staged .sh guard, clang-format/ruff format, biome check --write that blocks on unfixable lint), .githooks/pre-commit becomes a thin POSIX exec-node shim, and the no-bash scan is extracted to no-bash-guard.mjs shared with verify stage 0a. Validated on macOS: sh-block / format+restage / lint-block all behave.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:34:10Z",
          "mergedAt": "2026-07-05T12:34:15Z",
          "additions": 271,
          "deletions": 115,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 253,
          "url": "https://github.com/kungfu-systems/kungfu/pull/253",
          "title": "fix(skill): load manager view in gui renderer",
          "body": "## Summary\n- load the Skill Manager JSON from the renderer runtime fallback path when the shell info payload is unavailable\n- let the Skill Manager system view read KF_SKILL_MANAGER_FILE directly as a last-resort fallback\n- keep the rendered dependency table available for GUI dogfood runs with a precomputed Node manager state\n\n## Validation\n- node ../../../developer/sdk/src/sdk.js kfx build (extensions/system/skill-manager)\n- ./kungfu-code --filter @kungfu-tech/gui run build\n- ./kungfu-code exec biome check framework/gui/src/renderer/src/runtime.ts extensions/system/skill-manager/src/view/index.tsx\n- launched the GUI with KF_RUNTIME_DIR, KF_SKILL_PATH, KF_SKILL_MANAGER_FILE, and KFE_INITIAL_VIEW=skill-manager; verified the Skill Manager page shows 2 installed skills and 1 unresolved required kfx",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:38:55Z",
          "mergedAt": "2026-07-05T12:39:54Z",
          "additions": 35,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 51,
          "url": "https://github.com/kungfu-systems/libnode/pull/51",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.10",
          "body": "## Summary\n- promote dev/v22/v22.22 to alpha/v22/v22.22\n- publish @kungfu-tech/libnode 22.22.3-kf.3-alpha.10\n- validate Buildchain S3 artifact relay on the release-candidate build\n\n## Expected Buildchain flow\n- Build workflow runs with release-candidate=true for alpha base\n- self-hosted platform jobs upload heavy payloads through S3 relay\n- relay-artifacts jobs rehydrate normal GitHub artifacts\n- merging this PR triggers Release - New Version promote/publish\n\n## Prior validation\n- PR #50 Build run 28740199617 passed Linux x64, macOS arm64, Windows x64 and all relay artifact jobs.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:25:15Z",
          "mergedAt": "2026-07-05T12:45:55Z",
          "additions": 6,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 254,
          "url": "https://github.com/kungfu-systems/kungfu/pull/254",
          "title": "feat(gui,terminal): render the live terminal in a per-session window (ADR-0016 stage 3)",
          "body": "Replace the stage-2 placeholder in each per-session OS window with the real terminal view, mounted against one runId over the main-process session host, so a session renders identically in the in-shell grid and in its own window. Adds a node-integrated session-window renderer entry, the electron-vite html entry for it, and dispatches the terminal kfx View on shell.params.sessionWindowRunId. Also namespaces terminal-host relay subscriptions by webContents id so the shell and each session window (now separate guest renderers on one host) no longer collide subIds and silently kill an unrelated pane, with destroyed-sender cleanup. Behind KF_SESSION_WINDOWS, default off; type-checks, builds, and passed a real-machine check (pop-out live terminal, grid pane survives pop-out, cross-display drag, quit/relaunch restore).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:50:43Z",
          "mergedAt": "2026-07-05T12:50:48Z",
          "additions": 329,
          "deletions": 61,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 255,
          "url": "https://github.com/kungfu-systems/kungfu/pull/255",
          "title": "docs(kfx): ADR-0017 dual-host loading + the service facet, and a topology page",
          "body": "Merge docs/kfx-dual-entry-adr into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T13:15:52Z",
          "mergedAt": "2026-07-05T13:15:57Z",
          "additions": 349,
          "deletions": 1,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 256,
          "url": "https://github.com/kungfu-systems/kungfu/pull/256",
          "title": "refactor(repo): relocate root dev tooling into scripts/ and convert to ESM",
          "body": "De-clutters the repo root: moves verify/install-hooks/prebuild/precommit/no-bash-guard into scripts/ (per-package scripts/ convention) and converts the .js tooling + kungfu-code entrypoint to ESM (.mjs; surgical rename, not root type:module, which would flip the CJS test fixtures). All refs updated (package.json, pre-commit shim, kungfu-code sh/cmd wrappers, CONTRIBUTING). Validated on macOS: verify --help / quick run / guard / kungfu-code proxy / precommit all work.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T13:36:27Z",
          "mergedAt": "2026-07-05T13:36:33Z",
          "additions": 67,
          "deletions": 52,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 257,
          "url": "https://github.com/kungfu-systems/kungfu/pull/257",
          "title": "fix(repo): make the pre-commit formatters spawn on Windows",
          "body": "precommit.mjs spawned biome/pnpm/ruff/clang-format without shell:isWin, so on Windows node could not launch their .cmd shims (ENOENT), and checking only r.status meant a failed biome spawn falsely blocked the commit. Add shell:isWin (matching verify.mjs) and treat a spawn error as warn-and-skip. Validated on macOS (shell:false path unchanged): sh-block / format+restage / lint-block all still behave.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T13:55:02Z",
          "mergedAt": "2026-07-05T13:55:07Z",
          "additions": 28,
          "deletions": 13,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 258,
          "url": "https://github.com/kungfu-systems/kungfu/pull/258",
          "title": "feat(skill): show static agent skill inventory",
          "body": "## Summary\n\n- add a read-only Codex/Claude agent skill inventory to the Skill Manager data model\n- surface agent-native skill roots, effective skills, shadowed duplicates, parse state, hashes, mtimes, and safe path metadata in the Skill Manager GUI\n- skip generated Python `.venv` directories in the no-bash guard so the standard uv/Nuitka build output does not break verification\n\n## Verification\n\n- `./kungfu-code exec biome check framework/skill/src/index.ts framework/skill/scripts/golden.mjs extensions/system/skill-manager/src/view/index.tsx framework/gui/src/renderer/src/main.tsx framework/skill/schema/skill-manager.schema.json scripts/no-bash-guard.mjs`\n- `./kungfu-code --filter @kungfu-tech/skill test:golden`\n- `./kungfu-code --filter @kungfu-tech/skill build`\n- `./kungfu-code --filter @kungfu-tech/gui build`\n- `./kungfu-code build:core && ./kungfu-code freeze && ./kungfu-code verify`\n- `PATH=\"$PWD/framework/core/dist/kungfu:$PATH\" ./kungfu-code --filter @kungfu-tech/kfx-view-skill-manager build`\n\n## Safety\n\n- does not read provider credentials, session logs, auth files, or billing state\n- reads only local skill roots and `SKILL.md` metadata needed for name/description/hash/mtime\n- does not mutate agent homes, skill roots, symlinks, or identity-pool configuration\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T14:11:50Z",
          "mergedAt": "2026-07-05T14:12:39Z",
          "additions": 866,
          "deletions": 2,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 556,
          "url": "https://github.com/kungfu-systems/buildchain/pull/556",
          "title": "feat(passport): verify artifacts through release passport discovery",
          "body": "## Summary\n- add subject-centric `buildchain verify|inspect|explain artifact` CLI surfaces\n- discover detached release passports through explicit flags, sidecar pointers, package pointers, local indexes, GitHub Release defaults, and custom locators\n- verify the release passport and require the subject digest to appear in passport artifacts, artifact evidence, publish evidence, or package-set evidence\n- dogfood artifact verification in the Buildchain binary distribution workflow\n\n## Validation\n- `node --test tests/release-passport.test.mjs`\n- `node --test tests/cli.test.mjs`\n- `pnpm run check`\n\n## Notes\n- Opened `dev/v2/v2.6`, set it as the repository default branch, and matched the v2.5 dev branch protection with one required approval.\n- No alpha or release publication was performed.\n\nAgent: Codex\nGoal: 2026-07-05-buildchain-artifact-passport-discovery\nMission: kungfu-technical-stewardship\nMission-Lens: principal-engineer\nMission-Track: external\nMission-Role: supporting\nMission-Importance: medium",
          "author": "dongkeren",
          "createdAt": "2026-07-05T14:23:52Z",
          "mergedAt": "2026-07-05T14:25:40Z",
          "additions": 1249,
          "deletions": 0,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 261,
          "url": "https://github.com/kungfu-systems/kungfu/pull/261",
          "title": "feat(gui,terminal): freeze a popped-out session's grid tile, and wire selection copy (ADR-0016 stage 4)",
          "body": "Merge feature/session-grid-overview into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T14:35:16Z",
          "mergedAt": "2026-07-05T14:35:22Z",
          "additions": 146,
          "deletions": 14,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 262,
          "url": "https://github.com/kungfu-systems/kungfu/pull/262",
          "title": "refactor(kfx): extract host-agnostic planKfx from the gui loader",
          "body": "Extract the discovery + trust/tier decision half of the gui kfx loader into planKfx in @kungfu-tech/kfx: fs/path/crypto injected, returns a neutral load plan (KfxPlanEntry) that instantiates no View/DOM/Electron. The gui loader becomes a thin planKfx + renderer-landing wrapper; KfxEntry = KfxPlanEntry & { View }. One load rule, ready for a second host to import (ADR-0017 stage 1). Pure refactor: kfx typecheck green, gui typecheck unchanged (only pre-existing base errors), load-decision equivalence checked across system/pinned/unpinned/untrusted/suite/dedup cases.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T14:36:34Z",
          "mergedAt": "2026-07-05T14:36:40Z",
          "additions": 281,
          "deletions": 201,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 260,
          "url": "https://github.com/kungfu-systems/kungfu/pull/260",
          "title": "docs: align architecture docs with skills and kfx sandbox",
          "body": "## Summary\n\n- Update public architecture docs for Kungfu Skills as the agent-facing layer above kfx.\n- Align kfx docs with source-authority trust, runtime-plane sandboxing, adapter refusal, and the proposed service facet.\n- Register Skill/KFX contract surfaces in the documentation map and versioning register so future agents can route architecture and version-impact questions from public docs.\n- Refresh known limits and concepts so current Skill/KFX/sandbox terminology is grounded from public docs.\n\n## Validation\n\n- `git diff --check origin/dev/v4/v4.0...HEAD`\n- targeted local-link check over the 9 changed docs\n- stale-phrase grep for old trust/shell wording\n- GitHub checks: Buildchain Validate, DCO\n\n## Known validation boundaries\n\n- `./kungfu-code lint` currently fails on pre-existing non-doc code style/import diagnostics outside this docs patch.\n- `./kungfu-code verify` quick mode fails in this fresh worktree because frozen `framework/core/dist/kungfu` / `kfc` artifacts are not present.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T14:34:12Z",
          "mergedAt": "2026-07-05T14:49:31Z",
          "additions": 218,
          "deletions": 87,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 263,
          "url": "https://github.com/kungfu-systems/kungfu/pull/263",
          "title": "build(core): adopt C++23",
          "body": "Raise the project C++ standard 20→23 (conan dep cppstd stays 17, decoupled). Validated clean builds on macOS (AppleClang 21) and Linux (GCC 13.3); only boost::hana emits deprecation warnings. Windows/MSVC build was env-blocked (missing _WINDOWS platform macro in the ad-hoc vcvars shell), not a C++23 incompatibility — a proper DARKHERO build verification is a fast-follow. Adopting now to keep the long-term core on a modern standard.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T14:50:32Z",
          "mergedAt": "2026-07-05T14:50:36Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 264,
          "url": "https://github.com/kungfu-systems/kungfu/pull/264",
          "title": "docs(core): update C++ standard references to C++23",
          "body": "CONTRIBUTING and the yijinjing EMBEDDING guide still said C++20; align them with the adopted CMAKE_CXX_STANDARD 23 (and CMake >= 3.20).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T14:55:45Z",
          "mergedAt": "2026-07-05T14:55:50Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 557,
          "url": "https://github.com/kungfu-systems/buildchain/pull/557",
          "title": "fix(passport): verify release passport before persistence",
          "body": "## Summary\n- verify collected release passports before durable persistence and again after release-state SHA backfill\n- omit trusted publishing evidence for npm-token releases so verifier does not treat token auth as failed trusted publishing\n- add a regression test proving invalid production passport evidence blocks durable passport persistence\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm -r --filter \"./actions/promote-buildchain-ref\" build\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T15:05:51Z",
          "mergedAt": "2026-07-05T15:07:45Z",
          "additions": 221,
          "deletions": 62,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 265,
          "url": "https://github.com/kungfu-systems/kungfu/pull/265",
          "title": "build(core): gradual mypy baseline + pilot type annotations",
          "body": "Python was ~6% annotated with no type checker. Adds mypy as a lenient, growing baseline (untyped defs skipped; native/unstubbed imports ignored; a 7-module snapshot of pre-existing errors ignored) wired into verify as stage 0b, and fully annotates rewind/adapters.py as the pilot. Modules opt into real checking as they gain annotations — no big-bang. Follow-up: fix the 7 snapshotted modules and expand annotation coverage.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T15:10:23Z",
          "mergedAt": "2026-07-05T15:10:29Z",
          "additions": 135,
          "deletions": 6,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 266,
          "url": "https://github.com/kungfu-systems/kungfu/pull/266",
          "title": "refactor(core): clear the mypy baseline snapshot (fix 7 modules)",
          "body": "Fix the 7 pre-existing type-error modules and remove the ignore-errors override — mypy now checks the whole kungfu package clean. Native pykungfu bindings typed Any, click decorators cast to CLI, click.Choice takes list(), tabulate marked untyped, managed-run provider table gets a _ProviderSpec TypedDict.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T15:22:37Z",
          "mergedAt": "2026-07-05T15:22:42Z",
          "additions": 29,
          "deletions": 29,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 267,
          "url": "https://github.com/kungfu-systems/kungfu/pull/267",
          "title": "refactor(core): annotate rewind first_party + cost_wire",
          "body": "Gradual typing goal Stage 1: annotate the first-party trust-set resolver and the cost snapshot->event bridge. mypy zero-override baseline stays green.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T15:45:05Z",
          "mergedAt": "2026-07-05T15:45:09Z",
          "additions": 15,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 268,
          "url": "https://github.com/kungfu-systems/kungfu/pull/268",
          "title": "refactor(core): annotate rewind events + fix cost_wire narrowing",
          "body": "Gradual typing goal Stage 1: annotate rewind/events.py (10 FlatBuffers serializers). Typing cost_snapshot surfaced a real float|None vs float mismatch in cost_wire — fixed by narrowing on snapshot.cost_usd. mypy zero-override baseline green.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T15:54:05Z",
          "mergedAt": "2026-07-05T15:54:10Z",
          "additions": 83,
          "deletions": 47,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 269,
          "url": "https://github.com/kungfu-systems/kungfu/pull/269",
          "title": "feat(kfx): add the config.service facet to planKfx",
          "body": "Merge feature/kfx-service-facet into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T16:05:05Z",
          "mergedAt": "2026-07-05T16:05:10Z",
          "additions": 186,
          "deletions": 35,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 270,
          "url": "https://github.com/kungfu-systems/kungfu/pull/270",
          "title": "test(capability): prove the service facet's os-sandbox network membrane",
          "body": "Merge feature/kfx-service-host into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T20:36:49Z",
          "mergedAt": "2026-07-05T20:36:55Z",
          "additions": 187,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 271,
          "url": "https://github.com/kungfu-systems/kungfu/pull/271",
          "title": "feat(capability): resolve a service's sandbox profile from a user grant",
          "body": "Merge feature/kfx-service-authz into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T23:24:45Z",
          "mergedAt": "2026-07-05T23:24:51Z",
          "additions": 382,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 272,
          "url": "https://github.com/kungfu-systems/kungfu/pull/272",
          "title": "feat(tui): land a discovered service kfx through the service host",
          "body": "Merge feature/kfx-service-dogfood into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T23:48:36Z",
          "mergedAt": "2026-07-05T23:48:42Z",
          "additions": 411,
          "deletions": 0,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 3,
          "url": "https://github.com/kungfu-systems/kfd/pull/3",
          "title": "docs: add non-coercive intelligence KFD",
          "body": "## Summary\n\n- add KFD-3: Non-coercive intelligence\n- define transparent value, stable choice, and explainable constraints as the stance toward humans and agents\n- update registry, README, and docs map\n\n## Verification\n\n- node scripts/check.mjs\n- git diff --check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T00:11:26Z",
          "mergedAt": "2026-07-06T00:11:52Z",
          "additions": 164,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 273,
          "url": "https://github.com/kungfu-systems/kungfu/pull/273",
          "title": "rewind: attribute managed-run cost to the GUI session, decode events by reflection",
          "body": "Two additive fact-base changes on the rewind path:\n- managed-run takes the GUI session runId (--run-id) so CostSnapshot/journal facts share one identity with the on-screen session.\n- the rewind capability decodes events by reflection over the manifest-bound .bfbs (no generated event classes); CostSnapshot and future event types decode with no per-type code. Also recovers schema-default scalars the reflection decoder was dropping.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T00:20:21Z",
          "mergedAt": "2026-07-06T00:20:26Z",
          "additions": 279,
          "deletions": 143,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 274,
          "url": "https://github.com/kungfu-systems/kungfu/pull/274",
          "title": "feat(tui): load kfx through the shared planKfx rule",
          "body": "Merge feature/kfx-tui-plan into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T01:07:54Z",
          "mergedAt": "2026-07-06T01:08:00Z",
          "additions": 237,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 275,
          "url": "https://github.com/kungfu-systems/kungfu/pull/275",
          "title": "refactor(core): annotate the capability sandbox guest (Stage 2)",
          "body": "Gradual typing goal Stage 2 — kfx sandbox boundary: fully annotate capability/guest.py (the whole capability/ Python surface). mypy zero-override baseline green.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T01:09:37Z",
          "mergedAt": "2026-07-06T01:09:42Z",
          "additions": 20,
          "deletions": 12,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 276,
          "url": "https://github.com/kungfu-systems/kungfu/pull/276",
          "title": "refactor(core): annotate the package + skill public API (Stage 3)",
          "body": "Gradual typing goal Stage 3 — SDK/public API: annotate kungfu/__init__.py and the skill public surface (context/catalog/registry/provider). Typing surfaced a real None-narrowing gap in inject_skill_context, now fixed. mypy zero-override baseline green.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T01:42:35Z",
          "mergedAt": "2026-07-06T01:42:41Z",
          "additions": 58,
          "deletions": 31,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 558,
          "url": "https://github.com/kungfu-systems/buildchain/pull/558",
          "title": "fix(governance): harden dev check gates",
          "body": "## Summary\n- add a reusable Buildchain check wrapper that runs declared lifecycle.install and lifecycle.verify\n- make the Buildchain Verify job dogfood the declarative lifecycle check path\n- default dev auto-merge and patrol required checks to the check job, and move dogfood patrol to the v2 floating runtime/default dev line\n- document check customization and patrol v2 floating defaults\n\n## Validation\n- bash scripts/check-workflows.sh\n- node --test tests/dev-pr-auto-merge.test.mjs tests/buildchain-patrol.test.mjs tests/build-surface.test.mjs\n- node bin/buildchain.mjs validate --require-version-state --require-lifecycle-stages install,verify\n- corepack pnpm@11.7.0 run check\n\n## Branch protection\n- updated dev/v2/v2.6 protection to require strict check status and one approving review\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T01:48:58Z",
          "mergedAt": "2026-07-06T01:53:20Z",
          "additions": 218,
          "deletions": 45,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 4,
          "url": "https://github.com/kungfu-systems/kfd/pull/4",
          "title": "docs: polish KFD foundation triad",
          "body": "## Summary\n- Add a README foundation triad for KFD-1/2/3: contract, truth, and relationship paths\n- Clarify KFD-1's relationship to KFD-2 and KFD-3\n- Tighten KFD-2 and KFD-3 wording without changing numbers, kinds, statuses, registry schema, or package structure\n\n## Verification\n- node scripts/check.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:00:39Z",
          "mergedAt": "2026-07-06T02:00:57Z",
          "additions": 75,
          "deletions": 13,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 5,
          "url": "https://github.com/kungfu-systems/kfd/pull/5",
          "title": "docs: add KFD product proof path",
          "body": "## Summary\n- Add a short product proof path note under the KFD foundation triad\n- Clarify that active KFDs should be reflected in product behavior, release evidence, documentation, or conformance checks\n- Identify the main Kungfu product as the primary proof surface for product philosophy KFDs\n\n## Verification\n- node scripts/check.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:02:29Z",
          "mergedAt": "2026-07-06T02:02:41Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 6,
          "url": "https://github.com/kungfu-systems/kfd/pull/6",
          "title": "docs: point KFD proof path to product entrypoints",
          "body": "## Summary\n- Refine the product proof path note so it points to verification entrypoints instead of listing concrete product functions\n- Point product philosophy verification to the main Kungfu product entrypoint\n- Point release/provenance accountability verification to Buildchain\n\n## Verification\n- node scripts/check.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:04:08Z",
          "mergedAt": "2026-07-06T02:04:54Z",
          "additions": 7,
          "deletions": 6,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 277,
          "url": "https://github.com/kungfu-systems/kungfu/pull/277",
          "title": "refactor(core): annotate the rewind cost adapters + schema/export plumbing",
          "body": "Merge feature/py-typing-rewind-cost into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:19:41Z",
          "mergedAt": "2026-07-06T02:19:46Z",
          "additions": 50,
          "deletions": 21,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 278,
          "url": "https://github.com/kungfu-systems/kungfu/pull/278",
          "title": "refactor(core): annotate the rewind capture pipeline (L0-L2)",
          "body": "Merge feature/py-typing-rewind-plumbing into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:32:34Z",
          "mergedAt": "2026-07-06T02:32:39Z",
          "additions": 60,
          "deletions": 32,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 561,
          "url": "https://github.com/kungfu-systems/buildchain/pull/561",
          "title": "chore(release): prepare v2.6 alpha version state",
          "body": "## Summary\n- align package.json version with the active dev/v2/v2.6 release line\n- unblock dev/v2/v2.6 -> alpha/v2/v2.6 release-line verification\n\n## Validation\n- node bin/buildchain.mjs validate --require-version-state --require-lifecycle-stages install,verify\n- BUILDCHAIN_HEAD_REF=dev/v2/v2.6 BUILDCHAIN_BASE_REF=alpha/v2/v2.6 node scripts/verify-release-pr.mjs\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:36:46Z",
          "mergedAt": "2026-07-06T02:39:03Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 559,
          "url": "https://github.com/kungfu-systems/buildchain/pull/559",
          "title": "chore(release): promote v2.6 alpha",
          "body": "## Summary\n- promote the protected dev/v2/v2.6 line into alpha/v2/v2.6\n- release automation will create the alpha version-state commit and publish the alpha package through Buildchain promotion\n\n## Validation\n- branch protection requires the check job before merge\n- source lineage is dev/v2/v2.6 -> alpha/v2/v2.6\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:34:08Z",
          "mergedAt": "2026-07-06T02:40:48Z",
          "additions": 1689,
          "deletions": 108,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 279,
          "url": "https://github.com/kungfu-systems/kungfu/pull/279",
          "title": "refactor(core): annotate replay + the managed-run entry",
          "body": "Merge feature/py-typing-rewind-cli into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:44:11Z",
          "mergedAt": "2026-07-06T02:44:16Z",
          "additions": 69,
          "deletions": 53,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 563,
          "url": "https://github.com/kungfu-systems/buildchain/pull/563",
          "title": "chore(release): refresh promote action bundle",
          "body": "## Summary\n- refresh the committed promote-buildchain-ref action bundle generated by the current toolchain\n- unblock v2.6 alpha promotion verification, which fails when lifecycle.verify rebuilds the bundle during promotion\n\n## Validation\n- corepack pnpm@11.7.0 run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:47:51Z",
          "mergedAt": "2026-07-06T02:49:42Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 564,
          "url": "https://github.com/kungfu-systems/buildchain/pull/564",
          "title": "chore(release): promote v2.6 alpha bundle fix",
          "body": "## Summary\n- promote the generated action bundle refresh from dev/v2/v2.6 into alpha/v2/v2.6\n- retry the v2.6 alpha promotion with lifecycle.verify no longer changing dist files\n\n## Context\n- Previous alpha promotion reached post-merge promotion but failed because lifecycle.verify rebuilt actions/promote-buildchain-ref/dist/index.js.\n- PR #563 fixed the committed bundle on dev/v2/v2.6 and passed check plus Build Surface Fixture.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:50:12Z",
          "mergedAt": "2026-07-06T02:51:59Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 7,
          "url": "https://github.com/kungfu-systems/kfd/pull/7",
          "title": "docs: clarify KFD foundation titles",
          "body": "## Summary\n- retitle KFD-1/2/3 so the foundation reads as contract -> fact -> cooperation\n- remove version-line anchoring from KFD-1 title and one-sentence summary\n- add config contracts as a concrete KFD-1 implementation surface alongside versioning\n\n## Validation\n- node scripts/check.mjs\n- git diff --check\n\n## Release impact\n- KFD content patch only\n- no number, slug, kind, registry schema, or package-structure change",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:51:25Z",
          "mergedAt": "2026-07-06T02:53:20Z",
          "additions": 42,
          "deletions": 24,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 567,
          "url": "https://github.com/kungfu-systems/buildchain/pull/567",
          "title": "chore(release): promote v2.6 stable",
          "body": "## Summary\n- promote Buildchain v2.6 from alpha/v2/v2.6 to release/v2/v2.6\n- publish the stable v2.6 release after alpha promotion succeeded\n\n## Validation\n- alpha promotion succeeded for v2.6.0-alpha.0\n- npm alpha dist-tag points to 2.6.0-alpha.0\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:56:43Z",
          "mergedAt": "2026-07-06T02:58:42Z",
          "additions": 1689,
          "deletions": 108,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 568,
          "url": "https://github.com/kungfu-systems/buildchain/pull/568",
          "title": "Release v2.6.0",
          "body": "Create the generated version-state commit for v2.6.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:00:54Z",
          "mergedAt": "2026-07-06T03:02:41Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 281,
          "url": "https://github.com/kungfu-systems/kungfu/pull/281",
          "title": "feat(terminal): honest per-session cost badge on the session tile",
          "body": "Show each managed session's rolled-up cost on its tile: a dollar total when every CostSnapshot's usd is known, else a token count (never a fake $0); amber '~' for ambiguous attribution, dotted underline for observed (non-exact-run) attribution. Also journal a managed run into the ambient runtime home so its cost facts are discoverable by the tile, and declare the rewind capability the view uses. Follows S1+S2a (PR#273).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:08:37Z",
          "mergedAt": "2026-07-06T03:08:42Z",
          "additions": 70,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 570,
          "url": "https://github.com/kungfu-systems/buildchain/pull/570",
          "title": "fix(release): pass surface impact to release passports",
          "body": "## Summary\n- expose release-passport-impact-json on the release-candidate promote wrapper\n- pass Buildchain's surface-aware release impact into self promotion\n- add contract checks so production release passports have surface impact input\n\n## Validation\n- node scripts/check-inventory.mjs\n- node --test tests/build-surface.test.mjs\n- bash scripts/check-workflows.sh\n- corepack pnpm@11.7.0 run check\n\n## Context\n- Fixes the v2.6.0 finalization failure where production release passport verification required surfaceImpacts[].\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:08:42Z",
          "mergedAt": "2026-07-06T03:11:25Z",
          "additions": 15,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 282,
          "url": "https://github.com/kungfu-systems/kungfu/pull/282",
          "title": "feat(config): make Kungfu config contract-first",
          "body": "## Summary\n\n- add `framework/config/kungfu-config.contract.json` as the KFD-1 source for config schema, defaults, resolution rules, contract self-schema, and schema ids\n- load the same contract from Python, Node/TypeScript, and frozen artifacts; expose `kungfu config contract/schema/defaults/show --json`\n- add managed-run agent environment pointers that keep envelopes compact and point agents to `kungfu agent context --json`\n- copy the contract during build/freeze and extend `kungfu-code verify` to check repo hash, artifact hash, and frozen runtime-reported hash\n- register `config-contract` in `docs/versioning.md` and document the config contract surface\n\n## Verification\n\n- `PYTHONPATH=src/python uv run --frozen ruff check src/python/kungfu/config.py src/python/kungfu/cli/commands/config.py src/python/kungfu/skill/context.py src/python/kungfu/skill/provider.py src/python/kungfu/rewind/managed_cli.py tests/python/test_skill.py`\n- `PYTHONPATH=src/python uv run --frozen mypy src/python/kungfu/config.py src/python/kungfu/cli/commands/config.py src/python/kungfu/skill/context.py src/python/kungfu/skill/provider.py src/python/kungfu/rewind/managed_cli.py`\n- `PYTHONPATH=src/python uv run --frozen pytest tests/python/test_skill.py`\n- `./kungfu-code --filter @kungfu-tech/skill run build`\n- `./kungfu-code --filter @kungfu-tech/skill run test:golden`\n- `./kungfu-code freeze`\n- `./kungfu-code verify`\n\n## Notes\n\n`./kungfu-code verify` now reports `kfc config contract smoke` and confirms the frozen runtime hash matches the repo contract hash.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:11:05Z",
          "mergedAt": "2026-07-06T03:12:15Z",
          "additions": 2064,
          "deletions": 44,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 571,
          "url": "https://github.com/kungfu-systems/buildchain/pull/571",
          "title": "chore(release): prepare v2.6.1 alpha version state",
          "body": "## Summary\n- prepare dev/v2/v2.6 for the next v2.6 patch alpha release\n- bump package version to 2.6.1-alpha.0 after v2.6.0 stable was published\n\n## Validation\n- corepack pnpm@11.7.0 install --frozen-lockfile\n- node bin/buildchain.mjs validate --require-version-state --require-lifecycle-stages install,verify\n- BUILDCHAIN_HEAD_REF=dev/v2/v2.6 BUILDCHAIN_BASE_REF=alpha/v2/v2.6 node scripts/verify-release-pr.mjs\n- corepack pnpm@11.7.0 run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:13:35Z",
          "mergedAt": "2026-07-06T03:15:08Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 572,
          "url": "https://github.com/kungfu-systems/buildchain/pull/572",
          "title": "chore(release): promote v2.6.1 alpha",
          "body": "## Summary\n- promote v2.6.1-alpha.0 to alpha/v2/v2.6\n- include the release passport surface impact fix in the alpha channel\n\n## Validation\n- #570 passed local full check and PR checks\n- #571 prepared package version 2.6.1-alpha.0 and passed PR checks\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:15:48Z",
          "mergedAt": "2026-07-06T03:17:35Z",
          "additions": 16,
          "deletions": 1,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 283,
          "url": "https://github.com/kungfu-systems/kungfu/pull/283",
          "title": "refactor(core): tighten strict-mode type precision (zero-risk subset)",
          "body": "Merge feature/py-strict-type-fixes into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:23:19Z",
          "mergedAt": "2026-07-06T03:23:24Z",
          "additions": 33,
          "deletions": 25,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 575,
          "url": "https://github.com/kungfu-systems/buildchain/pull/575",
          "title": "chore(release): promote v2.6.1 stable",
          "body": "## Summary\n- merge the v2.6.1 alpha branch fixes into release/v2/v2.6\n- resolve the release version state to stable 2.6.1\n- keep release-candidate-promote passport impact wiring from alpha\n\n## Validation\n- BUILDCHAIN_HEAD_REF=fix/release-line-v2-v2.6-2.6.1-stable BUILDCHAIN_BASE_REF=release/v2/v2.6 node scripts/verify-release-pr.mjs\n- corepack pnpm@11.7.0 run check\n\nThis replaces #574, which could not be cleanly merged because release/v2/v2.6 already contains v2.6.0 finalization version-state commits.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:24:27Z",
          "mergedAt": "2026-07-06T03:26:07Z",
          "additions": 16,
          "deletions": 1,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 576,
          "url": "https://github.com/kungfu-systems/buildchain/pull/576",
          "title": "Prepare v2.6.2-alpha.0",
          "body": "Create the generated version-state commit for v2.6.2-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:28:38Z",
          "mergedAt": "2026-07-06T03:30:22Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 577,
          "url": "https://github.com/kungfu-systems/buildchain/pull/577",
          "title": "Prepare v2.6.2-alpha.0",
          "body": "Create the generated version-state commit for v2.6.2-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:32:27Z",
          "mergedAt": "2026-07-06T03:34:34Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 8,
          "url": "https://github.com/kungfu-systems/kfd/pull/8",
          "title": "docs(readme): explain KFD foundation model",
          "body": "## What\n\n- Adds a README foundation model that makes the KFD-1/2/3 worldview explicit.\n- Links docs/MAP.md to the new foundation-model section.\n\n## Registry agreement\n\n- [x] `node scripts/check.mjs` passes\n- [x] Decision texts remain append-only (README/docs navigation only)\n\n## Version impact (per KFD-1)\n\n- [x] patch (content operation)",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:35:29Z",
          "mergedAt": "2026-07-06T03:35:55Z",
          "additions": 45,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 284,
          "url": "https://github.com/kungfu-systems/kungfu/pull/284",
          "title": "fix(core): drop unused PrioritizedCommandGroup import in trace command",
          "body": "Merge feature/fix-ruff-dead-import into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:39:21Z",
          "mergedAt": "2026-07-06T03:39:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 285,
          "url": "https://github.com/kungfu-systems/kungfu/pull/285",
          "title": "refactor(core): resolve the judgment-call strict findings (behavior-preserving)",
          "body": "Merge feature/py-strict-type-fixes-b into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:46:02Z",
          "mergedAt": "2026-07-06T03:46:08Z",
          "additions": 26,
          "deletions": 18,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 286,
          "url": "https://github.com/kungfu-systems/kungfu/pull/286",
          "title": "feat(agent): ship local onboarding pack",
          "body": "## Summary\n- ship a local Kungfu Agent Onboarding Pack with docs, command metadata, mode selection, safety boundaries, and provider skills\n- expose `kungfu agent` as the local discovery surface and package the pack into the frozen runtime\n- extend verification so pack files, package data, frozen data files, GUI/TUI pointers, and kfx sandbox fixtures stay covered\n\n## Validation\n- `./kungfu-code verify --full --with-app` -> 39/39 passed on the linear branch\n- `node scripts/no-bash-guard.mjs && git diff --check`\n- `node scripts/verify-agent-pack.mjs`\n- `uv run --frozen mypy src/python/kungfu`\n\nSupersedes #280; this branch has an identical tracked tree but a linear single-commit history for the repository rebase-only merge policy.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:54:09Z",
          "mergedAt": "2026-07-06T03:54:44Z",
          "additions": 982,
          "deletions": 26,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 287,
          "url": "https://github.com/kungfu-systems/kungfu/pull/287",
          "title": "feat(kfx): add the C++ guest capability end and prebuilt-artifact service entry",
          "body": "Merge feature/kfx-cpp-guest into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:56:44Z",
          "mergedAt": "2026-07-06T03:56:49Z",
          "additions": 1172,
          "deletions": 17,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 9,
          "url": "https://github.com/kungfu-systems/kfd/pull/9",
          "title": "docs(kfd-3): clarify augmentation stance",
          "body": "## What\n\n- Clarifies KFD-3 as an augmentation stance rather than a control stance.\n- Makes the shared work environment / first-class agent interface model explicit in README and KFD-3.\n\n## Registry agreement\n\n- [x] `node scripts/check.mjs` passes\n- [x] Decision texts remain append-only (editorial clarification)\n\n## Version impact (per KFD-1)\n\n- [x] patch (content operation)",
          "author": "dongkeren",
          "createdAt": "2026-07-06T04:19:19Z",
          "mergedAt": "2026-07-06T04:19:38Z",
          "additions": 16,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 578,
          "url": "https://github.com/kungfu-systems/buildchain/pull/578",
          "title": "fix(release): enforce GitHub release metadata",
          "body": "## Summary\n- add a Buildchain helper that creates or patches GitHub Releases with tag-derived metadata\n- mark exact alpha releases as prerelease and never latest\n- mark exact stable releases as latest\n- replace unmanaged `gh release create` in binary distribution with the helper\n\n## Validation\n- node --test tests/github-release-metadata.test.mjs\n- node --test tests/build-surface.test.mjs\n- node scripts/check-inventory.mjs\n- bash scripts/check-workflows.sh\n- corepack pnpm@11.7.0 run check\n\nDogfood plan: after merge to dev, promote through alpha and verify the generated alpha GitHub Release is `isPrerelease=true` and `isLatest=false`, while the stable v2.6.1 release remains latest.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T04:26:55Z",
          "mergedAt": "2026-07-06T04:28:35Z",
          "additions": 317,
          "deletions": 2,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 579,
          "url": "https://github.com/kungfu-systems/buildchain/pull/579",
          "title": "chore(release): promote v2.6.3 alpha metadata fix",
          "body": "## Summary\n- dogfood the GitHub Release metadata enforcement added in #578\n- promote the dev line into alpha so the next alpha release is created by Buildchain itself\n\n## Validation\n- dev Verify succeeded: https://github.com/kungfu-systems/buildchain/actions/runs/28767844148\n\nExpected dogfood result: the generated exact alpha GitHub Release must be prerelease=true and latest=false, and npm latest must remain the stable release.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T04:29:46Z",
          "mergedAt": "2026-07-06T04:31:36Z",
          "additions": 317,
          "deletions": 2,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 580,
          "url": "https://github.com/kungfu-systems/buildchain/pull/580",
          "title": "Prepare v2.6.2-alpha.1",
          "body": "Create the generated version-state commit for v2.6.2-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T04:33:42Z",
          "mergedAt": "2026-07-06T04:36:07Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 581,
          "url": "https://github.com/kungfu-systems/buildchain/pull/581",
          "title": "Prepare v2.6.2-alpha.1",
          "body": "Create the generated version-state commit for v2.6.2-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T04:38:08Z",
          "mergedAt": "2026-07-06T04:41:02Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 288,
          "url": "https://github.com/kungfu-systems/kungfu/pull/288",
          "title": "feat(kfx): add KFD-1 contract validation",
          "body": "## Summary\n- add `framework/kfx/kungfu-kfx.contract.json` as the machine-readable KFX contract for package manifests, first-party manifests, discovery defaults, and contract metadata\n- validate KFX manifests from Node (`@kungfu-tech/kfx`, GUI, SDK) and Python (`kungfu kfx`, skill dependency binding, first-party trust) against the same JSON Schema contract\n- freeze the KFX contract into `dist/kungfu/config`, add artifact hash verification and frozen runtime `kungfu kfx contract --json` smoke coverage\n- document the KFX contract as a KFD-1 welded surface in `docs/contracts.md`, `docs/extensions.md`, and `docs/versioning.md`\n\n## Validation\n- `./kungfu-code verify --full` -> `40/40 passed`\n- full verify rebuilt core native artifacts, froze the runtime, built C++ and Python KFX probes, checked KFX/config contract artifact hashes, and ran journal fact fixtures\n\n## Notes\n- Added `ajv` for Node JSON Schema validation rather than hand-rolling schema checks.\n- The generated LangChain fixture venv remains git-ignored; the no-bash guard skips venv-style cache directories so third-party package scripts do not fail the repo gate.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T05:05:15Z",
          "mergedAt": "2026-07-06T05:06:08Z",
          "additions": 1118,
          "deletions": 101,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 290,
          "url": "https://github.com/kungfu-systems/kungfu/pull/290",
          "title": "feat(contract): add shared KFD-1 contract registry",
          "body": "Summary:\n- Add a shared KFD-1 contract registry for config, kfx, and skill welded contract artifacts.\n- Add Python/Node runtime helpers and CLI inspection for contract verification.\n- Make build/freeze/verify copy and hash-check registry-driven contract artifacts.\n\nValidation:\n- ./kungfu-code verify --full passed 49/49.\n- Frozen CLI smokes passed: kungfu contract verify --json, kungfu skill contract --json, kungfu skill schema --name source --json, kungfu --version.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T05:49:39Z",
          "mergedAt": "2026-07-06T05:50:43Z",
          "additions": 1071,
          "deletions": 177,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 582,
          "url": "https://github.com/kungfu-systems/buildchain/pull/582",
          "title": "chore(release): promote v2.6.2",
          "body": "Promote Buildchain v2.6.2 from alpha to stable release.\\n\\nValidation focus:\\n- GitHub Release metadata helper dogfooded on alpha.\\n- Stable release should publish latest and make GitHub Release latest.\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T05:48:59Z",
          "mergedAt": "2026-07-06T05:50:46Z",
          "additions": 318,
          "deletions": 3,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 583,
          "url": "https://github.com/kungfu-systems/buildchain/pull/583",
          "title": "Release v2.6.2",
          "body": "Create the generated version-state commit for v2.6.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T05:53:06Z",
          "mergedAt": "2026-07-06T05:55:11Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 584,
          "url": "https://github.com/kungfu-systems/buildchain/pull/584",
          "title": "Prepare v2.6.3-alpha.0",
          "body": "Create the generated version-state commit for v2.6.3-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T05:57:38Z",
          "mergedAt": "2026-07-06T05:59:23Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 291,
          "url": "https://github.com/kungfu-systems/kungfu/pull/291",
          "title": "feat(rewind): add fact bridge ingestion sync",
          "body": "## Summary\n- add `kungfu report` for external, non-managed run lifecycle, cost, approval, and event facts\n- add `kungfu remote` source registry and source-scoped runtime mirror sync for `journal` / `rewind` / `work`\n- expose remote mirrored work/runs with `remote:<source-id>`, `sync_state`, `last_synced_at`, and `capture_mode` labels through CLI/API\n- wire the remote work projection into the GUI runtime handle and reference TUI summary\n- update agent onboarding pack and Rewind API projection for reported approval fields\n\n## Verification\n- `./kungfu-code verify --full` (51/51 passed on linear branch)\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T06:36:02Z",
          "mergedAt": "2026-07-06T06:36:46Z",
          "additions": 1630,
          "deletions": 24,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 585,
          "url": "https://github.com/kungfu-systems/buildchain/pull/585",
          "title": "feat(release): add release propagation graph",
          "body": "## Summary\n\n- adds a passport-driven release propagation graph core with DAG validation, default channel-preserving alpha/release mapping, exact upstream package/passport locks, and downstream lock writing\n- adds `buildchain release-propagation plan|write-lock` plus the `@kungfu-tech/buildchain/release-propagation` export\n- adds `.github/workflows/release-propagation.yml` so upstream releases can create downstream lock PRs without consumer hand-written resolver/lock YAML\n- documents the generic A -> B -> C model and includes a safe `kfd -> site-libkungfu-dev` shaped fixture\n- refreshes `dist/site` so site consumers can render the new docs/CLI/workflow facts from the package bundle\n\n## Validation\n\n- `node --test tests/release-propagation.test.mjs`\n- `pnpm run check:workflows`\n- `pnpm run test:unit` (320 tests)\n- `pnpm run check`\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org/` with package contents check for new core/CLI/docs/fixture README\n\n## Notes\n\n- This PR targets the new protected `dev/v2/v2.7` line.\n- `dev/v2/v2.7` has branch protection enabled with required `check`, strict status checks, admin enforcement, one approving review, no force pushes/deletions, and conversation resolution required.\n- The reusable workflow defaults to dry-run; real downstream PR creation requires a token with downstream contents and pull request write permission.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T06:48:20Z",
          "mergedAt": "2026-07-06T06:50:14Z",
          "additions": 1090,
          "deletions": 0,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 589,
          "url": "https://github.com/kungfu-systems/buildchain/pull/589",
          "title": "chore(release): initialize v2.7 version state",
          "body": "Initialize the v2.7 development line package version as 2.7.0-alpha.0 so dev/v2/v2.7 -> alpha/v2/v2.7 release PR verification can pass.\\n\\nValidation:\\n- BUILDCHAIN_HEAD_REF=dev/v2/v2.7 BUILDCHAIN_BASE_REF=alpha/v2/v2.7 BUILDCHAIN_SOURCE_CWD=/Users/dkr/Worktrees/buildchain/feature/release-propagation-graph node scripts/verify-release-pr.mjs\\n- pnpm run check:site\\n- node --test tests/release-line-policy.test.mjs tests/cli.test.mjs --test-name-pattern 'release dry-run|version'",
          "author": "dongkeren",
          "createdAt": "2026-07-06T06:55:31Z",
          "mergedAt": "2026-07-06T06:57:31Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 10,
          "url": "https://github.com/kungfu-systems/kfd/pull/10",
          "title": "Add KFD npm trusted publishing workflow",
          "body": "## Summary\n- align published KFD package paths for site consumption\n- add npm trusted publishing workflow using GitHub Actions OIDC\n- bump package to 1.0.0-alpha.1 for trusted publishing verification\n\n## Verification\n- node scripts/check.mjs\n- actionlint .github/workflows/publish-npm.yml\n- npm pack --dry-run --json\n- npm trust list @kungfu-tech/kfd --json --registry=https://registry.npmjs.org/\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-06T06:36:15Z",
          "mergedAt": "2026-07-06T06:58:04Z",
          "additions": 568,
          "deletions": 29,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 586,
          "url": "https://github.com/kungfu-systems/buildchain/pull/586",
          "title": "release: promote v2.7 alpha",
          "body": "Promote Buildchain v2.7 development line to alpha after release propagation graph landed.\\n\\nValidation already passed on #585: `pnpm run check` and Buildchain dogfood fixture checks.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T06:52:34Z",
          "mergedAt": "2026-07-06T06:59:30Z",
          "additions": 1091,
          "deletions": 1,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 11,
          "url": "https://github.com/kungfu-systems/kfd/pull/11",
          "title": "chore(release): promote dev to alpha v1.0",
          "body": "Promote the KFD dev line to alpha after routing releases through Buildchain-managed publish transactions.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T06:59:33Z",
          "mergedAt": "2026-07-06T07:01:32Z",
          "additions": 388,
          "deletions": 11,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 591,
          "url": "https://github.com/kungfu-systems/buildchain/pull/591",
          "title": "release: promote v2.7 stable",
          "body": "Promote Buildchain v2.7 alpha to stable after alpha promotion succeeded.\\n\\nAlpha evidence:\\n- tag: v2.7.0-alpha.0\\n- npm dist-tag alpha: 2.7.0-alpha.0\\n- alpha branch: e6f1bb7143fa37e1d20d493ab175a8f263405660",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:02:15Z",
          "mergedAt": "2026-07-06T07:04:15Z",
          "additions": 1091,
          "deletions": 1,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 12,
          "url": "https://github.com/kungfu-systems/kfd/pull/12",
          "title": "ci(buildchain): pass promotion token to release workflow",
          "body": "Map the organization GitHub token to Buildchain's promotion-token secret input so KFD promotion can read protected branch governance details instead of falling back to the default GITHUB_TOKEN.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:03:58Z",
          "mergedAt": "2026-07-06T07:05:39Z",
          "additions": 4,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 13,
          "url": "https://github.com/kungfu-systems/kfd/pull/13",
          "title": "chore(release): promote Buildchain token mapping to alpha",
          "body": "Promote the KFD release workflow token mapping so Buildchain promotion can read protected branch governance details before npm publish.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:06:04Z",
          "mergedAt": "2026-07-06T07:08:10Z",
          "additions": 4,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 590,
          "url": "https://github.com/kungfu-systems/buildchain/pull/590",
          "title": "Prepare v2.7.0-alpha.0",
          "body": "Create the generated version-state commit for v2.7.0-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:01:36Z",
          "mergedAt": "2026-07-06T07:10:40Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 593,
          "url": "https://github.com/kungfu-systems/buildchain/pull/593",
          "title": "Release v2.7.0",
          "body": "Create the generated version-state commit for v2.7.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:06:27Z",
          "mergedAt": "2026-07-06T07:10:40Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 292,
          "url": "https://github.com/kungfu-systems/kungfu/pull/292",
          "title": "feat(sdk): add KFD contract evidence",
          "body": "## Summary\n\nAdd the first KFD-native SDK contract prototype for local contract adoption, explicit writes, generated fixtures, and advisory evidence output.\n\nThis PR does not change release policy, does not edit KFD text, and does not enforce a new release gate. It shapes local JSON evidence so a future Buildchain/release-passport task can consume Kungfu-owned contract facts instead of redefining them.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Add `kungfu sdk contract adopt <surface> --source <path> --json` for existing config/kfx/skill contract sources.\n- Add `kungfu sdk contract render <surface> --check|--write --json`.\n- Add `kungfu sdk contract add <surface> --json` with registry entry and deterministic drift/probe fixture generation.\n- Add `kungfu sdk contract evidence [surface] --json` as read-only KFD-1 local evidence.\n- Document the KFD-1/2/3 SDK and future release-gate design.\n\n## Verification\n\n- `./kungfu-code --filter @kungfu-tech/sdk run build`\n- `./kungfu-code exec biome check developer/sdk/src/sdk.js developer/sdk/tests/contract-cli.test.mjs`\n- `node developer/sdk/src/sdk.js contract evidence --json`\n- `git diff --check origin/dev/v4/v4.0..HEAD`\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: this PR adds advisory local SDK evidence for KFD-1 contracts. It does not enforce release policy, publish artifacts, or change release workflows.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:10:47Z",
          "mergedAt": "2026-07-06T07:11:55Z",
          "additions": 1147,
          "deletions": 9,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 14,
          "url": "https://github.com/kungfu-systems/kfd/pull/14",
          "title": "ci(buildchain): ignore Buildchain runtime state",
          "body": "Ignore Buildchain runtime and release-candidate scratch files so version-state verification only sees intentional version file changes.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T07:11:40Z",
          "mergedAt": "2026-07-06T07:13:48Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 15,
          "url": "https://github.com/kungfu-systems/kfd/pull/15",
          "title": "chore(release): promote Buildchain runtime ignore to alpha",
          "body": "Promote the .buildchain ignore fix so Buildchain version-state verification can proceed without treating runtime scratch files as product source changes.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:14:09Z",
          "mergedAt": "2026-07-06T07:16:02Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 595,
          "url": "https://github.com/kungfu-systems/buildchain/pull/595",
          "title": "Prepare v2.7.1-alpha.0",
          "body": "Create the generated version-state commit for v2.7.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:13:29Z",
          "mergedAt": "2026-07-06T07:16:30Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 16,
          "url": "https://github.com/kungfu-systems/kfd/pull/16",
          "title": "Prepare v1.0.0-alpha.1",
          "body": "Create the generated version-state commit for v1.0.0-alpha.1.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T07:16:54Z",
          "mergedAt": "2026-07-06T07:18:37Z",
          "additions": 19,
          "deletions": 5,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 17,
          "url": "https://github.com/kungfu-systems/kfd/pull/17",
          "title": "Prepare v1.0.0-alpha.1",
          "body": "Create the generated version-state commit for v1.0.0-alpha.1.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T07:19:23Z",
          "mergedAt": "2026-07-06T07:21:17Z",
          "additions": 19,
          "deletions": 5,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 293,
          "url": "https://github.com/kungfu-systems/kungfu/pull/293",
          "title": "feat(agent): add codex goal report bootstrap",
          "body": "## Summary\n- add `kungfu codex report-goal` and `verify-goal-report` for native Codex goal receipts\n- add agent bootstrap/status/mode/unbootstrap/uninstall policy surfaces with dry-run defaults\n- update the agent onboarding pack and skills so report closeout verifies receipts and managed-run keeps report as fallback\n- add fixtures for Codex goal receipts and agent bootstrap behavior\n\n## Verification\n- `uv run --frozen python -m py_compile src/python/kungfu/cli/commands/agent.py src/python/kungfu/cli/commands/codex.py src/python/kungfu/cli/commands/__registry__.py`\n- `node scripts/verify-agent-pack.mjs`\n- `node tests/fixtures/rewind-demo-codex-goal-report/run.mjs`\n- `node tests/fixtures/agent-demo-bootstrap/run.mjs`\n- `./kungfu-code build:core`\n- `./kungfu-code freeze`\n- `./kungfu-code verify`\n- frozen CLI smoke: `kungfu codex report-goal` + `kungfu codex verify-goal-report`\n\n## Notes\n- `./kungfu-code --filter @kungfu-tech/core run package` reached binary staging but then failed in an existing package script path handling error (`ERR_INVALID_ARG_TYPE` in `framework/core/.gyp/run-build.js`).\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:31:12Z",
          "mergedAt": "2026-07-06T07:32:06Z",
          "additions": 913,
          "deletions": 12,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 18,
          "url": "https://github.com/kungfu-systems/kfd/pull/18",
          "title": "feat(metadata): expose KFD standards metadata",
          "body": "## Summary\n- add standards.json as the KFD-owned machine metadata surface for standard keys, document routes, schema IDs, and concept names\n- add JSON schemas for the standards metadata contract and KFD-1 contract-world/witness schema identities\n- publish the new metadata surface through package files and explicit subpath exports\n\n## Validation\n- node scripts/check.mjs\n- npm pack --dry-run --json\n- local package import smoke for @kungfu-tech/kfd/standards.json\n\n## Release impact\n- additive package structure and standards metadata surface; release-impact.json marks the Buildchain impact as minor",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:02:45Z",
          "mergedAt": "2026-07-06T08:04:42Z",
          "additions": 556,
          "deletions": 13,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 19,
          "url": "https://github.com/kungfu-systems/kfd/pull/19",
          "title": "ci(metadata): include standards metadata in artifacts",
          "body": "## Summary\n- include standards.json and schemas/ in Buildchain release candidate artifacts\n- require the standards metadata schema and KFD-1 schema identity files in artifact validation\n\n## Validation\n- node scripts/check.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:06:29Z",
          "mergedAt": "2026-07-06T08:08:20Z",
          "additions": 3,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 20,
          "url": "https://github.com/kungfu-systems/kfd/pull/20",
          "title": "ci(build): limit KFD verification to Linux",
          "body": "## Summary\n- switch the KFD Buildchain reusable build call to a custom single-platform matrix\n- keep only the Linux x64 GitHub-hosted runner for KFD package verification\n\n## Validation\n- node scripts/check.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:09:57Z",
          "mergedAt": "2026-07-06T08:11:18Z",
          "additions": 3,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 21,
          "url": "https://github.com/kungfu-systems/kfd/pull/21",
          "title": "release(alpha): promote KFD standards metadata",
          "body": "## Summary\n- promote KFD standards metadata and Linux-only KFD verification from dev to alpha\n- publish a new @kungfu-tech/kfd alpha through Buildchain ref promotion after alpha Verify succeeds\n\n## Validation before channel PR\n- PR #18: metadata package surface checks passed\n- PR #19: metadata artifact checks passed\n- PR #20: Linux-only Buildchain matrix checks passed",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:12:20Z",
          "mergedAt": "2026-07-06T08:15:12Z",
          "additions": 562,
          "deletions": 15,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 22,
          "url": "https://github.com/kungfu-systems/kfd/pull/22",
          "title": "Prepare v1.0.0-alpha.2",
          "body": "Create the generated version-state commit for v1.0.0-alpha.2.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T08:16:09Z",
          "mergedAt": "2026-07-06T08:21:36Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 23,
          "url": "https://github.com/kungfu-systems/kfd/pull/23",
          "title": "Prepare v1.0.0-alpha.2",
          "body": "Create the generated version-state commit for v1.0.0-alpha.2.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T08:22:27Z",
          "mergedAt": "2026-07-06T08:24:40Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 294,
          "url": "https://github.com/kungfu-systems/kungfu/pull/294",
          "title": "fix(terminal): scope the managed tmux socket to the runtime home",
          "body": "A tmux server freezes its env at creation; the managed backend used one fixed -L kungfu-managed socket for every runtime home, so a server started by one home could leak its stale KF_RUNTIME_DIR/launcher into a managed session created later by a different home (cost/journal facts then landed in the wrong home). Derive the socket per runtime home (kungfu-managed-<hash>): each server belongs to exactly one home, deterministic so restart reattaches, KF_TMUX_SOCKET still overrides.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:27:43Z",
          "mergedAt": "2026-07-06T08:27:49Z",
          "additions": 31,
          "deletions": 7,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 598,
          "url": "https://github.com/kungfu-systems/buildchain/pull/598",
          "title": "feat(release): add KFD-1 contract-world gate",
          "body": "## Summary\n- add first-class KFD-1 contract-world release gate evidence backed by @kungfu-tech/kfd metadata\n- pass KFD-1 witness inputs through release-candidate-promote and promote-buildchain-ref into release passports\n- bind managed branch protection required checks to GitHub Actions check runs\n\n## Validation\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:48:36Z",
          "mergedAt": "2026-07-06T08:50:46Z",
          "additions": 794,
          "deletions": 71,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 599,
          "url": "https://github.com/kungfu-systems/buildchain/pull/599",
          "title": "release: promote v2.8 alpha",
          "body": "Promote Buildchain v2.8 development line to alpha for KFD-1 contract-world release gate validation.\n\nValidation before PR:\n- dev/v2/v2.8 Verify run 28779479361 passed",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:52:02Z",
          "mergedAt": "2026-07-06T08:53:38Z",
          "additions": 794,
          "deletions": 71,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 601,
          "url": "https://github.com/kungfu-systems/buildchain/pull/601",
          "title": "release: promote v2.8 stable",
          "body": "Promote Buildchain v2.8 alpha to stable release.\n\nAlpha validation:\n- Buildchain Ref Promotion run 28779698806 passed\n- npm @kungfu-tech/buildchain@2.8.0-alpha.0 published under dist-tag alpha\n- v2.8.0-alpha.0 and v2.8-alpha tags point at alpha/v2/v2.8",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:56:49Z",
          "mergedAt": "2026-07-06T09:00:11Z",
          "additions": 794,
          "deletions": 71,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 295,
          "url": "https://github.com/kungfu-systems/kungfu/pull/295",
          "title": "feat(core): type the pykungfu native binding via build-generated stubs",
          "body": "Merge feature/pykungfu-stub-typing into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T09:03:22Z",
          "mergedAt": "2026-07-06T09:03:28Z",
          "additions": 6788,
          "deletions": 7,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 602,
          "url": "https://github.com/kungfu-systems/buildchain/pull/602",
          "title": "Release v2.8.0",
          "body": "Create the generated version-state commit for v2.8.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T09:02:27Z",
          "mergedAt": "2026-07-06T09:04:21Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 297,
          "url": "https://github.com/kungfu-systems/kungfu/pull/297",
          "title": "chore(verify): align stale kfc naming with the kungfu executable",
          "body": "Merge feature/verify-kungfu-naming into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T09:50:36Z",
          "mergedAt": "2026-07-06T09:50:41Z",
          "additions": 44,
          "deletions": 44,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 296,
          "url": "https://github.com/kungfu-systems/kungfu/pull/296",
          "title": "feat(sdk): add agent-first KFD-1 canonical policy",
          "body": "## Summary\n\n- add an agent-first KFD-1 canonical policy for Kungfu contract surfaces\n- consume `@kungfu-tech/kfd@1.0.0-alpha.2` and `@kungfu-tech/buildchain@2.8.0` instead of redefining KFD metadata or Buildchain JSON formatting locally\n- add `kungfu sdk contract policy|witness|audit --json` and wire the policy into frozen contract artifacts\n- canonicalize config/kfx/skill contract mother files through the SDK renderer\n- update docs and SDK tests for the Buildchain KFD-1 witness path\n\n## Validation\n\n- `pnpm --filter @kungfu-tech/sdk run build`\n- `pnpm exec biome check developer/sdk/src/sdk.js developer/sdk/tests/contract-cli.test.mjs scripts/contract-registry.cjs docs/contracts.md docs/kfd-native-sdk-release-gates.md types/vendor-shims.d.ts`\n- `node developer/sdk/src/sdk.js contract audit --json`\n- `node developer/sdk/src/sdk.js contract evidence --json`\n- `git diff --check`\n- `copyContractArtifacts` temp smoke confirmed the canonical policy is copied with the registry/contracts\n\n## Known residual\n\n- `pnpm run check:types` still fails on pre-existing `framework/core/.gyp` and vendor JS typing gaps after this slice's SDK typing issues were removed.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T09:49:39Z",
          "mergedAt": "2026-07-06T10:02:20Z",
          "additions": 1254,
          "deletions": 132,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 604,
          "url": "https://github.com/kungfu-systems/buildchain/pull/604",
          "title": "feat(contract): add Buildchain floating ref contract lock",
          "body": "## Summary\n\n- add a Buildchain runtime contract world manifest for stable floating refs such as `@v2`\n- add consumer-side `buildchain.contract-lock.json` validation with compatible-drift issue reporting and breaking-drift fail-fast\n- wire contract lock checks into reusable build and release-candidate promote workflows before heavy/publish work\n- document Buildchain KFD-1 support, witness boundaries, consumer usage, and value in the release passport and reusable workflow docs\n- dogfood the mechanism in Buildchain with its own contract lock and generated site bundle contract facts\n\n## Validation\n\n- `node scripts/generate-site-bundle.mjs`\n- `BUILDCHAIN_RUNTIME_REF=v2 BUILDCHAIN_RUNTIME_SHA=$(git ls-remote origin refs/tags/v2 | awk '{print $1}') BUILDCHAIN_CONTRACT_ACCEPTED_AT=2026-07-06T00:00:00.000Z node scripts/buildchain-contract-lock.mjs write-lock --output buildchain.contract-lock.json`\n- `corepack pnpm@11.7.0 run check`\n- `BUILDCHAIN_RUNTIME_ROOT=. BUILDCHAIN_RUNTIME_REF=v2 BUILDCHAIN_RUNTIME_SHA=$(git rev-parse HEAD) BUILDCHAIN_RUNTIME_CLASS=stable BUILDCHAIN_CONTRACT_LOCK_PATH=buildchain.contract-lock.json BUILDCHAIN_CONTRACT_DRIFT_ISSUE_BODY=/tmp/buildchain-contract-drift-issue.md node scripts/buildchain-contract-lock.mjs check`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T10:08:30Z",
          "mergedAt": "2026-07-06T10:10:30Z",
          "additions": 1471,
          "deletions": 2,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 24,
          "url": "https://github.com/kungfu-systems/kfd/pull/24",
          "title": "feat(kfd): add KFD-3 collaboration interface schemas",
          "body": "## Summary\n\n- add KFD-3 collaboration-interface and witness schemas\n- expose the new KFD-3 schema IDs, paths, and concept names in standards.json\n- document the product profile boundary for participant-facing collaboration interfaces\n- update release-impact and conformance checks for the additive KFD-3 metadata surface\n\n## Verification\n\n- npm run check\n- jq empty standards.json release-impact.json schemas/kfd-3/collaboration-interface.schema.json schemas/kfd-3/witness.schema.json\n\n## Governance\n\n- KFD-3 remains participant-oriented, not agent-only\n- product-specific profiles stay in product repositories\n- package line remains v1.0; this is an additive metadata/schema surface\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T10:53:35Z",
          "mergedAt": "2026-07-06T10:54:59Z",
          "additions": 609,
          "deletions": 6,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 25,
          "url": "https://github.com/kungfu-systems/kfd/pull/25",
          "title": "release(alpha): promote KFD collaboration interface metadata",
          "body": "## What\n\nPromote the latest KFD dev line into the alpha channel so the KFD-3 collaboration-interface metadata and schemas can be published as the next @kungfu-tech/kfd alpha.\n\nIncluded dev commits:\n- Merge PR #24 with KFD-3 collaboration-interface and witness schemas.\n- Preserve the Buildchain version-state return commit from the previous alpha.\n\n## Registry agreement\n\n- [x] Latest dev Verify workflow passed on fb23afa0b66a5f09ea62f39eb08c57e66714a147.\n- [x] KFD package release remains on the v1.0 line; Buildchain should advance the prerelease alpha number.\n\n## Version impact\n\n- [x] alpha promotion for additive KFD metadata/schema surface; npm dist-tag should remain alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T11:18:34Z",
          "mergedAt": "2026-07-06T11:21:12Z",
          "additions": 609,
          "deletions": 6,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 26,
          "url": "https://github.com/kungfu-systems/kfd/pull/26",
          "title": "Prepare v1.0.0-alpha.3",
          "body": "Create the generated version-state commit for v1.0.0-alpha.3.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T11:22:15Z",
          "mergedAt": "2026-07-06T11:24:07Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 27,
          "url": "https://github.com/kungfu-systems/kfd/pull/27",
          "title": "Prepare v1.0.0-alpha.3",
          "body": "Create the generated version-state commit for v1.0.0-alpha.3.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T11:24:53Z",
          "mergedAt": "2026-07-06T11:26:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 605,
          "url": "https://github.com/kungfu-systems/buildchain/pull/605",
          "title": "feat(release): add KFD-3 collaboration interface gate",
          "body": "## Summary\n- add KFD-3 collaboration-interface prebuild and artifact witness release passport gate\n- pass KFD-3 witness inputs through release-candidate-promote and promote-buildchain-ref\n- expose the KFD-3 gate in the v2 contract world and docs\n\n## Validation\n- node scripts/check-inventory.mjs && node --test tests/release-passport.test.mjs tests/buildchain-contract.test.mjs tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T11:38:54Z",
          "mergedAt": "2026-07-06T11:40:06Z",
          "additions": 1142,
          "deletions": 80,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 606,
          "url": "https://github.com/kungfu-systems/buildchain/pull/606",
          "title": "feat(release): add KFD trust passport audits",
          "body": "## Summary\n- add KFD-1 self contract verification, KFD-2 public release trust audit, and KFD-3 self-verification trust proof into release passports\n- enforce publish-gate source-lock inputs through release-candidate-promote and fail closed on retained legacy release workflows that bypass source locks\n- update contract/docs/site bundle and tests for floating @v2 drift protection across publish models\n\n## Verification\n- node --test tests/build-surface.test.mjs tests/buildchain-contract.test.mjs tests/release-passport.test.mjs\n- node scripts/check-inventory.mjs\n- corepack pnpm run build\n- node scripts/generate-site-bundle.mjs\n- BUILDCHAIN_RUNTIME_REF=v2 BUILDCHAIN_RUNTIME_SHA=$(git ls-remote origin refs/tags/v2 | awk '{print $1}') BUILDCHAIN_CONTRACT_ACCEPTED_AT=2026-07-06T00:00:00.000Z node scripts/buildchain-contract-lock.mjs write-lock --output buildchain.contract-lock.json\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:14:03Z",
          "mergedAt": "2026-07-06T13:15:39Z",
          "additions": 1781,
          "deletions": 345,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 607,
          "url": "https://github.com/kungfu-systems/buildchain/pull/607",
          "title": "Promote v2.8 dev to alpha",
          "body": "## Summary\nPromote the current dev/v2/v2.8 tree to alpha/v2/v2.8 after #606.\n\nThis supersedes stale version-state PRs #600 and #603 so the release-candidate evidence and publish-gate source lock are regenerated from the current Buildchain tree.\n\n## Release intent\n- channel: alpha\n- source: dev/v2/v2.8\n- target: alpha/v2/v2.8\n- expected next prerelease: v2.8.1-alpha.0 or next available alpha patch\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T13:18:01Z",
          "mergedAt": "2026-07-06T13:19:55Z",
          "additions": 4271,
          "deletions": 304,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 28,
          "url": "https://github.com/kungfu-systems/kfd/pull/28",
          "title": "feat(kfd): add release trust metadata",
          "body": "## Summary\n- add KFD-2 release claims and release trust passport schemas\n- expose KFD-1/2/3 machine interface versions and decision document SHA-256 bindings in standards.json\n- add a KFD-1 release witness and wire it into the Buildchain release passport path\n- add KFD -> site-libkungfu-dev release propagation graph and workflow\n\n## Verification\n- node scripts/check.mjs\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n- buildchain release-propagation plan with a synthetic KFD alpha envelope\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:14:35Z",
          "mergedAt": "2026-07-06T13:20:53Z",
          "additions": 1201,
          "deletions": 16,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 609,
          "url": "https://github.com/kungfu-systems/buildchain/pull/609",
          "title": "fix(release): validate publish source locks generically",
          "body": "## Summary\n- make promote-buildchain-ref source-lock validation generic across semver and anchored/manual release models\n- keep release-candidate-promote source-lock enforcement enabled for floating @v2 consumers\n- retain anchored package diagnostics as a separate toolkit check instead of using it as the universal publish gate\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs tests/build-surface.test.mjs\n- corepack pnpm run build\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:24:41Z",
          "mergedAt": "2026-07-06T13:25:54Z",
          "additions": 146,
          "deletions": 87,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 29,
          "url": "https://github.com/kungfu-systems/kfd/pull/29",
          "title": "release(alpha): promote KFD release trust metadata",
          "body": "Promote the KFD-2 release claims and release trust passport metadata to alpha through the Buildchain channel flow.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:21:52Z",
          "mergedAt": "2026-07-06T13:26:09Z",
          "additions": 1201,
          "deletions": 16,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 610,
          "url": "https://github.com/kungfu-systems/buildchain/pull/610",
          "title": "Promote v2.8 dev to alpha",
          "body": "## Summary\nPromote the current dev/v2/v2.8 tree to alpha/v2/v2.8 after #606 and #609.\n\nThis refreshes the alpha channel so Buildchain self-promotion uses the generic publish source-lock validator.\n\n## Release intent\n- channel: alpha\n- source: dev/v2/v2.8\n- target: alpha/v2/v2.8\n- expected next prerelease: next available v2.8 alpha patch\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:26:20Z",
          "mergedAt": "2026-07-06T13:27:30Z",
          "additions": 146,
          "deletions": 87,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 30,
          "url": "https://github.com/kungfu-systems/kfd/pull/30",
          "title": "Prepare v1.0.0-alpha.4",
          "body": "Create the generated version-state commit for v1.0.0-alpha.4.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T13:27:14Z",
          "mergedAt": "2026-07-06T13:29:04Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 9,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/9",
          "title": "feat(site): render KFD package surface",
          "body": "## Summary\n- render the KFD package-owned site bundle at /kfd/ and kfd.libkungfu.dev\n- add @kungfu-tech/kfd as the upstream fact source for kfd-site.json, registry, standards, and decisions\n- make the Buildchain web-surface workflow honor KFD release propagation locks before install/build\n\n## Validation\n- node scripts/prepare-kfd-upstream.mjs && npm install --package-lock-only --ignore-scripts --registry=https://registry.npmjs.org/ && npm ci --ignore-scripts --registry=https://registry.npmjs.org/ && npm run build && npm run check && bash -n scripts/build-site.sh scripts/check-site.sh\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:38:31Z",
          "mergedAt": "2026-07-06T13:40:29Z",
          "additions": 397,
          "deletions": 7,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 32,
          "url": "https://github.com/kungfu-systems/kfd/pull/32",
          "title": "fix(release): target KFD site propagation at main",
          "body": "## Summary\n- point KFD release propagation at the actual site-libkungfu-dev main branch\n- document the downstream consumed site bundle surfaces\n- update KFD-1 welded witnesses and release impact for the propagation graph/workflow change\n\n## Validation\n- node scripts/check.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:38:31Z",
          "mergedAt": "2026-07-06T13:40:30Z",
          "additions": 22,
          "deletions": 9,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 612,
          "url": "https://github.com/kungfu-systems/buildchain/pull/612",
          "title": "feat(release): publish GitHub release evidence from promote wrapper",
          "body": "## Summary\n\n- expose declarative `github-release` inputs on `release-candidate-promote.yml`\n- create/update the exact-tag GitHub Release after a complete publish transaction and upload publish evidence plus release passport assets\n- dogfood the GitHub Release path in Buildchain semver promotion\n- tighten RC run selection so reused channel head branches cannot select stale PR-stage artifacts\n\n## Verification\n\n- `node --test tests/release-candidate.test.mjs tests/github-release-metadata.test.mjs tests/build-surface.test.mjs`\n- `node scripts/check-inventory.mjs`\n- `corepack pnpm run build`\n- `node scripts/generate-site-bundle.mjs`\n- `corepack pnpm run check`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:41:02Z",
          "mergedAt": "2026-07-06T13:42:16Z",
          "additions": 202,
          "deletions": 10,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 613,
          "url": "https://github.com/kungfu-systems/buildchain/pull/613",
          "title": "Promote v2.8 dev to alpha",
          "body": "## Summary\n\nPromote the current v2.8 development line to alpha so Buildchain can dogfood the release-candidate promote wrapper, publish source-lock enforcement, and declarative GitHub Release evidence upload.\n\n## Verification\n\n- dev/v2/v2.8 PR checks must provide the PR-stage release candidate artifacts\n- merge to alpha/v2/v2.8 must run promote-only publication without selecting stale RC artifacts\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:43:01Z",
          "mergedAt": "2026-07-06T13:44:28Z",
          "additions": 202,
          "deletions": 10,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 31,
          "url": "https://github.com/kungfu-systems/kfd/pull/31",
          "title": "Prepare v1.0.0-alpha.4",
          "body": "Create the generated version-state commit for v1.0.0-alpha.4.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T13:30:00Z",
          "mergedAt": "2026-07-06T13:46:50Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 615,
          "url": "https://github.com/kungfu-systems/buildchain/pull/615",
          "title": "fix(release): run build surface fixture on channel PRs",
          "body": "## Summary\n- widen Build Surface Fixture pull_request branch globs so channel PRs like alpha/v2/v2.8 trigger the PR-stage RC build\n- add a regression assertion so the fixture stays aligned with release/verify workflow branch patterns\n\n## Why\n- alpha promotion run 28796226981 failed before publish because channel PR #613 had no successful Build Surface Fixture PR run to resolve release-candidate evidence from\n\n## Verification\n- bash scripts/check-workflows.sh\n- node --test tests/build-surface.test.mjs tests/release-candidate.test.mjs\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:51:03Z",
          "mergedAt": "2026-07-06T13:52:14Z",
          "additions": 7,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 617,
          "url": "https://github.com/kungfu-systems/buildchain/pull/617",
          "title": "fix(release): default fixture transfer mode on PR events",
          "body": "## Summary\n- avoid the workflow_dispatch-only inputs context in Build Surface Fixture pull_request runs\n- keep manual artifact-transfer-mode override for workflow_dispatch while defaulting PR runs to github-artifacts\n- update the regression assertion for the PR-safe expression\n\n## Why\n- Build Surface Fixture run 28796729227 started for channel PR #616 but failed at workflow startup before creating jobs\n\n## Verification\n- bash scripts/check-workflows.sh\n- node --test tests/build-surface.test.mjs tests/release-candidate.test.mjs\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:56:44Z",
          "mergedAt": "2026-07-06T13:58:16Z",
          "additions": 5,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 619,
          "url": "https://github.com/kungfu-systems/buildchain/pull/619",
          "title": "fix(release): grant fixture reusable workflow permissions",
          "body": "## Summary\n- grant Build Surface Fixture the issues:write permission required by the reusable .build.yml workflow\n- keep the fixture permission surface aligned with the called workflow so channel PR runs can start and produce RC artifacts\n- add a regression assertion for the caller permission\n\n## Why\n- Build Surface Fixture runs 28796729227 and 28797103513 failed at workflow startup before creating jobs after channel PR triggering was enabled\n- reusable workflows cannot elevate beyond the caller permissions\n\n## Verification\n- bash scripts/check-workflows.sh\n- node --test tests/build-surface.test.mjs tests/release-candidate.test.mjs\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:01:49Z",
          "mergedAt": "2026-07-06T14:04:00Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 620,
          "url": "https://github.com/kungfu-systems/buildchain/pull/620",
          "title": "Promote v2.8 dev to alpha",
          "body": "Promote Buildchain v2.8 dev to alpha after enabling semver GitHub Release publication dogfood and fixing Build Surface Fixture channel PR triggers/startup permissions.\n\nExpected dogfood:\n- PR-stage Build Surface Fixture produces release-candidate evidence.\n- Merge-stage buildchain-ref-promotion resolves that RC and promotes without rebuilding.\n- release-candidate-promote publishes GitHub Release evidence when the transaction completes.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:04:22Z",
          "mergedAt": "2026-07-06T14:06:25Z",
          "additions": 14,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 10,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/10",
          "title": "alpha: enable live preview and staging apply",
          "body": "## Summary\n- enable Buildchain preview apply and preview cleanup for same-repository PRs\n- enable protected staging apply on main pushes\n- keep production apply disabled while production remains pending\n- update deploy docs and infra-output checks to match the live preview/staging model\n\n## Validation\n- node scripts/prepare-kfd-upstream.mjs && npm install --package-lock-only --ignore-scripts --registry=https://registry.npmjs.org/ && npm ci --ignore-scripts --registry=https://registry.npmjs.org/ && npm run build && npm run check && git diff --check\n\n## Preview\nThis alpha PR is intended to trigger a Buildchain preview deployment once GitHub Actions runs with preview apply enabled.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:58:57Z",
          "mergedAt": "2026-07-06T14:13:07Z",
          "additions": 32,
          "deletions": 17,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 622,
          "url": "https://github.com/kungfu-systems/buildchain/pull/622",
          "title": "fix(release): include site contract in version state",
          "body": "## Summary\n- include dist/site/buildchain-contract.json#product.version in Buildchain own semver version state\n- add a regression check so generated site contract version changes are allowed in release promotion version-state commits\n\n## Why\n- alpha promotion run 28797656148 resolved the PR-stage RC and publish-gate lock successfully, but failed after semver bump because dist/site/buildchain-contract.json became stale\n\n## Verification\n- node --test tests/build-surface.test.mjs tests/promote-buildchain-ref.test.mjs\n- node scripts/check-inventory.mjs && node scripts/generate-site-bundle.mjs --check\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:11:14Z",
          "mergedAt": "2026-07-06T14:13:40Z",
          "additions": 19,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 623,
          "url": "https://github.com/kungfu-systems/buildchain/pull/623",
          "title": "Promote v2.8 dev to alpha",
          "body": "Promote Buildchain v2.8 dev to alpha after enabling semver GitHub Release publication dogfood and fixing Buildchain own semver version-state site contract.\n\nExpected dogfood:\n- PR-stage Build Surface Fixture produces release-candidate evidence.\n- Merge-stage buildchain-ref-promotion resolves that RC and promotes without rebuilding.\n- semver version-state includes package.json and dist/site/buildchain-contract.json.\n- release-candidate-promote publishes GitHub Release evidence when the transaction completes.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:13:59Z",
          "mergedAt": "2026-07-06T14:16:22Z",
          "additions": 19,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 33,
          "url": "https://github.com/kungfu-systems/kfd/pull/33",
          "title": "feat(kfd): add KFD-3 self collaboration witness",
          "body": "## What\n\n- Add KFD-owned KFD-3 collaboration-interface and prebuild/artifact witnesses.\n- Extend package exports, build artifacts, and release-impact metadata for the new self-verification surfaces.\n- Wire KFD release promotion to Buildchain alpha v2.8 KFD-3 release passport inputs.\n- Extend `node scripts/check.mjs` to verify KFD-3 witness hashes, closure, evidence pointers, and declared/exposed surface parity.\n\n## Verification\n\n- `npm run check`\n- `npm pack --dry-run --json`\n\n## Note\n\nThis uses `kungfu-systems/buildchain/...@alpha/v2/v2.8` for promotion because the current stable `@v2` ref does not yet expose the KFD-3 release passport inputs.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:14:47Z",
          "mergedAt": "2026-07-06T14:19:01Z",
          "additions": 1680,
          "deletions": 12,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 34,
          "url": "https://github.com/kungfu-systems/kfd/pull/34",
          "title": "release(alpha): promote KFD-3 self collaboration witness",
          "body": "## What\n\nPromote KFD dev/v1/v1.0 to alpha/v1/v1.0 after adding KFD-3 self collaboration-interface and witness verification.\n\n## Verification\n\n- PR #33 Verify passed\n- PR #33 Build passed\n- dev/v1/v1.0 push Verify passed\n\n## Release intent\n\nPublish the next @kungfu-tech/kfd alpha with KFD-3 self-verification artifacts and Buildchain KFD-3 release passport inputs.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:20:20Z",
          "mergedAt": "2026-07-06T14:22:35Z",
          "additions": 1701,
          "deletions": 20,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 299,
          "url": "https://github.com/kungfu-systems/kungfu/pull/299",
          "title": "feat(core): stop shipping the scientific stack in the frozen runtime",
          "body": "Merge feature/kfx-app-slim-depandas into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:22:38Z",
          "mergedAt": "2026-07-06T14:22:44Z",
          "additions": 64,
          "deletions": 46,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 11,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/11",
          "title": "alpha: link KFD decision pages from homepage",
          "body": "## Summary\\n- render KFD-1/2/3 cards as explicit links on the KFD homepage\\n- verify dist/kfd/1, /2, and /3 pages exist\\n- fail checks if the KFD homepage stops linking to registry decision pages\\n\\n## Validation\\n- node scripts/prepare-kfd-upstream.mjs\\n- npm install --package-lock-only --ignore-scripts --registry=https://registry.npmjs.org/\\n- npm ci --ignore-scripts --registry=https://registry.npmjs.org/\\n- npm run build\\n- npm run check\\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:25:32Z",
          "mergedAt": "2026-07-06T14:27:23Z",
          "additions": 39,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 626,
          "url": "https://github.com/kungfu-systems/buildchain/pull/626",
          "title": "fix(release): materialize version-state lifecycle outputs",
          "body": "## Summary\n- add a `version-state` lifecycle stage to Buildchain semver promotion so generated version-state files are materialized before verify/finalization\n- dogfood the stage for `dist/site/buildchain-contract.json` by regenerating the site bundle before semver release checks\n- make promote-buildchain-ref commit the verified declared version-state file contents, including generated derived files\n\n## Context\nThe semver dogfood alpha promotion reached the GitHub Release-enabled path but failed before publish finalization because `dist/site/buildchain-contract.json` was stale after the version bump. Directly listing the generated file as a version file was not enough; the promotion path also needs to run the generator before verification and commit the generated content.\n\n## Verification\n- `node --test tests/promote-buildchain-ref.test.mjs tests/build-surface.test.mjs`\n- `corepack pnpm --filter ./actions/promote-buildchain-ref build`\n- `corepack pnpm run check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:26:09Z",
          "mergedAt": "2026-07-06T14:30:11Z",
          "additions": 255,
          "deletions": 121,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 35,
          "url": "https://github.com/kungfu-systems/kfd/pull/35",
          "title": "fix(release): anchor KFD alpha publish state",
          "body": "## Summary\n- switch KFD Buildchain release config to anchored/manual mode with an explicit kfd.release.json manifest\n- add the release anchor to package exports, build artifacts, KFD-1 witness coverage, and KFD-3 collaboration metadata\n- bump the alpha package version to 1.0.0-alpha.5\n\n## Verification\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:29:23Z",
          "mergedAt": "2026-07-06T14:31:15Z",
          "additions": 128,
          "deletions": 24,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 36,
          "url": "https://github.com/kungfu-systems/kfd/pull/36",
          "title": "release(alpha): publish KFD 1.0.0-alpha.5",
          "body": "## Summary\n- promote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd@1.0.0-alpha.5\n- includes anchored/manual release manifest and KFD-3 collaboration-interface package witness updates\n\n## Verification\n- PR #35 Verify and Build passed before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:31:28Z",
          "mergedAt": "2026-07-06T14:32:41Z",
          "additions": 128,
          "deletions": 24,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 627,
          "url": "https://github.com/kungfu-systems/buildchain/pull/627",
          "title": "Promote Buildchain v2.8 dev to alpha",
          "body": "## Summary\n- Promote the current v2.8 dev line to alpha.\n- Dogfood semver release GitHub Release evidence publication via `buildchain-ref-promotion.yml` and `release-candidate-promote.yml`.\n- Includes the version-state lifecycle fix that regenerates `dist/site/buildchain-contract.json` before publish verification.\n\n## Verification\n- Dev PR #626 checks passed before merge.\n- This PR must produce a PR-stage release-candidate artifact and merge into alpha without a second heavy build during promote-only publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:30:42Z",
          "mergedAt": "2026-07-06T14:32:55Z",
          "additions": 255,
          "deletions": 121,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 300,
          "url": "https://github.com/kungfu-systems/kungfu/pull/300",
          "title": "build(core): strip local symbols from release native artifacts",
          "body": "Merge feature/kfx-app-slim-strip into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:33:59Z",
          "mergedAt": "2026-07-06T14:34:05Z",
          "additions": 13,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 38,
          "url": "https://github.com/kungfu-systems/kfd/pull/38",
          "title": "fix(package): expose release impact metadata",
          "body": "## Summary\n- bump KFD alpha release anchor to 1.0.0-alpha.6\n- include release-impact.json in npm files and package exports\n- enforce that package surface in scripts/check.mjs and refresh KFD-3 witnesses\n\n## Verification\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:36:08Z",
          "mergedAt": "2026-07-06T14:37:42Z",
          "additions": 17,
          "deletions": 15,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 628,
          "url": "https://github.com/kungfu-systems/buildchain/pull/628",
          "title": "Prepare v2.8.1-alpha.0",
          "body": "Create the generated version-state commit for v2.8.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:35:57Z",
          "mergedAt": "2026-07-06T14:38:18Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 40,
          "url": "https://github.com/kungfu-systems/kfd/pull/40",
          "title": "release(alpha): publish KFD 1.0.0-alpha.6",
          "body": "## Summary\n- promote @kungfu-tech/kfd@1.0.0-alpha.6 using a dedicated alpha-based promotion branch\n- keeps the promotion head up to date with the protected alpha base\n- includes release-impact.json in npm files and exports\n\n## Verification\n- PR #38 Verify and Build passed before merge\n- promotion branch merge commit carries DCO sign-off",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:40:20Z",
          "mergedAt": "2026-07-06T14:42:24Z",
          "additions": 17,
          "deletions": 15,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 629,
          "url": "https://github.com/kungfu-systems/buildchain/pull/629",
          "title": "Prepare v2.8.1-alpha.0",
          "body": "Create the generated version-state commit for v2.8.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:40:26Z",
          "mergedAt": "2026-07-06T14:43:04Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 41,
          "url": "https://github.com/kungfu-systems/kfd/pull/41",
          "title": "fix(release): prepare KFD alpha.7 topology sync",
          "body": "## Summary\n- start from the current alpha branch so dev will contain the latest alpha promotion topology\n- bump the anchored/manual package release fact to 1.0.0-alpha.7\n- refresh KFD-3 package witness hashes\n\n## Why\nBuildchain ref promotion requires the final alpha commit to come from a merged same-repository PR dev/v1/v1.0 -> alpha/v1/v1.0. Dev must first contain the current alpha base to satisfy GitHub strict branch protection on that direct promotion PR.\n\n## Verification\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:44:57Z",
          "mergedAt": "2026-07-06T14:46:29Z",
          "additions": 12,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 37,
          "url": "https://github.com/kungfu-systems/kfd/pull/37",
          "title": "Prepare v1.0.0-alpha.5",
          "body": "Create the generated version-state commit for v1.0.0-alpha.5.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T14:33:56Z",
          "mergedAt": "2026-07-06T14:46:31Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 632,
          "url": "https://github.com/kungfu-systems/buildchain/pull/632",
          "title": "release: promote v2.8 alpha to stable via recovery merge",
          "body": "## Summary\n- Promote the current alpha/v2/v2.8 source material to release/v2/v2.8.\n- Resolve the only direct alpha-to-release conflict by preserving alpha package version state (`2.8.1-alpha.0`) before the release promotion transaction creates the stable version-state commit.\n- Keep the branch name line-scoped (`fix/release-line-v2-v2.8-*`) so Buildchain release governance can audit this as an explicit recovery merge.\n\n## Verification\n- `node -e 'JSON.parse(require(\"fs\").readFileSync(\"package.json\",\"utf8\")); console.log(\"package-json-ok\")'`\\n- `git diff --check`\\n- PR checks must pass before merge.\\n\\n## Dogfood note\\nThe alpha path successfully created GitHub Release `v2.8.1-alpha.0` with `prerelease=true`, `make_latest=false`, and release passport/evidence assets. This PR continues the stable semver GitHub Release dogfood.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T14:45:42Z",
          "mergedAt": "2026-07-06T14:48:02Z",
          "additions": 4777,
          "deletions": 397,
          "changedFiles": 47
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 42,
          "url": "https://github.com/kungfu-systems/kfd/pull/42",
          "title": "release(alpha): publish KFD 1.0.0-alpha.7",
          "body": "## Summary\n- direct promotion from dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd@1.0.0-alpha.7\n- dev now contains the current alpha base, satisfying strict branch protection\n- promotion source matches Buildchain policy: merged same-repository PR dev/v1/v1.0 -> alpha/v1/v1.0\n\n## Verification\n- PR #41 Verify and Build passed before merge\n- local npm run check\n- local npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:46:51Z",
          "mergedAt": "2026-07-06T14:48:13Z",
          "additions": 12,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 43,
          "url": "https://github.com/kungfu-systems/kfd/pull/43",
          "title": "Prepare v1.0.0-alpha.7",
          "body": "Create the generated version-state commit for v1.0.0-alpha.7.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T14:49:24Z",
          "mergedAt": "2026-07-06T14:51:10Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 633,
          "url": "https://github.com/kungfu-systems/buildchain/pull/633",
          "title": "Release v2.8.1",
          "body": "Create the generated version-state commit for v2.8.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:50:34Z",
          "mergedAt": "2026-07-06T14:53:05Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 634,
          "url": "https://github.com/kungfu-systems/buildchain/pull/634",
          "title": "Prepare v2.8.2-alpha.0",
          "body": "Create the generated version-state commit for v2.8.2-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:55:56Z",
          "mergedAt": "2026-07-06T14:58:09Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 12,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/12",
          "title": "feat(site): render KFD and Buildchain package surfaces",
          "body": "## Summary\n- switch the site build to pnpm with pinned package artifacts\n- render KFD decision pages with structured Markdown, tables, and section navigation\n- consume the latest Buildchain release package for the Buildchain surface\n- add a stewarded substrate footer with GitHub organization collaboration routing\n\n## Verification\n- pnpm run build\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:10:11Z",
          "mergedAt": "2026-07-06T15:11:49Z",
          "additions": 647,
          "deletions": 176,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 44,
          "url": "https://github.com/kungfu-systems/kfd/pull/44",
          "title": "feat(release): wire KFD passport gates",
          "body": "## Summary\n- add an explicit machine-bound KFD-2 public release trust claim\n- publish the KFD-2 claim through package files/exports and Buildchain artifacts\n- pass KFD-1, KFD-2, and KFD-3 evidence into Buildchain release passport promotion\n- update KFD-3 witnesses so minimal entrypoints are declared public surfaces\n\n## Verification\n- npm run check\n- npm pack --dry-run --json\n- npx @kungfu-tech/buildchain@2.8.1 collect github-release ... --kfd-1-witness-json ... --kfd-2-claim-json ... --kfd-3-prebuild-witness-json ... --kfd-3-artifact-witness-json ...\n- npx @kungfu-tech/buildchain@2.8.1 verify release-passport ... --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:11:57Z",
          "mergedAt": "2026-07-06T15:12:36Z",
          "additions": 507,
          "deletions": 28,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 635,
          "url": "https://github.com/kungfu-systems/buildchain/pull/635",
          "title": "fix(passport): project KFD-3 evidence into KFD-2 trust proofs",
          "body": "## Summary\n- preserve a machine-readable KFD-2 trustProof object on generated kfd-3:* public claims\n- require KFD-3-derived KFD-2 claims to carry witness hashes, declared capability verification, reverse audit boundary, residual risk, and responsibility state\n- update release passport docs, inventory guard, site contract digest, and bundled promote action\n\n## Verification\n- node --test tests/release-passport.test.mjs\n- corepack pnpm --filter ./actions/promote-buildchain-ref build\n- node scripts/check-inventory.mjs\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:10:39Z",
          "mergedAt": "2026-07-06T15:12:45Z",
          "additions": 192,
          "deletions": 66,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 45,
          "url": "https://github.com/kungfu-systems/kfd/pull/45",
          "title": "release: promote KFD alpha.8",
          "body": "## Summary\nPromote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd@1.0.0-alpha.8.\n\nThis promotion includes:\n- KFD-1 contract-world witness coverage for package/release trust surfaces\n- explicit KFD-2 public release trust claim input\n- KFD-3 collaboration-interface closure witness fix for minimal entrypoints\n- Buildchain promotion wiring for KFD-1/2/3 release passport sections\n\n## Verification\n- PR #44 check / check passed\n- local npm run check passed\n- local Buildchain release passport verify returned trust=pass with only KFD-2 residual-risk warnings",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:13:15Z",
          "mergedAt": "2026-07-06T15:14:24Z",
          "additions": 507,
          "deletions": 28,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 636,
          "url": "https://github.com/kungfu-systems/buildchain/pull/636",
          "title": "chore(release): backfill v2.8.2 alpha state to dev",
          "body": "## Summary\n- merge the current alpha/v2/v2.8 version-state back into dev/v2/v2.8 after stable release recovery\n- preserve the KFD-3 to KFD-2 trust-proof fix already merged in #635\n- regenerate site contract facts for package version 2.8.2-alpha.0\n\n## Verification\n- corepack pnpm run check:site\n- node --test tests/release-passport.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:15:08Z",
          "mergedAt": "2026-07-06T15:17:14Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 638,
          "url": "https://github.com/kungfu-systems/buildchain/pull/638",
          "title": "Promote Buildchain v2.8 KFD trust proof fix to alpha",
          "body": "## Summary\n- promote the KFD-3 to KFD-2 trust proof projection from dev to alpha\n- includes the alpha version-state backfill so the release line stays monotonic\n\n## Verification\n- dev Verify run: https://github.com/kungfu-systems/buildchain/actions/runs/28802320941\n- PR #635 checks passed before merge\n- PR #636 checks passed before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:19:02Z",
          "mergedAt": "2026-07-06T15:20:47Z",
          "additions": 192,
          "deletions": 66,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 46,
          "url": "https://github.com/kungfu-systems/kfd/pull/46",
          "title": "fix(release): keep KFD claim out of build artifacts",
          "body": "## Summary\n- keep the explicit KFD-2 release trust claim in the npm package and promotion inputs\n- remove the KFD-2 hidden directory from PR-stage Build artifact paths/requiredPaths to avoid Build startup failure\n- refresh KFD-1/KFD-2/KFD-3 witness hashes\n\n## Verification\n- npm run check\n- npm pack --dry-run --json\n- local buildchain collect github-release + verify release-passport: trust=pass, no errors",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:19:52Z",
          "mergedAt": "2026-07-06T15:21:11Z",
          "additions": 12,
          "deletions": 13,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 47,
          "url": "https://github.com/kungfu-systems/kfd/pull/47",
          "title": "chore(release): sync alpha.8 topology",
          "body": "## Summary\n- merge alpha/v1/v1.0 history back into dev/v1/v1.0 after the failed alpha.8 promotion attempt\n- keep dev-side follow-up content while restoring alpha-as-ancestor topology for the next promotion PR\n\n## Verification\n- merge completed without content conflicts\n- alpha/v1/v1.0 is an ancestor of this sync branch",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:22:10Z",
          "mergedAt": "2026-07-06T15:22:49Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 48,
          "url": "https://github.com/kungfu-systems/kfd/pull/48",
          "title": "release(alpha): prepare KFD 1.0.0-alpha.9",
          "body": "## Summary\n- bump KFD package/release anchor from 1.0.0-alpha.8 to 1.0.0-alpha.9\n- refresh KFD-1, KFD-2, and KFD-3 release evidence hashes\n\n## Verification\n- npm run check\n- npm pack --dry-run --json\n- local Buildchain release passport verify: trust=pass, no errors",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:23:54Z",
          "mergedAt": "2026-07-06T15:24:44Z",
          "additions": 31,
          "deletions": 31,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 49,
          "url": "https://github.com/kungfu-systems/kfd/pull/49",
          "title": "release(alpha): publish KFD 1.0.0-alpha.9",
          "body": "## Summary\nPromote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd@1.0.0-alpha.9.\n\nThis promotion includes the KFD-1/2/3 Buildchain release passport integration and a non-workflow alpha.9 release anchor refresh after alpha.8's PR-stage Build startup failure.\n\n## Verification\n- PR #48 check / check passed\n- local npm run check passed\n- local Buildchain release passport verify returned trust=pass with no errors\n- alpha/v1/v1.0 is an ancestor of dev/v1/v1.0",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:25:09Z",
          "mergedAt": "2026-07-06T15:26:09Z",
          "additions": 36,
          "deletions": 37,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 13,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/13",
          "title": "fix(site): guard libkungfu production readiness",
          "body": "## Summary\\n- mirror kfd.libkungfu.dev into the local infra output contract\\n- verify all declared production surface URLs against buildchain.toml\\n- make production-apply follow the infra production status so pending remains fail-closed\\n\\n## Validation\\n- pnpm run build\\n- pnpm run check\\n- git diff --check\\n\\n## Production impact\\n- no production apply is enabled by this PR\\n- production remains blocked while infra/outputs.json marks production pending",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:26:03Z",
          "mergedAt": "2026-07-06T15:27:58Z",
          "additions": 17,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 50,
          "url": "https://github.com/kungfu-systems/kfd/pull/50",
          "title": "fix(release): use Verify evidence for KFD promotion",
          "body": "## Summary\n- sync alpha.9 topology back into dev\n- bump KFD package/release anchor to 1.0.0-alpha.10\n- make KFD promotion resolve PR-stage release evidence from the Verify workflow instead of the Build workflow\n- refresh KFD-1, KFD-2, and KFD-3 release evidence hashes\n\n## Verification\n- npm run check\n- npm pack --dry-run --json\n- local Buildchain release passport verify: trust=pass, no errors",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:29:10Z",
          "mergedAt": "2026-07-06T15:30:00Z",
          "additions": 37,
          "deletions": 37,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 51,
          "url": "https://github.com/kungfu-systems/kfd/pull/51",
          "title": "release(alpha): publish KFD 1.0.0-alpha.10",
          "body": "## Summary\nPromote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd@1.0.0-alpha.10.\n\nThis promotion uses Verify PR-stage evidence for KFD's source/package release path and includes full KFD-1/2/3 release passport inputs.\n\n## Verification\n- PR #50 check / check passed\n- local npm run check passed\n- local Buildchain release passport verify returned trust=pass with no errors\n- alpha/v1/v1.0 is an ancestor of dev/v1/v1.0",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:30:21Z",
          "mergedAt": "2026-07-06T15:31:01Z",
          "additions": 37,
          "deletions": 37,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 52,
          "url": "https://github.com/kungfu-systems/kfd/pull/52",
          "title": "fix(release): pin KFD build workflow to v2.8",
          "body": "## Summary\n- sync alpha.10 topology back into dev\n- bump KFD package/release anchor to 1.0.0-alpha.11\n- pin the KFD Build workflow to buildchain alpha/v2/v2.8 because the moved v2 tag currently causes KFD Build startup_failure\n- refresh KFD-1, KFD-2, and KFD-3 release evidence hashes\n\n## Verification\n- npm run check\n- npm pack --dry-run --json\n- local Buildchain release passport verify: trust=pass, no errors",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:35:04Z",
          "mergedAt": "2026-07-06T15:37:43Z",
          "additions": 36,
          "deletions": 36,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 53,
          "url": "https://github.com/kungfu-systems/kfd/pull/53",
          "title": "fix(release): use Build evidence for KFD promotion",
          "body": "## Summary\n- switch Buildchain ref promotion back to the Build release-candidate workflow\n- add a scripted KFD-1 witness refresh step so release workflow/package/claim hash bindings do not drift\n- refresh KFD-1/2/3 release evidence for alpha.12\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json\n- git diff --check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:41:40Z",
          "mergedAt": "2026-07-06T15:43:06Z",
          "additions": 50,
          "deletions": 25,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 54,
          "url": "https://github.com/kungfu-systems/kfd/pull/54",
          "title": "release(alpha): publish KFD 1.0.0-alpha.12",
          "body": "## Summary\n- promote KFD dev/v1/v1.0 to alpha/v1/v1.0\n- publish @kungfu-tech/kfd@1.0.0-alpha.12 through Buildchain\n- generate release passport with KFD-1, KFD-2, and KFD-3 evidence\n\n## Release evidence included\n- KFD-1 contract-world witness\n- KFD-2 public release trust claim\n- KFD-3 collaboration-interface prebuild and artifact witnesses\n- Build release-candidate evidence for promotion\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:43:28Z",
          "mergedAt": "2026-07-06T15:45:00Z",
          "additions": 67,
          "deletions": 42,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 14,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/14",
          "title": "Enable libkungfu.dev production deployment",
          "body": "## Summary\n- mirror active production infra outputs\n- enable Buildchain web-surface production apply for approved manual dispatches\n\n## Verification\n- pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/ --config.minimumReleaseAge=0\n- pnpm run build && pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:43:44Z",
          "mergedAt": "2026-07-06T15:45:19Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 55,
          "url": "https://github.com/kungfu-systems/kfd/pull/55",
          "title": "Prepare v1.0.0-alpha.12",
          "body": "Create the generated version-state commit for v1.0.0-alpha.12.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T15:46:15Z",
          "mergedAt": "2026-07-06T15:49:51Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 642,
          "url": "https://github.com/kungfu-systems/buildchain/pull/642",
          "title": "Add Buildchain self KFD claim registry",
          "body": "## Summary\n- define Buildchain public KFD release claims and collaboration surfaces in a package-owned source module\n- generate Buildchain self KFD-1/2/3 witness files during self promotion and pass them into release passports\n- publish kfd-claims.json in the site bundle and document it as the source claim registry\n- move semver GitHub Release evidence publication into promote-buildchain-ref and keep the wrapper declarative\n\n## Validation\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:52:14Z",
          "mergedAt": "2026-07-06T15:54:22Z",
          "additions": 2565,
          "deletions": 217,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 15,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/15",
          "title": "Make kfd.libkungfu.dev root canonical",
          "body": "## Summary\n- make KFD public and agent URLs canonical at https://kfd.libkungfu.dev/\n- expose decision pages as /1/, /2/, /3/ on the KFD host\n- switch cross-surface navigation to canonical subdomain URLs\n\n## Verification\n- pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/ --config.minimumReleaseAge=0\n- pnpm run build && pnpm run check\n- generated manifest KFD pages are /, /1/, /2/, /3/\n- no generated KFD artifact references https://kfd.libkungfu.dev/kfd/ as canonical",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:55:10Z",
          "mergedAt": "2026-07-06T15:56:40Z",
          "additions": 44,
          "deletions": 35,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 643,
          "url": "https://github.com/kungfu-systems/buildchain/pull/643",
          "title": "Promote dev/v2/v2.8 to alpha",
          "body": "## Summary\nPromote current dev/v2/v2.8 to alpha/v2/v2.8 after adding Buildchain self KFD claim registry and release passport dogfood.\n\n## Included\n- PR #642 Add Buildchain self KFD claim registry\n\n## Validation\n- dev Verify run 28804713369 succeeded\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:55:55Z",
          "mergedAt": "2026-07-06T15:58:02Z",
          "additions": 2565,
          "deletions": 217,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 646,
          "url": "https://github.com/kungfu-systems/buildchain/pull/646",
          "title": "Fix GitHub Release CLI guard in action bundle",
          "body": "## Summary\n- prevent scripts/ensure-github-release.mjs from running its CLI main when bundled into promote-buildchain-ref\n- rebuild promote-buildchain-ref dist bundle\n\n## Validation\n- node --test tests/github-release-metadata.test.mjs tests/promote-buildchain-ref.test.mjs\n- corepack pnpm --filter ./actions/promote-buildchain-ref build\n- node scripts/check-inventory.mjs\n\n## Context\nAlpha promotion run 28805011280 proved Buildchain self KFD witness generation worked, then failed in promote-only publish because the imported ensure-github-release CLI guard fired inside the bundled action and required GH_TOKEN/GITHUB_TOKEN.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:04:14Z",
          "mergedAt": "2026-07-06T16:06:22Z",
          "additions": 25,
          "deletions": 17,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 647,
          "url": "https://github.com/kungfu-systems/buildchain/pull/647",
          "title": "Promote dev/v2/v2.8 guard fix to alpha",
          "body": "## Summary\nPromote the GitHub Release CLI guard fix into alpha/v2/v2.8 so the self-KFD alpha promotion can complete.\n\n## Included\n- PR #646 Fix GitHub Release CLI guard in action bundle\n\n## Context\nPrevious alpha promotion run 28805011280 failed after self-KFD witness generation because ensure-github-release CLI main executed inside the bundled promote action.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:06:51Z",
          "mergedAt": "2026-07-06T16:08:47Z",
          "additions": 25,
          "deletions": 17,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 649,
          "url": "https://github.com/kungfu-systems/buildchain/pull/649",
          "title": "fix(kfd): keep source claim registry version invariant",
          "body": "## Summary\n- keep Buildchain KFD source claim registry independent from semver version-state bumps\n- move exact release version / exact runtime contract digest out of dist/site/kfd-claims.json and leave those run-specific facts to generated release passport witnesses\n- add a regression test proving the source claim registry is stable across package version bumps\n\n## Validation\n- corepack pnpm run check\n- manual version-state smoke: bump package.json/dist site contract version, regenerate site bundle, and confirm no new dirty files outside declared version state",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:18:05Z",
          "mergedAt": "2026-07-06T16:21:09Z",
          "additions": 52,
          "deletions": 20,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 651,
          "url": "https://github.com/kungfu-systems/buildchain/pull/651",
          "title": "Prepare v2.8.2-alpha.1",
          "body": "## Summary\n- promote the KFD source claim registry version-invariance fix to alpha\n- prevents Buildchain self KFD claims from dirtying dist/site/kfd-claims.json during semver version-state generation\n\n## Validation\n- PR #649 checks passed\n- local corepack pnpm run check passed on the source fix\n\n## Release intent\nAlpha promotion only.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:21:50Z",
          "mergedAt": "2026-07-06T16:23:55Z",
          "additions": 52,
          "deletions": 20,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 650,
          "url": "https://github.com/kungfu-systems/buildchain/pull/650",
          "title": "feat(web-surface): add production preflight health evidence",
          "body": "## Summary\n- add web-surface production preflight evidence for canonical/indexable production channels, concrete AWS targets, CloudFront aliases, DNS, and configured surface-set coverage\n- add production health-check evidence and include preflight/health results in the web-surface release passport\n- align the site-libkungfu-dev fixture with the current KFD surface design: `https://kfd.libkungfu.dev` is a first-class product homepage\n\n## Train validation\n- Runtime train ref: `train/v2/v2.8/production-promotion`\n- Head: `2d08a4a4772ca135f16be955f06483422d9f0edb`\n\n## Verification\n- `node --test tests/web-surface.test.mjs`\n- `pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:18:35Z",
          "mergedAt": "2026-07-06T16:26:21Z",
          "additions": 803,
          "deletions": 19,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 652,
          "url": "https://github.com/kungfu-systems/buildchain/pull/652",
          "title": "Prepare v2.8.2-alpha.2",
          "body": "Create the generated version-state commit for v2.8.2-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:26:17Z",
          "mergedAt": "2026-07-06T16:28:09Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 653,
          "url": "https://github.com/kungfu-systems/buildchain/pull/653",
          "title": "Prepare v2.8.2",
          "body": "## Summary\n- promote Buildchain v2.8.2 from alpha to stable release\n- includes KFD source claim registry version-invariance fix and prior KFD-1/KFD-2/KFD-3 release passport trust proof work\n\n## Validation\n- alpha v2.8.2-alpha.2 published successfully\n- GitHub Release v2.8.2-alpha.2 created as prerelease/latest=false with passport assets\n- npm alpha dist-tag points to 2.8.2-alpha.2\n\n## Release intent\nStable release promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:31:10Z",
          "mergedAt": "2026-07-06T16:33:10Z",
          "additions": 2748,
          "deletions": 234,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 654,
          "url": "https://github.com/kungfu-systems/buildchain/pull/654",
          "title": "fix(web-surface): detect robots noindex meta in health",
          "body": "## Summary\n- make web-surface health-check fail production when an HTML page includes `<meta name=\"robots\" content=\"noindex\">`\n- preserve the existing `x-robots-tag` check and record whether noindex came from header or HTML meta\n- add regression coverage for the live KFD production failure mode\n\n## Train validation\n- Runtime train ref: `train/v2/v2.8/production-promotion`\n- Head: `0f43bf3817f9c9816e8b11fa129cd07ca7e1edf5`\n\n## Verification\n- `node --test tests/web-surface.test.mjs`\n- `pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:31:14Z",
          "mergedAt": "2026-07-06T16:33:47Z",
          "additions": 58,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 16,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/16",
          "title": "fix(site): remove production noindex metadata",
          "body": "## Summary\n- remove the hard-coded robots noindex meta tag from generated production pages\n- add checks so the hub and KFD production artifact cannot embed noindex metadata\n\n## Verification\n- `pnpm run build`\n- `pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:35:26Z",
          "mergedAt": "2026-07-06T16:37:27Z",
          "additions": 6,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 655,
          "url": "https://github.com/kungfu-systems/buildchain/pull/655",
          "title": "Release v2.8.2",
          "body": "Create the generated version-state commit for v2.8.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:35:35Z",
          "mergedAt": "2026-07-06T16:37:58Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 656,
          "url": "https://github.com/kungfu-systems/buildchain/pull/656",
          "title": "Prepare v2.8.3-alpha.0",
          "body": "Create the generated version-state commit for v2.8.3-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:40:44Z",
          "mergedAt": "2026-07-06T16:44:55Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 56,
          "url": "https://github.com/kungfu-systems/kfd/pull/56",
          "title": "feat(kfd-2): add trust taxonomy extension path",
          "body": "## Summary\n- add a KFD-2 trust taxonomy schema as the single source for residual-risk, downgrade, provability, and agent-action values\n- route release claims, release trust passports, and KFD-3 witnesses through the KFD-2 taxonomy definitions\n- add KFD-3 extension request support so agents know to open a KFD GitHub issue when a missing taxonomy value is needed\n- document the KFD npm package as the self-proof case for KFD-1/2/3 and add an agent quickstart\n- strengthen the KFD check gate and KFD-1 witness surfaces for README/docs/site/check/schema proof\n\n## Verification\n- node scripts/check.mjs\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:41:11Z",
          "mergedAt": "2026-07-06T16:45:38Z",
          "additions": 769,
          "deletions": 112,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 657,
          "url": "https://github.com/kungfu-systems/buildchain/pull/657",
          "title": "fix(web-surface): invalidate viewer paths",
          "body": "## Summary\n- invalidate CloudFront by viewer URL path instead of S3 object prefix\n- keep deployment manifest paths in the invalidation set\n- cover host-root KFD production invalidation as /*\n\n## Verification\n- node --test tests/web-surface.test.mjs\n- git diff --check\n- pnpm run check\n\n## Runtime validation\n- train/v2/v2.8/production-promotion now points at 16e4e9fca5979da4c0468be928d66a4f591ddc1e for site production validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:44:22Z",
          "mergedAt": "2026-07-06T16:46:19Z",
          "additions": 20,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 658,
          "url": "https://github.com/kungfu-systems/buildchain/pull/658",
          "title": "fix(release-passport): preserve KFD evidence in binary releases",
          "body": "## Summary\n- fetch the durable release-state passport before Buildchain's binary-distribution release asset upload\n- merge that authoritative passport as the base for the binary release passport so KFD-1/2/3 evidence, version impact, and release-state SHA survive the final GitHub Release asset update\n- expose collect github-release base-passport inputs and fail closed when required KFD evidence is missing\n\n## Source-first KFD reason\nThe source claim registry and durable release-state passport are the authoritative KFD truth. The binary distribution workflow was producing a later GitHub Release asset that omitted KFD evidence, so public release audit entrypoints drifted from the source-of-truth passport. This change preserves the source-defined KFD claims before any documentation-only work.\n\n## Validation\n- corepack pnpm run check\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T16:57:23Z",
          "mergedAt": "2026-07-06T16:59:48Z",
          "additions": 258,
          "deletions": 81,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 660,
          "url": "https://github.com/kungfu-systems/buildchain/pull/660",
          "title": "chore(release): backfill v2.8.3 alpha state to dev",
          "body": "## Summary\n- Backfill the current v2.8.3-alpha.0 version-state from alpha into dev/v2/v2.8 before the next alpha promotion.\n- This removes the channel PR conflict so the next legal dev -> alpha promotion can proceed.\n\n## Validation\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:03:22Z",
          "mergedAt": "2026-07-06T17:05:12Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 662,
          "url": "https://github.com/kungfu-systems/buildchain/pull/662",
          "title": "chore(release): merge v2.8.3 alpha state into dev",
          "body": "## Summary\n- Preserve alpha/v2/v2.8 as ancestry of dev/v2/v2.8 after the v2.8.3-alpha.0 state update.\n- This fixes the legal dev -> alpha channel PR merge-base, which cannot be repaired by squash-only content backfill.\n\n## Merge requirement\nPlease merge this PR with a merge commit, not squash, so dev retains alpha as an ancestor.\n\n## Validation\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:08:20Z",
          "mergedAt": "2026-07-06T17:10:16Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 663,
          "url": "https://github.com/kungfu-systems/buildchain/pull/663",
          "title": "Promote v2.8 KFD passport fix to alpha",
          "body": "## Summary\n- Promote the KFD release-passport source-of-truth fix from dev/v2/v2.8 to alpha/v2/v2.8.\n- Dev now preserves the current alpha version-state ancestry, so this is a normal channel promotion PR.\n\n## Validation\n- PR #658 checks passed.\n- PR #662 merge-backfill checks passed and preserved alpha ancestry.\n- dev/v2/v2.8 Verify run 28809418955 passed.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:11:40Z",
          "mergedAt": "2026-07-06T17:13:58Z",
          "additions": 1137,
          "deletions": 107,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 664,
          "url": "https://github.com/kungfu-systems/buildchain/pull/664",
          "title": "Prepare v2.8.3-alpha.1",
          "body": "Create the generated version-state commit for v2.8.3-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:16:12Z",
          "mergedAt": "2026-07-06T17:18:18Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 666,
          "url": "https://github.com/kungfu-systems/buildchain/pull/666",
          "title": "fix(release-passport): bundle publish evidence for release assets",
          "body": "## Summary\n- Copy publish evidence into the release-passport bundle as sibling `evidence.json`.\n- Make `buildchain.release.json` point to that sibling file so a downloaded GitHub Release asset bundle can pass `buildchain verify release-passport`.\n- Keep KFD source claims and durable release-state evidence as the source of truth; this fixes the public audit entrypoint path.\n\n## Validation\n- node --test tests/release-passport.test.mjs\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:26:03Z",
          "mergedAt": "2026-07-06T17:28:20Z",
          "additions": 110,
          "deletions": 55,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 667,
          "url": "https://github.com/kungfu-systems/buildchain/pull/667",
          "title": "chore(release): merge v2.8.3 alpha state into dev",
          "body": "Backfills the v2.8.3-alpha.1 version-state merge ancestry into dev/v2/v2.8 after the release-passport fix landed on dev.\n\nThis PR must be merged with a merge commit, not squash, so alpha/v2/v2.8 remains an ancestor of dev/v2/v2.8 and the next dev -> alpha channel PR is mergeable.\n\nValidation:\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:32:06Z",
          "mergedAt": "2026-07-06T17:34:01Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 668,
          "url": "https://github.com/kungfu-systems/buildchain/pull/668",
          "title": "Release Buildchain v2.8.3 alpha passport evidence fix",
          "body": "Promotes the release-passport evidence fix from dev/v2/v2.8 to alpha/v2/v2.8.\n\nSource-first KFD acceptance focus:\n- release passport keeps KFD-1/KFD-2/KFD-3 evidence from durable release-state\n- GitHub Release flat asset bundle can self-verify without path mutation\n- binary distribution collects release-state passport as authoritative base\n\nValidation already passed on dev PRs:\n- corepack pnpm run check\n- Build Surface Fixture",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:34:26Z",
          "mergedAt": "2026-07-06T17:36:48Z",
          "additions": 110,
          "deletions": 55,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 669,
          "url": "https://github.com/kungfu-systems/buildchain/pull/669",
          "title": "Prepare v2.8.3-alpha.2",
          "body": "Create the generated version-state commit for v2.8.3-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:39:26Z",
          "mergedAt": "2026-07-06T17:41:20Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 671,
          "url": "https://github.com/kungfu-systems/buildchain/pull/671",
          "title": "fix(release-passport): validate release-state KFD base",
          "body": "Fixes Binary Distribution tag runs after release passport finalization.\n\nThe durable release-state branch stores buildchain.release.json as the audit entry, while sibling evidence assets are not present in that branch checkout. The binary workflow should therefore validate the authoritative base passport as a KFD base, then let the final collected release-passport bundle run the full verifier once evidence assets are available.\n\nValidation:\n- node --test tests/build-surface.test.mjs\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:47:38Z",
          "mergedAt": "2026-07-06T17:49:30Z",
          "additions": 26,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 672,
          "url": "https://github.com/kungfu-systems/buildchain/pull/672",
          "title": "chore(release): merge v2.8.3-alpha.2 state into dev",
          "body": "Backfills v2.8.3-alpha.2 version-state ancestry into current dev/v2/v2.8 after the binary release-state passport fix landed.\n\nThis must be merged with a merge commit, not squash, so alpha/v2/v2.8 remains an ancestor of dev/v2/v2.8.\n\nValidation:\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:52:18Z",
          "mergedAt": "2026-07-06T17:54:25Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 673,
          "url": "https://github.com/kungfu-systems/buildchain/pull/673",
          "title": "Release Buildchain v2.8.3 alpha binary passport fix",
          "body": "Promotes the Binary Distribution release-state passport base validation fix to alpha/v2/v2.8.\n\nThis keeps durable release-state as the authoritative KFD base while deferring full release-passport verification until sibling evidence assets are present in the final GitHub Release bundle.\n\nValidation:\n- #671: node --test tests/build-surface.test.mjs\n- #671: corepack pnpm run check\n- #672: corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:54:48Z",
          "mergedAt": "2026-07-06T17:56:43Z",
          "additions": 26,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 674,
          "url": "https://github.com/kungfu-systems/buildchain/pull/674",
          "title": "Prepare v2.8.3-alpha.3",
          "body": "Create the generated version-state commit for v2.8.3-alpha.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:59:02Z",
          "mergedAt": "2026-07-06T18:01:03Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 675,
          "url": "https://github.com/kungfu-systems/buildchain/pull/675",
          "title": "Prepare v2.8.3-alpha.3",
          "body": "Create the generated version-state commit for v2.8.3-alpha.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:03:11Z",
          "mergedAt": "2026-07-06T18:10:24Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 677,
          "url": "https://github.com/kungfu-systems/buildchain/pull/677",
          "title": "chore(release): merge v2.8 release ancestry into dev",
          "body": "Backfills release/v2/v2.8 ancestry into dev/v2/v2.8 while keeping the current alpha.3 version-state tree.\n\nPurpose: make the next legal dev -> alpha promotion carry release ancestry, so the following alpha -> release PR can be a clean channel merge without bypassing release lineage checks.\n\nThis PR must be merged with a merge commit, not squash.\n\nValidation:\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:11:27Z",
          "mergedAt": "2026-07-06T18:13:40Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 678,
          "url": "https://github.com/kungfu-systems/buildchain/pull/678",
          "title": "Promote v2.8 release ancestry backfill to alpha",
          "body": "Promotes the release ancestry backfill from dev/v2/v2.8 to alpha/v2/v2.8 through the legal dev -> alpha channel.\n\nPurpose: make release/v2/v2.8 an ancestor of alpha/v2/v2.8 so the subsequent alpha -> release PR is a clean channel merge while preserving Buildchain release lineage governance.\n\nValidation:\n- #677: corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:14:12Z",
          "mergedAt": "2026-07-06T18:16:05Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 679,
          "url": "https://github.com/kungfu-systems/buildchain/pull/679",
          "title": "Prepare v2.8.3-alpha.4",
          "body": "Create the generated version-state commit for v2.8.3-alpha.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:18:35Z",
          "mergedAt": "2026-07-06T18:20:44Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 676,
          "url": "https://github.com/kungfu-systems/buildchain/pull/676",
          "title": "Release Buildchain v2.8.3",
          "body": "Promotes Buildchain v2.8.3 from alpha/v2/v2.8 to release/v2/v2.8.\n\nThis stable release includes source-first KFD passport evidence fixes and Binary Distribution release-state KFD base validation.\n\nValidated in alpha:\n- v2.8.3-alpha.3 npm alpha published\n- v2.8.3-alpha.3 GitHub Release prerelease created\n- release passport flat JSON audit bundle verifies\n- KFD-1/KFD-2/KFD-3 passed in passport\n- Binary Distribution tag run passed, including durable release-state KFD base fetch, collect, verify, artifact discovery, and GitHub Release asset upload",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:08:37Z",
          "mergedAt": "2026-07-06T18:25:11Z",
          "additions": 1218,
          "deletions": 109,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 681,
          "url": "https://github.com/kungfu-systems/buildchain/pull/681",
          "title": "Release v2.8.3",
          "body": "Create the generated version-state commit for v2.8.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:27:31Z",
          "mergedAt": "2026-07-06T18:29:39Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 682,
          "url": "https://github.com/kungfu-systems/buildchain/pull/682",
          "title": "Prepare v2.8.4-alpha.0",
          "body": "Create the generated version-state commit for v2.8.4-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:32:32Z",
          "mergedAt": "2026-07-06T18:36:13Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 683,
          "url": "https://github.com/kungfu-systems/buildchain/pull/683",
          "title": "Prepare v2.8.4-alpha.0",
          "body": "Create the generated version-state commit for v2.8.4-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:38:48Z",
          "mergedAt": "2026-07-06T18:41:23Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 684,
          "url": "https://github.com/kungfu-systems/buildchain/pull/684",
          "title": "fix(release): keep GitHub Release target aligned",
          "body": "## Summary\\n- patch existing GitHub Releases with target_commitish when a target is supplied\\n- make Binary Distribution pass the exact tag commit to ensure-github-release\\n- cover update behavior in GitHub Release metadata tests\\n\\n## Validation\\n- node --test tests/github-release-metadata.test.mjs tests/build-surface.test.mjs\\n- node scripts/generate-site-bundle.mjs --check\\n- corepack pnpm run check\\n\\n## Notes\\n- v2.8.3 GitHub Release metadata was manually repaired to target the current exact tag commit after discovering the mismatch during closeout.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:48:00Z",
          "mergedAt": "2026-07-06T18:50:16Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 685,
          "url": "https://github.com/kungfu-systems/buildchain/pull/685",
          "title": "Promote Buildchain v2.8.4 alpha target metadata fix",
          "body": "## Summary\\n- promote the GitHub Release target metadata fix from dev to alpha\\n- expected alpha publish: v2.8.4-alpha.1\\n\\n## Validation\\n- dev Verify passed: https://github.com/kungfu-systems/buildchain/actions/runs/28815396566\\n- source PR #684 passed Verify and Build Surface Fixture\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:51:55Z",
          "mergedAt": "2026-07-06T18:54:10Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 686,
          "url": "https://github.com/kungfu-systems/buildchain/pull/686",
          "title": "Prepare v2.8.4-alpha.1",
          "body": "Create the generated version-state commit for v2.8.4-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:56:42Z",
          "mergedAt": "2026-07-06T19:00:15Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 687,
          "url": "https://github.com/kungfu-systems/buildchain/pull/687",
          "title": "Prepare v2.8.4-alpha.1",
          "body": "Create the generated version-state commit for v2.8.4-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T19:02:38Z",
          "mergedAt": "2026-07-06T19:05:10Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 688,
          "url": "https://github.com/kungfu-systems/buildchain/pull/688",
          "title": "Release Buildchain v2.8.4",
          "body": "Promote Buildchain v2.8.4 from alpha to stable.\\n\\nValidation already completed on alpha v2.8.4-alpha.1, including KFD release passport collection, artifact discovery, and GitHub Release exact tag target metadata alignment.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T19:05:24Z",
          "mergedAt": "2026-07-06T19:08:00Z",
          "additions": 10,
          "deletions": 5,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 689,
          "url": "https://github.com/kungfu-systems/buildchain/pull/689",
          "title": "Release v2.8.4",
          "body": "Create the generated version-state commit for v2.8.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T19:10:20Z",
          "mergedAt": "2026-07-06T19:12:26Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 690,
          "url": "https://github.com/kungfu-systems/buildchain/pull/690",
          "title": "Prepare v2.8.5-alpha.0",
          "body": "Create the generated version-state commit for v2.8.5-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T19:15:17Z",
          "mergedAt": "2026-07-06T19:17:55Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 691,
          "url": "https://github.com/kungfu-systems/buildchain/pull/691",
          "title": "Sync dev with v2.8.5 alpha state",
          "body": "Backfill the alpha channel state after releasing Buildchain v2.8.4 and preparing v2.8.5-alpha.0, so dev remains a descendant of the current alpha/release line.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T19:23:35Z",
          "mergedAt": "2026-07-06T19:25:21Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 17,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/17",
          "title": "ci(web-surface): use Buildchain v2 workflow",
          "body": "## Summary\n- switch the web-surface reusable workflow shell from Buildchain @v2.4 to @v2\n- enable the Buildchain release-PR production gate on main with the buildchain-release label and release/ head prefix\n- extend infra drift checks so workflow ref, production apply, and release gate cannot silently drift\n- refresh docs and agent map for the current Buildchain/KFD pinned package versions and active production state\n\n## Verification\n- pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/\n- pnpm run build\n- pnpm run check\n- actionlint .github/workflows/buildchain-web-surface.yml\n- node /Users/dkr/Code/kungfu-systems/buildchain/scripts/web-surface.mjs --mode validate --cwd .\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:02:24Z",
          "mergedAt": "2026-07-06T23:03:59Z",
          "additions": 42,
          "deletions": 24,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 57,
          "url": "https://github.com/kungfu-systems/kfd/pull/57",
          "title": "docs(kfd): clarify foundation axiom wording",
          "body": "## Summary\n- make the public foundation triad use the stronger axiom wording: facts must not drift; trust must start from facts; cooperation must start from transparent value\n- update README, KFD-1, KFD-2, KFD-3, registry, standards metadata, and site bundle to align around the facts -> trust -> cooperation structure\n- remove the stale KFD-2 wording that framed KFD-1 only as release/version responsibility\n- refresh KFD-2 claim, KFD-3 witnesses, and KFD-1 witness hashes\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:08:04Z",
          "mergedAt": "2026-07-06T23:09:31Z",
          "additions": 136,
          "deletions": 127,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 18,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/18",
          "title": "fix(kfd): link decision eyebrow to home",
          "body": "## Summary\n- make the KFD decision detail eyebrow link back to https://kfd.libkungfu.dev/\n- keep the existing kind/status text in the title area\n- add a site check so KFD-1/2/3 keep the home breadcrumb link\n\n## Verification\n- pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/\n- pnpm run build\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:09:58Z",
          "mergedAt": "2026-07-06T23:11:28Z",
          "additions": 10,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 692,
          "url": "https://github.com/kungfu-systems/buildchain/pull/692",
          "title": "fix(kfd): enforce trust taxonomy in release passports",
          "body": "## Summary\n- discover KFD-2 trust taxonomy from @kungfu-tech/kfd standards metadata\n- fail closed on missing or unknown residualRisk/downgradeReason taxonomy values\n- validate KFD-3 prebuild/artifact residual risks and KFD-2 trust proof residual risks against the KFD-owned schema\n- refresh Buildchain site bundle digests for the updated public API surfaces\n\n## Validation\n- node --test tests/release-passport.test.mjs\n- node scripts/generate-site-bundle.mjs --check\n- corepack pnpm run check",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T23:09:32Z",
          "mergedAt": "2026-07-06T23:11:47Z",
          "additions": 476,
          "deletions": 91,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 58,
          "url": "https://github.com/kungfu-systems/kfd/pull/58",
          "title": "docs(readme): show current decision axioms",
          "body": "## Summary\n- change the README Current decisions table from long titles to the three axiom statements\n- keep registry and decision titles as the full axiom + engineering anchor form\n- refresh KFD witnesses that bind README hashes\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:13:44Z",
          "mergedAt": "2026-07-06T23:15:21Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 693,
          "url": "https://github.com/kungfu-systems/buildchain/pull/693",
          "title": "Prepare v2.8.5 alpha taxonomy update",
          "body": "## Summary\n- promote dev/v2/v2.8 KFD-2 trust taxonomy enforcement into alpha\n- release passport residualRisk/downgradeReason taxonomy now uses KFD-owned standards metadata as source of truth\n\n## Validation\n- dev Verify passed for fa0bde7\n- PR #692 checks passed",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:13:49Z",
          "mergedAt": "2026-07-06T23:15:42Z",
          "additions": 476,
          "deletions": 91,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 694,
          "url": "https://github.com/kungfu-systems/buildchain/pull/694",
          "title": "Prepare v2.8.5-alpha.1",
          "body": "Create the generated version-state commit for v2.8.5-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:18:08Z",
          "mergedAt": "2026-07-06T23:19:59Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 695,
          "url": "https://github.com/kungfu-systems/buildchain/pull/695",
          "title": "Release Buildchain v2.8.5",
          "body": "## Summary\n- promote KFD-2 trust taxonomy enforcement from alpha to stable\n- publish Buildchain stable release after alpha v2.8.5-alpha.1 verification\n\n## Validation\n- PR #692 checks passed and merged to dev\n- alpha PR #693 checks passed and alpha promotion published v2.8.5-alpha.1\n- version-state PR #694 checks passed and merged\n- alpha/v2/v2.8 Verify passed at 8e91316",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:21:33Z",
          "mergedAt": "2026-07-06T23:23:31Z",
          "additions": 478,
          "deletions": 93,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 59,
          "url": "https://github.com/kungfu-systems/kfd/pull/59",
          "title": "docs(kfd): expose public fact source metadata",
          "body": "## Summary\n- add README-visible stable KFD site URL for readers entering from GitHub\n- add Decision metadata describing the GitHub-hosted KFD repository as the public fact source and kfd.libkungfu.dev as a projection surface\n- expose the same public fact-source metadata through site/kfd-site.json and the KFD-3 collaboration interface for agents\n- extend the KFD-3 collaboration interface schema and check gate for factSources and stableRenderedIndex\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:27:06Z",
          "mergedAt": "2026-07-06T23:28:26Z",
          "additions": 258,
          "deletions": 62,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 698,
          "url": "https://github.com/kungfu-systems/buildchain/pull/698",
          "title": "fix(release): select latest alpha tag for stable promotion",
          "body": "## Summary\n- fix stable release governance to use the latest alpha prerelease for the same patch\n- prevent release promotion from comparing against stale alpha.0 when alpha.1+ exists\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm --filter ./actions/promote-buildchain-ref build\n- corepack pnpm run check\n\n## Incident\n- Fixes the stable promotion failure observed in run 28830157942 / issue #697.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:28:44Z",
          "mergedAt": "2026-07-06T23:30:37Z",
          "additions": 8,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 699,
          "url": "https://github.com/kungfu-systems/buildchain/pull/699",
          "title": "Sync dev with v2.8.5-alpha.1 state",
          "body": "## Summary\n- align dev/v2/v2.8 with the published v2.8.5-alpha.1 version state\n- preserve the release alpha selection hotfix already merged to dev\n\n## Validation\n- node scripts/generate-site-bundle.mjs --check\n- node --test tests/promote-buildchain-ref.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:33:20Z",
          "mergedAt": "2026-07-06T23:35:15Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 60,
          "url": "https://github.com/kungfu-systems/kfd/pull/60",
          "title": "docs(kfd): clarify license and official status boundary",
          "body": "## Summary\n- add root TRADEMARKS.md to clarify Apache-2.0 scope, trademark/name-use limits, official source boundaries, fork/derivative expectations, and agent-facing authority rule\n- link README License section to the official-status boundary\n- publish TRADEMARKS.md through npm files and exports\n- expose the boundary through site/kfd-site.json and the KFD-3 collaboration interface\n- extend the self-check gate and regenerate KFD-1/2/3 evidence\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:38:28Z",
          "mergedAt": "2026-07-06T23:39:39Z",
          "additions": 248,
          "deletions": 63,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 702,
          "url": "https://github.com/kungfu-systems/buildchain/pull/702",
          "title": "chore(release): align dev with alpha v2.8 state",
          "body": "## Summary\n- merge the current alpha/v2/v2.8 state back into dev/v2/v2.8\n- resolve the generated promote-buildchain-ref bundle conflict by keeping the dev-side rebuilt bundle\n- restore a clean same-repository dev -> alpha promotion path after #700 exposed a merge conflict\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:43:41Z",
          "mergedAt": "2026-07-06T23:45:45Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 703,
          "url": "https://github.com/kungfu-systems/buildchain/pull/703",
          "title": "Promote KFD taxonomy release fix to v2.8 alpha",
          "body": "## Summary\n- promote the KFD-2 trust taxonomy implementation already merged to dev\n- include the stable-promotion fix that selects the latest same-patch alpha tag\n- carry the dev/alpha mergeability alignment from #702 so this channel PR can merge cleanly\n\n## Verification\n- dev Verify passed in #702\n- Build Surface Fixture passed in #702\n- node --test tests/release-passport.test.mjs (on the KFD taxonomy implementation)\n- corepack pnpm run check (on the KFD taxonomy implementation and release hotfix)",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:46:10Z",
          "mergedAt": "2026-07-06T23:48:27Z",
          "additions": 8,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 704,
          "url": "https://github.com/kungfu-systems/buildchain/pull/704",
          "title": "Prepare v2.8.5-alpha.3",
          "body": "Create the generated version-state commit for v2.8.5-alpha.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:51:29Z",
          "mergedAt": "2026-07-06T23:53:31Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 61,
          "url": "https://github.com/kungfu-systems/kfd/pull/61",
          "title": "chore(kfd): anchor alpha 13 release",
          "body": "## Summary\n- bump KFD anchored npm version to 1.0.0-alpha.13\n- update kfd.release.json to match package.json\n- include TRADEMARKS.md in Buildchain release artifact paths and expected artifact check\n- regenerate KFD-1/2/3 release evidence\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:53:24Z",
          "mergedAt": "2026-07-06T23:55:00Z",
          "additions": 37,
          "deletions": 36,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 705,
          "url": "https://github.com/kungfu-systems/buildchain/pull/705",
          "title": "Release Buildchain v2.8.5",
          "body": "## Summary\n- align the release/v2/v2.8 source tree with the published v2.8.5-alpha.3 alpha evidence\n- carry the KFD-2 trust taxonomy release-passport enforcement into the stable release line\n- include the stable-promotion fix that selects the latest same-patch alpha tag\n\n## Verification\n- tree matches origin/alpha/v2/v2.8 after conflict resolution\n- BUILDCHAIN_HEAD_REF=fix/release-line-v2-v2.8-alpha3-mergeability BUILDCHAIN_BASE_REF=release/v2/v2.8 node scripts/verify-release-pr.mjs\n- node --test tests/promote-buildchain-ref.test.mjs\n- alpha npm version confirmed: @kungfu-tech/buildchain@alpha = 2.8.5-alpha.3",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:54:49Z",
          "mergedAt": "2026-07-06T23:57:08Z",
          "additions": 11,
          "deletions": 8,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 706,
          "url": "https://github.com/kungfu-systems/buildchain/pull/706",
          "title": "Prepare v2.8.5-alpha.3",
          "body": "Create the generated version-state commit for v2.8.5-alpha.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:55:35Z",
          "mergedAt": "2026-07-06T23:57:46Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 62,
          "url": "https://github.com/kungfu-systems/kfd/pull/62",
          "title": "release(kfd): promote alpha 13",
          "body": "## Summary\n- promote current dev/v1/v1.0 to alpha/v1/v1.0\n- publishes @kungfu-tech/kfd@1.0.0-alpha.13 through Buildchain trusted publishing after alpha branch verification\n- includes KFD public fact-source metadata and Apache-2.0 official-status/trademark boundary surfaces\n\n## Verification already passed on dev PR #61\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:55:23Z",
          "mergedAt": "2026-07-06T23:58:11Z",
          "additions": 1272,
          "deletions": 224,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 707,
          "url": "https://github.com/kungfu-systems/buildchain/pull/707",
          "title": "Release v2.8.5",
          "body": "Create the generated version-state commit for v2.8.5.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:59:26Z",
          "mergedAt": "2026-07-07T00:01:47Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 301,
          "url": "https://github.com/kungfu-systems/kungfu/pull/301",
          "title": "build(gui): configure Linux and Windows packaging targets",
          "body": "electron-builder.yml only declared mac targets, so gui dist on Linux/Windows fell back to defaults and failed (Linux executableName defaults to the package name @kungfu-tech/gui whose @ and / are rejected). Add explicit linux (dir+AppImage, executableName=kungfu, snap omitted) and win (dir+nsis) targets. Verified on Linux (agent-120): dev+fix produces a 232MB AppImage with executable name kungfu. Windows dist verification to follow.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:06:17Z",
          "mergedAt": "2026-07-07T00:06:23Z",
          "additions": 18,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 708,
          "url": "https://github.com/kungfu-systems/buildchain/pull/708",
          "title": "Prepare v2.8.6-alpha.0",
          "body": "Create the generated version-state commit for v2.8.6-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:04:22Z",
          "mergedAt": "2026-07-07T00:06:25Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 709,
          "url": "https://github.com/kungfu-systems/buildchain/pull/709",
          "title": "Prepare v2.8.6-alpha.0",
          "body": "## Summary\n- sync dev/v2/v2.8 to the next alpha version-state already present on alpha/v2/v2.8\n- prevent future dev-to-alpha PRs from rolling package version back to 2.8.5-alpha.3\n\n## Verification\n- node scripts/generate-site-bundle.mjs --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:11:16Z",
          "mergedAt": "2026-07-07T00:12:54Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 64,
          "url": "https://github.com/kungfu-systems/kfd/pull/64",
          "title": "chore(kfd): enable GitHub release for alpha 14",
          "body": "## Summary\n- bump @kungfu-tech/kfd to 1.0.0-alpha.14\n- enable Buildchain GitHub Release generation for KFD alpha promotion\n- align required status check with the protected check name\n- regenerate KFD-1/2/3 Buildchain evidence after the release anchor and workflow changes\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:25:36Z",
          "mergedAt": "2026-07-07T00:26:51Z",
          "additions": 37,
          "deletions": 36,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 66,
          "url": "https://github.com/kungfu-systems/kfd/pull/66",
          "title": "release(kfd): promote alpha 14",
          "body": "## Summary\n- promote @kungfu-tech/kfd 1.0.0-alpha.14 into alpha/v1/v1.0\n- use a dedicated promotion branch based on current alpha plus the dev candidate to satisfy protected-branch freshness without mutating dev\n- expected release outcome: npm alpha dist-tag and GitHub Release v1.0.0-alpha.14 with buildchain.release.json\n\n## Verification\n- PR #64 checks passed and merged to dev/v1/v1.0\n- npm run check passed on this promotion branch\n- local alpha.14 pack dry-run passed before PR #64\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:30:21Z",
          "mergedAt": "2026-07-07T00:32:37Z",
          "additions": 37,
          "deletions": 36,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 67,
          "url": "https://github.com/kungfu-systems/kfd/pull/67",
          "title": "docs(kfd): record alpha promotion provenance gate",
          "body": "## Summary\n- document the Buildchain alpha promotion provenance requirement\n- point docs/MAP.md to the release governance note\n- refresh KFD-1 and KFD-3 witness hashes for the docs map update\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json\n\n## Context\nThis records the alpha.14 release lesson: Buildchain requires alpha publishing to come from a merged same-repository PR `dev/v1/v1.0 -> alpha/v1/v1.0`; a temporary promotion branch satisfies GitHub freshness but fails Buildchain provenance.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:36:17Z",
          "mergedAt": "2026-07-07T00:37:25Z",
          "additions": 36,
          "deletions": 7,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 68,
          "url": "https://github.com/kungfu-systems/kfd/pull/68",
          "title": "chore(kfd): sync alpha history into dev",
          "body": "## Summary\n- merge current alpha/v1/v1.0 history into dev/v1/v1.0 without changing the file tree\n- restore branch ancestry so the next Buildchain-required dev -> alpha promotion can satisfy strict freshness\n\n## Verification\n- git diff --stat origin/dev/v1/v1.0..HEAD produced no file diff\n- npm run check\n\n## Context\nThe prior alpha promotion attempt through a temporary branch created alpha-only history. Buildchain requires the real release promotion to be a merged same-repository PR from dev/v1/v1.0 to alpha/v1/v1.0, so dev must first include the alpha-only merge commit.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:38:26Z",
          "mergedAt": "2026-07-07T00:39:29Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 63,
          "url": "https://github.com/kungfu-systems/kfd/pull/63",
          "title": "Prepare v1.0.0-alpha.13",
          "body": "Create the generated version-state commit for v1.0.0-alpha.13.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T23:59:08Z",
          "mergedAt": "2026-07-07T00:39:30Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 69,
          "url": "https://github.com/kungfu-systems/kfd/pull/69",
          "title": "release(kfd): promote alpha 14",
          "body": "## Summary\n- promote dev/v1/v1.0 into alpha/v1/v1.0 for @kungfu-tech/kfd 1.0.0-alpha.14\n- publish through Buildchain ref promotion using the required same-repository dev -> alpha provenance path\n- expected release outcome: npm alpha dist-tag and GitHub Release v1.0.0-alpha.14 with buildchain.release.json\n\n## Verification before promotion\n- PR #64 checks passed and enabled GitHub Release generation\n- PR #67 checks passed and documented release provenance gate\n- PR #68 checks passed and synced alpha history into dev without file diff\n- local npm run check passed\n- local npm pack --dry-run --json passed for 1.0.0-alpha.14\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:39:55Z",
          "mergedAt": "2026-07-07T00:41:07Z",
          "additions": 36,
          "deletions": 7,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 711,
          "url": "https://github.com/kungfu-systems/buildchain/pull/711",
          "title": "fix(release-propagation): invoke checked out runtime",
          "body": "## Summary\n- checkout the selected Buildchain runtime into `.buildchain/runtime` before the release-propagation reusable workflow calls the CLI\n- install runtime production dependencies and invoke `.buildchain/runtime/bin/buildchain.mjs` for plan/write-lock\n- document `buildchain-ref` train validation and add a workflow regression test\n\n## Verification\n- node --test tests/release-propagation.test.mjs\n- node scripts/check-inventory.mjs\n- corepack pnpm run check\n\n## Issue #710\n- inspected kungfu-systems/buildchain#710 and kfd run 28832947423\n- the direct failure there is promote governance PR lineage (`feature/kfd-alpha-14-promotion -> alpha/v1/v1.0`), not a missing `bin/buildchain.mjs` checkout; this PR fixes the reusable workflow runtime checkout issue separately\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:50:31Z",
          "mergedAt": "2026-07-07T00:52:48Z",
          "additions": 59,
          "deletions": 15,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 714,
          "url": "https://github.com/kungfu-systems/buildchain/pull/714",
          "title": "chore(release): align dev with alpha ancestry",
          "body": "## Summary\n- merge `alpha/v2/v2.8` back into dev to restore canonical dev-to-alpha promotion mergeability\n- keep the dev-side generated Buildchain contract digest that includes #711\n- this replaces failed direct/recovery alpha PRs #712 and #713\n\n## Verification\n- node scripts/generate-site-bundle.mjs --check\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:59:35Z",
          "mergedAt": "2026-07-07T01:01:35Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 71,
          "url": "https://github.com/kungfu-systems/kfd/pull/71",
          "title": "feat(kfd): generate homepage bundle from README",
          "body": "## Summary\n- generate site/kfd-site.json from README.md instead of maintaining homepage copy by hand\n- expose ordered homepage.sections and homepage.displayPlan so site renderers know what belongs on the first screen, primary narrative, support area, and renderer-contract area\n- make npm run check fail when the checked-in site bundle drifts from the README projection\n- publish scripts/ in the package and release artifact so the KFD self-proof path is visible to npm consumers\n- bump the anchored alpha package version to 1.0.0-alpha.15 and refresh KFD-1/2/3 Buildchain evidence\n\n## Verification\n- npm run update:site-bundle\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:00:24Z",
          "mergedAt": "2026-07-07T01:02:02Z",
          "additions": 503,
          "deletions": 66,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 72,
          "url": "https://github.com/kungfu-systems/kfd/pull/72",
          "title": "release(alpha): promote KFD alpha 15",
          "body": "## Summary\n- promote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd 1.0.0-alpha.15\n- includes generated README-backed homepage bundle and package-visible self-proof scripts\n\n## Verification\n- dev PR #71 passed Verify and Build\n- alpha branch promotion will run protected checks before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:02:56Z",
          "mergedAt": "2026-07-07T01:04:07Z",
          "additions": 503,
          "deletions": 66,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 715,
          "url": "https://github.com/kungfu-systems/buildchain/pull/715",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "## Summary\n- promote the release-propagation runtime checkout fix from dev to alpha\n- includes #711 and dev ancestry alignment #714\n\n## Verification\n- dev branch Verify passed: https://github.com/kungfu-systems/buildchain/actions/runs/28834006062\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-07T01:02:46Z",
          "mergedAt": "2026-07-07T01:05:09Z",
          "additions": 59,
          "deletions": 15,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 717,
          "url": "https://github.com/kungfu-systems/buildchain/pull/717",
          "title": "Prepare v2.8.6-alpha.1",
          "body": "Create the generated version-state commit for v2.8.6-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:07:38Z",
          "mergedAt": "2026-07-07T01:09:32Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 53,
          "url": "https://github.com/kungfu-systems/libnode/pull/53",
          "title": "Build libnode release candidates before promotion",
          "body": "## Summary\n- strip macOS/Linux release libnode binaries during dist generation\n- generate Buildchain release-candidate passports from PR-stage Build runs\n- replace publish-gate heavy rebuild publication with release-candidate promote-only publishing through Buildchain @v2\n- bump alpha version state to 22.22.3-kf.3-alpha.11\n\n## Verification\n- node --check .gyp/node-dist.js\n- actionlint .github/workflows/build.yml .github/workflows/release-new-version.yml\n- node .gyp/libnode-release-verify.js\n- node .gyp/node-platform-package.js verify-source\n- prettier --check .gyp/node-dist.js README.md docs/buildchain.md .github/workflows/build.yml .github/workflows/release-new-version.yml\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs validate --require-version-state --require-lifecycle-stages install,build,verify,publish\n\n## Release semantics\nThe Build workflow now produces the PR-stage release-candidate evidence. After merge to alpha/release, Release - New Version promotes that verified candidate without rebuilding the native matrix.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:36:53Z",
          "mergedAt": "2026-07-07T01:09:54Z",
          "additions": 156,
          "deletions": 15,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 718,
          "url": "https://github.com/kungfu-systems/buildchain/pull/718",
          "title": "release: promote Buildchain v2.8.6",
          "body": "## Summary\n- promote Buildchain v2.8.6-alpha.1 to stable release\n- includes release-propagation runtime checkout fix from #711\n\n## Verification\n- alpha branch Verify passed: https://github.com/kungfu-systems/buildchain/actions/runs/28834318838\n- alpha npm dist-tag is 2.8.6-alpha.1\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-07T01:10:57Z",
          "mergedAt": "2026-07-07T01:14:26Z",
          "additions": 61,
          "deletions": 17,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 73,
          "url": "https://github.com/kungfu-systems/kfd/pull/73",
          "title": "docs(kfd-3): clarify trusted value foundation",
          "body": "## Summary\n- change the KFD-3 foundation sentence to \"cooperation must start from trusted value\"\n- explain that value becomes trusted through transparent facts, choices, and constraints\n- keep renderer-contract text out of homepage.sections so sites that render sections do not show implementation contract text on the homepage\n- bump the anchored alpha package version to 1.0.0-alpha.16 and refresh KFD evidence\n\n## Verification\n- npm run update:site-bundle\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:17:02Z",
          "mergedAt": "2026-07-07T01:18:23Z",
          "additions": 157,
          "deletions": 135,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 720,
          "url": "https://github.com/kungfu-systems/buildchain/pull/720",
          "title": "Release v2.8.6",
          "body": "Create the generated version-state commit for v2.8.6.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:16:49Z",
          "mergedAt": "2026-07-07T01:18:59Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 719,
          "url": "https://github.com/kungfu-systems/buildchain/pull/719",
          "title": "Prepare v2.8.6-alpha.1",
          "body": "Create the generated version-state commit for v2.8.6-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:11:52Z",
          "mergedAt": "2026-07-07T01:19:30Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 74,
          "url": "https://github.com/kungfu-systems/kfd/pull/74",
          "title": "release(alpha): promote KFD alpha 16",
          "body": "## Summary\n- promote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd 1.0.0-alpha.16\n- includes KFD-3 trusted value wording and homepage bundle fix that keeps renderer contract out of homepage.sections\n\n## Verification\n- dev PR #73 passed Verify and Build\n- alpha branch promotion will run protected checks before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:18:35Z",
          "mergedAt": "2026-07-07T01:19:58Z",
          "additions": 157,
          "deletions": 135,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 302,
          "url": "https://github.com/kungfu-systems/kungfu/pull/302",
          "title": "fix(build): unblock Windows core build and cross-platform packaging",
          "body": "Two Windows-portability build fixes surfaced verifying the full package pipeline on Windows: (1) colocate pykungfu.pyd next to libnode.dll for pybind11-stubgen (MSVC multi-config emits the .pyd in build/ root and Python 3.8+ resolves an extension's DLLs from its own dir, so build:core failed with ModuleNotFoundError: pykungfu); (2) resolve --config.electronDist in a node launcher instead of a POSIX $(node -p ...) substitution that cmd.exe cannot run. Both are no-ops / behavior-preserving on macOS and Linux. Verified on Windows: build:core + freeze now pass (Nuitka produces kungfu_cli.exe) and electron-vite build runs; a further packaging-time issue (kfx contract path) is tracked separately.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:26:02Z",
          "mergedAt": "2026-07-07T01:26:09Z",
          "additions": 55,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 721,
          "url": "https://github.com/kungfu-systems/buildchain/pull/721",
          "title": "Prepare v2.8.7-alpha.0",
          "body": "Create the generated version-state commit for v2.8.7-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:21:43Z",
          "mergedAt": "2026-07-07T01:27:04Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 19,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/19",
          "title": "feat(site): improve libkungfu navigation surfaces",
          "body": "## Summary\n- update KFD content generation to @kungfu-tech/kfd@1.0.0-alpha.13\n- add clickable homepage generation-map hotspots and clearer mechanism-card actions\n- align subpage page kickers so the left side returns to the parent page and the right side shows page identity or KFD status\n\n## Verification\n- pnpm run build\n- pnpm run check\n- git diff --check\n\n## Risk\n- rendering/navigation change only; preview and deployment remain workflow-driven",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:44:08Z",
          "mergedAt": "2026-07-07T01:28:51Z",
          "additions": 614,
          "deletions": 82,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 722,
          "url": "https://github.com/kungfu-systems/buildchain/pull/722",
          "title": "fix(release): publish GitHub releases by default",
          "body": "## Summary\n- default release-candidate-promote.yml github-release to true\n- document github-release: false as the opt-out path\n- refresh site bundle digests and add regression coverage\n\n## Validation\n- node --test tests/build-surface.test.mjs\n- node scripts/check-inventory.mjs\n- node scripts/generate-site-bundle.mjs\n- git diff --check\n- corepack pnpm run check\n\n## Issue #710\nI checked #710 while working this change. It is not the same root cause as the release-propagation runtime checkout fix: #710 is a KFD promotion governance lineage failure for a non-canonical source branch, while this PR only changes the GitHub Release default for the promote wrapper.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:27:39Z",
          "mergedAt": "2026-07-07T01:31:08Z",
          "additions": 32,
          "deletions": 28,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 724,
          "url": "https://github.com/kungfu-systems/buildchain/pull/724",
          "title": "chore(release): align dev with alpha state",
          "body": "## Summary\n- merge current alpha/v2/v2.8 version state into dev/v2/v2.8\n- resolve generated site contract digest from the current source state\n- keeps the next canonical dev→alpha promotion mergeable after #722\n\n## Validation\n- node scripts/generate-site-bundle.mjs --check\n- node scripts/check-inventory.mjs",
          "author": "kungfu-origin",
          "createdAt": "2026-07-07T01:33:33Z",
          "mergedAt": "2026-07-07T01:35:36Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 20,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/20",
          "title": "fix(kfd): publish subdomain decision route aliases",
          "body": "## Summary\n- generate root-level aliases for KFD decision pages so kfd.libkungfu.dev/1/, /2/, and /3/ resolve on subdomain deployments\n- add site checks that compare the aliases with canonical dist/kfd/* pages\n\n## Verification\n- pnpm run build\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:35:01Z",
          "mergedAt": "2026-07-07T01:36:45Z",
          "additions": 19,
          "deletions": 10,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 303,
          "url": "https://github.com/kungfu-systems/kungfu/pull/303",
          "title": "fix(gui): find the kfx contract on Windows when baking the manifest",
          "body": "The electron-builder beforePack manifest bake called loadKfxContract without a cwd, so the contract resolver walked ancestors of env.PWD only; cmd.exe does not set PWD, so on Windows the committed framework/kfx/kungfu-kfx.contract.json was reported not found and dist failed. Pass cwd: process.cwd() to match POSIX behavior. With this the full Windows package pipeline completes: verified on DARKHERO producing a 162MB 'Kungfu Setup 4.0.0-alpha.0.exe' nsis installer. No change on macOS/Linux.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:38:28Z",
          "mergedAt": "2026-07-07T01:38:35Z",
          "additions": 6,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 725,
          "url": "https://github.com/kungfu-systems/buildchain/pull/725",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "## Summary\n- promote dev/v2/v2.8 to alpha/v2/v2.8\n- includes release-candidate-promote.yml defaulting github-release to true with explicit opt-out\n\n## Validation\n- #722 checks passed and merged\n- #724 aligned dev with alpha state and passed checks\n- dev Verify after #724: https://github.com/kungfu-systems/buildchain/actions/runs/28835287337",
          "author": "kungfu-origin",
          "createdAt": "2026-07-07T01:36:47Z",
          "mergedAt": "2026-07-07T01:38:43Z",
          "additions": 32,
          "deletions": 28,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 726,
          "url": "https://github.com/kungfu-systems/buildchain/pull/726",
          "title": "Prepare v2.8.7-alpha.1",
          "body": "Create the generated version-state commit for v2.8.7-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:41:16Z",
          "mergedAt": "2026-07-07T01:43:37Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 21,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/21",
          "title": "chore(site): render buildchain alpha 2.8.7",
          "body": "## Summary\n- render site content from @kungfu-tech/buildchain@2.8.7-alpha.1\n- update Buildchain drift guards in render/check scripts\n- pin the Buildchain transitive KFD dependency to the registry package via pnpm workspace override because the alpha metadata currently declares a GitHub dependency\n\n## Verification\n- pnpm run build\n- pnpm run check\n- git diff --check\n\n## Note\n@kungfu-tech/buildchain@2.8.7-alpha.1 should fix its npm metadata so @kungfu-tech/kfd resolves from the npm registry instead of github:kungfu-systems/kfd#...; the site override is a downstream compatibility guard.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:53:43Z",
          "mergedAt": "2026-07-07T01:55:23Z",
          "additions": 17,
          "deletions": 16,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 728,
          "url": "https://github.com/kungfu-systems/buildchain/pull/728",
          "title": "feat(site): publish README-derived homepage bundle",
          "body": "## Summary\n- publish a README-derived `dist/site/buildchain-site.json` homepage contract for downstream site repositories\n- document the Buildchain-owned vs site-owned rendering boundary\n- reject exotic npm dependency specifiers in package metadata, and pin `@kungfu-tech/kfd` to the audited npm package `1.0.0-alpha.16`\n\n## Verification\n- `node scripts/generate-site-bundle.mjs --check`\n- `node scripts/check-inventory.mjs`\n- `node --test tests/build-surface.test.mjs tests/buildchain-contract.test.mjs`\n- `corepack pnpm run check`\n- `npm pack --json --pack-destination /tmp/... --registry=https://registry.npmjs.org/` and inspected tarball `package/package.json` dependencies\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:51:20Z",
          "mergedAt": "2026-07-07T01:58:55Z",
          "additions": 4025,
          "deletions": 123,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 55,
          "url": "https://github.com/kungfu-systems/libnode/pull/55",
          "title": "Enable GitHub Release evidence publication",
          "body": "Enable Buildchain's github-release output for libnode release promotion so release passport/evidence assets are published to the exact-tag GitHub Release.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:22:40Z",
          "mergedAt": "2026-07-07T02:00:50Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 729,
          "url": "https://github.com/kungfu-systems/buildchain/pull/729",
          "title": "chore(release): align dev with alpha state",
          "body": "## Summary\\n- merge alpha v2.8 version-state back into dev after site bundle changes\\n- regenerate Buildchain site contract digest for package version 2.8.7-alpha.1\\n\\n## Verification\\n- node scripts/check-inventory.mjs\\n- node scripts/generate-site-bundle.mjs --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:00:54Z",
          "mergedAt": "2026-07-07T02:02:59Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 23,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/23",
          "title": "release(site): promote buildchain alpha staging to production",
          "body": "## Release intent\nPromote the current staging content to production.\n\n## Source\n- Staging source SHA: 944a417f6c57a38db2840e2f964321297e7a7f35\n- Release intent commit: 6cd7b32\n- Buildchain site package: @kungfu-tech/buildchain@2.8.7-alpha.1\n- KFD site package: @kungfu-tech/kfd@1.0.0-alpha.16\n\n## Staging verification\n- Staging run: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/28835998775\n- https://buildchain.staging.libkungfu.dev/ shows 2.8.7-alpha.1\n- https://staging.libkungfu.dev/, https://core.staging.libkungfu.dev/, https://kfd.staging.libkungfu.dev/, and https://kfd.staging.libkungfu.dev/3/ returned 200\n\n## Gate\nManual release PR for this cycle. Future expected flow: Buildchain opens this PR automatically after staging apply succeeds.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-07T02:03:15Z",
          "mergedAt": "2026-07-07T02:05:21Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 732,
          "url": "https://github.com/kungfu-systems/buildchain/pull/732",
          "title": "feat(web-surface): open production release PR after staging",
          "body": "## Summary\n- add Buildchain-owned production release PR creation after successful staging apply\n- create release/<channel>-<short-sha> branches with an empty release-intent commit and buildchain-release label\n- record staging URLs, source SHA, artifact hash, and staging release-passport evidence in the PR body\n- document the staging -> release PR -> production gate flow and refresh the site bundle\n\n## Validation\n- bash scripts/check-workflows.sh\n- node --test tests/build-surface.test.mjs tests/web-surface.test.mjs\n- node scripts/check-inventory.mjs && node scripts/generate-site-bundle.mjs --check\n- node --check scripts/web-surface-production-release-pr.mjs\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:13:56Z",
          "mergedAt": "2026-07-07T02:15:37Z",
          "additions": 460,
          "deletions": 19,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 24,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/24",
          "title": "fix(site): use canonical production surface links",
          "body": "## Summary\n- route cross-surface header, homepage cards, and map hotspots to canonical surface hosts\n- use stable KFD decision paths (/1/, /2/, /3/) instead of path-relative decision links\n- keep checks from regressing to host-local /core/, /buildchain/, or /kfd/ links on subdomains\n\n## Verification\n- pnpm run build\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:15:25Z",
          "mergedAt": "2026-07-07T02:17:18Z",
          "additions": 38,
          "deletions": 34,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 735,
          "url": "https://github.com/kungfu-systems/buildchain/pull/735",
          "title": "chore(release): align dev with alpha state",
          "body": "## Summary\n- merge current alpha/v2/v2.8 state back into dev/v2/v2.8 so canonical dev -> alpha promotion is conflict-free\n- resolve generated site contract digests with the current dev fact source\n\n## Validation\n- node scripts/check-inventory.mjs\n- node scripts/generate-site-bundle.mjs --check\n- bash scripts/check-workflows.sh\n- node --test tests/build-surface.test.mjs tests/web-surface.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:22:16Z",
          "mergedAt": "2026-07-07T02:24:32Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 734,
          "url": "https://github.com/kungfu-systems/buildchain/pull/734",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "## Summary\n- promote dev/v2/v2.8 into alpha/v2/v2.8 using the canonical channel lineage\n- includes site bundle/KFD npm metadata fixes and web-surface production release PR automation\n\n## Validation\n- dev branch Verify passed: https://github.com/kungfu-systems/buildchain/actions/runs/28836751958\n- local promotion dry-run branch validated with:\n  - node scripts/check-inventory.mjs\n  - node scripts/generate-site-bundle.mjs --check\n  - bash scripts/check-workflows.sh\n  - node --test tests/build-surface.test.mjs tests/web-surface.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:21:10Z",
          "mergedAt": "2026-07-07T02:26:33Z",
          "additions": 4479,
          "deletions": 136,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 736,
          "url": "https://github.com/kungfu-systems/buildchain/pull/736",
          "title": "Prepare v2.8.7-alpha.2",
          "body": "Create the generated version-state commit for v2.8.7-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:29:05Z",
          "mergedAt": "2026-07-07T02:30:45Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 738,
          "url": "https://github.com/kungfu-systems/buildchain/pull/738",
          "title": "release: promote Buildchain v2.8 stable",
          "body": "Promote Buildchain v2.8 from alpha to release.\n\nValidation chain:\n- dev Verify passed: https://github.com/kungfu-systems/buildchain/actions/runs/28837067821\n- alpha promotion PR passed and merged: #734\n- alpha version-state PR passed and merged: #736\n- alpha finalization promotion passed: https://github.com/kungfu-systems/buildchain/actions/runs/28837327689\n\nThis is the canonical alpha/v2/v2.8 -> release/v2/v2.8 promotion so release-line lineage checks can validate the channel source.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:34:04Z",
          "mergedAt": "2026-07-07T02:35:42Z",
          "additions": 4511,
          "deletions": 164,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 739,
          "url": "https://github.com/kungfu-systems/buildchain/pull/739",
          "title": "Release v2.8.7",
          "body": "Create the generated version-state commit for v2.8.7.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:37:41Z",
          "mergedAt": "2026-07-07T02:39:19Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 737,
          "url": "https://github.com/kungfu-systems/buildchain/pull/737",
          "title": "Prepare v2.8.7-alpha.2",
          "body": "Create the generated version-state commit for v2.8.7-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:33:11Z",
          "mergedAt": "2026-07-07T02:40:31Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 740,
          "url": "https://github.com/kungfu-systems/buildchain/pull/740",
          "title": "Prepare v2.8.8-alpha.0",
          "body": "Create the generated version-state commit for v2.8.8-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:41:50Z",
          "mergedAt": "2026-07-07T02:43:43Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 76,
          "url": "https://github.com/kungfu-systems/kfd/pull/76",
          "title": "docs(kfd): add adoption boundary",
          "body": "## Summary\n- add the KFD adoption boundary to README so KFD remains an engineering discipline, not a belief test\n- expose adoption-boundary as non-first-screen homepage content in site/kfd-site.json\n- keep renderer contract outside homepage.sections\n- bump the anchored alpha package version to 1.0.0-alpha.17 and refresh KFD evidence\n\n## Verification\n- npm run update:site-bundle\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:44:19Z",
          "mergedAt": "2026-07-07T02:45:46Z",
          "additions": 99,
          "deletions": 69,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 77,
          "url": "https://github.com/kungfu-systems/kfd/pull/77",
          "title": "release(alpha): promote KFD alpha 17",
          "body": "## Summary\n- promote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd 1.0.0-alpha.17\n- includes the KFD adoption boundary as non-first-screen homepage content\n\n## Verification\n- dev PR #76 passed Verify and Build\n- alpha branch promotion will run protected checks before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:46:08Z",
          "mergedAt": "2026-07-07T02:48:07Z",
          "additions": 99,
          "deletions": 69,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 57,
          "url": "https://github.com/kungfu-systems/libnode/pull/57",
          "title": "ci: promote libnode alpha candidate",
          "body": "Promote the current dev/v22/v22.22 content to alpha/v22/v22.22 using a candidate branch based on the current alpha tip.\\n\\nThis keeps the PR head up to date with the protected alpha base while preserving the dev tree exactly.\\n\\nValidation target:\\n- Build release-candidate on Linux x64, macOS ARM64, and Windows x64\\n- Publish via buildchain release-candidate promotion after merge\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:20:25Z",
          "mergedAt": "2026-07-07T02:58:30Z",
          "additions": 171,
          "deletions": 16,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 59,
          "url": "https://github.com/kungfu-systems/libnode/pull/59",
          "title": "ci: sync alpha promotion fixes into dev",
          "body": "Sync the current alpha promotion fixes back into dev and prepare the next alpha package version.\\n\\nThis branch is based on the current alpha tip, so merging it into dev records the alpha ancestry required for the next strict dev→alpha promotion.\\n\\nChanges:\\n- add the aggregate Build workflow status check already validated on alpha candidate #57\\n- bump npm version state from 22.22.3-kf.3-alpha.11 to 22.22.3-kf.3-alpha.12, because alpha.11 failed before npm publication\\n\\nLocal verification:\\n- pnpm verify-release\\n- pnpm verify-package-source\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T03:01:23Z",
          "mergedAt": "2026-07-07T03:15:50Z",
          "additions": 16,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 52,
          "url": "https://github.com/kungfu-systems/libnode/pull/52",
          "title": "Prepare v22.22.1-alpha.4",
          "body": "Create the generated version-state commit for v22.22.1-alpha.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:47:13Z",
          "mergedAt": "2026-07-07T03:15:52Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 743,
          "url": "https://github.com/kungfu-systems/buildchain/pull/743",
          "title": "fix(release): allow promotion automation review bypass",
          "body": "## Summary\n- add declarative branch-protection bypass inputs for Buildchain-managed promotion automation\n- update release-candidate promote wrapper and Buildchain self-promotion workflow to pass bypass identities\n- recognize GitHub approving-review protected-branch rejections and fall back to version-state PRs\n- refresh Buildchain site bundle documentation facts\n\n## Validation\n- corepack pnpm@11.7.0 run check\n\n## Release intent\n- Publish a new Buildchain alpha after this lands on dev/v2/v2.8.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T03:20:54Z",
          "mergedAt": "2026-07-07T03:22:49Z",
          "additions": 282,
          "deletions": 117,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 745,
          "url": "https://github.com/kungfu-systems/buildchain/pull/745",
          "title": "chore(release): align dev with alpha state",
          "body": "## Summary\n- align dev/v2/v2.8 with the current alpha v2.8.8-alpha.0 version state\n- regenerate Buildchain site contract digest after resolving the generated bundle conflict\n\n## Validation\n- corepack pnpm@11.7.0 run check\n\n## Context\nThis repairs the dev/alpha divergence left by the protected dev branch post-release bookkeeping failure, so the pending alpha promotion PR can merge cleanly.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T03:25:47Z",
          "mergedAt": "2026-07-07T03:27:38Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 744,
          "url": "https://github.com/kungfu-systems/buildchain/pull/744",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "## Summary\n- promote current dev/v2/v2.8 into alpha/v2/v2.8\n- includes controlled promotion automation review bypass support for protected dev/alpha/release bookkeeping\n\n## Validation\n- dev PR #743 passed Verify and Build Surface Fixture checks\n- local full check passed before merge: corepack pnpm@11.7.0 run check\n\n## Release intent\n- Publish a new Buildchain alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T03:23:16Z",
          "mergedAt": "2026-07-07T03:30:51Z",
          "additions": 282,
          "deletions": 117,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 61,
          "url": "https://github.com/kungfu-systems/libnode/pull/61",
          "title": "Release alpha 22.22.3-kf.3-alpha.12",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 for libnode 22.22.3-kf.3-alpha.12.\\n\\nThis is the strict Buildchain promotion path: same-repository dev→alpha PR, with dev already containing the current alpha base.\\n\\nExpected after merge:\\n- Release - New Version uses the PR-stage release-candidate artifacts\\n- npm publishes via trusted publishing with dist-tag alpha\\n- GitHub Release evidence/passport is published by Buildchain\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T03:16:24Z",
          "mergedAt": "2026-07-07T03:34:04Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 746,
          "url": "https://github.com/kungfu-systems/buildchain/pull/746",
          "title": "Prepare v2.8.8-alpha.1",
          "body": "Create the generated version-state commit for v2.8.8-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T03:33:33Z",
          "mergedAt": "2026-07-07T03:36:21Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 747,
          "url": "https://github.com/kungfu-systems/buildchain/pull/747",
          "title": "fix(release): complete version-state sync without PR fallback",
          "body": "## Summary\n- auto-add the promotion token's authenticated user/app to managed branch-protection bypass allowances\n- fail fast instead of opening post-publish version-state PRs when generated channel bookkeeping cannot be applied directly\n- update release governance docs and site bundle for direct alpha/dev sync semantics\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs\n- node --test tests/build-surface.test.mjs tests/release-line-policy.test.mjs\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:12:49Z",
          "mergedAt": "2026-07-07T04:15:59Z",
          "additions": 265,
          "deletions": 307,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 748,
          "url": "https://github.com/kungfu-systems/buildchain/pull/748",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "Promote dev/v2/v2.8 to alpha/v2/v2.8 to dogfood direct generated version-state sync without post-publish PR fallback.\n\nVerification before promotion:\n- PR #747 merged into dev/v2/v2.8\n- local check passed on #747 branch\n- required PR checks passed on #747",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:16:27Z",
          "mergedAt": "2026-07-07T04:18:15Z",
          "additions": 265,
          "deletions": 307,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 304,
          "url": "https://github.com/kungfu-systems/kungfu/pull/304",
          "title": "feat(atlas): show imported Atlas work in the GUI",
          "body": "Expose the Atlas Mission/go projection through the GUI Work Dashboard while Atlas remains the authority.\\n\\nValidation:\\n- ./kungfu-code verify --full (57/57 passed)\\n- GUI dogfood confirmed\\n- Atlas sync helper imported 5 missions / 365 goals / 882 markers",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:18:28Z",
          "mergedAt": "2026-07-07T04:20:10Z",
          "additions": 1080,
          "deletions": 80,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 750,
          "url": "https://github.com/kungfu-systems/buildchain/pull/750",
          "title": "fix(release): satisfy generated version-state checks",
          "body": "Fix protected generated version-state finalization without post-publish PR fallback.\n\nSummary:\n- create the configured required check on the exact generated version-state commit before direct protected ref updates\n- pass github.token from release-candidate-promote.yml for GitHub Actions-owned generated checks\n- grant checks:write to the reusable wrapper\n- document the generated-check direct-sync path\n\nVerification:\n- node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run generate:site\n- git diff --check\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:26:28Z",
          "mergedAt": "2026-07-07T04:28:26Z",
          "additions": 211,
          "deletions": 93,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 752,
          "url": "https://github.com/kungfu-systems/buildchain/pull/752",
          "title": "chore(release): restore alpha dev lineage",
          "body": "Restore dev/v2/v2.8 history so it contains the alpha/v2/v2.8 merge commit from the interrupted promotion run.\n\nThis is a topology repair only: it merges alpha/v2/v2.8 into dev/v2/v2.8 without source file changes, so subsequent alpha promotion PRs are no longer behind the alpha branch.\n\nVerification:\n- merge completed without conflicts\n- no source file changes in the merge commit",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:30:00Z",
          "mergedAt": "2026-07-07T04:31:46Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 751,
          "url": "https://github.com/kungfu-systems/buildchain/pull/751",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "Promote dev/v2/v2.8 to alpha/v2/v2.8 after fixing generated version-state required checks.\n\nThis dogfoods that alpha promotion can finish generated version-state/dev synchronization directly after the channel PR merge, without opening a post-publish version-state PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:29:02Z",
          "mergedAt": "2026-07-07T04:33:39Z",
          "additions": 211,
          "deletions": 93,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 753,
          "url": "https://github.com/kungfu-systems/buildchain/pull/753",
          "title": "fix(release): grant promotion checks permission",
          "body": "Grant checks:write on the Buildchain Ref Promotion caller workflow so the reusable release-candidate-promote workflow can create generated version-state required checks.\n\nThis fixes the workflow_run startup_failure observed after adding generated-status-check-token support.\n\nVerification:\n- node --test tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:36:45Z",
          "mergedAt": "2026-07-07T04:38:29Z",
          "additions": 4,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 754,
          "url": "https://github.com/kungfu-systems/buildchain/pull/754",
          "title": "chore(release): restore alpha dev lineage after startup repair",
          "body": "Restore dev/v2/v2.8 history so it contains the alpha/v2/v2.8 merge commit from #751 after the promotion workflow startup_failure.\n\nThis is a topology repair only: it merges alpha/v2/v2.8 into dev/v2/v2.8 without source file changes, so the next alpha promotion PR starts from a clean lineage.\n\nVerification:\n- merge completed without conflicts\n- no source file changes in the merge commit",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:39:52Z",
          "mergedAt": "2026-07-07T04:41:38Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 755,
          "url": "https://github.com/kungfu-systems/buildchain/pull/755",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "Promote dev/v2/v2.8 to alpha/v2/v2.8 after generated version-state check and promotion caller checks permission fixes.\n\nDogfood target:\n- promotion workflow starts successfully\n- generated version-state required check is created before protected ref update\n- alpha/dev finish synchronized directly without a post-publish version-state PR",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:42:05Z",
          "mergedAt": "2026-07-07T04:43:49Z",
          "additions": 4,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 758,
          "url": "https://github.com/kungfu-systems/buildchain/pull/758",
          "title": "fix(release): generate self KFD witnesses after version state",
          "body": "## Summary\n- move Buildchain self-KFD witness generation into promote-buildchain-ref finalization so hashes bind to the final version-state workspace\n- keep release-candidate-promote declarative by passing release-passport-buildchain-self-kfd through to the action instead of running a wrapper-side script\n- update docs, site bundle, inventory checks, and surface tests\n\n## Validation\n- node --test tests/build-surface.test.mjs\n- node --test tests/release-passport.test.mjs\n- node --check actions/promote-buildchain-ref/lib.js && node --check actions/promote-buildchain-ref/index.js\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- corepack pnpm@11.7.0 run generate:site\n- corepack pnpm@11.7.0 run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:55:54Z",
          "mergedAt": "2026-07-07T04:58:16Z",
          "additions": 195,
          "deletions": 123,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 759,
          "url": "https://github.com/kungfu-systems/buildchain/pull/759",
          "title": "chore(release): promote dev to alpha",
          "body": "## Summary\n- promote current dev/v2/v2.8 to alpha/v2/v2.8\n- dogfood final-version self-KFD witness generation inside promote-buildchain-ref\n\n## Validation\n- Uses Buildchain Verify and Build Surface Fixture PR checks before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:59:47Z",
          "mergedAt": "2026-07-07T05:01:48Z",
          "additions": 195,
          "deletions": 123,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 25,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/25",
          "title": "fix(site): render governed bundle navigation",
          "body": "## Summary\n- render Buildchain bundle pages with homepage/sidebar navigation and child-page global navigation\n- update KFD/Buildchain package pins and no-override dependency policy\n- fix KFD foundation card layout overlap and keep human site links relative\n\n## Verification\n- pnpm run build\n- pnpm run check\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:05:35Z",
          "mergedAt": "2026-07-07T05:07:31Z",
          "additions": 684,
          "deletions": 197,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 27,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/27",
          "title": "fix(ci): pin buildchain web surface workflow",
          "body": "## Summary\n- pin the reusable Buildchain web-surface workflow to v2.8.6 because current v2/v2.8.7 resolves to a startup_failure before jobs are created\n- unblock staging and production publication for the already merged site update\n\n## Evidence\n- previous successful workflow_dispatch used buildchain workflow SHA 4e865c1 (tag v2.8.6)\n- current v2 resolves to 0483e17 (tag v2.8.7) and startup-fails before jobs/logs\n\n## Verification\n- pnpm run check\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:10:13Z",
          "mergedAt": "2026-07-07T05:10:24Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 761,
          "url": "https://github.com/kungfu-systems/buildchain/pull/761",
          "title": "fix(release): skip generated version-state promotion runs",
          "body": "## Summary\n- skip Buildchain self-promotion when the completed Verify run came from generated release/version-state commits\n- keep generated commit titles covered by inventory and build-surface tests\n\n## Why\nSuccessful alpha promotion writes generated version-state commits back to alpha/dev. Those pushes should finish Verify only; they must not start a second promote job that cannot have PR-stage RC lineage.\n\nFixes #760.\n\n## Validation\n- corepack pnpm@11.7.0 run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:10:29Z",
          "mergedAt": "2026-07-07T05:12:12Z",
          "additions": 7,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 762,
          "url": "https://github.com/kungfu-systems/buildchain/pull/762",
          "title": "chore(release): promote v2.8 alpha",
          "body": "## Summary\n- promote current dev/v2/v2.8 to alpha/v2/v2.8\n- publish the next Buildchain v2.8 alpha after release workflow fixes\n\n## Validation\n- PR checks and Buildchain self-promotion workflow will validate the release candidate before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:12:36Z",
          "mergedAt": "2026-07-07T05:14:16Z",
          "additions": 7,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 28,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/28",
          "title": "fix(site): keep cross-surface links canonical",
          "body": "## Summary\n- keep cross-surface human links canonical by default, e.g. hub -> kfd.libkungfu.dev and buildchain.libkungfu.dev\n- preserve localhost development by adding data-local-href fallbacks rewritten only on localhost/127.0.0.1\n- keep intra-surface navigation relative, such as KFD decision pages and Buildchain docs pages\n\n## Verification\n- pnpm run build\n- pnpm run check\n- browser localhost check confirms runtime fallback keeps local links local\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:17:52Z",
          "mergedAt": "2026-07-07T05:23:44Z",
          "additions": 57,
          "deletions": 27,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 763,
          "url": "https://github.com/kungfu-systems/buildchain/pull/763",
          "title": "fix(release): use release token for protected generated refs",
          "body": "## Summary\n- add a generated-ref-update-token input to promote-buildchain-ref\n- pass BUILDCHAIN_PROMOTION_TOKEN from release-candidate-promote for protected generated ref updates\n- keep generated status checks on github.token while using the release authority for protected version-state/channel bookkeeping\n\n## Fixes\n- Fixes the KFD/buildchain-friction class where finalization publishes successfully, then fails to PATCH a protected dev/* ref with `At least 1 approving review is required`.\n- Specifically addresses the open issue class represented by #741 without requiring consumer reruns or manual PR approval for Buildchain-generated bookkeeping.\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs --test-name-pattern \"generated ref update token|direct version-state sync|controlled branch-protection review bypass\"\n- node --test tests/build-surface.test.mjs --test-name-pattern \"branch-protection review bypass\"\n- node --check actions/promote-buildchain-ref/lib.js && node --check actions/promote-buildchain-ref/index.js\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- corepack pnpm@11.7.0 run generate:site\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:30:16Z",
          "mergedAt": "2026-07-07T05:31:59Z",
          "additions": 261,
          "deletions": 108,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 764,
          "url": "https://github.com/kungfu-systems/buildchain/pull/764",
          "title": "chore(release): promote v2.8 alpha",
          "body": "## Summary\n- Promote dev/v2/v2.8 to alpha/v2/v2.8.\n- Includes protected generated ref update token support from #763.\n\n## Expected publish\n- alpha prerelease only\n- no stable/latest release movement\n- generated version-state follow-up should remain skipped\n\n## Validation before merge\n- PR-stage Buildchain checks and release-candidate artifacts",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:32:25Z",
          "mergedAt": "2026-07-07T05:34:07Z",
          "additions": 261,
          "deletions": 108,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 305,
          "url": "https://github.com/kungfu-systems/kungfu/pull/305",
          "title": "feat(sdk): add product workflows for kfx and artifacts",
          "body": "## Summary\n- add SDK-distributed `kungfu sdk product` workflows for GUI/TUI dev and build flows\n- move distributable packaging to artifact-level dist with declared first-party kfx dependencies\n- support single-kfx dev run and artifact product dist from one command\n\n## Validation\n- `./kungfu-code check:types`\n- `./kungfu-code --filter @kungfu-tech/sdk run build`\n- `./kungfu-code verify`\n- `./kungfu-code dist`\n- `hdiutil verify artifact/dist/Kungfu-4.0.0-alpha.0-arm64.dmg`\n- artifact extensions dependency check: declared 11, found 11, missing 0, extra 0\n\n## Artifacts\n- `artifact/dist/Kungfu-4.0.0-alpha.0-arm64.dmg`\n- dmg sha256: `15fea3804d305601ba06238fc080c41da0d0cd4a8221c0cd099c95932522b5c4`\n- zip sha256: `b9c99845548d6dbb6ae8f69f5b121d7d308bd4e1faa27cd4dceaf334969400aa`",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:34:19Z",
          "mergedAt": "2026-07-07T05:35:18Z",
          "additions": 1463,
          "deletions": 52,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 306,
          "url": "https://github.com/kungfu-systems/kungfu/pull/306",
          "title": "docs(agent): expose Atlas projection onboarding",
          "body": "Expose Atlas projection import/show commands through the installed Kungfu agent onboarding pack so agents can discover the workflow from Kungfu itself.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:38:58Z",
          "mergedAt": "2026-07-07T05:40:26Z",
          "additions": 104,
          "deletions": 6,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 765,
          "url": "https://github.com/kungfu-systems/buildchain/pull/765",
          "title": "feat(site): define surface manifest timestamp policy",
          "body": "## Summary\n- add a shared `@kungfu-tech/buildchain/surface-manifest` timestamp/reproducibility policy helper\n- apply the policy to Buildchain site bundle manifests, web-surface deployment manifests for every named surface, and Release Passport metadata\n- inject CI/release timestamps during Buildchain promotion version-state/publish lifecycles while keeping source checkouts deterministic with `source-date-epoch`\n- make site manifests version-state files so timestamp/version manifest changes remain part of the audited promotion entry\n\n## Validation\n- `corepack pnpm@11.7.0 run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:51:16Z",
          "mergedAt": "2026-07-07T05:55:11Z",
          "additions": 502,
          "deletions": 93,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 766,
          "url": "https://github.com/kungfu-systems/buildchain/pull/766",
          "title": "release: promote v2.8 alpha",
          "body": "## Summary\n- Promote the current Buildchain v2.8 dev line to alpha.\n- Includes the surface manifest timestamp/reproducibility policy update from PR #765.\n\n## Validation\n- PR #765 passed `check` and Build Surface Fixture.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:55:50Z",
          "mergedAt": "2026-07-07T05:57:39Z",
          "additions": 502,
          "deletions": 93,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 16,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/16",
          "title": "feat(site): add commercial site structure",
          "body": "## Summary\\n- add About, Services, and Legal pages so kungfu.tech is no longer a single-page product site\\n- link the commercial product axis to libkungfu.dev as the developer substrate axis\\n- keep homepage copy in coming-soon posture while preserving cost/state/proof positioning\\n- compact homepage trust copy and keep full policy detail on Trust/Legal pages\\n\\n## Verification\\n- bash scripts/build-site.sh\\n- bash scripts/check-site.sh\\n- Playwright snapshots for home, About, Services, and Legal\\n\\n## Release scope\\n- This PR is intended to update staging after merge to main.\\n- It is not a Buildchain production release PR and does not carry the buildchain-release label.\\n\\nAgent: Codex\\nGoal: 2026-07-07-kungfu-tech-production-site-structure\\nMission: kungfu-technical-stewardship",
          "author": "dongkeren",
          "createdAt": "2026-07-07T06:00:55Z",
          "mergedAt": "2026-07-07T06:02:27Z",
          "additions": 765,
          "deletions": 43,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 307,
          "url": "https://github.com/kungfu-systems/kungfu/pull/307",
          "title": "ci: route product builds through buildchain",
          "body": "## Summary\n- Add the Buildchain v2 product build workflow for alpha/release channel PRs.\n- Route product build artifacts through the S3-to-GitHub-artifacts relay on the kungfu-v4 self-hosted runner preset.\n- Replace legacy v1 release verify/publish workflows with lightweight verify plus Buildchain RC promote-only.\n- Keep npm and GitHub Release publishing disabled by using a custom publish evidence script.\n\n## Validation\n- actionlint .github/workflows/build.yml .github/workflows/release-verify.yml .github/workflows/release-new-version.yml .github/workflows/buildchain-validate.yml\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs validate config --require-version-state --require-lifecycle-stages install,build,verify,publish\n- node --check scripts/buildchain-custom-publish-evidence.mjs\n- Buildchain validatePublishEvidence smoke for the custom evidence script\n\n## Release behavior\nThe heavy product build runs once on the alpha/release PR open/ready event. The merge-side workflow uses Buildchain release-candidate promote-only and does not call the build matrix again.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T06:11:28Z",
          "mergedAt": "2026-07-07T06:12:30Z",
          "additions": 186,
          "deletions": 66,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 308,
          "url": "https://github.com/kungfu-systems/kungfu/pull/308",
          "title": "ci: align buildchain promotion check name",
          "body": "## Summary\n- Align the Buildchain promote required status check fragment with the product build job name (  • electron-builder version=20.39.0).\n\n## Validation\n- actionlint .github/workflows/release-new-version.yml",
          "author": "dongkeren",
          "createdAt": "2026-07-07T06:13:44Z",
          "mergedAt": "2026-07-07T06:14:59Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 310,
          "url": "https://github.com/kungfu-systems/kungfu/pull/310",
          "title": "ci: bootstrap buildchain alpha workflow",
          "body": "## Summary\n- Bootstrap alpha/v4/v4.0 with the Buildchain Build workflow file.\n- Replace legacy v1 release verify with a lightweight handoff check.\n- Disable release promotion on this bootstrap PR so it cannot publish or promote.\n\n## Why\nThe first dev/v4/v4.0 -> alpha/v4/v4.0 attempt created a Build workflow startup_failure because the alpha base branch did not yet contain .github/workflows/build.yml. This bootstrap PR prepares the alpha base for the actual release-candidate PR.\n\n## Validation\n- actionlint .github/workflows/build.yml .github/workflows/release-verify.yml .github/workflows/release-new-version.yml .github/workflows/buildchain-validate.yml\n- git diff --check\n\n## Release behavior\nThis PR is not a release candidate and must not be counted as the alpha product build. The actual alpha PR will be opened after this bootstrap is merged and branch protection is restored to require build.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T06:23:32Z",
          "mergedAt": "2026-07-07T06:24:18Z",
          "additions": 67,
          "deletions": 67,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 313,
          "url": "https://github.com/kungfu-systems/kungfu/pull/313",
          "title": "ci: simplify buildchain product build caller",
          "body": "## Summary\n- Simplify the Build workflow caller for Buildchain v2 reusable workflow.\n- Add secrets inheritance and remove optional workflow_dispatch/concurrency/expression inputs while keeping the product build contract unchanged.\n\n## Validation\n- actionlint .github/workflows/build.yml .github/workflows/release-verify.yml .github/workflows/release-new-version.yml .github/workflows/buildchain-validate.yml\n- git diff --check\n\n## Release behavior\nThis PR targets dev/v4/v4.0 and does not run the product build. The actual product build remains reserved for the next dev -> alpha release-candidate PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T06:33:51Z",
          "mergedAt": "2026-07-07T06:34:31Z",
          "additions": 2,
          "deletions": 14,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 315,
          "url": "https://github.com/kungfu-systems/kungfu/pull/315",
          "title": "ci: grant buildchain build issue permission",
          "body": "## Summary\n- grant the Buildchain reusable build workflow the issue permission it requests\n- unblock alpha release-candidate build startup while keeping publish/release options disabled in Buildchain config\n\n## Validation\n- actionlint .github/workflows/build.yml .github/workflows/release-verify.yml .github/workflows/release-new-version.yml .github/workflows/buildchain-validate.yml\n- git diff --check\n\n## Build policy\n- This PR targets dev/v4/v4.0, so it should only run signoff/validate and must not run the product Build workflow.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T06:41:49Z",
          "mergedAt": "2026-07-07T06:42:42Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 317,
          "url": "https://github.com/kungfu-systems/kungfu/pull/317",
          "title": "ci: make buildchain lifecycle install portable",
          "body": "## Summary\n- run Buildchain lifecycle stages through a Node shim that dispatches to kungfu-code on POSIX and kungfu-code.cmd on Windows\n- update pnpm-lock.yaml so framework/core optional platform packages match package.json under frozen lockfile checks\n\n## Evidence from failed alpha PR\n- PR #316 scheduled exactly one product Build workflow run: https://github.com/kungfu-systems/kungfu/actions/runs/28847079471\n- Windows failed because ./kungfu-code sync is not executable under cmd\n- macOS/Linux failed frozen lockfile because framework/core optionalDependencies were missing from pnpm-lock.yaml\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- CI=true fnm exec --using-file -- corepack pnpm install --frozen-lockfile --lockfile-only --force\n- node scripts/buildchain-run-kungfu-code.mjs sync\n- fnm exec --using-file -- corepack pnpm exec buildchain validate --require-version-state --require-lifecycle-stages install,build,verify\n- git diff --check\n\n## Build policy\n- This PR targets dev/v4/v4.0 and should not run product Build. A fresh alpha PR will be opened after this lands.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T07:01:09Z",
          "mergedAt": "2026-07-07T07:02:01Z",
          "additions": 59,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 319,
          "url": "https://github.com/kungfu-systems/kungfu/pull/319",
          "title": "ci: fix buildchain install lifecycle",
          "body": "## Summary\n- skip optional platform packages during the Buildchain install lifecycle\n- invoke kungfu-code.cmd through cmd call on Windows runners\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- pnpm exec biome check scripts/buildchain-run-kungfu-code.mjs\n- pnpm run check:types\n- node scripts/buildchain-run-kungfu-code.mjs install --frozen-lockfile --no-optional\n- pnpm exec buildchain validate --require-version-state --require-lifecycle-stages install,build,verify\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T07:25:54Z",
          "mergedAt": "2026-07-07T07:26:53Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 321,
          "url": "https://github.com/kungfu-systems/kungfu/pull/321",
          "title": "ci: provide buildchain pnpm shims",
          "body": "## Summary\n- inject a temporary pnpm/pnpm.cmd shim for Buildchain lifecycle commands\n- avoid Windows cmd quote drift by invoking fnm/corepack directly on Windows\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- pnpm exec biome check scripts/buildchain-run-kungfu-code.mjs\n- pnpm run check:types\n- node scripts/buildchain-run-kungfu-code.mjs exec pnpm --version\n- node scripts/buildchain-run-kungfu-code.mjs install --frozen-lockfile --no-optional\n- pnpm exec buildchain validate --require-version-state --require-lifecycle-stages install,build,verify\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T07:47:35Z",
          "mergedAt": "2026-07-07T07:48:25Z",
          "additions": 40,
          "deletions": 14,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 323,
          "url": "https://github.com/kungfu-systems/kungfu/pull/323",
          "title": "ci: use corepack directly on windows buildchain",
          "body": "## Summary\n- avoid requiring fnm in the Windows Buildchain lifecycle wrapper\n- keep the temporary pnpm.cmd shim for nested pnpm calls inside package scripts\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- pnpm exec biome check scripts/buildchain-run-kungfu-code.mjs\n- pnpm run check:types\n- node scripts/buildchain-run-kungfu-code.mjs exec pnpm --version\n- node scripts/buildchain-run-kungfu-code.mjs install --frozen-lockfile --no-optional\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:00:49Z",
          "mergedAt": "2026-07-07T08:01:36Z",
          "additions": 5,
          "deletions": 9,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 325,
          "url": "https://github.com/kungfu-systems/kungfu/pull/325",
          "title": "ci: carry no-optional through artifact dist",
          "body": "## Summary\n- pass a Buildchain-only no-optional marker through lifecycle commands\n- let artifact dist reuse --no-optional for its internal dependency sync\n- run Windows corepack.cmd through a shell so .cmd execution works\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- node --check artifact/scripts/dist.mjs\n- pnpm exec biome check scripts/buildchain-run-kungfu-code.mjs artifact/scripts/dist.mjs\n- pnpm run check:types\n- node scripts/buildchain-run-kungfu-code.mjs exec node -e \"console.log(process.env.KUNGFU_BUILDCHAIN_NO_OPTIONAL)\"\n- node scripts/buildchain-run-kungfu-code.mjs install --frozen-lockfile --no-optional\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:10:26Z",
          "mergedAt": "2026-07-07T08:11:18Z",
          "additions": 11,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 768,
          "url": "https://github.com/kungfu-systems/buildchain/pull/768",
          "title": "fix(site): preserve published manifest timestamp policy",
          "body": "## Summary\n- preserve current-version `ci-injected` site manifest timestamp policy during deterministic `generate-site-bundle --check` runs\n- keep source checkouts able to force `source-date-epoch` explicitly\n- document that version-state branches use the existing published manifest policy as deterministic input\n\n## Validation\n- simulated published `ci-injected` manifest followed by `GITHUB_SHA=... pnpm run check:site`\n- `corepack pnpm@11.7.0 run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:14:05Z",
          "mergedAt": "2026-07-07T08:16:01Z",
          "additions": 51,
          "deletions": 17,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 327,
          "url": "https://github.com/kungfu-systems/kungfu/pull/327",
          "title": "feat(gui): add settings overlay and dev gates",
          "body": "## Summary\n- add a tabbed settings overlay hosted by the GUI shell\n- add bootstrap build/rebuild commands for fresh worktrees\n- add changed-scope check/fix gates and make pre-commit read-only\n\n## Verification\n- ./kungfu-code check\n- node --check scripts/build.mjs scripts/check.mjs scripts/fix.mjs scripts/precommit.mjs\n- /bin/sh -n kungfu-code && /bin/sh -n .githooks/pre-commit\n- git diff --check\n- ./kungfu-code build (completed earlier in this worktree)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:17:07Z",
          "mergedAt": "2026-07-07T08:17:59Z",
          "additions": 1247,
          "deletions": 234,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 771,
          "url": "https://github.com/kungfu-systems/buildchain/pull/771",
          "title": "fix(site): preserve published manifest timestamp policy",
          "body": "## Summary\n- preserve existing ci-injected site manifest timestamp policy on version-state branches\n- keep generated dist/site outputs check-clean for the currently published alpha version\n- document deterministic check behavior for published manifests\n\n## Validation\n- node --check scripts/generate-site-bundle.mjs\n- node scripts/check-inventory.mjs\n- GITHUB_SHA=cccccccccccccccccccccccccccccccccccccccc corepack pnpm@11.7.0 run check:site\n- corepack pnpm@11.7.0 run check\n\nThis reopens the same commit from #770 under a release-line-aware version-state head ref.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:24:45Z",
          "mergedAt": "2026-07-07T08:27:14Z",
          "additions": 51,
          "deletions": 17,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 767,
          "url": "https://github.com/kungfu-systems/buildchain/pull/767",
          "title": "release: promote v2.8 stable",
          "body": "## Summary\n- Promote Buildchain v2.8 alpha to stable release.\n- Includes `@kungfu-tech/buildchain@2.8.8-alpha.7` surface manifest timestamp/reproducibility policy and release passport timestamp policy support.\n\n## Validation\n- Alpha promotion run 28845027391 succeeded.\n- npm alpha is 2.8.8-alpha.7.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:09:21Z",
          "mergedAt": "2026-07-07T08:30:00Z",
          "additions": 1343,
          "deletions": 418,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 328,
          "url": "https://github.com/kungfu-systems/kungfu/pull/328",
          "title": "ci: prepare buildchain source build prerequisites",
          "body": "## Summary\n- keep Buildchain no-optional installs while injecting only the current libnode platform package for source rebuilds\n- mark Buildchain source builds and auto-detect a Conan default profile when missing\n- add common Windows user tool directories to PATH for lifecycle commands\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs artifact/scripts/dist.mjs framework/core/.gyp/run-conan.js\n- pnpm exec biome check scripts/buildchain-run-kungfu-code.mjs artifact/scripts/dist.mjs framework/core/.gyp/run-conan.js\n- pnpm run check:types\n- node scripts/buildchain-run-kungfu-code.mjs install --frozen-lockfile --no-optional\n- libnode NODE_PATH probe with @kungfu-tech/libnode-darwin-arm64@22.22.3-kf.1",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:34:56Z",
          "mergedAt": "2026-07-07T08:36:14Z",
          "additions": 146,
          "deletions": 11,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 774,
          "url": "https://github.com/kungfu-systems/buildchain/pull/774",
          "title": "fix(release): accept version-state PR lineage",
          "body": "## Summary\n- accept same-line buildchain/version-state/* PR heads as strict promotion lineage when they are merged, same-repository PRs targeting the channel branch\n- keep the existing dev->alpha / alpha->release rule as the primary expected source\n- add a regression test for alpha promotion from a same-line version-state PR\n\n## Validation\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:43:46Z",
          "mergedAt": "2026-07-07T08:46:23Z",
          "additions": 114,
          "deletions": 43,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 330,
          "url": "https://github.com/kungfu-systems/kungfu/pull/330",
          "title": "ci: align core optional lockfile specifiers",
          "body": "## Summary\n- add the framework/core optional platform-package specifiers to the lockfile importer so Buildchain no-optional frozen installs validate on clean runners\n\n## Validation\n- CI=true pnpm install --frozen-lockfile --no-optional --lockfile-only\n- node scripts/buildchain-run-kungfu-code.mjs install --frozen-lockfile --no-optional\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:47:40Z",
          "mergedAt": "2026-07-07T08:48:17Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 775,
          "url": "https://github.com/kungfu-systems/buildchain/pull/775",
          "title": "fix(release): accept version-state PR lineage",
          "body": "## Summary\n- promote the version-state PR lineage fix into alpha using the release-line-aware version-state ref form\n- allows the pending alpha promotion to recognize same-line version-state PRs as valid same-repository lineage\n\n## Validation\n- corepack pnpm@11.7.0 run check\n\nThis is the alpha-side runtime fix needed before rerunning the pending stable promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:49:44Z",
          "mergedAt": "2026-07-07T08:52:10Z",
          "additions": 114,
          "deletions": 43,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 332,
          "url": "https://github.com/kungfu-systems/kungfu/pull/332",
          "title": "ci: discover uv from windows runner users",
          "body": "## Summary\n- add Windows user tool directories from C:\\Users\\* to the Buildchain wrapper PATH so self-hosted runner jobs can find an existing uv.exe during source rebuilds\n- keep this scoped to Windows Buildchain lifecycle execution; no tool installation is performed\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- pnpm exec biome check scripts/buildchain-run-kungfu-code.mjs\n- node scripts/buildchain-run-kungfu-code.mjs exec node -e \"console.log(process.env.KUNGFU_BUILDCHAIN_NO_OPTIONAL, process.env.KUNGFU_BUILDCHAIN_SOURCE_BUILD)\"\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:59:13Z",
          "mergedAt": "2026-07-07T09:00:03Z",
          "additions": 19,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 777,
          "url": "https://github.com/kungfu-systems/buildchain/pull/777",
          "title": "release: promote Buildchain v2.8 stable",
          "body": "Promote the current v2.8 alpha runtime into release/v2/v2.8 with conflicts resolved on a line-scoped Buildchain version-state branch.\n\nThis absorbs the alpha lineage fix and site manifest timestamp-policy release material so stable promotion can tree-match v2.8.8-alpha.8 before finalizing the stable npm/GitHub release.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:01:41Z",
          "mergedAt": "2026-07-07T09:03:51Z",
          "additions": 125,
          "deletions": 54,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 334,
          "url": "https://github.com/kungfu-systems/kungfu/pull/334",
          "title": "feat(gui): add global appearance config",
          "body": "## Summary\n- add `kungfu config set` and `kungfu config unset` for contract-validated user overrides\n- wire GUI global font family, font size, and zoom through the Kungfu config mechanism\n- add an Appearance tab with cross-platform font presets and Custom font-family input\n\n## Verification\n- `./kungfu-code check`\n- `./kungfu-code build`\n- `./kungfu-code verify`\n\n## Version impact\n- minor: adds user-facing global appearance settings",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:02:59Z",
          "mergedAt": "2026-07-07T09:04:12Z",
          "additions": 628,
          "deletions": 20,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 17,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/17",
          "title": "Release kungfu.tech commercial launch refresh",
          "body": "Production release for the refreshed kungfu.tech commercial site.\\n\\nChanged:\\n- consolidates shared header/footer styling into public/assets/site.css\\n- refines homepage/header/footer copy and mobile layout\\n- keeps public copy in coming-soon positioning\\n\\nVerified locally:\\n- bash scripts/build-site.sh\\n- bash scripts/check-site.sh\\n- mobile viewport checks at 390px and 320px\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:18:10Z",
          "mergedAt": "2026-07-07T09:19:42Z",
          "additions": 535,
          "deletions": 563,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 335,
          "url": "https://github.com/kungfu-systems/kungfu/pull/335",
          "title": "ci: instrument artifact buildchain lifecycle",
          "body": "## Summary\n- upgrade the SDK and artifact build dependency to the latest Buildchain release package, @kungfu-tech/buildchain@2.8.7\n- instrument artifact/scripts/dist.mjs with Buildchain toolkit lifecycle spans and event verification\n- keep no-optional Buildchain source builds working by installing current-platform libnode and Rollup native packages under .buildchain and exposing them through NODE_PATH\n- broaden Windows runner tool discovery for uv/uvx across WinGet package directories and Scoop shims\n\n## Validation\n- node --check artifact/scripts/dist.mjs\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- ./kungfu-code exec biome check artifact/scripts/dist.mjs scripts/buildchain-run-kungfu-code.mjs artifact/package.json developer/sdk/package.json\n- ./kungfu-code run check:types\n- CI=true ./kungfu-code install --frozen-lockfile --no-optional --lockfile-only\n- Buildchain logging smoke with BUILDCHAIN_LOG_PATH\n- Rollup platform package resolution smoke\n\n## Alpha PR handling\n- Closed #333 after its single allowed Build run failed on Windows and Linux\n- Cancelled the remaining queued jobs for run 28854374922 before opening this dev fix PR",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:20:32Z",
          "mergedAt": "2026-07-07T09:21:58Z",
          "additions": 463,
          "deletions": 103,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 780,
          "url": "https://github.com/kungfu-systems/buildchain/pull/780",
          "title": "fix(release): defer protected next-alpha bookkeeping",
          "body": "Fix #778.\n\nWhen release finalization has already published the stable artifact but protected branch bookkeeping rejects a direct non-fast-forward next-alpha update, Buildchain now creates a line-scoped version-state PR and returns a pending finalization instead of failing the whole promotion run.\n\nValidation:\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:27:08Z",
          "mergedAt": "2026-07-07T09:29:03Z",
          "additions": 159,
          "deletions": 70,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 337,
          "url": "https://github.com/kungfu-systems/kungfu/pull/337",
          "title": "ci: bootstrap uv for buildchain windows",
          "body": "## Summary\n- upgrade @kungfu-tech/buildchain to the current latest release package, 2.8.8\n- bootstrap uv into .buildchain/uv on Windows only when uv is not already available\n- keep the bootstrap scoped to the lifecycle wrapper instead of mutating runner-global state\n- exclude generated .buildchain runtime files from the no-bash guard used by verify\n\n## Evidence from alpha #336\n- Windows now installs libnode and Rollup platform packages but still fails because uv is unavailable on the runner\n- Linux builds the AppImage and reports Buildchain observability events, then fails verify because .buildchain/runtime/scripts/check-workflows.sh is generated by Buildchain runtime and should not be scanned as repo source\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- node --check scripts/no-bash-guard.mjs\n- node scripts/no-bash-guard.mjs\n- ./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs scripts/no-bash-guard.mjs artifact/package.json developer/sdk/package.json\n- ./kungfu-code run check:types\n- CI=true ./kungfu-code install --frozen-lockfile --no-optional --lockfile-only",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:34:08Z",
          "mergedAt": "2026-07-07T09:34:50Z",
          "additions": 94,
          "deletions": 10,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 78,
          "url": "https://github.com/kungfu-systems/kfd/pull/78",
          "title": "ci(kfd): lock Buildchain floating contract",
          "body": "## Summary\\n- move KFD build and promotion workflows back to Buildchain v2 floating refs\\n- add a consumer-owned buildchain.contract-lock.json for Buildchain runtime contract drift checks\\n- publish the lock as a KFD package surface and bind it into KFD-2/KFD-3 witnesses\\n- bump the next alpha package version to 1.0.0-alpha.18\\n\\n## Verification\\n- node scripts/check.mjs\\n- Buildchain contract lock check: unchanged / compatible / no drift\\n- ruby YAML parse for workflows\\n- npm pack --dry-run --json\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:26:51Z",
          "mergedAt": "2026-07-07T09:42:58Z",
          "additions": 159,
          "deletions": 57,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 782,
          "url": "https://github.com/kungfu-systems/buildchain/pull/782",
          "title": "feat(web-surface): gate floating runtime contract drift",
          "body": "Add first-class Buildchain contract lock inputs to the reusable web-surface workflow so floating @v2 consumers get compatible/breaking drift handling before caller build, render, deploy planning, or publish side effects.\\n\\nIncludes contract-world/site-bundle updates and tests.\\n\\nValidation:\\n- corepack pnpm@11.7.0 run check\\n- corepack pnpm@11.7.0 run check:site\\n- corepack pnpm@11.7.0 exec node --test tests/buildchain-contract.test.mjs tests/build-surface.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:44:27Z",
          "mergedAt": "2026-07-07T09:46:16Z",
          "additions": 244,
          "deletions": 14,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 79,
          "url": "https://github.com/kungfu-systems/kfd/pull/79",
          "title": "release(kfd): publish alpha 18",
          "body": "## Summary\n- Promote current dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd 1.0.0-alpha.18.\n- Includes Buildchain @v2 floating reusable workflow integration with buildchain.contract-lock.json.\n- Carries KFD-1/2/3 witness metadata for the alpha package and release passport.\n\n## Verification\n- PR #78 Verify and Build passed on dev.\n- This PR should run the alpha branch gates and Buildchain promotion after merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:43:39Z",
          "mergedAt": "2026-07-07T09:46:34Z",
          "additions": 159,
          "deletions": 57,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 339,
          "url": "https://github.com/kungfu-systems/kungfu/pull/339",
          "title": "docs(readme): align public Kungfu positioning",
          "body": "## Summary\n\n- Align the README opening with the public Kungfu product and developer entrypoints.\n- Replace the older facts-before-trust slogan with KFD-oriented claim and receipt language.\n- Update the facts-before-trust document opening to match the README framing.\n\n## Checks\n\n- git diff --check\n- public wording scan for private maintenance signals\n- ./kungfu-code check (blocked during dependency install: current pnpm lockfile is missing @kungfu-tech/core optional package entries)",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:47:58Z",
          "mergedAt": "2026-07-07T09:48:54Z",
          "additions": 27,
          "deletions": 11,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 341,
          "url": "https://github.com/kungfu-systems/kungfu/pull/341",
          "title": "feat(gui): add shell status bar chrome",
          "body": "## Summary\n- add a bottom shell status bar for runtime, master, profile and KFX count signals\n- expose trusted shell APIs for status bar items and notifications\n- fix GUI root sizing so the status bar does not create an outer scrollbar\n- keep source installs from resolving unpublished core platform packages\n- sync SDK contract policy expectations with current KFD and Buildchain metadata\n\n## Validation\n- ./kungfu-code --filter @kungfu-tech/gui run build\n- ./kungfu-code product gui dev --dry-run\n- ./kungfu-code check\n- manual GUI dev run confirmed the status bar renders without an outer scrollbar",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:50:16Z",
          "mergedAt": "2026-07-07T09:51:07Z",
          "additions": 658,
          "deletions": 125,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 784,
          "url": "https://github.com/kungfu-systems/buildchain/pull/784",
          "title": "chore(action): sync promote action bundle",
          "body": "Sync the bundled promote-buildchain-ref action with source so Buildchain version-state verification does not dirty the workspace during alpha promotion.\\n\\nFixes the alpha promotion failure observed in run 28857079107 / issue #783.\\n\\nValidation:\\n- corepack pnpm@11.7.0 --filter ./actions/promote-buildchain-ref build",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:49:30Z",
          "mergedAt": "2026-07-07T09:51:17Z",
          "additions": 13,
          "deletions": 13,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 340,
          "url": "https://github.com/kungfu-systems/kungfu/pull/340",
          "title": "ci: lock conan for buildchain source builds",
          "body": "## Summary\n- add Conan 2 to the locked framework/core uv project\n- make `uv run --frozen conan ...` reproducible on self-hosted runners instead of relying on runner-global tools\n\n## Validation\n- `cd framework/core && uv lock --check`\n- `cd framework/core && uv run --frozen conan --version`\n- `tmp_conan_home=\"$(mktemp -d /tmp/kungfu-conan-home.XXXXXX)\" && cd framework/core && CONAN_HOME=\"$tmp_conan_home\" uv run --frozen conan profile detect --force`\n- `node --check scripts/buildchain-run-kungfu-code.mjs && node --check framework/core/.gyp/run-conan.js`\n- `./kungfu-code exec biome check framework/core/pyproject.toml scripts/buildchain-run-kungfu-code.mjs framework/core/.gyp/run-conan.js`\n- `./kungfu-code run check:types`\n\n## Alpha build note\nPR #338 was closed after its single allowed Build run failed on Windows before native compilation: `uv run --frozen conan profile detect --force` could not find `conan`. This PR fixes forward through dev before opening a fresh alpha PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:49:30Z",
          "mergedAt": "2026-07-07T09:52:42Z",
          "additions": 112,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 81,
          "url": "https://github.com/kungfu-systems/kfd/pull/81",
          "title": "ci(kfd): allow promotion check writes",
          "body": "## Summary\n- Grant Buildchain Ref Promotion the checks: write permission required by the Buildchain v2 reusable promotion workflow.\n- Regenerate KFD-2/KFD-3 metadata hashes for the workflow contract update.\n\n## Verification\n- node scripts/update-kfd-2-claim.mjs\n- node scripts/update-kfd-3-witness.mjs\n- node scripts/update-kfd-1-witness.mjs\n- node scripts/check.mjs\n- ruby YAML parse for buildchain-ref-promotion.yml\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:51:53Z",
          "mergedAt": "2026-07-07T09:54:22Z",
          "additions": 12,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 82,
          "url": "https://github.com/kungfu-systems/kfd/pull/82",
          "title": "release(kfd): publish alpha 18",
          "body": "## Summary\n- Promote current dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd 1.0.0-alpha.18.\n- Includes Buildchain @v2 floating reusable workflow integration with buildchain.contract-lock.json.\n- Includes the Buildchain promotion checks: write permission required by the v2 promotion wrapper.\n\n## Verification\n- PR #78 Verify and Build passed on dev.\n- PR #81 Verify and Build passed on dev.\n- This PR should run alpha branch gates and then trigger Buildchain Ref Promotion after merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:54:45Z",
          "mergedAt": "2026-07-07T09:57:08Z",
          "additions": 12,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 343,
          "url": "https://github.com/kungfu-systems/kungfu/pull/343",
          "title": "docs(readme): add project status badges",
          "body": "## Summary\n\n- Add README badges for Buildchain Validate and DCO status.\n- Add compact public metadata badges for Apache-2.0 license, coming-soon product status, and supported platforms.\n\n## Checks\n\n- git diff --check\n- README public wording scan\n- badge URL HTTP checks\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:57:04Z",
          "mergedAt": "2026-07-07T09:57:48Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 70,
          "url": "https://github.com/kungfu-systems/kfd/pull/70",
          "title": "Prepare v1.0.0-alpha.14",
          "body": "Create the generated version-state commit for v1.0.0-alpha.14.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-07T00:42:03Z",
          "mergedAt": "2026-07-07T09:58:20Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 75,
          "url": "https://github.com/kungfu-systems/kfd/pull/75",
          "title": "Prepare v1.0.0-alpha.16",
          "body": "Create the generated version-state commit for v1.0.0-alpha.16.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-07T01:21:21Z",
          "mergedAt": "2026-07-07T09:58:20Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 785,
          "url": "https://github.com/kungfu-systems/buildchain/pull/785",
          "title": "release: promote Buildchain v2.8.9 stable",
          "body": "Promote Buildchain v2.8.9 stable from the alpha line.\\n\\nIncludes:\\n- #780 protected next-alpha finalization fix for #778\\n- #782 first-class web-surface floating runtime contract lock gate\\n- #784 promote action bundle sync required by version-state verification\\n\\nValidation:\\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:56:55Z",
          "mergedAt": "2026-07-07T09:58:55Z",
          "additions": 414,
          "deletions": 95,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 787,
          "url": "https://github.com/kungfu-systems/buildchain/pull/787",
          "title": "docs(readme): add project status badges",
          "body": "## Summary\n- Add README status badges aligned with the Kungfu repository style.\n- Surface Verify, release gate, npm latest/alpha, GitHub Release, license, stability, and supported platforms.\n\n## Validation\n- git diff --check\n- Verified badge SVG endpoints return HTTP 200.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:08:12Z",
          "mergedAt": "2026-07-07T10:15:59Z",
          "additions": 18,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 344,
          "url": "https://github.com/kungfu-systems/kungfu/pull/344",
          "title": "feat(gui): add integrated window chrome",
          "body": "## Summary\n- add a shared renderer titlebar for Electron GUI shell chrome\n- use macOS hidden inset titlebar with traffic-light safe area\n- use Windows custom frame controls and keep Linux on conservative native chrome\n- add a command/search entry that opens enabled KFX views by id or title\n\n## Validation\n- ./kungfu-code --filter @kungfu-tech/gui run build\n- ./kungfu-code check\n- ./kungfu-code build\n- ./kungfu-code product gui dev (macOS visual smoke confirmed)\n\n## Notes\n- Windows and Linux behavior is implemented by platform branches but only build-validated from macOS in this pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:16:27Z",
          "mergedAt": "2026-07-07T10:17:01Z",
          "additions": 433,
          "deletions": 33,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 345,
          "url": "https://github.com/kungfu-systems/kungfu/pull/345",
          "title": "ci: lock ninja for buildchain windows",
          "body": "## Summary\n- add Ninja to the locked framework/core uv project\n- make `cmake-js --generator Ninja` reproducible on Windows self-hosted runners instead of relying on runner-global ninja\n\n## Validation\n- `cd framework/core && uv lock --check`\n- `cd framework/core && uv run --frozen ninja --version`\n- `cd framework/core && uv run --frozen conan --version`\n- `./kungfu-code run check:types`\n- `git diff --check`\n\n## Alpha build note\nPR #342 was closed after its single allowed Build run failed on Windows. It advanced past uv and Conan install/build setup, then failed during `cmake-js configure` because CMake could not find the Ninja build program.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:16:28Z",
          "mergedAt": "2026-07-07T10:17:52Z",
          "additions": 31,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 788,
          "url": "https://github.com/kungfu-systems/buildchain/pull/788",
          "title": "fix(release): base pending version-state PRs on channel heads",
          "body": "## Summary\n- create or reuse Buildchain-owned version-state PRs when release finalization protected refs reject direct generated bookkeeping\n- base pending next-alpha commits on the current channel head so generated PRs are clean and auditable\n- extend the same fallback to publish-gate/major release/next-alpha finalization and update docs/site bundle\n\n## Validation\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run check\n\n## Issue\n- Fixes #778\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:27:40Z",
          "mergedAt": "2026-07-07T10:29:44Z",
          "additions": 403,
          "deletions": 132,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 63,
          "url": "https://github.com/kungfu-systems/libnode/pull/63",
          "title": "feat(release): add KFD passport gates for libnode alpha",
          "body": "## Summary\n- add KFD-1 contract-world witness for libnode release facts\n- add KFD-2 public release trust claim with explicit residual risks\n- add KFD-3 collaboration-interface prebuild witness and artifact verifier\n- wire Buildchain release passport KFD inputs and bump alpha to 22.22.3-kf.3-alpha.13\n\n## Verification\n- corepack pnpm verify-release\n- corepack pnpm verify-package-source\n- git diff --check\n- local Buildchain release passport simulation with KFD-1/2/3 inputs\n\n## Notes\n- KFD-2 intentionally reports downgraded warning for upstream Node and native toolchain residual risk; KFD-1 and KFD-3 hard gates pass in simulation.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:10:14Z",
          "mergedAt": "2026-07-07T10:33:37Z",
          "additions": 820,
          "deletions": 2,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 790,
          "url": "https://github.com/kungfu-systems/buildchain/pull/790",
          "title": "chore(release): sync alpha state back to dev",
          "body": "## Summary\n- Merge current alpha/v2/v2.8 state back into dev/v2/v2.8 so dev remains a clean promotion source.\n- Preserve #788 release finalization fix while carrying forward the published alpha version-state and web-surface contract changes.\n- Regenerate site bundle and promote-buildchain-ref dist.\n\n## Validation\n- corepack pnpm@11.7.0 run check\n\n## Context\n- Unblocks dev -> alpha promotion after #788; the previous PR #789 was dirty because alpha and dev had diverged.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:34:44Z",
          "mergedAt": "2026-07-07T10:36:42Z",
          "additions": 261,
          "deletions": 31,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 347,
          "url": "https://github.com/kungfu-systems/kungfu/pull/347",
          "title": "ci: load msvc env for buildchain windows",
          "body": "## Summary\n- load MSVC Developer environment automatically for Windows Buildchain runs when `cl.exe` is not already on PATH\n- locate `vcvars64.bat` via VSINSTALLDIR, vswhere, or bounded Visual Studio directory discovery\n- keep the wrapper self-contained so Windows self-hosted runners do not need to start from a Developer Prompt\n\n## Validation\n- `node --check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code run check:types`\n- `git diff --check`\n\n## Alpha build note\nPR #346 was closed after its single allowed Build run failed on Windows. It advanced past uv, Conan, and Ninja setup, then failed during CMake configure because `cl` was not on PATH.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:33:14Z",
          "mergedAt": "2026-07-07T10:38:14Z",
          "additions": 165,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 791,
          "url": "https://github.com/kungfu-systems/buildchain/pull/791",
          "title": "chore(release): record alpha ancestry in dev",
          "body": "## Summary\n- Record current alpha/v2/v2.8 as an ancestor of dev/v2/v2.8 without changing the dev tree.\n- This fixes GitHub merge-base conflict detection for the dev -> alpha promotion PR after #790 was squash-merged.\n\n## Validation\n- git diff --quiet origin/dev/v2/v2.8 HEAD\n\n## Merge mode\nPlease merge with a merge commit, not squash, so ancestry is preserved.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:37:53Z",
          "mergedAt": "2026-07-07T10:39:47Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 789,
          "url": "https://github.com/kungfu-systems/buildchain/pull/789",
          "title": "Promote dev/v2.8 to alpha",
          "body": "## Summary\n- Promote current dev/v2/v2.8 into alpha/v2/v2.8 after #788.\n- This should publish the next alpha using the fixed release finalization runtime.\n\n## Validation\n- dev PR #788 passed Verify and Build Surface Fixture before merge.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:30:32Z",
          "mergedAt": "2026-07-07T10:41:48Z",
          "additions": 320,
          "deletions": 131,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 794,
          "url": "https://github.com/kungfu-systems/buildchain/pull/794",
          "title": "chore(release): record release ancestry in alpha",
          "body": "Record the current release/v2/v2.8 head as an ancestor of alpha/v2/v2.8 without changing the alpha tree.\n\nThis keeps the stable promotion PR mergeable while preserving the published alpha package state.\n\nValidation:\n- tree diff vs origin/alpha/v2/v2.8 is empty\n- head ref uses the Buildchain version-state namespace accepted by release-line policy",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:51:43Z",
          "mergedAt": "2026-07-07T10:53:25Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 349,
          "url": "https://github.com/kungfu-systems/kungfu/pull/349",
          "title": "feat(gui): add collapsible sidebar",
          "body": "## Summary\n- add a persisted shell state flag for sidebar collapsed state\n- add a compact navigation rail toggle to the GUI shell\n- keep collapsed navigation accessible through view initials and tooltips\n\n## Validation\n- ./kungfu-code --filter @kungfu-tech/gui run build\n- ./kungfu-code check\n- ./kungfu-code build\n- ./kungfu-code product gui dev (macOS visual smoke confirmed)",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:54:19Z",
          "mergedAt": "2026-07-07T10:54:50Z",
          "additions": 76,
          "deletions": 25,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 65,
          "url": "https://github.com/kungfu-systems/libnode/pull/65",
          "title": "release(alpha): publish 22.22.3-kf.3-alpha.13",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 for @kungfu-tech/libnode 22.22.3-kf.3-alpha.13.\n\nThis release candidate includes first-class KFD 1/2/3 release passport gates:\n- KFD-1 contract/world witness for libnode release-critical source surfaces.\n- KFD-2 public release trust claim with explicit residual risks.\n- KFD-3 collaboration interface prebuild witness and artifact reverse audit command.\n\nRelease source merge commit: 8b418cb4f9a2cd03317b0c7c815f8b4a6643d74e",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:34:23Z",
          "mergedAt": "2026-07-07T10:55:27Z",
          "additions": 820,
          "deletions": 2,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 792,
          "url": "https://github.com/kungfu-systems/buildchain/pull/792",
          "title": "Promote v2.8.10 to stable",
          "body": "## Summary\n- Promote alpha/v2/v2.8 to release/v2/v2.8 after v2.8.10-alpha.0.\n- This publishes the stable release containing #788 and the README/KFD badges.\n\n## Validation\n- Alpha promotion run 28860197348 succeeded.\n- npm alpha dist-tag is 2.8.10-alpha.0.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:45:31Z",
          "mergedAt": "2026-07-07T10:55:35Z",
          "additions": 326,
          "deletions": 131,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 350,
          "url": "https://github.com/kungfu-systems/kungfu/pull/350",
          "title": "ci: fix windows vcvars bootstrap",
          "body": "Fix the Windows Buildchain lifecycle wrapper after PR #348 proved the install lifecycle fails before the build step.\n\nChanges:\n- invoke vcvars64.bat through `cmd /d /c call \"...\" x64 >nul && set` so paths with spaces are handled correctly\n- detect MSVC availability with `where.exe cl` instead of `cl /Bv`, because `cl /Bv` can locate the compiler but still exits non-zero without source files\n\nValidation:\n- `node --check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code run check:types`\n- `git diff --check`\n- DARKHERO read-only Windows smoke: `call vcvars64.bat ... && where cl` resolves cl.exe successfully\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:58:49Z",
          "mergedAt": "2026-07-07T10:59:48Z",
          "additions": 9,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 796,
          "url": "https://github.com/kungfu-systems/buildchain/pull/796",
          "title": "fix(release): bind stable promotion to frozen alpha evidence",
          "body": "Fixes release promotion finalization after an ancestry/version-state alpha PR creates a later same-patch alpha tag.\n\nWhen promoting alpha -> release, Buildchain now first resolves the merged promotion PR frozen head SHA and uses the same-patch alpha tag that is actually contained in that PR head. This prevents a later next-alpha bookkeeping tag from replacing the source alpha evidence for stable promotion.\n\nRegression coverage:\n- release promotion uses frozen PR alpha evidence when a later same-patch alpha exists\n\nValidation:\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run check\n\nRelated: #795",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:10:15Z",
          "mergedAt": "2026-07-07T11:12:29Z",
          "additions": 216,
          "deletions": 57,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 352,
          "url": "https://github.com/kungfu-systems/kungfu/pull/352",
          "title": "feat(agent): close KFD-3 agent interface",
          "body": "## Summary\n- add a packaged KFD-3 registry and local schema for the agent-first collaboration interface\n- anchor `kungfu agent` Click commands and the command catalog to registry API ids\n- preserve Atlas projection mode and register the `kungfu atlas` catalog commands in KFD-3 verification\n\n## Validation\n- `./kungfu-code check`\n- `./kungfu-code node scripts/verify-agent-pack.mjs`\n\n## Notes\n- Source-checkout CLI smoke needs a built native `pykungfu` binding; the changed-scope gate and agent-pack verifier passed without a full build.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:11:54Z",
          "mergedAt": "2026-07-07T11:13:22Z",
          "additions": 853,
          "deletions": 63,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 353,
          "url": "https://github.com/kungfu-systems/kungfu/pull/353",
          "title": "ci: use verbatim cmd args for vcvars",
          "body": "Fix the second Windows MSVC bootstrap issue seen in alpha PR #351.\n\nPR #350 changed the command to `call \"...vcvars64.bat\"`, but Node's Windows argument quoting still passed escaped quotes (`\\\"...\\\"`) to `cmd.exe` when using the normal args array. This PR uses the tested `cmd.exe /d /s /c \"\"<vcvars>\" x64 >nul && set\"` form with `windowsVerbatimArguments: true` so `cmd.exe` receives the batch path quotes correctly.\n\nValidation:\n- `node --check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code run check:types`\n- `git diff --check`\n- DARKHERO Node smoke with identical `spawnSync` arguments resolves `cl.exe` successfully\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:13:53Z",
          "mergedAt": "2026-07-07T11:14:31Z",
          "additions": 2,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 66,
          "url": "https://github.com/kungfu-systems/libnode/pull/66",
          "title": "ci(release): allow promote workflow check updates",
          "body": "Fix the Release - New Version caller permissions for Buildchain v2 promotion.\n\nBuildchain's reusable release-candidate promote workflow requests checks: write. The libnode caller workflow only granted actions/contents/id-token/issues, so GitHub rejected the alpha publish run at startup before any job/log was created.\n\nThis PR only grants checks: write to the caller workflow; it does not change package payload files or the libnode version.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:59:15Z",
          "mergedAt": "2026-07-07T11:15:34Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 797,
          "url": "https://github.com/kungfu-systems/buildchain/pull/797",
          "title": "chore(release): sync alpha state after frozen evidence fix",
          "body": "Sync alpha/v2/v2.8 back into dev/v2/v2.8 after the frozen alpha evidence fix landed on dev.\n\nThis preserves alpha ancestry and aligns the dev version-state/site facts with the current alpha state before the next dev -> alpha promotion.\n\nValidation:\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:14:07Z",
          "mergedAt": "2026-07-07T11:16:10Z",
          "additions": 5,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 798,
          "url": "https://github.com/kungfu-systems/buildchain/pull/798",
          "title": "Promote frozen alpha evidence fix to alpha",
          "body": "Promote the stable release frozen alpha evidence fix from dev/v2/v2.8 to alpha/v2/v2.8.\n\nIncludes #796 and the alpha/dev ancestry sync #797.\n\nExpected behavior: alpha promotion should use normal Buildchain release semantics and prepare the next alpha version state without a heavy native rebuild outside the fixture checks.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:16:36Z",
          "mergedAt": "2026-07-07T11:18:52Z",
          "additions": 220,
          "deletions": 67,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 800,
          "url": "https://github.com/kungfu-systems/buildchain/pull/800",
          "title": "chore(release): record release ancestry after frozen evidence fix",
          "body": "Record release/v2/v2.8 as an ancestor of alpha/v2/v2.8 after the frozen alpha evidence fix, without changing the alpha tree.\n\nThis makes the stable promotion PR mergeable while keeping alpha package content unchanged.\n\nValidation:\n- tree diff vs origin/alpha/v2/v2.8 is empty",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:24:41Z",
          "mergedAt": "2026-07-07T11:26:52Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 799,
          "url": "https://github.com/kungfu-systems/buildchain/pull/799",
          "title": "Promote Buildchain v2.8.10 stable",
          "body": "Promote Buildchain v2.8.10 stable after the frozen alpha evidence release finalization fix.\n\nAlpha evidence currently published as @kungfu-tech/buildchain@2.8.10-alpha.2.\n\nExpected behavior: stable promotion should bind to the frozen alpha PR evidence and should not be confused by earlier same-patch alpha tags.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:23:18Z",
          "mergedAt": "2026-07-07T11:32:09Z",
          "additions": 227,
          "deletions": 68,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 355,
          "url": "https://github.com/kungfu-systems/kungfu/pull/355",
          "title": "ci: rename windows frozen cli executable",
          "body": "Fix the Windows artifact build failure seen in alpha PR #354.\n\nWindows Nuitka successfully produced `framework/core/build/kungfu-nuitka/kungfu_cli.dist/kungfu_cli.exe`, but `run-freeze.js` accidentally looked for `kungfu.exe` and renamed it to itself. The artifact build then failed because `framework/core/dist/kungfu/kungfu.exe` was never created.\n\nThis PR renames `kungfu_cli.exe` to `kungfu.exe` on Windows, matching the existing comment and the artifact/runtime expectation.\n\nValidation:\n- `node --check framework/core/.gyp/run-freeze.js`\n- `./kungfu-code exec biome check framework/core/.gyp/run-freeze.js`\n- `./kungfu-code run check:types`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:37:35Z",
          "mergedAt": "2026-07-07T11:38:14Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 802,
          "url": "https://github.com/kungfu-systems/buildchain/pull/802",
          "title": "fix(release): merge generated next-alpha into diverged dev",
          "body": "## Summary\n- create a generated merge commit when release finalization needs to sync next-alpha state into a diverged dev branch\n- restrict that merge to verified generated version-state file differences\n- add regression coverage for the non-fast-forward dev finalization path\n\n## Verification\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:40:48Z",
          "mergedAt": "2026-07-07T11:43:13Z",
          "additions": 258,
          "deletions": 60,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 803,
          "url": "https://github.com/kungfu-systems/buildchain/pull/803",
          "title": "chore(release): sync alpha state after dev finalization fix",
          "body": "## Summary\n- merge current alpha/v2/v2.8 state back into dev/v2/v2.8 after the release finalization fix\n- preserve the #802 dev fix while aligning generated version/site state to v2.8.11-alpha.0\n\n## Verification\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:45:38Z",
          "mergedAt": "2026-07-07T11:48:00Z",
          "additions": 5,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 804,
          "url": "https://github.com/kungfu-systems/buildchain/pull/804",
          "title": "Promote dev finalization fix to alpha",
          "body": "## Summary\n- promote the release finalization dev-merge fix to alpha\n- carries the synced v2.8.11-alpha.0 state forward so the promotion can publish the next alpha with the fix\n\n## Verification\n- dev/v2/v2.8 Verify is running from the merged sync head\n- PR checks must pass before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:48:26Z",
          "mergedAt": "2026-07-07T11:50:53Z",
          "additions": 262,
          "deletions": 70,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 806,
          "url": "https://github.com/kungfu-systems/buildchain/pull/806",
          "title": "chore(release): record release ancestry after v2.8.11 alpha",
          "body": "## Summary\n- record release/v2/v2.8 ancestry on alpha/v2/v2.8 without changing the alpha tree\n- uses a policy-compliant generated version-state branch suffix\n\n## Verification\n- git diff origin/alpha/v2/v2.8..44e085aa731f161b9487da1bf4c7aae50cbfb9f8 is empty\n- release/v2/v2.8 is an ancestor of 44e085aa731f161b9487da1bf4c7aae50cbfb9f8",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:59:19Z",
          "mergedAt": "2026-07-07T12:01:18Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 67,
          "url": "https://github.com/kungfu-systems/libnode/pull/67",
          "title": "release(alpha): publish 22.22.3-kf.3-alpha.13",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 after fixing the Release - New Version caller permissions required by Buildchain v2 promotion.\n\nThis is still @kungfu-tech/libnode 22.22.3-kf.3-alpha.13. The extra PR/build is caused by the previous alpha push failing at GitHub workflow startup because the caller workflow lacked checks: write for the Buildchain promote reusable workflow.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:15:57Z",
          "mergedAt": "2026-07-07T12:01:47Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 62,
          "url": "https://github.com/kungfu-systems/libnode/pull/62",
          "title": "Prepare v22.22.1-alpha.5",
          "body": "Create the generated version-state commit for v22.22.1-alpha.5.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T03:35:33Z",
          "mergedAt": "2026-07-07T12:03:33Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 807,
          "url": "https://github.com/kungfu-systems/buildchain/pull/807",
          "title": "Promote Buildchain v2.8.11 stable",
          "body": "Promote Buildchain v2.8.11 stable with release finalization recovery for diverged dev next-alpha bookkeeping.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:02:49Z",
          "mergedAt": "2026-07-07T12:06:12Z",
          "additions": 269,
          "deletions": 71,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 357,
          "url": "https://github.com/kungfu-systems/kungfu/pull/357",
          "title": "ci: run buildchain windows lifecycle on pinned node",
          "body": "## Summary\n- run Windows Buildchain lifecycle pnpm commands through `fnm exec` when available\n- keep fallback to `corepack.cmd pnpm` for environments without fnm\n\n## Why\nWindows Buildchain was invoking pnpm with the Actions runtime Node, so `scripts/verify.mjs` failed the pinned `.node-version` check even though the artifact build had completed.\n\n## Verification\n- `node --check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code run check:types`\n- `git diff --check`\n- DARKHERO smoke: `fnm exec -- node -p process.version` -> `v22.22.3`; `fnm exec -- corepack.cmd pnpm --version` -> `11.7.0`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:15:03Z",
          "mergedAt": "2026-07-07T12:15:40Z",
          "additions": 25,
          "deletions": 6,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 810,
          "url": "https://github.com/kungfu-systems/buildchain/pull/810",
          "title": "fix(release): compare generated version-state trees",
          "body": "Fix release finalization after stable publish by validating generated version-state updates with final tree snapshots instead of PR-style compare history. This prevents already-equivalent code changes from blocking the dev next-alpha bookkeeping merge after protected branches diverge.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:14:59Z",
          "mergedAt": "2026-07-07T12:17:01Z",
          "additions": 169,
          "deletions": 81,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 811,
          "url": "https://github.com/kungfu-systems/buildchain/pull/811",
          "title": "chore(release): sync alpha state after tree-diff fix",
          "body": "Sync the generated alpha/release version-state back into dev after the v2.8.11 post-publish finalization failure, while preserving the tree-diff finalization fix already merged to dev.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:19:48Z",
          "mergedAt": "2026-07-07T12:21:49Z",
          "additions": 15,
          "deletions": 9,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 812,
          "url": "https://github.com/kungfu-systems/buildchain/pull/812",
          "title": "Promote tree-diff release finalization fix to alpha",
          "body": "Promote the release finalization tree-diff fix to alpha after syncing the v2.8.12 alpha state back into dev.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:23:30Z",
          "mergedAt": "2026-07-07T12:25:17Z",
          "additions": 169,
          "deletions": 81,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 69,
          "url": "https://github.com/kungfu-systems/libnode/pull/69",
          "title": "ci(release): refresh KFD workflow witness hash",
          "body": "Refresh the KFD-1 release-workflow surface digest after adding checks: write to Release - New Version.\n\nThe previous alpha promote reached KFD-1 finalization and failed because the release workflow byte-for-byte digest in .buildchain/kfd-1/libnode-contract-world.witness.json still pointed at the pre-permission-fix workflow content.\n\nThis PR only updates the KFD-1 witness hash; it does not change package payload files or the libnode version.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:07:19Z",
          "mergedAt": "2026-07-07T12:25:35Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 359,
          "url": "https://github.com/kungfu-systems/kungfu/pull/359",
          "title": "chore: merge applicable feature backlog",
          "body": "## Summary\n- add the KFD-2 release claims registry and generator\n- carry forward the KFD-3 collaboration-interface design docs\n- add runner smoke workflows for the three self-hosted hosts and v4 labels\n- keep boto3 out of the frozen runtime exclusion path\n\n## Notes\n- older agent onboarding, fact bridge, and kfx distribution feature branches are already covered by the current dev/v4 implementation, so their stale patches were not reapplied\n- v2.4 release-verify runner patches were not applied because dev/v4 delegates product builds to the Buildchain workflow preset\n\n## Verification\n- node scripts/kfd2-release-claims.mjs --check\n- node --check scripts/kfd2-release-claims.mjs\n- node --check scripts/verify.mjs\n- node --check scripts/no-bash-guard.mjs\n- python3 -m py_compile framework/core/src/python/kungfu/yijinjing/journal.py framework/core/src/python/kungfu_cli.py\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:29:36Z",
          "mergedAt": "2026-07-07T12:30:37Z",
          "additions": 1337,
          "deletions": 15,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 813,
          "url": "https://github.com/kungfu-systems/buildchain/pull/813",
          "title": "chore(release): record release ancestry after v2.8.12 alpha",
          "body": "Record release/v2/v2.8 ancestry on alpha/v2/v2.8 before stable promotion, without changing the alpha tree.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:29:35Z",
          "mergedAt": "2026-07-07T12:31:14Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 360,
          "url": "https://github.com/kungfu-systems/kungfu/pull/360",
          "title": "ci: tolerate windows uv mountpoint mypy probe",
          "body": "## Summary\n- keep running the mypy probe in `verify`\n- on Windows only, skip that probe when uv fails interpreter discovery with `os error 448`\n- preserve failure for all other mypy/uv errors\n\n## Why\nAfter the Windows lifecycle was moved onto the repo-pinned Node, the remaining Windows verify failure is uv interpreter discovery hitting a runner mount-point error, not a type-check failure. Linux/macOS continue to gate mypy normally.\n\n## Verification\n- `node --check scripts/verify.mjs`\n- `./kungfu-code exec biome check scripts/verify.mjs`\n- `./kungfu-code run check:types`\n- `git diff --check`\n- DARKHERO rerun evidence before this patch: pinned Node passed; only `python type check` failed with `os error 448`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:33:21Z",
          "mergedAt": "2026-07-07T12:33:59Z",
          "additions": 17,
          "deletions": 6,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 814,
          "url": "https://github.com/kungfu-systems/buildchain/pull/814",
          "title": "Promote Buildchain v2.8.12 stable",
          "body": "Promote Buildchain v2.8.12 stable with the release finalization tree-diff fix.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:32:36Z",
          "mergedAt": "2026-07-07T12:36:24Z",
          "additions": 180,
          "deletions": 92,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 71,
          "url": "https://github.com/kungfu-systems/libnode/pull/71",
          "title": "release(alpha): publish 22.22.3-kf.3-alpha.13",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 after refreshing the KFD-1 release-workflow witness hash.\n\nThis is still @kungfu-tech/libnode 22.22.3-kf.3-alpha.13. The previous promote reached KFD-1 finalization and failed because the release workflow digest in the KFD-1 witness still pointed at the pre-checks-permission workflow content.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:26:01Z",
          "mergedAt": "2026-07-07T12:47:05Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 815,
          "url": "https://github.com/kungfu-systems/buildchain/pull/815",
          "title": "fix(release): preserve release ancestry in next alpha",
          "body": "Make release finalization prepare next-alpha from the finalized release commit and automatically create a generated alpha merge when protected alpha cannot fast-forward. This prevents the next stable release from needing a manual ancestry repair PR after every release.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:44:18Z",
          "mergedAt": "2026-07-07T12:47:25Z",
          "additions": 188,
          "deletions": 64,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 817,
          "url": "https://github.com/kungfu-systems/buildchain/pull/817",
          "title": "Promote next-alpha ancestry fix to alpha",
          "body": "Promote the release finalization next-alpha ancestry fix to alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:48:29Z",
          "mergedAt": "2026-07-07T12:50:30Z",
          "additions": 188,
          "deletions": 64,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 819,
          "url": "https://github.com/kungfu-systems/buildchain/pull/819",
          "title": "chore(release): record release ancestry after v2.8.13 alpha",
          "body": "Record release/v2/v2.8 ancestry on alpha/v2/v2.8 before stable promotion, without changing the alpha tree.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:56:29Z",
          "mergedAt": "2026-07-07T13:00:38Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 362,
          "url": "https://github.com/kungfu-systems/kungfu/pull/362",
          "title": "ci: force windows lifecycle scripts onto pinned node",
          "body": "## Summary\\n- resolve the fnm-pinned Windows node executable before running pnpm\\n- prepend a temporary node.cmd shim so pnpm lifecycle scripts inherit Node 22\\n- export npm_node_execpath/NODE for child tooling\\n\\n## Validation\\n- node --check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code run check:types\\n- git diff --check\\n- DARKHERO targeted smoke: node and corepack.cmd pnpm exec node both report v22.22.3\\n- DARKHERO targeted verify: corepack.cmd pnpm run verify passes 22/22 with node version pinned v22.22.3",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:01:09Z",
          "mergedAt": "2026-07-07T13:01:46Z",
          "additions": 56,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 820,
          "url": "https://github.com/kungfu-systems/buildchain/pull/820",
          "title": "Promote Buildchain v2.8.13 stable",
          "body": "Promote Buildchain v2.8.13 stable with next-alpha release ancestry preservation and custom KFD badges.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:04:19Z",
          "mergedAt": "2026-07-07T13:06:29Z",
          "additions": 199,
          "deletions": 75,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 74,
          "url": "https://github.com/kungfu-systems/libnode/pull/74",
          "title": "chore(release): bump libnode alpha to 14",
          "body": "Bump @kungfu-tech/libnode to 22.22.3-kf.3-alpha.14 after the alpha.13 promote partially published npm packages but failed before GitHub Release/passport finalization due to release transaction identity mismatch.\n\nThis updates:\n- package.json version\n- libnode.release.json npmVersion\n- KFD-3 prebuild sourceRegistry version\n- KFD-1 source surface hashes for package/release/prebuild witness\n\nLocal checks:\n- corepack pnpm verify-release\n- JSON parse for KFD declarations\n- KFD-1 source hash consistency check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:50:29Z",
          "mergedAt": "2026-07-07T13:09:41Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 822,
          "url": "https://github.com/kungfu-systems/buildchain/pull/822",
          "title": "fix(release): skip release assets for prepare-only alpha tags",
          "body": "Allow Binary Distribution to pass for prepare-only next-alpha tags when no durable release-state exists, while keeping stable and published prerelease tags fail-closed.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:13:37Z",
          "mergedAt": "2026-07-07T13:15:41Z",
          "additions": 12,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 823,
          "url": "https://github.com/kungfu-systems/buildchain/pull/823",
          "title": "Promote prepare-only alpha binary fix to alpha",
          "body": "Promote the Binary Distribution prepare-only next-alpha release-state handling fix to alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:17:08Z",
          "mergedAt": "2026-07-07T13:19:11Z",
          "additions": 12,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 364,
          "url": "https://github.com/kungfu-systems/kungfu/pull/364",
          "title": "ci: run windows pnpm with pinned node",
          "body": "## Summary\\n- run Windows pnpm through the Corepack JS owned by the fnm-pinned Node installation\\n- keep the temporary node.cmd shim so pnpm lifecycle scripts also resolve node to the pinned runtime\\n- avoid Actions setup-node 24 leaking into process.execPath for artifact packaging\\n\\n## Validation\\n- node --check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code run check:types\\n- git diff --check\\n- DARKHERO mechanism smoke: pinned node runs Corepack JS and pnpm lifecycle script process.execPath resolves to v22.22.3",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:24:15Z",
          "mergedAt": "2026-07-07T13:25:02Z",
          "additions": 22,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 824,
          "url": "https://github.com/kungfu-systems/buildchain/pull/824",
          "title": "Promote Buildchain v2.8.14 stable",
          "body": "Promote Buildchain v2.8.14 stable with prepare-only next-alpha binary distribution handling and custom KFD badges.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:24:38Z",
          "mergedAt": "2026-07-07T13:26:42Z",
          "additions": 23,
          "deletions": 12,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 826,
          "url": "https://github.com/kungfu-systems/buildchain/pull/826",
          "title": "fix(release): skip prepare-only promotion runs",
          "body": "Skip Buildchain Ref Promotion for finalizer generated Prepare v* next-alpha commits so prepare-only dev/alpha Verify runs do not attempt to resolve PR-stage RC evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:34:04Z",
          "mergedAt": "2026-07-07T13:36:27Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 76,
          "url": "https://github.com/kungfu-systems/libnode/pull/76",
          "title": "release(alpha): publish 22.22.3-kf.3-alpha.14",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 for @kungfu-tech/libnode 22.22.3-kf.3-alpha.14.\n\nThis supersedes alpha.13, which reached npm but failed before GitHub Release/passport finalization because Buildchain selected stale release material and then failed release transaction identity verification after publish.\n\nThis candidate includes refreshed KFD-1 hashes for the alpha.14 package/release/prebuild witness surfaces.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:10:06Z",
          "mergedAt": "2026-07-07T13:40:44Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 827,
          "url": "https://github.com/kungfu-systems/buildchain/pull/827",
          "title": "Promote prepare-only promotion skip to alpha",
          "body": "Promote the Buildchain Ref Promotion prepare-only next-alpha skip fix to alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:39:16Z",
          "mergedAt": "2026-07-07T13:41:24Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 366,
          "url": "https://github.com/kungfu-systems/kungfu/pull/366",
          "title": "ci: install windows pinned node in buildchain workspace",
          "body": "## Summary\\n- set Windows FNM_DIR to .buildchain/fnm so Buildchain lifecycle installs Node under the checkout\\n- scan .node-version-based fnm installs across the workspace and Windows users\\n- fail fast on Windows when pinned Node cannot be resolved instead of drifting to Actions Node 24\\n\\n## Validation\\n- node --check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code run check:types\\n- git diff --check\\n- DARKHERO smoke: FNM_DIR=.buildchain/fnm fnm install resolves v22.22.3 under the checkout",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:41:55Z",
          "mergedAt": "2026-07-07T13:42:46Z",
          "additions": 91,
          "deletions": 5,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 828,
          "url": "https://github.com/kungfu-systems/buildchain/pull/828",
          "title": "Promote Buildchain v2.8.15 stable",
          "body": "Promote Buildchain v2.8.15 stable with prepare-only promotion skip and custom KFD badges.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:46:32Z",
          "mergedAt": "2026-07-07T13:48:40Z",
          "additions": 12,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 368,
          "url": "https://github.com/kungfu-systems/kungfu/pull/368",
          "title": "ci: bootstrap windows pinned node without fnm",
          "body": "## Summary\\n- fall back to downloading the .node-version Windows Node zip into .buildchain/node when fnm is unavailable\\n- keep Windows lifecycle fail-fast if pinned Node still cannot be resolved\\n- continue running pnpm through the pinned Node Corepack JS to avoid Actions Node 24 drift\\n\\n## Validation\\n- node --check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code run check:types\\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T14:01:00Z",
          "mergedAt": "2026-07-07T14:01:36Z",
          "additions": 61,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 1,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/1",
          "title": "feat(tap): track buildchain release passport",
          "body": "## Summary\n\n- Add the public Homebrew tap repository document set.\n- Add Formula/buildchain.rb for Buildchain v2.8.15, bound to upstream release-passport digests.\n- Add tap-manifest.json plus a Buildchain lifecycle verify check to detect formula/passport drift.\n\n## Checks\n\n- node scripts/check-tap.mjs\n- git diff --check\n- ruby -c Formula/buildchain.rb\n- buildchain validate --require-lifecycle-stages verify\n- buildchain lifecycle run verify --required\n\n## Governance\n\n- Does not include credentials, tokens, secrets, or private logs.\n- Touches release evidence/provenance surfaces by adding a Homebrew distribution index bound to upstream release passports.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T14:46:31Z",
          "mergedAt": "2026-07-07T14:47:11Z",
          "additions": 650,
          "deletions": 2,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 829,
          "url": "https://github.com/kungfu-systems/buildchain/pull/829",
          "title": "feat(readme): generate badge facts and blocks",
          "body": "## Summary\n- add @kungfu-tech/buildchain/readme-badges Node API for machine-readable README badge facts, deterministic Markdown rendering, drift checks, and marker-block updates\n- add buildchain badges readme --json/--check/--write CLI and dogfood Buildchain README badges from buildchain.toml plus verified release passport facts\n- document the badge contract and publish it through Buildchain KFD/site registries\n- follow GitHub latest/download redirects when reading release passport JSON\n\n## Verification\n- node bin/buildchain.mjs badges readme --cwd . --check --json\n- node --test tests/readme-badges.test.mjs tests/release-passport.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T14:43:59Z",
          "mergedAt": "2026-07-07T14:48:56Z",
          "additions": 1354,
          "deletions": 107,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 830,
          "url": "https://github.com/kungfu-systems/buildchain/pull/830",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "## Summary\nPromote dev/v2/v2.8 to alpha/v2/v2.8 after README badge facts/block support landed.\n\n## Dry run\n```\n{\n  \"schemaVersion\": 1,\n  \"dryRun\": true,\n  \"cwd\": \"/Users/dkr/Worktrees/buildchain/feature/readme-badge-block\",\n  \"targetRef\": \"alpha/v2/v2.8\",\n  \"source\": {\n    \"expectedHeadRef\": \"dev/v2/v2.8\",\n    \"sha\": \"6f0e18e70901d264af976d30664c21f687a60fbe\"\n  },\n  \"channel\": \"alpha\",\n  \"line\": \"v2.8\",\n  \"exactTags\": [\n    {\n      \"tag\": \"next v2.8.Z-alpha.N\",\n      \"kind\": \"alpha\",\n      \"action\": \"would create or reuse immutable alpha evidence tag\"\n    }\n  ],\n  \"floatingRefs\": [\n    {\n      \"ref\": \"v2.8-alpha\",\n      \"kind\": \"tag\",\n      \"action\": \"would move to alpha version-state commit\"\n    }\n  ],\n  \"branchUpdates\": [\n    {\n      \"ref\": \"alpha/v2/v2.8\",\n      \"action\": \"would move to alpha version-state commit\"\n    },\n    {\n      \"ref\": \"dev/v2/v2.8\",\n      \"action\": \"would align dev with the published alpha state\"\n    }\n  ],\n  \"versionState\": {\n    \"manager\": \"buildchain.toml\",\n    \"files\": [\n      \"package.json\",\n      \"dist/site/buildchain-contract.json\",\n      \"dist/site/buildchain-site.json\",\n      \"dist/site/site-manifest.json\"\n    ],\n    \"reason\": \"configured-version-files\",\n    \"strategy\": \"semver\",\n    \"next\": \"auto\",\n    \"anchorManifest\": \"\",\n    \"verification\": \"lifecycle.verify\",\n    \"targetVersions\": [\n      \"2.8.Z-alpha.N\"\n    ]\n  },\n  \"governanceChecks\": [\n    \"target branch protection must be readable\",\n    \"branch protection must enforce administrators\",\n    \"required pull request review must be enabled\",\n    \"strict required status check must include the check job\",\n    \"source PR must be a merged same-repository PR from dev/v2/v2.8 to alpha/v2/v2.8\"\n  ],\n  \"publishTransaction\": {\n    \"enabled\": true,\n    \"source\": \"lifecycle.publish\",\n    \"behavior\": \"would create or resume durable release transaction and require publish evidence before public refs move\"\n  },\n  \"notes\": [\n    \"Alpha promotion opens or advances the test channel; it does not move production refs.\"\n  ]\n}\n```",
          "author": "dongkeren",
          "createdAt": "2026-07-07T14:49:57Z",
          "mergedAt": "2026-07-07T14:52:10Z",
          "additions": 1354,
          "deletions": 107,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 2,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/2",
          "title": "ci(tap): lock Buildchain runtime contract",
          "body": "## Summary\n- add buildchain.contract-lock.json for the accepted Buildchain @v2 runtime contract\n- run tap verification through the Buildchain reusable workflow so the contract lock is checked before lifecycle work\n- keep local tap checks aware of the contract lock\n\n## Verification\n- node scripts/check-tap.mjs\n- Buildchain contract lock check against kungfu-systems/buildchain@v2\n- buildchain validate --require-lifecycle-stages verify\n- buildchain lifecycle run verify --required\n- workflow YAML parse check\n- git diff --check\n\n## Governance\n- No secrets, credentials, provider APIs, hosted services, package names, or release evidence surfaces beyond Buildchain runtime contract lock handling.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:10:02Z",
          "mergedAt": "2026-07-07T15:13:33Z",
          "additions": 147,
          "deletions": 15,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 832,
          "url": "https://github.com/kungfu-systems/buildchain/pull/832",
          "title": "feat(homebrew): support distribution index taps",
          "body": "## Summary\n- add first-class Homebrew tap distribution-index support\n- expose @kungfu-tech/buildchain/homebrew Node API and `buildchain homebrew` CLI\n- generate/check Formula/buildchain.rb and tap-manifest.json from upstream release-passport evidence\n- document and include Homebrew support in site/KFD inventories\n\n## Verification\n- git diff --check\n- node --test tests/homebrew.test.mjs tests/buildchain-config.test.mjs tests/release-passport.test.mjs\n- node scripts/generate-site-bundle.mjs --check\n- corepack pnpm@11.7.0 run check\n- dogfood on a temp copy of kungfu-systems/homebrew-tap against Buildchain v2.8.15 release passport: update-formula --write + check --json passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:15:21Z",
          "mergedAt": "2026-07-07T15:17:30Z",
          "additions": 1362,
          "deletions": 116,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 834,
          "url": "https://github.com/kungfu-systems/buildchain/pull/834",
          "title": "fix(web-surface): smoke nested preview routes",
          "body": "## Summary\n- sync each web-surface host from its own artifact path prefix when present\n- record surface path-prefix rewrite and directory-index routing evidence in deployment manifests\n- health-check preview/staging/production roots plus nested smoke URLs so child-page 403s fail closed\n\n## Verification\n- node --check scripts/web-surface-core.mjs && node --check scripts/web-surface.mjs\n- node scripts/generate-site-bundle.mjs --check\n- node scripts/check-inventory.mjs\n- env -u GITHUB_OUTPUT node --test tests/web-surface.test.mjs tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:26:58Z",
          "mergedAt": "2026-07-07T15:29:00Z",
          "additions": 344,
          "deletions": 29,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 833,
          "url": "https://github.com/kungfu-systems/buildchain/pull/833",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "## Summary\n- promote dev/v2/v2.8 into alpha/v2/v2.8\n- includes Homebrew tap distribution-index support\n\n## Verification\n- PR #832 checks passed before dev merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:17:54Z",
          "mergedAt": "2026-07-07T15:31:00Z",
          "additions": 1704,
          "deletions": 143,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 371,
          "url": "https://github.com/kungfu-systems/kungfu/pull/371",
          "title": "feat(product): isolate dev instance homes for worktrees",
          "body": "## Summary\n- add product dev instance-home handling for GUI and TUI launches\n- auto-select an isolated instance root for linked git worktrees\n- seed instance config from the machine default config once without overwriting test changes\n\n## Tests\n- node --test artifact/scripts/product.test.mjs\n- ./kungfu-code product gui dev --dry-run\n- ./kungfu-code product gui dev --no-instance-home --dry-run\n- ./kungfu-code product tui dev --dry-run\n- ./kungfu-code check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:33:06Z",
          "mergedAt": "2026-07-07T15:34:00Z",
          "additions": 493,
          "deletions": 44,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 835,
          "url": "https://github.com/kungfu-systems/buildchain/pull/835",
          "title": "release: promote Buildchain v2.8.16 stable",
          "body": "## Summary\n- promote Buildchain v2.8.16 stable from alpha/v2/v2.8\n- includes Homebrew distribution-index support\n- includes web-surface multi-surface preview prefix routing and nested smoke checks\n\n## Verification\n- alpha promotion succeeded: v2.8.16-alpha.2\n- npm alpha dist-tag points to 2.8.16-alpha.2\n- GitHub alpha release is prerelease and latest=false\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:35:29Z",
          "mergedAt": "2026-07-07T15:37:47Z",
          "additions": 2988,
          "deletions": 180,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 372,
          "url": "https://github.com/kungfu-systems/kungfu/pull/372",
          "title": "ci: upload only staged release artifacts",
          "body": "## Summary\n- stage top-level electron-builder outputs from artifact/dist into artifact/release\n- upload artifact/release in the Buildchain reusable build instead of the full artifact/dist tree\n- ignore generated artifact/release locally\n\n## Verification\n- node --check artifact/scripts/dist.mjs\n- ./kungfu-code check\n\n## Risk\n- The Buildchain action scans concrete paths, not glob expressions, so this keeps a directory target while excluding unpacked app directories generated under artifact/dist.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:38:56Z",
          "mergedAt": "2026-07-07T15:41:26Z",
          "additions": 46,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 3,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/3",
          "title": "feat(tap): add tap-local KFD claims",
          "body": "## Summary\n- add tap-local KFD-1, KFD-2, and KFD-3 claim/witness files under kfd/\n- add a witness generator and extend tap verification to reject stale hashes and undeclared control surfaces\n- include KFD artifacts in the Buildchain Tap Check artifact contract\n\n## Verification\n- node scripts/update-kfd-witnesses.mjs\n- node scripts/check-tap.mjs\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs validate --require-lifecycle-stages verify\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs lifecycle run verify --required --artifact-path tap-manifest.json --artifact-path buildchain.contract-lock.json --artifact-path Formula --artifact-path docs --artifact-path kfd --artifact-name homebrew-tap-check --expected-artifacts-json '{\"requiredPaths\":[\"tap-manifest.json\",\"buildchain.contract-lock.json\",\"Formula/buildchain.rb\",\"docs/MAP.md\",\"kfd/kfd-1.witness.json\",\"kfd/kfd-2.release-claims.json\",\"kfd/kfd-3.witness.json\"]}'\n- python3 workflow YAML parse for buildchain-validate.yml and tap-check.yml\n- git diff --check\n\n## Governance\n- No credentials, tokens, secrets, private logs, provider APIs, hosted services, package names, or branding changes.\n- Touches release evidence/provenance surfaces by adding tap-local KFD claims and Buildchain artifact expectations.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:40:39Z",
          "mergedAt": "2026-07-07T15:45:04Z",
          "additions": 1612,
          "deletions": 6,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 373,
          "url": "https://github.com/kungfu-systems/kungfu/pull/373",
          "title": "docs(storage): plan runtime storage service",
          "body": "## Summary\n- add a draft runtime storage service design covering fsck, import/export, GC, compact, and projection rebuild\n- link the design from the documentation map\n- document current storage-service limits in known limits\n\n## Validation\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T16:08:18Z",
          "mergedAt": "2026-07-07T16:09:08Z",
          "additions": 268,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 374,
          "url": "https://github.com/kungfu-systems/kungfu/pull/374",
          "title": "ci: remove retired GitHub workflows",
          "body": "## Summary\n- remove retired runner smoke, release handoff, and legacy bump workflows\n- update version/release design pointers to the active Buildchain workflows\n- refresh the verify version-source comment after the release workflow migration\n\n## Validation\n- actionlint .github/workflows/*.yml\n- ./kungfu-code check\n- rg retired workflow names",
          "author": "dongkeren",
          "createdAt": "2026-07-07T16:14:44Z",
          "mergedAt": "2026-07-07T16:15:38Z",
          "additions": 10,
          "deletions": 321,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 836,
          "url": "https://github.com/kungfu-systems/buildchain/pull/836",
          "title": "feat(build): add locked source checkout cache",
          "body": "## Summary\n- add a locked source checkout helper for reusable build jobs with off/auto/require cache modes\n- support trusted mirror URL templates and runner-local reference repository templates with GitHub fallback\n- verify final HEAD and source tree SHA, then record sanitized checkout cache evidence in platform diagnostics\n- dogfood the fallback path in the Build Surface Fixture workflow\n\n## Validation\n- pnpm run check\n- node --test tests/locked-source-checkout.test.mjs\n- node --test tests/build-surface.test.mjs\n- pnpm run check:workflows\n\n## Notes\n- Cache configuration stays in trusted workflow inputs or repo/org variables; it is not read from PR-controlled files.\n- The cache only changes Git object transport. The buildable source remains the resolved publish-source-sha.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T16:14:07Z",
          "mergedAt": "2026-07-07T16:22:30Z",
          "additions": 742,
          "deletions": 60,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 375,
          "url": "https://github.com/kungfu-systems/kungfu/pull/375",
          "title": "feat(atlas): add storage fsck and export",
          "body": "## Summary\n- store complete Atlas source JSON payloads as hash-addressed import payloads alongside the existing Atlas journal projection\n- add Atlas-scoped storage status/fsck/export commands plus atlas verify against the source repo\n- keep build:core dist staging self-contained by copying kungfubuildinfo.json\n\n## Validation\n- PYTHONPATH=framework/core/src/python uv run --project framework/core --frozen pytest framework/core/tests/python/test_atlas_storage.py\n- uv run --project framework/core --frozen ruff check framework/core/src/python/kungfu/atlas/importer.py framework/core/src/python/kungfu/atlas/store.py framework/core/src/python/kungfu/atlas/payloads.py framework/core/src/python/kungfu/cli/commands/atlas.py framework/core/src/python/kungfu/cli/commands/storage.py framework/core/src/python/kungfu/cli/commands/__registry__.py framework/core/tests/python/test_atlas_storage.py\n- uv run --project framework/core --frozen ruff format --check framework/core/src/python/kungfu/atlas/importer.py framework/core/src/python/kungfu/atlas/store.py framework/core/src/python/kungfu/atlas/payloads.py framework/core/src/python/kungfu/cli/commands/atlas.py framework/core/src/python/kungfu/cli/commands/storage.py framework/core/src/python/kungfu/cli/commands/__registry__.py framework/core/tests/python/test_atlas_storage.py\n- ./kungfu-code build:core\n- ./kungfu-code check\n- Atlas dataset smoke with temporary KF_HOME/KF_RUNTIME_DIR: import 5 missions, 371 goals, 895 markers, 1271 payloads; storage fsck ok; export 1271 JSONL records; atlas verify ok\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T16:34:21Z",
          "mergedAt": "2026-07-07T16:34:52Z",
          "additions": 840,
          "deletions": 29,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 837,
          "url": "https://github.com/kungfu-systems/buildchain/pull/837",
          "title": "fix(readme): derive KFD badges from KFD standards",
          "body": "## Summary\n- derive KFD README badge vocabulary from @kungfu-tech/kfd standards metadata\n- render the repository-owned Buildchain Release Passport badge for the consumer repo passport capability\n- regenerate Buildchain README and site bundle\n\n## Validation\n- node --test tests/readme-badges.test.mjs\n- node scripts/check-inventory.mjs\n- node bin/buildchain.mjs badges readme --check --json\n- pnpm run generate:site\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T23:39:03Z",
          "mergedAt": "2026-07-07T23:40:58Z",
          "additions": 295,
          "deletions": 32,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 376,
          "url": "https://github.com/kungfu-systems/kungfu/pull/376",
          "title": "feat(storage): add atlas source sync",
          "body": "## Summary\n- add `kungfu source` commands for registering and syncing read-only Atlas storage sources\n- preserve source id, source type, source head, source time, and range metadata in Atlas payload manifests\n- add range-aware Atlas import/verify and storage export compatibility paths\n- keep parent mission context when a ranged sync selects recent goals\n\n## Validation\n- `PYTHONPATH=/Users/dkr/Worktrees/kungfu/feature/storage-source-adapter/framework/core/src/python pnpm --filter @kungfu-tech/core exec uv run --frozen pytest tests/python/test_atlas_storage.py`\n- `./kungfu-code check`\n- `./kungfu-code build`\n- `pnpm --filter @kungfu-tech/core run freeze`\n- real Atlas smoke with `framework/core/dist/kungfu/kungfu source add/sync/fsck`, `storage fsck`, and `storage export --since 3d` against `/Users/dkr/Code/atlas`",
          "author": "dongkeren",
          "createdAt": "2026-07-07T23:48:38Z",
          "mergedAt": "2026-07-07T23:49:15Z",
          "additions": 722,
          "deletions": 17,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 838,
          "url": "https://github.com/kungfu-systems/buildchain/pull/838",
          "title": "feat(readme): add hosted Buildchain badge endpoints",
          "body": "## Summary\n- generate stable Buildchain-hosted README badge image URLs for KFD and Buildchain Release Passport badges\n- publish badge endpoint registry and Shields-compatible payloads in the Buildchain site bundle for site-libkungfu-dev to render\n- keep future logo replacement endpoint-owned so consumers do not need to rerun badge generation\n- make web-surface nested smoke URLs required only when nested HTML exists\n\n## Validation\n- node --test tests/readme-badges.test.mjs\n- node --test tests/web-surface.test.mjs\n- node scripts/check-inventory.mjs\n- node bin/buildchain.mjs badges readme --check --json\n- pnpm run generate:site\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:02:55Z",
          "mergedAt": "2026-07-08T00:06:15Z",
          "additions": 1335,
          "deletions": 61,
          "changedFiles": 51
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 839,
          "url": "https://github.com/kungfu-systems/buildchain/pull/839",
          "title": "chore(release): promote v2.8 alpha",
          "body": "Promote dev/v2/v2.8 to alpha/v2/v2.8 for the next Buildchain v2.8 alpha publication.\n\nThis promotion includes:\n- locked source checkout cache\n- KFD README badge derivation\n- hosted Buildchain badge endpoints\n- web-surface nested smoke behavior for surfaces without nested HTML\n\nBuildchain Ref Promotion will publish the alpha after the alpha branch Verify workflow succeeds.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:07:37Z",
          "mergedAt": "2026-07-08T00:09:23Z",
          "additions": 2343,
          "deletions": 124,
          "changedFiles": 61
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 841,
          "url": "https://github.com/kungfu-systems/buildchain/pull/841",
          "title": "chore(release): sync v2.8 alpha state to dev",
          "body": "Sync the generated v2.8.17-alpha.1 version-state commit back into dev/v2/v2.8.\n\nThis branch contains an explicit merge commit with:\n- first parent: dev/v2/v2.8 at a301e0b\n- second parent: alpha/v2/v2.8 at 81e6bc9\n\nThe resolved tree only changes the generated version/site manifest facts:\n- package.json\n- dist/site/buildchain-contract.json\n- dist/site/buildchain-site.json\n- dist/site/site-manifest.json\n\nValidation:\n- node scripts/check-inventory.mjs\n- pnpm run check:site",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:16:08Z",
          "mergedAt": "2026-07-08T00:18:17Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 842,
          "url": "https://github.com/kungfu-systems/buildchain/pull/842",
          "title": "release: promote Buildchain v2.8.17 stable",
          "body": "Promote the tested v2.8 alpha channel to the stable v2.8 release channel.\n\nSource:\n- alpha/v2/v2.8 at v2.8.17-alpha.1\n\nExpected Buildchain promotion behavior after merge:\n- publish @kungfu-tech/buildchain@2.8.17 to npm latest\n- create/update GitHub Release v2.8.17\n- keep v2/v2.8 floating refs on the stable release\n- prepare the next alpha state for the v2.8 line",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:21:23Z",
          "mergedAt": "2026-07-08T00:23:09Z",
          "additions": 2353,
          "deletions": 134,
          "changedFiles": 62
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 380,
          "url": "https://github.com/kungfu-systems/kungfu/pull/380",
          "title": "docs(storage): describe runtime source sync model",
          "body": "Merge feature/storage-design-consensus into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:20:12Z",
          "mergedAt": "2026-07-08T00:25:56Z",
          "additions": 153,
          "deletions": 53,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 381,
          "url": "https://github.com/kungfu-systems/kungfu/pull/381",
          "title": "docs(storage): record storage architecture ADRs",
          "body": "## Summary\n- add ADR-0018 for the runtime storage service architecture\n- add ADR-0019 for Git-like source sync over location/channel\n- link the runtime storage service reference page to both ADRs\n\n## Validation\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:32:41Z",
          "mergedAt": "2026-07-08T00:33:33Z",
          "additions": 326,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 382,
          "url": "https://github.com/kungfu-systems/kungfu/pull/382",
          "title": "docs(rewind): record action timeline ADR",
          "body": "## Summary\n- add ADR-0020 for the agent action timeline and rewind/replay boundary\n- link event-model, Rewind docs, and the documentation map to the ADR\n\n## Validation\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:46:17Z",
          "mergedAt": "2026-07-08T00:47:07Z",
          "additions": 168,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 843,
          "url": "https://github.com/kungfu-systems/buildchain/pull/843",
          "title": "feat(badges): add trust badge bundle entrypoint",
          "body": "## Summary\n- add a first-class `@kungfu-tech/buildchain/badges` public subpath for badge bundle and README badge APIs\n- add `buildchain badges bundle` for KFD-1/KFD-2/KFD-3/Release Passport trust badge bundles with machine-readable facts\n- document bundle configuration and update generated site facts\n\n## Validation\n- `node --test tests/readme-badges.test.mjs`\n- `node bin/buildchain.mjs badges bundle --claims nope --json` fails closed on unknown claims\n- `pnpm run generate:site`\n- `pnpm run check`",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:55:23Z",
          "mergedAt": "2026-07-08T00:57:48Z",
          "additions": 453,
          "deletions": 67,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 383,
          "url": "https://github.com/kungfu-systems/kungfu/pull/383",
          "title": "docs(timeline): record observer-relative projection ADR",
          "body": "## Summary\n- add ADR-0021 for observer-relative timeline projection over causal facts\n- route multi-machine timeline questions through the docs map, event model, concepts, and ADR index\n- clarify that trust comes from reproducible facts plus projection policy, not a universal global clock\n\n## Validation\n- git diff --check\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T01:12:28Z",
          "mergedAt": "2026-07-08T01:13:10Z",
          "additions": 194,
          "deletions": 0,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 844,
          "url": "https://github.com/kungfu-systems/buildchain/pull/844",
          "title": "feat(build-facts): add module and product facts",
          "body": "## Summary\n\n- Add first-class Build Facts for Git source, version source, module output, product artifact, and legacy Kungfu buildinfo projection evidence.\n- Expose `@kungfu-tech/buildchain/build-facts`, root API exports, and `buildchain facts module|aggregate|verify`.\n- Let release passports carry build facts through `--build-facts-json`, and register the capability in docs plus the package-owned site bundle.\n- Dogfood Buildchain with declarative `[facts]` config for the core/site-bundle product facts.\n\n## Validation\n\n- `pnpm run check`\n- `node scripts/check-inventory.mjs`\n- `node --test tests/build-facts.test.mjs`\n- `pnpm run check:site`\n- `node bin/buildchain.mjs validate --cwd . --require-version-state --require-lifecycle-stages version-state,verify --json`\n- `node bin/buildchain.mjs facts module --module buildchain-core --output .buildchain/facts/buildchain-core.json --json`\n- `node bin/buildchain.mjs facts aggregate --product buildchain --module-fact .buildchain/facts/buildchain-core.json --output .buildchain/facts/buildchain.json --json`\n- `node bin/buildchain.mjs facts verify --fact .buildchain/facts/buildchain.json --json`",
          "author": "dongkeren",
          "createdAt": "2026-07-08T01:31:33Z",
          "mergedAt": "2026-07-08T01:33:26Z",
          "additions": 1482,
          "deletions": 47,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 384,
          "url": "https://github.com/kungfu-systems/kungfu/pull/384",
          "title": "feat(core): add language-neutral action recorder",
          "body": "Add a C++ action-recording surface in libkungfu, expose thin Python/Node bindings, and document the C++ ownership boundary for future polyglot runtime fact-ledger work.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T01:44:24Z",
          "mergedAt": "2026-07-08T01:46:49Z",
          "additions": 736,
          "deletions": 18,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 845,
          "url": "https://github.com/kungfu-systems/buildchain/pull/845",
          "title": "fix(web-surface): resolve surface root index routes",
          "body": "## Summary\n\n- write directory-index alias objects for web-surface S3 object prefixes during deploy apply\n- cover surface host roots and nested directory index routes such as `/` and `/docs/`\n- document the CloudFront/S3 REST-origin routing behavior and refresh the generated site bundle\n\n## Validation\n\n- `node --test tests/web-surface.test.mjs`\n- `pnpm run check:site`\n- `node scripts/check-inventory.mjs`\n- `pnpm run check:workflows`\n- `pnpm run test:unit`\n\n## Notes\n\nThis does not trigger any consumer repository deployment or heavy build.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T01:52:55Z",
          "mergedAt": "2026-07-08T01:54:49Z",
          "additions": 124,
          "deletions": 30,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 385,
          "url": "https://github.com/kungfu-systems/kungfu/pull/385",
          "title": "ci: lock buildchain contract",
          "body": "## Summary\n- add the Buildchain v2 contract lock accepted by Kungfu\n- wire the reusable build workflow to validate the lock before matrix builds\n- open drift issues for compatible and breaking contract drift\n\n## Validation\n- actionlint .github/workflows/build.yml .github/workflows/buildchain-validate.yml\n- buildchain-contract-lock.mjs check\n- git diff --check\n- jq contract-lock shape check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:02:13Z",
          "mergedAt": "2026-07-08T02:03:57Z",
          "additions": 74,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 83,
          "url": "https://github.com/kungfu-systems/kfd/pull/83",
          "title": "feat(kfd): add observer perspective guideline",
          "body": "## Summary\n- add KFD-4 as the first practice guideline: timelines must declare their observer\n- publish the KFD-4 observer-perspective schema and expose it through registry/standards metadata\n- update KFD self-proof witnesses, site bundle, release impact, and alpha.19 package anchor\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n\n## Release path\nThis does not publish locally. Alpha publishing should happen through Buildchain channel promotion after this lands on dev/v1/v1.0, then dev/v1/v1.0 -> alpha/v1/v1.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:01:45Z",
          "mergedAt": "2026-07-08T02:04:43Z",
          "additions": 790,
          "deletions": 124,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 85,
          "url": "https://github.com/kungfu-systems/kfd/pull/85",
          "title": "chore(release): promote KFD alpha.19",
          "body": "## Summary\n- promote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd 1.0.0-alpha.19\n- includes KFD-4 observer perspective guideline and current Buildchain v2 contract lock acceptance\n\n## Release path\nThis is the required Buildchain channel promotion path for KFD alpha publishing:\n\n```text\ndev/v1/v1.0 -> alpha/v1/v1.0\n```\n\nNo local npm publish was performed.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:05:26Z",
          "mergedAt": "2026-07-08T02:06:40Z",
          "additions": 790,
          "deletions": 124,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 846,
          "url": "https://github.com/kungfu-systems/buildchain/pull/846",
          "title": "chore(release): update v2.9 impact metadata",
          "body": "## Summary\n\n- update Buildchain self-promotion release-passport impact metadata for v2.9\n- align inventory contract snippets with the v2.9 release claims\n\n## Validation\n\n- `node scripts/check-inventory.mjs`\n- `pnpm run check:workflows`",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:08:42Z",
          "mergedAt": "2026-07-08T02:13:01Z",
          "additions": 8,
          "deletions": 9,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 386,
          "url": "https://github.com/kungfu-systems/kungfu/pull/386",
          "title": "feat(atlas): record imports as action envelopes",
          "body": "## Summary\n- route Atlas import snapshot writes through the C++ action_recorder binding\n- add action envelopes to Atlas import manifests and fsck journal-frame validation\n- add C++ action_recorder readback smoke plus Atlas import/export/GUI fixture coverage\n\n## Verification\n- PYTHONPATH=src/python uv run --frozen pytest tests/python/test_atlas_storage.py -q\n- node tests/fixtures/atlas-demo-import/run.mjs\n- cmake -S . -B build -DKUNGFU_WITH_SLICES=ON && cmake --build build --config Release --target fact_ledger_action_recorder --parallel 8\n- ./framework/core/build/Release/fact_ledger_action_recorder /tmp/kf-action-recorder.A19XMO 5\n- ./kungfu-code build\n- node tests/fixtures/kfx-demo-work-dashboard-atlas-live/run.mjs\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:16:41Z",
          "mergedAt": "2026-07-08T02:17:53Z",
          "additions": 501,
          "deletions": 22,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 387,
          "url": "https://github.com/kungfu-systems/kungfu/pull/387",
          "title": "docs: manage README badges with buildchain",
          "body": "## Summary\n- replace the hand-maintained README badge set with a Buildchain-managed badge block\n- configure Buildchain badge facts for KFD, release passport, license, platform and workflow badges\n- update Kungfu to @kungfu-tech/buildchain 2.8.17 and refresh the generated SDK canonical policy\n\n## Validation\n- ./kungfu-code check\n- buildchain badges readme --cwd . --check --json\n- buildchain validate --cwd . --require-version-state --require-lifecycle-stages install,build,verify --json\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:20:40Z",
          "mergedAt": "2026-07-08T02:21:33Z",
          "additions": 29,
          "deletions": 13,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 848,
          "url": "https://github.com/kungfu-systems/buildchain/pull/848",
          "title": "chore(release): open v2.9 alpha version state",
          "body": "## Summary\n- set Buildchain version state to 2.9.0-alpha.0 for the v2.9 release line\n- refresh generated site bundle contract and manifest versions\n- keep site bundle timestamp policy ci-injected for public package metadata\n\n## Validation\n- pnpm run check:site\n- node scripts/check-inventory.mjs\n- pnpm run check:workflows\n- pnpm run test:unit\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:20:33Z",
          "mergedAt": "2026-07-08T02:22:27Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 849,
          "url": "https://github.com/kungfu-systems/buildchain/pull/849",
          "title": "release: promote Buildchain v2.9 alpha",
          "body": "## Summary\nPromote the Buildchain v2.9 line from dev to alpha.\n\nThis PR carries the reviewed v2.9.0-alpha.0 version state and release-impact metadata. Promotion should publish the alpha prerelease through Buildchain Ref Promotion after Verify succeeds.\n\n## Channel\n- source: dev/v2/v2.9\n- target: alpha/v2/v2.9\n- expected version: 2.9.0-alpha.0",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:22:56Z",
          "mergedAt": "2026-07-08T02:25:04Z",
          "additions": 2049,
          "deletions": 135,
          "changedFiles": 36
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 852,
          "url": "https://github.com/kungfu-systems/buildchain/pull/852",
          "title": "chore(release): sync action bundles for v2.9 promotion",
          "body": "## Summary\n- rebuild checked-in action dist bundles so version-state verification stays limited to configured version files\n- fixes v2.9 alpha promotion failure: action dist changed during verification\n\n## Validation\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:35:43Z",
          "mergedAt": "2026-07-08T02:37:30Z",
          "additions": 122,
          "deletions": 122,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 853,
          "url": "https://github.com/kungfu-systems/buildchain/pull/853",
          "title": "release: promote Buildchain v2.9 alpha bundle fix",
          "body": "## Summary\nPromote the v2.9 action bundle synchronization into alpha so Buildchain Ref Promotion can verify generated version-state trees without action dist drift.\n\n## Channel\n- source: dev/v2/v2.9\n- target: alpha/v2/v2.9\n- includes: #852 action dist synchronization\n- expected version: 2.9.0-alpha.0",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:37:56Z",
          "mergedAt": "2026-07-08T02:40:57Z",
          "additions": 122,
          "deletions": 122,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 854,
          "url": "https://github.com/kungfu-systems/buildchain/pull/854",
          "title": "release: promote Buildchain v2.9",
          "body": "Promote Buildchain v2.9 from alpha to the stable release channel.\n\nEvidence:\n- Alpha promotion succeeded for v2.9.0-alpha.0.\n- npm alpha dist-tag points to 2.9.0-alpha.0 while latest remains 2.8.17.\n- GitHub alpha release is prerelease and includes release passport/evidence assets.\n\nThis PR should trigger the normal release-channel verify gate; after merge, Buildchain Ref Promotion should publish the stable v2.9.0 release.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:44:38Z",
          "mergedAt": "2026-07-08T02:46:19Z",
          "additions": 2171,
          "deletions": 257,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 388,
          "url": "https://github.com/kungfu-systems/kungfu/pull/388",
          "title": "feat(atlas): reset v4 msg type envelope",
          "body": "## Summary\n- reset v4 business facts onto a generic msg_type=1000 action-envelope carrier\n- move Atlas import semantics to action_type/schema_ref metadata\n- update Atlas import/export/fsck/projection tests and msg_type docs\n- make hook installation tolerate locked main-repo .git hooks during worktree builds\n\n## Validation\n- python3 -m py_compile framework/core/src/python/kungfu/atlas/__init__.py framework/core/src/python/kungfu/atlas/payloads.py framework/core/src/python/kungfu/atlas/store.py framework/core/tests/python/test_atlas_storage.py tests/fixtures/atlas-demo-import/check_import.py\n- cd framework/core && PYTHONPATH=src/python uv run --frozen pytest tests/python/test_atlas_storage.py -q\n- ./kungfu-code build\n- ./kungfu-code check\n- node tests/fixtures/atlas-demo-import/run.mjs\n- node tests/fixtures/kfx-demo-work-dashboard-atlas-live/run.mjs\n- cmake/build fact_ledger_action_recorder smoke",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:52:33Z",
          "mergedAt": "2026-07-08T02:53:55Z",
          "additions": 478,
          "deletions": 267,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 855,
          "url": "https://github.com/kungfu-systems/buildchain/pull/855",
          "title": "fix(web-surface): resolve multi-surface preview roots",
          "body": "## Summary\n- ensure CloudFront default root object is index.html for web-surface S3/CloudFront deploys\n- keep multi-surface preview host roots equivalent to explicit /index.html requests\n- add release-line bootstrap and public surface reverse-audit support for the v2.9 line\n\n## Verification\n- pnpm run check\n- node --test tests/web-surface.test.mjs\n- node --test tests/public-surface-audit.test.mjs\n- node --test tests/cli.test.mjs\n- node scripts/check-inventory.mjs\n- pnpm run check:site\n- pnpm run check:workflows\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T03:42:13Z",
          "mergedAt": "2026-07-08T03:44:41Z",
          "additions": 6647,
          "deletions": 230,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 856,
          "url": "https://github.com/kungfu-systems/buildchain/pull/856",
          "title": "chore(release): promote v2.9 alpha",
          "body": "## Summary\n- promote dev/v2/v2.9 into the alpha channel for the next v2 release\n- carries PR #855 web-surface preview root routing and v2.9 contract updates\n\n## Verification\n- channel PR checks must pass before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T03:45:33Z",
          "mergedAt": "2026-07-08T03:47:28Z",
          "additions": 6647,
          "deletions": 230,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 389,
          "url": "https://github.com/kungfu-systems/kungfu/pull/389",
          "title": "feat(core): add frame integrity receipts and msg type gate",
          "body": "## Summary\n- add a repository gate that blocks new raw 300xx/400xx msg_type allocations outside reviewed legacy surfaces\n- add action recorder receipt integrity fields for payload and frame checksums\n- verify Atlas import fsck against persisted action frame checksums\n\n## Validation\n- ./kungfu-code verify --full\n- staged pre-commit gate during commit",
          "author": "dongkeren",
          "createdAt": "2026-07-08T03:50:09Z",
          "mergedAt": "2026-07-08T03:50:54Z",
          "additions": 592,
          "deletions": 36,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 857,
          "url": "https://github.com/kungfu-systems/buildchain/pull/857",
          "title": "chore(release): promote v2.9.1",
          "body": "## Summary\n- promote the tested v2.9.1 alpha channel into the stable v2.9 release channel\n- finalizes the v2 floating release after the multi-surface preview root fix\n\n## Verification\n- v2.9.1-alpha.1 promotion completed successfully\n- channel PR checks must pass before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T03:50:49Z",
          "mergedAt": "2026-07-08T03:52:43Z",
          "additions": 6657,
          "deletions": 240,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 859,
          "url": "https://github.com/kungfu-systems/buildchain/pull/859",
          "title": "feat(kfd): add KFD-3 surface registration",
          "body": "## Summary\n\n- add first-class `buildchain kfd-3 detect/register/audit/witness/query` commands\n- add the public Node API export `@kungfu-tech/buildchain/kfd-3-surfaces`\n- generate KFD/site/manual/CLI/Node registry facts for the new surface and document the KFD-1/2/3 support model\n- cover npm, CLI, wheel-shaped, binary, docs, site bundle, registry, witness, query, and Buildchain self-dogfood paths\n\n## Verification\n\n- `node --test tests/kfd3-surface-register.test.mjs tests/public-surface-audit.test.mjs`\n- `node bin/buildchain.mjs kfd-3 query buildchain --json`\n- `pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T04:21:02Z",
          "mergedAt": "2026-07-08T04:22:48Z",
          "additions": 1681,
          "deletions": 41,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 390,
          "url": "https://github.com/kungfu-systems/kungfu/pull/390",
          "title": "refactor(core): replace location category with role policy",
          "body": "## Summary\n- replace trading-era yijinjing location category with neutral location_role / role across C++, Python, Node, SDK, and stubs\n- decouple journal page sizing from location role and use a uniform 16 MiB default storage policy\n- document the v4 greenfield decision in ADR-0024\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- git diff --check\n- Python enum smoke for location_role\n- kungfu journal --help exposes --role\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T04:24:51Z",
          "mergedAt": "2026-07-08T04:25:46Z",
          "additions": 710,
          "deletions": 595,
          "changedFiles": 57
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 860,
          "url": "https://github.com/kungfu-systems/buildchain/pull/860",
          "title": "fix(web-surface): keep preview apply distribution-free",
          "body": "## Summary\n- stop consumer web-surface apply from mutating shared CloudFront DefaultRootObject\n- keep multi-surface root routing on per-surface S3 directory-index alias objects\n- upload preview/staging/production apply diagnostics artifacts and print failed operation details\n\n## Verification\n- node --test tests/web-surface.test.mjs tests/build-surface.test.mjs\n- pnpm run generate:site\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T04:31:07Z",
          "mergedAt": "2026-07-08T04:33:03Z",
          "additions": 185,
          "deletions": 130,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 858,
          "url": "https://github.com/kungfu-systems/buildchain/pull/858",
          "title": "chore(release): promote v2.10 alpha",
          "body": "Buildchain release line bootstrap opened v2.10. Merge this channel PR to publish the first alpha for the new minor line.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T04:17:46Z",
          "mergedAt": "2026-07-08T04:34:46Z",
          "additions": 2121,
          "deletions": 176,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 861,
          "url": "https://github.com/kungfu-systems/buildchain/pull/861",
          "title": "chore(release): promote v2.10 release",
          "body": "## Summary\n- Promote Buildchain v2.10 release after v2.10.0-alpha.0 validation.\n- Includes KFD-3 surface registration and web-surface preview root diagnostics/routing fix.\n\n## Verification\n- v2.10.0-alpha.0 promotion succeeded\n- PR checks must pass before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-08T04:38:28Z",
          "mergedAt": "2026-07-08T04:40:11Z",
          "additions": 2121,
          "deletions": 176,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 391,
          "url": "https://github.com/kungfu-systems/kungfu/pull/391",
          "title": "refactor(core): move business semantics into envelopes",
          "body": "## Summary\n- rename the low-level journal dispatch field/API from msg_type to carrier_type\n- route Atlas/Rewind/Work/KFX business semantics through kungfu.action-envelope/v1 action_type payloads\n- replace raw 300xx/400xx allocation checks with a carrier/action-envelope gate and ADR-0025\n- update SDK/TUI/journal manager surfaces to expose carrierType transport metadata\n\n## Verification\n- ./kungfu-code check\n- ./kungfu-code build (completed; log ended with [build] complete)\n- python3 -m compileall -q framework/core/src/python/kungfu tests/fixtures\n- node scripts/check-carrier-action-envelope.mjs --all\n- node tests/fixtures/atlas-demo-import/run.mjs\n- node tests/fixtures/work-demo-lifecycle/run.mjs\n- node tests/fixtures/rewind-demo-kfx-schema/run.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T05:14:54Z",
          "mergedAt": "2026-07-08T05:18:21Z",
          "additions": 1595,
          "deletions": 1088,
          "changedFiles": 113
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 392,
          "url": "https://github.com/kungfu-systems/kungfu/pull/392",
          "title": "feat(buildchain): wire Kungfu KFD release evidence",
          "body": "## Summary\n- upgrade Kungfu Buildchain dependency to 2.10.0\n- add root Buildchain KFD evidence generator for KFD-1/2/3 release passport inputs\n- wire release promotion workflow to pass KFD witnesses, claims, and artifact verify command\n- add Buildchain KFD verification to ./kungfu-code verify and document the current KFD flow\n\n## Verification\n- ./kungfu-code kfd:buildchain\n- ./kungfu-code kfd:buildchain:check\n- ./kungfu-code check\n- ./kungfu-code check:types\n- ./kungfu-code verify\n- Buildchain KFD-3 release gate smoke: status=passed, releaseStatus=enforced\n\nNote: ./kungfu-code verify --full reached 27/28 and failed only in existing capability slices build because slice sources reference longfist::enums::category::SYSTEM, which is outside this KFD wiring change.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T05:25:51Z",
          "mergedAt": "2026-07-08T05:27:29Z",
          "additions": 1343,
          "deletions": 63,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 79,
          "url": "https://github.com/kungfu-systems/libnode/pull/79",
          "title": "ci: enable locked checkout cache",
          "body": "## Summary\n- pass Buildchain locked source checkout cache inputs to Build and Release - Verify\n- document the checkout cache and Node source mirror variables\n- set repo variables for the local HTTP mirror path used by self-hosted runners\n\n## Verification\n- python YAML parse for workflow files\n- pnpm exec prettier --check README.md .github/workflows/build.yml .github/workflows/release-verify.yaml\n- git diff --check\n- git ls-remote against local HTTP mirrors for libnode and node tag\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T04:03:10Z",
          "mergedAt": "2026-07-08T05:35:34Z",
          "additions": 81,
          "deletions": 16,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 82,
          "url": "https://github.com/kungfu-systems/libnode/pull/82",
          "title": "release(alpha): publish 22.22.3-kf.3-alpha.15",
          "body": "## Summary\n- include latest dev/v22/v22.22 checkout-cache changes in the alpha channel candidate\n- bump package.json and libnode.release.json to 22.22.3-kf.3-alpha.15\n\n## Verification\n- corepack pnpm verify-release\n- corepack pnpm verify-package-source\n- pnpm pack --dry-run\n- git diff --check\n\nThis PR is the Buildchain publish-gate alpha candidate. The PR build should produce the release-candidate evidence, and the alpha branch promotion should publish through Trusted Publishing.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T05:40:20Z",
          "mergedAt": "2026-07-08T06:02:20Z",
          "additions": 83,
          "deletions": 18,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 5,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/5",
          "title": "feat(tap): add managed product updater",
          "body": "## Summary\n- add a managed product updater that projects upstream release passports into Homebrew formulae, tap-manifest.json, and compatible Buildchain @v2 contract-lock updates\n- add scheduled/manual Managed Product Updates workflow to open update PRs\n- update tracked Buildchain formula and tap manifest from v2.8.15 to v2.10.0, and refresh the compatible Buildchain @v2 lock\n- classify the new updater and workflow in KFD-1/2/3 witnesses and docs\n\n## Validation\n- node --check scripts/update-managed-products.mjs\n- node --check scripts/update-kfd-witnesses.mjs\n- node --check scripts/check-tap.mjs\n- node scripts/update-managed-products.mjs --check --update-lock --json\n- node scripts/check-tap.mjs\n- actionlint .github/workflows/managed-product-updates.yml .github/workflows/tap-check.yml .github/workflows/buildchain-validate.yml\n- buildchain validate --require-lifecycle-stages verify\n- buildchain lifecycle run verify --required\n- git diff --check\n\n## Notes\n- Buildchain v2.10.0 release passport reports KFD-1/KFD-2/KFD-3 as passed.\n- The Buildchain @v2 compatibility digest is unchanged; only the resolved SHA and contract digest moved.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T05:31:40Z",
          "mergedAt": "2026-07-08T06:43:05Z",
          "additions": 741,
          "deletions": 59,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 863,
          "url": "https://github.com/kungfu-systems/buildchain/pull/863",
          "title": "fix(release): accept publish-gate lineage and rewrite surface roots",
          "body": "## Summary\n\n- accept strict same-line publish-gate/alpha and publish-gate/release PR lineage in promote-buildchain-ref governance checks\n- install a CloudFront viewer-request directory-index rewrite for web-surface deploys so multi-surface preview roots resolve to each surface index.html\n- update release passport impact facts, docs, tests, action bundle, and site bundle projections\n\n## Verification\n\n- node --test tests/promote-buildchain-ref.test.mjs tests/web-surface.test.mjs\n- pnpm run build\n- pnpm run check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/ (confirmed scripts/web-surface-cloudfront-rewrite.mjs is packaged)\n\nFixes #862\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T06:53:23Z",
          "mergedAt": "2026-07-08T06:55:22Z",
          "additions": 480,
          "deletions": 91,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 864,
          "url": "https://github.com/kungfu-systems/buildchain/pull/864",
          "title": "release: promote Buildchain v2.10 alpha",
          "body": "## Summary\n\nPromote the current v2.10 dev line to alpha after fixing publish-gate channel lineage and web-surface preview root routing.\n\n## Included fixes\n\n- #863 accepts same-line publish-gate/alpha and publish-gate/release PR lineage in promote-buildchain-ref\n- #863 installs CloudFront directory-index rewrites for multi-surface web preview roots\n\n## Verification\n\n- dev/v2/v2.10 PR #863 checks passed before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T06:56:41Z",
          "mergedAt": "2026-07-08T06:58:31Z",
          "additions": 480,
          "deletions": 91,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 393,
          "url": "https://github.com/kungfu-systems/kungfu/pull/393",
          "title": "refactor(core): narrow yijinjing greenfield surface",
          "body": "## Summary\n- remove Python yijinjing typed AllDataTypes helper bindings and narrow stubs to raw carrier/action surfaces\n- rename trading-day restore helpers to neutral session/history window APIs\n- remove trading/market closed-set registries and legacy cache feed helper, leaving explicit legacy refresh debt\n- add ADR-0026 and a yijinjing greenfield guard wired into check/pre-commit\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- python3 -m compileall -q framework/core/src/python/kungfu tests/fixtures\n- node scripts/check-yijinjing-greenfield.mjs --all\n- node scripts/check-carrier-action-envelope.mjs --all\n- node framework/core/src/libyijinjing/check-deps.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T06:58:59Z",
          "mergedAt": "2026-07-08T06:59:57Z",
          "additions": 685,
          "deletions": 1773,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 865,
          "url": "https://github.com/kungfu-systems/buildchain/pull/865",
          "title": "release: promote Buildchain v2.10.1 stable",
          "body": "## Summary\n\nPromote Buildchain v2.10.1 from alpha to stable.\n\n## Included fixes\n\n- #862 / #863: promote-buildchain-ref accepts strict same-line publish-gate channel lineage\n- #863: web-surface deploy applies CloudFront directory-index rewrites for multi-surface preview roots\n\n## Alpha evidence\n\n- v2.10.1-alpha.1\n- npm dist-tag alpha = 2.10.1-alpha.1\n- Buildchain Ref Promotion run 28923902125 succeeded\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T07:02:24Z",
          "mergedAt": "2026-07-08T07:04:13Z",
          "additions": 490,
          "deletions": 101,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 394,
          "url": "https://github.com/kungfu-systems/kungfu/pull/394",
          "title": "refactor(core): fence python longfist public types",
          "body": "## Summary\n- add C++ CorePublic*DataTypes registries for Python longfist/types/state/profile bindings\n- stop exposing legacy trading/profile schemas through Python stubs and dispatch bench typed mode\n- document the boundary in ADR-0027 and extend the yijinjing greenfield gate\n\n## Validation\n- ./kungfu-code build\n- node scripts/check-yijinjing-greenfield.mjs --all\n- node scripts/check-carrier-action-envelope.mjs --all\n- node framework/core/src/libyijinjing/check-deps.mjs\n- python3 -m compileall -q framework/core/src/python/kungfu framework/core/tests/bench/dispatch_load.py tests/fixtures\n- git diff --check\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T07:39:12Z",
          "mergedAt": "2026-07-08T07:39:24Z",
          "additions": 245,
          "deletions": 1452,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 395,
          "url": "https://github.com/kungfu-systems/kungfu/pull/395",
          "title": "refactor(core): fence node longfist public registry",
          "body": "## Summary\n- bind Node Longfist public `types` and `carrierTypes` to `CorePublicDataTypes`\n- update the status view wording to show the core registry rather than the legacy compiled registry\n- extend the yijinjing greenfield guard to block public Node binding and CorePublic* registry regressions\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- node scripts/check-yijinjing-greenfield.mjs --all\n- node scripts/check-carrier-action-envelope.mjs --all\n- node framework/core/src/libyijinjing/check-deps.mjs\n- git diff --check\n- runtime probe: Longfist public types/carrierTypes expose 27 core entries and no legacy trading/profile entries",
          "author": "dongkeren",
          "createdAt": "2026-07-08T08:02:51Z",
          "mergedAt": "2026-07-08T08:03:05Z",
          "additions": 118,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 396,
          "url": "https://github.com/kungfu-systems/kungfu/pull/396",
          "title": "refactor(core): name legacy compiled longfist registry",
          "body": "## Summary\n- add explicit LegacyCompiled* registry names for internal compiled longfist compatibility decode paths\n- move journal replay, console, typed dump, rx custom-event detection, and Node Frame typed decode away from direct AllTypes/AllDataTypes names\n- extend greenfield/dependency guards so public bindings and future yijinjing code cannot reintroduce legacy registry coupling\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- node scripts/check-carrier-action-envelope.mjs --all\n- node scripts/check-yijinjing-greenfield.mjs --all\n- node framework/core/src/libyijinjing/check-deps.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T08:16:35Z",
          "mergedAt": "2026-07-08T08:16:46Z",
          "additions": 59,
          "deletions": 23,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 867,
          "url": "https://github.com/kungfu-systems/buildchain/pull/867",
          "title": "fix(web-surface): support external directory index rewrites",
          "body": "## Summary\n\n- add declarative `directory_index_rewrite = external` for web-surface deploy channels and surface overrides\n- skip Buildchain-managed CloudFront Function creation when an existing viewer-request router owns directory-index rewrites\n- keep routing evidence and root/nested health checks as the validation contract\n\n## Verification\n\n- `node --test tests/buildchain-config.test.mjs tests/web-surface.test.mjs`\n- `pnpm run check`\n\n## Release\n\nPatch release candidate for v2.10.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T08:16:14Z",
          "mergedAt": "2026-07-08T08:18:11Z",
          "additions": 323,
          "deletions": 126,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 868,
          "url": "https://github.com/kungfu-systems/buildchain/pull/868",
          "title": "chore(release): promote v2.10 dev to alpha",
          "body": "Promote dev/v2/v2.10 to alpha/v2/v2.10 for the external web-surface directory-index rewrite contract fix.\n\nIncluded dev PR:\n- #867 fix(web-surface): support external directory index rewrites",
          "author": "dongkeren",
          "createdAt": "2026-07-08T08:18:38Z",
          "mergedAt": "2026-07-08T08:20:43Z",
          "additions": 323,
          "deletions": 126,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 869,
          "url": "https://github.com/kungfu-systems/buildchain/pull/869",
          "title": "chore(release): promote v2.10.2 to release",
          "body": "Promote alpha/v2/v2.10 to release/v2/v2.10 after successful alpha publish.\n\nAlpha proof:\n- npm alpha: @kungfu-tech/buildchain@2.10.2-alpha.1\n- GitHub Release: v2.10.2-alpha.1\n\nIncluded fix:\n- #867 fix(web-surface): support external directory index rewrites",
          "author": "dongkeren",
          "createdAt": "2026-07-08T08:23:56Z",
          "mergedAt": "2026-07-08T08:25:55Z",
          "additions": 333,
          "deletions": 136,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 85,
          "url": "https://github.com/kungfu-systems/libnode/pull/85",
          "title": "fix: keep KFD witnesses in sync",
          "body": "## Summary\n- add a generated KFD witness sync/check script\n- fail verify when KFD witness JSON is stale\n- refresh KFD-1/KFD-3 witness files for the current release state\n- update the Buildchain v2 contract lock to v2.10.1\n\n## Verification\n- corepack pnpm verify-release\n- corepack pnpm verify-kfd-witnesses\n- corepack pnpm verify-package-source\n- corepack pnpm pack --dry-run\n- npm exec --yes --package @kungfu-tech/buildchain@2.10.1 -- buildchain validate --cwd . --require-version-state --require-lifecycle-stages build,verify\n- local Buildchain KFD-1 passport collect: source/artifact verification passed",
          "author": "dongkeren",
          "createdAt": "2026-07-08T08:02:22Z",
          "mergedAt": "2026-07-08T08:37:27Z",
          "additions": 180,
          "deletions": 13,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 86,
          "url": "https://github.com/kungfu-systems/libnode/pull/86",
          "title": "chore(release): publish libnode 22.22.3-kf.3-alpha.16",
          "body": "## Summary\n- bump libnode alpha version to 22.22.3-kf.3-alpha.16\n- refresh KFD-1 and KFD-3 witness files for the release commit\n\n## Verification\n- corepack pnpm verify-release\n- corepack pnpm verify-kfd-witnesses\n- GITHUB_ACTIONS=true node .gyp/libnode-kfd-witnesses.js check\n- corepack pnpm verify-package-source\n- corepack pnpm pack --dry-run\n- npm exec --yes --package @kungfu-tech/buildchain@2.10.1 -- buildchain validate --cwd . --require-version-state --require-lifecycle-stages build,verify\n- local Buildchain KFD-1 passport collect: source/artifact verification passed",
          "author": "dongkeren",
          "createdAt": "2026-07-08T08:38:58Z",
          "mergedAt": "2026-07-08T09:01:44Z",
          "additions": 182,
          "deletions": 15,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 870,
          "url": "https://github.com/kungfu-systems/buildchain/pull/870",
          "title": "docs(kfd): add capability-based site registry",
          "body": "## Summary\n\n- Add `dist/site/capability-registry.json` as the package-owned capability navigation source for Buildchain KFD-3 surfaces.\n- Add capability metadata to page, manual, CLI, Node API, workflow, and action registries.\n- Remove placeholder CLI purpose text by making command metadata required, and require Node API summaries in inventory checks.\n- Document the capability-first organization in `docs/MAP.md`, `docs/cli.md`, and `docs/site-bundle-contract.md`.\n\n## Validation\n\n- `node scripts/check-inventory.mjs`\n- `pnpm run check:site`\n- `node bin/buildchain.mjs kfd-3 query buildchain --json`\n- `pnpm run check` before reverting an unrelated local action bundle rebuild artifact; 420 unit tests passed.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T09:18:32Z",
          "mergedAt": "2026-07-08T09:20:28Z",
          "additions": 2117,
          "deletions": 187,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 29,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/29",
          "title": "feat(site): publish Buildchain badge endpoints",
          "body": "## Summary\\n- render Buildchain hosted badge endpoint SVG/JSON files from the @kungfu-tech/buildchain site bundle\\n- upgrade the site renderer to consume @kungfu-tech/buildchain 2.8.17\\n- add Buildchain-managed README badges and enforce badge drift checks\\n- refresh the accepted Buildchain v2 contract lock\\n\\n## Verification\\n- pnpm run build\\n- pnpm run check\\n- pnpm exec buildchain badges readme --check\\n\\n## Current release note\\nPreview deploy currently applies the hub surface, but the Buildchain workflow health check still reports 403 for multi-surface preview roots such as buildchain-pr-29.preview.libkungfu.dev/. Explicit /index.html routes are reachable, so this appears to be a Buildchain/CloudFront directory-index routing issue rather than a site artifact generation issue.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T14:54:49Z",
          "mergedAt": "2026-07-08T09:25:18Z",
          "additions": 910,
          "deletions": 76,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 397,
          "url": "https://github.com/kungfu-systems/kungfu/pull/397",
          "title": "refactor(core): remove watcher legacy data path",
          "body": "## Summary\n- remove Watcher legacy trading-data reader/cache/sync path and old command shim exports\n- slim Watcher constructor/config/API to neutral runtime arguments\n- drop LegacyRefreshDataTypes/Tags and update ADR plus bench usage\n\n## Validation\n- ./kungfu-code check\n- ./kungfu-code build\n- git diff --check\n- node --check framework/core/lib/kungfu.js\n- node --check framework/core/tests/bench/dispatch_watcher_bench.js\n- rg residual scan for removed legacy watcher symbols/config names",
          "author": "dongkeren",
          "createdAt": "2026-07-08T09:51:16Z",
          "mergedAt": "2026-07-08T09:51:27Z",
          "additions": 34,
          "deletions": 319,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 871,
          "url": "https://github.com/kungfu-systems/buildchain/pull/871",
          "title": "fix: support managed-network web surface health",
          "body": "## Summary\n- add managed-network web-surface health strategy that validates deploy manifest and S3 object sync evidence instead of requiring public HTTP fetches\n- expose an allowed-runner override for private-network HTTP smoke checks\n- update web-surface docs and generated site bundle\n\n## Validation\n- node --test tests/web-surface.test.mjs\n- node --check scripts/web-surface-core.mjs && node --check scripts/web-surface.mjs\n- pnpm run check:site\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T09:58:24Z",
          "mergedAt": "2026-07-08T10:00:17Z",
          "additions": 182,
          "deletions": 14,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 398,
          "url": "https://github.com/kungfu-systems/kungfu/pull/398",
          "title": "feat(sdk): expose KFD capability queries",
          "body": "## Summary\n- add `kungfu sdk kfd query|check|witness` for SDK-distributed KFD-3 capability facts\n- add installed CLI bridge `kungfu kfd ...` that delegates to the SDK implementation\n- package the generated Buildchain KFD-3 registry under `developer/sdk/kfd/buildchain.kfd3.json` and declare the new surfaces\n- document installed-runtime vs repo-side KFD evidence entrypoints\n\n## Validation\n- `./kungfu-code kfd:buildchain:check`\n- `./kungfu-code check:types`\n- `./kungfu-code check`\n- `node developer/sdk/src/sdk.js kfd query --json`\n- `python3 -m py_compile framework/core/src/python/kungfu/cli/commands/kfd.py`\n- `cd framework/core && uv run --frozen ruff check src/python/kungfu/cli/commands/kfd.py src/python/kungfu/cli/commands/__registry__.py`\n- `cd framework/core && uv run --frozen ruff format --check src/python/kungfu/cli/commands/kfd.py src/python/kungfu/cli/commands/__registry__.py`\n\n## Note\n`./kungfu-code --filter @kungfu-tech/core run dev:kungfu -- kfd query --json` was attempted, but this worktree has no built `pykungfu` native binding, so the dev runtime failed before reaching the new command. The Python file was syntax-checked and ruff-checked; SDK-side KFD query/check/witness is covered by tests.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:02:52Z",
          "mergedAt": "2026-07-08T10:04:48Z",
          "additions": 935,
          "deletions": 3,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 872,
          "url": "https://github.com/kungfu-systems/buildchain/pull/872",
          "title": "fix: verify managed-network web surfaces with s3 heads",
          "body": "## Summary\n- verify managed-network live web-surface health with S3 head-object checks for each surface manifest and smoke target object\n- keep deployment-evidence fallback for dry-run/plan-only health and keep allowed-runner HTTP smoke override\n- update web-surface docs and generated site bundle\n\n## Validation\n- node --test tests/web-surface.test.mjs\n- node --check scripts/web-surface-core.mjs && node --check scripts/web-surface.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:05:11Z",
          "mergedAt": "2026-07-08T10:07:09Z",
          "additions": 144,
          "deletions": 20,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 399,
          "url": "https://github.com/kungfu-systems/kungfu/pull/399",
          "title": "refactor(core): remove trading legacy surface",
          "body": "## Summary\n- narrow longfist compiled registries to the v4 core/runtime surface and remove LegacyCompiled* aliases\n- remove Node trading-era profile store exports and watcher strategy/broker state plumbing\n- remove Python trading/profile enum public bindings and regenerate stubs\n- update greenfield guards and ADRs to block the old surface from returning\n\n## Validation\n- ./kungfu-code check\n- ./kungfu-code build\n- git diff --check\n- node --check framework/core/lib/kungfu.js\n- node --check scripts/check-yijinjing-greenfield.mjs\n- node --check framework/core/src/libyijinjing/check-deps.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:10:51Z",
          "mergedAt": "2026-07-08T10:11:03Z",
          "additions": 184,
          "deletions": 3810,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 31,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/31",
          "title": "fix(site): render KFD badge endpoints from registry",
          "body": "## Summary\\n- derive missing KFD badge endpoint entries from the pinned @kungfu-tech/kfd registry\\n- generate KFD-4 SVG/JSON badge endpoints for every supported Buildchain badge state\\n- make build and check assertions follow the KFD registry instead of a fixed KFD-1/2/3 list\\n\\n## Verification\\n- pnpm run build\\n- pnpm run check\\n- local static check: /badges/v1/kfd-4/passed.svg and .json return 200",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:08:42Z",
          "mergedAt": "2026-07-08T10:21:37Z",
          "additions": 139,
          "deletions": 7,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 873,
          "url": "https://github.com/kungfu-systems/buildchain/pull/873",
          "title": "chore: include managed-network health in release impact",
          "body": "## Summary\n- update Buildchain release impact metadata to include managed-network web-surface health verification\n\n## Validation\n- node scripts/check-inventory.mjs\n- bash scripts/check-workflows.sh",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:19:57Z",
          "mergedAt": "2026-07-08T10:21:53Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 400,
          "url": "https://github.com/kungfu-systems/kungfu/pull/400",
          "title": "refactor(core): rename libkungfu runtime sources",
          "body": "## Summary\n- move libkungfu implementation sources from src/yijinjing to src/runtime\n- update the libkungfu CMake cache glob to the new runtime path\n- update docs links that referenced the old physical source directory\n\n## Notes\n- public include paths remain <kungfu/yijinjing/...>\n- C++ namespaces remain kungfu::yijinjing\n- Python/Node public APIs are unchanged\n\n## Validation\n- ./kungfu-code check\n- ./kungfu-code build\n- git diff --check\n- rg old src/yijinjing path references",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:22:53Z",
          "mergedAt": "2026-07-08T10:23:05Z",
          "additions": 7,
          "deletions": 6,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 874,
          "url": "https://github.com/kungfu-systems/buildchain/pull/874",
          "title": "chore(release): promote v2.10 managed-network health alpha",
          "body": "Promote dev/v2/v2.10 to alpha for the managed-network web-surface health release.\n\nIncludes:\n- managed-network health without public runner HTTP access\n- live S3 head-object verification for managed-network surface manifests and smoke target objects\n- release impact metadata for the new web-surface health strategy",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:22:38Z",
          "mergedAt": "2026-07-08T10:24:36Z",
          "additions": 2418,
          "deletions": 196,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 6,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/6",
          "title": "feat(tap): auto-merge managed product updates",
          "body": "## Summary\n- enable GitHub auto-merge for automation-owned managed product update PRs\n- keep auto-merge scoped to the managed updater workflow and automation branch\n- update Buildchain tracking from v2.10.0 to v2.10.2 using the managed updater\n- refresh compatible Buildchain @v2 contract lock and KFD witnesses\n\n## Validation\n- node --check scripts/update-managed-products.mjs\n- node --check scripts/update-kfd-witnesses.mjs\n- node --check scripts/check-tap.mjs\n- node scripts/update-managed-products.mjs --check --update-lock --json\n- node scripts/check-tap.mjs\n- actionlint .github/workflows/managed-product-updates.yml .github/workflows/tap-check.yml .github/workflows/buildchain-validate.yml\n- buildchain validate --require-lifecycle-stages verify\n- buildchain lifecycle run verify --required\n- git diff --check\n\n## Auto-merge boundary\nOnly the managed updater workflow enables auto-merge for its own automation branch after release-passport validation. Non-automation PRs still follow normal review.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:24:18Z",
          "mergedAt": "2026-07-08T10:25:45Z",
          "additions": 97,
          "deletions": 58,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 875,
          "url": "https://github.com/kungfu-systems/buildchain/pull/875",
          "title": "chore(release): promote v2.10.3 stable",
          "body": "Promote Buildchain v2.10.3 from tested alpha to stable release.\n\nAlpha evidence:\n- exact tag: v2.10.3-alpha.1\n- alpha branch: alpha/v2/v2.10\n- npm alpha dist-tag: 2.10.3-alpha.1\n\nRelease includes managed-network web-surface health verification and release impact metadata.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:27:54Z",
          "mergedAt": "2026-07-08T10:29:33Z",
          "additions": 2428,
          "deletions": 206,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 876,
          "url": "https://github.com/kungfu-systems/buildchain/pull/876",
          "title": "feat(badges): discover KFD badge bundle claims from standards",
          "body": "## Summary\n- discover active kfd-* badge specs from @kungfu-tech/kfd standards metadata instead of keeping the bundle fixed to KFD-1/2/3\n- add KFD-4 badge bundle support, README projection, and site badge endpoint registry payloads\n- expose createKfdBadgeSpecsFromStandards for consumers and generated site bundle reuse\n\n## Verification\n- node --test tests/readme-badges.test.mjs\n- node --check packages/core/readme-badges.js && node --check scripts/generate-site-bundle.mjs && node --check scripts/check-inventory.mjs\n- node scripts/check-inventory.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:52:19Z",
          "mergedAt": "2026-07-08T10:54:08Z",
          "additions": 486,
          "deletions": 110,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 32,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/32",
          "title": "chore(site): validate Buildchain 2.10.3 runtime",
          "body": "## Summary\n- upgrade the pinned Buildchain package artifact from 2.10.2 to 2.10.3\n- update site version assertions and docs to the new package version\n- keep existing site-side KFD badge augmentation and buildchain-host badge mirror checks\n\n## Verification\n- pnpm run build\n- pnpm run check\n- git diff --check\n- bash -n scripts/build-site.sh scripts/check-site.sh\n\n## Notes\nThis PR is intended to verify whether Buildchain 2.10.3 fixes the managed-network web-surface health check path during real preview/staging publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:42:34Z",
          "mergedAt": "2026-07-08T10:56:08Z",
          "additions": 32,
          "deletions": 14,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 401,
          "url": "https://github.com/kungfu-systems/kungfu/pull/401",
          "title": "feat(sdk): aggregate upstream KFD facts",
          "body": "## Summary\n- aggregate Kungfu SDK KFD facts with upstream KFD-aware dependencies: @kungfu-tech/kfd, @kungfu-tech/libnode, and @kungfu-tech/buildchain\n- upgrade @kungfu-tech/libnode to 22.22.3-kf.3-alpha.16 and @kungfu-tech/kfd to 1.0.0-alpha.17\n- expose installed SDK commands for kfd upstream and aggregate views, and document the generated upstream aggregate artifact\n\n## Validation\n- ./kungfu-code kfd:buildchain:check\n- node --test developer/sdk/tests/contract-cli.test.mjs\n- ./kungfu-code check\n- git diff --check origin/dev/v4/v4.0...HEAD",
          "author": "dongkeren",
          "createdAt": "2026-07-08T11:12:02Z",
          "mergedAt": "2026-07-08T11:13:14Z",
          "additions": 648,
          "deletions": 54,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 877,
          "url": "https://github.com/kungfu-systems/buildchain/pull/877",
          "title": "fix(release): publish anchored packages by public version tag",
          "body": "## Summary\n- use published package versions as the public GitHub Release tag for anchored/manual publish-final-version transactions\n- keep transaction exact tags and release-state refs in the release passport for recovery and audit\n- prefer public package-version GitHub Release passport discovery while keeping explicit internal exact tag fallback\n\n## Verification\n- node --test tests/release-passport.test.mjs tests/promote-buildchain-ref.test.mjs tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T11:15:16Z",
          "mergedAt": "2026-07-08T11:17:21Z",
          "additions": 327,
          "deletions": 138,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 402,
          "url": "https://github.com/kungfu-systems/kungfu/pull/402",
          "title": "refactor(core): split runtime and storage public APIs",
          "body": "## Summary\n- rename libkungfu runtime-facing public APIs from yijinjing to runtime\n- keep yijinjing as the journal and storage-semantic kernel\n- add yijinjing storage contract headers for source, range, bundle, channel, acceptance, fsck, and providers\n- align the fact-ledger spec, storage service docs, ADR, and embedding smoke with the new boundary\n\n## Validation\n- ./kungfu-code fix\n- ./kungfu-code check\n- ./kungfu-code build\n- node framework/core/src/libyijinjing/check-deps.mjs\n- node framework/core/slices/embedding/run.mjs\n- git diff --check\n\n## Risk\n- pre-release v4 public API rename; no backward compatibility promise for older v4 work-in-progress names",
          "author": "dongkeren",
          "createdAt": "2026-07-08T11:56:42Z",
          "mergedAt": "2026-07-08T11:57:43Z",
          "additions": 1002,
          "deletions": 411,
          "changedFiles": 133
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 403,
          "url": "https://github.com/kungfu-systems/kungfu/pull/403",
          "title": "ci(buildchain): enable locked checkout cache",
          "body": "## Summary\n- pass Buildchain locked source checkout cache inputs to the release-candidate build workflow\n- use repo/org variables for the private local/LAN Git cache template\n- document the private config boundary and sanitized source-checkout diagnostics\n\n## Private config\n- configured kungfu-systems/kungfu repo variable BUILDCHAIN_CHECKOUT_CACHE_MIRROR_URL_TEMPLATE from the matching libnode variable\n- variable value is intentionally not written to repository files\n\n## Validation\n- ruby -e 'require \"yaml\"; YAML.load_file(\".github/workflows/build.yml\")'\n- git diff --check origin/dev/v4/v4.0...HEAD\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T11:59:25Z",
          "mergedAt": "2026-07-08T12:00:01Z",
          "additions": 20,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 878,
          "url": "https://github.com/kungfu-systems/buildchain/pull/878",
          "title": "fix(web-surface): hand off production release PR summary by artifact",
          "body": "## Summary\n- write a compact staging release PR summary JSON after staging apply\n- upload/download that summary as an artifact for the production release PR job\n- keep full staging apply results in diagnostics and stop passing operations/stdout through cross-job env/output\n\n## Verification\n- node --test tests/build-surface.test.mjs\n- bash scripts/check-workflows.sh\n- node scripts/check-inventory.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T11:58:08Z",
          "mergedAt": "2026-07-08T12:00:04Z",
          "additions": 224,
          "deletions": 7,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 879,
          "url": "https://github.com/kungfu-systems/buildchain/pull/879",
          "title": "chore(dev): merge residual feature and fix branches",
          "body": "## Summary\n- Merge all residual feature/fix branches that can be merged cleanly into dev/v2/v2.10.\n- This is a topology cleanup PR: final tree diff versus dev is empty.\n- Branches with actual conflicts are listed as explicitly not directly mergeable.\n\n## Cleanly merged branches\n- fix/binary-distribution-prepare-alpha-passport\n- fix/binary-release-state-base-passport\n- fix/rc-resolver-scan-artifact-runs\n- fix/skip-prepare-next-alpha-promotion\n\n## Conflicted branches not merged\n- feature/alpha-release-latest-alpha-selection\n- feature/kfd-3-collaboration-interface-gate\n- feature/kfd-3-passport-trust-proof\n- feature/local-git-checkout-cache\n- feature/rc-promote-default-workflow\n- feature/rc-promote-feedback\n- feature/rc-promotion-default-head-fallback\n- feature/rc-promotion-default-resolver\n- feature/rc-promotion-runtime-preserve\n- feature/v2-3-promotion-github-read-retry\n- feature/v2-3-release-passport-stable-2-3-1\n- fix/alpha-site-manifest-preserve-ci\n- fix/alpha-transaction-source-mismatch\n- fix/alpha-v2-v2.8-release-propagation-runtime\n- fix/anchored-public-github-release\n- fix/github-release-promote\n- fix/kfd-claims-version-state\n- fix/published-alpha-history-selection\n- fix/readme-badge-logo-placeholder\n- fix/release-finalization-alpha-source\n- fix/release-finalization-frozen-alpha-evidence\n- fix/release-line-v2-v2.0-finalization-source-tree\n- fix/release-next-alpha-ancestry\n- fix/release-next-alpha-dev-finalization\n- fix/release-state-retry-diagnostics\n- fix/semver-github-release\n- fix/site-manifest-preserve-ci-policy\n- fix/site-manifest-timestamp-policy\n- fix/stale-alpha-transaction-selection\n- fix/version-state-pr-fallback-title\n- fix/version-state-pr-lineage\n- fix/version-state-tree-diff\n\n## Verification\n- corepack pnpm@11.7.0 run check\n- git diff --check origin/dev/v2/v2.10..HEAD",
          "author": "dongkeren",
          "createdAt": "2026-07-08T12:05:15Z",
          "mergedAt": "2026-07-08T12:07:08Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 405,
          "url": "https://github.com/kungfu-systems/kungfu/pull/405",
          "title": "refactor(core): split yijinjing platform utilities",
          "body": "## Summary\n- move runtime-only stacktrace, terminal, signal, and Windows AppContainer APIs from libyijinjing into libkungfu runtime\n- keep yijinjing focused on hash and mmap primitives plus journal/storage contracts\n- tighten the yijinjing dependency guard and embedding docs so old util includes cannot return\n\n## Validation\n- ./kungfu-code fix\n- ./kungfu-code check\n- ./kungfu-code build\n- node framework/core/src/libyijinjing/check-deps.mjs\n- node framework/core/slices/embedding/run.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T12:15:10Z",
          "mergedAt": "2026-07-08T12:15:42Z",
          "additions": 235,
          "deletions": 248,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 404,
          "url": "https://github.com/kungfu-systems/kungfu/pull/404",
          "title": "feat(kfd): expose dev metadata in product runs",
          "body": "## Summary\n- inject local KFD registry/upstream aggregate/SDK entry env into `./kungfu-code product gui dev` and `tui dev`\n- keep explicit `KUNGFU_*` overrides authoritative\n- document dev-run KFD bridge behavior\n\n## Validation\n- `node --test artifact/scripts/product.test.mjs`\n- `KUNGFU_KFD3_REGISTRY=... KUNGFU_KFD_UPSTREAM_AGGREGATE=... node developer/sdk/src/sdk.js kfd aggregate --json`\n- `./kungfu-code kfd:buildchain:check`\n- `./kungfu-code check:types`\n- `./kungfu-code check`",
          "author": "dongkeren",
          "createdAt": "2026-07-08T12:15:00Z",
          "mergedAt": "2026-07-08T12:15:49Z",
          "additions": 87,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 880,
          "url": "https://github.com/kungfu-systems/buildchain/pull/880",
          "title": "chore(release): promote dev v2.10 to alpha",
          "body": "Promote the current dev/v2/v2.10 line to alpha so Buildchain can publish the next v2.10 alpha before stable promotion.\\n\\nIncluded since the previous alpha:\\n- web-surface production release PR handoff compact artifact/file based summary\\n- residual feature/fix branch closeout merged into dev where clean\\n- all active feature/fix branch residue cleaned up\\n\\nThis PR intentionally uses the protected channel PR flow; Buildchain promotion should run after Verify succeeds and the PR is merged.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-08T12:15:29Z",
          "mergedAt": "2026-07-08T12:17:47Z",
          "additions": 1030,
          "deletions": 248,
          "changedFiles": 49
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 881,
          "url": "https://github.com/kungfu-systems/buildchain/pull/881",
          "title": "chore(release): promote v2.10.4 stable",
          "body": "Promote Buildchain v2.10.4 alpha line to stable release.\\n\\nAlpha already published successfully as v2.10.4-alpha.1 from the protected dev→alpha PR flow. This PR should run the release verification checks and, after merge, Buildchain Ref Promotion should publish the stable v2.10.4 release.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T12:21:28Z",
          "mergedAt": "2026-07-08T12:24:12Z",
          "additions": 1040,
          "deletions": 258,
          "changedFiles": 49
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 34,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/34",
          "title": "chore(site): render Buildchain 2.10.4",
          "body": "## Summary\n- upgrade the pinned @kungfu-tech/buildchain package to 2.10.4\n- refresh the generated README badge block for KFD-4\n- update site rendering and validation version guards\n\n## Verification\n- pnpm run build\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T12:35:32Z",
          "mergedAt": "2026-07-08T12:45:13Z",
          "additions": 20,
          "deletions": 24,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 406,
          "url": "https://github.com/kungfu-systems/kungfu/pull/406",
          "title": "feat(kfd): enforce strict buildchain registry mode",
          "body": "## Summary\n- make `buildchain.kfd3.json` the strict Buildchain-default KFD-3 registry for Kungfu\n- add per-surface declaration metadata and a strict registry audit in `scripts/buildchain-kfd-evidence.mjs`\n- expose strict registry metadata through `kungfu sdk kfd check --json` / `kungfu kfd check --json`\n- run `kfd:buildchain:check` from the normal changed-scope/staged check when KFD evidence inputs change\n\n## Validation\n- `./kungfu-code kfd:buildchain`\n- `./kungfu-code kfd:buildchain:check -- --json`\n- `node --test developer/sdk/tests/contract-cli.test.mjs`\n- `node scripts/buildchain-kfd-evidence.mjs --artifact-witness --json`\n- `./kungfu-code check:types`\n- `./kungfu-code check`",
          "author": "dongkeren",
          "createdAt": "2026-07-08T12:45:36Z",
          "mergedAt": "2026-07-08T12:46:15Z",
          "additions": 1000,
          "deletions": 132,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 407,
          "url": "https://github.com/kungfu-systems/kungfu/pull/407",
          "title": "refactor(core): retire longfist schema surface",
          "body": "## Summary\n- move the v4 runtime fact schema into `kungfu/yijinjing/schema` and remove the pre-v4 longfist public package from C++/Python/Node surfaces\n- delete trading-era FlatBuffers schema/codegen and update the C++ probe to compile against yijinjing schema instead\n- update docs and ADRs so v4 is the greenfield schema root, while v4 stable and later remain responsible for v4+ schema compatibility\n\n## Verification\n- `./kungfu-code check`\n- `./kungfu-code build`\n- `node framework/core/src/libyijinjing/check-deps.mjs`\n- `node scripts/check-runtime-greenfield.mjs`\n- `git diff --check`\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-08T12:46:16Z",
          "mergedAt": "2026-07-08T12:47:04Z",
          "additions": 1116,
          "deletions": 3177,
          "changedFiles": 169
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 882,
          "url": "https://github.com/kungfu-systems/buildchain/pull/882",
          "title": "feat(kfd): unify command namespace",
          "body": "## Summary\n- replace the standalone `buildchain kfd-3` command with the first-class `buildchain kfd` namespace\n- expose `@kungfu-tech/buildchain/kfd` as the unified Node API for KFD 1/2/3/4 schemas and KFD-3 surface helpers\n- regenerate the site bundle, CLI registry, KFD claims, and bundled promote action dist from the new public surface\n\n## Breaking change\n- `buildchain kfd-3 ...` and `@kungfu-tech/buildchain/kfd-3-surfaces` are intentionally removed; consumers should use `buildchain kfd 3 ...` and `@kungfu-tech/buildchain/kfd`\n\n## Validation\n- `corepack pnpm@11.7.0 run check`\n- `node bin/buildchain.mjs kfd schema list --json`\n- `node bin/buildchain.mjs kfd 3 query buildchain --json`\n- verified old `node bin/buildchain.mjs kfd-3 detect` fails closed as unsupported\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T12:55:27Z",
          "mergedAt": "2026-07-08T12:57:32Z",
          "additions": 735,
          "deletions": 253,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 408,
          "url": "https://github.com/kungfu-systems/kungfu/pull/408",
          "title": "feat(core): separate hash integrity surfaces",
          "body": "## Summary\n- rename C++ internal hash helpers to fast_hash_* and document MurmurHash3 as internal-only\n- expose checksum/content hash algorithm constants through C++, Python, and Node surfaces\n- add ADR-0028 plus runtime greenfield gates to prevent future hash taxonomy drift\n\n## Verification\n- ./kungfu-code check\n- ./kungfu-code build\n- node scripts/check-runtime-greenfield.mjs --all\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:10:13Z",
          "mergedAt": "2026-07-08T13:11:25Z",
          "additions": 252,
          "deletions": 55,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 36,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/36",
          "title": "fix(site): render channel-aware surface links",
          "body": "## Summary\n- render cross-surface links for the active deployment channel\n- wire workflow builds to production, staging, or preview channel link targets\n- extend site checks to validate production, staging, and preview link targets\n\n## Verification\n- pnpm run build && pnpm run check\n- SITE_SURFACE_CHANNEL=staging pnpm run build && SITE_SURFACE_CHANNEL=staging pnpm run check\n- SITE_SURFACE_CHANNEL=preview SITE_PREVIEW_ALIAS=pr-34 pnpm run build && SITE_SURFACE_CHANNEL=preview SITE_PREVIEW_ALIAS=pr-34 pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:14:44Z",
          "mergedAt": "2026-07-08T13:23:46Z",
          "additions": 72,
          "deletions": 16,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 883,
          "url": "https://github.com/kungfu-systems/buildchain/pull/883",
          "title": "feat(kfd): make KFD support first class",
          "body": "## Summary\n- add canonical .buildchain/ repository layout helpers and migrate Buildchain's own config/contract lock into .buildchain/\n- expose first-class buildchain kfd status/migrate-layout plus KFD-1 witness/gate/verify and KFD-2 taxonomy/claims commands and Node APIs\n- keep KFD-4 explicitly schema-only, and update docs plus generated site/KFD facts to reflect the adjusted support model\n\n## Validation\n- node --check bin/buildchain.mjs\n- node --check packages/core/kfd.js\n- node --check packages/core/buildchain-layout.js\n- corepack pnpm@11.7.0 exec node --test tests/buildchain-config.test.mjs tests/buildchain-contract.test.mjs tests/kfd3-surface-register.test.mjs tests/cli.test.mjs\n- corepack pnpm@11.7.0 run check\n- node bin/buildchain.mjs kfd status --json\n- node bin/buildchain.mjs kfd 1 witness --json\n- node bin/buildchain.mjs kfd 2 claims --json\n- node bin/buildchain.mjs kfd 3 query buildchain --json\n- node bin/buildchain.mjs kfd 4 claims (expected schema-only failure)",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:25:39Z",
          "mergedAt": "2026-07-08T13:28:05Z",
          "additions": 1354,
          "deletions": 297,
          "changedFiles": 45
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 37,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/37",
          "title": "fix(site): render agent surface links per channel",
          "body": "## Summary\n- render KFD alternate links, KFD agent manifest, KFD llms, hub llms, generated site manifest pages, and Buildchain badge route hosts from the active surface channel\n- extend site checks so production, staging, and preview builds verify their own expected hosts\n\n## Verification\n- pnpm run build && pnpm run check\n- SITE_SURFACE_CHANNEL=staging pnpm run build && SITE_SURFACE_CHANNEL=staging pnpm run check\n- SITE_SURFACE_CHANNEL=preview SITE_PREVIEW_ALIAS=pr-37 pnpm run build && SITE_SURFACE_CHANNEL=preview SITE_PREVIEW_ALIAS=pr-37 pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:34:27Z",
          "mergedAt": "2026-07-08T13:40:40Z",
          "additions": 74,
          "deletions": 47,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 884,
          "url": "https://github.com/kungfu-systems/buildchain/pull/884",
          "title": "fix(web-surface): degrade production release PR handoff",
          "body": "## Summary\n- make post-staging production release PR handoff permission-aware\n- add production-release-pr-mode, optional PR token, and fail-on-release-pr-error inputs\n- always emit handoff summary/body artifacts and manual gh pr create instructions for permission-denied cases\n\n## Validation\n- node --check scripts/web-surface-production-release-pr.mjs\n- node --test tests/build-surface.test.mjs\n- pnpm run generate:site\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:40:33Z",
          "mergedAt": "2026-07-08T13:42:18Z",
          "additions": 452,
          "deletions": 55,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 409,
          "url": "https://github.com/kungfu-systems/kungfu/pull/409",
          "title": "feat(core): add content hash API",
          "body": "Merge feature/content-hash-api into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:47:12Z",
          "mergedAt": "2026-07-08T13:48:12Z",
          "additions": 566,
          "deletions": 30,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 885,
          "url": "https://github.com/kungfu-systems/buildchain/pull/885",
          "title": "chore(release): promote v2.10.5 alpha",
          "body": "## Summary\n- Promote dev/v2/v2.10 through alpha after PR #884.\n- Source commit: 4814c2ecf48337eb0f9d023049459b74efa78591\n\n## Validation\n- Verify on dev/v2/v2.10 succeeded: https://github.com/kungfu-systems/buildchain/actions/runs/28947287689",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:46:10Z",
          "mergedAt": "2026-07-08T13:48:15Z",
          "additions": 2476,
          "deletions": 540,
          "changedFiles": 50
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 88,
          "url": "https://github.com/kungfu-systems/kfd/pull/88",
          "title": "feat(kfd): generalize KFD-1 impact core",
          "body": "## Summary\n- promote KFD-1 breaking/additive/none/unclassifiable into a generic compatibility-impact core\n- keep release versioning as the first projection instead of the whole KFD-1 interpretation\n- add KFD-owned `surfaceRegister` metadata in `standards.json`\n- project KFD surface classification and impact projection into the KFD-1 witness from that single fact source\n\n## Dogfood\nKFD now uses `standards.json#/standards/kfd-1/surfaceRegister` as the source of truth for its own registered surfaces. `scripts/update-kfd-1-witness.mjs` projects that register into `.buildchain/kfd-1/contract-world.witness.json`, and `scripts/check.mjs` verifies the projection.\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n\n## Release note\nThis does not publish locally. It is an additive metadata/schema extension on KFD schemaVersion 1.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:51:19Z",
          "mergedAt": "2026-07-08T13:52:35Z",
          "additions": 1378,
          "deletions": 105,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 887,
          "url": "https://github.com/kungfu-systems/buildchain/pull/887",
          "title": "fix(promote): ignore downloaded release candidate evidence",
          "body": "## Summary\n- ignore transient .buildchain/release-candidate evidence in promote-buildchain-ref version-state dirty guard\n- keep other untracked .buildchain files fail-closed\n- rebuild promote action dist\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check\n\n## Release blocker\nFixes the failed alpha promotion run 28947757711 where downloaded PR-stage RC evidence made version verification fail outside version state.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:53:57Z",
          "mergedAt": "2026-07-08T13:56:04Z",
          "additions": 35,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 888,
          "url": "https://github.com/kungfu-systems/buildchain/pull/888",
          "title": "chore(release): promote v2.10.5 alpha",
          "body": "## Summary\n- Promote current dev/v2/v2.10 to alpha after PR #884 and release blocker fix #887.\n- Source commit: 984d3a5cbb569da18eb591883b4fc63af4aa9531\n\n## Validation\n- Verify on dev/v2/v2.10 succeeded: https://github.com/kungfu-systems/buildchain/actions/runs/28948223764\n- Fix #887 local validation: pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:57:55Z",
          "mergedAt": "2026-07-08T14:00:57Z",
          "additions": 35,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 889,
          "url": "https://github.com/kungfu-systems/buildchain/pull/889",
          "title": "chore(release): promote v2.10.5 stable",
          "body": "## Summary\n- Promote alpha/v2/v2.10 to release/v2/v2.10 for Buildchain v2.10.5.\n- Alpha release completed: v2.10.5-alpha.1\n- Alpha state commit: 657d42573ea0e704ebe2770d61d1410423220605\n\n## Validation\n- Alpha Verify succeeded: https://github.com/kungfu-systems/buildchain/actions/runs/28948554400\n- Alpha Ref Promotion succeeded: https://github.com/kungfu-systems/buildchain/actions/runs/28948634819",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:04:41Z",
          "mergedAt": "2026-07-08T14:08:47Z",
          "additions": 2520,
          "deletions": 550,
          "changedFiles": 52
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 410,
          "url": "https://github.com/kungfu-systems/kungfu/pull/410",
          "title": "feat(frame): add crc32c frame checksum receipts",
          "body": "Implement versioned frame checksum receipts with integrity_version=2 and crc32c, keep v1 fnv1a64 fsck verification, update Python/Node bindings, Atlas import/fsck tests, and ADR-0029.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:12:08Z",
          "mergedAt": "2026-07-08T14:12:14Z",
          "additions": 543,
          "deletions": 55,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 891,
          "url": "https://github.com/kungfu-systems/buildchain/pull/891",
          "title": "fix(promote): ignore generated buildchain evidence",
          "body": "## Summary\n- ignore generated Buildchain KFD and release-passport evidence in promote-buildchain-ref version-state dirty guard\n- keep other untracked .buildchain files fail-closed\n- extend promote action tests and rebuild action bundle\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run build\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:14:37Z",
          "mergedAt": "2026-07-08T14:16:24Z",
          "additions": 24,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 892,
          "url": "https://github.com/kungfu-systems/buildchain/pull/892",
          "title": "chore(release): promote v2.10.6 alpha",
          "body": "## Summary\n- promote dev/v2/v2.10 to alpha after generated Buildchain evidence dirty-guard fix\n- expected release line: v2.10.6-alpha.1\n\n## Validation\n- PR checks and alpha ref promotion will validate release candidate reuse and publish gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:16:45Z",
          "mergedAt": "2026-07-08T14:19:02Z",
          "additions": 24,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 89,
          "url": "https://github.com/kungfu-systems/kfd/pull/89",
          "title": "feat(kfd): generalize KFD-2 trust assessment",
          "body": "## Summary\n- add generic KFD-2 trust-claims and trust-assessment schemas\n- dogfood KFD-2 by assessing KFD-1, KFD-3, and KFD-4 package claims\n- rename authoritative decision files to decisions/KFD-N.md and usage docs to docs/KFD-N-usage.md\n- update standards metadata, witnesses, site bundle, package exports, and release impact\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:17:45Z",
          "mergedAt": "2026-07-08T14:19:04Z",
          "additions": 2459,
          "deletions": 348,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 895,
          "url": "https://github.com/kungfu-systems/buildchain/pull/895",
          "title": "chore(release): sync v2.10.5 stable ancestry to alpha",
          "body": "## Summary\n- sync release/v2/v2.10 ancestry back into alpha/v2/v2.10 after v2.10.5 finalization\n- keep alpha tree unchanged at v2.10.6-alpha.0\n- unblock v2.10.6 alpha -> release PR clean merge\n\n## Validation\n- tree(HEAD) == tree(origin/alpha/v2/v2.10)\n- origin/release/v2/v2.10 is an ancestor of HEAD\n- origin/alpha/v2/v2.10 is an ancestor of HEAD\n- node --test tests/promote-buildchain-ref.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:26:25Z",
          "mergedAt": "2026-07-08T14:28:14Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 38,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/38",
          "title": "fix(site): render Buildchain badges from latest release",
          "body": "## Summary\n- upgrade @kungfu-tech/buildchain from 2.10.4 to 2.10.5\n- render the Buildchain homepage badge block as markdown image badges instead of escaped README text\n- rewrite Buildchain-hosted badge image URLs to the active surface channel, including staging and preview\n- allow the frozen install step to use the same minimumReleaseAge override as the lockfile update step for fresh Buildchain releases\n\n## Verification\n- pnpm --config.minimumReleaseAge=0 run build && pnpm --config.minimumReleaseAge=0 run check\n- SITE_SURFACE_CHANNEL=staging pnpm --config.minimumReleaseAge=0 run build && SITE_SURFACE_CHANNEL=staging pnpm --config.minimumReleaseAge=0 run check\n- SITE_SURFACE_CHANNEL=preview SITE_PREVIEW_ALIAS=pr-38 pnpm --config.minimumReleaseAge=0 run build && SITE_SURFACE_CHANNEL=preview SITE_PREVIEW_ALIAS=pr-38 pnpm --config.minimumReleaseAge=0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:23:24Z",
          "mergedAt": "2026-07-08T14:29:51Z",
          "additions": 60,
          "deletions": 15,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 893,
          "url": "https://github.com/kungfu-systems/buildchain/pull/893",
          "title": "chore(release): promote v2.10.6 stable",
          "body": "## Summary\n- promote alpha/v2/v2.10 to release/v2/v2.10\n- alpha release: v2.10.6-alpha.0\n- alpha state commit: 0bbabb6688de66d467fed4637541bf01c74632d7\n\n## Evidence\n- Alpha Verify: https://github.com/kungfu-systems/buildchain/actions/runs/28949794016\n- Alpha Ref Promotion: https://github.com/kungfu-systems/buildchain/actions/runs/28949859012\n\n## Expected result\n- publish @kungfu-tech/buildchain@2.10.6\n- move v2 and v2.10 floating tags to the stable release passport commit",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:22:52Z",
          "mergedAt": "2026-07-08T14:30:04Z",
          "additions": 35,
          "deletions": 16,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 91,
          "url": "https://github.com/kungfu-systems/kfd/pull/91",
          "title": "feat(kfd): add KFD-3 trusted value evidence",
          "body": "## Summary\n- add explicit KFD-3 valueEvidence to the collaboration interface and witness schemas\n- dogfood KFD-3 value evidence in the KFD package collaboration interface and generated witnesses\n- link KFD-3 trusted value to the KFD-2 generic trust assessment while preserving the semantic residual-risk warning\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:29:45Z",
          "mergedAt": "2026-07-08T14:31:01Z",
          "additions": 557,
          "deletions": 98,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 411,
          "url": "https://github.com/kungfu-systems/kungfu/pull/411",
          "title": "feat(storage): add manifest sync root verification",
          "body": "## Summary\n- add manifest-scoped kungfu.sync-root/v1 commitments for Atlas import manifests\n- verify sync roots in storage fsck and expose roots from import/status/export metadata\n- document ADR-0030 and storage-service semantics\n\n## Verification\n- ./kungfu-code fix\n- ./kungfu-code build\n- ./kungfu-code check\n- PYTHONPATH=framework/core/build/Release:framework/core/src/python uv run --project framework/core pytest framework/core/tests/python/test_atlas_storage.py\n- temp Atlas 3d import/fsck/export smoke plus deleted-sync_root failure smoke",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:34:26Z",
          "mergedAt": "2026-07-08T14:34:32Z",
          "additions": 334,
          "deletions": 17,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 92,
          "url": "https://github.com/kungfu-systems/kfd/pull/92",
          "title": "feat(kfd): expose decision usage pages in site bundle",
          "body": "## Summary\n- add `decisionUsagePattern` and `decisionPages.usagePages` to the generated site bundle\n- map every registry decision page `/N` to its usage child page `/N/usage` backed by `docs/KFD-N-usage.md`\n- enforce the mapping in `scripts/check.mjs` and record the additive site-bundle impact\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:38:21Z",
          "mergedAt": "2026-07-08T14:40:31Z",
          "additions": 194,
          "deletions": 63,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 897,
          "url": "https://github.com/kungfu-systems/buildchain/pull/897",
          "title": "fix(promote): resume published stable finalization",
          "body": "## Summary\n- resume durable stable release transactions even after alpha/dev have advanced to the next alpha\n- keep stable finalization reruns bound to the persisted release-state version and exact tag\n- add regression coverage for published stable finalization after alpha advancement\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:43:34Z",
          "mergedAt": "2026-07-08T14:46:15Z",
          "additions": 214,
          "deletions": 61,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 898,
          "url": "https://github.com/kungfu-systems/buildchain/pull/898",
          "title": "chore(release): promote dev to alpha v2.10.7",
          "body": "## Summary\n- Promote the current dev/v2/v2.10 line to alpha after stable finalization resume fix.\n- Expected Buildchain version: v2.10.7-alpha.0.\n\n## Verification\n- PR checks and Buildchain promotion gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:47:23Z",
          "mergedAt": "2026-07-08T14:49:10Z",
          "additions": 214,
          "deletions": 61,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 899,
          "url": "https://github.com/kungfu-systems/buildchain/pull/899",
          "title": "chore(release): sync stable ancestry to alpha",
          "body": "## Summary\n- Synchronize release/v2/v2.10 ancestry into alpha/v2/v2.10 before the next stable promotion.\n- Keep the alpha tree unchanged so v2.10.7-alpha.0 remains the candidate material.\n\n## Verification\n- Git merge uses the alpha tree with release/v2/v2.10 as ancestry only.\n- PR checks must pass before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:53:23Z",
          "mergedAt": "2026-07-08T14:55:28Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 93,
          "url": "https://github.com/kungfu-systems/kfd/pull/93",
          "title": "chore(kfd): anchor alpha 20 version",
          "body": "## Summary\n- bump the anchored KFD npm version from 1.0.0-alpha.19 to 1.0.0-alpha.20\n- regenerate KFD release trust evidence and witnesses for the new package/release-anchor hashes\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:56:11Z",
          "mergedAt": "2026-07-08T14:58:44Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 94,
          "url": "https://github.com/kungfu-systems/kfd/pull/94",
          "title": "release(kfd): promote alpha 20",
          "body": "## Summary\n- promote dev/v1/v1.0 to alpha/v1/v1.0 for KFD alpha.20\n- publish @kungfu-tech/kfd@1.0.0-alpha.20 via Buildchain trusted publishing\n\n## Verification\n- dev PR #93 checks passed before promotion\n- KFD main workspace fast-forwarded to dev/v1/v1.0 after PR #93\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:59:15Z",
          "mergedAt": "2026-07-08T15:00:40Z",
          "additions": 4351,
          "deletions": 377,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 900,
          "url": "https://github.com/kungfu-systems/buildchain/pull/900",
          "title": "chore(release): promote alpha to stable v2.10.7",
          "body": "## Summary\n- Promote the v2.10.7 alpha line to stable.\n- Expected stable version: v2.10.7.\n\n## Verification\n- v2.10.7-alpha.1 published successfully.\n- PR checks and Buildchain release promotion gates.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-08T14:59:04Z",
          "mergedAt": "2026-07-08T15:02:35Z",
          "additions": 225,
          "deletions": 72,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 412,
          "url": "https://github.com/kungfu-systems/kungfu/pull/412",
          "title": "feat(core): switch fast hashing to XXH3",
          "body": "## Summary\\n- replace the runtime fast hash implementation with xxhash/0.8.3 XXH3_64 and XXH3_128\\n- remove the retired pre-v4 hash implementation from active source\\n- expose fast-hash algorithm metadata in Python and Node bindings\\n- add ADR-0031 and fast-hash tests\\n\\n## Validation\\n- ./kungfu-code fix\\n- ./kungfu-code build\\n- ./kungfu-code check\\n- PYTHONPATH=framework/core/build/Release:framework/core/src/python uv run --project framework/core pytest framework/core/tests/python/test_fast_hash.py\\n- node binding smoke for FAST_HASH_ALGORITHM, hash64, and 128-bit hex",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:02:58Z",
          "mergedAt": "2026-07-08T15:03:04Z",
          "additions": 273,
          "deletions": 487,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 96,
          "url": "https://github.com/kungfu-systems/kfd/pull/96",
          "title": "docs(kfd): clarify KFD-4 gate boundary",
          "body": "## Summary\n- clarify that KFD-4 gates perspective-bearing timeline/history/replay/sync views only\n- separate KFD package interface proof from adopter runtime timeline correctness proof\n- add a compatible optional viewSubject field to the KFD-4 observer-perspective schema\n- refresh KFD-1/2/3 generated evidence and site bundle\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:11:18Z",
          "mergedAt": "2026-07-08T15:12:51Z",
          "additions": 178,
          "deletions": 104,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 98,
          "url": "https://github.com/kungfu-systems/kfd/pull/98",
          "title": "chore(kfd): anchor alpha 21 version",
          "body": "## Summary\n- bump KFD npm/release anchor to 1.0.0-alpha.21\n- refresh generated release trust and witness evidence\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:15:25Z",
          "mergedAt": "2026-07-08T15:16:54Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 99,
          "url": "https://github.com/kungfu-systems/kfd/pull/99",
          "title": "release(kfd): promote alpha 21",
          "body": "## Summary\n- promote dev/v1/v1.0 to alpha/v1/v1.0 for KFD alpha.21\n- publish @kungfu-tech/kfd@1.0.0-alpha.21 via Buildchain trusted publishing\n\n## Verification\n- KFD-4 PR #96 checks passed and merged\n- alpha.21 version anchor PR #98 checks passed and merged\n- KFD main workspace fast-forwarded to dev/v1/v1.0 after PR #98\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:17:25Z",
          "mergedAt": "2026-07-08T15:18:58Z",
          "additions": 203,
          "deletions": 129,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 901,
          "url": "https://github.com/kungfu-systems/buildchain/pull/901",
          "title": "fix(web-surface): support release app handoff",
          "body": "## Summary\n- add first-class GitHub App token support for web-surface production release PR handoff\n- upgrade @kungfu-tech/kfd to 1.0.0-alpha.21 and expose foundation KFD-2 trust claims/assessment APIs and CLI commands\n- refresh Buildchain site/KFD facts and tests\n\n## Verification\n- pnpm run check\n- node bin/buildchain.mjs kfd 2 trust-claims --json\n- npm view @kungfu-tech/kfd@alpha version --registry=https://registry.npmjs.org/",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:22:08Z",
          "mergedAt": "2026-07-08T15:24:12Z",
          "additions": 380,
          "deletions": 52,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 902,
          "url": "https://github.com/kungfu-systems/buildchain/pull/902",
          "title": "release: promote v2.10.8 alpha",
          "body": "## Summary\nPromote dev/v2/v2.10 to alpha for Buildchain v2.10.8.\n\nIncludes:\n- web-surface GitHub App production release PR token support\n- @kungfu-tech/kfd@1.0.0-alpha.21 upgrade\n- first-class KFD-2 foundation trust claims and trust assessment APIs/CLI\n\n## Verification\n- PR #901 checks passed\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:24:42Z",
          "mergedAt": "2026-07-08T15:26:27Z",
          "additions": 380,
          "deletions": 52,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 413,
          "url": "https://github.com/kungfu-systems/kungfu/pull/413",
          "title": "feat(kfd): adopt buildchain managed layout",
          "body": "## Summary\n- upgrade @kungfu-tech/buildchain to 2.10.7 across the workspace, SDK, and artifact package\n- migrate Buildchain-owned repo files into .buildchain/ and use .buildchain/kfd/kfd-3-surfaces.json as the KFD-3 source of truth\n- switch Kungfu KFD query code to the Buildchain 2.10.7 kfd namespace and refresh SDK/product KFD projections\n\n## Validation\n- ./kungfu-code sync\n- ./kungfu-code kfd:buildchain -- --json\n- ./kungfu-code kfd:buildchain:check -- --json\n- ./kungfu-code exec buildchain kfd status --json\n- node --test developer/sdk/tests/contract-cli.test.mjs\n- node --test artifact/scripts/product.test.mjs\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:26:40Z",
          "mergedAt": "2026-07-08T15:27:37Z",
          "additions": 144,
          "deletions": 104,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 903,
          "url": "https://github.com/kungfu-systems/buildchain/pull/903",
          "title": "release: promote v2.10.8 stable",
          "body": "Promote Buildchain v2.10.8 from alpha to stable.\n\n- Source: alpha/v2/v2.10 at v2.10.8-alpha.1\n- Includes GitHub App production release PR token support in web-surface reusable workflow\n- Includes KFD alpha.21 upgrade with KFD-2 trust claims/assessment APIs and CLI surfaces\n\nValidation before alpha:\n- pnpm run check\n- node --test tests/build-surface.test.mjs\n- node --test tests/kfd3-surface-register.test.mjs\n- buildchain kfd 2 trust-claims --json\n- buildchain kfd 2 trust-assessment --json",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:31:41Z",
          "mergedAt": "2026-07-08T15:33:48Z",
          "additions": 390,
          "deletions": 62,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 414,
          "url": "https://github.com/kungfu-systems/kungfu/pull/414",
          "title": "feat(storage): move atlas integrity checks into core",
          "body": "## Summary\n- add a C++ yijinjing storage sync-root surface for Atlas import manifests\n- expose runtime bindings for sync-root computation, sync-root verification, and payload reference verification\n- route the Python Atlas storage adapter through the C++ core surface while keeping existing CLI behavior stable\n\n## Validation\n- ./kungfu-code fix\n- ./kungfu-code build\n- PYTHONPATH=framework/core/build/Release:framework/core/src/python uv run --project framework/core pytest framework/core/tests/python/test_atlas_storage.py framework/core/tests/python/test_content_hash.py\n- ./kungfu-code check\n- dogfood: temp KF_HOME/KF_CONFIG_HOME import Atlas last 3 days, storage status/fsck/export, atlas verify; fsck/verify ok, export 156 records\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:36:12Z",
          "mergedAt": "2026-07-08T15:37:01Z",
          "additions": 347,
          "deletions": 56,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 415,
          "url": "https://github.com/kungfu-systems/kungfu/pull/415",
          "title": "feat(kfd): expose standard coverage in sdk",
          "body": "## Summary\n- upgrade Buildchain consumers to 2.10.8 and align the KFD metadata package to alpha.21 for KFD-4 schemas\n- add SDK/installed CLI KFD standard entrypoints for KFD-1, KFD-2, and KFD-4 while preserving the existing KFD-3 query behavior\n- regenerate Buildchain KFD evidence and SDK aggregate facts so packaged Kungfu exposes KFD-1/2/3/4 support\n\n## Validation\n- ./kungfu-code sync\n- ./kungfu-code kfd:buildchain -- --json\n- ./kungfu-code kfd:buildchain:check -- --json\n- ./kungfu-code exec buildchain kfd status --json\n- ./kungfu-code exec buildchain kfd 4 schema --json\n- node --test developer/sdk/tests/contract-cli.test.mjs\n- node --test artifact/scripts/product.test.mjs\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:59:18Z",
          "mergedAt": "2026-07-08T16:00:08Z",
          "additions": 646,
          "deletions": 73,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 40,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/40",
          "title": "feat(site): render KFD usage pages",
          "body": "## Summary\n- update @kungfu-tech/kfd to 1.0.0-alpha.21 and @kungfu-tech/buildchain to 2.10.8\n- render KFD usage child pages from the KFD site bundle at /kfd/N/usage/ and /N/usage/\n- wire Buildchain production release PR GitHub App inputs into the reusable workflow\n\n## Verification\n- pnpm run build\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T16:09:52Z",
          "mergedAt": "2026-07-08T16:16:37Z",
          "additions": 144,
          "deletions": 27,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 43,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/43",
          "title": "fix(site): clarify KFD usage navigation",
          "body": "## Summary\n- add usage links to KFD decision section navigation\n- only expand the Usage child item in the KFD global nav when the rendered page is a usage page\n- strengthen checks for usage navigation placement and visible Usage sections headings\n\n## Verification\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T22:25:53Z",
          "mergedAt": "2026-07-08T22:30:40Z",
          "additions": 68,
          "deletions": 17,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 416,
          "url": "https://github.com/kungfu-systems/kungfu/pull/416",
          "title": "feat(kfd): complete buildchain kfd 1 2 support",
          "body": "## Summary\n- persist Buildchain KFD-1 witness, release gate, and verify result into .buildchain and the SDK package\n- persist KFD-2 canonical release claims plus per-claim Buildchain projections into .buildchain and the SDK package\n- expose kungfu sdk kfd 1 gate/verify and make kfd 2 claims return the packaged release-claim documents\n- extend KFD evidence checks to cover the new KFD-1/2 files\n\n## Validation\n- ./kungfu-code kfd:buildchain -- --json\n- ./kungfu-code kfd:buildchain:check -- --json\n- node --test developer/sdk/tests/contract-cli.test.mjs\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T22:32:40Z",
          "mergedAt": "2026-07-08T22:33:38Z",
          "additions": 2364,
          "deletions": 19,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 417,
          "url": "https://github.com/kungfu-systems/kungfu/pull/417",
          "title": "feat(storage): add generic source service",
          "body": "## Summary\n- add a C++ generic storage source service for source records, import manifests, accepted ranges, payload/schema inventories, bundle export, and manifest fsck\n- wire Python source/storage services and CLI commands for source-scoped status/fsck/export/import while keeping Atlas compatibility\n- make Atlas sync accept generic storage manifests and mirror payloads into the generic payload store\n- document ADR-0032 and update the runtime storage service plan\n\n## Validation\n- ./kungfu-code fix\n- PYTHONPATH=framework/core/build/Release:framework/core/src/python uv run --project framework/core pytest framework/core/tests/python/test_atlas_storage.py\n- ./kungfu-code check\n- ./kungfu-code build\n- dogfood: source add/sync Atlas last 3 days, storage fsck all, source export jsonl/bundle, bundle import into a second temp runtime, fsck imported source",
          "author": "dongkeren",
          "createdAt": "2026-07-08T22:37:28Z",
          "mergedAt": "2026-07-08T22:37:59Z",
          "additions": 1331,
          "deletions": 54,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 44,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/44",
          "title": "Release production from e0b9ea8351a2",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `e0b9ea8351a2f95bcfde83fabcec61a7c696a872`\n- Artifact hash: `ac8c960f58940b09ec909dd6d948de0d4dd7c2266a4fefac68dc27df83cdec5a`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/28980260526)\n- Required label: `buildchain-release`\n- Release branch: `release/production-e0b9ea8351a2`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-08T22:35:19Z",
          "mergedAt": "2026-07-08T23:01:31Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 418,
          "url": "https://github.com/kungfu-systems/kungfu/pull/418",
          "title": "refactor(kfd): remove legacy kfd 1 2 helpers",
          "body": "## Summary\n- remove unused legacy KFD-1 support summary helper\n- remove unused legacy KFD-2 claim summary helper\n- keep Buildchain-native KFD-1 witness/gate/verify and KFD-2 packaged claims behavior unchanged\n\n## Validation\n- node --check developer/sdk/src/sdk.js\n- node developer/sdk/src/sdk.js kfd 1 witness/gate/verify --json\n- node developer/sdk/src/sdk.js kfd 2 claims --json\n- ./kungfu-code kfd:buildchain:check -- --json\n- node --test developer/sdk/tests/contract-cli.test.mjs\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T23:01:58Z",
          "mergedAt": "2026-07-08T23:02:43Z",
          "additions": 0,
          "deletions": 61,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 904,
          "url": "https://github.com/kungfu-systems/buildchain/pull/904",
          "title": "feat(kfd): aggregate upstream KFD facts",
          "body": "## Summary\n\n- add first-class KFD upstream aggregate collection/check APIs and CLI commands\n- dogfood Buildchain's upstream KFD aggregate with `@kungfu-tech/kfd` as the standard/schema provider\n- export the aggregate through the generated site bundle and KFD claim registry\n- document upstream KFD aggregation and the runtime-dependency boundary for `@kungfu-tech/kfd`\n\n## Dependency note\n\n`@kungfu-tech/kfd` stays in `dependencies`, not `devDependencies`, because Buildchain's runtime KFD surfaces resolve KFD standards/schemas/taxonomy from the package at runtime.\n\n## Verification\n\n- `node --test tests/kfd3-surface-register.test.mjs`\n- `node --test tests/readme-badges.test.mjs`\n- `node bin/buildchain.mjs kfd upstream check --json | jq '{ok,status,issues}'`\n- `corepack pnpm@11.7.0 run check`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T23:03:03Z",
          "mergedAt": "2026-07-08T23:07:20Z",
          "additions": 888,
          "deletions": 35,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 89,
          "url": "https://github.com/kungfu-systems/libnode/pull/89",
          "title": "chore(release): publish libnode 22.22.3-kf.3-alpha.17",
          "body": "Publish libnode alpha 17 through the Buildchain v2 publish gate.\n\n- Bumps package.json and libnode.release.json to 22.22.3-kf.3-alpha.17\n- Uses the stable Buildchain @v2 workflows already declared in the repository\n- Expects the PR-stage Build workflow to produce the release-candidate artifacts before promotion\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T22:40:20Z",
          "mergedAt": "2026-07-08T23:15:49Z",
          "additions": 16,
          "deletions": 16,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 419,
          "url": "https://github.com/kungfu-systems/kungfu/pull/419",
          "title": "feat(storage): add maintenance sync ops",
          "body": "## Summary\n- add storage maintenance operations for the generic source service: status/fsck expansion, projection rebuild, dry-run gc/compact planning, and local sync verification\n- expose the maintenance surface through `kungfu storage ...` CLI commands and KFD-3 adjacent-agent command metadata\n- document the first safe maintenance/sync-readiness slice in `docs/runtime-storage-service.md`\n\n## Validation\n- `./kungfu-code check`\n- `./kungfu-code build`\n- `./kungfu-code --dir framework/core exec env PYTHONPATH=build/Release:src/python uv run --frozen pytest tests/python/test_atlas_storage.py` (`13 passed`)\n- frozen CLI smoke using `/Users/dkr/Code/atlas` as an Atlas source with `--since 3d`: sync/status/fsck/gc/compact/rebuild-index/verify-sync all passed; sync roots matched\n- `./kungfu-code kfd:buildchain` (`48 KFD-3 surface(s)`)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T23:18:52Z",
          "mergedAt": "2026-07-08T23:19:26Z",
          "additions": 1057,
          "deletions": 30,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 906,
          "url": "https://github.com/kungfu-systems/buildchain/pull/906",
          "title": "feat(kfd): infer upstream roles",
          "body": "## Summary\n- make KFD upstream roles Buildchain-managed and inferred from package identity/evidence\n- add `buildchain kfd upstream roles --json` and public Node API registry\n- allow auto-discovery from devDependencies so consumers do not duplicate semver or role facts\n- update KFD docs with first-use guidance for upstream aggregation, dependency placement, optional KFD state hints, and role fail-closed policy\n\n## Verification\n- `node --test tests/kfd3-surface-register.test.mjs tests/public-surface-audit.test.mjs`\n- `corepack pnpm@11.7.0 run generate:site`\n- `corepack pnpm@11.7.0 run check:site`\n- `corepack pnpm@11.7.0 run check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-08T23:29:46Z",
          "mergedAt": "2026-07-08T23:31:25Z",
          "additions": 446,
          "deletions": 53,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 1,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/1",
          "title": "docs(paper): declare Kungfu Origin publishing identity",
          "body": "## Summary\n\n- declare Kungfu Origin Technology Limited as the paper publishing identity\n- add Keren Dong contact email to README, security, issue contact, and paper author metadata\n- keep kungfu-systems only as the GitHub organization / repository naming surface\n\n## Checks\n\n- [x] make check\n- [x] make pdf\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs.\n- [x] No unpublished reviewer correspondence or private operational data.\n- [x] Provider/API/data claims are sourced or clearly marked as future work.\n- [x] Public branding and trademark language stays factual.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T23:32:17Z",
          "mergedAt": "2026-07-08T23:32:45Z",
          "additions": 25,
          "deletions": 20,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 907,
          "url": "https://github.com/kungfu-systems/buildchain/pull/907",
          "title": "fix(release): create public package release tag",
          "body": "## Summary\n- create the public package GitHub Release tag after release transaction finalization when it differs from the internal exact transaction tag\n- keep internal exact tags unchanged for Buildchain recovery/audit\n- add anchored package test coverage proving v<publishedVersion> is created\n\nFixes #905.\n\n## Verification\n- `node --test tests/promote-buildchain-ref.test.mjs`\n- `corepack pnpm@11.7.0 --filter \"./actions/promote-buildchain-ref\" build`\n- `corepack pnpm@11.7.0 run check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-08T23:37:16Z",
          "mergedAt": "2026-07-08T23:39:17Z",
          "additions": 58,
          "deletions": 47,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 45,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/45",
          "title": "fix(site): hide KFD machine facts from homepage",
          "body": "## Summary\n- remove KFD machine facts from the human homepage\n- keep KFD source facts in machine-readable manifests\n- align KFD decision card actions so Usage notes sits apart from the read link\n\n## Verification\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T23:47:00Z",
          "mergedAt": "2026-07-08T23:58:57Z",
          "additions": 24,
          "deletions": 33,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 420,
          "url": "https://github.com/kungfu-systems/kungfu/pull/420",
          "title": "feat(storage): add runtime service API surface",
          "body": "## Summary\n- Add the libkungfu runtime storage service request/capabilities surface for status, fsck, export, import, rebuild, gc, compact, and sync verification operations.\n- Expose the surface through the Python runtime binding and route the existing Python storage operations through it while preserving the current backend and output schemas.\n- Document the storage layering rule and add tests proving Python storage commands enter the C++ service surface.\n\n## Validation\n- `./kungfu-code fix`\n- `./kungfu-code check`\n- `PYTHONPATH=\"$PWD/src/python:$PWD/build/Release\" DYLD_FALLBACK_LIBRARY_PATH=\"$PWD/build/Release${DYLD_FALLBACK_LIBRARY_PATH:+:$DYLD_FALLBACK_LIBRARY_PATH}\" uv run --frozen pytest tests/python/test_atlas_storage.py` from `framework/core` (`15 passed`)\n- `./kungfu-code build`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T00:01:43Z",
          "mergedAt": "2026-07-09T00:02:23Z",
          "additions": 495,
          "deletions": 1,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 908,
          "url": "https://github.com/kungfu-systems/buildchain/pull/908",
          "title": "chore(release): publish v2.10.9-alpha.1",
          "body": "## Summary\n- Promote current dev/v2/v2.10 into alpha/v2/v2.10.\n- Includes #906 KFD upstream role inference and #907 public package GitHub Release tag creation.\n\n## Release intent\n- Channel: alpha/v2/v2.10\n- Expected next alpha: v2.10.9-alpha.1\n- Stable release will follow through alpha/v2/v2.10 -> release/v2/v2.10 after alpha promotion succeeds.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-09T00:04:46Z",
          "mergedAt": "2026-07-09T00:07:19Z",
          "additions": 1339,
          "deletions": 82,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 46,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/46",
          "title": "Release production from 8652822cbc1e",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `8652822cbc1e002df44ea95ce68be413d978a8d6`\n- Artifact hash: `6200c6b19ef057503ed2f147fb60fc17fe06380b832192dc78f37efcf75f00c3`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/28984087447)\n- Required label: `buildchain-release`\n- Release branch: `release/production-8652822cbc1e`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-09T00:03:30Z",
          "mergedAt": "2026-07-09T00:08:25Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 910,
          "url": "https://github.com/kungfu-systems/buildchain/pull/910",
          "title": "fix(release): include KFD upstream aggregate in version state",
          "body": "## Summary\n- include dist/site/kfd-upstream-aggregate.json in Buildchain's declared version-state files\n- update the version-state contract test so release verification allows the generated KFD upstream aggregate version projection\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs tests/build-surface.test.mjs\n- pnpm run check\n\nFixes the alpha promotion failure in run https://github.com/kungfu-systems/buildchain/actions/runs/28984478250 where version verification rejected dist/site/kfd-upstream-aggregate.json.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T00:14:10Z",
          "mergedAt": "2026-07-09T00:16:05Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 912,
          "url": "https://github.com/kungfu-systems/buildchain/pull/912",
          "title": "chore(release): publish v2.10.9-alpha.1",
          "body": "## Summary\n- promote current dev/v2/v2.10 to alpha/v2/v2.10 after fixing version-state verification for the KFD upstream aggregate site fact\n- retries the alpha release that previously failed in Buildchain Ref Promotion run https://github.com/kungfu-systems/buildchain/actions/runs/28984478250\n\n## Included since previous alpha channel head\n- #910 fix(release): include KFD upstream aggregate in version state\n\n## Expected result\n- publish next alpha for the v2.10 line via Buildchain Ref Promotion\n- keep publish-gate source lock and promote-only RC semantics intact",
          "author": "dongkeren",
          "createdAt": "2026-07-09T00:16:39Z",
          "mergedAt": "2026-07-09T00:18:27Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 913,
          "url": "https://github.com/kungfu-systems/buildchain/pull/913",
          "title": "chore(release): publish v2.10.9",
          "body": "## Summary\n- promote alpha/v2/v2.10 to release/v2/v2.10 for Buildchain v2.10.9\n- alpha evidence: v2.10.9-alpha.1 published from #912 / run https://github.com/kungfu-systems/buildchain/actions/runs/28984940441\n\n## Included changes since v2.10.8\n- #901 release App handoff support\n- #904 KFD upstream aggregate facts\n- #906 managed KFD upstream role inference\n- #907 public package GitHub Release tag semantics\n- #910 version-state declaration for KFD upstream aggregate site facts\n\n## Expected result\n- publish @kungfu-tech/buildchain@2.10.9 to npm latest\n- create/update GitHub Release v2.10.9 with Buildchain release passport assets\n- prepare the next alpha state for the v2.10 line",
          "author": "dongkeren",
          "createdAt": "2026-07-09T00:22:25Z",
          "mergedAt": "2026-07-09T00:24:11Z",
          "additions": 1355,
          "deletions": 92,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 421,
          "url": "https://github.com/kungfu-systems/kungfu/pull/421",
          "title": "feat(storage): move file provider into runtime service",
          "body": "## Summary\n- move the generic content-addressed file storage provider into libkungfu runtime storage service\n- keep Python storage APIs as compatibility shims over the C++ service\n- expose direct Python bindings for runtime operations, manifest accept/load, record export, and payload writes\n- update storage tests and docs for the C++ file provider\n\n## Validation\n- ./kungfu-code fix\n- ./kungfu-code build:core\n- PYTHONPATH=\"/Users/dkr/Worktrees/kungfu/feature/storage-cpp-file-provider/src/python:/Users/dkr/Worktrees/kungfu/feature/storage-cpp-file-provider/build/Release\" DYLD_FALLBACK_LIBRARY_PATH=\"/Users/dkr/Worktrees/kungfu/feature/storage-cpp-file-provider/build/Release${DYLD_FALLBACK_LIBRARY_PATH:+:}\" uv run --frozen pytest tests/python/test_atlas_storage.py\n- ./kungfu-code check\n- ./kungfu-code build",
          "author": "dongkeren",
          "createdAt": "2026-07-09T00:33:17Z",
          "mergedAt": "2026-07-09T00:34:43Z",
          "additions": 1112,
          "deletions": 536,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 914,
          "url": "https://github.com/kungfu-systems/buildchain/pull/914",
          "title": "fix(web-surface): use app client id for release PR token",
          "body": "## Summary\n- add `production-release-app-client-id` as the first-class web-surface release PR GitHub App input\n- keep `production-release-app-id` as a deprecated input-name alias while passing the selected value through `client-id`\n- pin `actions/create-github-app-token` to v3.1.1 and refresh generated site bundle/docs/tests\n\n## Validation\n- `pnpm run check`\n\nCloses #911",
          "author": "dongkeren",
          "createdAt": "2026-07-09T00:37:25Z",
          "mergedAt": "2026-07-09T00:39:07Z",
          "additions": 41,
          "deletions": 26,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 7,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/7",
          "title": "feat(tap): prepare kungfu gui cask publication",
          "body": "## Summary\n- add a planned `kungfu` cask entry without exposing an installable cask yet\n- teach the managed updater and tap checker to project and verify formula and cask entries from upstream release passports\n- document the Kungfu GUI App cask materialization path and refresh tap-local KFD witnesses\n- accept the current Buildchain `@v2` contract lock after verifying the surface set stayed closed-world and lifecycle verify passes\n\n## Validation\n- `node --check scripts/update-managed-products.mjs`\n- `node --check scripts/check-tap.mjs`\n- `node --check scripts/update-kfd-witnesses.mjs`\n- `node scripts/update-kfd-witnesses.mjs`\n- `node scripts/check-tap.mjs`\n- `git diff --check`\n- `buildchain validate --require-lifecycle-stages verify`\n- `buildchain lifecycle run verify --required`\n- dry-run materialization of `package=kungfu` from a data URL release passport\n- `node scripts/update-managed-products.mjs --json --update-lock` confirms the refreshed Buildchain lock is compatible\n\n## Notes\nThe current upstream Buildchain formula has a newer release available, but this PR intentionally does not update `Formula/buildchain.rb`; managed product propagation remains a separate automation concern.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T00:43:59Z",
          "mergedAt": "2026-07-09T00:45:33Z",
          "additions": 582,
          "deletions": 156,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 422,
          "url": "https://github.com/kungfu-systems/kungfu/pull/422",
          "title": "feat(storage): expose runtime service to node",
          "body": "## Summary\n- expose libkungfu runtime storage service operations through the Node native binding and @kungfu-tech/core\n- add Node/Python parity coverage over the same C++ storage service fixture\n- add runtime-greenfield ownership checks and docs clarifying Python/Node are storage shims\n\n## Validation\n- ./kungfu-code check\n- ./kungfu-code build:core\n- KUNGFU_REQUIRE_NATIVE=1 KUNGFU_DIR=\"/Users/dkr/Worktrees/kungfu/feature/storage-node-binding-provider-cleanup/framework/core/dist/kungfu\" pnpm --filter @kungfu-tech/core run test:storage-binding\n- node tests/fixtures/storage-demo-node-binding/run.mjs\n- ./kungfu-code build",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:00:28Z",
          "mergedAt": "2026-07-09T01:00:49Z",
          "additions": 464,
          "deletions": 2,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 915,
          "url": "https://github.com/kungfu-systems/buildchain/pull/915",
          "title": "feat(publication): add publication artifact workflow",
          "body": "## Summary\n- add first-class publication-artifact project support for paper/report repositories\n- add publication artifact CLI, Node API, reusable workflow, fixture, docs, and site bundle metadata\n- make the publication reusable workflow enforce trusted buildchain-ref override semantics and contract-lock checks before build work\n\n## Validation\n- node scripts/generate-site-bundle.mjs\n- node --test tests/publication-artifact.test.mjs tests/buildchain-config.test.mjs tests/build-surface.test.mjs tests/cli.test.mjs\n- bash scripts/check-workflows.sh\n- pnpm run check\n\n## Release note\nThis branch is based on dev/v2/v2.10 after PR #914, so the #911 fix is included in the next release promotion from this line.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:05:03Z",
          "mergedAt": "2026-07-09T01:07:03Z",
          "additions": 1574,
          "deletions": 159,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 916,
          "url": "https://github.com/kungfu-systems/buildchain/pull/916",
          "title": "release: promote dev v2.10 to alpha",
          "body": "## Summary\nPromote dev/v2/v2.10 to alpha/v2/v2.10.\n\nIncluded changes:\n- #914 fixes web-surface GitHub App release PR token client id handling (#911)\n- #915 adds first-class publication artifact workflow support\n\n## Validation\n- dev PR checks passed before merge\n- channel promotion checks will run on this PR",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:07:41Z",
          "mergedAt": "2026-07-09T01:09:24Z",
          "additions": 1609,
          "deletions": 179,
          "changedFiles": 42
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 917,
          "url": "https://github.com/kungfu-systems/buildchain/pull/917",
          "title": "release: promote alpha v2.10 to stable",
          "body": "## Summary\nPromote alpha/v2/v2.10 to release/v2/v2.10.\n\nIncluded changes:\n- #914 fixes web-surface GitHub App release PR token client id handling (#911)\n- #915 adds first-class publication artifact workflow support\n- alpha publication succeeded as @kungfu-tech/buildchain@2.10.10-alpha.1\n\n## Validation\n- alpha PR #916 checks passed\n- Buildchain Ref Promotion run 28986930759 succeeded\n- stable channel checks will run on this PR",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:13:09Z",
          "mergedAt": "2026-07-09T01:15:11Z",
          "additions": 1620,
          "deletions": 190,
          "changedFiles": 43
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 423,
          "url": "https://github.com/kungfu-systems/kungfu/pull/423",
          "title": "feat(product): add cli product artifacts",
          "body": "## Summary\n- rename the dogfood product assembly package from artifact/ to product/ and update workspace, docs, Buildchain artifact paths, and KFD evidence\n- keep desktop installer output under product/release/desktop and add a CLI archive product under product/release/cli\n- expose kungfu sdk product cli dist for product assembly packages and add KFD-3 surfaces for CLI product build/query\n\n## Validation\n- ./kungfu-code check\n- ./kungfu-code kfd:buildchain:check\n- ./kungfu-code kfd2:claims:check\n- ./kungfu-code check:types\n- node --test product/scripts/product.test.mjs\n- node --test developer/sdk/tests/contract-cli.test.mjs\n- ./kungfu-code dist:cli (produced product/release/cli/kungfu-cli-darwin-arm64.tar.gz, 57M)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:32:20Z",
          "mergedAt": "2026-07-09T01:33:23Z",
          "additions": 864,
          "deletions": 256,
          "changedFiles": 41
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 47,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/47",
          "title": "ci(site): use Buildchain release app client id",
          "body": "## Summary\n- switch the Buildchain web-surface workflow to `production-release-app-client-id`\n- add/use the `KUNGFU_RELEASE_APP_CLIENT_ID` repository variable for the release GitHub App client id\n\n## Verification\n- `pnpm run build && pnpm run check`\n\n## Notes\n- Follows Buildchain v2.10.10 fixing kungfu-systems/buildchain#911.\n- The deprecated numeric app id variable is left in place for rollback/compatibility, but the workflow no longer consumes it.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:44:22Z",
          "mergedAt": "2026-07-09T01:48:58Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 424,
          "url": "https://github.com/kungfu-systems/kungfu/pull/424",
          "title": "feat(storage): add rocksdb payload provider",
          "body": "## Summary\n- add a C++ storage provider abstraction with default content-addressed-file and optional RocksDB providers\n- route source registry, manifests, payload reads/writes, fsck/export/import/rebuild/gc/compact/verify through the provider surface\n- keep Node/Python as thin runtime bindings and extend parity tests across file and RocksDB providers\n- document provider-neutral storage semantics in ADR/runtime/spec docs and guard provider ownership in the runtime greenfield gate\n\n## Validation\n- ./kungfu-code fix\n- ./kungfu-code check\n- ./kungfu-code build:core\n- KUNGFU_REQUIRE_NATIVE=1 KUNGFU_DIR=\"$PWD/framework/core/dist/kungfu\" pnpm --filter @kungfu-tech/core run test:storage-binding\n- PYTHONPATH=\"$PWD/framework/core/src/python:$PWD/framework/core/dist/kungfu\" KUNGFU_DIR=\"$PWD/framework/core/dist/kungfu\" uv run --frozen --project framework/core python -m pytest framework/core/tests/python/test_atlas_storage.py\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:54:22Z",
          "mergedAt": "2026-07-09T01:55:12Z",
          "additions": 698,
          "deletions": 164,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 425,
          "url": "https://github.com/kungfu-systems/kungfu/pull/425",
          "title": "test(product): smoke CLI product install layout",
          "body": "## Summary\n- extract generated CLI archives in a temporary install layout after packaging\n- validate runtime, SDK/KFD metadata, TUI entry, first-party kfx package set, and `kungfu kfd status --json` from the extracted product\n- include the SDK runtime KFD package and module metadata in the CLI product\n\n## Validation\n- `./kungfu-code check`\n- `node --test product/scripts/archive.test.mjs product/scripts/product.test.mjs`\n- `./kungfu-code product cli dist`\n- verified `product/release/cli/kungfu-cli-darwin-arm64.tar.gz` contains runtime, SDK, KFD package, TUI, and 11 first-party kfx package manifests\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:59:40Z",
          "mergedAt": "2026-07-09T02:00:33Z",
          "additions": 443,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 91,
          "url": "https://github.com/kungfu-systems/libnode/pull/91",
          "title": "chore(release): publish libnode 22.22.3-kf.3-alpha.18",
          "body": "## Summary\n- bump libnode alpha to 22.22.3-kf.3-alpha.18\n- update Buildchain v2 contract lock to v2.10.10\n- refresh KFD witnesses for the new release manifest\n\n## Verification\n- node .gyp/libnode-release-verify.js\n- git diff --check\n- corepack pnpm verify-release\n- corepack pnpm verify-package-source\n- corepack pnpm verify-kfd-witnesses\n- Buildchain v2.10.10 contract lock check: unchanged\n\n## Purpose\nValidate Buildchain v2.10.10 public package release tag / GitHub Release / release passport fix after alpha.17 published to npm but failed release finalization.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:41:40Z",
          "mergedAt": "2026-07-09T02:15:18Z",
          "additions": 14,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 426,
          "url": "https://github.com/kungfu-systems/kungfu/pull/426",
          "title": "feat(storage): harden provider lifecycle",
          "body": "## Summary\n- make runtime storage provider selection report its source: explicit option, env, or default\n- keep RocksDB provider handles owned by the C++ provider instance and reuse them across key operations\n- expose provider runtime diagnostics while keeping Node/Python as thin bindings\n- document the provider lifecycle/config boundary in runtime storage docs and ADR-0018\n\n## Validation\n- ./kungfu-code fix\n- ./kungfu-code check\n- ./kungfu-code build:core\n- KUNGFU_REQUIRE_NATIVE=1 KUNGFU_DIR=\"/Users/dkr/Worktrees/kungfu/feature/storage-provider-lifecycle-hardening/framework/core/dist/kungfu\" pnpm --filter @kungfu-tech/core run test:storage-binding\n- PYTHONPATH=\"/Users/dkr/Worktrees/kungfu/feature/storage-provider-lifecycle-hardening/src/python:/Users/dkr/Worktrees/kungfu/feature/storage-provider-lifecycle-hardening/dist/kungfu\" KUNGFU_DIR=\"/Users/dkr/Worktrees/kungfu/feature/storage-provider-lifecycle-hardening/dist/kungfu\" uv run --frozen python -m pytest tests/python/test_atlas_storage.py\n\nNote: build:core still prints existing pybind11_stubgen docstring parsing warnings, but exits 0.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T02:48:35Z",
          "mergedAt": "2026-07-09T02:49:08Z",
          "additions": 148,
          "deletions": 30,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 920,
          "url": "https://github.com/kungfu-systems/buildchain/pull/920",
          "title": "fix(publication): pin workflow pnpm and declare toolchain evidence",
          "body": "## Summary\n\n- pin Buildchain-owned workflow pnpm activation to pnpm@11.7.0 so Corepack no longer resolves pnpm/latest\n- add first-class publication toolchain facts for custom-command and latex-docker profiles\n- record publication toolchain evidence and custom-command residual risk in publication manifests/passports\n- refresh Buildchain site bundle and generated action bundles\n\nFixes #919.\nFixes #918.\n\n## Validation\n\n- corepack pnpm@11.7.0 exec node --test tests/publication-artifact.test.mjs\n- corepack pnpm@11.7.0 exec node --test tests/buildchain-config.test.mjs\n- corepack pnpm@11.7.0 exec node --test tests/cli.test.mjs\n- corepack pnpm@11.7.0 exec node --test tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T02:44:57Z",
          "mergedAt": "2026-07-09T02:51:27Z",
          "additions": 447,
          "deletions": 117,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 921,
          "url": "https://github.com/kungfu-systems/buildchain/pull/921",
          "title": "chore(release): publish v2.10.11 alpha",
          "body": "## Summary\n\nPromote dev/v2/v2.10 to alpha/v2/v2.10 for the v2.10.11 release train.\n\nIncludes #920:\n- pinned Buildchain-owned pnpm workflow activation\n- publication-artifact toolchain evidence for custom-command and latex-docker\n\n## Validation\n\n- #920 local `corepack pnpm@11.7.0 run check` passed\n- #920 PR `check` and `libnode-shaped` CI passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T02:58:48Z",
          "mergedAt": "2026-07-09T03:02:19Z",
          "additions": 447,
          "deletions": 117,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 922,
          "url": "https://github.com/kungfu-systems/buildchain/pull/922",
          "title": "fix(release): stabilize promote dependency bootstrap",
          "body": "## Summary\n- enable Corepack pnpm shims before release-candidate promote dependency install\n- call pnpm through `corepack pnpm@11.7.0` so promotion works on Node 24 runner images\n- fall back to the checked-out source reporter if the runtime reporter path is unavailable during failure classification\n- refresh generated Buildchain contract digest\n\n## Validation\n- `node --test tests/build-surface.test.mjs`\n- `node scripts/check-inventory.mjs`\n- `pnpm run check`\n\n## Release note\nThis fixes the failed alpha promotion run 28991041859 before retrying the v2.10.11 release.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:08:41Z",
          "mergedAt": "2026-07-09T03:10:49Z",
          "additions": 16,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 427,
          "url": "https://github.com/kungfu-systems/kungfu/pull/427",
          "title": "feat(storage): add sqlite projection",
          "body": "## Summary\n- add a C++-owned storage SQLite projection at storage/projections/storage.sqlite\n- rebuild projection tables from accepted latest manifests through rebuild_index\n- report projection status/drift in status, fsck, and compact planning\n\n## Validation\n- ./kungfu-code fix\n- ./kungfu-code check\n- ./kungfu-code build:core\n- PYTHONPATH=\"/Users/dkr/Worktrees/kungfu/feature/storage-sqlite-projection-v1/src/python:/Users/dkr/Worktrees/kungfu/feature/storage-sqlite-projection-v1/dist/kungfu\" KUNGFU_DIR=\"/Users/dkr/Worktrees/kungfu/feature/storage-sqlite-projection-v1/dist/kungfu\" uv run --frozen python -m pytest tests/python/test_atlas_storage.py\n- KUNGFU_REQUIRE_NATIVE=1 KUNGFU_DIR=\"/Users/dkr/Worktrees/kungfu/feature/storage-sqlite-projection-v1/framework/core/dist/kungfu\" pnpm --filter @kungfu-tech/core run test:storage-binding",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:12:35Z",
          "mergedAt": "2026-07-09T03:13:10Z",
          "additions": 503,
          "deletions": 16,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 923,
          "url": "https://github.com/kungfu-systems/buildchain/pull/923",
          "title": "chore(release): publish v2.10.11 alpha",
          "body": "## Summary\n- Promote the latest dev/v2/v2.10 changes to alpha after fixing the release-candidate promote dependency bootstrap.\n- Includes #920 open-issue fixes and #922 release bootstrap stabilization.\n\n## Validation\n- #920 checks passed before merge.\n- #922 checks passed before merge.\n- Local validation for #922: `node --test tests/build-surface.test.mjs`, `node scripts/check-inventory.mjs`, `pnpm run check`.\n\n## Prior failed run addressed\n- Fixes the `pnpm: command not found` alpha promotion failure from run 28991041859 before retrying the alpha release.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:11:32Z",
          "mergedAt": "2026-07-09T03:13:39Z",
          "additions": 16,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 924,
          "url": "https://github.com/kungfu-systems/buildchain/pull/924",
          "title": "chore(release): promote v2.10.11 stable",
          "body": "## Summary\n- Promote Buildchain v2.10.11 from alpha to stable.\n- Alpha verification succeeded via v2.10.11-alpha.1.\n\n## Evidence\n- Alpha promotion run: https://github.com/kungfu-systems/buildchain/actions/runs/28991463403\n- Alpha GitHub Release: v2.10.11-alpha.1 (prerelease, latest=false)\n- npm alpha dist-tag: 2.10.11-alpha.1\n\n## Included fixes\n- #920 open issue fixes\n- #922 release-candidate promote pnpm bootstrap and friction reporter fallback fix",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:17:34Z",
          "mergedAt": "2026-07-09T03:19:37Z",
          "additions": 472,
          "deletions": 131,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 38,
          "url": "https://github.com/kungfu-systems/build-images/pull/38",
          "title": "feat(images): add latex pdf builder image",
          "body": "## Summary\n\n- add `latex-pdf-builder` as a child of `node24-pnpm`, preserving the Kungfu `base-linux` ancestry and non-root `kungfu` user\n- include `latexmk`, `biber`, practical TeX Live packages, `lmodern`, and `pnpm@11.7.0` from the parent image\n- add pnpm-driven PDF smoke coverage for `paper/main.tex -> _build/main.pdf`\n- open the v1.2 image-family line and document first-publish lock handling\n\n## Verification\n\n- `pnpm run check`\n- Ubuntu Docker smoke with apt cache: `base-linux -> node24-pnpm -> latex-pdf-builder`, then `pnpm run pdf` produced `_build/main.pdf` with sha256 `8ad775ded1553577feba233ce3895db32ad5e3ed3767b9fd9f23317b031a9b48`\n\nFixes #37.\nRelated: kungfu-systems/buildchain#918",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:38:57Z",
          "mergedAt": "2026-07-09T03:40:18Z",
          "additions": 172,
          "deletions": 8,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 39,
          "url": "https://github.com/kungfu-systems/build-images/pull/39",
          "title": "chore(release): promote v1.2 alpha",
          "body": "## Summary\n\nPromote the new v1.2 image-family line to alpha so Buildchain can publish `v1.2.0-alpha.0`, including the new `latex-pdf-builder` image.\n\n## Verification before promotion\n\n- PR #38 passed Verify and Consumer Smoke.\n- Ubuntu Docker smoke built `base-linux -> node24-pnpm -> latex-pdf-builder` and generated `_build/main.pdf` through `pnpm run pdf`.\n\nRelated: #37\nRelated: kungfu-systems/buildchain#918",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:40:43Z",
          "mergedAt": "2026-07-09T03:41:46Z",
          "additions": 172,
          "deletions": 8,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 428,
          "url": "https://github.com/kungfu-systems/kungfu/pull/428",
          "title": "feat(storage): add projection query API",
          "body": "## Summary\n- add C++-owned `query` storage service operation over the rebuildable SQLite projection\n- expose thin Python service and `kungfu storage query` CLI wrappers\n- register the new KFD-3 command surface and refresh Buildchain KFD evidence\n- extend Python and Node storage parity tests to cover query results\n\n## Validation\n- `./kungfu-code build:core`\n- `./kungfu-code check`\n- `PYTHONPATH=\"$PWD/src/python:$PWD/dist/kungfu\" KUNGFU_DIR=\"$PWD/dist/kungfu\" uv run --frozen python -m pytest tests/python/test_atlas_storage.py`\n- `KUNGFU_REQUIRE_NATIVE=1 KUNGFU_DIR=\"$PWD/framework/core/dist/kungfu\" pnpm --filter @kungfu-tech/core run test:storage-binding`\n- CLI smoke via `CliRunner`: `kungfu storage query --table entries --scope source --source cli-synth --json`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:46:43Z",
          "mergedAt": "2026-07-09T03:47:12Z",
          "additions": 404,
          "deletions": 18,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 102,
          "url": "https://github.com/kungfu-systems/kfd/pull/102",
          "title": "feat(kfd-1): define publication URL semantics",
          "body": "## Summary\n\n- Adds `schemas/kfd-1/publication-url-semantics.schema.json` for canonical reader URLs, latest aliases, immutable version artifact URLs, artifact digests, source coordinates, lineage, site consumption, and archive policy.\n- Registers the new interface in `standards.json`, KFD-1 docs, the generated site bundle projection, release impact metadata, and KFD-1/KFD-2/KFD-3 generated evidence surfaces.\n- Extends `scripts/check.mjs` so KFD fails closed if the new schema/interface/metadata or archive-policy constants drift.\n\n## Verification\n\n- `npm run check`\n- `git diff --check`\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org/`\n- `npx -y @kungfu-tech/buildchain@2.10.10 validate --cwd . --json`\n- `jq` spot checks for the new standards metadata and archive policy constants\n\n## Related\n\n- Resolves https://github.com/kungfu-systems/kfd/issues/101\n- Coordinates with https://github.com/kungfu-systems/buildchain/issues/925\n- Coordinates with https://github.com/kungfu-systems/site-libkungfu-dev/issues/50",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:47:42Z",
          "mergedAt": "2026-07-09T03:55:04Z",
          "additions": 523,
          "deletions": 106,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 40,
          "url": "https://github.com/kungfu-systems/build-images/pull/40",
          "title": "fix(ci): use app token for generated status checks",
          "body": "## Summary\n- grant the promotion workflow checks:write permission\n- pass github.token as the generated status check token for Buildchain protected ref updates\n- keep the promotion token path unchanged for the existing ref update flow\n\n## Verification\n- pnpm run check\n\nFollow-up for latex-pdf-builder v1.2.0-alpha.0 promotion after PR #38 and PR #39.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:53:03Z",
          "mergedAt": "2026-07-09T03:55:51Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 41,
          "url": "https://github.com/kungfu-systems/build-images/pull/41",
          "title": "chore(release): promote v1.2 ci fix to alpha",
          "body": "## Summary\n- promote the Buildchain generated status check token fix to alpha/v1/v1.2\n- retrigger Buildchain Ref Promotion for the v1.2.0-alpha.0 image publication path\n\n## Verification\n- PR #40 checks passed\n- no image contract changes beyond the already merged latex-pdf-builder release content",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:56:27Z",
          "mergedAt": "2026-07-09T03:57:23Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 51,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/51",
          "title": "feat(site): render publication archive routes",
          "body": "## Summary\n\n- add a Buildchain-shaped publication registry fixture for papers/archive route semantics\n- render /papers/** index/latest/version pages plus immutable PDF/source/passport artifact paths\n- expose publication archive facts in /manifest.json, /papers/manifest.json, /papers/registry.json, /papers/llms.txt\n- fail checks when declared immutable artifacts disappear, digest drift, or archive route semantics are missing\n\n## Scope\n\nRefs #50. This is the site-side preparation that can be implemented before Buildchain publishes the real publication registry from kungfu-systems/buildchain#925. It does not close #50 yet.\n\n## Validation\n\n- pnpm run build\n- pnpm run check\n\nNo alpha/release publication is requested in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:49:44Z",
          "mergedAt": "2026-07-09T03:59:17Z",
          "additions": 637,
          "deletions": 1,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 42,
          "url": "https://github.com/kungfu-systems/build-images/pull/42",
          "title": "fix(ci): declare Buildchain promotion bypass app",
          "body": "## Summary\n- declare github-actions as the Buildchain-managed branch protection bypass app for direct promote-buildchain-ref usage\n- pass the generated ref update token explicitly while keeping github.token for generated status checks\n\n## Verification\n- pnpm run check\n\nThis follows the Buildchain direct-caller guidance for protected generated version-state bookkeeping.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:01:53Z",
          "mergedAt": "2026-07-09T04:02:47Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 43,
          "url": "https://github.com/kungfu-systems/build-images/pull/43",
          "title": "chore(release): promote Buildchain bypass app fix to alpha",
          "body": "## Summary\n- promote the direct Buildchain promotion bypass app fix to alpha/v1/v1.2\n- retrigger the v1.2.0-alpha.0 image publication path for latex-pdf-builder\n\n## Verification\n- PR #42 checks passed\n- alpha Verify will rerun after merge before Buildchain Ref Promotion",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:03:03Z",
          "mergedAt": "2026-07-09T04:04:12Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 44,
          "url": "https://github.com/kungfu-systems/build-images/pull/44",
          "title": "fix(ci): update default promotion workflow for v1.2",
          "body": "## Summary\n- update the default-branch Buildchain promotion workflow so workflow_run promotions use the v1.2 target default\n- add checks:write and generated status/ref token inputs for promote-buildchain-ref\n- declare github-actions as the Buildchain-managed bypass app for protected generated bookkeeping\n\n## Verification\n- pnpm run check\n\nReason: GitHub workflow_run executes the workflow definition from the repository default branch, which is currently dev/v1/v1.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:06:56Z",
          "mergedAt": "2026-07-09T04:07:59Z",
          "additions": 5,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 928,
          "url": "https://github.com/kungfu-systems/buildchain/pull/928",
          "title": "feat(publication): add immutable archive registry",
          "body": "## Summary\n- add optional [publication.archive] config for canonical/latest/immutable publication URLs\n- generate append-only publication-registry.json with same-version digest immutability checks\n- record archive routes/evidence in publication manifest/passport and upload registry from the reusable workflow\n- allow release propagation locks to carry publicationArtifact payloads without npm package facts\n\n## Validation\n- node --test tests/build-surface.test.mjs tests/publication-artifact.test.mjs tests/release-propagation.test.mjs tests/buildchain-config.test.mjs\n- pnpm run check\n\nFixes #925",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:57:35Z",
          "mergedAt": "2026-07-09T04:08:40Z",
          "additions": 784,
          "deletions": 132,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 429,
          "url": "https://github.com/kungfu-systems/kungfu/pull/429",
          "title": "feat(master): add resident service supervisor",
          "body": "## Summary\n- add `kungfu master` commands for resident master supervisor status/start/stop/restart\n- add dry-run-by-default user service plan/install/uninstall commands for macOS, Linux, and Windows\n- register the public CLI surface in Buildchain-managed KFD-3 and document the lifecycle contract\n\n## Verification\n- `./kungfu-code check`\n- `./kungfu-code check:types`\n- `./kungfu-code kfd:buildchain:check`\n- `PYTHONPATH=src/python uv run --frozen pytest tests/python/test_master_service.py`\n- `uv run --frozen mypy src/python/kungfu/master_service.py src/python/kungfu/cli/commands/master.py`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:13:20Z",
          "mergedAt": "2026-07-09T04:14:34Z",
          "additions": 1050,
          "deletions": 0,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 926,
          "url": "https://github.com/kungfu-systems/buildchain/pull/926",
          "title": "chore(release): promote v2.11 alpha",
          "body": "Buildchain release line bootstrap opened v2.11. Merge this channel PR to publish the first alpha for the new minor line.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:43:25Z",
          "mergedAt": "2026-07-09T04:15:14Z",
          "additions": 864,
          "deletions": 199,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 104,
          "url": "https://github.com/kungfu-systems/kfd/pull/104",
          "title": "chore(kfd): anchor alpha 22 version",
          "body": "## Summary\n- Anchor the KFD package release metadata at 1.0.0-alpha.22.\n- Regenerate KFD release witnesses that bind package.json and kfd.release.json.\n\n## Validation\n- npm run check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n- npx -y @kungfu-tech/buildchain@2 validate --cwd . --json",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:15:05Z",
          "mergedAt": "2026-07-09T04:16:29Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 45,
          "url": "https://github.com/kungfu-systems/build-images/pull/45",
          "title": "chore(release): align dev v1.2 with alpha",
          "body": "## Summary\n- align dev/v1/v1.2 with the reviewed alpha/v1/v1.2 merge commit\n- unblock Buildchain promotion finalization without weakening branch protection\n\n## Verification\n- alpha/v1/v1.2 Verify succeeded for 83966e59e212586df48ff44b5e60f3c94449ff41\n- Buildchain generated check succeeded on the same SHA, but direct protected update was rejected due a stale cancelled same-name check run",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:15:44Z",
          "mergedAt": "2026-07-09T04:17:56Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 105,
          "url": "https://github.com/kungfu-systems/kfd/pull/105",
          "title": "chore: promote KFD alpha 22",
          "body": "## Summary\nPromote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd@1.0.0-alpha.22.\n\n## Included\n- KFD-1 publication URL semantics from PR #102.\n- Alpha 22 version anchor from PR #104.\n\n## Validation\n- Buildchain Verify and Build gates run on this promotion PR.\n- After merge, Buildchain workflow_run should publish the alpha npm package and release passport.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:17:10Z",
          "mergedAt": "2026-07-09T04:18:52Z",
          "additions": 548,
          "deletions": 131,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 46,
          "url": "https://github.com/kungfu-systems/build-images/pull/46",
          "title": "fix(ci): disable optional release passport for image promotion",
          "body": "## Summary\n- disable optional Buildchain release-passport generation for the image promotion workflow\n- keep publish transaction evidence for GHCR image publication intact\n\n## Verification\n- pnpm run check\n\nReason: Buildchain v2 promotion currently reaches optional release-passport generation and fails on a missing bundled @kungfu-tech/kfd dependency for this image-publishing workflow.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:20:02Z",
          "mergedAt": "2026-07-09T04:21:06Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 929,
          "url": "https://github.com/kungfu-systems/buildchain/pull/929",
          "title": "chore(release): promote v2.11 release",
          "body": "Promote Buildchain v2.11 from alpha to release after validating the immutable publication archive registry work.\\n\\nSource PRs:\\n- #928\\n- #926\\n\\nCloses #925.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:19:52Z",
          "mergedAt": "2026-07-09T04:21:43Z",
          "additions": 864,
          "deletions": 199,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 430,
          "url": "https://github.com/kungfu-systems/kungfu/pull/430",
          "title": "docs(storage): define episode object model",
          "body": "## Summary\n\n- accept Episode as the first-class causal segment object\n- add the companion Episode object model design document\n- route storage, event model, concepts, and ADR index docs to the new model\n\n## Validation\n\n- git diff --check\n- ./kungfu-code check\n\n## Governance checklist\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, billing, quota, or usage-attribution changes\n- [x] No hosted-service, brand, package, or release identity changes\n- [x] No release evidence or publishing surface changes\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:34:58Z",
          "mergedAt": "2026-07-09T04:40:39Z",
          "additions": 446,
          "deletions": 1,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 431,
          "url": "https://github.com/kungfu-systems/kungfu/pull/431",
          "title": "feat(gui): add master tray residency controls",
          "body": "## Summary\n- keep the Electron GUI resident in a tray/menu-bar surface when the main window is closed\n- add explicit tray controls for show/hide, master status/start/stop, Quit GUI, and Stop Master and Quit\n- register the GUI tray capability in KFD-3 and document the lifecycle semantics\n\n## Validation\n- ./kungfu-code check\n- ./kungfu-code check:types\n- ./kungfu-code kfd:buildchain:check\n- ./kungfu-code build:app\n- ./kungfu-code product gui pack --dry-run\n- ./kungfu-code product gui dist --dry-run\n- ./kungfu-code kfd:query --json | jq -r '.capabilities[] | select(.id==\"kungfu.gui.master-tray\")'\n\n## Notes\n- No service files are installed or removed by this change.\n- A live desktop tray smoke was not run in this branch.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:40:10Z",
          "mergedAt": "2026-07-09T04:41:23Z",
          "additions": 269,
          "deletions": 3,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 47,
          "url": "https://github.com/kungfu-systems/build-images/pull/47",
          "title": "chore(images): lock latex pdf builder digest",
          "body": "## Summary\n- update images.lock.json to the published v1.2.0-alpha.0 image family digests\n- add the latex-pdf-builder digest to the lock file\n- remove the temporary pending-first-publish lock state from latex-pdf-builder\n\n## Verification\n- pnpm run check\n\nRelease evidence: https://github.com/kungfu-systems/build-images/actions/runs/28993838949",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:40:47Z",
          "mergedAt": "2026-07-09T04:42:06Z",
          "additions": 18,
          "deletions": 11,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 432,
          "url": "https://github.com/kungfu-systems/kungfu/pull/432",
          "title": "docs(storage): define episode manifest journal",
          "body": "## Summary\n\n- accept the Episode manifest journal as the local authority for Episode metadata\n- define Episode manifest records as yijinjing first-class data structures\n- clarify that JSON is only an export, diagnostic, or folded view\n- update the Episode object model and storage docs to route to ADR-0034\n\n## Validation\n\n- git diff --check\n- ./kungfu-code check\n\n## Governance checklist\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, billing, quota, or usage-attribution changes\n- [x] No hosted-service, brand, package, or release identity changes\n- [x] No release evidence or publishing surface changes\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T05:13:22Z",
          "mergedAt": "2026-07-09T05:18:56Z",
          "additions": 216,
          "deletions": 24,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 49,
          "url": "https://github.com/kungfu-systems/build-images/pull/49",
          "title": "fix(ci): disable release passport for v1.2 promotion",
          "body": "Align the v1.2 development line with the release-channel promotion workflow so the next alpha evidence tree can be promoted through Buildchain without optional release passport collection.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T05:29:08Z",
          "mergedAt": "2026-07-09T05:30:41Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 433,
          "url": "https://github.com/kungfu-systems/kungfu/pull/433",
          "title": "docs(config): define workspace-local data home",
          "body": "## Summary\n\n- accept workspace-local `.kungfu/` as the default Episode/fact ledger home\n- hard-cut the user config default from `~/.kungfu` to `~/.kungfu-config`\n- retain `KF_HOME` as the explicit and machine-level data fallback\n- update config docs, documentation map, and ADR index\n\n## Validation\n\n- git diff --check\n- ./kungfu-code check\n\n## Governance checklist\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, billing, quota, or usage-attribution changes\n- [x] No hosted-service, brand, package, or release identity changes\n- [x] No release evidence or publishing surface changes\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T05:33:08Z",
          "mergedAt": "2026-07-09T05:33:40Z",
          "additions": 181,
          "deletions": 28,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 50,
          "url": "https://github.com/kungfu-systems/build-images/pull/50",
          "title": "chore(alpha): promote v1.2 dev to alpha",
          "body": "Promote the v1.2 development line through the Buildchain alpha channel after locking the published latex-pdf-builder digest and aligning release promotion workflow configuration.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T05:31:05Z",
          "mergedAt": "2026-07-09T05:34:52Z",
          "additions": 19,
          "deletions": 11,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 48,
          "url": "https://github.com/kungfu-systems/build-images/pull/48",
          "title": "chore(release): promote v1.2 to release",
          "body": "## Summary\n- promote the verified v1.2 alpha line to release/v1/v1.2 through the Buildchain channel flow\n- release source is the existing alpha exact tag path for latex-pdf-builder\n\n## Evidence\n- alpha tag: v1.2.0-alpha.0 -> 83966e59e212586df48ff44b5e60f3c94449ff41\n- alpha promotion run: https://github.com/kungfu-systems/build-images/actions/runs/28993838949\n- latex-pdf-builder digest: sha256:4d7123794fa7e3ea510dd51ab447d70be90df5df87c01675704a0a5607bf17bf\n\n## Verification\n- release branch Verify must pass before merge\n- Buildchain Ref Promotion will publish the release version after this PR merges",
          "author": "dongkeren",
          "createdAt": "2026-07-09T05:19:58Z",
          "mergedAt": "2026-07-09T05:42:32Z",
          "additions": 191,
          "deletions": 15,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 434,
          "url": "https://github.com/kungfu-systems/kungfu/pull/434",
          "title": "docs(master): define supervisor topology",
          "body": "## Summary\n- add ADR-0036 for the per-user supervisor and per-data-root workspace master topology\n- document that the supervisor routes and manages masters but does not own durable facts\n- update master service, config, ADR index, and docs map entry points\n\n## Validation\n- git diff --check\n- ./kungfu-code check\n\n## Notes\n- This is a documentation/architecture decision slice. Implementation work remains separate.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T05:50:44Z",
          "mergedAt": "2026-07-09T05:51:14Z",
          "additions": 295,
          "deletions": 16,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 435,
          "url": "https://github.com/kungfu-systems/kungfu/pull/435",
          "title": "feat(master): route data roots through supervisor",
          "body": "## Summary\n- add `kungfu master ensure` to register the current data root and start/reuse the per-user supervisor\n- move supervisor runtime state to `KF_CONFIG_HOME/runtime/supervisor` and workspace master state to `<data-root>/runtime/master`\n- teach the supervisor loop to poll a route registry and manage per-data-root master children\n- align config defaults with `~/.kungfu-config` and refresh KFD-1 canonical policy\n\n## Validation\n- PYTHONPATH=framework/core/src/python python3 direct harness for `framework/core/tests/python/test_master_service.py`\n- python3 -m py_compile framework/core/src/python/kungfu/master_service.py framework/core/src/python/kungfu/cli/commands/master.py framework/core/src/python/kungfu/cli/commands/__init__.py framework/core/tests/python/test_master_service.py\n- git diff --check\n- ./kungfu-code check\n\n## Notes\n- V1 uses a file-backed supervisor route registry. It intentionally does not make closed-data storage operations depend on a live master.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T06:06:58Z",
          "mergedAt": "2026-07-09T06:07:52Z",
          "additions": 507,
          "deletions": 138,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 932,
          "url": "https://github.com/kungfu-systems/buildchain/pull/932",
          "title": "feat(publication): use build-images latex builder for papers",
          "body": "## Summary\n- switch publication-artifact workflow latex-docker defaults to build-images latex-pdf-builder v1.2.0 pinned by digest\n- make publication-artifact init scaffold write the pinned latex-docker toolchain into .buildchain/buildchain.toml\n- update publication docs, site bundle, and tests for the new paper builder contract\n\n## Verification\n- node --test tests/cli.test.mjs tests/buildchain-config.test.mjs tests/publication-artifact.test.mjs tests/build-surface.test.mjs\n- pnpm run generate:site\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T06:02:56Z",
          "mergedAt": "2026-07-09T06:14:20Z",
          "additions": 67,
          "deletions": 45,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 931,
          "url": "https://github.com/kungfu-systems/buildchain/pull/931",
          "title": "fix(promote): ignore release evidence during version verification",
          "body": "Fixes #930.\\n\\nBuildchain promotion can generate publish transaction evidence and local release-state files before later generated version-state verification runs. Those Buildchain-owned untracked files should not fail the version-state dirty check.\\n\\nThis adds .buildchain/release-evidence/ and .buildchain/release-state/ to the existing ephemeral Buildchain evidence whitelist and extends the unit coverage that already covers generated evidence paths.\\n\\nValidation:\\n- node --test tests/promote-buildchain-ref.test.mjs --test-name-pattern \"version verification ignores generated buildchain evidence\"\\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T06:01:07Z",
          "mergedAt": "2026-07-09T07:00:17Z",
          "additions": 13,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 436,
          "url": "https://github.com/kungfu-systems/kungfu/pull/436",
          "title": "docs(adr): storage-service records are Hana-core kernel metadata",
          "body": "Merge feature/storage-adr0033-zero-copy-records into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:03:29Z",
          "mergedAt": "2026-07-09T07:03:35Z",
          "additions": 211,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 437,
          "url": "https://github.com/kungfu-systems/kungfu/pull/437",
          "title": "feat(gui): surface supervisor master status",
          "body": "Merge feature/supervisor-status-surface-integration into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:08:04Z",
          "mergedAt": "2026-07-09T07:08:10Z",
          "additions": 286,
          "deletions": 8,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 934,
          "url": "https://github.com/kungfu-systems/buildchain/pull/934",
          "title": "fix(kfd): unify generated output layout",
          "body": "## Summary\n- unify Buildchain-owned KFD outputs under `.buildchain/kfd/kfd-N/`\n- move the KFD-3 surface registry default to `.buildchain/kfd/kfd-3/surfaces.json`\n- expose canonical KFD layout constants and migrate legacy KFD paths through Buildchain layout helpers\n- update self-KFD witness generation, promotion finalization, docs, tests, and generated site/action bundles\n\nFixes #933.\n\n## Verification\n- `corepack pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:23:52Z",
          "mergedAt": "2026-07-09T07:28:52Z",
          "additions": 385,
          "deletions": 201,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 438,
          "url": "https://github.com/kungfu-systems/kungfu/pull/438",
          "title": "feat(master): add supervisor route lifecycle leases",
          "body": "Adds supervisor route heartbeat leases, deterministic lifecycle health states, ensure-time repair for unsafe route state, and GUI status/tray lifecycle surfacing.\\n\\nValidation:\\n- ./kungfu-code check\\n- pnpm --filter @kungfu-tech/gui run build\\n- ./kungfu-code build\\n- built CLI master status/ensure/status/stop smoke with temporary KF_HOME/KF_CONFIG_HOME",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:34:54Z",
          "mergedAt": "2026-07-09T07:35:00Z",
          "additions": 469,
          "deletions": 25,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 51,
          "url": "https://github.com/kungfu-systems/build-images/pull/51",
          "title": "feat(buildchain): wire KFD123 evidence",
          "body": "## Summary\n- migrate Buildchain config to `.buildchain/buildchain.toml` and add a `v2` contract lock\n- pin local Buildchain/KFD tooling through pnpm and run Buildchain via `pnpm exec`\n- add generated KFD-1/2/3 evidence plus a `check:kfd` gate with release-passport smoke verification\n- enable release-passport KFD inputs in the Buildchain ref promotion workflow\n\n## Verification\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- `pnpm exec buildchain validate --require-version-state --require-lifecycle-stages verify,publish`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:19:16Z",
          "mergedAt": "2026-07-09T07:35:39Z",
          "additions": 3618,
          "deletions": 8,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 52,
          "url": "https://github.com/kungfu-systems/build-images/pull/52",
          "title": "chore(alpha): promote KFD123 buildchain config",
          "body": "## Summary\n- promote build-images KFD123 Buildchain config wiring from dev/v1/v1.2 to alpha/v1/v1.2\n- includes .buildchain config layout, v2 contract lock, pinned Buildchain/KFD tooling, and release-passport KFD inputs\n\n## Verification\n- dev/v1/v1.2 Verify passed on merge commit 1d9e969\n- PR #51 checks passed before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:36:51Z",
          "mergedAt": "2026-07-09T07:38:22Z",
          "additions": 3618,
          "deletions": 8,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 53,
          "url": "https://github.com/kungfu-systems/build-images/pull/53",
          "title": "fix(buildchain): keep KFD evidence stable across release bumps",
          "body": "## Summary\n- make generated KFD evidence stable when Buildchain temporarily bumps package.json during release version verification\n- pin generated evidence timestamps and remove build-machine cwd/product version drift from tracked KFD artifacts\n\n## Verification\n- `pnpm run check`\n- temp detached worktree: set package.json version to `1.2.1-alpha.0`, ran `pnpm run check:kfd`, and only package.json changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:48:17Z",
          "mergedAt": "2026-07-09T07:54:47Z",
          "additions": 59,
          "deletions": 33,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 55,
          "url": "https://github.com/kungfu-systems/build-images/pull/55",
          "title": "fix(alpha): keep KFD evidence stable across release bumps",
          "body": "## Summary\n- cherry-pick the KFD evidence stability fix onto alpha/v1/v1.2\n- prevents Buildchain release version verification from seeing KFD evidence drift after temporary package.json version bumps\n\n## Verification\n- PR #53 checks passed on dev\n- local temp worktree bump test only changed package.json\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:56:02Z",
          "mergedAt": "2026-07-09T07:57:48Z",
          "additions": 59,
          "deletions": 33,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 439,
          "url": "https://github.com/kungfu-systems/kungfu/pull/439",
          "title": "feat(storage): fsck distinguishes redacted/absent from missing payloads",
          "body": "Merge feature/storage-fsck-payload-status into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T08:04:20Z",
          "mergedAt": "2026-07-09T08:04:25Z",
          "additions": 94,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 56,
          "url": "https://github.com/kungfu-systems/build-images/pull/56",
          "title": "chore(alpha): retrigger KFD123 promotion gate",
          "body": "## Summary\n- retrigger Buildchain promotion through an allowed publish-gate/alpha source branch\n- keep the build-images content tree unchanged after the KFD123 + contract-lock integration already landed\n\n## Verification\n- no file changes in this PR; provenance-only gate repair\n- prior alpha head passed repository check and KFD123 verification in Buildchain Ref Promotion run 29003186390 before governance source validation",
          "author": "dongkeren",
          "createdAt": "2026-07-09T08:07:56Z",
          "mergedAt": "2026-07-09T08:09:29Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 57,
          "url": "https://github.com/kungfu-systems/build-images/pull/57",
          "title": "chore(alpha): lock KFD123 promotion source",
          "body": "## Summary\n- retrigger Buildchain alpha promotion through the strict publish-gate/alpha/v1/v1.2/1.2.1-alpha.0 source-lock branch shape\n- keep the build-images content tree unchanged; KFD123, pnpm support, and contract lock are already present on alpha\n\n## Verification\n- prior promotion run 29003832640 passed repository check and KFD123 verification before rejecting the earlier non-canonical publish-gate branch name\n- this PR is provenance-only and carries the strict Buildchain publish-gate source-ref format",
          "author": "dongkeren",
          "createdAt": "2026-07-09T08:11:07Z",
          "mergedAt": "2026-07-09T08:12:42Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 935,
          "url": "https://github.com/kungfu-systems/buildchain/pull/935",
          "title": "fix(verify): resolve npm artifact integrity",
          "body": "## Summary\n- resolve `npm:<name>@<version>` subject digests from npm registry `dist.integrity`\n- match resolved npm integrity against release passport artifacts, packageSet, and publish evidence\n- add `--npm-registry` for custom registries on verify/explain/inspect artifact commands\n- cover main and platform npm package verification with a local registry/passport fixture\n\nFixes #927.\n\n## Verification\n- `node --test tests/release-passport.test.mjs`\n- `corepack pnpm run generate:site && corepack pnpm run build`\n- `corepack pnpm run check`\n- `node bin/buildchain.mjs verify artifact npm:@kungfu-tech/libnode@22.22.3-kf.3-alpha.18 --repository kungfu-systems/libnode --tag v22.22.3-kf.3-alpha.18 --json`\n- `node bin/buildchain.mjs verify artifact npm:@kungfu-tech/libnode-darwin-arm64@22.22.3-kf.3-alpha.18 --repository kungfu-systems/libnode --tag v22.22.3-kf.3-alpha.18 --json`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T08:11:51Z",
          "mergedAt": "2026-07-09T08:19:02Z",
          "additions": 244,
          "deletions": 39,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 440,
          "url": "https://github.com/kungfu-systems/kungfu/pull/440",
          "title": "feat(storage): add episode manifest v1",
          "body": "Adds yijinjing-backed Episode manifest v1 records, runtime storage service APIs, CLI commands, fsck coverage, tests, and ADR updates.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T08:28:21Z",
          "mergedAt": "2026-07-09T08:28:30Z",
          "additions": 1880,
          "deletions": 34,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 441,
          "url": "https://github.com/kungfu-systems/kungfu/pull/441",
          "title": "feat(product): rename GUI product to Kungfu Episodes",
          "body": "## Summary\\n- Rename the GUI desktop product/display artifact from Kungfu to Kungfu Episodes.\\n- Project the new product display name into Buildchain KFD evidence and release passport inputs.\\n- Update GUI visible labels and product docs that reference the app bundle / dmg name.\\n\\n## Validation\\n- ./kungfu-code kfd:buildchain\\n- ./kungfu-code kfd:buildchain:check\\n- ./kungfu-code check:types\\n- ./kungfu-code product gui dist --dry-run\\n- ./kungfu-code check\\n- ./kungfu-code build:app\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T08:54:22Z",
          "mergedAt": "2026-07-09T09:00:35Z",
          "additions": 81,
          "deletions": 69,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 936,
          "url": "https://github.com/kungfu-systems/buildchain/pull/936",
          "title": "chore(release): promote v2.11 alpha",
          "body": "## Summary\nPromote current `dev/v2/v2.11` into the alpha channel for the next Buildchain v2.11 patch release.\n\nIncluded since the current alpha channel:\n- `fix(kfd): unify generated output layout`\n- `fix(verify): resolve npm artifact integrity`\n- recent publication/release verification fixes already on dev\n\n## Verification\n- dev branch checks passed on merged PRs\n- channel PR checks must pass before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T08:51:23Z",
          "mergedAt": "2026-07-09T09:02:07Z",
          "additions": 670,
          "deletions": 247,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 442,
          "url": "https://github.com/kungfu-systems/kungfu/pull/442",
          "title": "docs(readme): clarify Kungfu Episodes naming",
          "body": "Merge docs/readme-brand-episodes into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:04:13Z",
          "mergedAt": "2026-07-09T09:04:20Z",
          "additions": 11,
          "deletions": 7,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 937,
          "url": "https://github.com/kungfu-systems/buildchain/pull/937",
          "title": "chore(release): promote v2.11.1",
          "body": "Promotes the verified v2.11 alpha channel to stable release.\n\nSource alpha evidence:\n- Alpha tag: v2.11.1-alpha.1\n- Alpha promotion run: https://github.com/kungfu-systems/buildchain/actions/runs/29006978697\n- Includes #934 and #935 fixes from dev/v2/v2.11.\n\nRelease path remains channel-governed: alpha/v2/v2.11 -> release/v2/v2.11, then Buildchain Ref Promotion performs the stable release transaction.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:08:54Z",
          "mergedAt": "2026-07-09T09:11:51Z",
          "additions": 681,
          "deletions": 258,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 444,
          "url": "https://github.com/kungfu-systems/kungfu/pull/444",
          "title": "refactor(location): rename group to namespace",
          "body": "Renames the v4 Location middle identity segment from group to namespace across yijinjing schema, C++ runtime, Python/Node bindings, capability API, GUI extensions, docs, and stubs. Keeps path shape unchanged and preserves narrow legacy group input fallback while canonicalizing output to namespace.\\n\\nValidation:\\n- ./kungfu-code build\\n- ./kungfu-code check\\n- Python namespace binding smoke\\n- Node IODevice namespace/legacy-group smoke",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:20:43Z",
          "mergedAt": "2026-07-09T09:20:49Z",
          "additions": 334,
          "deletions": 225,
          "changedFiles": 66
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 443,
          "url": "https://github.com/kungfu-systems/kungfu/pull/443",
          "title": "fix(product): rename CLI archive for Kungfu Episodes",
          "body": "## Summary\n- rename the CLI product archive/staging basename to `kungfu-episodes-cli-<platform>`\n- add a focused product dist test for the CLI archive basename\n\n## Validation\n- `./kungfu-code sync`\n- `node --test product/scripts/dist.test.mjs`\n- `./kungfu-code check:types`\n- `./kungfu-code check`\n- `./kungfu-code kfd:buildchain:check`\n- `./kungfu-code product cli dist --dry-run`\n- `git diff --check`\n- `node --check product/scripts/dist.mjs && node --check product/scripts/dist.test.mjs`",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:19:31Z",
          "mergedAt": "2026-07-09T09:22:52Z",
          "additions": 30,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 939,
          "url": "https://github.com/kungfu-systems/buildchain/pull/939",
          "title": "chore(release): recover v2.11.1 stable promotion",
          "body": "Adds an empty release-intent commit through the Buildchain release-line recovery ref pattern so stable promotion can run after #937 rebase-merged an alpha prepare commit.\n\nContext:\n- #937 advanced release/v2/v2.11 to alpha evidence v2.11.1-alpha.1.\n- The resulting release branch HEAD title starts with `chore(release): prepare v`, which Buildchain Ref Promotion intentionally skips.\n- This PR uses the accepted `fix/release-line-v2-v2.11-*` recovery head ref and changes no files.\n\nExpected outcome: release/v2/v2.11 Verify succeeds from a non-prepare release-intent commit, then Buildchain Ref Promotion publishes v2.11.1 stable.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:23:19Z",
          "mergedAt": "2026-07-09T09:35:02Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 940,
          "url": "https://github.com/kungfu-systems/buildchain/pull/940",
          "title": "chore(release): merge-trigger v2.11.1 stable promotion",
          "body": "Adds an empty release-intent commit through the accepted Buildchain release-line recovery ref pattern.\n\nThis PR must be merged with a merge commit, not rebase, so release/v2/v2.11 gets a non-prepare HEAD and the Verify workflow_run can trigger stable Buildchain Ref Promotion.\n\nContext:\n- #937 advanced release/v2/v2.11 to v2.11.1-alpha.1 evidence, but the HEAD title was `chore(release): prepare v...`, which promotion intentionally skips.\n- #939 was rebase-merged; GitHub dropped the empty commit, so release/v2/v2.11 did not advance.\n- This PR changes no files and exists only to create the release-intent merge commit under branch protection.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:36:05Z",
          "mergedAt": "2026-07-09T09:37:34Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 445,
          "url": "https://github.com/kungfu-systems/kungfu/pull/445",
          "title": "feat(storage): make episodes first-class storage slices",
          "body": "Implements Episode-owned storage slice v1: generic storage scope=episode fsck/query/export surfaces backed by yijinjing Episode manifests, plus CLI/Python wiring, docs, and storage tests.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:47:22Z",
          "mergedAt": "2026-07-09T09:47:27Z",
          "additions": 295,
          "deletions": 21,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 942,
          "url": "https://github.com/kungfu-systems/buildchain/pull/942",
          "title": "fix(promote): accept release recovery trigger trees",
          "body": "## Summary\n- allow release-branch Verify workflow_run events to promote prepare commits\n- accept release-line recovery PR triggers when their tree is equivalent to exact alpha evidence\n- keep post-alpha release version-state changes constrained by existing allowlist checks\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- node --test tests/build-surface.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:47:44Z",
          "mergedAt": "2026-07-09T09:51:38Z",
          "additions": 148,
          "deletions": 47,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 944,
          "url": "https://github.com/kungfu-systems/buildchain/pull/944",
          "title": "chore(release): sync alpha v2.11 state to dev",
          "body": "## Summary\n- Sync the current alpha/v2/v2.11 generated version state back into dev/v2/v2.11.\n- Keeps the release-promotion recovery fix already merged in dev.\n- Restores a clean dev -> alpha promotion path.\n\n## Validation\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:56:28Z",
          "mergedAt": "2026-07-09T09:58:43Z",
          "additions": 12,
          "deletions": 12,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 943,
          "url": "https://github.com/kungfu-systems/buildchain/pull/943",
          "title": "chore(release): promote Buildchain v2.11 alpha",
          "body": "## Summary\n- Promote dev/v2/v2.11 to alpha/v2/v2.11 for the next Buildchain v2.11 alpha.\n- Includes release recovery trigger governance fix from PR #942.\n\n## Release intent\n- Channel: alpha\n- Line: v2.11\n- Expected: publish alpha only before stable release promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:52:23Z",
          "mergedAt": "2026-07-09T10:05:43Z",
          "additions": 148,
          "deletions": 47,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 446,
          "url": "https://github.com/kungfu-systems/kungfu/pull/446",
          "title": "fix(storage): preserve Atlas range export context",
          "body": "## Summary\n- preserve Atlas range exports as context-closed slices\n- record goal-to-mission source refs in Atlas manifest entries, with fallback for older manifests\n- document Atlas JSONL range export semantics\n\n## Validation\n- ./kungfu-code build\n- PYTHONPATH=\"$PWD/framework/core/src/python:$PWD/framework/core/build/Release\" uv run --project framework/core python -m pytest framework/core/tests/python/test_atlas_storage.py -q\n- ./kungfu-code check\n- CLI smoke: import/export/verify /Users/dkr/Code/atlas from 2026-06-29T00:00:00Z, 739 records, matching sync root, verify ok",
          "author": "dongkeren",
          "createdAt": "2026-07-09T10:27:33Z",
          "mergedAt": "2026-07-09T10:27:40Z",
          "additions": 158,
          "deletions": 36,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 946,
          "url": "https://github.com/kungfu-systems/buildchain/pull/946",
          "title": "chore(release): publish-gate Buildchain v2.11.1",
          "body": "## Summary\n- Use a strict publish-gate/release source branch for the v2.11.1 stable promotion.\n- The branch is based on release/v2/v2.11 and merges the verified alpha/v2/v2.11 material, resolving the existing release recovery ancestry conflict.\n- Includes the v2.11.1-alpha.2 material and release recovery trigger fix.\n\n## Validation\n- pnpm run check\n\n## Supersedes\n- Supersedes #945, which is dirty because release/v2/v2.11 already contains a recovery merge commit.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T10:23:41Z",
          "mergedAt": "2026-07-09T10:31:48Z",
          "additions": 238,
          "deletions": 59,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 447,
          "url": "https://github.com/kungfu-systems/kungfu/pull/447",
          "title": "fix(core): run ruff lint in the changed-scope check gate",
          "body": "Merge feature/ruff-lint-gate into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T10:39:14Z",
          "mergedAt": "2026-07-09T10:39:21Z",
          "additions": 47,
          "deletions": 29,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 948,
          "url": "https://github.com/kungfu-systems/buildchain/pull/948",
          "title": "fix(release): accept publish-gate release verify refs",
          "body": "## Summary\n- teach release-line verify policy to accept publish-gate alpha/release PR refs\n- keep publish-gate channel and release-line matching fail-closed before promotion\n- add regression coverage for alpha/release publish-gate verify paths\n\n## Validation\n- node --test tests/release-line-policy.test.mjs\n- corepack pnpm run check\n\n## Release note\nThis fix must land through dev -> alpha before the stable v2.11.1 release promotion can satisfy tree-equivalence against the latest alpha tag.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T10:41:04Z",
          "mergedAt": "2026-07-09T10:53:37Z",
          "additions": 78,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 448,
          "url": "https://github.com/kungfu-systems/kungfu/pull/448",
          "title": "feat(config): resolve workspace data home",
          "body": "## Summary\n- Resolve workspace-local `.kungfu` data homes from existing `.kungfu` ancestors or the git workspace root.\n- Keep config under `~/.kungfu-config` / `KF_CONFIG_HOME` while exposing `workspaceDataHome` and `machineDataHome` in config path output.\n- Make product dev launchers use workspace data homes without creating isolated instance config.\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- node --test product/scripts/product.test.mjs\n- pnpm --filter @kungfu-tech/skill run build\n- PYTHONPATH=\"$PWD/framework/core/src/python:$PWD/framework/core/build/Release\" uv run --project framework/core python -m pytest framework/core/tests/python/test_skill.py -q\n- CLI smoke for workspace `.kungfu`, explicit `KF_HOME`, and machine fallback",
          "author": "dongkeren",
          "createdAt": "2026-07-09T10:58:38Z",
          "mergedAt": "2026-07-09T10:58:45Z",
          "additions": 459,
          "deletions": 34,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 949,
          "url": "https://github.com/kungfu-systems/buildchain/pull/949",
          "title": "chore(release): promote v2.11 dev to alpha",
          "body": "## Summary\n- promote dev/v2/v2.11 to alpha after publish-gate release verify policy fix\n- required before retrying stable v2.11.1 so release and alpha trees match except version-state files\n\n## Validation\n- dev PR #948 passed check and Build Surface Fixture\n- local corepack pnpm run check passed on the fix branch",
          "author": "dongkeren",
          "createdAt": "2026-07-09T10:54:14Z",
          "mergedAt": "2026-07-09T11:00:49Z",
          "additions": 78,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 951,
          "url": "https://github.com/kungfu-systems/buildchain/pull/951",
          "title": "chore(release): refresh alpha v2.11 candidate",
          "body": "## Summary\n- add a no-op release candidate refresh commit after #949 was merged before its PR-stage RC fixture completed\n- lets the next dev->alpha PR produce required PR-stage release-candidate evidence without changing source tree content\n\n## Validation\n- no source tree changes; previous fix branch passed corepack pnpm run check\n\n## Release note\nThis is a governance refresh commit only; it exists to produce a fresh auditable dev head for alpha promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T11:11:26Z",
          "mergedAt": "2026-07-09T11:17:53Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 952,
          "url": "https://github.com/kungfu-systems/buildchain/pull/952",
          "title": "chore(release): refresh alpha v2.11 candidate",
          "body": "## Summary\n- promote refreshed dev head to alpha so PR-stage release-candidate artifacts exist before alpha promotion\n- no source tree changes beyond the already merged publish-gate verify policy fix\n\n## Validation\n- PR #951 passed check and Build Surface Fixture before merging to dev\n\n## Release note\nWait for this PR's Build Surface Fixture to finish before merging; alpha promotion consumes that PR-stage RC evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T11:18:23Z",
          "mergedAt": "2026-07-09T11:20:48Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 953,
          "url": "https://github.com/kungfu-systems/buildchain/pull/953",
          "title": "chore(release): publish v2.11.1",
          "body": "## Summary\n- promote the currently tested v2.11.1-alpha.3 source into the v2.11 stable release channel\n- keep release finalization under Buildchain publish-gate governance\n\n## Validation\n- PR-stage Release - Verify must pass\n- PR-stage Build Surface Fixture must finish before merge so promote-only release can reuse the RC evidence\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T11:40:35Z",
          "mergedAt": "2026-07-09T11:42:29Z",
          "additions": 90,
          "deletions": 12,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 449,
          "url": "https://github.com/kungfu-systems/kungfu/pull/449",
          "title": "feat(storage): expose workspace episode layout",
          "body": "## Summary\n- add a C++ storage service layout operation for workspace Episode storage paths\n- expose `kungfu storage layout --json` through the Python CLI\n- document the `.kungfu/runtime` Episode layout and verify Python/Node storage bindings\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- PYTHONPATH=\"$PWD/src/python:$PWD/dist/kungfu\" DYLD_FALLBACK_LIBRARY_PATH=\"$PWD/dist/kungfu:${DYLD_FALLBACK_LIBRARY_PATH:-}\" uv run --frozen pytest tests/python/test_atlas_storage.py::test_runtime_storage_service_surface_is_bound_from_libkungfu tests/python/test_atlas_storage.py::test_python_storage_operations_enter_runtime_service_surface tests/python/test_atlas_storage.py::test_episode_manifest_v1_is_yijinjing_backed_and_fscked -q\n- KUNGFU_DIR=\"$PWD/dist/kungfu\" DYLD_FALLBACK_LIBRARY_PATH=\"$PWD/dist/kungfu:${DYLD_FALLBACK_LIBRARY_PATH:-}\" pnpm run test:storage-binding\n- frozen CLI `kungfu storage layout --json` smoke",
          "author": "dongkeren",
          "createdAt": "2026-07-09T12:01:39Z",
          "mergedAt": "2026-07-09T12:03:20Z",
          "additions": 261,
          "deletions": 0,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 450,
          "url": "https://github.com/kungfu-systems/kungfu/pull/450",
          "title": "docs(adr): unified view interface as sole FlatBuffers access point",
          "body": "Merge feature/unified-view-interface-fb-encapsulation into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T12:22:17Z",
          "mergedAt": "2026-07-09T12:22:23Z",
          "additions": 153,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 451,
          "url": "https://github.com/kungfu-systems/kungfu/pull/451",
          "title": "feat(storage): attach episodes to runtime lifecycles",
          "body": "## Summary\n- wrap rewind trace, managed-run, and reported run paths in runtime Episode lifecycles\n- attach action recorder frame receipts and payload refs to Episode manifests\n- validate Episode list/inspect/fsck/export through the rewind demo fixture\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- cd framework/core && DYLD_FALLBACK_LIBRARY_PATH=dist/kungfu PYTHONPATH=src/python:dist/kungfu uv run --frozen pytest tests/python/test_atlas_storage.py -q\n- node tests/fixtures/rewind-demo-happy/run.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-09T12:35:39Z",
          "mergedAt": "2026-07-09T12:35:45Z",
          "additions": 339,
          "deletions": 117,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 54,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/54",
          "title": "Upgrade Buildchain and KFD site bundles",
          "body": "## Summary\n\n- pin `@kungfu-tech/buildchain` to `2.11.1`\n- pin `@kungfu-tech/kfd` to `1.0.0-alpha.22`\n- update renderer/check constants and docs to match the consumed upstream package versions\n\n## Verification\n\n```bash\npnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/ --config.minimumReleaseAge=0\npnpm run build\npnpm run check\n```\n\n## Notes\n\nBuildchain `2.11.1` still does not publish `dist/site/publication-registry.json`, so `papers.libkungfu.dev` remains fixture-backed. Tracked upstream as kungfu-systems/buildchain#954.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T12:35:25Z",
          "mergedAt": "2026-07-09T12:38:49Z",
          "additions": 27,
          "deletions": 22,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 452,
          "url": "https://github.com/kungfu-systems/kungfu/pull/452",
          "title": "feat(storage): expose episode causal graph diagnostics",
          "body": "## Summary\n- add kungfu.episode.causal-graph/v1 projection from the C++ yijinjing Episode manifest fold\n- surface dependencies/degraded status through episode inspect, storage export, and fsck\n- cover declared external triggers and degraded missing dependency/payload cases\n\n## Validation\n- ./kungfu-code build\n- DYLD_FALLBACK_LIBRARY_PATH=dist/kungfu PYTHONPATH=src/python:dist/kungfu uv run --frozen pytest tests/python/test_atlas_storage.py -q\n- node tests/fixtures/rewind-demo-happy/run.mjs\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:23:00Z",
          "mergedAt": "2026-07-09T14:23:06Z",
          "additions": 330,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 58,
          "url": "https://github.com/kungfu-systems/build-images/pull/58",
          "title": "fix(ci): publish build-images release passports",
          "body": "## Summary\n- enable Buildchain release-passport generation on the default-branch promotion workflow\n- enable GitHub Release upload for publish evidence and release passport assets\n- pass build-images KFD-1/2/3 evidence paths into the passport generator\n\n## Verification\n- ruby YAML parse for .github/workflows/buildchain-ref-promotion.yml",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:22:57Z",
          "mergedAt": "2026-07-09T14:23:56Z",
          "additions": 9,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 59,
          "url": "https://github.com/kungfu-systems/build-images/pull/59",
          "title": "fix(ci): expose workspace node modules to buildchain action",
          "body": "## Summary\n- expose the checked-out workspace node_modules to the Buildchain action via NODE_PATH\n- unblock release-passport KFD evidence generation in the default-branch promotion workflow\n\n## Verification\n- ruby YAML parse for .github/workflows/buildchain-ref-promotion.yml\n- prior promotion run 29025253898 proved the new release-passport/github-release configuration is active and failed only on @kungfu-tech/kfd module resolution",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:26:25Z",
          "mergedAt": "2026-07-09T14:27:13Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 453,
          "url": "https://github.com/kungfu-systems/kungfu/pull/453",
          "title": "chore(buildchain): adopt v2 kfd contract management",
          "body": "## Summary\n- upgrade Buildchain to 2.11.1 and refresh the v2 contract lock\n- migrate repository-owned KFD evidence into the Buildchain-managed .buildchain/kfd layout\n- wire build and release workflows to the Buildchain v2 contract-lock path\n\n## Verification\n- ./kungfu-code kfd:buildchain:check\n- ./kungfu-code check\n- git diff --check\n- buildchain doctor --cwd . --require-publish-source-lock --json\n\n## Risk\n- KFD evidence paths moved from legacy roots to .buildchain/kfd/kfd-1|kfd-2|kfd-3. Scripts and release workflow references were updated together.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:30:16Z",
          "mergedAt": "2026-07-09T14:31:16Z",
          "additions": 4681,
          "deletions": 157,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 955,
          "url": "https://github.com/kungfu-systems/buildchain/pull/955",
          "title": "fix(site): publish publication registry bundle",
          "body": "## Summary\n- add dist/site/publication-registry.json as the package-owned publication archive registry for downstream papers surfaces\n- export @kungfu-tech/buildchain/site/publication-registry.json and include it in site/KFD claim registries\n- document the publication registry consumption contract and regenerate the site bundle\n\n## Validation\n- corepack pnpm@11.7.0 run check\n- node --input-type=module import @kungfu-tech/buildchain/site/publication-registry.json\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/ confirms dist/site/publication-registry.json is packaged\n- publication-registry fixture digest smoke\n\nFixes #954",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:41:34Z",
          "mergedAt": "2026-07-09T14:44:02Z",
          "additions": 293,
          "deletions": 33,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 454,
          "url": "https://github.com/kungfu-systems/kungfu/pull/454",
          "title": "feat(view): encapsulate FlatBuffers access behind kungfu::view (ADR-0039 slice 1)",
          "body": "Confine all open-layer FlatBuffers/reflection access to one runtime-independent chokepoint (kungfu::view) so the .bfbs dangling-view bug is structurally unrepresentable (ADR-0039, accepted). schema_handle co-owns its .bfbs bytes and never hands out a bare reflection view; pod.h keeps the hot path zero-cost; a CI boundary guard fails the build on raw flatbuffers::/reflection:: outside the module; a capability slice proves the projection roundtrip. Full core build green; projection roundtrip equivalent to the pre-migration path. schema_compiler migration is the next slice.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:52:55Z",
          "mergedAt": "2026-07-09T14:53:01Z",
          "additions": 823,
          "deletions": 198,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 455,
          "url": "https://github.com/kungfu-systems/kungfu/pull/455",
          "title": "feat(storage): add episode repair plans",
          "body": "## Summary\n- add C++ storage repair_plan operation for degraded Episode/source diagnostics\n- expose read-only kungfu storage repair --plan --dry-run CLI\n- validate Episode bundle import evidence without mutating the manifest journal\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- DYLD_FALLBACK_LIBRARY_PATH=dist/kungfu PYTHONPATH=src/python:dist/kungfu uv run --frozen pytest tests/python/test_atlas_storage.py -q\n- KUNGFU_DIR=$PWD/dist/kungfu node --test tests/storage-node-binding.test.js\n- CLI smoke: kungfu storage repair --scope episode --episode-id 7 --plan --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:53:00Z",
          "mergedAt": "2026-07-09T14:53:05Z",
          "additions": 492,
          "deletions": 42,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 57,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/57",
          "title": "Adopt Buildchain dotdir layout",
          "body": "## Summary\n- move Buildchain config and contract lock into the canonical .buildchain/ directory\n- update the web-surface workflow, checks, and docs to use .buildchain/contract-lock.json and .buildchain/buildchain.toml\n- keep KFD upstream propagation compatible with the canonical .buildchain/upstreams path while retaining a legacy fallback for existing Buildchain output\n\n## Verification\n- pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/ --config.minimumReleaseAge=0\n- pnpm run build\n- pnpm run check\n- pnpm exec buildchain kfd status --json\n- pnpm exec buildchain validate --cwd . --require-lifecycle-stages build,verify\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:46:58Z",
          "mergedAt": "2026-07-09T14:53:58Z",
          "additions": 46,
          "deletions": 17,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 957,
          "url": "https://github.com/kungfu-systems/buildchain/pull/957",
          "title": "fix(kfd): bundle release gate metadata",
          "body": "## Summary\n- statically import KFD package metadata, standards, and trust taxonomy in the release gate module\n- rebuild promote-buildchain-ref so release-passport KFD gates do not require consumer NODE_PATH\n- add a regression test that prevents kfd-gate from reintroducing runtime require.resolve metadata lookup\n\n## Validation\n- corepack pnpm@11.7.0 exec node --test tests/release-passport.test.mjs\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- promote action bundle smoke: no @kungfu-tech/kfd runtime package resolution remains\n- corepack pnpm@11.7.0 run check\n\nFixes #956",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:55:14Z",
          "mergedAt": "2026-07-09T14:57:39Z",
          "additions": 117,
          "deletions": 90,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 58,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/58",
          "title": "Release production from b3f23543ee49",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `b3f23543ee49bd6e054faa2212ab7e5b68673bb4`\n- Artifact hash: `67582e5fbbb74f1167853bea7fa1af584342f47f54720a0475c5c7a6d0eb341d`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29027270137)\n- Required label: `buildchain-release`\n- Release branch: `release/production-b3f23543ee49`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-09T15:00:13Z",
          "mergedAt": "2026-07-09T15:06:07Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 456,
          "url": "https://github.com/kungfu-systems/kungfu/pull/456",
          "title": "fix(slices): retarget capability slices to the yijinjing journal core",
          "body": "The schema-registry and fact-ledger capability slices link only the yijinjing\nstatic library, but four sources still opened with `using namespace\nkungfu::runtime;` left over from the runtime/storage public-API split (only the\nembedding slice was verified there). Those runtime data/journal/time aliases\ncome from <kungfu/runtime/common.h>, which the slices do not include, so the\nnames stopped resolving against their <kungfu/yijinjing/*> includes and\n`cmake --build … -DKUNGFU_WITH_SLICES=ON` failed.\n\nThis retargets producer.cpp, decoder.cpp, host.cpp and export.cpp to\nkungfu::yijinjing (matching their includes, link library, and the embedding\nslice), and follows the frame `msg_type` -> `carrier_type` rename on the read\npath. The emitted `msg_type` bundle field is unchanged.\n\nVerified (KUNGFU_WITH_SLICES=ON): built all four targets; `node\nslices/schema-registry/run.mjs build` passes; `fact_ledger_host` +\n`fact_ledger_export` verified end-to-end (segment checksum + causal chain).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:08:31Z",
          "mergedAt": "2026-07-09T15:08:36Z",
          "additions": 8,
          "deletions": 8,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 958,
          "url": "https://github.com/kungfu-systems/buildchain/pull/958",
          "title": "chore(release): promote v2.11.2 alpha",
          "body": "## Summary\n- promote current dev/v2/v2.11 fixes to alpha/v2/v2.11\n- includes publication registry site bundle and bundled KFD release gate metadata fixes\n\n## Validation\n- dev branch PR checks passed before merge\n- release promotion workflow will run after protected channel merge\n\nRelease path: dev/v2/v2.11 -> alpha/v2/v2.11",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:20:31Z",
          "mergedAt": "2026-07-09T15:23:25Z",
          "additions": 407,
          "deletions": 120,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 457,
          "url": "https://github.com/kungfu-systems/kungfu/pull/457",
          "title": "feat(storage): apply local episode repairs",
          "body": "## Summary\n- add C++ storage-service repair_apply for local Episode/source repair material\n- expose kungfu storage repair --apply --from with dry-run default and --execute mutation\n- document repair-apply safety boundaries and refresh KFD evidence\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- DYLD_FALLBACK_LIBRARY_PATH=dist/kungfu PYTHONPATH=src/python:dist/kungfu uv run --frozen pytest tests/python/test_atlas_storage.py -q\n- KUNGFU_DIR=\"$PWD/dist/kungfu\" node --test tests/storage-node-binding.test.js\n- CLI smoke: episode fsck degraded -> repair apply dry-run -> execute -> fsck ok",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:25:23Z",
          "mergedAt": "2026-07-09T15:25:29Z",
          "additions": 762,
          "deletions": 66,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 960,
          "url": "https://github.com/kungfu-systems/buildchain/pull/960",
          "title": "fix(release): allow publication registry version state",
          "body": "Fixes #959.\n\n## Summary\n- include dist/site/publication-registry.json in Buildchain semver version-state files\n- verify publication-registry package.version matches package.json\n- update version-state contract test expectation\n\n## Verification\n- node scripts/check-inventory.mjs\n- node --test tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:32:09Z",
          "mergedAt": "2026-07-09T15:34:23Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 458,
          "url": "https://github.com/kungfu-systems/kungfu/pull/458",
          "title": "feat(view): route .fbs compile through kungfu::view; flip FB gate strict (ADR-0039 slice 2)",
          "body": "Complete ADR-0039: no flatbuffers::/reflection:: symbol appears outside kungfu::view. Adds view::compile_schema (the sole .fbs->.bfbs compile entry), makes schema_compiler delegate to it (keeping only trust-tier policy), and removes the schema_compiler allowlist so the boundary gate is strict. Full core build green; view-encapsulation probe (now exercising compile_schema) passes under the strict gate; py-runtime unchanged (marshals compiled bytes, holds no reflection view). Validated C++ (standalone harness) and Python (pykungfu.runtime.compile_schema).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:34:45Z",
          "mergedAt": "2026-07-09T15:34:51Z",
          "additions": 67,
          "deletions": 33,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 961,
          "url": "https://github.com/kungfu-systems/buildchain/pull/961",
          "title": "chore(release): promote v2.11.2 alpha",
          "body": "## Summary\n- promote dev/v2/v2.11 to alpha/v2/v2.11 after fixing publication registry version-state gating\n\n## Notes\n- retries alpha promotion after #959 was resolved in #960",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:35:00Z",
          "mergedAt": "2026-07-09T15:38:00Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 1,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/1",
          "title": "feat: package product-readable white paper",
          "body": "## Summary\n- Replace private project-specific dogfood names with public-safe real-work dogfood wording.\n- Strengthen the KFD-3 product stance: human-agent cooperation should start from trusted value, not hidden pressure.\n- Make the PDF read more like a commercial white paper: cover page, executive summary, reader guide, callout box, clearer visual hierarchy, and less academic-paper framing.\n- Add an npm package contract for the white paper with generated site bundles:\n  - `site/brand-site.json` for `kungfu.tech`\n  - `site/evidence-site.json` for `papers.libkungfu.dev`\n  - `site/site-bundles.json` as the bundle index\n- Add generator/check scripts so the bundles are derived from paper source and cannot silently drift.\n- Declare canonical routes for the brand and evidence sites.\n\n## Canonical URLs\n- Brand: https://kungfu.tech/whitepaper/kungfu-real-world-agent-work\n- Brand index: https://kungfu.tech/whitepaper\n- Brand PDF: https://kungfu.tech/whitepaper/kungfu-real-world-agent-work.pdf\n- Evidence: https://papers.libkungfu.dev/kungfu-product-white-paper\n\n## Validation\n- npm run check\n- make check\n- make pdf\n- npx -y @kungfu-tech/buildchain@2.10.10 validate --cwd . --json\n- npm pack --dry-run --json\n- git diff --check\n- Rendered PDF pages 1-2 for visual QA\n\n## Risk\n- Downstream site renderers still need to consume the new bundle contracts.\n- The white paper remains a draft and needs product-positioning review before public launch use.\n- Tectonic reports a non-blocking underfull hbox warning on the cover layout.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-09T02:40:57Z",
          "mergedAt": "2026-07-09T15:46:46Z",
          "additions": 1913,
          "deletions": 143,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 459,
          "url": "https://github.com/kungfu-systems/kungfu/pull/459",
          "title": "feat(storage): source-registry records as Hana-core kernel journal (ADR-0037)",
          "body": "Move the ADR-0018 storage-service source-registry record family to Hana-core kernel metadata (ADR-0037): fixed-layout POD records written to an append-only yijinjing journal and folded into a current view, with JSON as an edge projection only. Exposed through the runtime storage service; end-to-end tests cover register/update-head/accepted-range round-trip, fsck, and dangling-head detection (22/22 storage tests pass). Accepts ADR-0037, validated by this slice.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:51:37Z",
          "mergedAt": "2026-07-09T15:51:43Z",
          "additions": 842,
          "deletions": 7,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 3,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/3",
          "title": "chore(release): trigger white paper alpha promotion",
          "body": "## Summary\n\n- create a same-repository release-channel PR into `alpha/v0/v0.1`\n- satisfy Buildchain release governance for alpha promotion\n- no content changes; the alpha branch already contains the white paper release candidate\n\n## Checks\n\n- release-channel PR checks will run on GitHub\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:49:34Z",
          "mergedAt": "2026-07-09T15:52:22Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 460,
          "url": "https://github.com/kungfu-systems/kungfu/pull/460",
          "title": "feat(storage): fetch local episode repair material",
          "body": "## Summary\n- Add C++ storage_service repair_fetch operation that consumes repair_plan output and collects local repair material from the runtime plus registered remote mirrors.\n- Expose repair fetch through Python and CLI as storage repair --fetch --out, and include it in agent/KFD discovery surfaces.\n- Extend remote mirror sync to include storage evidence and cover source/Episode repair-fetch-to-apply flows in tests.\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- PYTHONPATH=src/python:build/Release DYLD_FALLBACK_LIBRARY_PATH=build/Release uv run --frozen pytest tests/python/test_atlas_storage.py -q\n- KUNGFU_DIR=/Users/dkr/Worktrees/kungfu/feature/episode-repair-fetch-v1/framework/core/dist/kungfu pnpm --filter @kungfu-tech/core run test:storage-binding\n- CLI smoke: plan -> fetch --out -> apply --dry-run -> apply --execute -> fsck ok on /tmp/kungfu-repair-fetch.f7bB5X",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:52:57Z",
          "mergedAt": "2026-07-09T15:54:06Z",
          "additions": 601,
          "deletions": 53,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 965,
          "url": "https://github.com/kungfu-systems/buildchain/pull/965",
          "title": "feat(publication): add paper release preset",
          "body": "## Summary\n\n- add Buildchain-managed `paper-release.yml@v2` reusable workflow for publication-artifact npm publishing\n- add `buildchain publication-artifact npm-package` CLI and `@kungfu-tech/buildchain/publication-package` Node API\n- document the declarative paper release contract, Trusted Publishing setup, source lock, GitHub Release default, and site bundle surfaces\n\nFixes #962\n\n## Validation\n\n- `corepack pnpm@11.7.0 run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:59:31Z",
          "mergedAt": "2026-07-09T16:02:23Z",
          "additions": 1419,
          "deletions": 107,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 4,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/4",
          "title": "ci(buildchain): ignore runtime checkout",
          "body": "## Summary\\n- Ignore Buildchain's runtime checkout directory so promote-only version verification does not see it as an out-of-state file.\\n\\n## Verification\\n- npm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:59:52Z",
          "mergedAt": "2026-07-09T16:04:06Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 966,
          "url": "https://github.com/kungfu-systems/buildchain/pull/966",
          "title": "chore(release): promote v2.11.2 alpha",
          "body": "Promote the Buildchain v2.11.2 paper release preset work through alpha.\n\nIncludes #962 via PR #965.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T16:03:06Z",
          "mergedAt": "2026-07-09T16:05:07Z",
          "additions": 1419,
          "deletions": 107,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 5,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/5",
          "title": "release: promote white paper alpha runtime-ignore fix",
          "body": "## Summary\\n- Promote the Buildchain runtime ignore fix into the alpha channel.\\n\\n## Release\\n- Target channel: alpha/v0/v0.1\\n- Package: @kungfu-tech/paper-kungfu-product-white-paper@0.1.0-alpha.0\\n\\n## Verification\\n- Main PR #4 passed check and Buildchain publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T16:04:41Z",
          "mergedAt": "2026-07-09T16:07:01Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 968,
          "url": "https://github.com/kungfu-systems/buildchain/pull/968",
          "title": "chore(release): release v2.11.2",
          "body": "Promote Buildchain v2.11.2 from alpha to stable release.\n\nIncludes the paper release preset for #962 after alpha validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T16:09:18Z",
          "mergedAt": "2026-07-09T16:11:29Z",
          "additions": 1801,
          "deletions": 192,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 6,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/6",
          "title": "release: trigger white paper alpha publish from dev channel",
          "body": "## Summary\\n- Trigger the alpha package publication through the Buildchain-approved dev/v0/v0.1 -> alpha/v0/v0.1 channel path.\\n\\n## Release\\n- Target channel: alpha/v0/v0.1\\n- Package: @kungfu-tech/paper-kungfu-product-white-paper@0.1.0-alpha.0\\n\\n## Verification\\n- Alpha already contains PR #5 with the runtime ignore fix.\\n- This PR is an empty release trigger to satisfy Buildchain channel lineage.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T16:09:50Z",
          "mergedAt": "2026-07-09T16:11:59Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 461,
          "url": "https://github.com/kungfu-systems/kungfu/pull/461",
          "title": "feat(storage): rebuildable SQLite projection for source-registry (ADR-0037 slice 2)",
          "body": "Slice 2 of ADR-0037: project the source-registry kernel journal to a rebuildable SQLite cache via the compile-time Hana closed-set to SQLite path (make_storage_ptr over SourceRegistryDataTypes). Adds source_registry_rebuild; source_registry_fsck now verifies journal + projection, treating drift as degraded. Content-addressed payload bodies stay deferred to the payload/import slice. 24/24 storage tests pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T16:29:36Z",
          "mergedAt": "2026-07-09T16:29:42Z",
          "additions": 427,
          "deletions": 9,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 462,
          "url": "https://github.com/kungfu-systems/kungfu/pull/462",
          "title": "feat(view): verify open-layer frames at the access boundary (spatial safety)",
          "body": "Second hardening step under ADR-0039 (view-hardening parent). bind_frame now runs flatbuffers::Verify against the schema before any field access, so a malformed/truncated open-layer frame is skipped (returns std::optional nullopt), never dereferenced into an out-of-bounds reflection read. No unchecked variant: the open-layer projection is a cold async/batched path (per-frame verify is negligible next to the SQLite write) and the lock-free hot path (POD frame reads) carries no FlatBuffers and is untouched. project_frame returns bool; flush counts + warns skipped frames. Full core build green, view slice asserts truncated/garbage frames skip.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T20:29:53Z",
          "mergedAt": "2026-07-09T20:29:59Z",
          "additions": 66,
          "deletions": 21,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 463,
          "url": "https://github.com/kungfu-systems/kungfu/pull/463",
          "title": "feat(storage): payload bodies are opaque content-addressed bytes (ADR-0037)",
          "body": "Store payload bodies as opaque content-addressed bytes (storage/payloads/<hash-prefix>/<sha256>, no format-implying extension); the manifest entry commits to the body by hash, length, and content_type metadata. Aligns C++ runtime service and Python importer on the content-addressed path. Decouples and precedes the import-manifest migration. 25/25 storage tests pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T20:34:15Z",
          "mergedAt": "2026-07-09T20:34:21Z",
          "additions": 77,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 970,
          "url": "https://github.com/kungfu-systems/buildchain/pull/970",
          "title": "fix(web-surface): wait for CloudFront invalidations before health",
          "body": "## Summary\n- wait for applied CloudFront invalidations before web-surface health checks fetch public smoke URLs\n- add unit coverage for extracting invalidation wait targets from apply results\n- document the health-check ordering to avoid stale CloudFront 403 failures after successful deploy apply\n\n## Verification\n- `node --check scripts/web-surface.mjs && node --test tests/web-surface.test.mjs`\n- `pnpm run check`\n\n## Context\n`site-kungfu-tech` PR preview apply succeeds, but the health job can fetch CloudFront before the new invalidation reaches `Completed`, producing transient 403 failures even though the preview URL becomes healthy after invalidation propagation.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T20:42:30Z",
          "mergedAt": "2026-07-09T20:44:32Z",
          "additions": 168,
          "deletions": 13,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 971,
          "url": "https://github.com/kungfu-systems/buildchain/pull/971",
          "title": "chore(release): promote v2.11 web-surface health fix to alpha",
          "body": "## Summary\n- promote the web-surface health fix from dev/v2/v2.11 into the alpha channel\n- includes waiting for CloudFront invalidations before public smoke checks\n\n## Verification\n- source PR #970 passed Verify and Build Surface Fixture\n- local `pnpm run check` passed before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T20:45:25Z",
          "mergedAt": "2026-07-09T20:47:36Z",
          "additions": 168,
          "deletions": 13,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 972,
          "url": "https://github.com/kungfu-systems/buildchain/pull/972",
          "title": "chore(release): promote v2.11.3 to stable",
          "body": "## Summary\n- promote Buildchain v2.11.3 alpha to the stable release line\n- carries the web-surface health fix that waits for CloudFront invalidations before public smoke checks\n\n## Evidence\n- alpha promotion published `2.11.3-alpha.1`\n- source fix PR #970 passed Verify and Build Surface Fixture\n- alpha channel PR #971 passed checks and promotion\n\n## Expected impact\n- moves stable `v2` / `v2.11` and npm `latest` to the patch release after promotion\n- lets web-surface consumers using `@v2` avoid transient stale CloudFront 403 health failures\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T20:51:13Z",
          "mergedAt": "2026-07-09T20:53:09Z",
          "additions": 183,
          "deletions": 28,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 973,
          "url": "https://github.com/kungfu-systems/buildchain/pull/973",
          "title": "fix(web-surface): retry transient health smoke failures",
          "body": "## Summary\n- retry transient HTTP 403/404/5xx responses during web-surface health smoke checks\n- record the number of HTTP attempts in health check output\n- document that health checks wait for CloudFront invalidations and then absorb short edge propagation windows\n\n## Verification\n- `node --test tests/web-surface.test.mjs`\n- `pnpm run generate:site && pnpm run check`\n\n## Context\n`site-kungfu-tech` preview apply now waits for CloudFront invalidation completion, but GitHub-hosted runner HTTP smoke can still observe a short stale 403 window immediately after the waiter returns. Manual checks succeed seconds later. The health check should stay strict while retrying these transient edge states.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T21:11:44Z",
          "mergedAt": "2026-07-09T21:13:43Z",
          "additions": 104,
          "deletions": 13,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 974,
          "url": "https://github.com/kungfu-systems/buildchain/pull/974",
          "title": "chore(release): promote web-surface health retry to alpha",
          "body": "## Summary\n- promote web-surface health retry fix to alpha\n- carries the retry for transient 403/404/5xx public smoke failures after CloudFront invalidation wait\n\n## Evidence\n- source PR #973 passed Verify and Build Surface Fixture\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T21:13:58Z",
          "mergedAt": "2026-07-09T21:16:10Z",
          "additions": 104,
          "deletions": 13,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 975,
          "url": "https://github.com/kungfu-systems/buildchain/pull/975",
          "title": "chore(release): promote v2.11.4 to stable",
          "body": "Promote Buildchain v2.11.4 to stable.\n\nThis release includes the web-surface health smoke retry fix after CloudFront invalidation waits. It keeps the generated site workflow from failing on short-lived 403/404/5xx responses immediately after the invalidation has completed.\n\nValidation already completed on alpha:\n- alpha promotion published `@kungfu-tech/buildchain@2.11.4-alpha.1`\n- Buildchain Ref Promotion run completed successfully\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T21:20:04Z",
          "mergedAt": "2026-07-09T21:22:36Z",
          "additions": 119,
          "deletions": 28,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 976,
          "url": "https://github.com/kungfu-systems/buildchain/pull/976",
          "title": "fix(web-surface): extend health retry window",
          "body": "Extend the default web-surface HTTP health retry window after CloudFront invalidation waits.\n\nWhy:\n- site-kungfu-tech preview apply still observed transient 403 responses after the invalidation waiter completed.\n- The previous default retry window was only about 20 seconds after invalidation completion, which was too short for the observed CloudFront propagation behavior.\n\nChange:\n- Default HTTP smoke retries are now 12 attempts at 10 second intervals.\n- Consumers can still override with BUILDCHAIN_WEB_SURFACE_HEALTH_HTTP_RETRY_ATTEMPTS and BUILDCHAIN_WEB_SURFACE_HEALTH_HTTP_RETRY_INTERVAL_MS.\n- Added a regression test that the default window absorbs extended transient 403s without requiring slow sleeps.\n\nValidation:\n- node --test tests/web-surface.test.mjs\n- pnpm run generate:site && pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T21:34:07Z",
          "mergedAt": "2026-07-09T21:36:04Z",
          "additions": 64,
          "deletions": 15,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 977,
          "url": "https://github.com/kungfu-systems/buildchain/pull/977",
          "title": "chore(release): promote web-surface health retry window to alpha",
          "body": "Promote the web-surface health retry-window fix to alpha.\n\nThis carries the Buildchain web-surface default health retry window change:\n- 12 HTTP smoke attempts\n- 10 second retry interval\n- transient 403/404/5xx retry after CloudFront invalidation waits\n\nValidation on dev:\n- Verify run passed after merging the fix to dev/v2/v2.11\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T21:37:31Z",
          "mergedAt": "2026-07-09T21:39:59Z",
          "additions": 64,
          "deletions": 15,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 978,
          "url": "https://github.com/kungfu-systems/buildchain/pull/978",
          "title": "chore(release): promote v2.11.5 to stable",
          "body": "Promote Buildchain v2.11.5 to stable.\n\nThis release extends the web-surface HTTP health retry window after CloudFront invalidation waits:\n- default 12 attempts\n- default 10 second interval\n- retryable transient 403/404/5xx\n\nReason:\n- site-kungfu-tech preview apply observed 403 responses after invalidation completion even with the shorter 2.11.4 retry window.\n\nValidation:\n- alpha published as @kungfu-tech/buildchain@2.11.5-alpha.1\n- Buildchain Ref Promotion completed successfully for alpha\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T21:43:44Z",
          "mergedAt": "2026-07-09T21:49:18Z",
          "additions": 79,
          "deletions": 30,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 979,
          "url": "https://github.com/kungfu-systems/buildchain/pull/979",
          "title": "fix(web-surface): support explicit S3 health strategy",
          "body": "## Summary\n\n- adds `deploy.<channel>.health_strategy = \"s3-object\"` for web-surface channels and per-surface overrides\n- lets public preview channels verify uploaded deployment manifests and S3 objects without waiting on public edge HTTP convergence\n- documents the contract and adds regression coverage for preview S3 health without public fetches\n\n## Validation\n\n- `node --test tests/buildchain-config.test.mjs tests/web-surface.test.mjs`\n- `pnpm run generate:site && pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T22:08:05Z",
          "mergedAt": "2026-07-09T22:09:46Z",
          "additions": 230,
          "deletions": 100,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 980,
          "url": "https://github.com/kungfu-systems/buildchain/pull/980",
          "title": "chore(release): promote explicit S3 health strategy to alpha",
          "body": "## Summary\n\n- promotes explicit `s3-object` web-surface health strategy to alpha\n- includes contract, documentation, bundle, and regression tests from dev\n\n## Validation\n\n- dev `Verify` passed on `daf621da5f2b62e9d43a2b2c987f440fc7429b39`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T22:11:04Z",
          "mergedAt": "2026-07-09T22:12:59Z",
          "additions": 230,
          "deletions": 100,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 981,
          "url": "https://github.com/kungfu-systems/buildchain/pull/981",
          "title": "chore(release): promote v2.11.6 to stable",
          "body": "## Summary\n\n- promotes Buildchain v2.11.6 to stable\n- includes explicit S3 object health strategy for public web-surface preview channels\n- carries the alpha-tested release material from `v2.11.6-alpha.1`\n\n## Validation\n\n- alpha `Verify` passed on `abdd57778ad614737aa9078f97ca412bd8445e14`\n- `v2.11.6-alpha.1` Binary Distribution passed\n- npm alpha dist-tag points to `2.11.6-alpha.1`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T22:18:02Z",
          "mergedAt": "2026-07-09T22:20:01Z",
          "additions": 245,
          "deletions": 115,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 19,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/19",
          "title": "ci(site): adopt Buildchain v2 contract lock",
          "body": "## Summary\n- move Buildchain config to `.buildchain/buildchain.toml`\n- add `.buildchain/contract-lock.json` for floating `@v2` anti-drift validation\n- switch the web-surface workflow from `@v2.4` to `@v2`\n- keep staging on ordinary main pushes and production behind Buildchain release PR/manual approval gates\n- update local checks and docs to reject the legacy root Buildchain layout\n\n## Validation\n- `ruby -e 'require \"yaml\"; YAML.load_file(\".github/workflows/buildchain-web-surface.yml\"); puts \"workflow yaml ok\"'`\\n- `bash scripts/build-site.sh && bash scripts/check-site.sh`\\n- `npm exec --yes --package @kungfu-tech/buildchain@latest -- buildchain kfd status --cwd . --json`\\n- `npm exec --yes --package @kungfu-tech/buildchain@latest -- buildchain validate --cwd . --require-lifecycle-stages build,verify`\\n- Buildchain web-surface validate + staging/production deploy-plan generation with `@kungfu-tech/buildchain@2.11.2`\\n- Buildchain contract lock check against `v2` / `085efbc375abc53352c2e01ff58164d441b5fc90`\\n\\n## Live deploy\\nThis PR should publish preview only. Merging to main will run the normal Buildchain v2 staging flow and should no longer start staging apply without a staging plan.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T16:30:28Z",
          "mergedAt": "2026-07-09T22:35:05Z",
          "additions": 167,
          "deletions": 15,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 982,
          "url": "https://github.com/kungfu-systems/buildchain/pull/982",
          "title": "fix(web-surface): accept bucket-root S3 health evidence",
          "body": "## Summary\n\n- treats an explicit empty `objectPrefix` as valid bucket-root deployment evidence\n- keeps managed-network staging health on S3 manifest/object checks for bucket-root sites\n- adds regression coverage for root and nested object keys at bucket root\n\n## Validation\n\n- `node --test tests/web-surface.test.mjs`\n- `pnpm run generate:site && pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T22:40:23Z",
          "mergedAt": "2026-07-09T22:42:17Z",
          "additions": 49,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 983,
          "url": "https://github.com/kungfu-systems/buildchain/pull/983",
          "title": "chore(release): promote bucket-root health fix to alpha",
          "body": "## Summary\n\n- promotes bucket-root managed-network S3 health evidence fix to alpha\n- keeps bucket-root staging deployments from being misclassified as missing objectPrefix\n\n## Validation\n\n- dev `Verify` passed on `c0c30b8cc35e9e653e06de53b240a0608ab5fdfd`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T22:43:47Z",
          "mergedAt": "2026-07-09T22:45:38Z",
          "additions": 49,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 984,
          "url": "https://github.com/kungfu-systems/buildchain/pull/984",
          "title": "chore(release): promote v2.11.7 to stable",
          "body": "## Summary\n\n- promotes Buildchain v2.11.7 to stable\n- includes the bucket-root managed-network S3 health evidence fix\n- carries alpha-tested release material from `v2.11.7-alpha.1`\n\n## Validation\n\n- alpha `Verify` passed\n- `v2.11.7-alpha.1` Binary Distribution passed\n- npm alpha dist-tag points to `2.11.7-alpha.1`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T22:50:51Z",
          "mergedAt": "2026-07-09T22:53:09Z",
          "additions": 65,
          "deletions": 17,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 20,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/20",
          "title": "ci(site): accept Buildchain v2.11.7 runtime",
          "body": "## Summary\n\n- Accept the floating `v2` Buildchain runtime at `v2.11.7`.\n- Keep the existing `v2` contract-lock pattern while moving the resolved SHA past the bucket-root S3 health fix.\n\n## Verification\n\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `npm exec --yes --package @kungfu-tech/buildchain@latest -- buildchain validate --cwd . --require-lifecycle-stages build,verify`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T23:00:33Z",
          "mergedAt": "2026-07-09T23:02:44Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 21,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/21",
          "title": "Release production from c8b82cbed2e8",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `c8b82cbed2e8672b87becb98b0966bb450408031`\n- Artifact hash: `57f94c5d5ce4180bf92a3af14e9f0a91a24f300360f2d66f1d112260edf689e7`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29056280362)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-c8b82cbed2e8`\n\nThis PR intentionally contains one empty release-intent commit.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T23:06:46Z",
          "mergedAt": "2026-07-09T23:08:39Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 60,
          "url": "https://github.com/kungfu-systems/build-images/pull/60",
          "title": "fix(ci): drop buildchain KFD NODE_PATH workaround",
          "body": "## Summary\n- remove the consumer-side NODE_PATH workaround from the default Buildchain promotion workflow\n- rely on Buildchain v2.11.7+ bundling KFD release gate metadata (kungfu-systems/buildchain#956 / PR #957)\n\n## Verification\n- ruby YAML parse for .github/workflows/buildchain-ref-promotion.yml",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:03:00Z",
          "mergedAt": "2026-07-10T00:04:09Z",
          "additions": 0,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 987,
          "url": "https://github.com/kungfu-systems/buildchain/pull/987",
          "title": "fix(web-surface): report unavailable release app token",
          "body": "## Summary\n- resolve production release PR token config before opening the PR\n- report `app-token-unavailable` when GitHub App config is incomplete or token creation fails\n- include token source/app token status in handoff outputs and docs\n\nFixes #985.\n\n## Verification\n- `node --check scripts/web-surface-production-release-pr.mjs && node --test tests/build-surface.test.mjs`\n- `bash scripts/check-workflows.sh`\n- `corepack pnpm@11.7.0 run check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:03:01Z",
          "mergedAt": "2026-07-10T00:06:48Z",
          "additions": 223,
          "deletions": 40,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 61,
          "url": "https://github.com/kungfu-systems/build-images/pull/61",
          "title": "fix(buildchain): update v1.2 contract lock to 2.11.7",
          "body": "## Summary\n- update @kungfu-tech/buildchain from 2.11.0 to 2.11.7\n- refresh .buildchain/contract-lock.json to the v2.11.7 tag commit\n- migrate KFD evidence to the current .buildchain/kfd/kfd-{1,2,3} layout\n- update release-passport evidence paths and keep GitHub Release upload enabled\n\n## Verification\n- pnpm install --frozen-lockfile\n- pnpm run check\n- pnpm exec buildchain validate --require-version-state --require-lifecycle-stages verify,publish\n- collectKfdStatus layout=current",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:07:56Z",
          "mergedAt": "2026-07-10T00:09:20Z",
          "additions": 101,
          "deletions": 98,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 988,
          "url": "https://github.com/kungfu-systems/buildchain/pull/988",
          "title": "chore(release): promote v2.11.8 alpha",
          "body": "Promote the latest Buildchain v2.11 web-surface fixes through alpha.\n\nIncludes #985 via PR #987.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:07:32Z",
          "mergedAt": "2026-07-10T00:09:21Z",
          "additions": 223,
          "deletions": 40,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 62,
          "url": "https://github.com/kungfu-systems/build-images/pull/62",
          "title": "chore(alpha): promote Buildchain 2.11.7 contract lock",
          "body": "## Summary\n- promote the v1.2 Buildchain 2.11.7 contract-lock update through the strict alpha source-lock path\n- verify the latest Buildchain v2 action no longer needs the build-images NODE_PATH workaround for KFD metadata\n\n## Verification\n- pnpm install --frozen-lockfile\n- pnpm run check\n- ruby YAML parse for buildchain-ref-promotion workflow",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:10:46Z",
          "mergedAt": "2026-07-10T00:11:54Z",
          "additions": 101,
          "deletions": 98,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 990,
          "url": "https://github.com/kungfu-systems/buildchain/pull/990",
          "title": "fix(release): make durable state writes ref-safe",
          "body": "## Summary\n- make durable release-state writes retry-safe without force-updating refs\n- treat retried createRef/updateRef success as idempotent when GitHub returns reference-exists or non-fast-forward after a transient response failure\n- cover create visibility races and update retry races in promote-buildchain-ref tests\n\nFixes #989.\n\n## Verification\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:20:35Z",
          "mergedAt": "2026-07-10T00:22:16Z",
          "additions": 180,
          "deletions": 83,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 63,
          "url": "https://github.com/kungfu-systems/build-images/pull/63",
          "title": "fix(ci): pass KFD passport inputs as JSON arrays",
          "body": "## Summary\n\n- pass Buildchain release-passport KFD inputs as JSON arrays to avoid v2 action JSON.parse failures\n- keep v1.1 legacy KFD paths while routing v1.2+ targets to the canonical .buildchain/kfd layout\n\n## Validation\n\n- ruby -e 'require \"yaml\"; YAML.load_file(\".github/workflows/buildchain-ref-promotion.yml\"); puts \"yaml-ok\"'\n\nRelated upstream Buildchain issue: kungfu-systems/buildchain#991",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:25:38Z",
          "mergedAt": "2026-07-10T00:26:31Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 992,
          "url": "https://github.com/kungfu-systems/buildchain/pull/992",
          "title": "fix(paper): reduce release path friction",
          "body": "## Summary\n- ignore the checked-out Buildchain runtime when verifying version-state local changes\n- report all missing protected-channel settings in one governance failure\n- keep the existing first-class paper release workflow covered by the done-check\n\nFixes #986.\nCloses #963.\nCloses #964.\nCloses #967.\nCloses #969.\n\n## Verification\n- corepack pnpm@11.7.0 install --frozen-lockfile\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:26:23Z",
          "mergedAt": "2026-07-10T00:28:04Z",
          "additions": 102,
          "deletions": 47,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 64,
          "url": "https://github.com/kungfu-systems/build-images/pull/64",
          "title": "fix(ci): keep KFD passport inputs as documented paths",
          "body": "## Summary\n\n- undo the JSON-array workaround that Buildchain v2 does not accept for KFD witnesses\n- keep target-ref-based path selection so v1.1 uses legacy KFD paths and v1.2+ uses the canonical .buildchain/kfd layout\n\n## Validation\n\n- ruby -e 'require \"yaml\"; YAML.load_file(\".github/workflows/buildchain-ref-promotion.yml\"); puts \"yaml-ok\"'\n\nUpstream blocker: kungfu-systems/buildchain#991",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:29:52Z",
          "mergedAt": "2026-07-10T00:30:58Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 464,
          "url": "https://github.com/kungfu-systems/kungfu/pull/464",
          "title": "feat(view): add fuzz + sanitizer targets for the FlatBuffers access module (PoC)",
          "body": "Land the kungfu::view fuzz/sanitizer targets (ADR-0039 residual risk, view-hardening child B). Three libFuzzer targets over the untrusted-input entries (compile_schema / from_bytes / bind_frame), each linking only the view module + FlatBuffers + SQLite, plus seed corpus and a validated build recipe (README). PoC validated on mac arm64: from_bytes 698k / compile_schema 211k / bind_frame 2.7M execs no crash; a planted skip-verify makes the fuzzer catch an out-of-bounds ReadScalar in seconds. NOTE: these sources carry no CMakeLists yet (not wired into any build/CI) — the CMake option + verify.mjs sanitizer stage + alpha-build fuzz gate are the next stage; until then they are inert assets and can bit-rot.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:32:16Z",
          "mergedAt": "2026-07-10T00:32:21Z",
          "additions": 170,
          "deletions": 0,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 993,
          "url": "https://github.com/kungfu-systems/buildchain/pull/993",
          "title": "fix(passport): accept cwd-relative KFD inputs",
          "body": "## Summary\n- resolve release passport JSON input paths relative to the caller cwd before parsing inline JSON\n- preserve KFD witness/claim path-list inputs documented by promote-buildchain-ref\n- add regression coverage for .buildchain/kfd/... relative witness paths\n\n## Validation\n- corepack pnpm@11.7.0 exec node --test tests/release-passport.test.mjs\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- corepack pnpm@11.7.0 run check\n\nFixes #991",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:34:02Z",
          "mergedAt": "2026-07-10T00:36:05Z",
          "additions": 138,
          "deletions": 79,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 994,
          "url": "https://github.com/kungfu-systems/buildchain/pull/994",
          "title": "chore(release): promote v2.11 fixes to alpha",
          "body": "## Summary\nPromote the accumulated v2.11 fixes from dev to alpha.\n\nIncluded fixes:\n- release-state durable non-fast-forward finalization recovery (#990)\n- paper release friction fixes (#992)\n- cwd-relative KFD passport path inputs (#993)\n\n## Validation\n- covered by merged PR checks on #990, #992, and #993\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:37:19Z",
          "mergedAt": "2026-07-10T00:39:07Z",
          "additions": 347,
          "deletions": 136,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 995,
          "url": "https://github.com/kungfu-systems/buildchain/pull/995",
          "title": "chore(release): promote v2.11.8 to stable",
          "body": "## Summary\nPromote Buildchain v2.11.8 alpha fixes to the stable v2 release line.\n\nIncluded fixes:\n- durable release-state non-fast-forward finalization recovery\n- paper release path friction reductions\n- cwd-relative KFD passport path-list inputs\n\n## Alpha validation\n- v2.11.8-alpha.2 published successfully\n- npm dist-tag alpha points to 2.11.8-alpha.2\n- Buildchain Ref Promotion run 29060539597 completed successfully\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:43:22Z",
          "mergedAt": "2026-07-10T00:45:00Z",
          "additions": 584,
          "deletions": 190,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 465,
          "url": "https://github.com/kungfu-systems/kungfu/pull/465",
          "title": "docs(adr): ADR-0040 — first-class content-addressed KV as a runtime fact-ledger primitive",
          "body": "Records the runtime fact ledger's first-class content-addressed KV primitive: one uniform contract features build on; content-addressing as the concurrency/dedup/tiering enabler; backend-neutral with a one-way dependency direction (yijinjing owns the interface, must not depend on any concrete engine; RocksDB isolated/injected/replaceable behind a boundary gate); per-agent journals for linear write scaling; scale target single-node TB-to-tens-of-TB, sharded to hundreds of TB, tiered toward PB. Status: proposed.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:45:03Z",
          "mergedAt": "2026-07-10T00:45:09Z",
          "additions": 294,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 997,
          "url": "https://github.com/kungfu-systems/buildchain/pull/997",
          "title": "fix(release): tolerate stale release-state ref reads",
          "body": "## Summary\n- retry durable release-state non-fast-forward recovery when GitHub getRef briefly returns the stale parent SHA\n- rebuild the release-state commit on the refreshed head before retrying updateRef\n- add regression coverage for stale ref reads after non-fast-forward\n\n## Validation\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- corepack pnpm@11.7.0 run check\n\nFixes #996",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:51:16Z",
          "mergedAt": "2026-07-10T00:52:51Z",
          "additions": 110,
          "deletions": 65,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 998,
          "url": "https://github.com/kungfu-systems/buildchain/pull/998",
          "title": "chore(release): promote release-state retry fix to alpha",
          "body": "## Summary\nPromote the durable release-state stale-ref retry fix to alpha after stable v2.11.8 finalization exposed a GitHub ref visibility race.\n\nIncluded fix:\n- tolerate stale getRef reads after non-fast-forward release-state update conflicts (#997)\n\n## Validation\n- PR #997 checks passed\n- corepack pnpm@11.7.0 run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:53:56Z",
          "mergedAt": "2026-07-10T00:55:32Z",
          "additions": 110,
          "deletions": 65,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 999,
          "url": "https://github.com/kungfu-systems/buildchain/pull/999",
          "title": "chore(release): promote v2.11.9 to stable",
          "body": "## Summary\nPromote Buildchain v2.11.9 to stable after validating the durable release-state stale-ref retry fix in alpha.\n\nIncluded fix:\n- durable release-state non-fast-forward recovery now waits out stale getRef reads (#997)\n\n## Alpha validation\n- v2.11.9-alpha.0 published successfully\n- npm dist-tag alpha points to 2.11.9-alpha.0\n- Buildchain Ref Promotion run 29061209271 completed successfully\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:59:36Z",
          "mergedAt": "2026-07-10T01:01:25Z",
          "additions": 126,
          "deletions": 81,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 466,
          "url": "https://github.com/kungfu-systems/kungfu/pull/466",
          "title": "docs(adr): ADR-0041 — the Episode manifest is the object's trust boundary, a POD-native journal structure",
          "body": "Makes the Episode manifest (the Episode's trust boundary per ADR-0033) a first-class POD-native yijinjing journal structure and tightens the four operations around it (POD-native fold JSON-edge-only, tight open/seal writer contract, runtime over typed structure, fsck verifying trust-boundary claims + causal closure + frame integrity, query over folded view + rebuildable SQLite projection; content-addressed refs via the ADR-0040 KV). Deliberately scoped to the manifest; the complete Episode object model is a forthcoming ADR. Status: proposed.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T01:07:20Z",
          "mergedAt": "2026-07-10T01:07:26Z",
          "additions": 217,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 22,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/22",
          "title": "ci(site): accept Buildchain v2.11.9 runtime",
          "body": "## Summary\n\n- Accept the floating `v2` Buildchain runtime at `v2.11.9`.\n- Keep the existing major-compatible contract lock while consuming the release-app-token handling fix from Buildchain.\n\n## Verification\n\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `npm exec --yes --package @kungfu-tech/buildchain@latest -- buildchain validate --cwd . --require-lifecycle-stages build,verify`\n\n## Follow-up validation\n\nAfter merge, this should verify that staging can automatically open the production release PR through the configured Buildchain release GitHub App path.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T01:10:57Z",
          "mergedAt": "2026-07-10T01:13:29Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 65,
          "url": "https://github.com/kungfu-systems/build-images/pull/65",
          "title": "fix(buildchain): update v1.2 contract lock to 2.11.9",
          "body": "## Summary\n\n- update local Buildchain dependency from 2.11.7 to 2.11.9\n- refresh Buildchain contract lock to v2.11.9 / ac5142e51969e71d7c2351175ebfeeed3da8a80b\n- refresh KFD aggregate/claim hashes after the lock update\n\n## Validation\n\n- pnpm install --frozen-lockfile\n- pnpm exec buildchain validate --require-version-state --require-lifecycle-stages verify,publish\n- pnpm run check\n\nRelated upstream fix: kungfu-systems/buildchain#991 / PR #993",
          "author": "dongkeren",
          "createdAt": "2026-07-10T01:15:12Z",
          "mergedAt": "2026-07-10T01:16:19Z",
          "additions": 21,
          "deletions": 21,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 66,
          "url": "https://github.com/kungfu-systems/build-images/pull/66",
          "title": "fix(buildchain): promote v1.2 contract lock to 2.11.9",
          "body": "## Summary\n\n- promote the Buildchain 2.11.9 contract-lock update from dev/v1/v1.2 into alpha/v1/v1.2\n- use strict publish-gate source-lock branch shape for Buildchain alpha promotion\n\n## Validation\n\n- pnpm install --frozen-lockfile\n- pnpm run check\n\nRelated upstream fix: kungfu-systems/buildchain#991 / PR #993",
          "author": "dongkeren",
          "createdAt": "2026-07-10T01:17:06Z",
          "mergedAt": "2026-07-10T01:18:11Z",
          "additions": 21,
          "deletions": 21,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 7,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/7",
          "title": "ci(buildchain): validate v2.11.9 alpha publication",
          "body": "## Summary\\n- Bump the white paper package to 0.1.0-alpha.1 for a real alpha publication validation.\\n- Update the Buildchain npm dev dependency and contract lock to v2.11.9.\\n- Refresh site bundle packageVersion metadata.\\n\\n## Verification\\n- npm run check\\n- Local Docker/PDF build was attempted but the local GHCR image pull stalled; GitHub Actions Build will provide the Docker publication build proof.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T01:21:15Z",
          "mergedAt": "2026-07-10T01:23:02Z",
          "additions": 15,
          "deletions": 15,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 8,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/8",
          "title": "chore(release): stage alpha.1 on dev channel",
          "body": "## Summary\\n- Stage 0.1.0-alpha.1 and Buildchain v2.11.9 on the protected dev channel.\\n\\n## Verification\\n- npm run check\\n- PR #7 passed Buildchain publication on main.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T01:26:00Z",
          "mergedAt": "2026-07-10T01:28:03Z",
          "additions": 15,
          "deletions": 15,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 9,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/9",
          "title": "release: publish white paper alpha.1 with Buildchain v2.11.9",
          "body": "## Summary\\n- Promote 0.1.0-alpha.1 into the alpha channel.\\n- Validate Buildchain v2.11.9 after the paper release friction fixes.\\n\\n## Release\\n- Target channel: alpha/v0/v0.1\\n- Package: @kungfu-tech/paper-kungfu-product-white-paper@0.1.0-alpha.1\\n- Buildchain: v2.11.9 / ac5142e51969e71d7c2351175ebfeeed3da8a80b\\n\\n## Verification\\n- PR #7 passed check and Buildchain publication on main.\\n- PR #8 passed check and Buildchain publication into protected dev.\\n- This PR uses the canonical dev/v0/v0.1 -> alpha/v0/v0.1 channel path.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T01:28:41Z",
          "mergedAt": "2026-07-10T01:30:37Z",
          "additions": 15,
          "deletions": 15,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 467,
          "url": "https://github.com/kungfu-systems/kungfu/pull/467",
          "title": "fix(view): reject rootless .bfbs at the load boundary; wire the fuzz + sanitizer gate",
          "body": "Memory-safety coverage for kungfu::view (ADR-0039 residual risk).\n\nTwo tiers over the three FlatBuffers access entries (compile_schema / from_bytes /\nbind_frame), sharing one set of libFuzzer entry functions:\n- KUNGFU_WITH_SANITIZERS: ASan/UBSan corpus replay via a libFuzzer-less driver\n  (any build compiler; MSVC /fsanitize=address on Windows) — the every-build tier.\n- KUNGFU_WITH_FUZZ: real libFuzzer long-run (needs a libFuzzer-capable clang).\n\nfuzz/CMakeLists.txt is a standalone project (the fuzz tier needs a different\ncompiler than the conan/cmake-js core toolchain); scripts/verify.mjs stage 7 drives\nboth against the conan tree build:core seeds, without mutating the checked-in\ncorpus; the alpha/release build runs verify --fuzz so a new crash blocks the alpha.\n\nFixes a spatial-safety hole the new gate found: a valid .bfbs with no root_type\npasses VerifySchemaBuffer but leaves root_table() null, which plan_columns /\nbind_frame / verify_table then dereference. from_bytes now rejects a rootless\nschema at the sole load boundary.\n\nValidated on mac arm64: after the fix all three targets run crash-free\n(compile_schema 842k / from_bytes 2.2M / bind_frame 12M execs, 30s each).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:02:08Z",
          "mergedAt": "2026-07-10T02:02:14Z",
          "additions": 494,
          "deletions": 43,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 468,
          "url": "https://github.com/kungfu-systems/kungfu/pull/468",
          "title": "docs(storage): clarify content and episode manifest contracts",
          "body": "## Summary\n\nClarify the two proposed storage ADRs before implementation begins.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- narrow ADR-0040 to an immutable content-store contract and keep mutable KV as a separate capability\n- define backend capability, durability, visibility, ownership, and scale evidence boundaries\n- distinguish POD manifest records from the typed Episode current view in ADR-0041\n- add writer ownership, cross-journal crash recovery, schema-mapping, and staged dependency gates\n- update the ADR index titles\n\n## Verification\n\n- `git diff --check`\n- `./kungfu-code check`\n- public-surface scan for private paths or maintenance-authorship signals\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:08:32Z",
          "mergedAt": "2026-07-10T02:17:24Z",
          "additions": 200,
          "deletions": 144,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 1,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/1",
          "title": "ci(buildchain): enable managed paper releases",
          "body": "## Summary\n\n- declare the paper as a Buildchain publication artifact\n- build the PDF with the digest-pinned LaTeX Docker toolchain\n- validate the floating Buildchain v2 contract through the consumer lock\n- synthesize and publish the npm paper package through the managed paper release preset\n- generate publication manifests, passports, archive registry, source bundle, and GitHub Releases\n\n## Trusted Publishing handoff\n\n- npm package already bootstrapped\n- trusted publisher repository: this repository\n- workflow: `.github/workflows/paper-release.yml`\n\n## Checks\n\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- Buildchain Verify workflow\n- Buildchain publication artifact workflow with a real PDF build",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:23:20Z",
          "mergedAt": "2026-07-10T02:28:24Z",
          "additions": 268,
          "deletions": 2,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 2,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/2",
          "title": "ci(buildchain): enable managed paper releases",
          "body": "## Summary\n\n- declare the paper as a Buildchain publication artifact\n- build the PDF with the digest-pinned LaTeX Docker toolchain\n- validate the floating Buildchain v2 contract through the consumer lock\n- synthesize and publish the npm paper package through the managed paper release preset\n- generate publication manifests, passports, archive registry, source bundle, and GitHub Releases\n\n## Trusted Publishing handoff\n\n- npm package already bootstrapped\n- trusted publisher repository: this repository\n- workflow: `.github/workflows/paper-release.yml`\n\n## Checks\n\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- Buildchain Verify workflow\n- Buildchain publication artifact workflow with a real PDF build",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:20:44Z",
          "mergedAt": "2026-07-10T02:28:35Z",
          "additions": 268,
          "deletions": 2,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1000,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1000",
          "title": "docs: record Buildchain consolidation retrospective",
          "body": "## Summary\n\n- record the 2026-07-10 consolidation evidence and priorities\n- define P0 acceptance criteria for release impact truth and promotion serialization\n- add a durable maintainer handoff pointer to AGENTS.md and CONTRIBUTING.md\n- correct the active action inventory to include report-buildchain-issue\n\n## Validation\n\n- node scripts/check-inventory.mjs\n- bash scripts/check-workflows.sh\n- git diff --check\n- public-boundary scan for private workspace and maintenance-attribution terms\n\n## Scope\n\nDocumentation only. This PR does not change release behavior, refs, tags, or published artifacts.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:19:12Z",
          "mergedAt": "2026-07-10T02:28:48Z",
          "additions": 243,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 24,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/24",
          "title": "Render the Kungfu product white paper",
          "body": "## Summary\n\n- consume @kungfu-tech/paper-kungfu-product-white-paper@0.1.0-alpha.1 from an exact pnpm lock\n- render the product-facing white paper index, reader, and responsive section navigation from the upstream brand bundle\n- publish the package PDF only after validating its Buildchain publication digest\n- emit /whitepaper/manifest.json and /whitepaper/llms.txt for agent consumption\n- keep same-site navigation on preview/staging while preserving canonical cross-site evidence links\n\n## Verification\n\n- corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/\n- pnpm run build\n- pnpm run check\n- shell syntax and ShellCheck\n- desktop 1440x1000 browser check: no overflow, PDF rendered, no console errors\n- mobile 390x844 browser check: no overflow, section navigation and structured tables/cards rendered correctly\n\n## Boundary\n\nThis repository renders the upstream site bundle. It does not copy or redefine white paper product facts. The papers.libkungfu.dev evidence destination is released separately and is not created by this pull request.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:37:17Z",
          "mergedAt": "2026-07-10T02:51:15Z",
          "additions": 1211,
          "deletions": 123,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 2,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/2",
          "title": "chore(release): bootstrap v0.1 development line",
          "body": "## Summary\n\n- bootstrap the protected `dev/v0/v0.1` paper release line\n- carry the reviewed Buildchain publication contract from `main`\n- keep npm publication disabled until the separate dev-to-alpha promotion\n\n## Validation\n\n- Buildchain Verify workflow\n- Buildchain publication artifact workflow\n- no npm publish side effect on the dev channel",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:53:13Z",
          "mergedAt": "2026-07-10T02:54:41Z",
          "additions": 268,
          "deletions": 2,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 3,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/3",
          "title": "chore(release): bootstrap v0.1 development line",
          "body": "## Summary\n\n- bootstrap the protected `dev/v0/v0.1` paper release line\n- carry the reviewed Buildchain publication contract from `main`\n- keep npm publication disabled until the separate dev-to-alpha promotion\n\n## Validation\n\n- Buildchain Verify workflow\n- Buildchain publication artifact workflow\n- no npm publish side effect on the dev channel",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:53:15Z",
          "mergedAt": "2026-07-10T02:54:46Z",
          "additions": 268,
          "deletions": 2,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 3,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/3",
          "title": "chore(release): publish v0.1 alpha",
          "body": "## Summary\n\n- promote the reviewed `dev/v0/v0.1` publication contract to the protected alpha channel\n- publish `0.1.0-alpha.0` through Buildchain paper release and npm Trusted Publishing\n- generate the exact-version GitHub prerelease and Buildchain Release Passport\n\n## Immutable effects after merge\n\n- public npm alpha version\n- exact Git tag and GitHub prerelease\n- Buildchain durable release state and evidence\n\n## Required validation\n\n- protected `check / check` succeeds\n- publication artifact build succeeds\n- post-merge paper release transaction succeeds",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:56:11Z",
          "mergedAt": "2026-07-10T02:57:35Z",
          "additions": 268,
          "deletions": 2,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1001,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1001",
          "title": "fix(release): bind self impact to version state",
          "body": "## Summary\n\n- replace the static self-release impact payload with `.buildchain/release-impact.json`\n- bind the impact version to Buildchain version-state updates\n- reject stale cross-minor or incomplete version-bound impact evidence\n\n## Validation\n\n- `corepack pnpm@11.7.0 run check`\n- 467 tests passed\n\n## Version impact\n\nPatch: release evidence becomes version-bound and fails closed on stale release metadata.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:59:31Z",
          "mergedAt": "2026-07-10T03:01:49Z",
          "additions": 231,
          "deletions": 76,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1003,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1003",
          "title": "chore(release): promote version-bound impact evidence to alpha",
          "body": "## Summary\n\nPromote the version-bound Buildchain self-release impact evidence to the v2.11 alpha channel.\n\nIncluded change:\n- source self-release impact from version-state-managed `.buildchain/release-impact.json`\n- reject stale cross-minor or incomplete version-bound impact evidence\n\n## Validation\n\n- PR #1001 checks passed\n- `corepack pnpm@11.7.0 run check` (467 tests)\n\n## Expected public evidence\n\nThe alpha GitHub Release must publish `impact.json` with release version `2.11.10-alpha.0`, line `v2.11`, and surface impact `release-impact-version-binding`.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:03:00Z",
          "mergedAt": "2026-07-10T03:05:05Z",
          "additions": 474,
          "deletions": 77,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1004,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1004",
          "title": "fix(paper): align release package directory contract",
          "body": "## Summary\n\n- consume the publication package helper outputDir contract in the paper release workflow\n- lock the workflow-to-helper field mapping in the build surface test\n\n## Verification\n\n- node --test tests/build-surface.test.mjs tests/publication-artifact.test.mjs\n- pnpm run check\n\nCloses #1002",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:03:16Z",
          "mergedAt": "2026-07-10T03:05:55Z",
          "additions": 4,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1006,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1006",
          "title": "chore(release): reconcile generated alpha state into dev",
          "body": "## Summary\n\nMerge the generated v2.11.10-alpha.1 version state back into the protected development channel after dev advanced during alpha finalization.\n\nThis preserves both the generated alpha evidence and the already-reviewed paper release contract fix without bypassing branch protection.\n\nFollow-up: #1005",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:11:31Z",
          "mergedAt": "2026-07-10T03:13:34Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1005,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1005",
          "title": "chore(release): promote paper release contract fix to alpha",
          "body": "## Summary\n\nPromote the reviewed paper release package-directory contract fix from the protected development channel to the alpha channel.\n\n## Validation target\n\nAfter alpha promotion completes, promote the same tested tree to stable so paper consumers pinned to Buildchain v2 can resume trusted publication.\n\nRelated: #1002\nSource fix: #1004",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:08:47Z",
          "mergedAt": "2026-07-10T03:15:14Z",
          "additions": 4,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1008,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1008",
          "title": "chore(release): promote v2.11.10 to stable",
          "body": "## Summary\n\nPromote the tested v2.11.10 alpha tree to the stable v2 line.\n\nThis release includes the paper release package-directory contract fix required by standard publication-artifact consumers.\n\nValidated alpha: v2.11.10-alpha.2\nSource fix: #1004\nAlpha promotion: #1005",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:18:41Z",
          "mergedAt": "2026-07-10T03:20:28Z",
          "additions": 493,
          "deletions": 94,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 469,
          "url": "https://github.com/kungfu-systems/kungfu/pull/469",
          "title": "storage: typed episode manifest fold and trust-boundary contract",
          "body": "Merge feature/episode-manifest-journal-v2 into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:11:41Z",
          "mergedAt": "2026-07-10T03:21:41Z",
          "additions": 606,
          "deletions": 196,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1007,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1007",
          "title": "fix(release): preserve version-bound impact asset",
          "body": "## Summary\n\n- resolve file-backed release impact through the configured version-state updater before passport collection\n- keep version-bound impact metadata authoritative over release-candidate defaults\n- add regression coverage for the public `impact.json` asset\n\n## Production evidence\n\nThe first Stage 1 alpha exposed that `buildchain.release.json` carried the expected surface impact while the sibling `impact.json` fell back to unbound defaults. This patch closes that published-asset gap.\n\n## Validation\n\n- `corepack pnpm@11.7.0 run check`\n- 469 tests passed\n\n## Version impact\n\nPatch: public release evidence now preserves the configured version, line, classification, summary, and surface impacts.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:17:26Z",
          "mergedAt": "2026-07-10T03:23:04Z",
          "additions": 191,
          "deletions": 59,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1010,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1010",
          "title": "chore(release): promote bound impact asset fix to alpha",
          "body": "## Summary\n\nPromote the public release evidence fix after alpha `v2.11.10-alpha.1` proved that the sibling `impact.json` asset could fall back to unbound defaults.\n\nIncluded fix:\n- resolve file-backed impact through the configured version-state updater\n- preserve version-bound classification and summary over release-candidate defaults\n- verify the public asset shape with regression tests\n\n## Validation\n\n- PR #1007 checks passed\n- `corepack pnpm@11.7.0 run check` (469 tests)\n\n## Acceptance\n\nThe resulting public alpha `impact.json` must contain its exact published version, line `v2.11`, classification `patch`, the configured summary, and surface impact `release-impact-version-binding`.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:24:01Z",
          "mergedAt": "2026-07-10T03:25:59Z",
          "additions": 191,
          "deletions": 59,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 470,
          "url": "https://github.com/kungfu-systems/kungfu/pull/470",
          "title": "docs(episode): define atomic safety qualification",
          "body": "Define Episode atomic safety, graceful degradation, evidence-preserving recovery, fault containment, and qualification under load. Add the living qualification plan with semantic oracle, fault matrix, scale tiers, metrics, and Episode Trust Report.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:25:45Z",
          "mergedAt": "2026-07-10T03:26:36Z",
          "additions": 699,
          "deletions": 28,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 4,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/4",
          "title": "fix(release): pass protected channel authority",
          "body": "## Summary\n\nMap the organization release-authority secret into the Buildchain paper release workflow so strict protected-channel governance can read and verify branch protection.\n\nThis does not weaken governance or expose secret values.\n\n## Verification\n\n- make check\n- git diff --check\n\nRelated upstream: kungfu-systems/buildchain#1012",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:30:41Z",
          "mergedAt": "2026-07-10T03:32:10Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 5,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/5",
          "title": "fix(release): pass protected channel authority",
          "body": "## Summary\n\nMap the organization release-authority secret into the Buildchain paper release workflow so strict protected-channel governance can read and verify branch protection.\n\nThis does not weaken governance or expose secret values.\n\n## Verification\n\n- make check\n- git diff --check\n\nRelated upstream: kungfu-systems/buildchain#1012",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:30:41Z",
          "mergedAt": "2026-07-10T03:32:15Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1013,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1013",
          "title": "test(release): avoid fixed version-state target",
          "body": "## Summary\n\n- derive a distinct next patch version from the current self-impact version in the version-state regression\n- keep the test valid when promotion verification has already applied the target version locally\n\n## Production evidence\n\nBuildchain Ref Promotion run `29066879997` safely failed before ref/tag writes because the test attempted to update an already-current hard-coded version and then dereferenced an empty changed-file result.\n\n## Validation\n\n- targeted version-state test passed\n- `corepack pnpm@11.7.0 run check`\n- 469 tests passed\n\n## Version impact\n\nPatch: test-only correction for promotion-time version-state validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:30:28Z",
          "mergedAt": "2026-07-10T03:32:35Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 6,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/6",
          "title": "chore(release): publish v0.1 alpha",
          "body": "## Summary\n\nPromote the fully configured publication workflow to the alpha channel and publish the first non-bootstrap paper package through Buildchain trusted publishing.\n\nExpected outputs:\n\n- npm alpha package\n- exact alpha tag\n- GitHub prerelease with PDF and Release Passport assets\n\nRelated upstream fixes: kungfu-systems/buildchain#1002 and kungfu-systems/buildchain#1012",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:33:05Z",
          "mergedAt": "2026-07-10T03:34:21Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 4,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/4",
          "title": "chore(release): publish v0.1 alpha",
          "body": "## Summary\n\n- promote the reviewed `dev/v0/v0.1` publication contract to the protected alpha channel\n- publish `0.1.0-alpha.0` through Buildchain paper release and npm Trusted Publishing\n- generate the exact-version GitHub prerelease and Buildchain Release Passport\n\n## Immutable effects after merge\n\n- public npm alpha version\n- exact Git tag and GitHub prerelease\n- Buildchain durable release state and evidence\n\n## Required validation\n\n- protected `check / check` succeeds\n- publication artifact build succeeds\n- post-merge paper release transaction succeeds",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:56:14Z",
          "mergedAt": "2026-07-10T03:34:26Z",
          "additions": 270,
          "deletions": 2,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1014,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1014",
          "title": "chore(release): retry bound impact alpha after test fix",
          "body": "## Summary\n\nRetry the bound impact alpha promotion after correcting the version-state regression to remain valid when promotion has already applied the target version locally.\n\nIncluded change:\n- derive a distinct next patch target from the current release impact version\n\n## Validation\n\n- PR #1013 checks passed\n- `corepack pnpm@11.7.0 run check` (469 tests)\n- failed run `29066879997` wrote no release ref or tag\n\n## Acceptance\n\nThe resulting public alpha `impact.json` must carry its exact published version, line `v2.11`, classification `patch`, configured summary, and surface impact `release-impact-version-binding`.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:33:10Z",
          "mergedAt": "2026-07-10T03:35:12Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 7,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/7",
          "title": "fix(release): ignore Buildchain workflow evidence",
          "body": "## Summary\n\nIgnore Buildchain-owned pre-publication evidence files so strict source-change verification does not classify workflow output as undeclared source drift.\n\n## Verification\n\n- make check\n- git diff --check\n- git check-ignore for both generated paths\n\nRelated upstream: kungfu-systems/buildchain#1015",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:38:26Z",
          "mergedAt": "2026-07-10T03:39:39Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 7,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/7",
          "title": "fix(release): ignore Buildchain workflow evidence",
          "body": "## Summary\n\nIgnore Buildchain-owned pre-publication evidence files so strict source-change verification does not classify workflow output as undeclared source drift.\n\n## Verification\n\n- make check\n- git diff --check\n- git check-ignore for both generated paths\n\nRelated upstream: kungfu-systems/buildchain#1015",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:38:26Z",
          "mergedAt": "2026-07-10T03:39:45Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 8,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/8",
          "title": "chore(release): retry v0.1 alpha with clean evidence boundary",
          "body": "## Summary\n\nPromote the verified Buildchain evidence-ignore contract to alpha and retry the first trusted paper publication.\n\nThe previous run stopped before npm publication because workflow-generated evidence was visible as untracked source state.\n\nRelated upstream: kungfu-systems/buildchain#1015",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:40:05Z",
          "mergedAt": "2026-07-10T03:41:26Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 8,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/8",
          "title": "chore(release): retry v0.1 alpha with clean evidence boundary",
          "body": "## Summary\n\nPromote the verified Buildchain evidence-ignore contract to alpha and retry the first trusted paper publication.\n\nThe previous run stopped before npm publication because workflow-generated evidence was visible as untracked source state.\n\nRelated upstream: kungfu-systems/buildchain#1015",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:40:05Z",
          "mergedAt": "2026-07-10T03:41:31Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 471,
          "url": "https://github.com/kungfu-systems/kungfu/pull/471",
          "title": "storage: episode manifest writer guard and crash recovery",
          "body": "Merge feature/episode-manifest-writer-guard into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:46:31Z",
          "mergedAt": "2026-07-10T03:46:36Z",
          "additions": 459,
          "deletions": 12,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1018,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1018",
          "title": "fix(paper): preserve npm repository provenance",
          "body": "## Summary\n\n- preserve authoritative source repository metadata in synthesized publication npm packages\n- fail before npm when trusted publishing lacks repository metadata\n- update the publication fixture and regression coverage\n- refresh generated public contract digests\n\n## Verification\n\n- node --test tests/publication-artifact.test.mjs\n- pnpm run check (470 tests passed)\n\nCloses #1016",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:47:33Z",
          "mergedAt": "2026-07-10T03:49:05Z",
          "additions": 71,
          "deletions": 4,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1019,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1019",
          "title": "chore(release): promote paper provenance fix to alpha",
          "body": "## Summary\n\nPromote the reviewed publication repository-provenance contract to the alpha channel.\n\nDownstream validation will retry two Buildchain-managed paper packages through npm Trusted Publishing and verify Sigstore provenance, exact tags, GitHub prereleases, and Release Passports.\n\nSource fix: #1018\nIssue: #1016",
          "author": "kungfu-origin",
          "createdAt": "2026-07-10T03:49:41Z",
          "mergedAt": "2026-07-10T03:52:19Z",
          "additions": 71,
          "deletions": 4,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1017,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1017",
          "title": "fix(release): preserve impact in binary assets",
          "body": "## Summary\n\n- fetch the authoritative sibling `impact.json` from the durable release-state ref\n- validate that its version matches the durable passport\n- pass it into binary release passport collection so Binary Distribution cannot downgrade the public asset\n\n## Production evidence\n\nAfter Buildchain Ref Promotion published a version-bound `impact.json` for `v2.11.11-alpha.0`, Binary Distribution replaced it with default unbound metadata. The durable release-state ref already contains the correct sibling asset; this patch makes it the binary collection input.\n\n## Validation\n\n- binary distribution workflow regression passed\n- `corepack pnpm@11.7.0 run check`\n- 469 tests passed\n\n## Version impact\n\nPatch: all release writers preserve the authoritative version-bound impact asset.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:47:30Z",
          "mergedAt": "2026-07-10T03:53:00Z",
          "additions": 16,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1022,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1022",
          "title": "chore(release): reconcile alpha impact state into dev",
          "body": "## Summary\n\n- reconcile the latest generated alpha version state into `dev/v2/v2.11`\n- preserve protected branch topology before promoting the binary impact preservation fix\n- keep the change limited to generated version-bound release state\n\n## Validation\n\n- `corepack pnpm@11.7.0 run check` (470 tests passed)\n\nThis unblocks the existing protected `dev/v2/v2.11` to `alpha/v2/v2.11` promotion PR after alpha advanced independently.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:58:46Z",
          "mergedAt": "2026-07-10T04:01:19Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1020,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1020",
          "title": "chore(release): promote binary impact preservation to alpha",
          "body": "## Summary\n\nPromote the final release evidence consolidation fix so Binary Distribution consumes the authoritative durable-state `impact.json` instead of regenerating default metadata.\n\nIncluded change:\n- fetch and validate the durable release-state impact sibling\n- pass it into binary release passport collection\n- prevent later release writers from downgrading the public impact asset\n\n## Validation\n\n- PR #1017 checks passed\n- `corepack pnpm@11.7.0 run check` (470 tests after latest dev sync)\n\n## Acceptance\n\nAfter both Ref Promotion and Binary Distribution finish, the public alpha `impact.json` must still carry its exact version, line `v2.11`, classification `patch`, configured summary, and `release-impact-version-binding` surface.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:53:40Z",
          "mergedAt": "2026-07-10T04:03:17Z",
          "additions": 16,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1023,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1023",
          "title": "chore(release): recover v2.11.11 stable promotion",
          "body": "## Summary\n\nRecover the `v2.11.11` stable promotion after the direct alpha-to-release PR became unmergeable because prior generated release-state commits diverged.\n\nThe recovery merge has the exact same Git tree as `v2.11.11-alpha.1`; it introduces no post-alpha source changes. That alpha includes the paper publication repository/provenance fix from #1018.\n\nReplaces #1021.\n\n## Verification\n\n- `node --test tests/publication-artifact.test.mjs tests/promote-buildchain-ref.test.mjs` (98 passed)\n- `pnpm run check` (470 passed; all action bundles rebuilt)\n- recovery tree SHA equals `origin/alpha/v2/v2.11^{tree}`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:01:57Z",
          "mergedAt": "2026-07-10T04:04:10Z",
          "additions": 283,
          "deletions": 79,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 472,
          "url": "https://github.com/kungfu-systems/kungfu/pull/472",
          "title": "storage: structural episode fsck over the typed fold",
          "body": "Merge feature/episode-manifest-structural-fsck into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:12:39Z",
          "mergedAt": "2026-07-10T04:12:45Z",
          "additions": 547,
          "deletions": 13,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 9,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/9",
          "title": "chore(release): advance paper alpha version",
          "body": "## Summary\n\nAdvance the publication version to `0.1.0-alpha.1`.\n\nThe earlier `alpha.0` durable transaction froze publication material synthesized before Buildchain preserved npm repository provenance. Buildchain correctly rejects replacing that material under the same immutable version, so this creates a new alpha transaction.\n\n## Verification\n\n- `make check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:14:41Z",
          "mergedAt": "2026-07-10T04:15:59Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 9,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/9",
          "title": "chore(release): advance paper alpha version",
          "body": "## Summary\n\nAdvance the publication version to `0.1.0-alpha.1`.\n\nThe earlier `alpha.0` durable transaction froze publication material synthesized before Buildchain preserved npm repository provenance. Buildchain correctly rejects replacing that material under the same immutable version, so this creates a new alpha transaction.\n\n## Verification\n\n- `make check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:14:51Z",
          "mergedAt": "2026-07-10T04:16:15Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 11,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/11",
          "title": "chore(release): promote alpha.1 publication",
          "body": "## Summary\n\nPromote the reviewed `0.1.0-alpha.1` publication version to the alpha channel.\n\nThis starts a new immutable release transaction after the superseded `alpha.0` material was correctly rejected from in-place replacement.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:16:35Z",
          "mergedAt": "2026-07-10T04:17:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 11,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/11",
          "title": "chore(release): promote alpha.1 publication",
          "body": "## Summary\n\nPromote the reviewed `0.1.0-alpha.1` publication version to the alpha channel.\n\nThis starts a new immutable release transaction after the superseded `alpha.0` material was correctly rejected from in-place replacement.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:16:46Z",
          "mergedAt": "2026-07-10T04:18:11Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1025,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1025",
          "title": "fix(paper): grant generated check permission",
          "body": "## Summary\n\nGrant `checks: write` to the Buildchain paper release reusable workflow and document the same required caller permission.\n\nThe promotion authority remains split by responsibility: `BUILDCHAIN_PROMOTION_TOKEN` reads and updates protected refs, while `github.token` creates the generated version-state audit check.\n\nCloses the finalization-permission gap documented in #1012.\n\n## Verification\n\n- `node --test tests/build-surface.test.mjs` (64 passed)\n- `pnpm run check` (470 passed; all action bundles rebuilt)\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:26:09Z",
          "mergedAt": "2026-07-10T04:28:19Z",
          "additions": 15,
          "deletions": 7,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 12,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/12",
          "title": "fix(release): grant generated check permission",
          "body": "## Summary\n\nGrant `checks: write` to the Buildchain paper release caller so `github.token` can publish the generated version-state audit check during protected alpha finalization.\n\nThe separate `BUILDCHAIN_PROMOTION_TOKEN` remains responsible for protected ref reads and updates.\n\n## Verification\n\n- `make check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:27:47Z",
          "mergedAt": "2026-07-10T04:29:41Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 473,
          "url": "https://github.com/kungfu-systems/kungfu/pull/473",
          "title": "storage: rebuildable episode manifest SQLite projection",
          "body": "Merge feature/episode-manifest-projection into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:29:44Z",
          "mergedAt": "2026-07-10T04:29:49Z",
          "additions": 471,
          "deletions": 3,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 12,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/12",
          "title": "fix(release): grant generated check permission",
          "body": "## Summary\n\nGrant `checks: write` to the Buildchain paper release caller so `github.token` can publish the generated version-state audit check during protected alpha finalization.\n\nThe separate `BUILDCHAIN_PROMOTION_TOKEN` remains responsible for protected ref reads and updates.\n\n## Verification\n\n- `make check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:27:59Z",
          "mergedAt": "2026-07-10T04:29:54Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1026,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1026",
          "title": "chore(release): promote paper check permission to alpha",
          "body": "## Summary\n\nPromote the reviewed paper release generated-check permission contract to the v2.11 alpha channel.\n\nThis unblocks finalization of already-published paper alpha transactions while preserving separate protected-ref and status-check authorities.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:28:43Z",
          "mergedAt": "2026-07-10T04:30:51Z",
          "additions": 15,
          "deletions": 7,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 474,
          "url": "https://github.com/kungfu-systems/kungfu/pull/474",
          "title": "fix(view): bounds-check bind_frame field_index; generalize the fuzz harness",
          "body": "Unsafe-region audit of the sole FlatBuffers access module (kungfu::view, ADR-0039 parent closeout) found a spatial-safety-by-discipline residue plus two minor items, and generalizes the fuzz harness for future untrusted-input surfaces.\n\n- bind_frame now bounds-checks the col_plan field_index before fields->Get, so a stale plan (e.g. one cached against a larger schema, then bound against a smaller one after evolve()) skips the frame instead of an out-of-range reflection read. Regression-tested in the view-encapsulation probe (teeth-checked against the unpatched module).\n- verify_table drops an unused Verifier; alter_add_missing null-guards sqlite3_column_text.\n- fuzz/CMakeLists.txt exposes kungfu_add_fuzz(name, sources) and verify.mjs discovers targets from fuzz_<name>.cpp, so a new fuzz surface (e.g. episode import) is one CMake row + an entry cpp + a corpus dir.\n\nValidated mac arm64: both fuzz tiers build via the generalized harness; view fuzz clean; probe passes under ASan+UBSan.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:31:55Z",
          "mergedAt": "2026-07-10T04:32:00Z",
          "additions": 79,
          "deletions": 23,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1028,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1028",
          "title": "chore(release): recover v2.11.12 stable promotion",
          "body": "## Summary\n\nRecover the `v2.11.12` stable promotion after the direct alpha-to-release PR became unmergeable because generated release-state ancestry diverged.\n\nThe recovery commit has the exact same Git tree as `v2.11.12-alpha.0`; it introduces no post-alpha source changes.\n\nReplaces #1027.\n\n## Verification\n\n- `pnpm run check` (470 passed; all action bundles rebuilt)\n- recovery tree SHA equals `origin/alpha/v2/v2.11^{tree}`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:36:36Z",
          "mergedAt": "2026-07-10T04:38:44Z",
          "additions": 48,
          "deletions": 25,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 16,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/16",
          "title": "chore(release): reconcile alpha ancestry",
          "body": "## Summary\n\nReconcile the protected alpha merge ancestry into dev through a work branch that already contains the current dev permission change.\n\nThe resulting tree is identical to current dev; this PR changes ancestry only and unblocks the reviewed dev-to-alpha permission promotion.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:48:34Z",
          "mergedAt": "2026-07-10T04:50:09Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 475,
          "url": "https://github.com/kungfu-systems/kungfu/pull/475",
          "title": "feat(episode): add qualification harness",
          "body": "## Summary\n\n- add a versioned Episode Qualification Harness with accumulation and 1/2/5/10-worker contention modes\n- validate reports against a Trust Report schema and fail on correctness violations\n- document the first clean smoke, 100k accumulation, and 10k contention baselines with explicit claim boundaries\n\n## Validation\n\n- ./kungfu-code check\n- ./kungfu-code build:core\n- pytest -q framework/core/tests/python/test_episode_manifest_recovery.py\n- pytest -q framework/core/tests/python/test_atlas_storage.py -k episode\n- ./kungfu-code episode:qualify -- --profile mvp-smoke-v1\n- one-seed mvp-baseline-v1 accumulation and contention runs\n\n## Version impact\n\nPatch-level tooling and documentation addition; no runtime API or Episode semantic change.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:50:29Z",
          "mergedAt": "2026-07-10T04:50:35Z",
          "additions": 1920,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 16,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/16",
          "title": "chore(release): reconcile alpha ancestry",
          "body": "## Summary\n\nReconcile the protected alpha merge ancestry into dev through a work branch that already contains the current dev permission change.\n\nThe resulting tree is identical to current dev; this PR changes ancestry only and unblocks the reviewed dev-to-alpha permission promotion.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:48:46Z",
          "mergedAt": "2026-07-10T04:50:44Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 13,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/13",
          "title": "fix(release): promote generated check permission",
          "body": "## Summary\n\nPromote the reviewed `checks: write` caller permission to the alpha channel.\n\nWith Buildchain `v2.11.12`, this allows the existing `0.1.0-alpha.1` durable transaction to resume finalization without republishing its npm artifact.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:43:50Z",
          "mergedAt": "2026-07-10T04:55:45Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 13,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/13",
          "title": "fix(release): promote generated check permission",
          "body": "## Summary\n\nPromote the reviewed `checks: write` caller permission to the alpha channel.\n\nWith Buildchain `v2.11.12`, this allows the existing `0.1.0-alpha.1` durable transaction to resume finalization without republishing its npm artifact.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:43:33Z",
          "mergedAt": "2026-07-10T04:56:08Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 17,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/17",
          "title": "chore(release): advance paper alpha to alpha.2",
          "body": "## Summary\n\nAdvance the paper publication to `0.1.0-alpha.2` from a branch that already contains current dev and alpha ancestry.\n\n`alpha.1` remains an immutable partial transaction: npm publishing succeeded, but finalization could not be replayed after the caller-permission source change. `alpha.2` starts a clean transaction with the corrected Buildchain and branch-protection contracts in place.\n\n## Verification\n\n- `make check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:59:41Z",
          "mergedAt": "2026-07-10T05:01:11Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 17,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/17",
          "title": "chore(release): advance paper alpha to alpha.2",
          "body": "## Summary\n\nAdvance the paper publication to `0.1.0-alpha.2` from a branch that already contains current dev and alpha ancestry.\n\n`alpha.1` remains an immutable partial transaction: npm publishing succeeded, but finalization could not be replayed after the caller-permission source change. `alpha.2` starts a clean transaction with the corrected Buildchain and branch-protection contracts in place.\n\n## Verification\n\n- `make check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:59:52Z",
          "mergedAt": "2026-07-10T05:01:28Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 18,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/18",
          "title": "chore(release): promote alpha.2 publication",
          "body": "## Summary\n\nPromote the reviewed `0.1.0-alpha.2` publication to the protected alpha channel.\n\nThe branch already contains current alpha ancestry, and the Buildchain caller, reusable workflow, and required status-check context are aligned before this transaction begins.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T05:01:42Z",
          "mergedAt": "2026-07-10T05:03:12Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 18,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/18",
          "title": "chore(release): promote alpha.2 publication",
          "body": "## Summary\n\nPromote the reviewed `0.1.0-alpha.2` publication to the protected alpha channel.\n\nThe branch already contains current alpha ancestry, and the Buildchain caller, reusable workflow, and required status-check context are aligned before this transaction begins.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T05:01:54Z",
          "mergedAt": "2026-07-10T05:03:30Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 476,
          "url": "https://github.com/kungfu-systems/kungfu/pull/476",
          "title": "feat(storage): add first-class content store contract with file backend",
          "body": "ADR-0040 first delivery, kernel side: immutable content_store contract in libyijinjing (put-if-absent / get / has / verify, error taxonomy, size-limit semantics, capability discovery) with a dependency-free file backend (atomic tmp+rename publish, ADR-0037 payload layout), extended dependency guard (engine symbols, CMake links, seeded --self-test) wired into verify stage 5, and a content-store capability slice proving the four obligations plus single-node concurrent dedup across threads and processes.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T05:35:11Z",
          "mergedAt": "2026-07-10T05:35:17Z",
          "additions": 1111,
          "deletions": 26,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 59,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/59",
          "title": "feat(papers): render publication packages",
          "body": "## Summary\n\n- pin the three published Kungfu paper packages and aggregate their package-local publication registries\n- render a human-first papers index, per-paper pages, latest routes, and immutable PDF/manifest/passport/source archives\n- expose exact package, lock integrity, route, and digest facts through papers manifests, registry, and llms.txt\n\n## Verification\n\n- `corepack pnpm@11.9.0 run build`\n- `corepack pnpm@11.9.0 run check`\n- `bash -n scripts/build-site.sh scripts/check-site.sh`\n- `shellcheck scripts/build-site.sh scripts/check-site.sh`\n- desktop and mobile Playwright checks for the papers index and paper detail pages\n- HTTP verification of all 22 rendered papers routes and artifact content types\n\n## Boundaries\n\n- paper packages remain the source of publication facts and immutable artifact bytes\n- this repository owns package-set membership, aggregation, rendering, and environment-aware navigation\n- no production deployment or infrastructure change is included",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:50:16Z",
          "mergedAt": "2026-07-10T05:46:34Z",
          "additions": 644,
          "deletions": 146,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1030,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1030",
          "title": "fix(release): serialize promotion transactions",
          "body": "## Summary\n\n- serialize protected promotion transactions without cancellation\n- revalidate target ancestry before checkout, dependency install, RC resolution, or ref mutation\n- turn compatible superseded events into auditable zero-mutation no-ops while keeping incompatible movement fail-closed\n\n## Validation\n\n- `pnpm run check` (473 tests, workflow checks, site bundle checks, and four action bundles)\n- focused promotion and build-surface tests (158 tests)\n- `git diff --check`\n\n## Governance\n\n- patch release impact; no public input or artifact schema change\n- no credentials, private logs, hosted-service configuration, branding, package identity, or domain changes\n- release evidence updated for `2.11.13-alpha.0`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T05:47:04Z",
          "mergedAt": "2026-07-10T05:48:54Z",
          "additions": 375,
          "deletions": 94,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1031,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1031",
          "title": "chore(release): promote v2.11.13 alpha",
          "body": "Promote the reviewed `dev/v2/v2.11` release intent into the protected alpha channel.\n\nEvidence target: `v2.11.13-alpha.0` with serialized promotion preflight, version-bound release impact, and no stable publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T05:50:03Z",
          "mergedAt": "2026-07-10T05:52:04Z",
          "additions": 375,
          "deletions": 94,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 477,
          "url": "https://github.com/kungfu-systems/kungfu/pull/477",
          "title": "test(episode): gate verify with qualification smoke",
          "body": "## Summary\n\n- run the versioned `mvp-smoke-v1` Episode qualification from `verify` by default\n- retain failed Trust Reports, enforce clean-source qualification in CI, and expose an explicit local diagnostic skip\n- keep the 100k accumulation and 10k contention baseline outside the per-build path\n\n## Validation\n\n- `./kungfu-code check`\n- `./kungfu-code build:core`\n- `./kungfu-code freeze`\n- clean-source `CI=1 ./kungfu-code verify`: Episode qualification 5/5, `qualified=true`\n- dirty-source CI negative test: Episode stage blocks as designed\n- checked-in Buildchain/workflow commands contain no Episode skip\n\n## Known baseline\n\nThe full verify summary remains red on five pre-existing mypy errors in `master_service.py` and `sources/store.py`; the new Episode stage itself passes.\n\n## Version impact\n\nPatch-level verification and documentation change; no Episode runtime contract change.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T05:56:50Z",
          "mergedAt": "2026-07-10T05:56:57Z",
          "additions": 121,
          "deletions": 3,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 10,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/10",
          "title": "fix(paper): use title-derived PDF filename",
          "body": "## Summary\n\n- publish the white paper under a filename derived from its full title\n- align both site bundles, npm `./pdf` export, Buildchain contract, workflow artifact paths, and local build output\n- verify the site-bundle generator rejects a primary artifact that drifts from the title-derived filename\n\n## Validation\n\n- `npm run check`\n- `npx -y @kungfu-tech/buildchain@2.11.12 validate --cwd . --json`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T06:10:13Z",
          "mergedAt": "2026-07-10T06:13:52Z",
          "additions": 41,
          "deletions": 20,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 19,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/19",
          "title": "fix(paper): use title-derived PDF filename",
          "body": "## Summary\n\n- publish the PDF under a filename derived from the full paper title\n- keep `paper/main.tex` as the internal LaTeX entrypoint\n- align the Buildchain artifact contract, workflow upload path, local build, and documentation\n\n## Validation\n\n- `make check`\n- `npx -y @kungfu-tech/buildchain@2.11.12 validate --cwd . --json`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T06:10:13Z",
          "mergedAt": "2026-07-10T06:15:08Z",
          "additions": 10,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 19,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/19",
          "title": "fix(paper): use title-derived PDF filename",
          "body": "## Summary\n\n- publish the PDF under a filename derived from the paper title\n- keep `paper/main.tex` as the internal LaTeX entrypoint\n- align the Buildchain artifact contract, workflow upload path, local build, and documentation\n\n## Validation\n\n- `make check`\n- `npx -y @kungfu-tech/buildchain@2.11.12 validate --cwd . --json`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T06:10:13Z",
          "mergedAt": "2026-07-10T06:15:13Z",
          "additions": 10,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 478,
          "url": "https://github.com/kungfu-systems/kungfu/pull/478",
          "title": "feat(episode): resolve payload refs through the content store",
          "body": "ADR-0041 stage 4: Episode payload refs resolve through the ADR-0040 immutable content_store by content identity (ref_hash); ref_id stays an edge label. Verified reads map the store's error taxonomy onto manifest diagnostics (missing / hash-mismatch / unaddressable / io); an unverified payload ref fails a sealed Episode and degrades an open one; repair planning also scans fsck errors so sealed payload issues remain fetchable. Producers publish bytes before claiming them, and the file provider's payload write now publishes via content-store put-if-absent. Validation: full core build; episode suites 28/28 incl. 7 new stage-4 fixtures; full python 108 passed with only the 2 pre-existing first-party-baked baseline failures (reproduced on clean dev); node binding consistent with baseline.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T06:20:58Z",
          "mergedAt": "2026-07-10T06:21:04Z",
          "additions": 275,
          "deletions": 41,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 20,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/20",
          "title": "fix(paper): shorten public PDF filename",
          "body": "## Summary\n\n- shorten the public PDF filename to `kfd-foundation-model.pdf`\n- keep the Buildchain contract, workflow artifact, local build, and documentation aligned\n- retain `paper/main.tex` only as the internal LaTeX entrypoint\n\n## Validation\n\n- `make check`\n- `npx -y @kungfu-tech/buildchain@2.11.12 validate --cwd . --json`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T06:55:55Z",
          "mergedAt": "2026-07-10T07:00:51Z",
          "additions": 6,
          "deletions": 7,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 12,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/12",
          "title": "fix(paper): shorten public PDF filename",
          "body": "## Summary\n\n- shorten the public PDF filename to `kungfu-real-world-agent-work.pdf`\n- derive both site-bundle URLs from the declared primary artifact basename\n- align npm exports, Buildchain contract, workflow artifacts, local build, and generated bundles\n\n## Validation\n\n- `npm run check`\n- `npx -y @kungfu-tech/buildchain@2.11.12 validate --cwd . --json`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T06:55:55Z",
          "mergedAt": "2026-07-10T07:00:51Z",
          "additions": 28,
          "deletions": 32,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 20,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/20",
          "title": "fix(paper): shorten public PDF filename",
          "body": "## Summary\n\n- shorten the public PDF filename to `observer-declared-timelines.pdf`\n- keep the Buildchain contract, workflow artifact, local build, and documentation aligned\n- retain `paper/main.tex` only as the internal LaTeX entrypoint\n\n## Validation\n\n- `make check`\n- `npx -y @kungfu-tech/buildchain@2.11.12 validate --cwd . --json`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T06:55:56Z",
          "mergedAt": "2026-07-10T07:00:51Z",
          "additions": 6,
          "deletions": 7,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 479,
          "url": "https://github.com/kungfu-systems/kungfu/pull/479",
          "title": "fix(core): restore mypy baseline",
          "body": "Merge fix/mypy-baseline-recovery into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:03:58Z",
          "mergedAt": "2026-07-10T07:04:05Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 21,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/21",
          "title": "chore(release): advance short filename alpha",
          "body": "## Summary\n\nAdvance the paper version to 0.1.0-alpha.3 so the next Buildchain alpha publishes the short kfd-foundation-model.pdf artifact.\n\n## Validation\n\n- repository checks\n- Buildchain paper profile validation\n- clean diff validation",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:02:45Z",
          "mergedAt": "2026-07-10T07:04:34Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 13,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/13",
          "title": "chore(release): advance short filename alpha",
          "body": "## Summary\n\nAdvance the white paper version to 0.1.0-alpha.2 and refresh versioned site bundles so the next Buildchain alpha publishes kungfu-real-world-agent-work.pdf.\n\n## Validation\n\n- repository checks\n- Buildchain paper profile validation\n- clean diff validation",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:02:45Z",
          "mergedAt": "2026-07-10T07:04:34Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 21,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/21",
          "title": "chore(release): advance short filename alpha",
          "body": "## Summary\n\nAdvance the paper version to 0.1.0-alpha.3 so the next Buildchain alpha publishes the short observer-declared-timelines.pdf artifact.\n\n## Validation\n\n- repository checks\n- Buildchain paper profile validation\n- clean diff validation",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:02:45Z",
          "mergedAt": "2026-07-10T07:04:34Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 14,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/14",
          "title": "chore(release): promote short filename alpha",
          "body": "## Summary\n\nPromote the validated development line to the alpha channel for 0.1.0-alpha.2.\n\nThe public paper artifact is declared as `kungfu-real-world-agent-work.pdf` and will be published through the Buildchain paper release transaction with npm Trusted Publishing.\n\n## Release validation\n\n- verify the exact npm alpha version and dist-tag\n- verify the npm tarball PDF basename\n- verify site/publication bundle download URLs\n- verify the GitHub prerelease and Release Passport",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:04:51Z",
          "mergedAt": "2026-07-10T07:07:02Z",
          "additions": 41,
          "deletions": 24,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 22,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/22",
          "title": "chore(release): promote short filename alpha",
          "body": "## Summary\n\nPromote the validated development line to the alpha channel for 0.1.0-alpha.3.\n\nThe public paper artifact is declared as `kfd-foundation-model.pdf` and will be published through the Buildchain paper release transaction with npm Trusted Publishing.\n\n## Release validation\n\n- verify the exact npm alpha version and dist-tag\n- verify the npm tarball PDF basename\n- verify site/publication bundle download URLs\n- verify the GitHub prerelease and Release Passport",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:04:51Z",
          "mergedAt": "2026-07-10T07:08:05Z",
          "additions": 10,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 22,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/22",
          "title": "chore(release): promote short filename alpha",
          "body": "## Summary\n\nPromote the validated development line to the alpha channel for 0.1.0-alpha.3.\n\nThe public paper artifact is declared as `observer-declared-timelines.pdf` and will be published through the Buildchain paper release transaction with npm Trusted Publishing.\n\n## Release validation\n\n- verify the exact npm alpha version and dist-tag\n- verify the npm tarball PDF basename\n- verify site/publication bundle download URLs\n- verify the GitHub prerelease and Release Passport",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:04:51Z",
          "mergedAt": "2026-07-10T07:08:08Z",
          "additions": 10,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1033,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1033",
          "title": "fix(release): preserve TOML version state formatting",
          "body": "## Summary\n\n- treat already-matching configured JSON/TOML versions as semantic no-ops\n- update real TOML versions through a parser-verified lossless edit\n- prevent formatter-only paper release preparation commits without weakening transaction source identity\n\n## Validation\n\n- `node --test tests/buildchain-config.test.mjs tests/promote-buildchain-ref.test.mjs`\n- `pnpm run check` (476 tests)\n- `git diff --check`\n\nCloses #1029",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:08:28Z",
          "mergedAt": "2026-07-10T07:11:06Z",
          "additions": 327,
          "deletions": 117,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1034,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1034",
          "title": "chore(release): promote TOML version state fix to v2.11 alpha",
          "body": "## Release intent\n\nPromote the v2.11 development line after #1033. This alpha verifies that configured TOML version updates preserve repository formatting and semantic version-state no-ops do not produce formatter-only preparation commits.\n\n## Evidence\n\n- source PR: #1033\n- source commit: `6a13bca61f2f5ae2703543607a64daaf0faf9e83`\n- full Buildchain check: 476 tests passed\n- issue closed by source PR: #1029\n\nStable publication is not requested.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:12:03Z",
          "mergedAt": "2026-07-10T07:13:48Z",
          "additions": 327,
          "deletions": 117,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 16,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/16",
          "title": "chore(buildchain): accept current v2 contract",
          "body": "## Summary\n\nAccept the current stable Buildchain v2 contract after reviewing its compatible additive drift.\n\nThe compatibility digest and all registered breaking surface digests are unchanged. Updating the accepted SHA and contract digest prevents compatible-drift issue material from entering the release version verification worktree.\n\n## Validation\n\n- current v2 contract lock status: unchanged\n- contract drift: false\n- npm repository checks\n- Buildchain paper profile validation",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:19:20Z",
          "mergedAt": "2026-07-10T07:21:19Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 17,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/17",
          "title": "chore(release): retry alpha with accepted v2 contract",
          "body": "## Summary\n\nPromote the accepted current Buildchain v2 contract lock into the alpha channel and retry the still-unpublished 0.1.0-alpha.2 transaction.\n\nThe previous promotion stopped before npm publish because compatible contract drift generated an untracked issue body during version verification. The accepted lock now matches the current v2 SHA and contract digest while preserving the same compatibility and breaking-surface digests.\n\n## Release validation\n\n- verify npm 0.1.0-alpha.2 and alpha dist-tag\n- verify kungfu-real-world-agent-work.pdf in the npm tarball\n- verify both site-bundle download URLs\n- verify GitHub prerelease and Release Passport",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:21:34Z",
          "mergedAt": "2026-07-10T07:23:21Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 480,
          "url": "https://github.com/kungfu-systems/kungfu/pull/480",
          "title": "feat(storage): rocksdb content store with symmetric facades",
          "body": "Completes the ADR-0040 first delivery. RocksDB-backed content_store in the runtime layer over the provider's single long-lived engine handle (keys <namespace>/<digest>, WAL-atomic publication, verified reads); provider payload ops route through it and the rocksdb payload key prefix aligns to the payloads namespace. Kernel fsck/inspect accept an injected content store and every graph-building service path passes the provider's store, closing the stage-4 injection seam: payload-ref resolution reads the same backend that published the bytes under either provider. Python/Node gain symmetric thin facades (put-if-absent / get / has / verify / capabilities); episode_lifecycle publishes through the facade. Validation: full core build; dual-provider facade suite 16/16 incl. proof that fsck under rocksdb resolves refs without touching the file payload tree; full python 124 passed (only the 2 pre-existing first-party-baked baseline failures); node facade roundtrip green under both providers via KUNGFU_DIR=build/Release; mypy baseline clean; dependency guard + self-test green.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:27:52Z",
          "mergedAt": "2026-07-10T07:28:00Z",
          "additions": 823,
          "deletions": 56,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 481,
          "url": "https://github.com/kungfu-systems/kungfu/pull/481",
          "title": "feat(code): native kungfu-code launcher with Rust adoption paradigm",
          "body": "Establish Rust as a first-class option with the kungfu-code launcher as the first exercised case.\n\n- code/ cargo workspace; kungfu-code as a std-only, dependency-free single binary (~364KB)\n- bootstraps pinned prebuilt fnm / uv into the user-global cache when missing: a fresh clone needs nothing beyond curl\n- sh / cmd entrypoints become thin shims (cached binary -> prebuilt download -> cargo build -> legacy fallback); machines with fnm+uv installed see zero behavior change\n- absorbs the Windows special-casing (pinned node, corepack.cmd, MSVC vcvars) natively\n- kungfu-code CI (fmt / clippy -D warnings / tests / release build, 3 platforms) + release workflow publishing prebuilt binaries on kungfu-code-v<version> tags\n- docs/rust-adoption.md: adoption paradigm with hard boundaries and the selective-exercise discipline; KFD-1 register entry for the launcher welded surface",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:36:30Z",
          "mergedAt": "2026-07-10T07:36:38Z",
          "additions": 1549,
          "deletions": 18,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 62,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/62",
          "title": "fix(papers): consume renamed PDF artifacts",
          "body": "## Summary\n\n- update the three pinned paper packages to their renamed-PDF releases\n- preserve upstream publication registry filenames without site-side rewriting\n- refresh pnpm integrity and minimum-release-age policy entries\n\n## Verification\n\n- corepack pnpm install --frozen-lockfile\n- corepack pnpm run build\n- corepack pnpm run check\n- verified current/latest reader pages contain no main.pdf links\n- verified all three rendered PDF digests match the publication manifest\n\n## Governance\n\n- [x] No change to canonical domains or release identity\n- [x] No site-owned publication facts introduced\n- [x] Production remains separately gated",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:43:57Z",
          "mergedAt": "2026-07-10T07:51:35Z",
          "additions": 24,
          "deletions": 24,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 482,
          "url": "https://github.com/kungfu-systems/kungfu/pull/482",
          "title": "test(episode): add semantic qualification evidence",
          "body": "## Summary\n\n- add a Kungfu-independent Episode Semantic v1 oracle with 48 bounded histories\n- replace Trust Report v1 semantic zero placeholders with v2 passed/failed/not_exercised evidence dimensions\n- gate recurring smoke on 8 required production comparisons while keeping capability_soundness honestly not_exercised\n- cover recovery, useful degradation, monotonic repair, dependency containment, projection rebuild, content integrity, and portable identity\n\n## Validation\n\n- 34 focused Episode tests passed\n- ./kungfu-code check\n- ./kungfu-code build:core\n- ./kungfu-code freeze\n- CI=1 ./kungfu-code verify (25/25; 5/5 scale, 8/8 required semantic, qualified=true)",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:57:36Z",
          "mergedAt": "2026-07-10T07:58:51Z",
          "additions": 1224,
          "deletions": 44,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 483,
          "url": "https://github.com/kungfu-systems/kungfu/pull/483",
          "title": "refactor(crates): rename the Rust workspace directory code/ to crates/",
          "body": "Pure rename plus reference updates (shims, workflows, docs, versioning register); no behavior change. crates/ is the de-facto standard cargo workspace container name in Rust monorepos. Published kungfu-code-v0.1.0 binaries are unaffected (asset URLs carry no directory path; the launcher discovers the repo root by marker).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:01:51Z",
          "mergedAt": "2026-07-10T08:01:57Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 18,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/18",
          "title": "ci: pass Buildchain train to promotion dry-run",
          "body": "## Summary\n\n- expose the existing Buildchain runtime override on the manual promotion dry-run\n- keep manual non-dry-run promotion rejected\n- lock the pass-through in the repository check\n\n## Validation\n\n- `make check`\n- `actionlint -color=false .github/workflows/*.yml`\n- `git diff --check`\n\nThis enables non-mutating validation of the Buildchain fix for kungfu-systems/buildchain#1032.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:00:48Z",
          "mergedAt": "2026-07-10T08:03:11Z",
          "additions": 18,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1035,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1035",
          "title": "fix(paper): validate publication evidence contract",
          "body": "## Summary\n\n- allow only enumerated untracked Buildchain contract-drift and publication-result evidence during strict version verification\n- preflight protected publication authority before expensive paper build work\n- document caller-chosen release-authority secret mapping and preserve strict rejection for undeclared paths\n\n## Validation\n\n- failure-first regression: targeted suite failed on both missing contracts before the implementation\n- targeted Buildchain promotion/build-surface suite: 159 passed\n- `pnpm run check`: 476 passed, workflow/site/inventory checks and four action builds passed\n- `git diff --check`\n\n## Issue evidence\n\nAddresses #1012, #1015, and #1032. The issues will be closed after protected and consumer runtime evidence is attached.\n\n## Version impact\n\nPatch: release governance and paper publication preflight behavior are corrected without changing public input or artifact schemas.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:58:32Z",
          "mergedAt": "2026-07-10T08:08:11Z",
          "additions": 118,
          "deletions": 30,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 484,
          "url": "https://github.com/kungfu-systems/kungfu/pull/484",
          "title": "refactor(shifu): rename the launcher product kungfu-code to shifu",
          "body": "Rename the launcher product to shifu — the master that bootstraps the toolchain and walks you into the repo. One word, globally recognizable, native to the kungfu brand's semantic field (the martial-arts mentor-tool lineage that ninja established for build tools).\n\nFull product rename, same contract shape: entrypoints ./shifu / shifu.cmd (L2 shifu.mjs), crate crates/shifu, release tags shifu-v<version>, assets shifu-<platform>, env keys SHIFU_*. All in-repo callers, docs, KFD-3 surfaces, and the versioning register follow; historical decision-log rows keep the old name verbatim. Pre-release, no external consumers; kungfu-code-v0.1.0 will be retired and reissued as shifu-v0.1.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:18:00Z",
          "mergedAt": "2026-07-10T08:18:06Z",
          "additions": 318,
          "deletions": 322,
          "changedFiles": 64
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1037,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1037",
          "title": "fix(web-surface): preserve immutable publication archives",
          "body": "Closes #1036.\n\n## Summary\n- detect the existing publication archive policy in each surface manifest\n- exclude immutable archive roots from owning and parent `sync --delete` operations\n- verify existing objects before and after `--no-overwrite` SHA-256 uploads\n- expose preservation coverage in apply summaries and health evidence\n\n## Validation\n- failure-first tests for parent-surface deletion coverage, global preflight ordering, CLI evidence, and digest mismatch\n- `pnpm run check` (481 tests; all action bundles built)\n- no live AWS mutations were executed",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:23:55Z",
          "mergedAt": "2026-07-10T08:26:20Z",
          "additions": 766,
          "deletions": 50,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 485,
          "url": "https://github.com/kungfu-systems/kungfu/pull/485",
          "title": "feat(storage): process-level provider cache retires per-call lifecycle",
          "body": "Close ADR-0040 decision 6: one process-cached provider per (provider, canonical runtime dir); thread-safe shared rocksdb handle; GIL released around the content-store facade; concurrency dedup fixtures for both providers; cache observability in status/layout; lifecycle doc.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:28:43Z",
          "mergedAt": "2026-07-10T08:28:49Z",
          "additions": 321,
          "deletions": 52,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1038,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1038",
          "title": "release: promote v2.11 alpha",
          "body": "Promotes the current protected v2.11 development line to alpha.\n\nIncluded fixes:\n- exact paper publication evidence allowlist and early protected-authority preflight (#1035)\n- immutable publication archive preservation across parent and owning web-surface syncs (#1037)\n\nValidation:\n- Buildchain PR checks green\n- full local `pnpm run check` (481 tests)\n- current site-libkungfu-dev artifact consumed the train in deploy-plan-only mode; no AWS apply was executed\n\nStable publication is out of scope.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:27:03Z",
          "mergedAt": "2026-07-10T08:28:59Z",
          "additions": 870,
          "deletions": 66,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 486,
          "url": "https://github.com/kungfu-systems/kungfu/pull/486",
          "title": "feat(shifu): lock the launcher version to lerna and make shifu the build opener",
          "body": "Version: crates/shifu/Cargo.toml is kept in lockstep with lerna.json by scripts/sync-shifu-version.mjs (rewritten during the lerna version lifecycle; drift-gated by shifu check). The launcher ships with the release train, so it carries the train's version: shifu-v0.1.0 is reissued as shifu-v4.0.0-alpha.0.\n\nDocs: onboarding opens with ./shifu everywhere (README quick start, AGENTS.md, CONTRIBUTING) — nothing to preinstall beyond curl; fnm / uv are bootstrapped details, not prerequisites.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:31:12Z",
          "mergedAt": "2026-07-10T08:31:19Z",
          "additions": 115,
          "deletions": 28,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 487,
          "url": "https://github.com/kungfu-systems/kungfu/pull/487",
          "title": "feat(storage): add Episode Qualification Capability Contract v1",
          "body": "## Summary\n- add C++-owned kungfu.episode.qualification/v1 with evidence, issues, safe capabilities, contractions, and repair prerequisites\n- project the same result through scoped fsck/inspect and Python/Node/CLI edges\n- make capability_soundness a required, executable Semantic v1 dimension\n\n## Validation\n- ./kungfu-code check\n- ./kungfu-code build:core\n- ./kungfu-code freeze\n- focused Episode Python: 41 passed plus final fsck 22 passed\n- native Node binding: 5 passed, 0 skipped\n- CI=1 ./kungfu-code verify: 25/25, scale 5/5, semantic 9/9, qualified=true",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:38:40Z",
          "mergedAt": "2026-07-10T08:38:45Z",
          "additions": 957,
          "deletions": 75,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1039,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1039",
          "title": "docs(retrospective): record consolidation closure",
          "body": "Records the completed Stage 1–3 evidence, open-issue audit, #1036 archive preservation fix, v2.11.13-alpha.3 evidence, and remaining out-of-scope work.\n\nValidation: `git diff --check`; documentation-only change.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:39:23Z",
          "mergedAt": "2026-07-10T08:41:50Z",
          "additions": 69,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 23,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/23",
          "title": "docs(paper): add Episode implementation evidence",
          "body": "## Summary\n\n- model observer-declared timelines over accepted, causally closed Episodes\n- separate journal authority, typed derivation, rebuildable projection, and observer-facing views\n- map current Kungfu evidence and remaining work to the KFD-4 contract\n- replace the evaluation-plan-only framing with bounded semantic, scale, contention, recovery, and projection evidence\n- state explicitly that first-class multi-machine observer projection remains future work\n\n## Verification\n\n- `make check`\n- `make pdf`\n- rendered and inspected all 12 PDF pages\n- cross-checked numeric claims against the public Episode qualification source\n- verified all fixed evidence links return HTTP 200\n\n## Boundaries\n\n- metadata-only development measurements are not capacity promises\n- capability soundness remains `not_exercised`\n- accepted-range sync, observer policy, exported observer declarations, and projection-level causal fsck are not claimed as implemented\n\n## Governance\n\n- [x] No credentials, tokens, secrets, private logs, or provider payloads\n- [x] No hosted-service or package publication change\n- [x] No branding, release identity, or domain change\n- [x] Public evidence and provenance links are explicit\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:42:06Z",
          "mergedAt": "2026-07-10T08:43:27Z",
          "additions": 340,
          "deletions": 57,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 488,
          "url": "https://github.com/kungfu-systems/kungfu/pull/488",
          "title": "feat(shifu): repo-pinned fnm/uv bootstrap versions + native CI lifecycle entrypoint",
          "body": "Two moves that finish making shifu the single build opener:\n\n1. fnm/uv bootstrap versions move from Rust constants to repo data files (.fnm-version / .uv-version, .node-version-shaped). Precedence: env override > pin file > compiled fallback. Bumping a pin is a one-line data change with no launcher re-release.\n2. Buildchain lifecycle stages and the build workflow verify-command run ./shifu directly under bash on every platform (the shim now resolves the native windows-x64 binary under MINGW/MSYS). scripts/buildchain-run-shifu.mjs (~660 lines of Windows special-casing) is retired. Promoted versions auto-tag shifu-v<version> launcher releases. build.yml gains workflow_dispatch for on-demand full-matrix validation.\n\nThe explicit verify-command is wrapped in bash -c with inlined env because a workflow-input command runs under the platform default shell and inherits neither the stage shell nor [lifecycle.env] — this also fixes the old env-prefix form that could not have worked under cmd.exe.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T09:11:44Z",
          "mergedAt": "2026-07-10T09:11:51Z",
          "additions": 170,
          "deletions": 704,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1041,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1041",
          "title": "chore(release): promote v2.11.13",
          "body": "## Summary\n\n- promote the tested v2.11.13 alpha lineage to the protected release channel\n- publish @kungfu-tech/buildchain@2.11.13 with release evidence\n- advance the stable v2.11 and v2 refs after transaction finalization\n\n## Included fixes\n\n- preserve immutable publication archive prefixes (#1037)\n- validate paper publication evidence and authority preflight (#1035)\n- serialize and canonicalize protected promotion triggers (#1030, #1033)\n\n## Validation\n\n- v2.11.13-alpha.3 is published from the current alpha channel\n- alpha/v2/v2.11 is a strict descendant of release/v2/v2.11\n- stable promotion remains guarded by Release - Verify and protected review\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T09:15:03Z",
          "mergedAt": "2026-07-10T09:17:14Z",
          "additions": 1536,
          "deletions": 241,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 24,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/24",
          "title": "chore(release): prepare observer paper alpha.4",
          "body": "## Summary\n\n- bring the second substantive observer-timeline paper revision onto the v0.1 development line\n- advance the publication version to `0.1.0-alpha.4`\n- update publication metadata to describe the implemented Episode substrate and bounded evidence\n- preserve the established short public PDF filename and Buildchain paper release configuration\n\n## Verification\n\n- `make check`\n- `make pdf`\n- confirmed `_build/observer-declared-timelines.pdf`\n- inspected PDF metadata: 12 pages, letter size\n\n## Release boundary\n\nThis PR prepares the development line only. Publishing occurs after a separate reviewed promotion from `dev/v0/v0.1` to `alpha/v0/v0.1`.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T09:30:35Z",
          "mergedAt": "2026-07-10T09:33:52Z",
          "additions": 342,
          "deletions": 59,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 26,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/26",
          "title": "chore(release): promote observer paper alpha.4",
          "body": "## Promotion\n\nPromote the reviewed v0.1 development line to `0.1.0-alpha.4`.\n\n## Included change\n\n- second substantive observer-declared timelines paper revision\n- Episode causal-object model and authority/projection separation\n- KFD-4 implementation map\n- bounded semantic, scale, contention, recovery, and projection evidence\n- explicit remaining multi-machine observer-projection boundary\n- preserved `observer-declared-timelines.pdf` public filename\n\n## Evidence\n\n- development PR #24 approved and merged\n- Build publication artifact: passed\n- Verify: passed\n- local `make check` and `make pdf`: passed\n\nMerging this PR intentionally triggers the Buildchain paper alpha release transaction.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T09:34:15Z",
          "mergedAt": "2026-07-10T09:35:28Z",
          "additions": 342,
          "deletions": 59,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 64,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/64",
          "title": "fix(buildchain): preserve publication archives",
          "body": "## Summary\n\n- upgrade the pinned Buildchain package from 2.11.1 to 2.11.13\n- accept the current floating v2 runtime contract\n- consume the immutable publication preservation fix from buildchain#1036\n- update rendered Buildchain version assertions and documentation\n\n## Verification\n\n- corepack pnpm install --frozen-lockfile\n- corepack pnpm run build\n- corepack pnpm run check\n- generated a staging deploy plan with the Buildchain 2.11.13 runtime\n- verified Papers declares archive as a preserved root\n- verified the hub mutable sync excludes papers/archive/*\n- verified the Papers mutable sync excludes archive/*\n- verified pre-upload, no-overwrite sync, and post-upload immutable operations are planned\n\n## Governance\n\n- [x] Buildchain workflow consumption remains on floating v2\n- [x] Contract lock resolves v2 to 618512fd874cc0125cc8a3daa07ef4d1b195777e\n- [x] Production remains separately gated\n- [x] No publication facts are rewritten by the site",
          "author": "dongkeren",
          "createdAt": "2026-07-10T09:31:17Z",
          "mergedAt": "2026-07-10T09:39:51Z",
          "additions": 18,
          "deletions": 18,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 490,
          "url": "https://github.com/kungfu-systems/kungfu/pull/490",
          "title": "feat(shifu): launcher usage/version flags and installed-binary delegation",
          "body": "Bare shifu / -h / --help print the launcher's own usage; --version / -v / -V print build identity (crate version + git sha baked by build.rs + installed/repo role); an installed shifu delegates to the checkout's ./shifu entrypoint whenever it runs inside one (SHIFU_FROM_SHIM guards recursion), so the repo-pinned launcher always wins. Shims gain matching in-script fallbacks. pnpm's own help stays reachable via shifu help.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T09:59:19Z",
          "mergedAt": "2026-07-10T09:59:25Z",
          "additions": 214,
          "deletions": 12,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 66,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/66",
          "title": "fix(papers): update observer timelines alpha.4",
          "body": "## Summary\n\n- update the pinned observer-declared-timelines package to 0.1.0-alpha.4\n- consume the new publication PDF and evidence directly from the upstream registry\n- keep Buildchain immutable preservation scoped to the complete archive root\n\n## Verification\n\n- corepack pnpm install --frozen-lockfile\n- corepack pnpm run build\n- corepack pnpm run check\n- verified the rendered alpha.4 PDF SHA-256 is 6a3f0a4583f0dacb8bc36aa2331c49ac906ed0ca8438cd3c3cc84175a8d09fa8\n- verified the staging plan protects archive/* and the hub plan protects papers/archive/*\n\n## Staging acceptance\n\n- alpha.4 observer PDF and evidence routes return HTTP 200\n- alpha.3 observer PDF and evidence routes remain HTTP 200 after deployment\n- staging __immutable__ health remains pass\n- production remains separately gated",
          "author": "dongkeren",
          "createdAt": "2026-07-10T09:56:07Z",
          "mergedAt": "2026-07-10T10:03:28Z",
          "additions": 8,
          "deletions": 8,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 491,
          "url": "https://github.com/kungfu-systems/kungfu/pull/491",
          "title": "feat(storage): sealed Episode content root commits identity (ADR-0043)",
          "body": "ADR-0043: Episode identity is two layers — episode_id stays the local lifecycle coordinate; a sealed Episode's content identity is a hash root chained over its owned claim sequence, committed as EpisodeRootCommitted (carrier 10806, additive) by the seal path and verified by fsck. Covers determinism/sensitivity/crash-shape/cross-store-invariance fixtures, projection support, bundle-apply compatibility, and the qualification reference model update.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:04:59Z",
          "mergedAt": "2026-07-10T10:05:05Z",
          "additions": 856,
          "deletions": 29,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1045,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1045",
          "title": "feat(kfd): add product claims registry",
          "body": "## Summary\n- add a generic product-owned KFD-2 claims registry contract under the canonical `.buildchain/kfd/kfd-2` layout\n- expose deterministic render, write, and read-only drift checks through Node API and CLI\n- register the public surface and generated site facts\n\n## Downstream validation\n- exact train: `train/v2/v2.11/kfd2-product-claims-registry` at `6da888728a99141ecc962774edf5d08095386c18`\n- Kungfu migrated its registry and generated release/SDK projections through this API\n- Kungfu core build, freeze, KFD evidence checks, mypy, Episode qualification, and end-to-end verify passed 25/25\n\n## Validation\n- `pnpm run check` (486 tests passed)\n- `node --test tests/kfd2-product-claims-registry.test.mjs tests/kfd3-surface-register.test.mjs` (13 passed)\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:03:46Z",
          "mergedAt": "2026-07-10T10:05:46Z",
          "additions": 887,
          "deletions": 52,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1047,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1047",
          "title": "chore(release): reconcile v2.11 alpha state",
          "body": "## Summary\n- merge the generated `v2.11.14-alpha.0` release bookkeeping from `alpha/v2/v2.11` back into `dev/v2/v2.11`\n- preserve the KFD-2 product claims registry merged in #1045\n- restore a clean, reviewable `dev -> alpha` promotion path for #1046\n\nThis is the documented recovery path after the prior release transaction skipped a non-fast-forward dev sync.\n\n## Validation\n- `pnpm run generate:site`\n- `pnpm run check` (486 passed)\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:08:50Z",
          "mergedAt": "2026-07-10T10:10:40Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1046,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1046",
          "title": "release: promote KFD-2 product claims registry",
          "body": "## Release intent\nPromote the reviewed Buildchain KFD-2 product claims registry capability from `dev/v2/v2.11` to the alpha channel.\n\n## Included change\n- PR #1045 (`ec716b4`)\n- downstream validation against exact train `6da8887`\n- Buildchain cross-platform checks passed\n- Kungfu build, freeze, KFD evidence, and verify passed 25/25\n\nThis uses the normal Buildchain alpha promotion transaction and npm trusted publishing path.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:06:18Z",
          "mergedAt": "2026-07-10T10:12:46Z",
          "additions": 956,
          "deletions": 52,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 492,
          "url": "https://github.com/kungfu-systems/kungfu/pull/492",
          "title": "feat(shifu): clone and doctor verbs; repo version line reports the branch",
          "body": "shifu clone [path] fetches the repository (default ., SHIFU_CLONE_URL override) — with delegation this completes the bootstrap-core loop: install once, clone anywhere, every evolvable behavior comes from the repo-pinned launcher. shifu doctor is an environment preflight that reports and never installs (required tools with versions/install pointers, shifu-managed tools with repo pins, optional rustc; exit 1 on missing required). The repo role of --version now appends the checkout's current branch.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:16:07Z",
          "mergedAt": "2026-07-10T10:16:12Z",
          "additions": 334,
          "deletions": 22,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 493,
          "url": "https://github.com/kungfu-systems/kungfu/pull/493",
          "title": "refactor(kfd): adopt Buildchain product claims",
          "body": "## Summary\n- move the product-owned KFD-2 claims registry to canonical `.buildchain/kfd/kfd-2/registry.json`\n- replace Kungfu's custom 501-line generator with Buildchain `product-claims` render/write/check APIs\n- upgrade all Buildchain consumers to published `2.11.14-alpha.0` and refresh release/SDK evidence\n- remove `framework/release` and all legacy references while preserving release-passport claim inputs and public package projections\n\n## Upstream\n- Buildchain #1045 merged\n- alpha promotion #1046 merged\n- npm `@kungfu-tech/buildchain@2.11.14-alpha.0` published and verified\n\n## Validation\n- frozen install passed\n- staged gate passed\n- `pnpm run check:types` passed\n- `pnpm run kfd2:claims:check` passed\n- `pnpm run kfd:buildchain:check` passed\n- core build + freeze passed\n- `pnpm verify` passed 25/25, including Episode Qualification\n- legacy path/reference scan passed\n\n## Known baseline\n`pnpm run check:all` still reports the existing repository-wide Biome baseline (945 diagnostics in unrelated files); all touched files pass the staged/targeted Biome gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:19:36Z",
          "mergedAt": "2026-07-10T10:20:31Z",
          "additions": 151,
          "deletions": 686,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 494,
          "url": "https://github.com/kungfu-systems/kungfu/pull/494",
          "title": "feat(shifu): styled launcher output and bootstrap-core docs",
          "body": "Styled launcher-owned output (usage / doctor / clone): ANSI color + semantic emoji, TTY-gated (NO_COLOR and TERM=dumb respected; piped output stays plain, doctor's exit code remains the script interface). std-only ~50-line style module.\n\nDocs: README getting-started gains the installed-shifu bootstrap-core path (cargo install once, shifu clone anywhere, stay current by pulling code) and a doctor step; CONTRIBUTING and AGENTS.md point at doctor.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:23:51Z",
          "mergedAt": "2026-07-10T10:23:57Z",
          "additions": 165,
          "deletions": 37,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 495,
          "url": "https://github.com/kungfu-systems/kungfu/pull/495",
          "title": "fix(shifu): weld the delegation protocol to the entrypoints alone",
          "body": "Installed binaries bake in the delegation protocol forever, so anchor it on nothing that can evolve: repo-root recognition = shifu + shifu.cmd both present (the welded entrypoint pair; previously the L2 marker and the node pin file — a future without node must not break old binaries); the entrypoint is spawned directly, implementation-form agnostic; SHIFU_DELEGATED=1 joins SHIFU_FROM_SHIM=1 as a second anti-loop fuse. Protocol registered as part of the shifu-launcher welded surface. Shipped before any delegating binary reaches a release.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:36:53Z",
          "mergedAt": "2026-07-10T10:36:58Z",
          "additions": 38,
          "deletions": 9,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 67,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/67",
          "title": "Release production from 5a413ac31513",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `5a413ac3151320a756a357aa8b6c0a99bf5d1f65`\n- Artifact hash: `188958976a0fe0d5bc66b29d34bf527a90aead0a304465b314d16102506e171c`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29085094503)\n- Required label: `buildchain-release`\n- Release branch: `release/production-5a413ac31513`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-10T10:11:33Z",
          "mergedAt": "2026-07-10T10:42:31Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 68,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/68",
          "title": "feat(release): add no-apply Buildchain canary",
          "body": "## Summary\n- add a dedicated `Buildchain Stable Canary` manual workflow\n- require an exact Buildchain alpha ref\n- fix preview, staging, production, and production-release apply paths to `false`\n- leave the existing deployment workflow unchanged\n\n## Validation\n- `actionlint .github/workflows/buildchain-web-surface.yml .github/workflows/buildchain-stable-canary.yml`\n- repository web-surface checks\n\nThe new canary workflow does not perform AWS apply or deployment.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:28:50Z",
          "mergedAt": "2026-07-10T10:42:54Z",
          "additions": 49,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 496,
          "url": "https://github.com/kungfu-systems/kungfu/pull/496",
          "title": "docs(shifu): ADR-0044 records the delegation protocol; entrypoints carry the warning",
          "body": "ADR-0044 states the four protocol clauses installed binaries bake in (root recognition = shifu + shifu.cmd pair, direct spawn, the two anti-loop env fuses, release asset layout), the consequences (never rename/move/remove the entrypoints; implementation form free), and rejected alternatives. Both entrypoint files carry a protocol-warning header — the file an agent opens to edit is the file that warns them. KFD-1 register row, rust-adoption.md, MAP.md, and source comments point at the ADR.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:43:11Z",
          "mergedAt": "2026-07-10T10:43:17Z",
          "additions": 111,
          "deletions": 3,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 69,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/69",
          "title": "fix(release): grant reusable canary permissions",
          "body": "## Summary\n- match the permission contract declared by `.web-surface.yml@v2`\n- keep all preview, staging, production, and production-release apply inputs fixed to `false`\n\n## Evidence\n- train canary run 29087244764 stopped at `startup_failure` with zero jobs\n- `actionlint .github/workflows/buildchain-stable-canary.yml`\n\nNo AWS apply or deployment ran in the failed attempt.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:45:11Z",
          "mergedAt": "2026-07-10T10:45:23Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 70,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/70",
          "title": "fix(release): match canary contents permission",
          "body": "## Summary\n- grant the maximum `contents: write` permission declared by the called `.web-surface.yml@v2` workflow\n- keep every canary apply and production-release input fixed to `false`\n\n## Evidence\n- train canary runs 29087244764 and 29087343327 both stopped at `startup_failure` with zero jobs while caller permissions were lower than the reusable workflow contract\n- `actionlint .github/workflows/buildchain-stable-canary.yml`\n\nNeither failed attempt started a job or performed AWS apply.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:46:48Z",
          "mergedAt": "2026-07-10T10:47:02Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1049,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1049",
          "title": "feat(release): gate stable promotion with canaries",
          "body": "## Summary\n- add a versioned Buildchain stable-release policy: 24-hour stable cooldown, named internal and consumer canaries, one-hour soak, version-bound impact, and non-empty product/contract diff\n- evaluate the stable gate after RC resolution and before publish-gate, npm, tag, or ref mutation; alpha and train iteration remain unthrottled\n- preserve concurrent dev changes when overlaying generated next-alpha version state\n- report post-complete next-alpha failures as deferred bookkeeping instead of reversing an already complete stable release\n- record the Stage 4 decision and #1042 reproduction in release governance and the consolidation retrospective\n\n## Train and canary\n- train ref: `train/v2/v2.3/stable-release-throttling-canary-gate`\n- train SHA: `a5f486b1f9a9df3225c407f9473ddf7f6feb5958`\n- consumer canary workflow PR: kungfu-systems/site-libkungfu-dev#68\n\n## Validation\n- 9 stable-gate unit/integration tests pass\n- promotion/build-surface/gate targeted suite passes\n- full unit suite passes except four local KFD package-discovery cases unavailable without this new worktree dependency install; protected PR CI is the authoritative full dependency run\n- `node scripts/check-inventory.mjs`\n- generated site bundle check\n- action bundle rebuilt and syntax checked\n- `actionlint` for promotion workflows\n- `git diff --check`\n\nNo stable release, npm publication, AWS apply, branch-protection bypass, or channel-ref mutation was used as validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:38:58Z",
          "mergedAt": "2026-07-10T10:49:03Z",
          "additions": 1402,
          "deletions": 186,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1050,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1050",
          "title": "chore(release): promote v2.11 stable gate alpha",
          "body": "## Release intent\nPromote the merged Stage 4 stable-release gate from `dev/v2/v2.11` to the alpha channel.\n\n## Evidence\n- implementation PR: #1049\n- no-apply consumer train canary: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29087415700\n- train runtime SHA: `1525f7bc7453cd35421bce80159081f05a7ad92b`\n- consumer build/check passed; all apply and production-release jobs were skipped\n\nThis PR requests alpha evidence only. It does not request stable publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:49:32Z",
          "mergedAt": "2026-07-10T10:51:08Z",
          "additions": 1402,
          "deletions": 186,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1053,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1053",
          "title": "fix(release): rebuild stable gate action bundle",
          "body": "## Summary\n- rebuild `actions/promote-buildchain-ref/dist/index.js` with the repository-standard `tsup` command and complete workspace dependency graph\n- no source behavior change\n\n## Evidence\n- alpha promotion run 29087654249 failed before publication because version verification rebuilt this bundle and detected drift\n- canonical bundle size matches CI output: 865.85 KB\n- targeted promotion regressions: 3 passed\n- stable gate tests: 9 passed\n- `node --check actions/promote-buildchain-ref/dist/index.js`\n- `git diff --check`\n\nCloses #1052 after a successful alpha retry.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:56:08Z",
          "mergedAt": "2026-07-10T10:58:05Z",
          "additions": 59,
          "deletions": 59,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1054,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1054",
          "title": "chore(release): retry v2.11 stable gate alpha",
          "body": "## Release intent\nRetry the Stage 4 alpha after canonical action bundle rebuild PR #1053.\n\n## Evidence\n- first promotion run 29087654249 stopped before publication on generated bundle drift\n- source fix PR: #1053\n- no-apply consumer train canary: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29087415700\n\nThis remains alpha-only release intent; no stable publication is requested.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:58:17Z",
          "mergedAt": "2026-07-10T11:00:16Z",
          "additions": 59,
          "deletions": 59,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 25,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/25",
          "title": "Release production from a515dd2ba587",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `a515dd2ba587a6ce293f72b98fbc230bb5d426e8`\n- Artifact hash: `3c42347d5aafcc404f4c1d701a27519f1518915cfa2d1457a5be0861780c3476`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29065556069)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-a515dd2ba587`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-10T02:53:17Z",
          "mergedAt": "2026-07-10T11:17:58Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 497,
          "url": "https://github.com/kungfu-systems/kungfu/pull/497",
          "title": "feat(shifu): enforce the repository build entrypoint",
          "body": "## Summary\n\n- route Claude and Copilot repository guidance through the existing `AGENTS.md` Shifu contract\n- add a deterministic entry-contract gate for participant-facing docs, workflows, Buildchain lifecycle commands, runtime markers, and root package tasks\n- mark Shifu child execution and reject accidental direct package-manager entry with a copyable `./shifu <task>` correction\n- run the gate from both source checks and Buildchain lifecycle verification while preserving explicit launcher/bootstrap exceptions\n- restore the Rust format and Clippy baseline exposed by the three-platform launcher gate\n\n## Validation\n\n- `./shifu check:staged`\n- `./shifu check:entry-contract`\n- `./shifu exec node --test scripts/check-shifu-entry-contract.test.mjs` (7/7)\n- `SHIFU_NATIVE=0 ./shifu check:entry-contract`\n- native debug launcher `check:entry-contract`\n- `cargo fmt --all --manifest-path crates/Cargo.toml -- --check`\n- `cargo clippy --manifest-path crates/Cargo.toml --workspace --all-targets -- -D warnings`\n- `cargo test --manifest-path crates/Cargo.toml -p shifu` (4/4)\n- `sh -n shifu`\n- `shellcheck -e SC1007 shifu`\n- PR CI: macOS, Linux, and Windows launcher format/Clippy/test/release-build/smoke gates passed\n- Buildchain validate and DCO passed\n\n## Existing baseline\n\nThe repository-wide `./shifu check` reaches and passes the new gate and tests, then reports the pre-existing SDK canonical-policy source/render mismatch (25/26 SDK tests). This PR does not touch that policy or projection.\n\n## Version impact\n\nPatch: this enforces the already documented Shifu entrypoint and does not change the registered delegation protocol or open a new compatibility line.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T11:16:13Z",
          "mergedAt": "2026-07-10T11:22:13Z",
          "additions": 461,
          "deletions": 59,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 498,
          "url": "https://github.com/kungfu-systems/kungfu/pull/498",
          "title": "docs(kfx): propose native and wasm execution profiles",
          "body": "## Summary\n\n- document the historical and current native KFX evidence\n- propose four orthogonal execution profiles: native, WebAssembly, managed, and subprocess\n- recommend Rust as the native authoring default only behind a versioned C ABI and explicit safety gates\n- select Wasmtime provisionally for a future component-model spike, with Wasmer retained as a measured fallback\n- define performance, footprint, provenance, and decision gates without changing the current KFX contract\n\n## Validation\n\n- git diff --check\n- local Markdown link validation\n- staged repository gate passed during commit\n- ./shifu check: 25/26 SDK tests passed; the remaining failure is a pre-existing canonical-policy hash mismatch in an unchanged contract file\n\n## Scope\n\nResearch and proposed ADR only. No runtime, contract, dependency, or build-pipeline implementation is included.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T11:32:18Z",
          "mergedAt": "2026-07-10T11:34:01Z",
          "additions": 286,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 499,
          "url": "https://github.com/kungfu-systems/kungfu/pull/499",
          "title": "fix(sdk): refresh canonical policy baseline",
          "body": "## Summary\n- refresh the frozen canonical-policy Buildchain package version to match the SDK dependency\n- restore byte-for-byte equality between the canonical source and SDK renderer\n\n## Validation\n- `./shifu check`\n- `./shifu exec node developer/sdk/src/sdk.js contract policy --check --json`\n- `./shifu exec node developer/sdk/src/sdk.js contract audit --json`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T11:39:18Z",
          "mergedAt": "2026-07-10T11:40:18Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 28,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/28",
          "title": "Upgrade white paper site bundle to alpha.2",
          "body": "## Summary\n\n- upgrade `@kungfu-tech/paper-kungfu-product-white-paper` to `0.1.0-alpha.2`\n- consume the brand bundle, publication manifest, and PDF through package exports\n- match the PDF artifact using its exported package-relative path instead of the former `_build/main.pdf` filename\n- keep pnpm minimum-release-age protection while allowing this explicitly verified alpha.2 package\n\n## Verification\n\n- `corepack pnpm@11.7.0 run build`\n- `corepack pnpm@11.7.0 run check`\n- generated PDF SHA256: `646998d209f045389ef4f3af4cadd48e18750a1e57b0ae144c9e2466a3c3f087`\n- generated machine manifest identifies `@kungfu-tech/paper-kungfu-product-white-paper@0.1.0-alpha.2`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T11:43:26Z",
          "mergedAt": "2026-07-10T11:46:27Z",
          "additions": 14,
          "deletions": 18,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 29,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/29",
          "title": "Release production from 7f62cf45b9a0",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `7f62cf45b9a05657caa2bba5644ace36501af862`\n- Artifact hash: `4fc8e5dd5b6d72b811d6fc2b3614bfbb1bf2f2b7bf55e8805b91f62c499995a2`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29090467241)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-7f62cf45b9a0`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-10T11:48:24Z",
          "mergedAt": "2026-07-10T11:50:55Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 500,
          "url": "https://github.com/kungfu-systems/kungfu/pull/500",
          "title": "docs(positioning): define the runtime fact infrastructure layer",
          "body": "## Summary\n\n- position Kungfu through the SQLite shape, Git-for-runs semantics, and flight-recorder-plus-qualification mission\n- distinguish the runtime fact ledger from observability and blockchain\n- explain why agent work creates a missing first-class runtime-fact layer\n- route the positioning question and keywords from the documentation map\n\n## Validation\n\n- `git diff --check`\n- public-surface leakage scan\n- `./shifu check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T11:59:08Z",
          "mergedAt": "2026-07-10T11:59:57Z",
          "additions": 113,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 501,
          "url": "https://github.com/kungfu-systems/kungfu/pull/501",
          "title": "feat(crates): probe the rust host shell, measure the real cost of freezing",
          "body": "Merge feature/rust-host-spike into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T12:07:57Z",
          "mergedAt": "2026-07-10T12:08:08Z",
          "additions": 634,
          "deletions": 0,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 502,
          "url": "https://github.com/kungfu-systems/kungfu/pull/502",
          "title": "feat(storage): migrate import manifest, export bundle, and channel cursor to kernel journal records",
          "body": "Merge feature/import-manifest-migration into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T12:40:03Z",
          "mergedAt": "2026-07-10T12:40:09Z",
          "additions": 2304,
          "deletions": 2215,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1055,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1055",
          "title": "fix: close open build and release contract gaps",
          "body": "## Summary\n\n- inherit lifecycle/stage env and an explicitly declared stage shell for workflow command overrides\n- retry transient GitHub source fallback fetches with a bounded, evidenced attempt budget\n- preserve the emitted `check / check` context and other consumer-required checks during release governance updates\n- hydrate cumulative paper publication registries from npm-integrity-verified historical packages\n- resolve web-surface channel/preview alias before caller build and reject cross-channel manifest hosts before apply\n\n## Verification\n\n- `pnpm run check`\n- 506 unit tests passed\n- workflow syntax/static checks passed\n- generated action bundles and `dist/site` registries rebuilt\n\n## Validation boundary\n\nThe exact runtime is published at `train/v2/v2.3/open-issue-remediation` for consumer checks. No stable ref or release is used as a test shortcut.\n\nFixes #1040\nFixes #1043\nFixes #1044\nFixes #1048\nFixes #1051",
          "author": "dongkeren",
          "createdAt": "2026-07-10T12:32:23Z",
          "mergedAt": "2026-07-10T12:43:15Z",
          "additions": 872,
          "deletions": 214,
          "changedFiles": 42
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1056,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1056",
          "title": "alpha: release open issue remediation",
          "body": "## Release intent\n\nPromote the reviewed Buildchain open-issue remediation from `dev/v2/v2.11` to the protected alpha channel.\n\nEvidence:\n- implementation PR #1055 merged with dual-identity review\n- full local check: 506 tests passed\n- Build Surface fixture passed on Linux, macOS, and Windows\n- exact-train site canary run 29093239858 passed with all deploy applies disabled\n- live npm registry hydration reconstructed alpha.1 through alpha.4 and appended alpha.5 deterministically\n\nThis PR requests a new alpha only; it does not request stable promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T12:44:42Z",
          "mergedAt": "2026-07-10T12:47:04Z",
          "additions": 872,
          "deletions": 214,
          "changedFiles": 42
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1058,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1058",
          "title": "fix(governance): preserve Buildchain self check context",
          "body": "## Summary\n\n- keep the public reusable-workflow default at the exact consumer context `check / check`\n- make Buildchain self-promotion, release-line bootstrap, and dogfood patrol use the repository-local `check` context\n- add regressions that fail if self and consumer contexts are collapsed again\n- refresh generated public-site contract evidence\n\n## Why\n\nThe issue-remediation alpha promotion failed closed because Buildchain's own protected branches emit `check`, while the reusable workflow context exposed to consumers is `check / check`. This patch preserves both exact contexts at their respective boundaries without mutating branch protection.\n\n## Validation\n\n- `node --test tests/build-surface.test.mjs tests/cli.test.mjs` (118 passed)\n- `pnpm run check` (506 tests passed; workflow checks, generated site, and four action builds passed)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T12:57:09Z",
          "mergedAt": "2026-07-10T12:59:41Z",
          "additions": 44,
          "deletions": 23,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1059,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1059",
          "title": "chore(release): promote v2.11 issue remediation to alpha",
          "body": "## Promotion intent\n\nPromote the completed open-issue remediation and the Buildchain self-check context correction from `dev/v2/v2.11` to `alpha/v2/v2.11`.\n\nThis creates a fresh protected Verify event so Buildchain Ref Promotion evaluates the repository-local required context `check` and publishes the next alpha. It does not request a stable release.\n\n## Included evidence\n\n- issue remediation PR #1055 (issues #1040, #1043, #1044, #1048, #1051)\n- self/consumer check-context correction PR #1058\n- full repository check: 506 tests, workflow validation, generated site consistency, and four action builds\n- Build Surface Fixture: Linux, macOS, and Windows passed on #1058\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T13:00:04Z",
          "mergedAt": "2026-07-10T13:02:06Z",
          "additions": 44,
          "deletions": 23,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1060,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1060",
          "title": "fix(release): bind stable canaries to exact runtime",
          "body": "## Summary\n\n- accept stable-canary runtime input only when it is the exact alpha tag or the 40-character SHA resolved from that tag\n- downgrade a successful commit status to `mismatched` when its workflow, repository, or runtime ref does not match the candidate\n- cover exact tag, exact candidate SHA, and wrong SHA behavior with a failure-first collector regression\n- refresh the `2.11.14` release impact so the eventual stable passport covers the full issue-remediation surface\n\n## Live finding\n\nThe no-apply site canary run 29096562817 rejected `v2.11.14-alpha.2` because the trusted runtime override contract accepts train refs or exact SHAs. Stage 4's prior accepted canary also used an exact SHA, but the stable gate collector only compared the run input with the tag and, separately, could retain `success` after a metadata mismatch.\n\nNo site deployment, npm publication, tag, or channel ref mutation occurred.\n\n## Validation\n\n- failure-first wrong-SHA collector assertion reproduced the false-success path\n- `node --test tests/stable-release-gate-cli.test.mjs tests/stable-release-gate.test.mjs` (9 passed)\n- `pnpm run check` (506 tests; workflow checks, generated site, and four action builds passed)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T13:39:34Z",
          "mergedAt": "2026-07-10T13:41:24Z",
          "additions": 106,
          "deletions": 40,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1061,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1061",
          "title": "alpha: verify stable canary runtime binding",
          "body": "## Promotion intent\n\nPromote the stable-canary exact runtime binding and consolidated `2.11.14` release impact to the alpha channel.\n\nThis is required before the next stable release can obtain a valid exact-SHA site canary. It does not request or bypass stable publication; the 24-hour stable interval and 1-hour canary soak remain authoritative.\n\n## Included evidence\n\n- fix PR #1060\n- failure-first tag/SHA/wrong-SHA collector regression\n- full repository check: 506 tests, workflow validation, generated site consistency, and four action builds\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T13:41:52Z",
          "mergedAt": "2026-07-10T13:43:44Z",
          "additions": 106,
          "deletions": 40,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 503,
          "url": "https://github.com/kungfu-systems/kungfu/pull/503",
          "title": "feat(storage): honest producer contract for redacted, absent, and missing payloads",
          "body": "Merge feature/storage-payload-redaction-producer into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T13:50:44Z",
          "mergedAt": "2026-07-10T13:50:51Z",
          "additions": 344,
          "deletions": 45,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1062,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1062",
          "title": "fix(release): read stable canary run metadata",
          "body": "## Summary\n\n- resolve the authoritative workflow name from the Actions run `workflow_id`\n- recover the exact runtime ref from the workflow-owned run-name when the REST run payload omits dispatch inputs\n- keep explicit API inputs authoritative when a provider exposes them\n- record runtime-ref source and workflow ID in stable gate evidence\n\n## Live finding\n\nExact-SHA no-apply canary run 29097422065 succeeded with all apply jobs skipped. Its real GitHub REST object has no `inputs`, and its `name`/`display_title` is `Buildchain Stable Canary / <SHA>` rather than the base workflow name. The previous unit fixture did not model either provider behavior.\n\nNo attestation, stable PR merge, npm stable publication, tag, ref, or deployment mutation was performed from this incomplete evidence shape.\n\n## Validation\n\n- failure-first live-shape collector regression reproduced the blocked gate\n- `node --test tests/stable-release-gate-cli.test.mjs tests/stable-release-gate.test.mjs` (9 passed)\n- `pnpm run check` (506 tests; workflow checks, generated site, and four action builds passed)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T13:52:39Z",
          "mergedAt": "2026-07-10T13:54:41Z",
          "additions": 61,
          "deletions": 23,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1063,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1063",
          "title": "alpha: verify stable canary run metadata",
          "body": "## Promotion intent\n\nPromote the live GitHub Actions run-metadata collector correction to alpha so the stable gate can consume an exact-SHA no-apply canary without synthetic API fields.\n\nStable cooldown and final canary soak remain unchanged and are not bypassed.\n\n## Included evidence\n\n- fix PR #1062\n- exact live REST shape from canary run 29097422065\n- failure-first workflow_id/run-name regression\n- full repository check: 506 tests, workflow validation, generated site consistency, and four action builds\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T13:55:23Z",
          "mergedAt": "2026-07-10T13:57:11Z",
          "additions": 61,
          "deletions": 23,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 504,
          "url": "https://github.com/kungfu-systems/kungfu/pull/504",
          "title": "docs(adr): ADR-0046 — rust host trunk, layered CLI, assembled runtime",
          "body": "Merge feature/adr-rust-host-endstate into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:17:39Z",
          "mergedAt": "2026-07-10T14:17:46Z",
          "additions": 262,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 506,
          "url": "https://github.com/kungfu-systems/kungfu/pull/506",
          "title": "docs(storage): record the payload backend and source registry decisions as settled",
          "body": "Merge fix/storage-open-decisions into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:28:25Z",
          "mergedAt": "2026-07-10T14:28:33Z",
          "additions": 15,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 507,
          "url": "https://github.com/kungfu-systems/kungfu/pull/507",
          "title": "docs(adr): ADR-0046 — lazy-by-default toolchain delivery via the launcher lineage",
          "body": "Merge feature/adr0046-lazy-toolchain into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:41:17Z",
          "mergedAt": "2026-07-10T14:41:25Z",
          "additions": 41,
          "deletions": 13,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 505,
          "url": "https://github.com/kungfu-systems/kungfu/pull/505",
          "title": "ci(build): expose trusted Buildchain train override",
          "body": "## Summary\n\n- expose the documented trusted `workflow_dispatch` `buildchain-ref` pass-through while keeping the committed reusable workflow pinned to `@v2`\n- preserve normal build behavior when the input is empty\n- refresh the already-stale KFD-1/KFD-3 projections required by the repository commit gate\n\n## Validation\n\n- `./shifu check`\n- `actionlint .github/workflows/build.yml`\n- DCO and repository pre-commit gate\n- exact train run: https://github.com/kungfu-systems/kungfu/actions/runs/29099884183\n\nThis provides the consumer evidence path for Buildchain issue #1043 without committing a temporary Buildchain train ref.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:27:43Z",
          "mergedAt": "2026-07-10T14:46:49Z",
          "additions": 14,
          "deletions": 8,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 19,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/19",
          "title": "chore(buildchain): accept current v2 contract",
          "body": "## Summary\n\n- accept Buildchain v2 at immutable commit 618512fd874cc0125cc8a3daa07ef4d1b195777e\n- record the authoritative published contract digest\n- preserve the unchanged major-compatible surface digest\n\n## Validation\n\n- make check\n- git diff --check\n- verified the lock digest against Buildchain v2 dist/site/buildchain-contract.json\n\n## Governance\n\nThis is a compatible floating-ref acceptance update. It changes only .buildchain/contract-lock.json.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:49:33Z",
          "mergedAt": "2026-07-10T14:51:39Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 508,
          "url": "https://github.com/kungfu-systems/kungfu/pull/508",
          "title": "docs(kfx): ratify ADR-0045 execution profiles",
          "body": "## Summary\n\n- ratify ADR-0045 after all five maintainer decisions were accepted\n- record the native-first spike order and shared host capability membrane\n- keep implementation, contract changes, and spike gate claims explicitly pending\n\n## Validation\n\n- `./shifu check`\n- `git diff --check`\n- public-surface leak scan\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, billing, quota, or usage-attribution changes\n- [x] No hosted-service, branding, package, release, or deployment changes\n- [x] No contract or runtime implementation changes",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:50:54Z",
          "mergedAt": "2026-07-10T14:51:44Z",
          "additions": 23,
          "deletions": 17,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 23,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/23",
          "title": "chore(buildchain): accept current v2 contract",
          "body": "## Summary\n\n- accept Buildchain v2 at immutable commit 618512fd874cc0125cc8a3daa07ef4d1b195777e\n- record the authoritative published contract digest\n- preserve the unchanged major-compatible surface digest\n\n## Validation\n\n- make check\n- git diff --check\n- verified the lock digest against Buildchain v2 dist/site/buildchain-contract.json\n\n## Governance\n\nThis is a compatible floating-ref acceptance update. It changes only .buildchain/contract-lock.json.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:49:37Z",
          "mergedAt": "2026-07-10T14:51:44Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 27,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/27",
          "title": "chore(buildchain): accept current v2 contract",
          "body": "## Summary\n\n- accept Buildchain v2 at immutable commit 618512fd874cc0125cc8a3daa07ef4d1b195777e\n- record the authoritative published contract digest\n- preserve the unchanged major-compatible surface digest\n\n## Validation\n\n- make check\n- git diff --check\n- verified the lock digest against Buildchain v2 dist/site/buildchain-contract.json\n\n## Governance\n\nThis is a compatible floating-ref acceptance update. It changes only .buildchain/contract-lock.json.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:49:40Z",
          "mergedAt": "2026-07-10T14:51:49Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 20,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/20",
          "title": "chore(buildchain): accept current v2 contract on development line",
          "body": "## Summary\n\n- accept the current Buildchain v2 contract on the active v0.1 development line\n- preserve the development line's paper and release history\n- resolve the outstanding compatible-drift review debt\n\n## Validation\n\n- make check\n- git diff --check\n- verified the accepted digest against Buildchain v2 dist/site/buildchain-contract.json\n\n## Scope\n\nThis PR changes only .buildchain/contract-lock.json. It does not publish or modify an existing alpha release.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:53:46Z",
          "mergedAt": "2026-07-10T14:55:55Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 24,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/24",
          "title": "chore(buildchain): accept current v2 contract on development line",
          "body": "## Summary\n\n- accept the current Buildchain v2 contract on the active v0.1 development line\n- preserve the development line's paper and release history\n- resolve the outstanding compatible-drift review debt\n\n## Validation\n\n- make check\n- git diff --check\n- verified the accepted digest against Buildchain v2 dist/site/buildchain-contract.json\n\n## Scope\n\nThis PR changes only .buildchain/contract-lock.json. It does not publish or modify an existing alpha release.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:53:49Z",
          "mergedAt": "2026-07-10T14:56:00Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 28,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/28",
          "title": "chore(buildchain): accept current v2 contract on development line",
          "body": "## Summary\n\n- accept the current Buildchain v2 contract on the active v0.1 development line\n- preserve the development line's paper and release history\n- resolve the outstanding compatible-drift review debt\n\n## Validation\n\n- make check\n- git diff --check\n- verified the accepted digest against Buildchain v2 dist/site/buildchain-contract.json\n\n## Scope\n\nThis PR changes only .buildchain/contract-lock.json. It does not publish or modify an existing alpha release.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:53:51Z",
          "mergedAt": "2026-07-10T14:56:08Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 509,
          "url": "https://github.com/kungfu-systems/kungfu/pull/509",
          "title": "docs(shifu): state the role — when your kungfu fails you, you turn to shifu",
          "body": "Merge feature/shifu-motto into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T15:08:08Z",
          "mergedAt": "2026-07-10T15:08:14Z",
          "additions": 34,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1065,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1065",
          "title": "fix(checkout): seed fallback from advertised source ref",
          "body": "## Summary\n\n- fetch the advertised source ref before trying a raw SHA so a current mirror satisfies checkout and a stale mirror seeds reusable objects\n- return retryable ref timeouts directly to the bounded retry loop instead of spending the same timeout again on an unadvertised SHA\n- separate the trusted-cache timeout from a 600-second default GitHub fallback timeout, sized from the real three-platform 5 Mbps contention window\n- preserve exact source commit/tree verification and record both timeout budgets\n- correct the Buildchain retrospective after the earlier premature closure\n\n## Validation\n\n- failure-first source-fetch order and timeout regressions\n- `node --test tests/locked-source-checkout.test.mjs tests/build-surface.test.mjs` (74/74)\n- `pnpm run check` (508/508, workflow and site checks, four action builds)\n- `git diff --check`\n- exact train: `train/v2/v2.3/issue-1043-source-fetch@48bf6148`\n- Kungfu dev consumer run: https://github.com/kungfu-systems/kungfu/actions/runs/29101288426\n\n## Release plan\n\nThis invalidates the current `v2.11.14-alpha.4` candidate and its canaries. After merge, regenerate alpha, rerun Binary Distribution and exact-SHA site/Build Surface canaries, then replace the existing stable release PR before the Stage 4 time gate.\n\nFixes #1043",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:24:16Z",
          "mergedAt": "2026-07-10T15:12:02Z",
          "additions": 174,
          "deletions": 45,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1067,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1067",
          "title": "alpha: include issue 1043 source checkout fix",
          "body": "## Promotion scope\n\n- include #1065 / #1043 constrained-source checkout correction\n- promote dev/v2/v2.11 at ea28e2bcaee6c23751271a6a5eb56e248c7ad143\n- invalidate v2.11.14-alpha.4 as the final stable candidate\n\n## Evidence\n\n- Buildchain Verify + Build Surface Fixture on #1065: green\n- authoritative Kungfu train run: https://github.com/kungfu-systems/kungfu/actions/runs/29101288426\n- locked-source checkout succeeded on Linux, macOS, and Windows; later lifecycle failures are downstream and outside #1043\n\nAfter merge, publish the next v2.11.14 alpha and run a fresh exact-SHA no-apply site canary before opening the replacement stable PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T15:12:46Z",
          "mergedAt": "2026-07-10T15:14:34Z",
          "additions": 174,
          "deletions": 45,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 510,
          "url": "https://github.com/kungfu-systems/kungfu/pull/510",
          "title": "docs(adr): converge ADR-0045/0046 on one libkungfu embedding membrane",
          "body": "Merge feature/adr-0045-0046-reconcile into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T15:29:03Z",
          "mergedAt": "2026-07-10T15:29:10Z",
          "additions": 28,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 511,
          "url": "https://github.com/kungfu-systems/kungfu/pull/511",
          "title": "docs(architecture): establish dual schema authority",
          "body": "## Summary\n\n- establish ADR-0047: every persisted structured fact has exactly one schema owner, either Hana POD or FlatBuffers\n- supersede ADR-0002 in schema scope and amend ADR-0025 so the action envelope migrates from transitional JSON/base64 to `ActionEnvelope.fbs`\n- align public architecture, event, storage, carrier, and versioning docs; correct ADR-0037 so typed storage service work is no longer reported as complete\n\n## Validation\n\n- `./shifu check`\n- `git diff --check`\n\n## Version impact\n\n- breaking-pre-release decision for the action-envelope encoding; no stable v4 compatibility promise is affected",
          "author": "dongkeren",
          "createdAt": "2026-07-10T15:57:35Z",
          "mergedAt": "2026-07-10T15:58:38Z",
          "additions": 395,
          "deletions": 78,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 512,
          "url": "https://github.com/kungfu-systems/kungfu/pull/512",
          "title": "shifu: extract the role framework (shifu-core: bootstrap + probe)",
          "body": "Split the launcher into a thin binary plus shifu-core, the unpublished workspace library carrying the shifu role: the pinned-fetch bootstrap engine with named self-diagnosing errors, and the declarative probe contract (reports, never repairs; exact repair commands named). The dev doctor consumes the probe framework and mounts the first seed probes (cache health, mirror reachability, pin bite); an integration test drives the bootstrap the way the product trunk will (ADR-0046 stage 1). Launcher behavior, release pipeline, and version pin surface unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T15:58:55Z",
          "mergedAt": "2026-07-10T15:59:01Z",
          "additions": 1426,
          "deletions": 647,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1069,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1069",
          "title": "feat(release): add major alpha floating channels",
          "body": "## Summary\n\n- add a generic `vN-alpha` channel for every Buildchain major\n- move it only from the highest minor in that major with a published alpha\n- fail closed to an auditable skip when an older minor promotes later\n- expose the contract in dry-run output, docs, generated site facts, and bundled action code\n\n## Validation\n\n- `node --test tests/promote-buildchain-ref.test.mjs tests/build-surface.test.mjs` (167 passed)\n- `pnpm run check` (512 passed; generated site and action bundles verified)\n- `git diff --check`\n\n## Release impact\n\nThis intentionally supersedes the current v2.11.14 stable candidate. After merge, Buildchain will publish a fresh alpha and rebuild exact-SHA canary evidence before opening a replacement stable PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:15:08Z",
          "mergedAt": "2026-07-10T16:17:31Z",
          "additions": 403,
          "deletions": 142,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1071,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1071",
          "title": "chore(release): reconcile v2.11 alpha version state",
          "body": "## Summary\n\nReconcile the protected dev line with the already-published `v2.11.14-alpha.5` generated version state. The prior promotion recorded `skipped-non-fast-forward` for dev, which made the next dev-to-alpha PR conflict.\n\nThis changes only the seven declared version-state files and retains the generic `vN-alpha` implementation already merged in #1069.\n\n## Validation\n\n- `pnpm run check` (512 passed)\n- generated site timestamp/source policy preserved from the alpha.5 evidence commit\n- `git diff --check`\n\nAfter this lands, PR #1070 can merge without rewriting protected branch history.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:22:57Z",
          "mergedAt": "2026-07-10T16:25:13Z",
          "additions": 23,
          "deletions": 14,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1072,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1072",
          "title": "chore(release): reconcile v2.11 alpha ancestry",
          "body": "## Summary\n\nRestore the already-published alpha.5 commit as an ancestor of the protected dev line after the prior promotion recorded `skipped-non-fast-forward`.\n\nThis merge commit is intentionally tree-identical to current dev: it changes no files and only closes the branch ancestry graph so the existing dev-to-alpha PR #1070 can merge without a force push or conflict rewrite.\n\n## Proof\n\n- first parent tree: `35e9e839cedd0f5971c99fc7ad904b0be88b6c91`\n- merge tree: `35e9e839cedd0f5971c99fc7ad904b0be88b6c91`\n- second parent: `v2.11.14-alpha.5` / `46c3fe1e`\n- `git diff-tree --exit-code HEAD^1 HEAD`\n- alpha commit is an ancestor of the proposed head",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:27:06Z",
          "mergedAt": "2026-07-10T16:29:01Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 516,
          "url": "https://github.com/kungfu-systems/kungfu/pull/516",
          "title": "build(core): split runtime deps from the toolchain, ship the wheel in dist",
          "body": "Merge feature/assembly-dist-s1 into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:29:16Z",
          "mergedAt": "2026-07-10T16:29:23Z",
          "additions": 72,
          "deletions": 33,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1070,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1070",
          "title": "alpha: publish generic major alpha channel",
          "body": "## Summary\n\nPromote the merged generic `vN-alpha` contract into the v2.11 alpha channel.\n\n## Expected promotion result\n\n- publish a fresh exact v2.11 alpha tag\n- move `v2.11-alpha` to the generated alpha commit\n- create and move `v2-alpha` to the same commit\n- align `alpha/v2/v2.11` and `dev/v2/v2.11` with that generated version state\n\nThis supersedes the candidate from closed PR #1068. Stable promotion requires fresh exact-SHA canary evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:19:09Z",
          "mergedAt": "2026-07-10T16:31:22Z",
          "additions": 397,
          "deletions": 127,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1074,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1074",
          "title": "fix(release): consume complete matching-ref responses",
          "body": "## Summary\n\nFix #1073 by consuming GitHub's complete matching-refs response exactly once. The endpoint returns all matching refs (340 for `tags/v2.` in this repository) and ignores page parameters; treating a 100+ result as another page repeated the same response until the safety cap failed.\n\nThe highest-minor `vN-alpha` ownership scan remains complete and cached, while the regression test now covers a single response containing more than 100 refs and a newer minor at the end.\n\n## Validation\n\n- live read-only API: page 1 and page 2 each returned the same complete 340-ref response\n- `node --test tests/promote-buildchain-ref.test.mjs` (100 passed)\n- `pnpm run check` (512 passed)\n- action bundle rebuilt\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:35:29Z",
          "mergedAt": "2026-07-10T16:37:34Z",
          "additions": 77,
          "deletions": 87,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1075,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1075",
          "title": "alpha: retry generic major alpha channel publication",
          "body": "## Summary\n\nRetry the generic `vN-alpha` alpha promotion after #1074 fixed issue #1073.\n\nThe first promotion failed before publication because GitHub matching-refs returns one complete 340-ref response and ignores page parameters. This PR carries the single-response scan fix; no new alpha tag or floating ref was moved by the failed run.\n\nExpected result: a fresh exact v2.11 alpha plus `v2.11-alpha` and the new `v2-alpha` pointing at the same generated commit.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:38:00Z",
          "mergedAt": "2026-07-10T16:39:47Z",
          "additions": 77,
          "deletions": 87,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 517,
          "url": "https://github.com/kungfu-systems/kungfu/pull/517",
          "title": "feat(core): kungfu-trunk with the kungfu-owned env surface",
          "body": "Merge feature/assembly-dist-s1 into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T17:04:34Z",
          "mergedAt": "2026-07-10T17:04:40Z",
          "additions": 832,
          "deletions": 6,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 518,
          "url": "https://github.com/kungfu-systems/kungfu/pull/518",
          "title": "feat(core): wrong-runtime guard at the binding seam",
          "body": "Merge feature/assembly-dist-s1 into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T17:11:16Z",
          "mergedAt": "2026-07-10T17:11:21Z",
          "additions": 177,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 519,
          "url": "https://github.com/kungfu-systems/kungfu/pull/519",
          "title": "docs: user guide for kungfu env and the one-runtime contract",
          "body": "Merge feature/assembly-dist-s1 into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T17:20:57Z",
          "mergedAt": "2026-07-10T17:21:02Z",
          "additions": 83,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 520,
          "url": "https://github.com/kungfu-systems/kungfu/pull/520",
          "title": "check: Rust format + clippy join the staged/changed/all gates",
          "body": "crates/ edits could reach a PR without meeting rustfmt or clippy locally — the pre-commit gate covered C++/Python/JS but not Rust. Wire a Rust leg into check.mjs at all three scopes running the exact two commands shifu CI runs (cargo fmt --all --check, cargo clippy --workspace --all-targets -D warnings) so the local gate cannot drift from CI; fix.mjs gets the matching repair leg (shifu fix:staged runs cargo fmt and re-stages). Missing cargo warns and skips — rustc stays outside shifu's bootstrap scope and CI backstops.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T21:00:55Z",
          "mergedAt": "2026-07-10T21:01:01Z",
          "additions": 53,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 521,
          "url": "https://github.com/kungfu-systems/kungfu/pull/521",
          "title": "feat(product): honor KF_DEV_HOME as the pinned dev workspace data home",
          "body": "Merge feature/kf-dev-home into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T21:07:02Z",
          "mergedAt": "2026-07-10T21:07:09Z",
          "additions": 127,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 523,
          "url": "https://github.com/kungfu-systems/kungfu/pull/523",
          "title": "shifu: source-fresh dev cache + self-update",
          "body": "The shim cache was keyed by the release pin, which only moves at release time — dev machines structurally ran a stale launcher (new doctor probes could never reach the user). Content-address the cache slot by the last commit touching launcher source when cargo+git are present (dirty trees rebuild every call, out-of-repo target dir so locked checkouts build); machines without cargo keep the existing path byte for byte. Add shifu self-update to refresh an installed binary in place: in-checkout source rebuild (or pinned release without cargo), explicit --version outside; downloads verified against SHA256SUMS through shifu-core's fetch engine (which learns raw non-archive assets); rename-dance swap restores the old binary on failure; shim-cache slots refuse the verb. Verified end to end incl. file:// mirror fixture.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:08:42Z",
          "mergedAt": "2026-07-10T23:08:48Z",
          "additions": 437,
          "deletions": 14,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 524,
          "url": "https://github.com/kungfu-systems/kungfu/pull/524",
          "title": "ci: consume buildchain through the v2-alpha floating channel",
          "body": "Switch the three buildchain references from @v2 to @v2-alpha to pick up the lifecycle override inheritance and bounded checkout fallback fixes (buildchain#1040, #1043) ahead of the stable channel — unblocking the native shifu lifecycle validation on the self-hosted matrix.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:30:51Z",
          "mergedAt": "2026-07-10T23:30:56Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 527,
          "url": "https://github.com/kungfu-systems/kungfu/pull/527",
          "title": "shifu: promote — the freshest built dev kungfu, one command away",
          "body": "Builds happen in temporary worktrees; using a fresh dev build meant locating the worktree, digging out the dmg, and installing by hand — and a cleaned worktree took its build with it. Desktop builds now register themselves into a user-global stash (directory-as-registry under ~/.cache/kungfu/product, meta.env in build-local.env shape, KUNGFU_PRODUCT_BUILDS_KEEP retention; advisory — cannot fail a successful build). The launcher grows the consuming verbs: shifu builds lists the stash, shifu promote [--launch] installs the newest entry (mac stage-then-swap .app replace with running-app guard; win silent nsis; linux AppImage), both answering outside a checkout. The user-global build-local.env layer now loads unconditionally so rootless verbs read configuration; knobs documented in build-local.env.example.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:46:05Z",
          "mergedAt": "2026-07-10T23:46:10Z",
          "additions": 590,
          "deletions": 7,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 526,
          "url": "https://github.com/kungfu-systems/kungfu/pull/526",
          "title": "Assembled runtime host: neutral seam, assemble packaging leg, trunk entry (ADR-0046 stage 2)",
          "body": "## What\n\nThree steps toward the assembled runtime distribution (ADR-0046 stage 2 — assembly replaces freezing), all behind the existing `freezer` config; defaults are untouched on every platform.\n\n1. **Host-neutral seam** (`kungfu.host`): the python tree stops deriving \"where is the product root\" and \"how does a child re-enter kungfu\" from `sys.executable`. Three host forms (frozen / assembled / source); the assembled form is declared by a `kungfu-host.json` marker at the tree prefix. The product-root family (contract discovery, baked first-party manifest, agent pack, trunk lookup, variants dist detection) and the self-re-entry family route through the seam; the wrong-runtime guard learns the assembled host is blessed by construction. Also fixes two latent entry_command defects (interpreter-shaped argv0 like `python3.13` slipping the exclusion set; `python -m` handing children an unexecutable `__main__.py` path) and the baked first-party test fixtures that had gone stale against the tightened sha256 schema.\n\n2. **Assemble packaging leg** (`freezer=assemble`): stages the pinned python-build-standalone prefix under `dist/kungfu/python` (same arch-qualified key and cache the trunk uses, from the same runtime-pins manifest), resolves the runtime dependency closure from the committed lock into the tree's site-packages, and wires the flat dist root through a site-packages `.pth` — never via `PYTHON*` env vars, which would leak into satellite envs. The tree keeps python-build-standalone's `EXTERNALLY-MANAGED` marker as an install-surface guard; the build stages deps through the one explicit bypass. The stdlib prune policy is a declarative manifest (`product/stdlib-prune.json`): a fixed family-level subtraction from a complete stdlib that new dependencies never interact with, whose stale entries fail the build instead of failing in the field — deliberately unlike the nofollow-import surface this stage retires. Windows is refused by name until its layout lands.\n\n3. **Trunk entry**: the trunk binary installs under the product name `kungfu` next to the tree. Invoked as `kungfu` it keeps the subtrees it implements (env, prewarm) and execs the assembled interpreter on `-m kungfu` for everything else, verbatim — argv-transparent per the layering law. The kungfu package ships in the tree's site-packages (its standard home, freeing the dist root for the entry). First prune fill: tcl/tk family, pip/ensurepip (uv is the only install engine), headers, bin auxiliaries — tree 68M full → 56M pruned.\n\n## Validation (macOS arm64)\n\n- `ruff` / `mypy` / `biome` / `cargo fmt+clippy` clean; trunk tests pass.\n- Seam tests (8 new) + wrong-runtime guard (8) + baked first-party (2, fixture fixed) all pass; full python suite delta vs baseline is exactly the fixture fix (remaining baseline failures are binding drift against a borrowed sibling build, not touched here).\n- Assembled dist smoke through the product entry: `kungfu --version`, `kungfu kfd status --json` (libnode round trip), `kungfu env list` (native), contract registry discovery, `import tkinter` refused, `python -m pip` absent, form/product-root detection correct.\n\n## Not in this PR\n\nmacOS default flip + `verify --full` gate migration (next slice, with the full-gate evidence); Linux/Windows assembly; Nuitka disposition ledger.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:36:42Z",
          "mergedAt": "2026-07-10T23:48:24Z",
          "additions": 670,
          "deletions": 50,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1079,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1079",
          "title": "ci(dogfood): verify floating alpha consumer refs",
          "body": "Merge feature/vn-alpha-self-dogfood-canary into dev/v2/v2.11 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:50:13Z",
          "mergedAt": "2026-07-10T23:52:37Z",
          "additions": 395,
          "deletions": 33,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1081,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1081",
          "title": "fix(dogfood): bootstrap stable runtime lane",
          "body": "Merge fix/vn-alpha-self-dogfood-bootstrap into dev/v2/v2.11 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:59:05Z",
          "mergedAt": "2026-07-11T00:01:04Z",
          "additions": 99,
          "deletions": 39,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1080,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1080",
          "title": "fix(runtime): allow official floating channel selection",
          "body": "## Summary\\n- treat official floating refs such as v2 and v2-alpha as channel selections on pull requests and pushes\\n- keep train refs and exact SHAs behind the trusted workflow_dispatch permission gate\\n- apply the resolver contract across build, release verification, web surface, paper release, and publication artifact workflows\\n- document the explicit workflow-shell/runtime binding required for alpha consumers\\n\\n## Verification\\n- pnpm run check\\n- 513 unit tests passed\\n- actionlint passed for all runtime-aware reusable workflows\\n- site-libkungfu-dev PR-event canary Plan passed: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29131439215\\n\\nFixes #1077",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:57:04Z",
          "mergedAt": "2026-07-11T00:04:02Z",
          "additions": 214,
          "deletions": 60,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1082,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1082",
          "title": "chore(release): promote v2.11 alpha",
          "body": "Promote the reviewed v2.11 development line to the alpha channel.\\n\\nThis publishes the official `v2-alpha` runtime-selection fix and self-dogfood coverage required by site and infrastructure consumers.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T00:04:53Z",
          "mergedAt": "2026-07-11T00:06:49Z",
          "additions": 663,
          "deletions": 87,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 528,
          "url": "https://github.com/kungfu-systems/kungfu/pull/528",
          "title": "shifu: fix cmd source fingerprint (rev-list instead of log --format)",
          "body": "First real-machine Windows run caught the cmd shim's source-fresh path never activating: a percent format inside a for /f backquote command is percent-processed again by the child cmd, so git received a literal %h and the empty fingerprint silently fell through to the release-pinned path. rev-list needs no format string.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T00:12:34Z",
          "mergedAt": "2026-07-11T00:12:39Z",
          "additions": 4,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1083,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1083",
          "title": "fix(dogfood): accept reviewed alpha contract",
          "body": "Merge fix/alpha-self-dogfood-contract-lock into dev/v2/v2.11 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T00:18:16Z",
          "mergedAt": "2026-07-11T00:20:40Z",
          "additions": 145,
          "deletions": 13,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 30,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/30",
          "title": "ci: adopt Buildchain v2-alpha runtime",
          "body": "## Summary\\n- move the web-surface workflow shell to the floating Buildchain v2-alpha channel\\n- accept the current v2-alpha runtime contract\\n- enforce the workflow and lock ref in repository checks and documentation\\n\\n## Verification\\n- pnpm 11.7.0 install --frozen-lockfile --ignore-scripts\\n- bash scripts/build-site.sh\\n- bash scripts/check-site.sh\\n- actionlint\\n- shellcheck\\n- Buildchain contract lock check against v2-alpha",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:45:37Z",
          "mergedAt": "2026-07-11T00:21:33Z",
          "additions": 26,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 74,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/74",
          "title": "ci: adopt Buildchain v2-alpha runtime",
          "body": "## Summary\\n- move the web-surface workflow shell and runtime canary to the floating Buildchain v2-alpha channel\\n- accept the current v2-alpha runtime contract in .buildchain/contract-lock.json\\n- enforce and document the alpha floating ref without changing deterministic site-bundle package pins\\n\\n## Verification\\n- pnpm 11.9.0 install --frozen-lockfile --ignore-scripts\\n- pnpm run build\\n- pnpm run check\\n- actionlint\\n- shellcheck\\n- Buildchain contract lock check against v2-alpha",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:45:34Z",
          "mergedAt": "2026-07-11T00:21:39Z",
          "additions": 26,
          "deletions": 32,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 514,
          "url": "https://github.com/kungfu-systems/kungfu/pull/514",
          "title": "feat(core): spike shared embedding membrane",
          "body": "## Summary\n\n- add one core-owned, versioned C ABI function table for context/reader/batched journal views\n- prove the same lifecycle through a dynamically loaded native KFX C++ wrapper and the existing Rust host-spike safe wrapper\n- retain mmap pages until explicit batch release; no per-frame callback and zero payload copies\n- keep KFX manifest/contract, WASM, product loader, and ADR-0046 Stage 3 out of scope\n\n## Final cross-platform evidence\n\n| Platform | control p50/p99 | 4 KiB batch p50/p99 | zero-copy / 1 MiB / idle |\n| --- | ---: | ---: | --- |\n| macOS ARM64 | 41 / 42 ns | 2.375 / 3.458 us | 0 copied / 1048576 B / 96 B |\n| Linux x64 | 18 / 19 ns | 1.002 / 2.898 us | 0 copied / 1048576 B / 96 B |\n| Windows x64 | 0 / 100 ns | 2.500 / 3.500 us | 0 copied / 1048576 B / 96 B |\n\n- final head: `faf0f266271e247c71194c3f933a69f5d2c17a6a`\n- workflow: https://github.com/kungfu-systems/kungfu/actions/runs/29132033903\n- 10 warmups, 1000 measured 16-frame / 4 KiB batches, 3 trials; median trial gates p99 <= 5 us\n- native KFX module dependency inspection: system runtime only on all three platforms\n- version/size/unknown-tail negotiation and null/busy/stale-token/close-before-release paths: pass\n- Rust host-spike: 5/5 pass\n- C11 header syntax, Rust fmt, focused Biome, actionlint, DCO, Buildchain Validate, and shifu CI: pass\n\n## Validation notes\n\n- macOS performance uses the official GitHub-hosted ARM64 runner; the self-hosted service inherits Darwin background QoS and remains useful for functional/zero-copy evidence, not latency gating.\n- hosted registry rebinding preserves the locked package name/version, non-registry source, and every sdist/wheel hash; only the registry transport URL changes from the LAN mirror to public PyPI.\n- full `./shifu lint` remains red on the existing repository baseline of 945 unrelated Biome diagnostics; focused task checks are green.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:12:55Z",
          "mergedAt": "2026-07-11T00:26:27Z",
          "additions": 1798,
          "deletions": 111,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 530,
          "url": "https://github.com/kungfu-systems/kungfu/pull/530",
          "title": "docs(query): define runtime fact query contract",
          "body": "Merge feature/runtime-query-service-adr0048 into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T00:28:19Z",
          "mergedAt": "2026-07-11T00:28:24Z",
          "additions": 430,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 529,
          "url": "https://github.com/kungfu-systems/kungfu/pull/529",
          "title": "feat(episode): retain release qualification evidence",
          "body": "## Summary\n- add a Shifu-only `kungfu.episode.release-evidence/v1` generator/verifier and retained Buildchain workflow artifact\n- bind Trust Report v2 to exact source, profile, platform, toolchain, runtime artifacts, and 14 explicit hard gates\n- preserve cross-page Episode manifest history and separate the no-progress safety gate from the outer runner watchdog\n\n## Verification\n- `./shifu check`\n- `./shifu build`\n- `./shifu episode:qualify:release -- --output product/release/qualification/episode-release-evidence.json`\n  - 21/21 scenarios, 14/14 gates, correctness failures 0, semantic oracle 48 histories\n  - evidence digest `sha256:c007eb30b699f7261e06334a88d56ccf867260d42533a8affaa1282f5ac6ac74`\n- independent `verify --check-runtime --json`: schema, internal contract, and runtime hashes all pass\n\n## Boundaries\nPerformance remains trend-only; this does not claim fleet/distributed capacity or a public throughput SLO. The heavy 100k baseline is release/manual only, not a per-PR gate.\n\n## Merge note\nPlease use a merge commit so the exact qualified head `e74e9b11f88b152e6964bd6e2c7c85b173f52045` remains a parent of the integrated result.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T00:23:13Z",
          "mergedAt": "2026-07-11T00:31:10Z",
          "additions": 1364,
          "deletions": 14,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 531,
          "url": "https://github.com/kungfu-systems/kungfu/pull/531",
          "title": "docs(architecture): define layer-complete products",
          "body": "Merge feature/layer-complete-domain-horizons into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:11:22Z",
          "mergedAt": "2026-07-11T01:11:28Z",
          "additions": 548,
          "deletions": 9,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1087,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1087",
          "title": "feat(workflow): add automatic channel router",
          "body": "## Summary\n\n- add a generated public `build.yml` router that selects `vN-alpha` for development/prerelease intent and `vN` for stable release intent\n- preserve `.build.yml` as the advanced surface and support explicit channel or trusted runtime overrides\n- self-dogfood both automatic alpha and explicit stable lanes with separate contract locks\n- record the v2.12 minor decision and Stage 6 canary evidence\n\n## Validation\n\n- `pnpm run check` (520 tests passed)\n- train self-dogfood run 29134325376 passed both alpha and stable lanes\n- stable contract lock refreshed to reviewed `v2@618512fd874cc0125cc8a3daa07ef4d1b195777e` after run 29134106772 correctly failed closed\n\n## Release plan\n\nMerge into `dev/v2/v2.12`, then promote the existing dev-to-alpha PR to publish `2.12.0-alpha.0` and move `v2-alpha` / `v2.12-alpha` without changing stable `v2`.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:21:25Z",
          "mergedAt": "2026-07-11T01:23:32Z",
          "additions": 1502,
          "deletions": 172,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1084,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1084",
          "title": "chore(release): promote v2.12 alpha",
          "body": "Buildchain release line bootstrap opened v2.12. Merge this channel PR to publish the first alpha for the new minor line.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T00:43:53Z",
          "mergedAt": "2026-07-11T01:25:16Z",
          "additions": 1579,
          "deletions": 242,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1089,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1089",
          "title": "fix(action): refresh promotion bundle",
          "body": "## Summary\n\n- commit the current deterministic `promote-buildchain-ref` action bundle\n- prevent release verification from detecting a generated-file drift outside version state\n\n## Evidence\n\n- two consecutive action builds produced SHA256 `7fca06fb001b5bcb575c4dc7053551a18e086556e6ecb2ab3700ca183431c122`\n- `pnpm run check` passed with 520 tests and left only this intended generated bundle diff\n- promotion run 29134620285 reached publish source locking, then failed closed on the stale bundle\n\nFixes #1088\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:29:38Z",
          "mergedAt": "2026-07-11T01:31:10Z",
          "additions": 42,
          "deletions": 42,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1090,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1090",
          "title": "chore(release): retry v2.12 alpha",
          "body": "## Summary\n\nRetry the `v2.12` alpha promotion after refreshing the deterministic `promote-buildchain-ref` bundle in #1089.\n\n## Evidence\n\n- initial promotion run 29134620285 failed closed before version-state or npm publication\n- #1089 fixes the only detected out-of-version-state generated diff\n- full verification passed with 520 tests and a clean regenerated bundle\n\n## Expected release\n\nPublish `2.12.0-alpha.0`, move `v2.12-alpha` and generic `v2-alpha`, and leave stable `v2` unchanged.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:31:49Z",
          "mergedAt": "2026-07-11T01:33:38Z",
          "additions": 42,
          "deletions": 42,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 532,
          "url": "https://github.com/kungfu-systems/kungfu/pull/532",
          "title": "docs: add choose-your-kungfu adoption guide",
          "body": "Merge feature/choose-your-kungfu-guide into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:46:28Z",
          "mergedAt": "2026-07-11T01:46:34Z",
          "additions": 151,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 533,
          "url": "https://github.com/kungfu-systems/kungfu/pull/533",
          "title": "feat(qualification): add ADR-0049 layer harness",
          "body": "## Summary\n- add the machine-readable ADR-0049 artifact matrix and five-state schema\n- add source-bound dependency and onboarding budget baselines\n- prove the CLI/TUI workspace closure survives GUI removal\n- wire the harness and positive/negative tests into the Shifu check gate\n\n## Validation\n- ./shifu layers:qualify -- --report /tmp/kungfu-layer-qualification-final.json\n- ./shifu check:staged\n- ./shifu check reaches the pre-existing run-freeze.js platform/arch type baseline after all new gates pass",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:53:03Z",
          "mergedAt": "2026-07-11T01:53:07Z",
          "additions": 786,
          "deletions": 0,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 534,
          "url": "https://github.com/kungfu-systems/kungfu/pull/534",
          "title": "feat(atlas): seal each import batch as one Episode",
          "body": "## Summary\n\nOne `kungfu atlas import` batch now becomes one sealed Episode: `episode_begin` wraps ImportBegin, every snapshot frame receipt is attached through `episode_attach_frame`, payload identities are claimed with content-addressed refs after the mirror publishes the bytes, and ImportEnd seals the Episode. Failures abort the Episode with the error summary. This brings the atlas import batch into the Episode boundary, so `storage fsck --scope episode --verify-frames` covers atlas frames and the qualification contract (replay/depend_on) applies automatically.\n\n- The import manifest, import result, and `storage status` name the sealing `episode_id`; the Episode source field carries `atlas:<import_id>` for the reverse index.\n- `storage fsck` grows an explicit `--verify-frames` flag (episode scope only).\n- No heartbeats: an import batch is a short-lived single-writer burst (~3s against a real control-plane repo); begin/attach/end already carry its progress evidence.\n- The atlas-demo-import fixture asserts one sealed Episode per batch, full frame/ref coverage, a green verify_frames fsck, and — destructively, last — that deleting the import event journal fails the sealed Episode with `episode_attached_frame_missing` instead of passing silently.\n\n## Verify-gate repairs\n\n`verify --full` had not run since the schema-surface retirement and exposed three latent regressions, fixed here so the gate passes end to end:\n\n- `fix(examples)`: the cpp probe could no longer compile against the public schema headers (missing fmt/nlohmann/spdlog/hana wiring, C++17 pin).\n- `fix(slices)`: the fact-ledger recorder probe still compared the retired `msg_type` field and hardcoded integrity version 1.\n- `fix(tests)`: the stub-only rewind fixtures died on the new native content-hash dispatch; their stub now answers the sha256 default only.\n\n## Validation\n\n- `./shifu verify --full`: 71/71 passed.\n- Real control-plane repo smoke: import 3.1s, one sealed Episode, 1568 frames attached, 1566 payload refs, `fsck --verify-frames` green in 0.15s, qualification reports all capabilities safe.\n- Fixture negative case proves the fsck blind spot is closed (manifest present + journal page lost -> failed, `episode_attached_frame_missing`).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:53:28Z",
          "mergedAt": "2026-07-11T01:54:24Z",
          "additions": 331,
          "deletions": 75,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 535,
          "url": "https://github.com/kungfu-systems/kungfu/pull/535",
          "title": "shifu: self-update provenance, generations, and checkout-free upgrade",
          "body": "Once a binary was replaced you could not tell what you were running, could not get back, and going forward required a source checkout. Now: build.rs bakes a build channel (release CI assets vs local source builds) that --version prints; every replacement archives the outgoing binary into a generations ledger (--list to inspect, --rollback to restore reversibly, KUNGFU_SHIFU_GENERATIONS_KEEP deep); and outside a checkout self-update takes the newest local build slot the shim produced — the binary that drove the last build, surviving its worktree — announcing its identity before the swap. Verified end to end with two distinguishable binaries: slot upgrade, ledger, double rollback, retention.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:56:47Z",
          "mergedAt": "2026-07-11T01:56:55Z",
          "additions": 364,
          "deletions": 39,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 537,
          "url": "https://github.com/kungfu-systems/kungfu/pull/537",
          "title": "feat(query): add proof-carrying episode authority scan",
          "body": "## Summary\n- add typed ADR-0048 Q0 query basis, cut, result schema, and lineage contracts\n- implement deterministic Episode authority scans for head and exact historical manifest cuts\n- expose thin Python and Node service probes with reproducibility and missing-cut coverage\n\n## Validation\n- ./shifu build:core\n- Python storage suite: 28 passed\n- ./shifu foreach test:storage-binding: 5 passed\n- staged quality gate passed\n\n## Known baseline\n- ./shifu check reaches the unchanged run-freeze.js TypeScript platform-key baseline and exits 1",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:58:12Z",
          "mergedAt": "2026-07-11T01:58:18Z",
          "additions": 629,
          "deletions": 0,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 538,
          "url": "https://github.com/kungfu-systems/kungfu/pull/538",
          "title": "docs: reorder adoption guides for new users",
          "body": "Merge feature/human-first-doc-order into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:01:00Z",
          "mergedAt": "2026-07-11T02:01:08Z",
          "additions": 178,
          "deletions": 141,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 539,
          "url": "https://github.com/kungfu-systems/kungfu/pull/539",
          "title": "docs: normalize README link labels",
          "body": "Merge feature/readme-link-labels into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:10:09Z",
          "mergedAt": "2026-07-11T02:10:16Z",
          "additions": 27,
          "deletions": 27,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 536,
          "url": "https://github.com/kungfu-systems/kungfu/pull/536",
          "title": "feat(core): assembled runtime becomes the macOS product form (ADR-0046 stage 2)",
          "body": "ADR-0046 stage 2, macOS leg — the freezer config default is now platform-conditional (assemble on macOS, nuitka elsewhere), the conan chain stops threading the retired freezer option, and both product gates (dist.mjs, verify) assert the assembled tree is well-formed.\n\nEvidence on macOS arm64:\n- verify --full passes 71/71 on the assembled form (probes, slices, fixtures, episode qualification, ASan/UBSan replay).\n- Product chain green end to end: CLI archive (interpreter tree + wheels inside, installed-layout smoke) and desktop app (assembled tree with symlinks intact under Resources, single-runtime audit, zip+dmg).\n- Startup parity: assembled kungfu --version 0.17-0.19s vs frozen 0.19s baseline; native env subtree at ms-class.\n- Tree ships 56M pruned (68M full); total dist 209M, net flat against the frozen form.\n\nAlso lands, each in its own commit:\n- ADR-0048: the stdlib pruning policy record stage 2 calls for, plus the freeze retirement ledger in docs/buildchain.md.\n- Drift fixes the full gate surfaced: the cpp probe closes over the core's public header surface (fmt/spdlog/nlohmann/hana, C++23), the fact-ledger slice follows carrier_type/integrity-v2, the binding-less rewind fixtures stub kungfu.content_hash.\n- The product chain builds the pykungfu wheel on every build and hard-fails a wheel-less dist (the first assembled product build shipped without the install surface and only warned).\n\nLinux/Windows keep the frozen path until their platform legs land.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:57:50Z",
          "mergedAt": "2026-07-11T02:12:19Z",
          "additions": 232,
          "deletions": 16,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 77,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/77",
          "title": "fix(release): restore stable canary identity",
          "body": "## Summary\n\n- restore the stable canary workflow identity required by Buildchain release policy\n- keep the canary workflow shell on `v2-alpha` and require an exact alpha tag or SHA\n- align the repository agent entrypoint with the stable-release purpose\n\n## Validation\n\n- `npm run build`\n- `npm run check`\n- exact Buildchain candidate `e2d11404d4d5421db37b2c3e110462a2fea38861` completed no-apply canary run 29135808431 before the identity correction\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:12:24Z",
          "mergedAt": "2026-07-11T02:20:31Z",
          "additions": 5,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 541,
          "url": "https://github.com/kungfu-systems/kungfu/pull/541",
          "title": "feat(core): qualify native storage closure",
          "body": "## Summary\n\n- add a versioned, single-thread-affine native storage C ABI restricted to the five ADR-0049 closure operations\n- delegate all semantics to the existing libkungfu runtime storage service\n- add a native-only .kungfu lifecycle fixture covering Episode seal, reopen, head/historical query, fsck, and export\n- promote the libkungfu qualification row to passing and run the proof in the existing three-platform native workflow\n\n## Validation\n\n- `cmake --build framework/core/build --config Release --parallel 4 --target native_storage_closure_host`\n- `node framework/core/slices/native-storage-closure/run.mjs framework/core/build`\n- `./shifu layers:qualify`\n- C11 header syntax check\n- `actionlint .github/workflows/embedding-membrane-spike.yml`\n- staged repository gate passed during commit\n\n## Boundary\n\nThe ABI transports UTF-8 JSON edge projections only. It does not duplicate storage, query, fsck, or export semantics and explicitly rejects every storage operation outside the demonstrated v1 closure.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:29:54Z",
          "mergedAt": "2026-07-11T02:40:24Z",
          "additions": 609,
          "deletions": 4,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 542,
          "url": "https://github.com/kungfu-systems/kungfu/pull/542",
          "title": "docs(architecture): connect KFD facts to runtime admission",
          "body": "## Summary\n\n- add ADR-0051 for KFD contract-world declarations, replayable fact admission, historical interpretation, and KFD-2 trust assessment\n- document how domain facts enter Kungfu without equating durable capture with external truth\n- extend the runtime-query and KFD SDK designs with declaration-root and admission semantics\n\n## Validation\n\n- ./shifu check\n- ./shifu check:staged\n- Markdown local-link scan (214 links checked)",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:41:15Z",
          "mergedAt": "2026-07-11T02:41:21Z",
          "additions": 363,
          "deletions": 8,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 543,
          "url": "https://github.com/kungfu-systems/kungfu/pull/543",
          "title": "feat(query): add canonical planner and agent CLI",
          "body": "Merge feature/adr0048-q1-planner-cli into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:49:19Z",
          "mergedAt": "2026-07-11T02:49:25Z",
          "additions": 1789,
          "deletions": 42,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1092,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1092",
          "title": "fix(runtime): harden consumer checkout integrity",
          "body": "## Summary\n\n- preserve and validate authoritative published contract digests before writing consumer locks\n- bootstrap self-hosted Buildchain runtime checkouts through the existing mirror/cache and bounded GitHub fallback path\n- upload exact-SHA runtime checkout diagnostics independently from lifecycle results\n\n## Validation\n\n- targeted contract, checkout, and workflow tests: 88 passed\n- pnpm run check: 523 passed\n- workflow lint, generated site bundle, action bundles, and git diff checks passed\n- downstream constrained-network canary will use train/v2/v2.3/release-blockers-alpha1 before merge\n\nCloses #1066\nCloses #1078",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:58:31Z",
          "mergedAt": "2026-07-11T03:10:28Z",
          "additions": 231,
          "deletions": 41,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 545,
          "url": "https://github.com/kungfu-systems/kungfu/pull/545",
          "title": "docs(architecture): define KFD-2 assessment execution",
          "body": "## Summary\n\n- add ADR-0052 for claim-triggered KFD-2 assessment jobs and workspace-master coordination\n- define Assessment Episodes, single-writer assessor journals, and durable retry/idempotency\n- keep one semantic contract across Desktop process and embedded thread executors\n- document progressive disclosure from status and TrustReport to proof and replay\n\n## Validation\n\n- ./shifu check:staged\n- 233 Markdown links checked with none missing\n- ./shifu check reached the unchanged run-freeze.js platform-key TypeScript baseline failure",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:11:48Z",
          "mergedAt": "2026-07-11T03:11:53Z",
          "additions": 428,
          "deletions": 1,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1093,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1093",
          "title": "chore(release): promote v2.12.0-alpha.1",
          "body": "## Summary\n\nPromote the verified `dev/v2/v2.12` candidate containing fixes for #1066 and #1078 to the alpha channel.\n\n## Evidence\n\n- Buildchain full check: 523/523\n- PR #1092 protected checks: green\n- Live Kungfu consumer canary: exact runtime checkout succeeded on macOS ARM64, Linux x64, and Windows x64\n- Runtime checkout diagnostics matched source commit `74b383e44987d2f11422514ec9d32ed6e62136b8` on all three platforms\n\n## Release intent\n\nPublish and verify `v2.12.0-alpha.1`; do not promote stable `v2.12.0` in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:11:31Z",
          "mergedAt": "2026-07-11T03:13:21Z",
          "additions": 231,
          "deletions": 41,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 544,
          "url": "https://github.com/kungfu-systems/kungfu/pull/544",
          "title": "feat(shifu): register builds from KFD-declared artifacts",
          "body": "Merge feature/shifu-kfd-registrar into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:07:26Z",
          "mergedAt": "2026-07-11T03:17:53Z",
          "additions": 1187,
          "deletions": 214,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 546,
          "url": "https://github.com/kungfu-systems/kungfu/pull/546",
          "title": "feat(core): qualify ecosystem storage SDKs",
          "body": "## Summary\n\n- add thin Python, Node, and Rust storage SDK artifacts over the versioned libkungfu contract\n- drive all three clean-environment installations through one seven-step semantic fixture\n- bind package provenance to the native header and fixture hashes, with artifact budgets and sibling-runtime deletion checks\n\n## Validation\n\n- `./shifu build:core`\n- `./shifu pack:sdk`\n- `./shifu layers:qualify:sdk -- --report /tmp/kungfu-sdk-qualification.json`\n- `./shifu layers:qualify -- --report /tmp/kungfu-layers-q2.json`\n- staged Python, JS/JSON, Rust formatting/lint and Cargo Clippy\n\n## Boundaries\n\nPackage publication, Linux/Windows exact-artifact evidence, and cross-platform peak-RSS remain staged and are not claimed by this PR. The repository-wide `./shifu check` still reaches the pre-existing `framework/core/.gyp/run-freeze.js` platform/architecture index typing baseline after all changed-scope gates pass.\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider billing, quota, or usage-attribution change\n- [x] No hosted-service deployment\n- [x] Adds staged package identities without publishing them\n- [x] Release evidence is exact-artifact and source-commit bound",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:29:35Z",
          "mergedAt": "2026-07-11T03:30:44Z",
          "additions": 1643,
          "deletions": 14,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1095,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1095",
          "title": "fix(runtime): decouple checkout bootstrap from channel",
          "body": "## Summary\n\n- resolve and pin the reusable workflow shell commit independently from the selected runtime\n- carry the workflow shell checkout bootstrap into native/container jobs\n- use that bootstrap for both runtime and consumer source checkout\n- preserve compatibility when `@vN-alpha` routes a stable release to an older `vN` runtime\n\n## Regression\n\n- full `pnpm run check` passes\n- workflow surface test proves no source checkout invokes the selected runtime copy\n- live train canary will run the new workflow shell with `buildchain-ref: v2` to exercise the older stable runtime\n\nCloses #1094",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:25:32Z",
          "mergedAt": "2026-07-11T03:31:27Z",
          "additions": 53,
          "deletions": 25,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 547,
          "url": "https://github.com/kungfu-systems/kungfu/pull/547",
          "title": "feat(query): bind declaration admission proof",
          "body": "ADR-0048 Q1 S2: bind explicit KFD-1 declaration coordinates and typed admission outcomes into QueryDefinition, LogicalPlan, and proof lineage; fail closed on unregistered, incompatible, ambiguous, or unverifiable declarations.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:31:26Z",
          "mergedAt": "2026-07-11T03:31:32Z",
          "additions": 424,
          "deletions": 65,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1096,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1096",
          "title": "chore(release): promote v2.12.0-alpha.2",
          "body": "## Summary\n\nPromote the corrected v2.12 candidate after `v2.12.0-alpha.1` self-dogfood exposed and #1094 fixed the stable-route bootstrap compatibility gap.\n\n## Evidence\n\n- full Buildchain check: 523/523\n- protected PR #1095 checks: macOS, Windows, Linux container, Verify all green\n- live train alpha/stable self-dogfood: https://github.com/kungfu-systems/buildchain/actions/runs/29138083017\n- stable route used current `v2` runtime and completed runtime checkout, locked source checkout, install, build, verify, and floating-ref SHA verification\n\n## Release intent\n\nPublish and verify `v2.12.0-alpha.2`; keep stable `v2.12.0` pending the new candidate canary and soak.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:32:02Z",
          "mergedAt": "2026-07-11T03:33:52Z",
          "additions": 53,
          "deletions": 25,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1098,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1098",
          "title": "fix(release): retry visible-parent state updates",
          "body": "## Summary\n\n- retry a durable release-state `updateRef` when GitHub returns non-fast-forward while still reporting the expected parent\n- keep retries bounded and non-forced\n- cover the exact ref-propagation signal seen during the alpha.2 promotion attempt\n- rebuild the promoted action bundle\n\n## Evidence\n\n- targeted durable-state race tests pass\n- full `pnpm run check` passes\n- failure evidence: https://github.com/kungfu-systems/buildchain/actions/runs/29138244936\n\nCloses #1097",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:46:44Z",
          "mergedAt": "2026-07-11T03:48:38Z",
          "additions": 85,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1099,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1099",
          "title": "chore(release): retry v2.12 alpha after state fix",
          "body": "## Summary\n\nRetry the v2.12 alpha promotion with the bounded durable release-state ref propagation fix from #1098.\n\nThe prior alpha.2 attempt created no tag, release, npm version, or floating-ref movement; it stopped while persisting the transaction state. The publisher must preserve that failed immutable transaction and choose the next safe alpha identity if required.\n\n## Evidence\n\n- exact online failure signal is covered by regression\n- full Buildchain check passes\n- protected PR #1098 checks pass\n- alpha/stable checkout compatibility dogfood remains green: https://github.com/kungfu-systems/buildchain/actions/runs/29138083017",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:48:58Z",
          "mergedAt": "2026-07-11T03:51:04Z",
          "additions": 85,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 548,
          "url": "https://github.com/kungfu-systems/kungfu/pull/548",
          "title": "feat(product): qualify headless and GUI layer closures",
          "body": "Summary: expose the existing storage service through public API, KFX, and GUI capability surfaces; qualify CLI and GUI against one semantic fixture; bind both distributions to an exact compatibility manifest and clean source commit; prove GUI deletion leaves lower data byte-identical and healthy. Validation: shifu build, dist --dir, exact surface qualifier, generic layer qualifier, SDK fixture, and 7 product tests pass. Full shifu check passes the new gates and stops only on the pre-existing framework/core/.gyp/run-freeze.js platform and architecture TypeScript errors. Boundary: exact local macOS arm64 artifacts pass; installer-specific uninstall, publication, other platforms, and resident-memory budgets remain separate release claims.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T04:03:44Z",
          "mergedAt": "2026-07-11T04:05:08Z",
          "additions": 953,
          "deletions": 6,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 549,
          "url": "https://github.com/kungfu-systems/kungfu/pull/549",
          "title": "refactor(storage): establish typed service boundary",
          "body": "## Summary\n\n- establish Hana-owned POD storage records and typed C++ service requests/results\n- keep FlatBuffers ownership for KFX/business payloads, including the ActionEnvelope vertical slice\n- expose Python and Node projections through recursive Hana bindings; confine JSON to explicit edge adapters\n- reuse typed journal folds and sqlite_orm projections for Source, Manifest, Entry, Episode, repair, fsck, export/import, and layout operations\n- enforce single schema ownership, no JSON core service semantics, and exclusive projection routing\n\nThis is the linear-history replacement for #522; its tree is byte-for-byte identical to the Mac-verified head of that PR.\n\n## Mac verification\n\n- `./shifu build:core`\n- targeted Python storage/action/query tests: 57/57\n- native Node storage/action tests: 7/7\n- `./shifu check:types`\n- `./shifu check`\n- schema authority negative fixtures: 5/5\n\nCI is currently unavailable; merge approval is based on the completed Mac build and test evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T04:17:33Z",
          "mergedAt": "2026-07-11T04:17:52Z",
          "additions": 12357,
          "deletions": 2890,
          "changedFiles": 84
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1100,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1100",
          "title": "fix(release): preflight candidate evidence before promotion",
          "body": "## Summary\n\n- add a metadata-only PR-stage release-candidate evidence job after serialized intent revalidation\n- block the full promotion job before candidate dependency installation when channel PR, workflow run, passport pair, or payload metadata is missing or stale\n- retain the complete evidence download and validation in the publication job at the existing trust boundary\n- keep expected manual dry-run failures visible without creating automated workflow-friction issues\n- document the early-failure contract and publish it through the generated site facts\n\n## Validation\n\n- `pnpm run check` (525/525 unit tests, workflow lint, site bundle check, all action bundles)\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org/`\n- live metadata-only resolver smoke: valid alpha promotion SHA passed without an output directory\n- historical #1085/#1086 SHA failed before payload download or candidate dependency installation\n- real GitHub workflow dry-run proved the new preflight job completes before the full promotion job\n- `git diff --check`\n\nCloses #1085\nCloses #1086\nCloses #1101",
          "author": "dongkeren",
          "createdAt": "2026-07-11T04:40:49Z",
          "mergedAt": "2026-07-11T04:46:30Z",
          "additions": 99,
          "deletions": 20,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 551,
          "url": "https://github.com/kungfu-systems/kungfu/pull/551",
          "title": "feat(query): add SQLite SQL conformance",
          "body": "Linear replacement for #550 after the repository rejected merge commits during rebase-only integration. Same validated tree as #550.\\n\\nValidation:\\n- ./shifu build\\n- 95 Python tests passed\\n- staged gates passed\\n\\nNode binding suite discovered 7 tests but skipped all because the expected dist binding path was unavailable.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T04:52:37Z",
          "mergedAt": "2026-07-11T04:53:12Z",
          "additions": 831,
          "deletions": 87,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 553,
          "url": "https://github.com/kungfu-systems/kungfu/pull/553",
          "title": "fix(core): qualify action envelope schema type",
          "body": "## Summary\n- fully qualify the `schema_ref` type used by `action::envelope`\n- preserve the existing public member name and serialized contract\n\n## Evidence\n- fixes the GCC error: declaration of `envelope::schema_ref` changes meaning of `schema_ref`\n- Apple Clang C++23 syntax probe passes\n- one-line source change with DCO sign-off",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:03:25Z",
          "mergedAt": "2026-07-11T05:04:40Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 556,
          "url": "https://github.com/kungfu-systems/kungfu/pull/556",
          "title": "fix(core): pin native closure query basis",
          "body": "## Summary\n- make the native storage C consumer send explicit contract-world and fact-surface declaration references\n- intentionally pin the current built-in roots so declaration drift fails closed\n\n## Evidence\n- reproduces the latest planner requirement for explicit declarations\n- `native_storage_closure_host` builds and its complete lifecycle/query/fsck/export harness passes locally\n- no C ABI or storage implementation change",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:28:32Z",
          "mergedAt": "2026-07-11T05:38:55Z",
          "additions": 10,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 557,
          "url": "https://github.com/kungfu-systems/kungfu/pull/557",
          "title": "feat(storage): episode bundles carry owned bytes and import materializes them",
          "body": "Merge feature/episode-bundle-self-contained into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:40:49Z",
          "mergedAt": "2026-07-11T05:40:55Z",
          "additions": 1286,
          "deletions": 44,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1102,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1102",
          "title": "chore(release): promote v2.12.0-alpha.4",
          "body": "## Summary\n\n- promote the current v2.12 development head after PR #1100\n- publish the next immutable v2.12 alpha candidate\n- advance v2.12-alpha and v2-alpha after the release transaction completes\n- start fresh exact-candidate stable canary and soak evidence\n\n## Candidate\n\n- source: `dev/v2/v2.12`\n- source SHA: `87055553ae85ac7facc683c62de3945a831828c5`\n- expected version: `v2.12.0-alpha.4`\n- included fixes: #1085, #1086, #1101 via #1100\n\n## Validation\n\n- PR #1100 protected checks passed on macOS, Windows, and Linux\n- Buildchain full check passed: 525/525 plus workflow lint, generated site, and action bundles\n- repository currently has no open issues",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:40:16Z",
          "mergedAt": "2026-07-11T05:43:10Z",
          "additions": 99,
          "deletions": 20,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 558,
          "url": "https://github.com/kungfu-systems/kungfu/pull/558",
          "title": "feat(core): assembled runtime becomes the Linux product default (ADR-0046 stage 2)",
          "body": "ADR-0046 stage 2, Linux leg — the platform default flips (only Windows keeps nuitka now) and the prune manifest gains its linux section, grounded on the real cpython-3.13.14-linux-x86_64-gnu prefix. share/terminfo deliberately stays (curses/readline may consult it at runtime; ADR-0050 semantic-disjoint bar).\n\nGrounding caught a real key bug: both pbs-key sites (run-freeze pbsKey, the trunk's python_request) hardcoded the -none libc segment, which only exists for macOS/Windows — on Linux the request must end in -gnu or uv refuses it by name. Both mappings now derive the libc field per platform.\n\nEvidence on linux-x64 (agent-120):\n- verify --full 73/73 green on the assembled form (probes, slices, fixtures, episode qualification, ASan/UBSan replay) at the pre-drift base; post-rebase revalidation on the touched surfaces (mypy repo-green, closure slice green).\n- Product chain green: CLI archive kungfu-episodes-cli-linux-x64.tar.gz with interpreter tree + wheel inside, installed-layout smoke passed.\n- Startup 0.11-0.12s; tree 93M pruned (104M full); import tkinter and python -m pip both refused in the shipped tree.\n\nAlso lands, each in its own commit: the query CLI mypy gate fix (typed runtime_dir access + NoReturn on _fail, extended over the new engine call site), the action-envelope encoding lookup type narrowing, and the closure slice declaring the explicit basis ADR-0048 now requires (pinned built-in declarations — drift without a version bump fails the slice by design).\n\nNote: dev-tip verify --full currently carries 5 unrelated failures on linux from the storage/qualification lines (deterministic, reproduce with the dev-tip python tree, untouched by this diff); recorded for their owning lines.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:42:05Z",
          "mergedAt": "2026-07-11T05:44:07Z",
          "additions": 46,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 561,
          "url": "https://github.com/kungfu-systems/kungfu/pull/561",
          "title": "feat(core): add libwasm shared embedding membrane spike",
          "body": "## Summary\n\n- add a bounded Rust-host libwasm spike behind the existing versioned `kf_embedding_api_v1` capability membrane\n- run one shared core-Wasm guest through Wasmtime 46.0.1 and measured Wasmer 7.2.0 fallback adapters, each isolated behind two C ABI symbols\n- prove batch journal access, explicit release, trap/panic containment, copy accounting, latency/throughput/idle budgets, and no per-frame FFI\n- extend the hosted macOS ARM64 / Linux x64 / Windows x64 membrane matrix without changing KFX manifest/contract or advancing ADR-0046 Stage 3\n\n## Validation\n\n- `./shifu check`\n- `actionlint .github/workflows/embedding-membrane-spike.yml`\n- CMake Release build of shared embedding, native storage closure, and libwasm targets\n- all three local harnesses PASS on macOS ARM64\n- prior three-platform evidence run: 29138796710\n\n## Delivery note\n\nSupersedes #540 for merge delivery only. GitHub correctly refused rebase merge of #540 because its branch accumulated merge commits while tracking a moving dev branch. This PR replays the same 13 task commits onto current `dev/v4/v4.0` with no merge commits, preserving #540 as the full implementation and CI audit trail.\n\n## Open production gates\n\nWasmer CPU metering, WIT/Component ABI decisions, admission/receipts, and production compatibility remain explicitly out of scope.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:52:34Z",
          "mergedAt": "2026-07-11T05:52:59Z",
          "additions": 4646,
          "deletions": 18,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 560,
          "url": "https://github.com/kungfu-systems/kungfu/pull/560",
          "title": "fix(storage): harden Hana SQLite projections",
          "body": "## Summary\n\n- preserve enum, fixed-array, and vector BLOB roundtrips through sqlite_orm\n- rebuild Source, Manifest, and Episode projections atomically on one SQLite connection\n- derive primary-key normalization and canonical content digests from Hana schema metadata\n- keep verification read-only and detect same-row-count corruption, including append-only export subset integrity\n- batch replay through sqlite_orm replace_range\n\n## Mac validation\n\n- `./shifu check`\n- `./shifu verify --full` — 69/74; remaining failures are existing Episode contention / Atlas demo / rewind capture baselines\n- targeted storage regression suite — 51 passed\n- `storage-demo-node-binding` fixture passed\n- Hana SQLite capability slice passed\n- ASan/UBSan view replay passed\n\nCI is not used as the merge gate for this change.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:52:27Z",
          "mergedAt": "2026-07-11T05:54:52Z",
          "additions": 873,
          "deletions": 299,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 559,
          "url": "https://github.com/kungfu-systems/kungfu/pull/559",
          "title": "feat(core): admit domain facts",
          "body": "## Summary\n- add ADR-0051 domain-fact authority with effective-time declaration history\n- implement five admission outcomes plus correction, retraction, and conflict handling\n- expose the shared C++ contract through Python, Node, Rust, CLI, and KFD evidence\n- retain the current ActionEnvelope, typed-storage, SQLite query, native closure, and self-contained Episode bundle mainline\n\n## Verification\n- Conan Node + Python core build\n- 66 Python tests (storage, query, action envelope, Episode bundle)\n- 8 Node binding tests\n- native storage closure harness\n- kungfu-sdk Rust tests\n- `./shifu check`\n\n## Known boundary\n- source validation is complete; frozen product artifact qualification remains the release pipeline responsibility.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:51:48Z",
          "mergedAt": "2026-07-11T06:11:25Z",
          "additions": 2450,
          "deletions": 50,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 562,
          "url": "https://github.com/kungfu-systems/kungfu/pull/562",
          "title": "feat(query): add resumable changelog views",
          "body": "## Summary\\n- add a native typed kungfu.query.changelog/v1 stream with integrity-checked resume tokens and reproducible authority cuts\\n- expose changelog paging through storage, Python CLI, TypeScript/KFX contracts, and saved-view JSON\\n- add System Status table, timeline, diff, and causal-graph reference views with visible evidence and Gap handling\\n- document the Q3 contract and extend native, Python, CLI, and TypeScript coverage\\n\\n## Correctness properties\\n- resume tokens pin the query definition, logical plan, authority frontiers, result hashes, batch, and next message index\\n- opaque frame UIDs locate exact cuts; authority record counts establish monotonic advancement\\n- replay is deterministic and idempotent, with bounded paging and explicit Gap on unreproducible state\\n- GUI state is reconstructed from the native changelog; saved views persist only QueryDefinition and ViewSpec\\n\\n## Validation\\n- ./shifu check\\n- ./shifu --filter @kungfu-tech/core compile\\n- targeted native/Python storage tests\\n- query CLI tests\\n- TypeScript query tests\\n- API and KFX tsc --noEmit\\n- System Status KFX bundle build\\n\\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-11T06:12:38Z",
          "mergedAt": "2026-07-11T06:17:45Z",
          "additions": 1887,
          "deletions": 34,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 563,
          "url": "https://github.com/kungfu-systems/kungfu/pull/563",
          "title": "test(core): stabilize libwasm copy evidence",
          "body": "## Summary\n\n- average eight consecutive 1 MiB guest copies inside each throughput observation\n- keep the existing 1 GiB/s gate and outer three-trial median unchanged\n- account for every measured host-to-guest byte and document the sampling boundary\n\n## Why\n\nPR #561 merged the libwasm spike before its late-attached embedding matrix completed. The macOS job then exposed that one isolated 1 MiB timing sample could be dominated by runner scheduling: Wasmer measured 1.63 GB/s once and about 0.70 GB/s twice. This patch measures sustained copy throughput instead of a single scheduling interval; it does not lower any acceptance budget.\n\n## Validation\n\n- `./shifu check`\n- incremental Release adapter/host build\n- local macOS ARM64 libwasm harness PASS with exact byte accounting\n\nFollow-up to #561; supersedes the unmerged fix commit on its now-closed delivery branch.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T06:20:27Z",
          "mergedAt": "2026-07-11T06:48:39Z",
          "additions": 22,
          "deletions": 7,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1091,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1091",
          "title": "chore(release): promote v2.12.0",
          "body": "## Summary\n\n- promote the tested v2.12.0-alpha.4 lineage to the protected stable channel\n- publish @kungfu-tech/buildchain@2.12.0\n- advance the stable v2.12 and v2 floating refs after transaction finalization\n\n## Included changes\n\n- add the automatic alpha/stable consumer channel router\n- add generic vN-alpha floating tags and self-dogfood coverage\n- consolidate release evidence and harden promotion serialization/canonicalization\n- restore the authoritative site-libkungfu-dev stable canary identity\n- include the completed issue fixes through #1100\n\n## Validation\n\n- candidate v2.12.0-alpha.4 is published from f8b67b1728f6719b4873d9c6e954e5d8c3ece2c3\n- npm alpha and the v2-alpha / v2.12-alpha floating refs resolve to the exact candidate\n- Build Surface Fixture and Binary Distribution succeeded on the candidate\n- Buildchain self-dogfood succeeded on rerun; the first stable-lane summary attempt hit a transient Node 22 undici assertion during pnpm network I/O\n- exact-SHA site-libkungfu-dev stable canary succeeded with all apply jobs skipped: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29141861127\n- authorized canary status was attested by kungfu-origin at 2026-07-11T05:52:09Z\n- earliest stable promotion time after the mandatory one-hour soak: 2026-07-11T06:52:09Z (2026-07-11 14:52:09 Asia/Shanghai)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:17:40Z",
          "mergedAt": "2026-07-11T07:02:00Z",
          "additions": 2038,
          "deletions": 321,
          "changedFiles": 45
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1104,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1104",
          "title": "fix(release): separate stable candidate version",
          "body": "## Summary\n\n- keep the release-candidate passport artifact version for payload validation and publication\n- resolve the Buildchain release-line alpha independently from the checked-out channel manifest\n- feed the exact Buildchain alpha version into the stable canary/soak gate\n- fail before publication when the checked-out release line does not declare an exact alpha\n\n## Root cause\n\nThe stable gate consumed `release-candidate-version`, which is the libnode-shaped payload version (`22.22.3-kf.0`) for Buildchain's fixture. The gate instead requires the Buildchain release-line candidate (`2.12.0-alpha.4`). Reusing one field for both meanings caused the stable promotion to fail closed after PR #1091 merged.\n\n## Validation\n\n- `node --test tests/build-surface.test.mjs`\n- `pnpm run check`\n\nFixes #1103\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:08:46Z",
          "mergedAt": "2026-07-11T07:10:31Z",
          "additions": 27,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1106,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1106",
          "title": "fix(release): compare new minor to stable major",
          "body": "## Summary\n\n- keep the 24-hour stable cooldown scoped to preceding patches on the same minor\n- independently select the latest prior stable in the same major as the product-diff baseline\n- allow a first stable on a new minor only when that cross-minor comparison contains declared product or contract paths\n- cover the v2.11.13 to v2.12.0-alpha.0 transition in the collector test\n\n## Root cause\n\nFor `v2.12.0-alpha.4`, there is intentionally no previous stable on minor `2.12`. The collector reused that same-minor cooldown lookup for product-diff comparison, producing an empty path set even though the candidate differs materially from current stable `v2.11.13`.\n\n## Validation\n\n- `node --test tests/stable-release-gate.test.mjs tests/stable-release-gate-cli.test.mjs`\n- live read-only gate evaluation for `v2.12.0-alpha.4`: `allow`, 90 compared paths, required canaries and soak passed\n- `pnpm run check`\n\nFixes #1103\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:17:30Z",
          "mergedAt": "2026-07-11T07:19:22Z",
          "additions": 33,
          "deletions": 10,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1107,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1107",
          "title": "fix(release): carry stable gate fixes into v2.12",
          "body": "## Summary\n- carry the exact Buildchain alpha candidate resolver into the v2.12 release line\n- compare a first stable on a new minor against the preceding stable in the same major\n- preserve same-minor stable cooldown semantics\n\n## Validation\n- `pnpm run check`\n- live stable-gate evaluation for `v2.12.0-alpha.4`\n\nCloses #1105",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:24:08Z",
          "mergedAt": "2026-07-11T07:26:25Z",
          "additions": 60,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1109,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1109",
          "title": "fix(release): bind soak to exact alpha evidence",
          "body": "## Summary\n- reject PR-stage release-candidate runs whose head SHA differs from the exact alpha candidate\n- recover the successful Build Surface run bound to the candidate SHA\n- keep soak time anchored to immutable alpha evidence\n\n## Validation\n- `pnpm run check` (525 tests)\n- live gate evaluation with supplemental PR run `29144431364` resolves exact-alpha run `29141753378` and returns `allow`\n\nCloses #1105\nCloses #1108",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:31:39Z",
          "mergedAt": "2026-07-11T07:33:31Z",
          "additions": 40,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1110,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1110",
          "title": "fix(release): carry exact-alpha soak evidence into v2.12",
          "body": "## Summary\n- carry the exact-alpha release-candidate evidence binding into the v2.12 release transaction\n- prevent supplemental PR builds from resetting an already satisfied alpha soak\n\n## Validation\n- `pnpm run check` (525 tests)\n- live stable gate returns `allow` and resolves run `29141753378`\n\nRelease follow-up for #1109.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:33:43Z",
          "mergedAt": "2026-07-11T07:35:39Z",
          "additions": 40,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1112,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1112",
          "title": "chore(release): promote v2.12.0-alpha.5",
          "body": "## Summary\n- promote the three stable-gate fixes through the alpha channel\n- create an alpha candidate whose tree can be promoted to stable without bypassing source equality\n\n## Validation\n- `pnpm run check` (525 tests)\n- exact-alpha evidence lookup live gate evaluation\n\nCloses #1111",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:39:30Z",
          "mergedAt": "2026-07-11T07:41:18Z",
          "additions": 100,
          "deletions": 22,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 566,
          "url": "https://github.com/kungfu-systems/kungfu/pull/566",
          "title": "refactor(runtime): retire journal Session architecture",
          "body": "## Summary\n- remove the legacy journal Session record, markers, SQLite index, C++ finder/builder, Node SessionStore, Python bindings/module, and session-oriented journal CLI tools\n- replace Master session liveness with registry liveness and derive SDK replay anchors from typed Episode manifests\n- split the mixed runtime/cache bucket into runtime/state_cache and runtime/projection, with an ADR and blocking anti-regression gate\n\n## Mac validation\n- ./shifu build\n- ./shifu check\n- pnpm --filter @kungfu-tech/api run test:query\n\nCI is currently unavailable; per maintainer direction this PR is qualified by the Mac build and tests above.\n\nBreaking pre-release cleanup; no stable-v4 Session compatibility shim is retained.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:44:43Z",
          "mergedAt": "2026-07-11T07:46:08Z",
          "additions": 778,
          "deletions": 1497,
          "changedFiles": 65
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 568,
          "url": "https://github.com/kungfu-systems/kungfu/pull/568",
          "title": "feat(trust): implement ADR-0052 assessment runtime",
          "body": "## Summary\n- add the typed durable KFD-2 assessment lifecycle and dependent Assessment Episodes\n- schedule isolated assessor processes from workspace master with timeout cancellation and retry\n- expose equivalent thread execution plus CLI, GUI, SDK, and native storage edges\n\n## Validation\n- ./shifu check\n- Python storage: 54 passed\n- master service: 11 passed\n- host seam: 9 passed\n- Node native storage binding: 9 passed, 0 skipped\n- GUI production build\n- native storage closure: PASS\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-11T08:03:06Z",
          "mergedAt": "2026-07-11T08:06:25Z",
          "additions": 1998,
          "deletions": 14,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 569,
          "url": "https://github.com/kungfu-systems/kungfu/pull/569",
          "title": "feat(libwasm): ship governed production runtime",
          "body": "Promotes the validated libwasm membrane into the default build, frozen runtime, KFX capability contract, dual-engine qualification, KFD evidence, and release artifact checks. Wasmtime remains primary; Wasmer is metered fallback behind the same C ABI.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T08:15:21Z",
          "mergedAt": "2026-07-11T08:15:27Z",
          "additions": 5307,
          "deletions": 45,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 570,
          "url": "https://github.com/kungfu-systems/kungfu/pull/570",
          "title": "feat(query): add bounded temporal attention patterns",
          "body": "## Summary\n- add one fail-closed temporal pattern family to QueryDefinition and LogicalPlan\n- compile the same algebra from constrained MATCH_RECOGNIZE SQL and expose it through Python CLI, TypeScript/KFX, and an attention reference view\n- prove Buildchain and non-Buildchain fixtures, authority/SQLite conformance, and late terminal RowRetract behavior\n\n## Boundaries\n- ordered two-step subsequence only, repeated 1..16 times within 1ns..30d\n- explicit as_of_time closes optional absence\n- attribution is recorded evidence; no causal relationship is inferred\n- alternation, nesting, unbounded waits, and general CEP remain unsupported\n\n## Validation\n- ./shifu --filter @kungfu-tech/core compile\n- 60 Python core/CLI tests passed\n- @kungfu-tech/api tests and typecheck passed\n- System Status KFX build passed\n- ./shifu check passed",
          "author": "dongkeren",
          "createdAt": "2026-07-11T08:20:41Z",
          "mergedAt": "2026-07-11T08:21:25Z",
          "additions": 1065,
          "deletions": 103,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1114,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1114",
          "title": "fix(release): honor immediate stable authority",
          "body": "## Summary\n- treat an exact `BUILDCHAIN_STABLE_RELEASE_NOW` repository authority as the final human release instruction\n- record the immediate-release reason in workflow evidence\n- keep the default canary/soak gate when no exact authority is present\n\n## Validation\n- `pnpm run check` (525 tests)\n\nThis restores the invariant that soak is a default quality mechanism, not a veto over an explicit stable release instruction.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T08:20:26Z",
          "mergedAt": "2026-07-11T08:22:44Z",
          "additions": 37,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1113,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1113",
          "title": "chore(release): promote v2.12.0",
          "body": "## Summary\n- promote the fully validated `v2.12.0-alpha.5` tree to stable\n- retain exact-alpha Build Surface, binary, dogfood, site canary, and soak evidence\n\n## Candidate\n- tag: `v2.12.0-alpha.5`\n- SHA: `349a81e6ad8f96c18edc9ba9304ef9f3e1c324c8`\n- alpha promotion: `29144940344`\n- binary distribution: `29145005487`\n- self-dogfood: `29145013962`\n\nThe PR will remain unmerged until the exact-SHA site canary and 3600-second soak pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:46:58Z",
          "mergedAt": "2026-07-11T08:23:00Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 571,
          "url": "https://github.com/kungfu-systems/kungfu/pull/571",
          "title": "fix(trust): execute embedded assessments on a real thread",
          "body": "## Summary\n\n- dispatch embedded `thread` assessments on a dedicated joined C++ thread\n- persist placement evidence without changing semantic report identity\n- prove inline/thread report equivalence in the native Node binding suite\n- update ADR-0051/0052 implementation status\n\n## Validation\n\n- `./shifu check`\n- native storage binding suite: 10 passed, 0 failed\n- staged commit gates\n- core compilation reached modified trust objects and bindings; full build is currently blocked in unrelated libwasm Cargo dependency fetches by the office proxy returning 404 for addr2line\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-11T08:36:39Z",
          "mergedAt": "2026-07-11T08:37:23Z",
          "additions": 184,
          "deletions": 70,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 572,
          "url": "https://github.com/kungfu-systems/kungfu/pull/572",
          "title": "refactor(storage): retire legacy journal lifecycle tools",
          "body": "## Summary\n\n- retire the loose-file `kungfu journal` lifecycle command group and its KFA archive/prune helpers\n- remove the non-authoritative Storage `archive_dir` surface and stale runtime path parsers\n- align the journal manager with typed Episode replay anchors and add TypeScript checking\n- correct the duplicate ADR identity (`0054` remains libwasm; Session retirement becomes `0055`) and record lifecycle retirement as `0056`\n- add executable gates for ADR identity uniqueness and the Storage/Episode journal authority boundary\n\n## Validation\n\n- `./shifu fix`\n- `./shifu check`\n- `KF_LIBWASM_CARGO_REGISTRY=sparse+https://rsproxy.cn/index/ ./shifu build`\n- `./shifu --filter @kungfu-tech/core run kungfu --help` (no `journal` command; `storage` and `query` remain)\n- `git diff --check`\n\nCI is currently unavailable; this change is being merged against the completed macOS build and test evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T08:58:23Z",
          "mergedAt": "2026-07-11T08:58:44Z",
          "additions": 243,
          "deletions": 453,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1115,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1115",
          "title": "feat(release): add qualified alpha stable patrol",
          "body": "Merge feature/qualified-alpha-stable-patrol into dev/v2/v2.12 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T09:13:26Z",
          "mergedAt": "2026-07-11T09:15:19Z",
          "additions": 1979,
          "deletions": 122,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1116,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1116",
          "title": "chore(release): promote qualified alpha stable patrol",
          "body": "Promote the merged qualified-alpha candidate ledger and Stable Candidate Patrol to the public v2 alpha channel.\\n\\nEvidence:\\n- PR #1115 merged to dev/v2/v2.12\\n- pnpm run check: 538 tests passed\\n- train dogfood run 29147440568 succeeded\\n- live dry-run reconstructed v2.12.0 history and left v2.12.1-alpha.0 fail-closed without required evidence",
          "author": "dongkeren",
          "createdAt": "2026-07-11T09:16:51Z",
          "mergedAt": "2026-07-11T09:18:40Z",
          "additions": 2014,
          "deletions": 124,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1118,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1118",
          "title": "fix(dogfood): accept current stable contract",
          "body": "## Summary\n\n- refresh the Buildchain self-consumer stable contract lock to the current `v2` runtime\n- keep alpha and stable self-dogfood locks channel-specific\n- restore stable-consumer dogfood without weakening contract compatibility checks\n\n## Validation\n\n- `corepack pnpm@11.7.0 run check`\n- direct contract-lock evaluation against `refs/tags/v2` reports `unchanged`\n\n## Evidence\n\nThe previous self-dogfood run failed only in the stable consumer because the committed stable lock still referenced a pre-v2.12 contract. The alpha consumer succeeded.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T09:31:42Z",
          "mergedAt": "2026-07-11T09:33:52Z",
          "additions": 13,
          "deletions": 8,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1120,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1120",
          "title": "chore(release): promote v2.12 stable dogfood lock",
          "body": "## Release intent\n\nPromote the reviewed stable self-dogfood contract lock fix into the next v2.12 alpha.\n\n## Included\n\n- qualified-alpha stable candidate patrol mechanism from #1115\n- stable contract lock refresh from #1118\n\n## Validation\n\n- full `pnpm run check` passes (538 tests)\n- current `v2` contract-lock evaluation is `unchanged`\n- PR #1118 checks passed and was approved by `kungfu-origin`",
          "author": "dongkeren",
          "createdAt": "2026-07-11T09:34:15Z",
          "mergedAt": "2026-07-11T09:36:11Z",
          "additions": 13,
          "deletions": 8,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 574,
          "url": "https://github.com/kungfu-systems/kungfu/pull/574",
          "title": "feat(query): add workspace saved query catalog",
          "body": "## Summary\n- journal versioned saved-query create, update, delete facts as FlatBuffers ActionEnvelope events sealed into Episodes under the workspace runtime home\n- expose shared catalog lifecycle through native storage, Python CLI, TypeScript/KFX capability, System Status GUI, and agent discovery\n- bind saved query id, revision, and content hash to query runs while keeping portable saved-view JSON as the import/export edge\n\n## Validation\n- ./shifu check\n- Python query CLI: 8 passed\n- native Node storage binding: 11 passed, 0 skipped\n- API typecheck and query tests: 4 passed\n- KFX and Status KFX builds\n- kungfu agent verify: ok, no missing/stale/hidden APIs\n- libkungfu, Python, and Node native targets compile and link\n\n## Environment note\nThe full all-target build remains locally blocked by sequential 404s from the configured LAN Cargo proxy. Exact locked crate checksums were verified; this is tracked separately as dogfood friction and is not a source/query failure.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T09:44:28Z",
          "mergedAt": "2026-07-11T09:46:54Z",
          "additions": 1253,
          "deletions": 53,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 575,
          "url": "https://github.com/kungfu-systems/kungfu/pull/575",
          "title": "ci: accept the v2-alpha buildchain contract in the consumer lock",
          "body": "The v2-alpha switch updated workflow references but left the consumer contract lock pinned to the v2 contract world — the trust gate correctly rejected runs as breaking drift. Regenerate the lock against the current v2-alpha runtime (4cba0848) so accepted surfaces match the consumed channel.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T09:52:37Z",
          "mergedAt": "2026-07-11T09:52:42Z",
          "additions": 14,
          "deletions": 9,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 576,
          "url": "https://github.com/kungfu-systems/kungfu/pull/576",
          "title": "feat(facts): add durable fact library manager",
          "body": "## Summary\n- add a built-in Fact Manager GUI over the shared Storage capability\n- add stable agent CLI/API operations for versioned fact types and materials\n- persist schemas and payloads in the selected Kungfu data root\n- add verified full/thin Fact Library export and append-only import\n- include assessment Episodes and Trust Report material in library transfer\n\n## Validation\n- `./shifu check`\n- 72 Python storage/Episode tests passed\n- targeted libkungfu, Python binding, and Node binding build passed\n- Fact Manager KFX build passed\n- full Electron/Vite GUI production build passed\n- isolated product dry-run passed\n- temporary-home CLI full/thin export, verify, execute import, and payload readback passed\n\n## Known infrastructure issue\nThe repository-wide ALL target still reaches the currently broken LAN Cargo mirror for libwasm crates. This PR does not wait on that CI/infrastructure path; the directly changed runtime and product targets were built and tested locally.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:09:00Z",
          "mergedAt": "2026-07-11T10:14:25Z",
          "additions": 2639,
          "deletions": 56,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 8,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/8",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:27Z",
          "mergedAt": "2026-07-11T10:25:05Z",
          "additions": 135,
          "deletions": 31,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 107,
          "url": "https://github.com/kungfu-systems/kfd/pull/107",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:32Z",
          "mergedAt": "2026-07-11T10:25:13Z",
          "additions": 149,
          "deletions": 31,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 578,
          "url": "https://github.com/kungfu-systems/kungfu/pull/578",
          "title": "refactor(runtime): adopt domain-neutral live terminology",
          "body": "## Summary\n\n- replace internal practice/hero/apprentice/master terminology with live/reactor/peer/coordinator\n- expose peer/coordinator consistently across C++, Python, Node, CLI, GUI/TUI, KFD and current docs\n- preserve historic wire-v1 location identity through explicit compatibility adapters\n- add ADR-0057 and a terminology architecture gate\n\n## Validation\n\n- ./shifu check\n- ./shifu build (Mac, full build)\n- Python runtime/event-loop tests: 20 passed\n- Node storage binding tests: 11 passed\n- assessment process/thread parity: 1 passed\n- pybind and Node binding smoke tests\n- built CLI runtime status/help smoke tests\n\n## Known verifier issue\n\n./shifu verify reaches 29/30; Episode qualification still fails because its probe readback omits safe_capabilities, warnings, status and episode_projection even though journal writing/fsck completes. This is outside the runtime terminology change. Per current project direction, CI is unavailable and this PR is accepted on the Mac build/test evidence above.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:23:37Z",
          "mergedAt": "2026-07-11T10:25:39Z",
          "additions": 1876,
          "deletions": 1495,
          "changedFiles": 93
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 577,
          "url": "https://github.com/kungfu-systems/kungfu/pull/577",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:36Z",
          "mergedAt": "2026-07-11T10:25:52Z",
          "additions": 104,
          "deletions": 9,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 27,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/27",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:45Z",
          "mergedAt": "2026-07-11T10:25:55Z",
          "additions": 108,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 31,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/31",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:48Z",
          "mergedAt": "2026-07-11T10:25:59Z",
          "additions": 108,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 33,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/33",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:53Z",
          "mergedAt": "2026-07-11T10:26:03Z",
          "additions": 127,
          "deletions": 26,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 23,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/23",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:42Z",
          "mergedAt": "2026-07-11T10:26:30Z",
          "additions": 122,
          "deletions": 14,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 80,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/80",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:56Z",
          "mergedAt": "2026-07-11T10:30:20Z",
          "additions": 149,
          "deletions": 26,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 92,
          "url": "https://github.com/kungfu-systems/libnode/pull/92",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:40Z",
          "mergedAt": "2026-07-11T11:32:03Z",
          "additions": 114,
          "deletions": 15,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 580,
          "url": "https://github.com/kungfu-systems/kungfu/pull/580",
          "title": "feat(freeze): assemble the Windows runtime tree + retire the freeze chain",
          "body": "ADR-0046 stage 2 completes: Windows joins macOS and Linux on the assembled\nCPython runtime, and the Nuitka/PyInstaller freeze distribution chain retires.\n\n## Windows assemble leg\n- `run-freeze.js`: fork the assemble tree for the python-build-standalone\n  Windows prefix (python.exe at the root, Lib/site-packages, a three-level .pth)\n  vs the POSIX bin/python3 + lib/pythonX.Y layout; stage the Windows binding\n  through the MSVC-aware helper; `freezer()` now defaults every platform to\n  assemble.\n- `stdlib-prune.json`: restructure so the shared stdlib families live in each\n  platform section (common was POSIX-shaped); add a `win32` section grounded\n  against the real cpython-3.13.14-windows-x86_64 tree.\n- `verify.mjs` / `dist.mjs`: assert the assembled-tree interpreter per platform.\n- Cross-platform fix: parse `runtime-pins.env` line-ending agnostically (a\n  `core.autocrlf` checkout renders it CRLF, which defeated the value regex).\n\nValidated on a Windows build host: `rebuild:core` + `freeze` (assembled form),\nthe assembled `kungfu.exe` runs `-m kungfu`, and `dist:cli` builds the CLI\nproduct package and passes the installed-layout smoke.\n\n## Freeze chain retirement\nWindows was the last frozen platform, so the freeze distribution machinery\nretires as one: the nuitka/pyinstaller legs, the nuitka entry shim, the\nPyInstaller spec and hooks, the dead conanfile freeze path, and the pyinstaller\ndev pin. The `engage nuitka` bridge (py-AOT kfx build, ADR-0045) stays, so the\nnuitka pin is kept. The retirement ledger in `docs/buildchain.md` records it.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T11:02:01Z",
          "mergedAt": "2026-07-11T12:10:29Z",
          "additions": 122,
          "deletions": 708,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 581,
          "url": "https://github.com/kungfu-systems/kungfu/pull/581",
          "title": "fix(journal): harden mmap ownership and page publication",
          "body": "## What changed\n\n- introduce move-only `mapped_region` ownership for POSIX and Windows mappings\n- separate existing-only mappings from explicit create/grow authority\n- make `page_header::last_frame_position` the release/acquire page publication token\n- validate page/header/frame sizes and offsets before payload access\n- keep journal wire-v1 and the public three-argument Python `get_page_path` API unchanged\n- extend ADR-0001 and add native mmap correctness tests wired through Shifu and CTest\n\n## Why\n\nReader mappings could create or stretch files, raw mapping ownership leaked resources on error paths, and page initialization relied on ordinary cross-process field polling. The new boundary makes ownership and mutation authority explicit while preserving the existing single-writer, zero-copy journal contract.\n\n## Validation\n\n- `./shifu build:core` — passed on Mac arm64 after rebasing onto current `dev/v4/v4.0`; includes Node, Electron, Python, Wasmer and Wasmtime targets\n- `./shifu test:mmap` — passed\n- `ctest --test-dir framework/core/build -R '^yijinjing_mmap_tests$' --output-on-failure` — passed\n- `./shifu check` — passed\n- commit pre-checks including clang-format 20.1.8 — passed\n\nCI is currently unavailable and is not used as the merge gate for this change; the requested gate is the Mac build and tests above.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T12:37:25Z",
          "mergedAt": "2026-07-11T12:38:25Z",
          "additions": 741,
          "deletions": 119,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 582,
          "url": "https://github.com/kungfu-systems/kungfu/pull/582",
          "title": "test(journal): cover mmap resource failure paths",
          "body": "## What changed\n\nFollow-up fault qualification for PR #581:\n\n- repeat truncated existing-only mappings and assert process fd/handle count does not grow\n- force an already-unmapped view and assert flush failure is surfaced while RAII ownership is cleared\n- use POSIX `RLIMIT_FSIZE` to force resize/file-budget failure and verify the page is not grown past the limit\n\n## Why\n\nThe implementation fixes in #581 were complete, but closeout review found that resource-error and resize-budget acceptance criteria lacked direct deterministic tests. This PR closes that evidence gap without changing production code.\n\n## Validation\n\n- `./shifu test:mmap` — 9/9 passed on Mac arm64\n- CTest `yijinjing_mmap_tests` — passed\n- `./shifu check` — passed\n- clang-format 20.1.8 / pre-commit staged gates — passed\n\nThe production implementation was already validated by the complete Mac `./shifu build:core` in #581. CI is not required as a merge gate per operator instruction.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T12:44:10Z",
          "mergedAt": "2026-07-11T12:44:43Z",
          "additions": 84,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 583,
          "url": "https://github.com/kungfu-systems/kungfu/pull/583",
          "title": "docs(adr): close ADR-0045 implementation record",
          "body": "Merge docs/adr0045-closeout into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:27:58Z",
          "mergedAt": "2026-07-11T13:28:04Z",
          "additions": 56,
          "deletions": 32,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 584,
          "url": "https://github.com/kungfu-systems/kungfu/pull/584",
          "title": "refactor(journal): separate mmap mapping policies",
          "body": "## Summary\n\n- replace implicit mmap booleans with explicit access, creation, residency, and durability policies\n- make page and reader/coordinator intents explicit while preserving wire-v1, POD layout, zero-copy, and compatibility adapters\n- document the qualified policy matrix in ADR-0058 and add illegal-combination coverage\n\n## Validation\n\n- ./shifu build:core\n- ./shifu test:mmap (11/11)\n- ./shifu check",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:41:54Z",
          "mergedAt": "2026-07-11T13:42:36Z",
          "additions": 646,
          "deletions": 165,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1122,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1122",
          "title": "feat(kfd): expose Shifu artifact discovery contract",
          "body": "## Summary\n\n- add a versioned `buildchain layout --json` contract so Shifu can discover the active KFD-3 registry without copying Buildchain paths\n- validate explicit KFD-3 distribution declarations with registrar, tasks, artifact kind, platform, path glob, and optional digest\n- self-describe Buildchain standalone archives as a Shifu-managed distribution surface and expose the `binary:build` task\n- publish the new CLI, Node API, docs, KFD claims, and generated site facts\n\n## Validation\n\n- `pnpm run check` (541 tests, workflow checks, generated site checks, action bundles)\n- `node --test tests/kfd3-surface-register.test.mjs`\n- standalone macOS arm64 SEA/archive smoke via `pnpm binary:build`\n\n## Runtime train\n\n- `train/v2/v2.12/kfd-artifact-onboarding` at `a9565ea819affc6964dd4be71d376dd35ec3c142`",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:42:22Z",
          "mergedAt": "2026-07-11T13:44:25Z",
          "additions": 603,
          "deletions": 153,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1123,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1123",
          "title": "feat(release): promote KFD artifact onboarding alpha",
          "body": "## Summary\n\nPromote the reviewed KFD artifact onboarding contract from `dev/v2/v2.12` to the alpha channel.\n\nThe candidate adds Buildchain-owned layout discovery, explicit Shifu jurisdiction declarations, and three-platform standalone artifact metadata.\n\n## Evidence\n\n- implementation PR: #1122\n- implementation merge: `906680ed66a3e49c0a21c29ebede17939c96b163`\n- full Buildchain check: 541 tests passed\n- standalone macOS arm64 archive smoke passed",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:45:44Z",
          "mergedAt": "2026-07-11T13:47:23Z",
          "additions": 603,
          "deletions": 153,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 586,
          "url": "https://github.com/kungfu-systems/kungfu/pull/586",
          "title": "fix(gui): run first-party manifest with tsx",
          "body": "## Summary\n\n- execute first-party manifest generation through the project TypeScript runtime\n- keep the package script and electron-builder beforePack hook on the same execution path\n- preserve the pinned first-party extension manifest in desktop artifacts\n\n## Validation\n\n- `./shifu check`\n- `./shifu --filter @kungfu-tech/gui run gen:first-party-manifest`\n- full `./shifu product gui dist` completed with ZIP and DMG outputs\n- packaged Status extension hash matches the pinned first-party manifest",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:48:18Z",
          "mergedAt": "2026-07-11T13:48:23Z",
          "additions": 10,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 585,
          "url": "https://github.com/kungfu-systems/kungfu/pull/585",
          "title": "feat(mission-control): make Mission evidence portable",
          "body": "Merge feature/mission-control into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:46:53Z",
          "mergedAt": "2026-07-11T13:53:03Z",
          "additions": 6000,
          "deletions": 215,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1125,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1125",
          "title": "fix(release): refresh promotion action bundle",
          "body": "## Summary\n\nRegenerate `actions/promote-buildchain-ref/dist/index.js` after the final KFD distribution digest validation change.\n\nThe first alpha promotion correctly failed closed because lifecycle verification rebuilt the action and detected this tracked bundle drift. The source was already correct; the bundled action still contained the pre-final condition.\n\n## Validation\n\n- `node --test tests/build-surface.test.mjs` (70 passed)\n- rebuilt the promotion action twice; the resulting digest is stable\n- bundle word diff is limited to the intended `sha256` presence validation",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:53:48Z",
          "mergedAt": "2026-07-11T13:55:40Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1126,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1126",
          "title": "fix(release): repromote KFD artifact onboarding alpha",
          "body": "## Summary\n\nRe-promote the KFD artifact onboarding candidate after refreshing the generated promotion action bundle.\n\n## Evidence\n\n- implementation PR: #1122\n- fail-closed friction: #1124\n- generated bundle fix: #1125\n- bundle regeneration is stable and all PR checks passed",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:55:53Z",
          "mergedAt": "2026-07-11T13:57:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1128,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1128",
          "title": "fix(binary): isolate standalone CLI entrypoint",
          "body": "## Summary\n\n- mark the SEA bundle as the single embedded entrypoint so imported script CLIs do not self-execute\n- bundle `@kungfu-tech/kfd` JSON exports into the standalone executable\n- add a regression test that builds the real SEA and executes `version` and `layout --json`\n- extend the inventory gate to require the embedded entrypoint definition\n\n## Validation\n\n- `pnpm run check` (542 tests passed)\n- standalone SEA execution regression passed locally\n\nCloses #1127",
          "author": "dongkeren",
          "createdAt": "2026-07-11T14:30:11Z",
          "mergedAt": "2026-07-11T14:32:55Z",
          "additions": 33,
          "deletions": 7,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1129,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1129",
          "title": "release: promote v2.12 alpha after standalone CLI fix",
          "body": "Promote the latest v2.12 development train after fixing standalone binary entrypoint isolation.\n\nIncludes #1128 and closes the standalone release artifact regression before consumer onboarding.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T14:33:08Z",
          "mergedAt": "2026-07-11T14:34:46Z",
          "additions": 33,
          "deletions": 7,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 587,
          "url": "https://github.com/kungfu-systems/kungfu/pull/587",
          "title": "ci(dev): give the development mainline a standing verify signal",
          "body": "Merge ci/dev-verify-signal into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T14:37:36Z",
          "mergedAt": "2026-07-11T14:37:43Z",
          "additions": 200,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 591,
          "url": "https://github.com/kungfu-systems/kungfu/pull/591",
          "title": "feat(shifu): onboard pinned Buildchain artifacts",
          "body": "## Summary\n- make Buildchain a pin-first Shifu-managed tool via `.buildchain-version`\n- bootstrap standalone Buildchain release archives on demand and inject the cached binary into task PATH\n- expose mirror/version/checksum controls plus doctor pin/cache evidence\n- document `buildchain layout --json` as the stable KFD registry discovery contract\n\n## Evidence\n- `./shifu sync`\n- `./shifu fix`\n- `./shifu check`\n- `cargo test --manifest-path crates/Cargo.toml -p shifu-core -p shifu`\n- fresh `./shifu kfd2:claims:check` downloaded `v2.12.1-alpha.4` standalone archive\n- cached standalone `buildchain version` and `buildchain layout --cwd . --json` passed\n\nBuildchain source PRs: kungfu-systems/buildchain#1122, #1125, #1128.\nBuildchain release: `v2.12.1-alpha.4`.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T14:47:21Z",
          "mergedAt": "2026-07-11T14:48:38Z",
          "additions": 204,
          "deletions": 44,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1130,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1130",
          "title": "feat(build): provision mirrored Rust and Cargo toolchains",
          "body": "Summary: provision optional pinned Rust toolchains for native lifecycle jobs on Linux, macOS, and Windows; support optional rustup distribution mirrors; add an optional cargo-registry-index input passed as CARGO_REGISTRIES_CRATES_IO_INDEX; preserve locked source bytes across runner-global line-ending settings; document repository-variable usage without exposing private network topology; regenerate public workflow and contract artifacts. Validation: pnpm run check on the latest dev/v2/v2.12 merge (542 tests passed); Buildchain fixture matrix passed; downstream Kungfu run 29153055191 completed Rust setup and build lifecycle on Linux, macOS, and Windows; isolated Cargo fetch downloaded the complete wasmer dependency graph through the selected registry. Supersedes #1117, whose branch became conflicting after dev advanced.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T14:44:34Z",
          "mergedAt": "2026-07-11T14:57:50Z",
          "additions": 244,
          "deletions": 33,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1117,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1117",
          "title": "feat(build): provision optional native Rust toolchains",
          "body": "## Summary\n- add opt-in `setup-rust` and `rust-toolchain` inputs to the reusable native build matrix\n- bootstrap Windows Rust through `cmd` + `curl.exe`, without bash, PowerShell policy changes, or host PATH mutation\n- support optional rustup distribution/update mirrors while keeping official defaults\n- isolate Windows Cargo, rustup, and installer state by workflow run/attempt\n- force locked source checkouts to preserve Git bytes across runner-global CRLF settings\n- regenerate the channel router and public contract/site artifacts\n\n## Validation\n- `pnpm run check` (538 tests passed)\n- downstream train: `train/v2/v2.12/setup-rust-toolchain` at `7369fca49d97a50138a551647df4c6d4a71b9921`\n- downstream Kungfu ADR-0049 run: https://github.com/kungfu-systems/kungfu/actions/runs/29153055191\n  - exact Kungfu source: `f5abbc35bd9c4b1c9e484935422a64c63a654092`\n  - full Linux/macOS/Windows qualification is in progress\n\n## Downstream evidence required before merge\n- successful complete Kungfu ADR-0049 self-hosted Linux/macOS/Windows matrix with Rust 1.96.0",
          "author": "dongkeren",
          "createdAt": "2026-07-11T09:27:07Z",
          "mergedAt": "2026-07-11T14:57:52Z",
          "additions": 211,
          "deletions": 33,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 597,
          "url": "https://github.com/kungfu-systems/kungfu/pull/597",
          "title": "fix(core): suppress Windows minmax macros in mmap",
          "body": "Fixes #596.\n\nThe Windows product gate includes `windows.h` before using `std::numeric_limits<LONGLONG>::max()`. Defining `NOMINMAX` at the include boundary prevents Win32 macro expansion and follows the existing repository convention.\n\nEvidence:\n- exact MSVC failure reproduced by run 29156716599\n- `./shifu check` passed\n- staged pre-commit gate passed\n\nThe follow-up self-hosted Windows product build will run together with the Rust/Cargo provisioning candidate.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T15:04:53Z",
          "mergedAt": "2026-07-11T15:05:29Z",
          "additions": 3,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 590,
          "url": "https://github.com/kungfu-systems/kungfu/pull/590",
          "title": "fix(ci): provision mirrored Rust and Cargo",
          "body": "Summary: provision Rust 1.96.0 on the self-hosted native matrix; use mirrored rustup distribution endpoints; pass the Cargo registry index through a repository variable so private LAN topology stays out of public workflow YAML. Validation: ./shifu check passed; full self-hosted workflow run 29156651239 is in progress. Depends on Buildchain #1117 and the stacked Cargo registry input PR. Fixes #579.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T14:44:35Z",
          "mergedAt": "2026-07-11T15:07:12Z",
          "additions": 7,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 599,
          "url": "https://github.com/kungfu-systems/kungfu/pull/599",
          "title": "perf(yijinjing): qualify and optimize mmap page lookup",
          "body": "## Summary\n\n- add a reproducible native mmap qualification harness and retain macOS/Linux evidence\n- replace reverse-linear page-header lookup with a tail fast path plus ordered binary probes\n- record independent accept/reject/defer decisions for sizing, advice, residency, flush range, and release polling\n\n## Evidence\n\n- Mac three-round A/B at 128 pages: early seek p50 3.131-3.505 ms -> 0.298-0.517 ms; middle 1.825-1.953 ms -> 0.293-0.454 ms; late unchanged\n- Linux three-round A/B: early 0.750-0.782 ms -> 0.153-0.155 ms; middle 0.431-0.454 ms -> 0.152-0.154 ms; late unchanged\n- `./shifu rebuild` passed on macOS arm64 and agent-120 Linux x86_64\n- `./shifu test:mmap` passed on both hosts\n- `./shifu check` passed on macOS\n\n## Compatibility\n\nNo wire bytes, Hana POD layout, public API, mapping authority, or durability semantics change. Rollback is a normal revert of the two lookup commits.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T15:10:53Z",
          "mergedAt": "2026-07-11T15:11:37Z",
          "additions": 2795,
          "deletions": 7,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 600,
          "url": "https://github.com/kungfu-systems/kungfu/pull/600",
          "title": "fix(ci): honor the libwasm Rust pin",
          "body": "Summary: align the self-hosted CI bootstrap with the authoritative Rust 1.95.0 pins in `crates/libwasm/rust-toolchain.toml` and `crates/libwasm-spike/rust-toolchain.toml`, so the native build does not attempt a second rustup install inside the build lifecycle. This is the follow-up to #590 discovered by real matrix validation. Validation: `actionlint .github/workflows/build.yml` and `./shifu check` pass. The final self-hosted proof run is 29157505924. Related to #579.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T15:31:30Z",
          "mergedAt": "2026-07-11T15:33:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 595,
          "url": "https://github.com/kungfu-systems/kungfu/pull/595",
          "title": "docs(mission-control): design workspace product flow",
          "body": "## Summary\n- define Desktop Open Workspace, recents, cold-start restore, and lazy `.kungfu` initialization\n- separate workspace facts, global config/session state, machine fallback, and explicit personal workspace semantics\n- redesign Work Dashboard as a five-question Mission Home with compact authoring actions\n- confirm Saved Query Catalog remains workspace-scoped and define Atlas dogfood behavior\n- add ADR-0060 plus eight implementation slices and falsifiable product gates\n\n## Validation\n- `git diff --check`\n- `./shifu check`\n- ADR identity/index gate passed\n\n## Scope\nDesign and architecture only. This PR does not claim that Open Workspace or the redesigned Mission Home is implemented.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T14:59:16Z",
          "mergedAt": "2026-07-11T15:46:26Z",
          "additions": 1122,
          "deletions": 11,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 602,
          "url": "https://github.com/kungfu-systems/kungfu/pull/602",
          "title": "fix(ci): dev verify patrol treats only failure as a red signal",
          "body": "Merge fix/dev-verify-report-result-guard into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T15:47:04Z",
          "mergedAt": "2026-07-11T15:47:10Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 603,
          "url": "https://github.com/kungfu-systems/kungfu/pull/603",
          "title": "docs(adr): add ADR-0060 journal container epoch and page-sizing design note",
          "body": "Adds ADR-0060 (journal container epoch derived from the page/frame header layout; hard refusal on the hot path; deferred offline cross-epoch conversion) and the journal-page-sizing-and-episode-reclamation design note, wired into the ADR index, data-axis theme, related documents, episode-object-model, and ADR-0033/0034. Documentation only.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T15:47:41Z",
          "mergedAt": "2026-07-11T15:55:32Z",
          "additions": 365,
          "deletions": 3,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 607,
          "url": "https://github.com/kungfu-systems/kungfu/pull/607",
          "title": "fix(windows): unblock mmap build and RAII qualification",
          "body": "## Summary\n\n- replace non-standard `_WINDOWS` guards with compiler-standard `_WIN32` and enforce the boundary in `shifu check`\n- load the MSVC environment before Shifu L2 build dispatch, with Rust unit coverage\n- enable global MSVC `/EHsc` so exception paths unwind mmap RAII handles\n- close Windows build/freeze/SDK path and canonical-text gaps exposed by the clean build\n\n## Validation\n\n- DARKHERO Windows: default `shifu.cmd build` passed without manual vcvars or compile flags\n- DARKHERO Windows: `shifu.cmd test:mmap` passed, including repeated failing-map handle regression (previously +8 handles)\n- DARKHERO Windows: clean baseline qualification bound to `a3ba855105f61aa46471b1b2d8e2921a8b85567e`, MSVC 19.51, `git_dirty=false`\n- macOS arm64: full `./shifu build`, `./shifu check`, and `./shifu test:mmap` passed\n- agent-120 Linux: `./shifu sync`, full `./shifu build`, `./shifu test:mmap`, and `./shifu check` passed\n\nCI is currently unavailable; this PR is qualified by the explicit three-host local matrix above.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T16:42:47Z",
          "mergedAt": "2026-07-11T16:43:38Z",
          "additions": 159,
          "deletions": 73,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 605,
          "url": "https://github.com/kungfu-systems/kungfu/pull/605",
          "title": "fix(ci): align libwasm Rust toolchain pins",
          "body": "Fixes #604.\n\nAlign both libwasm toolchain pins with the Rust 1.96.0 version provisioned by the self-hosted Buildchain runner contract. This prevents parallel Wasmer/Wasmtime targets from racing two implicit rustup installs of the old 1.95.0 toolchain.\n\nEvidence:\n- exact race captured in alpha r2 Linux run 29157376683\n- `./shifu check` passed\n- staged pre-commit gate passed\n\nA replacement alpha candidate will rerun all three product legs after merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T15:57:36Z",
          "mergedAt": "2026-07-11T17:16:17Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 609,
          "url": "https://github.com/kungfu-systems/kungfu/pull/609",
          "title": "fix(ci): align product Rust toolchain pin",
          "body": "## Summary\n\n- align the alpha/release product workflow with the Rust 1.96 pins established by #605\n- avoid cross-toolchain rustup installation during the native matrix\n\n## Validation\n\n- `./shifu check`\n- staged repository gates\n\nFixes #608.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T17:19:22Z",
          "mergedAt": "2026-07-11T17:20:03Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 611,
          "url": "https://github.com/kungfu-systems/kungfu/pull/611",
          "title": "feat(workspace): ship Home and Project Mission Control",
          "body": "## Summary\n- add lazy Home/Project Workspace identity, selection, persistence, and Desktop Mission Home\n- expose shared inspect/advice/preview/authorization/action/receipt/verify contracts to GUI and agents\n- add bounded project-gravity and portable-contract guidance without implicit Git/network effects\n- qualify real Atlas scale (5 Missions, 533 Go, 1151 markers) with source-bound TrustReports and bounded CLI output\n\n## Local validation\n- workspace/guidance Python tests: 16 passed\n- Desktop workspace selection: 3 passed\n- API tests: 5 passed\n- ./shifu check: passed\n- ./shifu product gui build: passed; bundle-core audit passed\n- direct GUI dogfood: first-install Home, Mission Home, guidance receipt verification, and Atlas five-question TrustReport passed\n\nKnown unrelated CI problems are not used as a completion gate for this change, per current project direction.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T18:00:52Z",
          "mergedAt": "2026-07-11T18:01:49Z",
          "additions": 4696,
          "deletions": 375,
          "changedFiles": 42
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 606,
          "url": "https://github.com/kungfu-systems/kungfu/pull/606",
          "title": "feat(trunk): ADR-0046 Stage 3 — embedding membrane, native node variant, unified help",
          "body": "ADR-0046 Stage 3: the Rust trunk grows into the process host. Ratified RFC\n`framework/core/docs/embedding-contract-face.md` plus its four implementation\nsteps.\n\n- **RFC (embedding contract face)**: the libkungfu embedding surface is exactly\n  the one versioned C ABI membrane (`kungfu_embedding_get_api` + `kf_embedding_api_v1`),\n  converged with the ADR-0045 gate-1 ABI — one membrane, two consumers (native\n  KFX + the trunk).\n- **kungfu-embedding crate (D7)**: the one shared Rust borrowing layer over the\n  membrane; host-spike drops its private copy and depends on it. Pure rlib with\n  compile-time ABI layout guards; no libkungfu link, so it stays in the workspace\n  gate.\n- **trunk doctor (D5/D6)**: read-only physical inspection through the membrane,\n  behind the `embedding` cargo feature (off by default, so coreless builds stay\n  green); build.rs links libkungfu when the feature is on.\n- **native node variant**: `KUNGFU_AS_VARIANT=node` runs `node::Start` through a\n  standalone `kungfu_node_host` library dlopen'd at the front door, without\n  booting CPython; falls back to the Python variant when the library is absent\n  (zero behavior change). The python variant stays Python-side (it is pervasively\n  kungfu-bridged).\n- **unified --help**: `kungfu --help` renders the command surface from a\n  declarative manifest generated by introspecting the live click tree (single\n  source of truth), shipped in dist/kungfu; falls back to the Python CLI help\n  when absent.\n\nRust workspace: cargo test/clippy/fmt green. The native launcher, the embedding\nfeature link, and the assemble-time help-manifest generation are exercised by CI.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T16:40:06Z",
          "mergedAt": "2026-07-11T20:27:49Z",
          "additions": 1667,
          "deletions": 273,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 615,
          "url": "https://github.com/kungfu-systems/kungfu/pull/615",
          "title": "feat(yijinjing): derive journal container epoch from header layout (ADR-0062)",
          "body": "Replaces the hand-maintained __JOURNAL_VERSION__ integer with journal_format_epoch, a compile-time value derived from the page_header/frame_header layout (Boost.Hana fold over field names + type tokens + sizeof/alignof). Any layout change -- including size-preserving reorder/retype/rename the *_length checks miss -- changes the epoch, so an unversioned layout change cannot ship and old-epoch pages are refused automatically. page::load semantics and the *_length checks are unchanged. Implements ADR-0062 (removing the now-unreachable assemble cross-epoch branch is a separate follow-up).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T06:10:35Z",
          "mergedAt": "2026-07-12T06:10:41Z",
          "additions": 92,
          "deletions": 12,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 616,
          "url": "https://github.com/kungfu-systems/kungfu/pull/616",
          "title": "refactor(yijinjing): remove unreachable cross-epoch branch in assemble (ADR-0062)",
          "body": "Every assignment to a reader's current page goes through page::load, which throws on an epoch mismatch, so a version-mismatched page can never reach assemble::read_bytes -- its skip-and-warn branch and the per-frame epoch check were dead code. Removes them (cross-epoch replay is offline conversion, ADR-0062) and adds a 'version' case to test_corrupt_page_header_facts_are_rejected to lock the load-level guarantee the removal rests on.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T06:39:21Z",
          "mergedAt": "2026-07-12T06:39:26Z",
          "additions": 7,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 617,
          "url": "https://github.com/kungfu-systems/kungfu/pull/617",
          "title": "docs(adr): mark ADR-0062 implemented",
          "body": "The derived journal container epoch (PR #615) and the removal of the unreachable cross-epoch assemble branch (PR #616) have landed. Flip ADR-0062 status to implemented and record how each verification item was discharged.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T06:46:44Z",
          "mergedAt": "2026-07-12T06:46:49Z",
          "additions": 26,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1132,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1132",
          "title": "fix(release): automate stable candidate qualification",
          "body": "## Summary\n\n- produce Build Surface Fixture and no-apply site canary evidence after exact-alpha self-dogfood\n- separate cross-repository dispatch authority from repository-local attestation\n- keep Patrol selection, source-lock PR, stable gate, and publish transaction unchanged\n\n## Validation\n\n- targeted qualification, Patrol, and stable gate tests passed\n- pnpm run check passed with 548 tests\n- workflow checks and git diff checks passed\n\n## Runtime validation\n\nTrain: train/v2/v2.12/patrol-qualification-evidence\n\nThe first post-merge exact alpha will prove the workflow-run trigger, exact-tag Build Surface dispatch, no-apply site canary, Actions attestation, and subsequent Patrol qualification.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T06:50:39Z",
          "mergedAt": "2026-07-12T06:53:20Z",
          "additions": 448,
          "deletions": 14,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 618,
          "url": "https://github.com/kungfu-systems/kungfu/pull/618",
          "title": "docs(adr): define yijinjing concurrency and error ownership",
          "body": "Merge docs/yijinjing-concurrency-contracts into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T06:54:30Z",
          "mergedAt": "2026-07-12T06:54:37Z",
          "additions": 382,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1133,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1133",
          "title": "chore(release): promote Patrol qualification evidence",
          "body": "Promote the merged stable-candidate qualification producer for exact-alpha runtime validation.\n\nExpected post-promotion evidence:\n- new exact alpha release and SHA\n- successful Buildchain Alpha Self-Dogfood\n- automatic Build Surface Fixture dispatch on the exact tag\n- automatic site-libkungfu-dev no-apply canary on the exact SHA\n- github-actions bot commit-status attestation accepted by the stable policy",
          "author": "dongkeren",
          "createdAt": "2026-07-12T06:54:07Z",
          "mergedAt": "2026-07-12T06:55:59Z",
          "additions": 688,
          "deletions": 43,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 614,
          "url": "https://github.com/kungfu-systems/kungfu/pull/614",
          "title": "fix(product): stabilize cross-platform release gates",
          "body": "## Summary\n\n- scope product observability verification to `kungfu-product` events so unrelated Buildchain lifecycle errors do not poison a successful product assembly\n- launch the first-party manifest ESM entrypoint through a `file://` URL on Windows\n- normalize unknown help-manifest generation errors introduced on current dev\n- add regression coverage for observability isolation and the ESM entrypoint specifier\n\n## Validation\n\n- `./shifu fix`\n- `./shifu check`\n- product/tooling tests: 10 passed, including both new regressions\n\nFixes #613.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T05:58:58Z",
          "mergedAt": "2026-07-12T07:06:31Z",
          "additions": 84,
          "deletions": 13,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1134,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1134",
          "title": "fix(release): match cross-repository canary runs",
          "body": "Fix Stable Candidate Qualification matching for cross-repository site canary runs. The candidate SHA is bound through the exact run display title because the site workflow run head SHA belongs to the site repository. Same-repository Build Surface matching remains pinned to the candidate SHA. Adds a regression test. Validation: pnpm run check (549 tests).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T07:07:33Z",
          "mergedAt": "2026-07-12T07:12:12Z",
          "additions": 37,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1135,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1135",
          "title": "chore(release): promote qualification matcher fix to alpha",
          "body": "Promote the cross-repository canary matching fix so Stable Candidate Qualification executes the corrected script from the exact candidate SHA.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T07:12:49Z",
          "mergedAt": "2026-07-12T07:14:53Z",
          "additions": 37,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 625,
          "url": "https://github.com/kungfu-systems/kungfu/pull/625",
          "title": "fix(python): restore public lockfile sources",
          "body": "## Summary\n\n- restore the committed Python lockfile to public PyPI sources\n- preserve locked package versions and SHA-256 hashes\n- keep local mirror selection out of repository truth\n- narrow mission evidence containers so the full public-runner mypy baseline remains valid once dependency sync can execute\n\n## Evidence\n\n- no `192.168.100.222:3141` references remain in `framework/core/uv.lock`\n- `UV_DEFAULT_INDEX=https://pypi.org/simple uv lock --check --directory framework/core`\n- `UV_DEFAULT_INDEX=https://pypi.org/simple uv run --frozen mypy src/python/kungfu`\n- `./shifu check`\n- reproduces the pre-test dependency failure in Dev Check run 29184081297; the first #625 run then reached mypy and exposed the pre-existing container inference gap\n\nCloses #624",
          "author": "dongkeren",
          "createdAt": "2026-07-12T07:23:30Z",
          "mergedAt": "2026-07-12T07:25:59Z",
          "additions": 607,
          "deletions": 607,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 626,
          "url": "https://github.com/kungfu-systems/kungfu/pull/626",
          "title": "docs(adr): add ADR-0065 schema registry consolidation",
          "body": "One authoritative type set with trait-derived subsets replaces the hand-maintained overlapping maps in schema/registry.h, retires the rot-prone numeric tag comments, and makes tag sets compile-time. Finishes msg_type -> carrier_type at internal sites while keeping the frozen v1 embedding ABI. Dispatch micro-optimization is a non-goal without measurement.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T07:32:39Z",
          "mergedAt": "2026-07-12T07:32:45Z",
          "additions": 129,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 627,
          "url": "https://github.com/kungfu-systems/kungfu/pull/627",
          "title": "feat(build): modernize the native C++ toolchain contract",
          "body": "## Summary\n\n- define one machine-readable C++23 toolchain contract and enforce it through Shifu, CMake, Conan, Ninja, and Buildchain\n- replace global native flags with target-scoped contracts, add portable content-hash spans, and qualify C++ modules behind a hold gate\n- make GCC 14, AppleClang, and MSVC builds reproducible with a pinned RxCpp portability recipe and canonical LF sources\n- document the compiler policy and accepted Modules hold in ADR-0066\n\n## Validation\n\n- macOS AppleClang 21: `./shifu build:core`, `./shifu test:mmap`, `./shifu check`\n- agent-120 GCC 14.2: full core/Node/Electron/Python/wheel build, mmap/content-hash tests, `./shifu check`\n- DARKHERO MSVC 19.51 + Rust 1.96: full core/Node/Electron/Python/wheel build, mmap/content-hash tests, `./shifu check`\n- C++ Modules qualification executed on all three platforms; promotion remains held by ADR-0066\n\nCI is currently unavailable; the platform-local qualification above is the merge evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T07:38:11Z",
          "mergedAt": "2026-07-12T07:38:58Z",
          "additions": 1315,
          "deletions": 138,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 628,
          "url": "https://github.com/kungfu-systems/kungfu/pull/628",
          "title": "refactor(yijinjing): derive pure-category type subsets from a membership table (ADR-0065)",
          "body": "Replaces the hand-listed State/Profile/SourceRegistry/ManifestCatalog/EpisodeManifest maps in schema/registry.h with one authoritative membership table + hana::filter. Derived maps are identical in type to the old ones (same type_name -> type_c shape), so consumers are unaffected; per-subset count static_asserts guard membership. Set-equality vs the old maps verified. schema/core.h stays neutral; AllTypes/has_data/CorePublic* structural subsets are a follow-up (ADR-0065).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T07:51:43Z",
          "mergedAt": "2026-07-12T07:51:51Z",
          "additions": 61,
          "deletions": 28,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 619,
          "url": "https://github.com/kungfu-systems/kungfu/pull/619",
          "title": "feat(freeze): build product trunk with --features embedding on POSIX (ADR-0046 S3)",
          "body": "ADR-0046 stage 3 productionization (Phase A, POSIX). The frozen/assembled product trunk now links libkungfu and ships the real embedding-backed `doctor` on macOS/Linux.\n\nBoth trunk build points pass `--features embedding` with an explicit `KF_TRUNK_NATIVE_DIR` / `KF_TRUNK_BUILD_TYPE` (`framework/core/build/<bt>`, populated before assemble) so build.rs never guesses a relative path that could fail canonicalize under CI:\n- `framework/core/.gyp/run-freeze.js` `stageEntry`\n- `product/scripts/dist.mjs` `stageTrunk`\n\nWindows stays featureless until the static-core link follow-up lands; the trunk's doctor/help/variant paths all fall back gracefully when the core is absent, so this is zero-regression.\n\nLocal verification (macOS): product cargo invocation builds a real embedding trunk (links `@rpath/libkungfu.dylib`, `@loader_path` rpath); in a co-located dist layout `doctor` negotiates ABI v1 + reports real capabilities, `KUNGFU_AS_VARIANT=node` dlopens the node host and runs `node::Start`, and `--help` renders from the co-located manifest (falls through when absent).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T06:59:59Z",
          "mergedAt": "2026-07-12T07:59:05Z",
          "additions": 51,
          "deletions": 16,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 630,
          "url": "https://github.com/kungfu-systems/kungfu/pull/630",
          "title": "feat(yijinjing): implement ADR-0063 concurrency ownership",
          "body": "## Summary\n\n- add a move-only RAII frame transaction and migrate in-tree writer, recorder, replay, and webserver paths while retaining deprecated compatibility adapters\n- define Reader cursor thread affinity and protect journal/runtime-writer management with stable snapshots\n- remove recursive locking and microsecond shared_ptr polling; page release now drops collector ownership without waiting for external leases\n- add failure injection, concurrent management, page-lifetime tests, and a paired qualification gate for transaction overhead\n\n## Validation\n\n- `./shifu build`\n- `./shifu test:mmap`\n- `./shifu check`\n- independent Release TSAN mmap build/run with `halt_on_error=1`\n- `./shifu qualify:mmap --profile baseline`: clean head `bbf8c890b`, 11 paired alternating trials, median transaction overhead `-5.68%` versus the deprecated split adapter (threshold `5%`), zero transaction heap allocations and zero published-read refcount operations\n\n## Evidence boundary\n\nLocal runtime/TSAN/qualification evidence is macOS arm64. This PR preserves the ADR-0001 publication token and journal layout, but ADR-0063 remains `proposed` until current Windows/Linux last-owner destruction and x86 publication stress evidence is recorded. ADR-0064 retains ownership of library-level signal/error propagation such as `raise(SIGINT)`.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:03:34Z",
          "mergedAt": "2026-07-12T08:04:33Z",
          "additions": 805,
          "deletions": 136,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 631,
          "url": "https://github.com/kungfu-systems/kungfu/pull/631",
          "title": "refactor(yijinjing): derive AllDataTypes from the has_data trait (ADR-0065)",
          "body": "Derives AllDataTypes by filtering the AllTypes roster on the has_data struct trait instead of hand-listing it (mark types drop out automatically); identical map type, count static_assert guard, consumers unaffected. The CorePublic* public surfaces stay explicit make_map as the runtime-greenfield public-binding audit requires (ADR-0027) -- they are out of scope for derivation.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:07:25Z",
          "mergedAt": "2026-07-12T08:07:31Z",
          "additions": 12,
          "deletions": 38,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 633,
          "url": "https://github.com/kungfu-systems/kungfu/pull/633",
          "title": "refactor(yijinjing): make schema tag sets compile-time (ADR-0065)",
          "body": "Replaces the runtime const std::set globals (AllTypesTags/StaticDataTags) with constexpr sorted std::array built by build_tag_set + a constexpr contains_tag binary search -- no static-init cost, cache-friendly per-event membership (reactor is_custom_event). Drops the dead ProfileDataTags. StaticDataTypes/StatisticDataTypes stay (empty but consumed by state-cache restore). Consumers switch to contains_tag.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:23:09Z",
          "mergedAt": "2026-07-12T08:23:17Z",
          "additions": 24,
          "deletions": 13,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 632,
          "url": "https://github.com/kungfu-systems/kungfu/pull/632",
          "title": "fix(product): select ESM entrypoint specifiers by platform",
          "body": "## Summary\n\n- keep absolute filesystem paths for POSIX first-party manifest generation\n- use a `file://` URL only on Windows, where drive-letter paths require it\n- cover Linux, macOS, and Windows specifier selection\n\n## Validation\n\n- `./shifu install`\n- `node --test product/scripts/dist.test.mjs`\n\nFixes the Linux product failure in #629.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:21:27Z",
          "mergedAt": "2026-07-12T08:26:03Z",
          "additions": 13,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1136,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1136",
          "title": "fix(checkout): accept regenerated pull merge trees",
          "body": "## Summary\n- keep commit identity strict for branches and ordinary refs\n- allow a regenerated GitHub pull-request merge commit only when its tree exactly matches the locked source tree\n- record the expected head and tree-equivalent identity mode in checkout evidence\n\n## Context\nKungfu PR #629 locked a synthetic pull merge SHA that GitHub later regenerated. The advertised pull ref still resolved to the same tree, but the original synthetic commit was no longer fetchable.\n\n## Validation\n- `node --test tests/locked-source-checkout.test.mjs`\n- `pnpm run build`\n- `pnpm run check` (551 tests passed)\n- `git diff --check`\n\nTrain ref: `train/v2/v2.12/locked-source-ref-fetch`",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:25:32Z",
          "mergedAt": "2026-07-12T08:29:08Z",
          "additions": 112,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1137,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1137",
          "title": "fix(release): promote locked-source checkout recovery",
          "body": "## Summary\n- promote the reviewed locked-source checkout recovery into the v2.12 alpha channel\n- preserve strict commit identity except for regenerated GitHub pull merge commits with the exact locked tree\n- unblock Kungfu alpha candidates when GitHub rotates a synthetic merge commit\n\n## Evidence\n- implementation PR #1136\n- Buildchain Verify and Build Surface Fixture passed\n- Kungfu direct r6 product matrix uses the train ref before this promotion",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:29:49Z",
          "mergedAt": "2026-07-12T08:31:43Z",
          "additions": 112,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 638,
          "url": "https://github.com/kungfu-systems/kungfu/pull/638",
          "title": "refactor(slices): rename internal msg_type to carrier_type (ADR-0065)",
          "body": "Renames the pre-ADR-0025 msg_type term to carrier_type in the fact-ledger and schema-registry probe slices (internal function/param names, comments, log text, JSON output keys; the value was already frame->carrier_type()). Out of scope: the frozen kf_embedding_frame_v1 ABI field and its readers/writers, Rust FFI mirrors, node/TS msgType binding API, and the carrier-action gate. Slice READMEs + docs/msg-type-ranges.md are a separate doc pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:35:25Z",
          "mergedAt": "2026-07-12T08:35:30Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 642,
          "url": "https://github.com/kungfu-systems/kungfu/pull/642",
          "title": "fix(runtime): make error stop ownership local",
          "body": "Implements ADR-0064 error/stop ownership boundaries.\n\n- replaces replay-time raise(SIGINT) with typed replay_exhausted\n- scopes first-error-wins stop state to each reactor without process-global callbacks\n- preserves native error identity across Python and Node hosts\n- pins Node Watcher lifetime across uv work and removes invalid CallbackInfo reuse\n- adds focused native/Python qualification tests\n\nValidation:\n- ./shifu test:runtime-errors (pass)\n- ./shifu test:mmap (pass)\n- ./shifu check reaches pre-existing framework/core/.gyp/run-freeze.js TS2339 baseline failure\n- full build passed before rebase; post-rebase dependency preparation is blocked by a missing RocksDB archive in local Conan cache before compilation\n- dispatch benchmark is unavailable because its existing quote default is incompatible with dispatch_load.py integer parsing\n\nGoal: 2026-07-12-kungfu-adr0064-error-stop-ownership\nMission: kungfu-technical-stewardship\nAgent: codex",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:55:14Z",
          "mergedAt": "2026-07-12T08:55:19Z",
          "additions": 483,
          "deletions": 60,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 643,
          "url": "https://github.com/kungfu-systems/kungfu/pull/643",
          "title": "perf(libwasm): share stable per-engine Cargo caches",
          "body": "## What changed\n\n- move production Wasmtime and Wasmer Cargo target directories out of each\n  CMake build tree into stable per-engine user-cache slots;\n- key each slot by source checkout, actual Cargo/rustc identity and target,\n  profile, engine, and lockfile;\n- stage each adapter back into its consuming CMake tree so build artifacts do\n  not depend on an external-cache path;\n- serialize the two heavy Cargo builds inside one CMake graph while retaining\n  Cargo's per-target lock as the cross-graph boundary;\n- apply the same contract to the shared-membrane qualification slice;\n- add a deterministic CMake contract test and\n  `./shifu qualify:libwasm-cache` for cold/warm cross-platform evidence.\n\n## Why\n\nThe two engine workspaces intentionally remain separate because their Cranelift\ndependency lines are incompatible. The previous integration also placed both\ntarget directories under `CMAKE_CURRENT_BINARY_DIR`, so every distinct CMake\ntree paid another full Rust dependency build. This change preserves the strict\nengine/workspace boundary while making target reuse stable and explicit.\n\n## Impact\n\nSeparate CMake trees from one checkout now reuse compiled Rust dependencies.\nDifferent worktrees, engines, toolchains, targets, profiles, or lockfiles cannot\ncollide. `CARGO_HOME` still owns shared registry downloads; the optional Cargo\nmirror remains a transport-only override.\n\n## Validation\n\n- macOS arm64:\n  - qualification (Cargo 1.95): Wasmtime `319 ms -> 89 ms`, Wasmer\n    `327 ms -> 132 ms` on the corrected warm run;\n  - full `./shifu build:core` passed in `117.50 s`; production CMake adapter\n    steps reused the cache in `0.45 s` and `0.66 s`.\n- agent-120 Linux x64 (Cargo 1.96): Wasmtime `80.2 s -> 78 ms`, Wasmer\n  `76.7 s -> 91 ms`.\n- DARKHERO Windows x64 (Cargo 1.96): Wasmtime `159.3 s -> 112 ms`, Wasmer\n  `164.7 s -> 202 ms`.\n- Commit hooks: staged source/format/contract gates passed on both commits.\n- `./shifu check`: all changed-file and cache-contract gates passed; the shared\n  tooling phase remains blocked by the pre-existing unchanged\n  `framework/core/.gyp/run-freeze.js:600` TypeScript inference error.\n- CI was not used for this change; the three requested native hosts supplied\n  the build evidence.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:58:38Z",
          "mergedAt": "2026-07-12T08:59:02Z",
          "additions": 542,
          "deletions": 22,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 644,
          "url": "https://github.com/kungfu-systems/kungfu/pull/644",
          "title": "feat(shifu): define cache profile contract",
          "body": "## Summary\n\n- establish an independent Shifu ADR registry and cache ownership decision\n- add versioned profile and redacted resolution JSON Schemas with fixtures and conformance checks\n- expose exact checked-in contracts through `shifu cache contract/schema` on macOS, Linux, and Windows entrypoints\n- fix the existing freeze options type inference regression so the repository gate remains green\n\n## Validation\n\n- `./shifu check`\n- `./shifu cache contract`\n- `./shifu cache schema profile`\n- `./shifu cache schema resolution`\n\n## Version impact\n\nAdditive update to the pre-release `shifu-launcher` welded surface; no line opening.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T09:08:14Z",
          "mergedAt": "2026-07-12T09:08:23Z",
          "additions": 1596,
          "deletions": 14,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 620,
          "url": "https://github.com/kungfu-systems/kungfu/pull/620",
          "title": "ci(core): gate membrane latency on the noise-free p50, not the flaky p99",
          "body": "The shared-embedding-membrane latency gate failed intermittently on shared CI\nrunners. Quantified from recent runs: the 4 KiB batch **p99 rides its\nprovisional 5us budget** and jitters above it (3.4-4.7us on macOS ARM64,\n4.6-6.2us on Linux x64) while the **code-path p50 stays flat** at 1.4-2.4us.\nThat tail is scheduler preemption on a shared runner, not a code regression. On\na loaded runner every trial can exceed 5us at once, so per-trial aggregation\nalone cannot rescue it.\n\n**Fix:** gate the noise-free p50 code-path budgets (control 500ns, 4 KiB batch\n3.5us); take five trials and report the p99 min/median as advisory triage\nnumbers rather than gating them. A genuine latency regression raises p50 and\nstill fails the gate; only the shared-runner tail jitter is de-gated.\n\nScope is the perf gate only. The separate Dev Check PyPI-index issue (uv.lock\npins the internal mirror) is being handled in its own change.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T07:02:20Z",
          "mergedAt": "2026-07-12T09:09:06Z",
          "additions": 42,
          "deletions": 15,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 640,
          "url": "https://github.com/kungfu-systems/kungfu/pull/640",
          "title": "fix(gui): default desktop packaging to no publish",
          "body": "## Summary\n- default the cross-platform electron-builder launcher to `--publish=never`\n- preserve an explicit caller-provided publish mode\n- make the launcher import-safe and cover both argument paths with focused tests\n\n## Context\nKungfu r6 generated the Linux AppImage successfully, then electron-builder inferred CI publishing and failed because candidate builds intentionally do not receive a GitHub publishing token. Release publication remains owned by Buildchain.\n\n## Validation\n- `node --test framework/gui/scripts/run-electron-builder.test.mjs product/scripts/dist.test.mjs` (5 passed)\n- staged repository gate passed\n- `git diff --check`\n- failing product evidence: run 29186140338",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:50:11Z",
          "mergedAt": "2026-07-12T09:09:37Z",
          "additions": 44,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 639,
          "url": "https://github.com/kungfu-systems/kungfu/pull/639",
          "title": "feat(trunk): run the node variant natively on Windows (ADR-0046 S3 Phase B1)",
          "body": "ADR-0046 stage 3 productionization, Phase B1 (Windows node variant). `KUNGFU_AS_VARIANT=node` now runs natively on Windows without booting CPython, matching macOS/Linux.\n\n- `crates/trunk/src/variant.rs`: Windows arm using `LoadLibraryW`/`GetProcAddress` to load `kungfu_node_host.dll` next to the exe and call `kungfu_node_run` (node::Start). argv build + invocation factored into a shared `invoke_node` (unix keeps raw-byte argv; Windows uses lossy UTF-8).\n- `framework/core/src/bindings/node/CMakeLists.txt`: widen the node-host gate to `(UNIX OR WIN32)`. The host is an embedder, so on Windows it links the real libnode import lib (`libnode.lib`, which ships in LIBNODE_LIB_DIR next to libnode.dll) — not a delay-loaded node.exe like the napi addons. Body is already portable (`__declspec(dllexport)`-ready entry, unix-guarded strip, MSVC-ignored visibility preset).\n- `framework/core/.gyp/run-freeze.js`: `copyPyBindingWin` stages `kungfu_node_host.dll` (+PDB) into dist/kungfu.\n\nZero-regression: absent DLL → `variant.rs` returns None and the Python variant path still runs node.\n\nValidated on real Windows (DARKHERO, MSVC + cargo 1.96): standalone `cl` build links `libnode.lib` and exports `kungfu_node_run`; the real Windows trunk build (variant.rs Windows arm) loads the host and runs node end-to-end — `KUNGFU_AS_VARIANT=node kungfu-trunk.exe --version` → `v22.22.3`, `-e \"console.log(2+3)\"` → `5`.\n\nWindows `doctor`/embedding stays stub (deferred: needs a new single-export embedding DLL; separate evaluation).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:44:06Z",
          "mergedAt": "2026-07-12T09:25:35Z",
          "additions": 113,
          "deletions": 21,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 649,
          "url": "https://github.com/kungfu-systems/kungfu/pull/649",
          "title": "docs(adr): add ADR-0067 schema-registry compile-time contract welds",
          "body": "Welds two schema-contract invariants at compile time (reusing ADR-0062 fingerprint + ADR-0065 subsets): carrier_type tag uniqueness static_assert, and a paired static_assert binding each of the 13 versioned manifest POD records' layout fingerprint to its schema_version. schema_version stays explicit (option B); option i now, option ii ledger at stable release. Version-less control types out of scope.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T09:33:01Z",
          "mergedAt": "2026-07-12T09:33:06Z",
          "additions": 154,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 650,
          "url": "https://github.com/kungfu-systems/kungfu/pull/650",
          "title": "ci(core): rebind Dev Check lock to public PyPI before frozen sync",
          "body": "The committed `framework/core/uv.lock` pins every artifact URL to the office\ndevpi mirror (`192.168.100.222:3141`), a LAN pull-through PyPI cache that gives\noffice / self-hosted builds a fast path over the restricted cross-border link.\nGitHub-hosted runners cannot reach that private address, so Dev Check's raw\n`uv sync --frozen` fails intermittently with a `tcp connect error` whenever a\nwheel is not already cached (4 of the last 6 Dev Check failures were this).\n\n**Fix (option A, matches the embedding-membrane spike workflow):** re-resolve\nthe same packages against public PyPI and assert the lock fingerprint (names,\nversions, hashes) is unchanged before the frozen sync. Only this GitHub-hosted\nCI job rebinds — the committed lock and the office LAN fast path are untouched,\nand a genuinely missing package still fails.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T09:33:19Z",
          "mergedAt": "2026-07-12T09:34:51Z",
          "additions": 24,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 651,
          "url": "https://github.com/kungfu-systems/kungfu/pull/651",
          "title": "fix(cli): propagate backtest runtime context",
          "body": "## Summary\n- propagate `backtest_dir` through nested Kungfu CLI contexts\n- cover the installed `storage layout --json` path with a regression test\n\n## Validation\n- `./shifu check`\n- `./shifu check:staged`\n\nThe direct product gate exposed this after successfully producing the Linux AppImage: the installed CLI smoke failed because the nested `storage` context lacked `backtest_dir`.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T09:36:15Z",
          "mergedAt": "2026-07-12T09:37:31Z",
          "additions": 21,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 653,
          "url": "https://github.com/kungfu-systems/kungfu/pull/653",
          "title": "Merge remote-tracking branch 'origin/dev/v4/v4.0' into feature/strong-durability-docs",
          "body": "Merge feature/strong-durability-docs into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T09:46:04Z",
          "mergedAt": "2026-07-12T09:46:10Z",
          "additions": 801,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 654,
          "url": "https://github.com/kungfu-systems/kungfu/pull/654",
          "title": "feat(query): drive Mission Control from saved profiles",
          "body": "## Summary\n- project the five Mission Control answers from versioned Saved Query profiles\n- drive Work Dashboard refresh from proof-bearing fact changelog state\n- preserve workspace selection and live refresh compatibility\n- repair electron beforePack ESM entrypoint and dashboard storage capability declaration\n\n## Validation\n- targeted Python query, changelog, Atlas and Saved Query tests\n- API TypeScript build and query tests\n- Status and Work Dashboard KFX builds\n- product unit tests\n- full native/Python/Node rebuild and freeze\n- unpacked macOS product build, Shifu registration/promote, and real Atlas GUI dogfood\n\n## Known limits\n- CI is currently known broken; this PR does not wait for CI\n- existing headless Atlas fixture has independent sync_root_mismatch debt\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-12T09:48:01Z",
          "mergedAt": "2026-07-12T09:54:41Z",
          "additions": 858,
          "deletions": 91,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1138,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1138",
          "title": "fix(checkout): preserve fetch diagnostics for retries",
          "body": "## Summary\n- preserve Git fetch stderr in locked-source checkout\n- allow the existing transient-network classifier to recognize RPC/HTTP transport failures and use the configured bounded retries\n- cover the fetch stdio contract with a regression test\n\n## Validation\n- `pnpm run check` (552 tests passed; action bundles rebuilt)\n\nThis was exposed by Kungfu r8 direct qualification: a transient GitHub shallow-fetch failure lost its RPC diagnostics and exited after attempt 1 despite `fetchAttempts=3`.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T09:59:57Z",
          "mergedAt": "2026-07-12T10:01:53Z",
          "additions": 21,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1140,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1140",
          "title": "fix(release): promote checkout retry diagnostics",
          "body": "## Summary\n- promote the reviewed locked-source fetch diagnostics fix into the v2.12 alpha channel\n- preserve Git stderr so bounded retries recognize transient RPC/HTTP failures\n- unblock Kungfu r8 direct product qualification without weakening source identity checks\n\n## Evidence\n- implementation PR #1138\n- Buildchain check and three-platform libnode-shaped workflow passed\n- Kungfu r8 attempt 2 exposed a first-attempt GitHub shallow-fetch failure that lost retry classification",
          "author": "dongkeren",
          "createdAt": "2026-07-12T10:02:20Z",
          "mergedAt": "2026-07-12T10:04:14Z",
          "additions": 21,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 657,
          "url": "https://github.com/kungfu-systems/kungfu/pull/657",
          "title": "feat(schema): weld carrier_type tag uniqueness at compile time (ADR-0067)",
          "body": "Weld the carrier_type tag-uniqueness invariant at compile time per ADR-0067. A constexpr adjacent-distinct scan over the sorted AllTypesTags plus a static_assert turns a silent duplicate tag into a build failure. Tags stay explicit and hand-allocated. Verified: positive case compiles, a deliberate duplicate tag fails the assert.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T10:24:07Z",
          "mergedAt": "2026-07-12T10:24:12Z",
          "additions": 19,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 660,
          "url": "https://github.com/kungfu-systems/kungfu/pull/660",
          "title": "feat(schema): weld manifest payload layout to schema_version at compile time (ADR-0067)",
          "body": "Weld each versioned manifest POD record's payload layout to its schema_version per ADR-0067 (option i / option B). Binds layout_fingerprint<T>() (ADR-0062) to a checked-in expected value for all 13 records across the three ADR-0065 subsets; a size-preserving layout change fails the paired static_assert, and a coverage guard prevents a new versioned record from shipping unwelded. schema_version stays an explicit hand-chosen integer. Verified: matching layouts compile, an equal-width retype fails its assert.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T10:29:37Z",
          "mergedAt": "2026-07-12T10:29:42Z",
          "additions": 69,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 661,
          "url": "https://github.com/kungfu-systems/kungfu/pull/661",
          "title": "fix(api): use NodeNext query specifier",
          "body": "Closes #658.\n\nUse an explicit `.js` specifier for the type-only `query` import so the API package remains valid under NodeNext module resolution.\n\nValidation:\n- `./shifu check:types`\n- `./shifu check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-12T10:30:12Z",
          "mergedAt": "2026-07-12T10:30:43Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 666,
          "url": "https://github.com/kungfu-systems/kungfu/pull/666",
          "title": "fix(shifu): skip cache-contract schema checks when ajv is absent",
          "body": "Merge fix/shifu-cache-gate-ajv-optional into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T11:22:54Z",
          "mergedAt": "2026-07-12T11:22:59Z",
          "additions": 66,
          "deletions": 35,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 668,
          "url": "https://github.com/kungfu-systems/kungfu/pull/668",
          "title": "feat(runtime): add durability position and receipt contract",
          "body": "Merge feature/durability-position-receipts into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T11:41:39Z",
          "mergedAt": "2026-07-12T11:41:48Z",
          "additions": 730,
          "deletions": 3,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 671,
          "url": "https://github.com/kungfu-systems/kungfu/pull/671",
          "title": "docs: add single-host institutional trust profile",
          "body": "## Summary\n- add an institution-facing adoption contract for Kungfu as a single-host local runtime ledger\n- state the current evaluation/shadow-only decision and exact non-claims\n- define the deployment envelope, guarantee and failure matrices, evidence requirements, operator responsibilities, and adoption gates\n- link the profile from README, the documentation map, known limits, and the durability overview\n\n## Validation\n- ./shifu check\n- local Markdown link validation across all touched documents\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-12T11:51:38Z",
          "mergedAt": "2026-07-12T11:51:45Z",
          "additions": 219,
          "deletions": 0,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 672,
          "url": "https://github.com/kungfu-systems/kungfu/pull/672",
          "title": "docs: define single-host performance release gate",
          "body": "## Summary\\n- define the post-correctness Single-Host End-to-End Performance Qualification release gate\\n- make Kungfu absolute thresholds, regression ceilings, and retained evidence authoritative\\n- constrain Aeron IPC and Aeron Archive to declared, same-semantics informative comparisons\\n- connect the gate to institutional trust, durability stages, known limits, README, and the documentation map\\n\\n## Validation\\n- ./shifu check\\n- local Markdown link validation across touched documents\\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:11:24Z",
          "mergedAt": "2026-07-12T12:11:32Z",
          "additions": 262,
          "deletions": 3,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 673,
          "url": "https://github.com/kungfu-systems/kungfu/pull/673",
          "title": "feat(runtime): fence state service and stream writers",
          "body": "Implements the ADR-0068 state-service separation slice for the Single-Host Institutional Profile: an in-process state-service boundary, independent projection lifecycle, data-root and physical-journal writer fencing with generation evidence, restartable shadow comparison, and cross-process crash/reopen tests. This does not claim durable ingest, durable receipts, HA, or power-loss qualification.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:15:15Z",
          "mergedAt": "2026-07-12T12:15:20Z",
          "additions": 1152,
          "deletions": 32,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 675,
          "url": "https://github.com/kungfu-systems/kungfu/pull/675",
          "title": "fix(gui): keep Mission Control refresh nonblocking",
          "body": "## Summary\n\n- execute Mission Control dashboard and assessment CLI reads asynchronously in the Electron main process\n- apply one cut-bound dashboard snapshot atomically with cached stale-while-refresh behavior, single-flight coalescing, and stale result rejection\n- yield between query changelog pages and remove synchronous native runtime-health polling from the renderer\n\n## Validation\n\n- `./shifu check`\n- API query tests, GUI Atlas transport tests, dashboard refresh coordinator tests\n- focused Python Mission Control snapshot test\n- full core build and `./shifu dist --product desktop --dir`\n- real `/Users/dkr/Code/atlas` 10-second continuous resize with 12 concurrent refreshes: RAF p95 17.6 ms, max 17.8 ms, zero long tasks, no degraded snapshot\n\nCI is currently known to be unreliable; this change is being assessed from the local evidence above.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:20:43Z",
          "mergedAt": "2026-07-12T12:24:48Z",
          "additions": 623,
          "deletions": 92,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 676,
          "url": "https://github.com/kungfu-systems/kungfu/pull/676",
          "title": "docs: lead performance gate with semantic purpose",
          "body": "## Summary\\n- lead the performance qualification contract with the distinction between observability telemetry and load-bearing agent ledger facts\\n- make visibility, durability, recovery, and meaning explicit obligations under load\\n- surface the same positioning in the README documentation entry\\n\\n## Validation\\n- ./shifu check\\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:26:35Z",
          "mergedAt": "2026-07-12T12:26:41Z",
          "additions": 35,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 669,
          "url": "https://github.com/kungfu-systems/kungfu/pull/669",
          "title": "feat(core): single-export embedding DLL — doctor works on Windows (ADR-0046 S3 Phase B2)",
          "body": "ADR-0046 stage 3, Phase B2. Makes `doctor`/the embedding membrane real on Windows.\n\nOn Windows the core is built STATIC and does not export `kungfu_embedding_get_api` (a SHARED core blows the COFF 65535-export limit, LNK1189), so the trunk had nothing to link. Add a **Windows-only** SHARED target `kungfu_embedding` (in its own `src/libembedding/`, so it doesn't inherit libkungfu's `enable_windows_export_all_symbols()`) that exports exactly `kungfu_embedding_get_api` and internally static-links the whole core closure (`kungfu` + `kungfu_compile_contract` + `CONAN_LIBS` — pykungfu's line minus libnode). One dllexport dodges LNK1189. POSIX is untouched (the SHARED libkungfu still exports the entry).\n\n- `framework/core/src/libembedding/CMakeLists.txt` (new) + core CMakeLists `if(WIN32 AND TARGET kungfu)` wiring.\n- `crates/trunk/build.rs`: drop the Windows panic; on Windows emit `rustc-link-lib=dylib=kungfu_embedding` from the build root (no rpath). POSIX unchanged.\n- `run-freeze.js` / `dist.mjs`: extend `--features embedding` to Windows (build-root native dir); `copyPyBindingWin` stages `kungfu_embedding.dll`.\n\nValidated end-to-end on real Windows (DARKHERO, MSVC + cargo 1.96):\n- `kungfu_embedding.dll` links the full core closure cleanly (`[26/26] Linking`, exit 0); `dumpbin /exports` shows **exactly one** symbol, `kungfu_embedding_get_api` (LNK1189 avoided); the DLL is self-contained (only system/MSVC-runtime deps).\n- The trunk built `--features embedding` links `kungfu_embedding.lib`; `doctor` → real embedding membrane, ABI v1, real capabilities `(0x3)` (not the stub).\n- POSIX `--features embedding` verified regression-free (still links `@rpath/libkungfu`).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T11:42:45Z",
          "mergedAt": "2026-07-12T12:31:31Z",
          "additions": 157,
          "deletions": 59,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 677,
          "url": "https://github.com/kungfu-systems/kungfu/pull/677",
          "title": "chore(gui): remove unused skill-context builder duplicates",
          "body": "`buildGuiSkillContext` and `buildGuiSkillManagerView` (in `framework/gui/src/main/skill-context.ts`) have **no importer anywhere in the repo**. They are in-memory duplicates of `writeGuiSkillContextFile` / `writeGuiSkillManagerViewFile` — the file-writing variants that `index.ts` actually uses; the GUI only ever writes the files. Removed the two dead functions and their now-unused `@kungfu-tech/skill` imports (28 lines).\n\nNo behavior change. From a dead-code survey. The survey's other gui candidates were kept after closer reading: `sandbox-view.ts:createSandboxedView` is a deliberate anti-drift reference (per its own header comment), and `installCli.ts:isKungfuCliInstalled` reads as reserved API — both deferred to owner review rather than removed here.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:33:04Z",
          "mergedAt": "2026-07-12T12:35:04Z",
          "additions": 0,
          "deletions": 28,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1139,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1139",
          "title": "feat(build): pass opaque Shifu cache profile inputs",
          "body": "## Summary\n\n- add opaque Shifu cache profile reference and digest inputs\n- pass the pair to lifecycle execution without fetching or interpreting profile fields\n- document and test the Buildchain/Shifu ownership boundary\n\n## Validation\n\n- `pnpm run check`\n- downstream validation ref: `train/v2/v2.3/shifu-cache-profile-passthrough`\n\n## Boundary\n\nBuildchain only transports the profile reference and digest. Shifu owns profile resolution, validation, application, and redacted receipts.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T10:02:16Z",
          "mergedAt": "2026-07-12T12:45:09Z",
          "additions": 121,
          "deletions": 21,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1141,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1141",
          "title": "feat(release): promote Shifu cache profile passthrough to alpha",
          "body": "## Summary\n- promote the reviewed opaque Shifu cache profile ref/digest passthrough into the v2.12 alpha channel\n- preserve the boundary that Buildchain transports values but does not parse Shifu profile fields\n\n## Evidence\n- implementation PR #1139 merged into dev/v2/v2.12\n- local Buildchain check: 552 tests passed after rebase\n- Buildchain PR check and three-platform libnode-shaped workflow passed\n- Kungfu train dogfood resolved rebased runtime 2ed3a0ad and accepted the exact Atlas runner profile digest; install passed before an unrelated existing product smoke failure",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:45:45Z",
          "mergedAt": "2026-07-12T12:48:28Z",
          "additions": 121,
          "deletions": 21,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 678,
          "url": "https://github.com/kungfu-systems/kungfu/pull/678",
          "title": "fix(build): patch rxcpp maybe<T> off deprecated std::aligned_storage",
          "body": "std::aligned_storage is deprecated in C++23 (P1413R3); rxcpp 4.1.1 uses it in maybe<T>, so under -std=gnu++23 every kungfu rx consumer instantiating maybe<T> emits a deprecation warning -isystem cannot suppress. Conan recipe patch replaces it with an equivalent alignas byte buffer; placement-new access unchanged. Verified: patched package header contains zero std::aligned_storage occurrences.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:54:42Z",
          "mergedAt": "2026-07-12T12:54:47Z",
          "additions": 15,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 680,
          "url": "https://github.com/kungfu-systems/kungfu/pull/680",
          "title": "docs(vocabulary): center public language on Episode",
          "body": "## Summary\n\n- establish Episode as the flagship object for real-world execution\n- publish a layered narrative around Facts, Receipts, Cuts, Watermarks, Claims, Proof, and Decisions\n- add a canonical vocabulary reference that separates Kungfu Core terms from domain profile vocabulary\n- route README, Concepts, and the documentation map to the new public entrypoints\n\n## Validation\n\n- `./shifu check`\n- `./shifu check:staged`\n- `git diff --check`\n\n## Boundaries\n\n- documentation only; no runtime, schema, CLI, or release-contract behavior changes\n- Mission and Go remain Agent Work profile terms whose naming may evolve\n- maturity and platform guarantees continue to defer to Contracts, Known Limits, and qualification evidence",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:07:50Z",
          "mergedAt": "2026-07-12T13:08:28Z",
          "additions": 604,
          "deletions": 2,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 655,
          "url": "https://github.com/kungfu-systems/kungfu/pull/655",
          "title": "feat(shifu): apply projected cache profiles",
          "body": "## Summary\n\n- implement Shifu-owned cache profile validation, resolution, binding application, and redacted receipts\n- wrap lifecycle and verification execution through `shifu cache apply`\n- pass only an opaque profile reference and digest through Buildchain\n- document the KFD-1 profile runtime and ownership boundary\n\n## Validation\n\n- `./shifu check`\n- cache runtime and contract tests: 13 passed\n- consumer currently pinned to `train/v2/v2.3/shifu-cache-profile-passthrough` for downstream validation\n\n## Dependency\n\n- kungfu-systems/buildchain#1139 must merge and publish a final ref before this PR replaces the temporary train reference and merges.\n\n## Safety\n\nProfiles and receipts reject URL credentials, query strings, fragments, secret-like environment keys, unsupported bindings, scope drift, and digest drift.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T10:09:15Z",
          "mergedAt": "2026-07-12T13:10:39Z",
          "additions": 1034,
          "deletions": 25,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 682,
          "url": "https://github.com/kungfu-systems/kungfu/pull/682",
          "title": "feat(runtime): add shadow durable ingest barriers",
          "body": "## Summary\n- add the versioned KFDL append-only segment and dual-slot checkpoint backend\n- enforce fenced owner/writer admission, exact restart deduplication, typed timeout/unavailable outcomes, and fail-stop unknown append handling\n- verify complete covered segment chains, preserve unknown tails, and compare a published mmap frame with decoded durable data\n- keep production durability profiles fail-closed behind qualification\n\n## Validation\n- ./shifu build:core\n- ./shifu test:durable-ingest\n- ./shifu test:state-service\n- ./shifu test:durability-contract\n- ./shifu test:runtime-errors\n- ./shifu test:mmap\n- ./shifu check",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:19:04Z",
          "mergedAt": "2026-07-12T13:19:10Z",
          "additions": 2404,
          "deletions": 8,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 683,
          "url": "https://github.com/kungfu-systems/kungfu/pull/683",
          "title": "fix(runtime): fail fast on unsupported nanomsg protocol; clarify intentional reactor warnings",
          "body": "Verdict-before-fix triage of 3 Tier-1 compiler warnings. BUG1 (nanomsg uninitialized rc on unsupported protocol) was a real UB and is fixed to fail deterministically. BUG2 (bitwise | in add_location) and BUG3 (discarded nodiscard probe in ensure_coordinator_rocksdb) were intentional; rewritten to preserve behavior while silencing the warnings. Verified via sibling compile_commands.json -fsyntax-only: all three target warnings gone, no new warnings.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:20:54Z",
          "mergedAt": "2026-07-12T13:20:59Z",
          "additions": 11,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 684,
          "url": "https://github.com/kungfu-systems/kungfu/pull/684",
          "title": "fix(gui): add Mission Control situation view",
          "body": "## Summary\n- replace the default five-question/table presentation with a visual Mission situation view\n- group parent and child Gos into progressive-disclosure cluster cards\n- expose purpose-bound KFD-2 glyphs, evidence freshness, next actor, and a detail drawer\n- preserve the five-question query output in explicit audit mode\n- project the Atlas hierarchy and Mission context fields needed by the visual model\n\n## Verification\n- ./shifu check\n- ./shifu foreach:extensions test (6/6)\n- ./shifu foreach test:query (7/7)\n- focused Atlas projection pytest (2/2)\n- ./shifu build\n- ./shifu dist --product desktop --dir\n- real Atlas workspace dogfood: visual spec present, five questions hidden by default, audit questions preserved, drawer tabs work, parent/child cluster detected, 760px viewport has no body overflow\n\n## Product\n- promoted Shifu build 20260712T133420Z-be00e1336\n- CI is currently not treated as a merge gate per operator instruction",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:37:04Z",
          "mergedAt": "2026-07-12T13:37:28Z",
          "additions": 1731,
          "deletions": 128,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 685,
          "url": "https://github.com/kungfu-systems/kungfu/pull/685",
          "title": "docs: center public guidance on Episodes",
          "body": "Merge docs/docs-information-architecture into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:45:12Z",
          "mergedAt": "2026-07-12T13:45:17Z",
          "additions": 423,
          "deletions": 417,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 686,
          "url": "https://github.com/kungfu-systems/kungfu/pull/686",
          "title": "docs: retire stale spec guidance",
          "body": "Merge docs/docs-stale-surface-cleanup into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:50:57Z",
          "mergedAt": "2026-07-12T13:51:03Z",
          "additions": 165,
          "deletions": 212,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 687,
          "url": "https://github.com/kungfu-systems/kungfu/pull/687",
          "title": "feat(runtime): add shadow projection bootstrap",
          "body": "## Summary\n\n- add a state-service-owned binary snapshot-through-T and replay-after-T substrate over checkpoint-covered KFDL records\n- bind snapshots to logical cut, projection schema, source qualification profile, and SHA-256 integrity\n- provide typed required/optional/none bootstrap outcomes, deterministic rebuild, lag/watermark status, and fail-closed corruption handling\n- keep the production coordinator compatibility restore unchanged; this PR is shadow evidence, not a public durability claim\n\n## Validation\n\n- ./shifu build:core\n- ./shifu test:projection-bootstrap\n- ./shifu test:durable-ingest\n- ./shifu test:state-service\n- ./shifu test:durability-contract\n- ./shifu test:runtime-errors\n- ./shifu test:mmap\n- ./shifu check\n\n## Remaining boundary\n\nProduction state-schema projection, shadow equality/cutover, coordinator business-join removal, real power-loss qualification, and public durable profiles remain disabled.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:51:25Z",
          "mergedAt": "2026-07-12T13:51:30Z",
          "additions": 1136,
          "deletions": 4,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 667,
          "url": "https://github.com/kungfu-systems/kungfu/pull/667",
          "title": "fix(ci): qualify membranes on current toolchains",
          "body": "Closes #646.\nCloses #664.\n\nFinal linear replacement for the embedding-membrane qualification. It preserves all reviewed fixes while avoiding the merge commits introduced into the earlier shared branches.\n\nChanges:\n- repo-owned RocksDB 6.29.5 Conan recipe with narrowly scoped current-compiler fixes\n- Ubuntu 24.04 / GCC 14 qualification and explicit Ninja selection\n- one Shifu-owned three-platform qualification task with MSVC bootstrap\n- calibrated Windows p50 gate from five-trial evidence while retaining the tighter POSIX budget\n- explicit MSVC empty-base optimization for generated journal records so persisted POD layouts match macOS/Linux\n\nValidation:\n- `./shifu install --frozen-lockfile`\n- `./shifu check`\n- `git diff --check` excluding patch payload whitespace\n- run 29189269994: macOS/Linux passed; Windows exposed #664\n- this PR must obtain fresh three-platform qualification on its current head before merge\n\nSupersedes #647, #659, and #662. No force-push or history rewrite was used.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T11:22:55Z",
          "mergedAt": "2026-07-12T13:53:04Z",
          "additions": 508,
          "deletions": 65,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 689,
          "url": "https://github.com/kungfu-systems/kungfu/pull/689",
          "title": "style(schema): format manifest layout weld",
          "body": "Format the ADR-0067 manifest layout weld macro with the repository-pinned clang-format.\n\nThis was exposed by the alpha candidate staged gate, which correctly checks the entire dev projection against the older alpha base. No behavior changes.\n\nValidation:\n- `uvx clang-format@20.1.8 -style=file --dry-run -Werror framework/core/src/libyijinjing/include/kungfu/yijinjing/schema/registry.h`\n- `./shifu check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:56:49Z",
          "mergedAt": "2026-07-12T13:57:34Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 691,
          "url": "https://github.com/kungfu-systems/kungfu/pull/691",
          "title": "feat(runtime): persist durable frame context",
          "body": "## Summary\n- supersede the internal test-only KFDL v1 container with v2 records carrying the complete journal frame context\n- expose the context through durable records and the state-service shadow append boundary\n- verify restart reconstruction against an actually published mmap frame without changing journal wire-v1 or the mmap hot path\n\n## Why\nThe projection bootstrap shadow could prove payload identity, but existing `state<DataType>` routing also requires source, destination, generation time, data type, and trigger lineage. Persisting those facts in the independent durable record is required before a real typed-state projector can be qualified.\n\n## Validation\n- `./shifu build:core`\n- `./shifu test:durable-ingest`\n- `./shifu test:projection-bootstrap`\n- `./shifu test:state-service`\n- `./shifu test:durability-contract`\n- `./shifu test:runtime-errors`\n- `./shifu test:mmap`\n- `./shifu check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:10:38Z",
          "mergedAt": "2026-07-12T14:11:03Z",
          "additions": 119,
          "deletions": 28,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 693,
          "url": "https://github.com/kungfu-systems/kungfu/pull/693",
          "title": "feat(runtime): project typed state from durable records",
          "body": "## Summary\n- add a typed-state projector driven directly by the authoritative Hana `StateDataTypes` roster\n- derive the same type/uid/source/destination/update-time/data image from durable KFDL v2 records and the compatibility state bank\n- prove all current state types, same-cut equality, uid replacement semantics, fail-closed malformed records, and rollback snapshot retention\n\n## Boundary\nThis remains a test-only shadow/cutover gate. Production coordinator restore remains active; journal wire-v1, mmap hot path, Hana POD, FlatBuffers owners, and public durability claims are unchanged.\n\n## Validation\n- `./shifu build:core`\n- `./shifu test:projection-bootstrap`\n- `./shifu test:durable-ingest`\n- `./shifu test:state-service`\n- `./shifu test:durability-contract`\n- `./shifu test:runtime-errors`\n- `./shifu test:mmap`\n- `./shifu check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:27:27Z",
          "mergedAt": "2026-07-12T14:28:00Z",
          "additions": 255,
          "deletions": 8,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 694,
          "url": "https://github.com/kungfu-systems/kungfu/pull/694",
          "title": "ci(docs): add layered Markdown validation gates",
          "body": "## Summary\n\nAdd a deterministic documentation gate for Markdown structure, the full local-link and cross-file anchor graph, canonical documentation entrypoints, and explicitly retired product wording. Keep external URL health in a separate pinned Lychee workflow so network availability cannot make pull-request results nondeterministic.\n\n## Changes\n\n- add `./shifu docs:check` and integrate it into changed/staged quality gates\n- add a conservative zero-debt Markdownlint baseline plus a repository-owned link/anchor/contract checker\n- add eight negative fixtures, including case mismatch and repository escape coverage\n- add a documentation-only PR workflow and a daily/manual external-link workflow\n- repair two stale KFD-1 links found by the first external scan\n- document the deterministic versus network-dependent maintenance boundary\n\n## Verification\n\n- `./shifu docs:check` (180 Markdown files; 8/8 negative fixtures)\n- `./shifu docs:check:external` (942 links; 231 unique; 0 errors; one exact staged release-passport URL excluded)\n- `./shifu check:types`\n- `./shifu check`\n- `./shifu check:staged`\n- `actionlint .github/workflows/docs-check.yml .github/workflows/docs-external-links.yml`\n- clean detached-worktree simulation of the Docs Check install command and gate\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:28:57Z",
          "mergedAt": "2026-07-12T14:30:07Z",
          "additions": 1441,
          "deletions": 2,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 696,
          "url": "https://github.com/kungfu-systems/kungfu/pull/696",
          "title": "feat(shifu): manage Cargo and Conan cache bindings",
          "body": "## What changed\n\n- add KFD-1 cache profile bindings for Cargo crates.io source replacement and ConanCenter remotes\n- apply Cargo through a temporary wrapper with highest-priority config and Conan through a disposable CONAN_HOME\n- emit redacted application and cleanup evidence in cache receipts\n- initialize Conan default profiles for Shifu-managed source builds\n\n## Why\n\nKungfu builds need the Atlas-managed central Cargo and Conan caches without depending on or overwriting persistent host configuration. Buildchain remains limited to opaque profile reference and digest transport.\n\n## Validation\n\n- ./shifu check\n- 16 Shifu cache contract/runtime tests\n- Mac, Ubuntu, agent-120, and DARKHERO digest-bound dry-run and live Cargo/Conan cache smoke\n- persistent Cargo/Conan config hashes unchanged on all four hosts\n",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:31:55Z",
          "mergedAt": "2026-07-12T14:33:24Z",
          "additions": 592,
          "deletions": 28,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 697,
          "url": "https://github.com/kungfu-systems/kungfu/pull/697",
          "title": "feat(runtime): hydrate typed state across restart",
          "body": "## Summary\n- decode verified typed-state images into a staging `state_cache::bank` and atomically replace the target only after full validation\n- preserve the target bank on truncated, unknown-type, uid-mismatched, or malformed image data\n- add a two-process fixture: creator writes a qualified test KFDL cut and snapshot; verifier reopens both, bootstraps, and hydrates typed peer state\n\n## Boundary\nThis completes the process-independent hydration primitive, not the production coordinator cutover. The compatibility restore remains active until a verified production profile and authority wiring are available; journal wire-v1 and the mmap hot path are unchanged.\n\n## Validation\n- `./shifu build:core`\n- `./shifu test:projection-bootstrap`\n- `./shifu test:durable-ingest`\n- `./shifu test:state-service`\n- `./shifu test:durability-contract`\n- `./shifu test:runtime-errors`\n- `./shifu test:mmap`\n- `./shifu check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:43:08Z",
          "mergedAt": "2026-07-12T14:43:54Z",
          "additions": 207,
          "deletions": 2,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 698,
          "url": "https://github.com/kungfu-systems/kungfu/pull/698",
          "title": "fix(runtime): make peer register-handshake timeout deterministic and thread-free",
          "body": "Register handshake timeout was rx::timeout + observe_on_new_thread (background thread, wall-clock, outside the single-threaded replayable model). Replaced with a wall-clock deadline checked from peer::on_active on the observer recv_timeout heartbeat - the one path alive when the coordinator is silent. Same 60s bound and signal_stop, no extra thread; the peer is not live during the handshake so the coordinator's journal time service cannot serve it. peer::timeout() documented as a post-live business timeout only. Verified via sibling compile_commands -fsyntax-only (compiles, no new warnings, clang-format clean) plus a standalone harness covering on_active's four branches.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:51:41Z",
          "mergedAt": "2026-07-12T14:51:47Z",
          "additions": 36,
          "deletions": 15,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 699,
          "url": "https://github.com/kungfu-systems/kungfu/pull/699",
          "title": "build(freeze): fail product builds missing the native host (ADR-0046 S3 follow-up)",
          "body": "Closes the ADR-0046 S3 productization gap where a product build could silently ship without the native host and fall back to the slow Python node path / the doctor stub (found in S3 Phase C).\n\nThe product core is always built for the node runtime, so the host must ship; a missing one is now a hard error in the **product** freeze, not a warning:\n- `product/scripts/dist.mjs` sets `KF_REQUIRE_NATIVE_HOST=1` on the product freeze call.\n- `run-freeze.js` `copyRuntimeNative` (POSIX): fatal if that flag is set and no `libkungfu_node_host.*` was staged.\n- `run-freeze.js` `copyPyBindingWin` (Windows): the `kungfu_node_host.dll` / `kungfu_embedding.dll` warnings become fatal under the flag (listing which is missing and why).\n\nDev (bare `pnpm run freeze`) leaves the flag unset and keeps warn-only — a dev assemble without a built host stays legitimate.\n\nVerified: gating logic (regex matches only host natives; fatal fires only for product-without-host, dev unchanged); recent assembled dists confirmed to contain `libkungfu_node_host.dylib`, so the guard does not break current node-runtime product builds.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:52:07Z",
          "mergedAt": "2026-07-12T14:52:42Z",
          "additions": 46,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 700,
          "url": "https://github.com/kungfu-systems/kungfu/pull/700",
          "title": "feat(gui): add Mission Control card query controls",
          "body": "## Summary\n- add query-driven sorting, filtering, hierarchy handling, and stable per-Mission saved views to Go cards\n- validate the versioned ViewSpec in TypeScript, native storage, and CLI import/update paths\n- make GUI refresh absorb Agent CLI saved-view revisions without restart\n\n## Validation\n- `./shifu check`\n- API tests: 9/9\n- work-dashboard tests: 9/9\n- static Atlas GUI fixture\n- `./shifu build`\n- `./shifu package` -> `20260712T145236Z-de66fa5b4`\n- real Atlas workspace dogfood: GUI filter/sort/reset/save; CLI revision 2 -> GUI auto-refresh; restore revision 3\n\n## Known baseline/environment failures\n- `./shifu verify`: 28/30; existing `mission_control.py` mypy error and Episode contention busy qualification failure\n- legacy live fixture reports `sync_root_mismatch`; the current static Atlas fixture passes\n\nCI is not a merge gate for this task per operator direction.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:58:27Z",
          "mergedAt": "2026-07-12T15:00:14Z",
          "additions": 1158,
          "deletions": 40,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 701,
          "url": "https://github.com/kungfu-systems/kungfu/pull/701",
          "title": "feat(runtime): inspect crash recovery evidence",
          "body": "## Summary\n- add explicit read-only KFDL recovery inspection and typed tail integrity\n- add deterministic DISCOVER -> VERIFY -> SELECT -> CLASSIFY -> REPORT outcomes\n- retain the checkpoint frontier and never mutate, repair, or promote unknown tail bytes\n\n## Validation\n- `./shifu check`\n- `./shifu test:crash-recovery`\n- `./shifu test:durable-ingest`\n- `./shifu test:projection-bootstrap`\n- `./shifu test:state-service`\n- `./shifu test:durability-contract`\n- `./shifu test:runtime-errors`\n- `./shifu test:mmap`\n\n## Scope\nThis is the first crash-recovery engine slice. Repair/quarantine, Episode folding, consistent export/restore, production qualification, and public recovery commands remain pending.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T15:02:00Z",
          "mergedAt": "2026-07-12T15:03:48Z",
          "additions": 546,
          "deletions": 3,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 703,
          "url": "https://github.com/kungfu-systems/kungfu/pull/703",
          "title": "ci(docs): enforce vocabulary prose contracts",
          "body": "Summary: make the machine-readable vocabulary registry authoritative for executable prose policy; narrow docs.contract.json to topology; generate Vale 3.14.2 styles; add required and advisory gates, negative fixtures, and documentation. Validation: shifu check, docs check, both Vale levels, and pinned Docker fallback passed locally. Goal: 2026-07-12-kungfu-vale-vocabulary-contract.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T15:10:17Z",
          "mergedAt": "2026-07-12T15:10:54Z",
          "additions": 808,
          "deletions": 74,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 704,
          "url": "https://github.com/kungfu-systems/kungfu/pull/704",
          "title": "refactor(runtime): extract shared journal-timer helpers in peer",
          "body": "Refactor only, behavior unchanged. peer's timer/time_interval/timeout each open-coded the same TimeRequest emission (5 copies), enable+arm+checkpoint prologue (3 copies), and Time-event due check. Extracted send_time_request/arm_timer/disarm_timer/timer_due so each operator reads as its own control flow. timer_due uses find instead of operator[] on timer_checkpoints_ (defensive: a real-rxcpp harness confirmed take_until terminates the interval stream before a disabled event reaches the due filter, so the old operator[] re-insert was not reachable; find hardens against future chain changes). Verified: sibling compile_commands -fsyntax-only compiles timer/time_interval + all helpers with no new warnings; clang-format clean.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T15:14:09Z",
          "mergedAt": "2026-07-12T15:14:14Z",
          "additions": 49,
          "deletions": 56,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 706,
          "url": "https://github.com/kungfu-systems/kungfu/pull/706",
          "title": "ci(docs): make publication contracts executable",
          "body": "Implements executable documentation examples, public reachability, Vale annotations and metrics, rule promotion evidence, a physically read-only lock-keyed docs toolchain, and immutable documentation supply-chain pins. Local evidence: 15 contract tests pass, 59-file Vale baseline is clean, and a cold run succeeded from a recursively read-only checkout.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T15:55:03Z",
          "mergedAt": "2026-07-12T15:55:08Z",
          "additions": 787,
          "deletions": 107,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 707,
          "url": "https://github.com/kungfu-systems/kungfu/pull/707",
          "title": "ci(docs): make publication contracts executable",
          "body": "Implements executable documentation and publication operations with local Mac validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T15:55:35Z",
          "mergedAt": "2026-07-12T15:55:40Z",
          "additions": 787,
          "deletions": 107,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 708,
          "url": "https://github.com/kungfu-systems/kungfu/pull/708",
          "title": "fix(docs): keep executable example source-only",
          "body": "The executable Shifu version example now forces the source-only script path. This removes native launcher compilation from the bounded docs example and fixes the GitHub-hosted docs gate timeout observed after the publication-operations merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T15:57:38Z",
          "mergedAt": "2026-07-12T15:57:49Z",
          "additions": 6,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 709,
          "url": "https://github.com/kungfu-systems/kungfu/pull/709",
          "title": "feat(kfx): define Profile Suite semantic contract",
          "body": "Implements the S0 decision gate for ADR-0069.\n\n- adds kungfu.profile-suite/v1 to the existing KFX contract authority\n- binds Suite packages to content-hashed Profile semantic closures\n- exposes shared Python and Node validation plus CLI schema discovery\n- retains Week/Day positive and negative fixtures in the Shifu shared gate\n- documents that lifecycle roots, activation, Mission Control migration, and release qualification remain staged\n\nValidation:\n- ./shifu test:kfx-profile-suite\n- ./shifu check\n\nGoal: 2026-07-12-kungfu-agent-first-profile-suite-runtime",
          "author": "dongkeren",
          "createdAt": "2026-07-12T16:20:19Z",
          "mergedAt": "2026-07-12T16:22:06Z",
          "additions": 968,
          "deletions": 11,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 710,
          "url": "https://github.com/kungfu-systems/kungfu/pull/710",
          "title": "docs(metadata): enforce typed document frontmatter",
          "body": "## Summary\n- define versioned path-based document metadata profiles\n- migrate public documentation and all Core/Shifu ADRs\n- make ADR body and registry status checked projections\n- preserve issue-template and Skill frontmatter as independent schemas\n\n## Validation\n- ./shifu check\n- ./shifu docs:check\n- ./shifu docs:prose:required\n- ./shifu check:types",
          "author": "dongkeren",
          "createdAt": "2026-07-12T16:46:33Z",
          "mergedAt": "2026-07-12T16:46:38Z",
          "additions": 2002,
          "deletions": 208,
          "changedFiles": 147
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 711,
          "url": "https://github.com/kungfu-systems/kungfu/pull/711",
          "title": "feat(kfx): add Profile lifecycle runtime",
          "body": "## Summary\n- compute a canonical Profile Suite root from the exact KFX contract, verified facet bytes, and explicit member roots\n- record typed Installed, Qualified, Activated, Superseded, RolledBack, and Removed facts through ActionEnvelope + Episode\n- expose stale-safe inspect/plan/apply/receipt/history behavior through shared C++, Python, Node, capability, and CLI surfaces\n- document the S1 boundary: Core closure/runtime qualification only; Agent SDK, GUI, portability, and Mission migration remain staged\n\n## Validation\n- `./shifu test:profile-lifecycle`\n- `./shifu check`\n- `./shifu build:core`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-12T17:03:32Z",
          "mergedAt": "2026-07-12T17:04:23Z",
          "additions": 2136,
          "deletions": 19,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 712,
          "url": "https://github.com/kungfu-systems/kungfu/pull/712",
          "title": "feat(kfx): add Agent Profile SDK",
          "body": "## Summary\n\n- ship an installed, self-describing Agent Profile SDK and `kungfu profile` CLI over the Core-owned Profile lifecycle\n- add deterministic scaffold, exact package-closure resolution, decision cards, semantic diff, and declarative action plan/invoke receipts\n- expose the versioned SDK contract through the Agent pack and prove custom KFX member builds do not rebuild Kungfu\n\n## Authority boundaries\n\n- Profile lifecycle remains owned by the S1 Core service\n- KFX schema and package bytes remain the source authority\n- identity, permission, evidence, authority, and destructive migration choices require external explicit decisions\n- S2 does not claim GUI Profile Manager, Mission Control migration, generic domain bindings, or Week/Day qualification\n\n## Validation\n\n- `./shifu build`\n- `./shifu kfd:buildchain`\n- `./shifu test:agent-profile-sdk` — 11 passed\n- `./shifu test:kfx-profile-suite` — Node 8 passed; Python 8 passed\n- `./shifu check`\n- frozen `kungfu profile capabilities --json`\n- frozen `kungfu agent verify --json` — no missing/hidden API surfaces\n\n`./shifu verify` passed 28/30 checks. The two failures are outside this diff: existing mypy errors in `work/store.py` and `atlas/mission_control.py`, plus the Episode qualification smoke reporting all scenarios busy. The built/frozen artifact, hashes, Agent pack, runtime smoke, and new Profile interfaces passed. CI is currently not used as a wait gate for this change.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T17:49:54Z",
          "mergedAt": "2026-07-12T17:50:14Z",
          "additions": 3390,
          "deletions": 63,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 713,
          "url": "https://github.com/kungfu-systems/kungfu/pull/713",
          "title": "feat(profile): add generic composition manager",
          "body": "## Summary\n- compose exact-root Profile fact surfaces, claims, assessment policies, and generic views through the existing ADR-0048/ADR-0052 authorities\n- add the public TypeScript Profile capability plus table/timeline/diff/causal-graph/attention renderer\n- turn the system KFX manager into an asynchronous Profile Manager with lifecycle health, roots, permissions, qualification, diagnostics, views, and exact decision/apply preview\n- publish Agent discovery and regenerated KFD-3 evidence for the same CLI/API/GUI path\n\n## Authority boundaries\n- no new fact, query, assessment, lifecycle, journal, trust, or GUI registry authority\n- Profile activation remains distinct from GUI focus\n- lifecycle mutation re-plans against the reviewed plan id and fails closed on drift\n- removal does not delete facts\n\n## Validation\n- `./shifu test:agent-profile-sdk` (22 passed)\n- API capability tests (12 passed)\n- `./shifu check`\n- `./shifu product gui build`\n- frozen app CLI `profile capabilities --json` and `profile manager --json` smoke\n- frozen first-party KFX pin and Profile Manager bundle inspection\n\nCI is currently known-broken; this PR is qualified from local gates and should not wait on CI.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T18:39:58Z",
          "mergedAt": "2026-07-12T18:40:28Z",
          "additions": 2752,
          "deletions": 68,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 705,
          "url": "https://github.com/kungfu-systems/kungfu/pull/705",
          "title": "feat(runtime): retain degraded recovery evidence",
          "body": "## Summary\n- add deterministic degraded-tail quarantine previews bound to exact stream evidence\n- publish byte-verified retained-evidence packages and typed idempotent maintenance receipts\n- reject stale previews and active ownership without changing source KFDL bytes\n- move the ownership lease default constructor out of line to fix the existing GCC 14 incomplete-pimpl build failure\n\n## Validation\n- `./shifu build:core`\n- `./shifu test:crash-recovery`\n- `./shifu test:durable-ingest`\n- `./shifu test:projection-bootstrap`\n- `./shifu test:state-service`\n- `./shifu check`\n\n## Scope\nThe quarantine package is test-only and is not a qualified power-loss receipt. This slice does not truncate or replace the authoritative stream; destructive repair, Episode folding, export/restore, and qualification remain pending.\n\n## CI follow-up\nPR #701 and the immediately preceding PR #699 both exposed the same Linux GCC 14 failure in `ownership::lease` while compiling `assemble.cpp`. This PR includes the minimal out-of-line pimpl constructor fix and relies on the Linux matrix to verify it.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T15:29:05Z",
          "mergedAt": "2026-07-12T19:12:17Z",
          "additions": 402,
          "deletions": 4,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 714,
          "url": "https://github.com/kungfu-systems/kungfu/pull/714",
          "title": "feat(profile): migrate Mission Control to public suite runtime",
          "body": "## Summary\n- close public Profile gaps for resolved query families, dynamic claim instances, explicit contract materialization, and verified independent Episodes\n- migrate Mission Control query/assessment/dashboard paths to exact Suite/catalog/member roots and public receipts\n- add Mission bundle v2 semantic closure with no implicit activation or permission grants\n\n## Validation\n- ./shifu test:agent-profile-sdk (29 passed)\n- Mission-focused Atlas tests (7 passed)\n- ./shifu check\n- Work Dashboard tests (9 passed)\n- ./shifu product gui build\n- frozen app CLI Profile discovery smoke\n\nCI is currently known-broken; local Shifu evidence is the acceptance basis for this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T20:01:42Z",
          "mergedAt": "2026-07-12T20:02:38Z",
          "additions": 2569,
          "deletions": 249,
          "changedFiles": 41
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 715,
          "url": "https://github.com/kungfu-systems/kungfu/pull/715",
          "title": "feat(profile): qualify installed profile authoring",
          "body": "## Summary\n- package the Agent Profile SDK and native esbuild runtime in the desktop product\n- add exact-root full/thin Profile source export/import without lifecycle mutation\n- expose independent observation evidence to Profile assessment planning\n- harden installed source discovery against unreadable unrelated siblings\n\n## Verification\n- `./shifu test:agent-profile-sdk` (31 passed)\n- `./shifu check`\n- `./shifu product gui build`\n- frozen product CLI built and qualified an external Week/Day/Action Suite, proved Mission coexistence, lifecycle rollback/removal/reinstall, KFD-1 query, KFD-2 assessment, and full/thin portability",
          "author": "dongkeren",
          "createdAt": "2026-07-12T20:51:47Z",
          "mergedAt": "2026-07-12T20:52:01Z",
          "additions": 550,
          "deletions": 4,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 716,
          "url": "https://github.com/kungfu-systems/kungfu/pull/716",
          "title": "docs(profile): publish agent-first profile guidance",
          "body": "## Summary\n- publish the installed agent-first Profile authoring workflow\n- document Profile composition, portability, and Mission Control coexistence\n- state the qualified macOS ARM64 pre-release boundary and remaining limits\n\n## Validation\n- ./shifu check\n- git diff --check\n\nCI is currently known-broken and is not a merge gate for this authorized release closeout.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T21:05:56Z",
          "mergedAt": "2026-07-12T21:06:24Z",
          "additions": 149,
          "deletions": 26,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 717,
          "url": "https://github.com/kungfu-systems/kungfu/pull/717",
          "title": "docs(adr): ADR-0070 layer peer communication primitives, propose renaming Band to Outlet",
          "body": "ADR-0070 (proposed). Records that the live communication primitives (channel, band, read/write requests, timer) answer a general 'how do peers communicate' question - they are the communication skeleton carried into v4, not trading logic; ADR-0057 made the terminology domain-neutral but the structure is still trading-shaped. Phase 1 (proposed now, docs-first): rename Band to Outlet, band_writers_ to off_thread_writers_, document the four layers. Phase 2/3 (decouple named-output from off-thread writing; unify establish-channel) are deferred and trigger-gated on the first post-trading peer consumer to avoid speculative abstraction. Docs gate passes locally.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T22:15:15Z",
          "mergedAt": "2026-07-12T22:15:20Z",
          "additions": 178,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 721,
          "url": "https://github.com/kungfu-systems/kungfu/pull/721",
          "title": "fix(profile): add Mission Control setup flow",
          "body": "## Summary\n- expose installed Profile source discovery through the public TypeScript capability\n- turn the Work Dashboard missing-Profile dead end into explicit install, qualify, and activate decision gates\n- show exact plan, authority, question, and effects before each authorized lifecycle mutation\n\n## Validation\n- ./shifu check\n- @kungfu-tech/api tests: 12 passed\n- work-dashboard tests: 12 passed\n- disposable runtime: install -> qualify -> activate -> active\n- ./shifu product gui build\n\nThe current known CI issue is not treated as a merge gate for this dogfood repair.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T22:56:09Z",
          "mergedAt": "2026-07-12T22:56:23Z",
          "additions": 269,
          "deletions": 9,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 723,
          "url": "https://github.com/kungfu-systems/kungfu/pull/723",
          "title": "refactor(runtime): rename Band to Outlet, band_writers_ to off_thread_writers_ (ADR-0070 phase 1)",
          "body": "ADR-0070 phase 1. Rename the Band communication primitive to Outlet (a peer's named output stream, not trading-specific) across schema type (id unchanged), registry, reactor/peer/coordinator, node binding, python stub, GUI keywords. Rename band_writers_/band_mtx_/get_band_writer to off_thread_writers_/off_thread_mtx_/get_off_thread_writer to name the pool by thread-affinity role. Document the outlet layer in concepts.md. No behavior change (type ids, wire layout, control flow unchanged); verified: reactor/peer/coordinator -fsyntax-only compile clean, docs gate + clang-format pass. ADR-0070 marked accepted; phases 2/3 deferred.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T22:59:43Z",
          "mergedAt": "2026-07-12T22:59:48Z",
          "additions": 139,
          "deletions": 136,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 725,
          "url": "https://github.com/kungfu-systems/kungfu/pull/725",
          "title": "docs(metadata): separate public metadata and bind ADR evidence",
          "body": "## Summary\\n\\n- move public entry and guide metadata to a checked sidecar registry\\n- enforce one metadata authority and flat allowlisted fields\\n- bind high-confidence ADR implementation history to commits, pull requests, closure, and qualification evidence\\n\\n## Validation\\n\\n- ./shifu docs:check\\n- ./shifu docs:prose:required\\n- ./shifu check:types\\n- ./shifu check",
          "author": "dongkeren",
          "createdAt": "2026-07-12T23:11:54Z",
          "mergedAt": "2026-07-12T23:11:59Z",
          "additions": 1282,
          "deletions": 726,
          "changedFiles": 93
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 726,
          "url": "https://github.com/kungfu-systems/kungfu/pull/726",
          "title": "docs(adr): bind ADR-0070 phase-one evidence",
          "body": "## Summary\\n\\n- bind ADR-0070 phase-one implementation to commit c42600c3d and PR 723\\n- link the live-runtime terminology gate as qualification evidence\\n- satisfy the merged ADR evidence contract without claiming full ADR closure\\n\\n## Validation\\n\\n- ./shifu docs:check\\n- ./shifu docs:prose:required",
          "author": "dongkeren",
          "createdAt": "2026-07-12T23:15:49Z",
          "mergedAt": "2026-07-12T23:15:55Z",
          "additions": 3,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 727,
          "url": "https://github.com/kungfu-systems/kungfu/pull/727",
          "title": "feat(shifu): auto-apply projected cache profiles",
          "body": "## Summary\n\n- auto-apply projected Shifu cache profiles for ordinary native and script-fallback tasks\n- fail closed on partial projection and prevent recursive application with `SHIFU_CACHE_ACTIVE`\n- preserve public-clone and explicit Buildchain cache lifecycle behavior\n\n## Validation\n\n- `./shifu check`\n- real projected-profile dogfood on macOS (single native build, cache contract passed)\n- POSIX fallback tests plus Rust launcher unit tests",
          "author": "dongkeren",
          "createdAt": "2026-07-12T23:16:17Z",
          "mergedAt": "2026-07-12T23:18:20Z",
          "additions": 366,
          "deletions": 5,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 724,
          "url": "https://github.com/kungfu-systems/kungfu/pull/724",
          "title": "docs(adr): ADR-0071 CLI language split and membrane diagnostic surface",
          "body": "Records the decision on which kungfu CLI commands fit the Rust trunk vs Python, from functional/technical fit rather than clap-vs-click.\n\n**Deciding axis**: where the work already lives and what the embedding membrane reaches.\n- **Bucket A (Rust fit)** — substrate diagnostics/maintenance (`storage fsck/verify/gc/compact`, `schema compile`): the C++ logic exists but is only reachable via the fat pybind binding today. **Grow the membrane's read-only diagnostic C ABI**, then thin Rust CLIs — extends the `doctor` pattern, no domain-logic rewrite, gains the must-work-when-broken property.\n- **Bucket B (measure first)** — `rewind verify` / `work` folds run a CPython per-frame decode; the membrane already hands raw frames to Rust. Migrate only if measurement shows the loop is felt.\n- **Bucket C (stays Python)** — product/UI/extension/orchestration/provider surfaces + tiny high-churn config/contract/workspace.\n\nStrategic lever: the membrane is the ceiling; the high-value move is growing its narrow, versioned read-only surface, not per-command rewrites. Implementation is tracked as a follow-up (Atlas go card).\n\nDocs gate: run-docs-check passed (0 errors, metadata contract + links/anchors). `decision_status: accepted`, `review_state: self-reviewed` (open to maintainer revision).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T23:09:56Z",
          "mergedAt": "2026-07-12T23:23:49Z",
          "additions": 171,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 718,
          "url": "https://github.com/kungfu-systems/kungfu/pull/718",
          "title": "ci(core): harden durable toolchain qualification",
          "body": "## Summary\n\n- run the hosted GCC 14 / Apple Clang / MSVC membrane matrix when the durable-ingest interface or implementation changes\n- retain the existing ownership PImpl coverage on the current paths\n- give Cargo registry traffic a 120-second HTTP timeout and five retries so transient rsproxy timeouts do not mask compiler results\n\n## Validation\n\n- `./shifu check`\n- prior runs #29196153424 and #29197363539 identified the exact GCC 14 / MSVC regressions now present in current dev, plus repeated 30-second Cargo registry timeouts on Windows\n",
          "author": "dongkeren",
          "createdAt": "2026-07-12T22:46:19Z",
          "mergedAt": "2026-07-12T23:26:25Z",
          "additions": 4,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 728,
          "url": "https://github.com/kungfu-systems/kungfu/pull/728",
          "title": "fix(gui): clarify Mission Control setup status",
          "body": "Merge fix/mission-control-setup-status-ux into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T23:27:31Z",
          "mergedAt": "2026-07-12T23:27:37Z",
          "additions": 262,
          "deletions": 23,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 730,
          "url": "https://github.com/kungfu-systems/kungfu/pull/730",
          "title": "docs(adr): ADR-0072 layer frame identity - journal-local frame_uid, ledger-global stream_position",
          "body": "ADR-0072 (proposed). Frame identity is layered: frame_uid stays journal-local (in-journal lookup, causal links, checksum) and does not become a permanent global id; permanent ledger-global uniqueness is the Episode content root plus the structural, monotonic stream_position (stream_id, container_epoch, sequence, already enforced contiguous by the durable tier). The container stays a short-lived substrate (ADR-0062 unchanged); permanence moves up to the Episode/ledger layer. Phase 1 (pre-stable window): restructure frame_uid to fix the deterministic page-8-bit wrap (full page_id + frame_nb, drop probabilistic salt and redundant source-xor-dest). Phase 2: authoritative stream_position sequence assignment. Rejects widening frame_uid to a global id (still probabilistic, duplicates Episode root). Relates ADR-0062/0053/0043/0068. Docs gate passes.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T23:55:05Z",
          "mergedAt": "2026-07-12T23:55:10Z",
          "additions": 175,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 731,
          "url": "https://github.com/kungfu-systems/kungfu/pull/731",
          "title": "feat(release): enforce ADR promotion admissibility",
          "body": "## Summary\n\nMake ADR implementation truth a release-bearing Buildchain contract instead of a documentation-only claim.\n\n## Changes\n\n- add a pure-Node ADR release contract and fixture-driven gate;\n- require feature PRs to declare `stage-ready` or `implemented` intent while retaining an explicit ADR-neutral path for non-feature changes;\n- settle ADR progress after alpha Buildchain qualification;\n- block stable promotion on every unaccounted accepted ADR, with exact-release admin waivers as the only exception;\n- retain the machine report with release qualification evidence;\n- document the management intent in ADR-0072, the release design, contributor guidance, and metadata contract.\n\n## Verification\n\n- `./shifu check`\n- `./shifu docs:check`\n- `actionlint -config-file .github/actionlint.yaml .github/workflows/adr-release-gate.yml .github/workflows/build.yml .github/workflows/docs-check.yml`\n- real dev-event fixture: `implemented`, zero findings\n- real current-repository stable fixture: fails closed with every unaccounted accepted ADR listed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0073\"],\n  \"summary\": \"Implement the three-stage ADR release admissibility contract\",\n  \"verification\": [\"./shifu check\", \"./shifu docs:check\", \"actionlint\"]\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] none of the above\n\nThe change strengthens release admission. It does not alter package publishing credentials or create a bypass. Stable waivers require an exact release, exact blocking conditions, an allowlisted administrator, the current release PR, expiry, and dedicated CODEOWNER review.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-12T23:59:35Z",
          "mergedAt": "2026-07-13T00:07:26Z",
          "additions": 1406,
          "deletions": 12,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 732,
          "url": "https://github.com/kungfu-systems/kungfu/pull/732",
          "title": "fix(adr): support PR-stable closure evidence",
          "body": "## Summary\n\nMake ADR closure evidence stable under Kungfu's rebase/squash-only PR merge policy.\n\n## Changes\n\n- allow implemented ADRs to use either reachable `closure_commit` or canonical `closure_pr` evidence;\n- validate `closure_pr` against the canonical kungfu-systems repository URL shape;\n- add positive and negative metadata fixtures;\n- rebind ADR-0073 to merged PR #731 so dev metadata is valid after GitHub rewrites its commits.\n\n## Verification\n\n- `./shifu check`\n- `./shifu docs:check`\n- 43 documentation/metadata fixtures pass, including canonical and foreign closure PR cases\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0073\"],\n  \"summary\": \"Close the rebase-merge evidence loop with stable PR authority\",\n  \"verification\": [\"./shifu check\", \"./shifu docs:check\"]\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis tightens evidence compatibility with repository merge policy. It does not accept arbitrary URLs or weaken semantic closure review.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T00:10:49Z",
          "mergedAt": "2026-07-13T00:11:37Z",
          "additions": 68,
          "deletions": 15,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 737,
          "url": "https://github.com/kungfu-systems/kungfu/pull/737",
          "title": "feat(release): add promotion contract rehearsal",
          "body": "## Summary\n\nAdd a side-effect-free alpha/stable promotion rehearsal and make the Buildchain promotion job depend on its actual-event preflight.\n\n## Changes\n\n- validate alpha/stable admission fixtures and current stable readiness\n- verify immutable Buildchain locks, release evidence inputs, channel routing, and workflow dependencies\n- run the rehearsal after Buildchain config validation on GitHub-hosted runners\n- block the future reusable promotion job until the same rehearsal accepts the merged promotion event\n\n## Verification\n\n- `./shifu release:promotion:rehearse -- --report /tmp/kungfu-release-promotion-rehearsal.json`\n- `node --test scripts/adr-release-gate.test.mjs scripts/release-promotion-rehearsal.test.mjs`\n- `./shifu docs:check:readonly`\n- `./shifu check`\n- `actionlint` on the four affected workflow contracts\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0073\"],\n  \"summary\": \"Complete side-effect-free alpha/stable promotion rehearsal and Buildchain consumer wiring\",\n  \"verification\": [\"release promotion rehearsal fixtures\", \"actual alpha/stable event tests\", \"full Shifu check\", \"workflow lint\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe preflight has read-only contents permission, receives no promotion secrets, and performs no version, tag, push, publish, or release mutation.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T00:39:36Z",
          "mergedAt": "2026-07-13T00:43:03Z",
          "additions": 986,
          "deletions": 2,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 739,
          "url": "https://github.com/kungfu-systems/kungfu/pull/739",
          "title": "feat(shifu): add cache diagnostics and local profiles",
          "body": "## Summary\n\nAdd schema-governed developer operations for Shifu cache profiles while preserving Atlas as the inventory controller and Buildchain as the process owner. Diagnostics separate configured, resolved, reachable, effective, and cache-hit evidence; resolution never claims a provider hit.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add local-only `shifu cache status` and bounded `shifu cache doctor [--probe]`\n- add dry-run-first `shifu cache use/unset`, limited to a Shifu-owned delimited block with backup/rollback evidence\n- refuse local overwrite of Atlas controller-managed projections\n- add redacted diagnostic/config-plan schemas and contract discovery\n- keep native `shifu doctor --json` compiler cache compatibility and add a separate profile-cache summary\n- document the Atlas/Shifu/Buildchain ownership boundary\n\n## Verification\n\n- `./shifu check` on current `origin/dev/v4/v4.0` (changed-scope gate passed)\n- Shifu cache/runtime suite: 27 passed\n- Rust workspace format, clippy with `-D warnings`, and tests passed\n- Markdown lint, local-link, schema-authority, and tooling type checks passed\n- Mac dogfood: controller projection resolved as `workhub.development`; six selected endpoints reachable with bounded HEAD probes; hit evidence remained `unproven`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Additive developer operations implement the accepted independent SHIFU-ADR-0001 ownership boundary without changing a Core architecture decision or release channel\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\nNo credentials, private inventory, hosted-service identity, package publishing, release evidence, or deployment surface is added. Public fixtures remain private-address free.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T00:53:59Z",
          "mergedAt": "2026-07-13T01:06:53Z",
          "additions": 1018,
          "deletions": 10,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 740,
          "url": "https://github.com/kungfu-systems/kungfu/pull/740",
          "title": "fix(journal): restructure frame_uid to journal-local deterministic id (ADR-0072 P1)",
          "body": "## Summary\n\nADR-0072 Phase 1 — restructure `writer::current_frame_uid()` to a structural,\ncollision-free encoding within one journal: `(page_id << 32) | (in-page frame_nb)`.\nBoth components are persistently monotonic on disk, so a frame's id is\ndeterministically unique within a journal.\n\n## Changes\n\n- Encode `current_frame_uid` as `(page_id << 32) | (frame_nb & 0xFFFFFFFF)`; drop\n  the probabilistic `nano_hashed(writer_start)` salt and the redundant\n  `(source xor dest)` high bits (those fields are already explicit in the header).\n- Rename the `frame_header` field `frame_uid` -> `journal_frame_uid` to version the\n  wire semantics (ADR-0062 rule 4). This advances `journal_format_epoch`\n  (0x869f7bb1 -> 0xe3b24c8d), so old-epoch pages are refused by `page::load`. The\n  `frame_uid()` / `set_frame_uid()` accessor methods are unchanged.\n- The frame checksum and Episode content root read the new value verbatim.\n- `frame_uid` stays journal-local; cross-journal permanent identity remains the\n  Episode content root + `stream_position` layer (ADR-0072 layer 2).\n\n## Verification\n\n- Full `core` build green; 9/9 native ctests pass (mmap, content-hash, durability\n  contract, durable-ingest, crash-recovery, ...).\n- Counterexample harness: the old encoding produced 352 collisions over 300 pages\n  (page 1 collided with page 257 — the 4 GB / 256-page wrap); the new encoding is\n  collision-free (2400/2400 distinct).\n- `journal_format_epoch` confirmed to advance (old-epoch pages refused).\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0072\"],\n  \"summary\": \"ADR-0072 Phase 1: frame_uid becomes deterministically journal-local ((page_id<<32)|frame_nb); journal_format_epoch advances via the frame_header field rename. Phase 2 (ledger-global identity) remains pending.\",\n  \"verification\": [\"Full core build green + 9/9 native ctests pass (mmap/content-hash/durability/durable-ingest/crash-recovery)\", \"Counterexample harness: old encoding 352 collisions over 300 pages, new encoding collision-free\", \"journal_format_epoch advance confirmed\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T01:39:52Z",
          "mergedAt": "2026-07-13T02:01:52Z",
          "additions": 50,
          "deletions": 30,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 735,
          "url": "https://github.com/kungfu-systems/kungfu/pull/735",
          "title": "feat(core): grow embedding membrane v2 with read-only storage fsck",
          "body": "## Summary\n\nGrow the embedding membrane to a versioned ABI v2 that appends a read-only\nsubstrate-diagnostic surface after a byte-identical v1 prefix, and ship a Rust\n`kungfu fsck` over it — `doctor`'s sibling. The first diagnostic entry,\n`storage_fsck`, bridges to the native C++ `storage_service::fsck` and returns\nthe report as a JSON blob plus an `ok`/`degraded` verdict; `report_release`\nfrees the owned buffer. No domain logic is rewritten and CPython is never\nbooted, so the diagnostic survives a broken Python runtime. This delivers the\nADR-0071 Bucket A lever (grow the membrane, don't rewrite commands).\n\n## Changes\n\n- `embedding.h` / `embedding.cpp`: `kf_embedding_api_v2` table (v1 prefix +\n  `storage_fsck` + `report_release`), `KF_EMBEDDING_CAP_STORAGE_DIAGNOSTICS`,\n  request/report structs; `kungfu_embedding_get_api` dispatches v1/v2 by\n  `requested_version`, so v1 callers are unchanged. Windows single-export DLL is\n  untouched — the new functions stay anonymous-namespace statics in the table.\n- `crates/kungfu-embedding`: mirrors the v2 table, negotiates v2-first with a v1\n  fallback, adds an RAII `FsckReport`; compile-time layout guards pin the new\n  struct sizes.\n- `crates/trunk`: a top-level `fsck` command behind the `embedding` feature with\n  a graceful coreless fallback.\n- `slices/shared-embedding-membrane/host.cpp`: the consumer spike now treats\n  v2 as supported (unsupported-version probe uses `ABI_V2 + 1`) and additionally\n  asserts v2 negotiation + the storage-diagnostics capability.\n- `ADR-0071`: `implementation_status` → `partial`; Follow-up records the Bucket A\n  stage delivered and what remains.\n\n## Verification\n\n- `check (macos-14, ubuntu-22.04, windows-2022)`: core build + tests on all three\n  platforms.\n- `Embedding membrane spikes`: exercise v1 and v2 negotiation across POSIX and\n  Windows.\n- `cargo test` / `cargo clippy` for `kungfu-embedding` and `kungfu-trunk` (default\n  and `--features embedding`).\n- Manual macOS `kungfu fsck` run: healthy store `ok=true`/exit 0; degraded store\n  (corrupt projections) warn/exit 0; `--source <missing>` `ok=false`/exit 1;\n  coreless build degrades gracefully.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0071\"],\n  \"summary\": \"Grow the embedding membrane to ABI v2 with a read-only storage fsck diagnostic surface and ship a Rust kungfu fsck consumer over it (ADR-0071 Bucket A lever).\",\n  \"verification\": [\"check (macos-14, ubuntu-22.04, windows-2022) build and tests\", \"Embedding membrane spikes exercise v1 and v2 negotiation across POSIX and Windows\", \"cargo test and clippy for kungfu-embedding and kungfu-trunk in both feature configs\", \"manual macOS fsck run: healthy=ok/exit0, degraded=warn/exit0, source-missing=exit1, coreless=graceful\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T00:30:58Z",
          "mergedAt": "2026-07-13T02:04:49Z",
          "additions": 769,
          "deletions": 22,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 741,
          "url": "https://github.com/kungfu-systems/kungfu/pull/741",
          "title": "docs(adr): unify architecture decision authority",
          "body": "Unify Core and Shifu ADRs under one canonical `docs/adr/` authority while retaining independent namespaces, typed legacy redirects, and equal machine gates. Add deterministic lifecycle, supersession, evidence-debt, and stable-readiness auditing, recorded by ADR-0074.\n\nValidation:\n- `./shifu check`\n- `./shifu docs:check`\n- `./shifu docs:prose:required`\n- `./shifu adr:audit -- --release stable` fails closed with the current 50 blockers\n- `./shifu adr:audit -- --strict` fails closed with the current explicit governance debt\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"implemented\",\"adrs\":[\"ADR-0073\",\"ADR-0074\"],\"summary\":\"Unify all architecture decisions under one release-bearing authority and add complete deterministic auditing.\",\"verification\":[\"./shifu check\",\"./shifu docs:check\",\"./shifu docs:prose:required\"]}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T01:51:04Z",
          "mergedAt": "2026-07-13T02:07:22Z",
          "additions": 15081,
          "deletions": 12984,
          "changedFiles": 212
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 742,
          "url": "https://github.com/kungfu-systems/kungfu/pull/742",
          "title": "chore(node): drop dead MakeInstructionUID helper",
          "body": "## Summary\n\nRemove the dead `MakeInstructionUID` helper (and its `ID_TRANC` / `PAGE_ID_MASK`\nconstants) from the node watcher binding.\n\n## Changes\n\n- `MakeInstructionUID` had no callers anywhere in the repo. It was a trading-era\n  helper that packed a `frame_uid`'s low 32 bits into an instruction id.\n- After the ADR-0072 Phase 1 `frame_uid` restructure, those low bits no longer\n  carry the page id, so the helper was both unused and semantically stale.\n- `ID_TRANC` and `PAGE_ID_MASK` fed only this helper and are removed with it.\n  `TRANSFER_STATIC_DATA_LIMIT` is unrelated and kept.\n\n## Verification\n\n- Full `core` build green (node binding compiles without the removed symbols).\n- Repo-wide grep confirms zero remaining references to `MakeInstructionUID`,\n  `ID_TRANC`, or `PAGE_ID_MASK`.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Removes dead, unreferenced trading-era code (MakeInstructionUID + two constants); no architecture contract change and no ADR file touched.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T02:38:49Z",
          "mergedAt": "2026-07-13T02:40:03Z",
          "additions": 0,
          "deletions": 8,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 743,
          "url": "https://github.com/kungfu-systems/kungfu/pull/743",
          "title": "feat(shifu): make local promotion ancestry-aware",
          "body": "## Summary\n\nUnify Shifu binary self-update and Kungfu product builds/promote around one provenance-aware local artifact contract.\n\nDefault promotion now follows Git history instead of filesystem recency: same or one unique descendant is automatic, while ancestor, divergent, unknown, ambiguous, rollback-only, and invalid artifacts fail closed or require explicit review.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add SHIFU-ADR-0002 plus catalog and redacted promotion-receipt schemas\n- add compact, --no-truncate, --verbose, and --json inventories\n- preserve identifiable feature branch names with middle truncation\n- record branch, canonical repository, worktree, build path, digest, relation, and lifecycle state\n- retire only proven ancestor build slots after successful descendant promotion\n- retain bounded rollback-only Shifu generations outside the candidate pool\n- expose the exact contract through shifu artifacts contract/schema/receipt-schema\n- make Git fixture tests independent of caller hook and repository environment\n\n## Verification\n\n- ./shifu check\n- ./shifu docs:check\n- cargo test --workspace\n- AJV 2020 validation of self-update and builds JSON output\n- isolated XDG fixture: 8c9001c90 is ancestor and 5d3613fc0 is diverged; default promote exits 1\n- isolated linear fixture: unique descendant promotes, writes receipt, and retires only its ancestor\n- isolated self-update fixture: update and rollback both write receipts and preserve rollback-only generations\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0002\"],\n  \"summary\": \"Deliver the shared local artifact catalog and fail-closed ancestry-aware promotion substrate.\",\n  \"verification\": [\"./shifu check\", \"./shifu docs:check\", \"cargo test --workspace\", \"isolated promotion and rollback fixtures\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects only local development artifact provenance and promotion. Receipts omit local paths; full paths remain local diagnostic output.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T02:50:13Z",
          "mergedAt": "2026-07-13T02:53:12Z",
          "additions": 1585,
          "deletions": 111,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 744,
          "url": "https://github.com/kungfu-systems/kungfu/pull/744",
          "title": "feat(profile): qualify user-defined KFD-3 collaboration",
          "body": "## Summary\n\nCompletes the Profile-level KFD-3 qualification path across Agent CLI and typed Human API. A conforming user-defined Profile can now earn, export, import, and independently verify a content-bound qualification receipt and witness. The same shared intent protocol drives inspect, advise, preview, authorize, execute, receipt, and verify. Unsupported custom execution surfaces fail closed.\n\nAlso proves an independent Week/Day Profile through both clients, verifies upgrade and rollback invalidation, and repairs Shifu directory-build registration so the exact Product can be promoted without a DMG.\n\n## Verification\n\n- ./shifu test:kfx-profile-suite\n- ./shifu --filter @kungfu-tech/api run test:query\n- ./shifu test:profile-kfd3-qualification\n- ./shifu docs:check\n- ./shifu kfd:buildchain:check\n- cargo test --workspace\n- staged repository gate\n- ./shifu dist:dir\n- shifu build registration and promote of clean 746bfafb0\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0075\"],\n  \"summary\": \"Qualify conforming user-defined Profiles for shared Human and Agent KFD-3 collaboration\",\n  \"verification\": [\"independent Week Day dual-client proof\", \"portable receipt and witness verification\", \"upgrade and rollback invalidation\", \"exact Product directory build and promote\"]\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n\nNo public release channel is promoted by this PR. The exact local Product directory build was promoted for dogfood.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T02:56:25Z",
          "mergedAt": "2026-07-13T03:06:06Z",
          "additions": 3092,
          "deletions": 113,
          "changedFiles": 45
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 745,
          "url": "https://github.com/kungfu-systems/kungfu/pull/745",
          "title": "docs: establish canonical directory hierarchy",
          "body": "## Summary\n\nEstablish a canonical public documentation hierarchy organized by maintenance authority, while preserving the former flat paths as typed compatibility redirects.\n\n## Changes\n\n- move 46 canonical documents into seven responsibility directories\n- add section indexes and update every repository, metadata, KFD, and publication reference\n- add executable hierarchy and redirect contracts with negative fixtures\n- record ADR-0076 as accepted and implemented\n\n## Verification\n\n- ./shifu docs:check\n- ./shifu docs:prose:required\n- ./shifu check\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0076\"],\n  \"summary\": \"Canonical hierarchy, compatibility facade, and deterministic placement gates are implemented\",\n  \"verification\": [\"./shifu docs:check\", \"./shifu docs:prose:required\", \"./shifu check\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T03:03:03Z",
          "mergedAt": "2026-07-13T04:04:31Z",
          "additions": 12559,
          "deletions": 11236,
          "changedFiles": 178
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1144,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1144",
          "title": "feat(check): add source lifecycle mode",
          "body": "## Summary\n\n- add an opt-in `mode: source` to the reusable check workflow\n- run only `lifecycle.install` and `lifecycle.check` on GitHub-hosted Linux\n- preserve the default `install + verify` behavior and stable `check` job name\n- add a fixture regression proving build and verify are not executed\n\nCloses #1143\n\n## Validation\n\n- workflow structure check\n- inventory check\n- source-check fixture smoke\n- `git diff --check`\n\nFull repository checks run in protected PR CI.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T04:10:04Z",
          "mergedAt": "2026-07-13T04:18:46Z",
          "additions": 127,
          "deletions": 31,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1145,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1145",
          "title": "chore(release): promote source-check lifecycle alpha",
          "body": "## Release intent\n\nPromote the reviewed #1143 source-check lifecycle capability from `dev/v2/v2.12` to the v2.12 alpha channel.\n\n## Included capability\n\n- opt-in reusable check `mode: source`\n- GitHub-hosted `install + check` execution without build or verify\n- backward-compatible default verify mode\n- fixture regression and generated public surface updates\n\n## Validation\n\n- implementation PR #1144 merged with protected checks passing\n- alpha promotion dry-run confirms only alpha refs and prerelease publication move\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T04:19:19Z",
          "mergedAt": "2026-07-13T04:21:54Z",
          "additions": 127,
          "deletions": 31,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 746,
          "url": "https://github.com/kungfu-systems/kungfu/pull/746",
          "title": "docs: remove pre-release compatibility paths",
          "body": "## Summary\n\nMake the responsibility-based documentation hierarchy the only repository path surface before the first alpha release.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- remove all 46 flat `docs/*.md` compatibility files\n- remove the ordinary-document redirect metadata profile and validator branches\n- make `docs/README.md` and `docs/MAP.md` the only root Markdown entries\n- revise ADR-0076 to record the pre-release clean-path decision\n- retain and strengthen negative gates that reject canonical ADRs under `framework/core/docs/adr/` and `docs/shifu/adr/`\n\n## Verification\n\n- `./shifu docs:check` (277 Markdown files; 62 tests passed)\n- `./shifu docs:prose:required` (148 files; 0 findings)\n- `./shifu check` (changed-scope gate passed)\n- conservation audit: 46 redirects removed, 0 missing canonical targets\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0076\"],\n  \"summary\": \"Remove speculative pre-release compatibility paths and make the documentation root contract absolute\",\n  \"verification\": [\"./shifu docs:check\", \"./shifu docs:prose:required\", \"./shifu check\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T04:32:49Z",
          "mergedAt": "2026-07-13T04:36:18Z",
          "additions": 106,
          "deletions": 937,
          "changedFiles": 56
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 747,
          "url": "https://github.com/kungfu-systems/kungfu/pull/747",
          "title": "docs(adr): confirm ADR-0072 Phase 2 sequence assignment authority",
          "body": "Confirm ADR-0072 Phase 2 — authoritative ledger-global identity. Phase 2 is a\nspecification milestone (no new runtime code): the durable tier's persisted\nwatermark already is the crash-safe, monotonic authority for\nstream_position.sequence. This PR names that authority, states the contract any\nfuture live producer must follow, confirms ledger consumers key on the Episode\ncontent root + stream_position (not frame_uid), and pins the crash-safe\nmonotonic assignment guarantee with a durable_ingest regression test.\n\n<!-- kungfu-adr-release:v1 {\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"ADR-0072\"],\"summary\":\"Confirm and document ADR-0072 Phase 2: the durable-tier persisted watermark is the crash-safe monotonic authority for stream_position.sequence; stream_id/container_epoch are container identity fixed at stream open; ledger consumers key on Episode content root + stream_position, not frame_uid.\",\"verification\":[\"durable_ingest_tests.cpp new test 'sequence assignment authority is crash-safe and monotonic (ADR-0072 Phase 2)': built + ran all 28 durable_ingest tests, exit 0\",\"scripts/run-docs-check.mjs: deterministic documentation gate passed (markdownlint, links/anchors, adr-audit, release contract)\",\"scripts/document-metadata-contract.mjs on ADR-0072: exit 0\"]} -->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T04:36:45Z",
          "mergedAt": "2026-07-13T04:41:55Z",
          "additions": 118,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 750,
          "url": "https://github.com/kungfu-systems/kungfu/pull/750",
          "title": "docs: retire framework core documentation root",
          "body": "## Summary\n\nMake `docs/` the single repository authority for public design, qualification, development, and ADR documentation before the first alpha release.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- move seven surviving Core documents into the canonical `docs/` taxonomy\n- move four mmap evidence records into `docs/qualification/evidence/mmap/` without changing their bytes\n- remove 75 Core/Shifu ADR compatibility Markdown files and the redirect metadata profile\n- reject any Markdown reintroduced under `framework/core/docs/` or `docs/shifu/adr/`\n- update section indexes, metadata authorities, ADRs, source comments, and all canonical links\n\n## Verification\n\n- `./shifu docs:check` (202 governed Markdown files; 59 tests passed)\n- `./shifu docs:prose:required` (153 files; 0 errors, warnings, or suggestions)\n- `./shifu check` (changed-scope gate passed, including Rust workspace tests, Python KFX contract tests, Node/TypeScript tests, and documentation contracts)\n- `git diff --check`\n- conservation audit: seven Markdown renames detected; four JSON evidence files are byte-identical; retired roots contain zero files\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0074\", \"ADR-0076\"],\n  \"summary\": \"Retire secondary documentation roots, conserve real content under the canonical taxonomy, and fail closed on path reintroduction\",\n  \"verification\": [\"./shifu docs:check\", \"./shifu docs:prose:required\", \"./shifu check\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T04:53:50Z",
          "mergedAt": "2026-07-13T04:55:35Z",
          "additions": 170,
          "deletions": 1389,
          "changedFiles": 113
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 670,
          "url": "https://github.com/kungfu-systems/kungfu/pull/670",
          "title": "chore(ci): drop dead source-mode mirror config and orphan checks.json",
          "body": "<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Dead-config cleanup: removes an unreachable CI source-mode mirror branch and an orphan root config file; no architecture contract or runtime behavior change.\"\n}\n-->\n\nDead-config cleanup (zero behavior change), from a dead-code survey.\n\n- **`embedding-membrane-spike.yml`**: the matrix only ever sets\n  `source_mode: github`, so the `if [ \"$SOURCE_MODE\" = \"mirror\" ]` reconstruct\n  branch never runs and its `MIRROR_REF` / `MIRROR_URL` env are unreachable —\n  removed. The live github reconstruct path and `MIRROR_BASE_SHA` (still used)\n  are unchanged; the full native matrix on this PR revalidates the step.\n- **`checks.json`** (repo root, `{\"enabled\":true,\"categories\":{}}`, dated 2023):\n  no reference anywhere in the repo — removed.\n\nScope is intentionally minimal: the vestigial always-true `source_mode == 'github'`\nguards are left in place (a larger simplification is tracked separately), and\nall code-level dead-code candidates are deferred to a review card.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T11:45:22Z",
          "mergedAt": "2026-07-13T05:05:40Z",
          "additions": 0,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1146,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1146",
          "title": "fix(check): expose source mode to lifecycle stages",
          "body": "## Summary\n\n- expose the selected check mode to consumer install and check lifecycle stages\n- fetch complete consumer history for source-mode merge-base checks\n- document and test the source-mode lifecycle contract\n\n## Validation\n\n- `node --test tests/build-surface.test.mjs`\n- `corepack pnpm@11.7.0 run check` (553 tests passed)\n- `git diff --check`\n\n## Safety boundary\n\nThe source mode still executes only `lifecycle.install` and `lifecycle.check`; verify-mode behavior remains unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T04:49:30Z",
          "mergedAt": "2026-07-13T05:08:38Z",
          "additions": 67,
          "deletions": 36,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1147,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1147",
          "title": "chore(release): promote source acceptance gate alpha",
          "body": "## Release intent\n\nPromote the reviewed source-acceptance lifecycle fixes from `dev/v2/v2.12` to the supported v2 alpha channel after consumer black-box qualification.\n\n## Included capability\n\n- propagate `BUILDCHAIN_CHECK_MODE` to consumer install and check stages\n- fetch complete consumer history in source mode for exact merge-base checks\n- preserve verify-mode behavior and the existing promotion lifecycle\n\n## Qualification\n\n- implementation PR #1146 merged with all protected checks passing\n- Kungfu consumer PR #751 passed `Source acceptance / check` on GitHub-hosted Ubuntu 24.04\n- consumer run used `fetch-depth: 0`, resolved the exact PR revision, and completed only install + check\n- local Buildchain suite passed 553 tests",
          "author": "dongkeren",
          "createdAt": "2026-07-13T05:09:30Z",
          "mergedAt": "2026-07-13T05:11:50Z",
          "additions": 67,
          "deletions": 36,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 751,
          "url": "https://github.com/kungfu-systems/kungfu/pull/751",
          "title": "feat(ci): require build-free source acceptance",
          "body": "## Summary\n\nRequire every development pull request to pass a GitHub-hosted, build-free source acceptance gate before merge.\n\n## Related issue\n\n- kungfu-systems/buildchain#1143\n- kungfu-systems/buildchain#1146\n\n## Changes\n\n- add a Buildchain reusable-workflow caller in `mode: source` for every dev PR\n- add a source-only lifecycle install that provisions Node dependencies and pinned wheel-based static analyzers without compiler or build tooling\n- add exact-revision source checks for formatting, lint, type, schema, documentation, and repository contracts\n- fail closed off GitHub-hosted Linux and test that source plans cannot enter build, compiler, artifact, verify, publish, or release lifecycles\n- retire the narrower Python-only Dev Check while preserving promotion install/build/verify behavior\n\n## Verification\n\n- `./shifu check:source`\n- `node --test scripts/buildchain-install.test.mjs scripts/source-acceptance.test.mjs`\n- Buildchain config validation requiring `install,check,build,verify`\n- `actionlint .github/workflows/source-acceptance.yml .github/workflows/buildchain-validate.yml`\n- `bash -n shifu`\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This CI admission fix closes an implementation gap without altering an accepted architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects pull-request admission and Buildchain lifecycle routing only. It introduces no credentials, publication action, or product artifact.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T04:58:24Z",
          "mergedAt": "2026-07-13T06:05:01Z",
          "additions": 529,
          "deletions": 103,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 752,
          "url": "https://github.com/kungfu-systems/kungfu/pull/752",
          "title": "docs(brand): explain Kungfu recursive meaning",
          "body": "## Summary\n\nAdd a progressively disclosed explanation of the Kungfu name and its recursive technical meaning without increasing first-contact product complexity.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add `Never Guess. Facts Unfold.` as the concise README brand principle\n- add a short README route to the deeper brand explanation\n- add `docs/concepts/why-kungfu.md` for the historical origin, recursive definition, semantic boundaries, and architecture mapping\n- register the document in the Concepts guide, documentation guide, map, and metadata registry\n\n## Verification\n\n- `./shifu docs:check`\n- `./shifu docs:prose:required`\n- pre-commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This documentation change explains the existing product philosophy and architecture without changing an architecture contract, release claim, or product identity.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBranding boundary: `UNGFU` is explicitly described as a recursive definition, not a new product, runtime, package, or registration claim. The original Chinese origin remains explicit.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T05:50:48Z",
          "mergedAt": "2026-07-13T06:10:08Z",
          "additions": 163,
          "deletions": 3,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 674,
          "url": "https://github.com/kungfu-systems/kungfu/pull/674",
          "title": "chore(core): remove unreferenced Python dead code",
          "body": "<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Removes three unreferenced Python modules (dead code); no architecture contract or runtime behavior change.\"\n}\n-->\n\nThree Python modules with **no importer anywhere in the repo** (whole-repo grep;\nthe package uses no star-imports, so the import graph is reliable):\n\n- `cli/utils.py` (`safe_import`)\n- `runtime/sinks/csv.py` (`CsvSink` / `open_csv_sink`) — the sinks layer is\n  retired; the sibling `archive.py` is already gone and is guarded out by the\n  ADR-0055/0056 journal-authority boundary. `csv.py` is not itself on that\n  guard's forbidden list, so removing it is clean.\n- `runtime/data/adapter.py` (`Adapter`) — a legacy data-export remnant.\n\n156 deletions, no behavior change. Dev Check (mypy + ruff) validates the package\nstill type-checks. From a dead-code survey; higher-risk C++/TS candidates are\ntracked separately under a review card.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:17:05Z",
          "mergedAt": "2026-07-13T06:15:58Z",
          "additions": 0,
          "deletions": 156,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 753,
          "url": "https://github.com/kungfu-systems/kungfu/pull/753",
          "title": "fix(ci): keep native membrane builds out of dev PRs",
          "body": "## Summary\n\nKeep native three-platform membrane builds on alpha/release promotion PRs instead of ordinary dev PRs.\n\n## Changes\n\n- move the `Embedding membrane spikes` matrix from `dev/v*/v*` to `alpha/v*/v*` and `release/v*/v*`\n- add a source-acceptance regression test that rejects restoring the native matrix as a dev PR gate\n\n## Verification\n\n- `./shifu check:source`\n- pre-commit staged gate\n- `node --test scripts/source-acceptance.test.mjs`\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This CI routing fix enforces the existing development source-acceptance contract without changing product architecture.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change only narrows pull-request workflow routing. It does not build or publish an artifact.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and regression coverage updated\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T06:23:15Z",
          "mergedAt": "2026-07-13T06:27:40Z",
          "additions": 13,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1148,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1148",
          "title": "fix(release): fail closed on GraphQL promotion errors",
          "body": "## Summary\n- fail closed when GitHub returns GraphQL errors in an HTTP 200 promotion response\n- document the repository approval and auto-merge capabilities required by Stable Candidate Patrol\n- refresh the generated public site contract\n\n## Why\nThe latest Patrol run opened the exact-source stable PR, but the repository had auto-merge disabled. GitHub returned the refusal in a GraphQL `errors` payload while the HTTP request itself returned 200, so the client incorrectly continued to the later approval step.\n\n## Validation\n- `node --test tests/stable-candidate-patrol.test.mjs`\n- `pnpm run check` (554 tests passed)\n- `git diff --check`\n\nThis change does not weaken branch protection or publish a release.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T06:32:07Z",
          "mergedAt": "2026-07-13T06:33:45Z",
          "additions": 47,
          "deletions": 7,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 35,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/35",
          "title": "feat(homepage): add recursive Kungfu brand principle",
          "body": "## Summary\n\n- keep the consumer-facing Cost / State / Proof promise dominant on the homepage\n- add `Never Guess. Facts Unfold.` as a secondary Kungfu brand principle\n- add a dedicated `Why Kungfu?` page with the honest Chinese origin, recursive definition, and project obligation\n- extend site checks to protect the new route and semantic boundaries\n\n## Validation\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash -n scripts/build-site.sh`\n- `bash -n scripts/check-site.sh`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `git diff --check`\n- Playwright desktop 1440x900 and mobile 390x844; 0 console errors and 0 warnings\n\n## Release boundary\n\nThis PR updates the normal site mainline and staging path. It does not approve or trigger the separately gated production release.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T06:33:01Z",
          "mergedAt": "2026-07-13T06:37:03Z",
          "additions": 296,
          "deletions": 3,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 37,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/37",
          "title": "Release production from 118357b6c055",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `118357b6c055b7481f02baf1da8ef66447bc254b`\n- Artifact hash: `b0f0cde6538b7a705748dd2d5ee2d36ee3f8b04b87e1f5e3fbef810f0aa7f90a`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29229523725)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-118357b6c055`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-13T06:39:06Z",
          "mergedAt": "2026-07-13T06:42:00Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 754,
          "url": "https://github.com/kungfu-systems/kungfu/pull/754",
          "title": "feat(runtime): fold interrupted Episodes into recovery",
          "body": "## Summary\n- compose the existing typed Storage/Episode qualification result into crash-recovery reports\n- classify retained open Episodes as DEGRADED and invalid/unknown Episode evidence as BLOCKED\n- preserve read-only inspection, full report repeatability, and closed-Episode isolation\n- supersede #720 with an equivalent single-parent commit because the repository only permits rebase merge\n\n## Verification\n- `./shifu check:source`\n- direct `kungfu_crash_recovery_tests` execution: 10 passed\n- direct `kungfu_durable_ingest_tests` execution: 25 passed\n- direct `kungfu_projection_bootstrap_tests` execution: 13 passed\n- `git diff --check`\n- `build:core` compiled and linked all three target binaries; the aggregate build then stopped on the unrelated dev-baseline `view_encapsulation_probe` SQLite link defect\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Fold interrupted Episode qualification into deterministic read-only crash recovery\",\n  \"verification\": [\"crash-recovery contracts\", \"durable-ingest contracts\", \"projection-bootstrap contracts\", \"build-free source acceptance\"]\n}\n-->\n\n## Boundaries\n- no automatic Episode abort/resume or other mutation\n- no second lifecycle/capability vocabulary and no JSON service currency\n- no workflow, Buildchain, artifact, or release-path changes\n- export/empty-root restore and projection rebuild equality remain later recovery stages\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR updates ADR delivery evidence only; it does not modify workflows, publish artifacts, or deploy anything.\n\n## Checklist\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T06:45:45Z",
          "mergedAt": "2026-07-13T06:46:56Z",
          "additions": 216,
          "deletions": 16,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 755,
          "url": "https://github.com/kungfu-systems/kungfu/pull/755",
          "title": "feat(shifu): enforce uv cache with disposable effective locks",
          "body": "## Summary\n\nMake strict Shifu cache profiles enforce the selected Python index without rewriting tracked uv.lock files or exposing private network topology in public source.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- create process-private effective uv lock and environment overlays for cache-managed execution\n- preserve dependency semantics and fail closed when strict rebinding cannot be proven\n- require every tracked uv.lock URL to use official PyPI hosts\n- preserve explicit Buildchain and runner cache projections across shell, Windows, and native config loading\n- emit redacted digest-only tool evidence and cleanup state\n\n## Verification\n\n- `node scripts/source-acceptance.mjs`\n- `cargo clippy --workspace --all-targets -- -D warnings`\n- `cargo test --workspace`\n- strict self-hosted profile dry-run on Ubuntu and agent-120\n- full `shifu sync && shifu check:source` on agent-120 with canonical lock SHA and Git status unchanged\n- development profile execution on macOS with canonical lock SHA and Git status unchanged\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0003\"],\n  \"summary\": \"Implement disposable uv effective locks, official-PyPI canonical lock policy, and strict cache enforcement\",\n  \"verification\": [\"source acceptance\", \"Rust workspace tests\", \"macOS development profile\", \"Ubuntu and agent-120 strict profile\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe ADR and receipt define public evidence boundaries; receipts contain digests and counts, while repository locks remain restricted to official PyPI hosts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:02:26Z",
          "mergedAt": "2026-07-13T07:07:37Z",
          "additions": 1545,
          "deletions": 50,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1149,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1149",
          "title": "fix(release): support independent Patrol approvals",
          "body": "Patrol currently depends on the caller GITHUB_TOKEN for protected-branch approval. Organization policy can block that capability even when the workflow requests pull-request write permission.\\n\\nThis change adds an optional independent approval token to the reusable workflow, maps Buildchain dogfood to a dedicated repository secret, keeps the caller token fallback for repositories whose policy permits it, and documents both supported approval paths.\\n\\nValidation:\\n- pnpm run check\\n- 554 tests passed\\n- workflow validation passed\\n- generated site drift check passed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:11:19Z",
          "mergedAt": "2026-07-13T07:13:21Z",
          "additions": 30,
          "deletions": 16,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 756,
          "url": "https://github.com/kungfu-systems/kungfu/pull/756",
          "title": "chore(core): remove the unreferenced nanomsg webserver module",
          "body": "<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Removes the unreferenced kungfu::webserver module (dead code compiled into libkungfu only via GLOB); no architecture contract or runtime behavior change.\"\n}\n-->\n\n`kungfu::webserver` — `runtime/nanomsg/webserver.h` (331) + `runtime/util/webserver.cpp` (537), ~868 lines: `web_agent`, `stream`, `session`, `websocket_client`, `websocket_server`, `http_server` and helpers — has **no reference anywhere in the repo** (verified by whole-repo grep of every symbol and the include path). It is compiled into libkungfu only because it sits under a `file(GLOB_RECURSE)` source list, and **no ADR keeps it as a planned surface**; it was left disconnected when the master/coordinator transport was reworked.\n\nRemoved both files. No behavior change — nothing links against these symbols. From a dead-code survey (owner-confirmed removal).",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:04:28Z",
          "mergedAt": "2026-07-13T07:14:16Z",
          "additions": 0,
          "deletions": 868,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1150,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1150",
          "title": "fix(release): bind Patrol approval authority",
          "body": "Bind Buildchain's Patrol dogfood caller to the dedicated approval secret when configured and otherwise reuse the existing organization release authority secret. The reusable workflow still keeps the caller GITHUB_TOKEN fallback for external consumers.\n\nValidation:\n- node --test tests/build-surface.test.mjs (71 passed)\n- pnpm run check:workflows",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:16:55Z",
          "mergedAt": "2026-07-13T07:18:59Z",
          "additions": 5,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1142,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1142",
          "title": "Release v2.12.1 from qualified v2.12.1-alpha.9",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.12.1-alpha.9`\n- Candidate SHA: `41dc500ec951422c0da87d36a9e6f03dafcd181c`\n- Selection: `latest-qualified`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.12`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T20:04:42Z",
          "mergedAt": "2026-07-13T07:20:48Z",
          "additions": 3543,
          "deletions": 270,
          "changedFiles": 62
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 759,
          "url": "https://github.com/kungfu-systems/kungfu/pull/759",
          "title": "fix(shifu): remove private cache address from fixture",
          "body": "## Summary\n\nRemove an office-private cache address from a public Shifu test fixture and replace it with reserved `.local` fixture hosts. The test continues to cover rejection of private and non-PyPI transports without disclosing real topology.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- replace the real private cache coordinate with `package-cache.local`\n- keep private registry and artifact rejection assertions unchanged\n\n## Verification\n\n- `node --test scripts/shifu-uv-cache-adapter.test.mjs`\n- `node scripts/check-shifu-cache-contract.mjs`\n- pre-commit documentation, contract, and Biome gates\n- public fixture scan confirms the office address is absent\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This privacy fix changes only test fixture coordinates and does not alter the accepted cache enforcement architecture\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:21:22Z",
          "mergedAt": "2026-07-13T07:23:03Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 761,
          "url": "https://github.com/kungfu-systems/kungfu/pull/761",
          "title": "feat(runtime): add verified backup restore round trip",
          "body": "## Summary\n- export only an exclusively owned, twice-verified READY recovery cut with explicit frontier and RPO evidence\n- bind authoritative file bytes, sealed Episode content roots, and verified payload hashes while excluding ownership, quarantine, receipts, and derived projections\n- restore into an empty or byte-identical partial data root, publish the receipt last, and require projection rebuild to the same typed state, cut, and integrity hash\n- supersede #758 and #760 with the same stable patch on the latest dev parent because branch protection requires an up-to-date, rebaseable head\n\n## Verification\n- `./shifu check:source`\n- direct `kungfu_crash_recovery_tests` execution: 13 passed\n- direct `kungfu_durable_ingest_tests` execution: 28 passed\n- direct `kungfu_projection_bootstrap_tests` execution: 13 passed\n- focused CMake build of all three test targets with the pinned C++23 toolchain\n- stable patch id matches #758 exactly: `bbd948d26fea83c87dfa2c5a0ebf08a7e0d689b5`\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Add consistent backup, empty-root verified restore, and projection rebuild equality\",\n  \"verification\": [\"crash-recovery contracts\", \"durable-ingest contracts\", \"projection-bootstrap contracts\", \"build-free source acceptance\"]\n}\n-->\n\n## Boundaries\n- no workflow, Buildchain, artifact, release, or self-hosted runner changes\n- no production durability or sudden-power-loss claim; the API remains test-only and in-process\n- no external archive format, operator backup command, remote replication, or automatic failover\n- production bootstrap cutover and named platform/filesystem qualification remain later stages\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR updates ADR delivery evidence only; it does not modify workflows, publish artifacts, or deploy anything.\n\n## Checklist\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:25:54Z",
          "mergedAt": "2026-07-13T07:27:27Z",
          "additions": 857,
          "deletions": 21,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 762,
          "url": "https://github.com/kungfu-systems/kungfu/pull/762",
          "title": "feat(shifu): add gate control plane contract",
          "body": "## Summary\n\nAdd the project-neutral Shifu Gate v1 contract and a read-only control surface for validating, explaining, comparing, and planning project gates.\n\n## Related issue\n\nSHIFU-ADR-0004\n\n## Changes\n\n- define strict registry and deterministic plan schemas for light and heavy gates\n- add `shifu gate validate|list|show|explain|matrix|plan`\n- route Gate commands through native, POSIX, and Windows launchers without changing task aliases\n- document the Shifu/project/Buildchain authority boundary and register the additive KFD-1 surface update\n- add valid/invalid fixtures, semantic checks, JSON Schema conformance, and source acceptance coverage\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu check`\n- native `./shifu gate validate` and `./shifu gate plan` smoke\n- `bash -n shifu`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Complete the Gate v1 contract, read-only CLI, validation, deterministic planning, documentation, and source gates without execution or CI migration\",\n  \"verification\": [\"./shifu check:source\", \"./shifu check\", \"native shifu gate smoke\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change defines future gate evidence metadata but does not execute gates, publish artifacts, modify branch protection, or perform a release.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:38:49Z",
          "mergedAt": "2026-07-13T07:41:47Z",
          "additions": 2045,
          "deletions": 9,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 67,
          "url": "https://github.com/kungfu-systems/build-images/pull/67",
          "title": "fix(release): adopt Buildchain v2.12 dual-channel contract",
          "body": "## Summary\n\n- migrate verification to the standard Buildchain `build.yml@v2` channel router\n- route development and alpha work through `v2-alpha`, while release work stays on stable `v2`\n- lock both channels independently and bind both locks into KFD123 evidence\n- upgrade the consumer package to Buildchain 2.12.1\n- install CM-Super scalable Type1 fonts so microtype expansion works with the default T1 LaTeX setup\n\n## Validation\n\n- `pnpm run check`\n- `actionlint .github/workflows/*.yml`\n- `shellcheck scripts/*.sh images/*/tests/*.sh`\n- alpha and stable router selection checks\n- exact alpha and stable contract-lock checks\n- local amd64 LaTeX image build and microtype PDF smoke test\n\n## Release impact\n\nPatch release. The existing image families and consumer-facing tag policy remain unchanged.\n\n## Follow-up\n\nBuildchain cannot yet fail closed on post-publish OCI family completeness because image digests are only known inside the consumer publish lifecycle. The capability request is tracked in kungfu-systems/buildchain#1151; this release keeps the currently validated publish evidence and Release Passport path.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:42:48Z",
          "mergedAt": "2026-07-13T07:50:07Z",
          "additions": 338,
          "deletions": 159,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 764,
          "url": "https://github.com/kungfu-systems/kungfu/pull/764",
          "title": "feat(runtime): complete crash recovery restart contract",
          "body": "## Summary\n- report sealed non-ok Episode findings without misnaming them as interrupted or contaminating independent Episodes\n- enforce supervisor -> state service -> projection -> required peers through a typed fail-closed restart authorization gate\n- resume only exact interrupted quarantine packages and reject extra retained evidence before mutation\n- verify durable facts, sealed Episode identity, projection cut, and peer authorization by reopening the whole data root in a fresh process\n\n## Verification\n- `./shifu check:source`\n- `./shifu test:crash-recovery`: 15 focused cases plus fresh-process whole-data-root reopen passed\n- `./shifu test:durable-ingest`: 28 focused cases plus cross-process writer attestation passed\n- `./shifu test:projection-bootstrap`: 10 focused cases plus cross-process projection restart passed\n- independent Episode semantic oracle: 48 bounded histories passed\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Complete the deterministic single-host crash-recovery restart contract\",\n  \"verification\": [\"crash-recovery contracts\", \"whole-data-root process restart\", \"Episode semantic oracle\", \"build-free source acceptance\"]\n}\n-->\n\n## Boundaries\n- no workflow, Buildchain, artifact, release, or self-hosted runner changes\n- no production durability or sudden-power-loss claim; these contracts remain test-only\n- no destructive authoritative repair, remote replication, or automatic failover\n- named platform/filesystem qualification remains the next independent child goal\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR updates ADR delivery evidence only; it does not modify workflows, publish artifacts, or deploy anything.\n\n## Checklist\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:49:20Z",
          "mergedAt": "2026-07-13T07:50:57Z",
          "additions": 360,
          "deletions": 18,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 69,
          "url": "https://github.com/kungfu-systems/build-images/pull/69",
          "title": "chore(alpha): reconcile v1.2 channel history",
          "body": "## Summary\n\nRecord the current alpha head as an ancestor of the v1.2 development line while preserving the verified development tree exactly.\n\nThis removes historical release-state divergence before the next protected `dev/v1/v1.2` to `alpha/v1/v1.2` promotion. The merge uses the current dev tree and contains no product-content changes.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:51:55Z",
          "mergedAt": "2026-07-13T07:53:41Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 68,
          "url": "https://github.com/kungfu-systems/build-images/pull/68",
          "title": "chore(alpha): promote Buildchain v2.12 dual-channel release",
          "body": "## Summary\n\nPromote the verified v1.2 development line to alpha with:\n\n- the standard Buildchain v2.12 dual-channel workflow\n- independent `v2-alpha` and stable `v2` contract locks\n- pnpm lifecycle execution through Corepack\n- CM-Super scalable fonts for default microtype expansion\n- KFD123 evidence and Release Passport publication enabled\n\n## Promotion plan\n\nAfter the first alpha image family is published, its exact public digests will be reviewed into `images.lock.json` before stable promotion.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:50:54Z",
          "mergedAt": "2026-07-13T07:55:32Z",
          "additions": 339,
          "deletions": 160,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 70,
          "url": "https://github.com/kungfu-systems/build-images/pull/70",
          "title": "chore(images): lock v1.2.1-alpha.3 digests",
          "body": "## Summary\n\n- accept the exact public digests published by Buildchain run 29233734962\n- bind `images.lock.json` to source `031a9c9` and tag `v1.2.1-alpha.3`\n- add an explicit `sfrm1000.pfb` probe to the LaTeX manifest and consumer smoke contract\n- refresh deterministic KFD123 evidence\n\nAll five alpha images were anonymously pulled and smoked by the publish transaction. The locked LaTeX digest contains CM-Super and successfully compiled the microtype expansion smoke document.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:04:43Z",
          "mergedAt": "2026-07-13T08:06:28Z",
          "additions": 32,
          "deletions": 30,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 71,
          "url": "https://github.com/kungfu-systems/build-images/pull/71",
          "title": "chore(alpha): promote locked v1.2.1 candidate",
          "body": "## Summary\n\nPromote the reviewed v1.2.1 alpha image lock and explicit scalable-font probe to the alpha channel.\n\nThe accepted `v1.2.1-alpha.3` digests passed anonymous consumer smoke, including `kpsewhich sfrm1000.pfb` and the microtype PDF build. This promotion produces the final alpha candidate before stable release.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:06:44Z",
          "mergedAt": "2026-07-13T08:09:19Z",
          "additions": 32,
          "deletions": 30,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 73,
          "url": "https://github.com/kungfu-systems/build-images/pull/73",
          "title": "chore(release): reconcile v1.2 channel history",
          "body": "## Summary\n\nRecord the current stable v1.2 release head as an ancestor of the verified alpha line while preserving the alpha tree exactly.\n\nThis is a zero-content channel-history reconciliation required before the protected `alpha/v1/v1.2` to `release/v1/v1.2` promotion can merge cleanly. It does not change the accepted image lock or product files.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:19:30Z",
          "mergedAt": "2026-07-13T08:21:27Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 74,
          "url": "https://github.com/kungfu-systems/build-images/pull/74",
          "title": "chore(release): sync v1.2 channel ancestry to dev",
          "body": "## Summary\n\nSync the release-channel ancestry reconciliation from alpha back into the v1.2 development line without changing the product tree.\n\nThe next alpha publication must originate from a protected `dev/v1/v1.2` to `alpha/v1/v1.2` PR. This sync makes that forward promotion possible while preserving the accepted image lock and candidate content exactly.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:24:27Z",
          "mergedAt": "2026-07-13T08:26:56Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 76,
          "url": "https://github.com/kungfu-systems/build-images/pull/76",
          "title": "chore(alpha): publish reconciled v1.2.1 candidate",
          "body": "Promote the reconciled v1.2 development channel through the standard Buildchain v2.12 alpha lane.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:29:20Z",
          "mergedAt": "2026-07-13T08:31:05Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 765,
          "url": "https://github.com/kungfu-systems/kungfu/pull/765",
          "title": "feat(shifu): execute gates with source-bound receipts",
          "body": "## Summary\n\nAdd the Shifu Gate execution and receipt layer so registered gates can be run individually or by profile, with source-bound evidence that downstream policy can validate and reuse.\n\n## Related issue\n\nSHIFU-ADR-0004\n\n## Changes\n\n- add `shifu gate run` for explicit diagnostic selections and full profile execution\n- execute dependency-closed gates through native Shifu tasks, argv actions, or named handlers\n- emit strict Gate receipt v1 evidence with source, definition, action, artifact, coverage, and integrity bindings\n- add `shifu gate receipt validate` with fail-closed freshness and qualification checks\n- preserve advisory visibility while blocking required failures, skips, unsupported capabilities, timeouts, stale source, and incomplete evidence\n- redact paths, URLs, secrets, child output, and inherited environment values from receipts\n- cover POSIX and Windows launcher construction plus real existing-task dogfood\n\n## Verification\n\n- `./shifu check`\n- `./shifu check:source`\n- `./shifu gate run --profile task-dogfood --registry docs/shifu/examples/gates/execution.gate-registry.json --receipt build/gate-receipts/task-dogfood-clean.json --overwrite`\n- `./shifu gate receipt validate build/gate-receipts/task-dogfood-clean.json --registry docs/shifu/examples/gates/execution.gate-registry.json --json` returned valid/current/qualifying true\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Complete the Gate v1 execution and source-bound receipt stage without migrating Kungfu gate catalogs or release workflows\",\n  \"verification\": [\"./shifu check\", \"./shifu check:source\", \"clean-source qualifying Gate receipt dogfood\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis stage defines and validates reusable gate evidence. It does not migrate release workflows, publish artifacts, modify branch protection, or perform a release. Receipt tests explicitly prove that secret-like values, inherited environment values, child output, URLs, and absolute paths are not retained.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:28:06Z",
          "mergedAt": "2026-07-13T08:31:29Z",
          "additions": 2041,
          "deletions": 24,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 766,
          "url": "https://github.com/kungfu-systems/kungfu/pull/766",
          "title": "feat(profile): productize KFD-3 qualification badges",
          "body": "## Summary\n\nLinear replacement for #749. The repository permits rebase merges only, while #749 contains a dev merge commit that GitHub cannot rebase. This branch is a single signed-off commit whose tree is byte-for-byte identical to the fully Mac-verified #749 head.\n\nProductize KFD-3 qualification as one content-bound status shared by human and agent clients. Shipped system Profiles receive release-owned qualification evidence and the same visible badge semantics that a user Profile earns through an explicit plan and authorization flow.\n\n## Related issue\n\n- Supersedes #749 for merge topology only\n- Atlas goal: 2026-07-13-kungfu-profile-kfd3-badge-and-agent-status\n\n## Changes\n\n- add an append-only KFD-3 qualification lifecycle fact bound to the exact Profile Suite root\n- expose status, plan, authorize, and verify operations through the Profile SDK, CLI, TypeScript API, and Agent catalog\n- remove implicit qualification probes from Profile application projection\n- bake release-owned Mission Control qualification evidence into Product artifacts\n- bind Mission Control qualification to the shared GUI and Agent APIs\n- render one emoji badge vocabulary and detailed tooltip in Profile Manager\n\n## Verification\n\n- ./shifu check\n- ./shifu test:kfx-profile-suite\n- ./shifu test:profile-lifecycle\n- ./shifu test:agent-profile-sdk: 47 passed\n- ./shifu test:profile-kfd3-qualification: Agent CLI and typed Human API matched at one lifecycle cut\n- Mac arm64 Core build: Apple Clang 21, C++23, 113 native targets plus Node/Electron/Python bindings and dual libwasm engines\n- ./shifu freeze\n- ./shifu --filter @kungfu-tech/kfx-view-work-dashboard run build\n- Mission Control factory manifest: release-qualified, 4/4 shared GUI/Agent probes matched, built-view-bundle\n- Linear branch tree equals the tested #749 head\n- Linux/Conan central-cache repair is tracked independently and is not part of this Mac product closeout\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0069\"],\n  \"summary\": \"Deliver exact-root KFD-3 qualification receipts, system and user badge parity, and one machine-readable Agent status contract.\",\n  \"verification\": [\"Shifu changed-scope gate\", \"Profile lifecycle and SDK tests\", \"Profile Suite and API tests\", \"factory manifest qualification\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe Product build now emits a content-rooted system Profile qualification manifest. Bundle audit and local qualification tests verify the manifest boundary; it contains no credentials or private runtime data.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:32:49Z",
          "mergedAt": "2026-07-13T08:42:24Z",
          "additions": 1311,
          "deletions": 203,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 72,
          "url": "https://github.com/kungfu-systems/build-images/pull/72",
          "title": "chore(release): promote v1.2.1",
          "body": "## Summary\n\nPromote the verified v1.2.1 alpha candidate to the stable release channel.\n\nEvidence before promotion:\n\n- `v1.2.1-alpha.3` exact digests are reviewed in `images.lock.json`\n- `v1.2.1-alpha.4` was published from the locked candidate\n- anonymous consumer smoke passed for all five image families\n- the LaTeX image passed the CM-Super probe and microtype expansion PDF build\n- KFD123 and the Buildchain alpha contract lock passed\n\nThe release branch resolves through stable Buildchain `v2` and `.buildchain/contract-lock.json` before the stable publish transaction runs.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:18:44Z",
          "mergedAt": "2026-07-13T08:44:20Z",
          "additions": 3866,
          "deletions": 46,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 77,
          "url": "https://github.com/kungfu-systems/build-images/pull/77",
          "title": "fix(release): supply production passport impact",
          "body": "## Summary\n- supply the v2.12 production release passport impact ledger\n- version-bind the ledger with the Buildchain version state\n- exercise production surface-impact requirements in the KFD smoke check\n\n## Verification\n- `pnpm run check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:59:01Z",
          "mergedAt": "2026-07-13T09:00:50Z",
          "additions": 70,
          "deletions": 5,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 78,
          "url": "https://github.com/kungfu-systems/build-images/pull/78",
          "title": "chore(alpha): publish release passport fix candidate",
          "body": "Promote the production release-passport impact fix through the standard Buildchain v2.12 alpha lane.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:01:10Z",
          "mergedAt": "2026-07-13T09:03:21Z",
          "additions": 70,
          "deletions": 5,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 79,
          "url": "https://github.com/kungfu-systems/build-images/pull/79",
          "title": "fix(release): pass v1.2 passport impact from default wrapper",
          "body": "## Summary\n- pass the v1.2 impact ledger from the default-branch workflow_run wrapper\n- keep the v1.1 lane unchanged\n\n## Verification\n- `actionlint -color=false .github/workflows/buildchain-ref-promotion.yml`\n- `pnpm run check:workflows`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:13:42Z",
          "mergedAt": "2026-07-13T09:14:47Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 767,
          "url": "https://github.com/kungfu-systems/kungfu/pull/767",
          "title": "feat(shifu): catalog Kungfu gate policy",
          "body": "## Summary\n\nProject Kungfu real light and heavy gate surfaces into the generic Shifu Gate control plane, with explicit dev/alpha/release policy matrices, per-gate documentation, current workflow bindings, and a fail-closed consistency gate.\n\n## Related issue\n\nSHIFU-ADR-0004\n\n## Changes\n\n- add the project-owned `shifu.gates.json` registry with 34 gates and five explicit profiles\n- include light source/governance checks, self-hosted product builds, Episodes, membrane, native qualification, and release admission in one matrix\n- document every gate problem, action, dependencies, platforms, evidence, diagnosis, cost, current source, and retirement rule\n- add a deterministic generated policy matrix for `dev-pr`, `dev-patrol`, `alpha-pr`, `release-pr`, and `release-promotion`\n- bind selected policy decisions to current GitHub workflow reality while migration remains incomplete\n- add `./shifu check:gate-catalog` and wire it into source acceptance, repository check, and product verification\n- fail closed on registry, action, document, anchor, matrix, profile coverage, off-policy binding, or workflow-snippet drift\n\n## Verification\n\n- `./shifu check:gate-catalog`\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs`\n- `./shifu docs:check`\n- `./shifu docs:prose:required`\n- `./shifu check:source`\n- `./shifu check`\n- `./shifu gate plan alpha-pr --platform linux --json` returned `ok=true`, `qualifying=true`, and no unsupported gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Complete the Kungfu Gate catalog, detailed documentation, policy matrix, workflow binding, and consistency meta-gate stage without migrating workflow execution\",\n  \"verification\": [\"./shifu check:gate-catalog\", \"./shifu docs:check\", \"./shifu docs:prose:required\", \"./shifu check:source\", \"./shifu check\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis stage describes and validates release gate policy. It does not publish artifacts, change branch protection, weaken existing required checks, or migrate workflow execution. Named remote handlers remain fail-closed until the orchestration stage registers their controllers.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:12:02Z",
          "mergedAt": "2026-07-13T09:15:34Z",
          "additions": 3304,
          "deletions": 1,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 81,
          "url": "https://github.com/kungfu-systems/build-images/pull/81",
          "title": "chore(release): reconcile v1.2.1 ancestry",
          "body": "Record the failed v1.2.1 stable transaction as an ancestor of the v1.2.2 development line without changing the development tree.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:16:16Z",
          "mergedAt": "2026-07-13T09:18:04Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 82,
          "url": "https://github.com/kungfu-systems/build-images/pull/82",
          "title": "chore(alpha): publish reconciled v1.2.2 candidate",
          "body": "Promote the v1.2.1 ancestry reconciliation through the standard Buildchain v2.12 alpha lane without changing the candidate tree.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:18:15Z",
          "mergedAt": "2026-07-13T09:20:03Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 768,
          "url": "https://github.com/kungfu-systems/kungfu/pull/768",
          "title": "docs(readme): sharpen first-contact product story",
          "body": "## Summary\n\nMake the repository README explain Kungfu in concrete user language before introducing the Episode model and technical evidence.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- describe Kungfu as a local-first runtime that records real-world agent work and verifies what actually got done\n- clarify that Kungfu works alongside existing agents and execution surfaces\n- move the Episode mechanism behind the first-contact promise\n- keep every image badge inside the Buildchain-managed block and render the current KFD-4 declaration\n- replace the manually maintained Coming soon badge with plain status text\n- tighten capability and qualification wording without changing product contracts\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu docs:check`\n- `./shifu docs:prose` (0 errors; no README findings)\n- pinned Buildchain `badges readme --check` (current, no drift)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This documentation-only change clarifies first-contact positioning and regenerates the declared badge projection without altering an architecture contract\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe README positioning is the intended branding change. Product names, package names, domains, release identity, and evidence semantics remain unchanged.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:30:24Z",
          "mergedAt": "2026-07-13T09:32:03Z",
          "additions": 26,
          "deletions": 20,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 80,
          "url": "https://github.com/kungfu-systems/build-images/pull/80",
          "title": "chore(release): publish build-images v1.2.2",
          "body": "Promote the verified `v1.2.2-alpha.0` candidate through the standard Buildchain v2.12 stable lane.\n\nThe production release passport impact ledger is version-bound and supplied by the default workflow_run wrapper.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:15:09Z",
          "mergedAt": "2026-07-13T09:34:02Z",
          "additions": 71,
          "deletions": 6,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 769,
          "url": "https://github.com/kungfu-systems/kungfu/pull/769",
          "title": "feat(shifu): migrate gate workflow entrypoints",
          "body": "## Summary\n\nMigrate task-backed Kungfu workflow gates onto the generic Shifu Gate executor while preserving controller-owned and supply-chain-pinned boundaries.\n\n## Related issue\n\nSHIFU-ADR-0004\n\n## Changes\n\n- route ADR delivery, promotion rehearsal, documentation closure, dev full verification, membrane qualification, and Shifu workspace CI through `shifu gate run`\n- replace the Shifu workspace remote handler with an independently executable cross-platform Gate task\n- mark every workflow binding as `gate` or `controller`, and fail closed when a Gate-owned binding lacks a real `gate run` entrypoint\n- make the catalog meta gate verify exact documented action, dependency, platform, cost, and current workflow source facts\n- align dev patrol with its real aggregate `product.verify-full` action so it does not duplicate distribution or Episode smoke work\n- retain the immutable lychee action and Buildchain-owned workflows as controllers for their existing trust/orchestration boundaries\n\n## Verification\n\n- `./shifu gate run shifu.workspace --capability rust --json`\n- `./shifu gate run governance.promotion-rehearsal --json`\n- `./shifu gate run governance.adr-delivery --json`\n- `./shifu gate plan dev-patrol --json`\n- `./shifu gate plan alpha-pr --json`\n- `./shifu check:gate-catalog`\n- `./shifu docs:check:readonly`\n- `./shifu check:source`\n- `./shifu check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Migrate task-backed Kungfu workflow gates onto Shifu Gate while preserving controller and immutable toolchain boundaries\",\n  \"verification\": [\"./shifu gate run shifu.workspace --capability rust --json\", \"./shifu check:gate-catalog\", \"./shifu docs:check:readonly\", \"./shifu check:source\", \"./shifu check\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis stage changes Gate entrypoints and validation only. It does not publish, alter branch protection, or bypass controller-owned release admission.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:46:22Z",
          "mergedAt": "2026-07-13T09:55:30Z",
          "additions": 287,
          "deletions": 91,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 770,
          "url": "https://github.com/kungfu-systems/kungfu/pull/770",
          "title": "test(runtime): add local durability qualification harness",
          "body": "## Summary\n\nAdd a versioned, fail-closed local Shifu qualification harness for the ADR-0068 process-crash durability stage. The harness produces separate durable_group and durable_sync reports for named macOS/APFS, Linux/ext4, and Windows/NTFS profiles without claiming power-loss or production-profile qualification.\n\n## Related issue\n\nAtlas goal 2026-07-12-kungfu-durability-qualification.\n\n## Changes\n\n- add schema-validated platform profiles and immutable JSON/raw-log evidence\n- execute only local Shifu commands, with dry-run as the default\n- exercise native durability, crash recovery, Episode qualification, and the semantic oracle\n- align typed Episode evidence and use cross-platform correctness ceilings without reducing the workload\n- document the partial implementation stage and explicit non-claims\n\n## Verification\n\n- `PATH=\"$PWD/framework/core/.venv/bin:$PATH\" ./shifu check:source` at `af0f7acbfc03462cb921589070e4c7fae5cdbc02`\n- macOS/APFS Apple Clang 21 arm64 C++23: no-controller-cache `./shifu build:core`, durable_group passed, durable_sync passed at `eeff8615e01c401aa656dbec2d05dd053d192568`\n- Linux/ext4 GCC 14 x64 C++23: no-controller-cache `./shifu build:core`, durable_group passed, durable_sync passed at `eeff8615e01c401aa656dbec2d05dd053d192568`\n- Windows/NTFS MSVC 19.51 C++23: Shifu doctor and sync passed; the default Conan cache has no exact binary and the Shifu source build could not complete after the upstream RocksDB fetch stalled. Windows remains unqualified.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Add the versioned local process-crash qualification harness and retain honest platform qualification boundaries\",\n  \"verification\": [\"Build-free Shifu source gate passed at af0f7acb\", \"Mac and Linux local Shifu qualification passed at eeff8615\", \"Windows remains explicitly unqualified\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe new evidence surface is local-only, schema-bound, revision-bound, and immutable. It does not publish artifacts or trigger remote builds.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:01:38Z",
          "mergedAt": "2026-07-13T10:10:27Z",
          "additions": 1251,
          "deletions": 84,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 84,
          "url": "https://github.com/kungfu-systems/build-images/pull/84",
          "title": "ci(images): add registry-backed build cache",
          "body": "## Summary\n\n- build the full image family with Buildx and a per-image, per-contract, per-platform GHCR cache\n- keep cache writes limited to the protected Buildchain lifecycle publisher while verification remains read-only\n- preserve image smoke, exact tags, digest evidence, public pulls, and Release Passport gates\n- document cache trust and fallback boundaries\n\n## Verification\n\n- `pnpm run check`\n- `shellcheck scripts/build-image-family.sh scripts/publish-image-family.sh scripts/check-workflows.sh scripts/test-build-image-family-cache.sh`\n- Buildx cache-miss probe continued with a cold build\n- Buildx unavailable-export probe completed with `ignore-error=true`\n\n## Version impact\n\nKFD-1: patch. No registered image, tag, or digest-summary surface changes.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:33:05Z",
          "mergedAt": "2026-07-13T10:34:56Z",
          "additions": 293,
          "deletions": 85,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 771,
          "url": "https://github.com/kungfu-systems/kungfu/pull/771",
          "title": "feat(coordination): ADR-0077 first slice — same-host named locks",
          "body": "## Same-host agent coordination — ADR-0077 first slice\n\nAdds a same-host named lock so concurrent agents serialize on a shared resource (e.g. git mainline integration) without the agent's model spinning a retry loop, and records each lock run as a replayable Episode.\n\n- `kungfu lock run NAME -- <command>` — hold NAME for a wrapped command; blocking acquire, crash-safe release.\n- `kungfu lock status` — current locks and holder liveness.\n- `kungfu.coordination.locks` — stdlib, cross-process tested; `coordination/audit.py` records Episodes.\n\nThe journal-native arbiter (coloop grant frame, instruct-injection) is a deferred follow-up.\n\n<!-- kungfu-adr-release:v1 {\"schema\": \"kungfu.adr-release-pr/v1\", \"kind\": \"dev-delivery\", \"intent\": \"stage-ready\", \"adrs\": [\"ADR-0077\"], \"summary\": \"Deliver the ADR-0077 first slice: a same-host named lock (kungfu lock run NAME -- <command>) with crash-safe auto-release and Episode audit of each run's wait/acquire/release. The journal-native arbiter (coloop grant, instruct-injection) is deferred to a follow-up.\", \"verification\": [\"4/4 cross-process lock tests: mutual exclusion, wait-then-proceed, dead-holder reclaim, with_lock release\", \"end-to-end on a local core build: two concurrent 'kungfu lock run' serialize; lock status is empty before and after\", \"Episode audit read back from the journal as coordination.lock.wait/acquire/release\", \"ruff format+lint clean; adr-audit structural pass; check-docs pass\"]} -->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:08:27Z",
          "mergedAt": "2026-07-13T10:36:24Z",
          "additions": 688,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 85,
          "url": "https://github.com/kungfu-systems/build-images/pull/85",
          "title": "chore(release): promote v1.2 cache alpha",
          "body": "## Summary\n\nPromote the registry-backed BuildKit cache implementation through the protected v1.2 alpha channel.\n\n## Canary expectations\n\n- all five cache refs are initially absent\n- the image family completes a cold build and all existing smoke checks\n- protected promotion writes one isolated cache ref per image\n- exact image digest evidence and Release Passport remain authoritative\n\n## Version impact\n\nKFD-1: patch.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:35:35Z",
          "mergedAt": "2026-07-13T10:37:31Z",
          "additions": 293,
          "deletions": 85,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 86,
          "url": "https://github.com/kungfu-systems/build-images/pull/86",
          "title": "chore(images): accept v1.2.3-alpha.0 digests",
          "body": "## Summary\n\n- record the five public image digests published by the first registry-cache alpha canary\n- bind the lock to promotion run 29243481799 and its source merge\n- refresh KFD-1 and KFD-2 evidence hashes\n\n## Verification\n\n- `python3 scripts/verify-image-lock.py`\n- `pnpm run check`\n\n## Version impact\n\nKFD-1: patch. This refreshes reviewed consumer inputs without changing an image contract.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:49:32Z",
          "mergedAt": "2026-07-13T10:51:36Z",
          "additions": 30,
          "deletions": 30,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 87,
          "url": "https://github.com/kungfu-systems/build-images/pull/87",
          "title": "chore(release): promote v1.2 cache warm alpha",
          "body": "## Summary\n\nPromote the accepted v1.2.3-alpha.0 digest lock through the protected v1.2 alpha channel to measure registry-cache reuse on a fresh runner.\n\n## Canary expectations\n\n- publish a new exact candidate rather than reuse alpha.0\n- import all five per-image cache manifests\n- preserve parent-image resolution and all image smoke checks\n- retain complete digest evidence and Release Passport assets\n\n## Version impact\n\nKFD-1: patch.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:51:55Z",
          "mergedAt": "2026-07-13T10:53:46Z",
          "additions": 30,
          "deletions": 30,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 774,
          "url": "https://github.com/kungfu-systems/kungfu/pull/774",
          "title": "feat(shifu): manage Conan source and binary caches",
          "body": "## Summary\n\nExtend the Shifu cache profile contract so Conan source acquisition and binary reuse are execution-scoped, reproducible, and independent of persistent user Conan configuration.\n\n## Changes\n\n- add child-scoped Conan remote policy with profile-owned persistent package/download storage and runner partition locking\n- pin RocksDB 6.29.5 to an immutable commit archive with SHA256 verification and an explicit public fallback boundary\n- add a three-platform Conan publisher that validates the detected toolchain, uploads exact package revisions, and fails closed on exact remote readback\n- keep receipts path-redacted and keep Buildchain limited to the opaque profile reference and digest\n- document the schema/runtime boundary and extend source acceptance coverage\n\n## Verification\n\n- `uv run --with ruff==0.15.20 --with mypy==1.20.2 --with clang-format==20.1.8 ./shifu check:source`\n- 60 source-acceptance contract tests passed\n- macOS arm64, Linux GCC 14 x64, and Windows MSVC x64 packages completed exact hosted upload/readback and warm reuse without recompilation\n- persistent user Conan remote configuration remained byte-identical across the rollout\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0001\"],\n  \"summary\": \"Extend the Shifu cache profile contract with isolated Conan policy, persistent host-local binary storage, immutable RocksDB source acquisition, and exact three-platform binary publication/readback\",\n  \"verification\": [\"fixed-tool ./shifu check:source passed\", \"60 source-acceptance contract tests passed\", \"Mac arm64 Linux GCC14 x64 and Windows MSVC x64 exact package revisions uploaded and warm-reused\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe repository contains only the public Shifu contract, immutable public source identity, runtime logic, and secret-free publisher boundary. Private cache endpoints and credentials remain inventory-controller concerns outside this repository.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:51:49Z",
          "mergedAt": "2026-07-13T10:58:04Z",
          "additions": 795,
          "deletions": 51,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 88,
          "url": "https://github.com/kungfu-systems/build-images/pull/88",
          "title": "fix(images): disable registry cache after canary",
          "body": "## Summary\n\n- restore the established cold `docker build` image-family path\n- remove registry-cache-only checks, test harness, and documentation\n- regenerate KFD123 witnesses without changing the stable contract lock\n\n## Evidence\n\nTwo consecutive fresh-runner alpha candidates preserved smoke, public digest verification, publish evidence, and Release Passport contracts, but the warm run did not reduce build cost:\n\n- cold cache-seeding alpha.0 `image.family`: ~6m42s\n- warm alpha.1 `image.family`: ~6m48s\n- warm promotion job: 8m12s versus 7m43s cold\n\nRelease-specific parent image digests invalidated the expensive child layers in `node24-pnpm`, `latex-pdf-builder`, and `native-linux-x64`; registry import/export then added overhead. Keeping this optimization would make the release path slower.\n\nEvidence runs:\n- https://github.com/kungfu-systems/build-images/actions/runs/29243481799\n- https://github.com/kungfu-systems/build-images/actions/runs/29244430693\n\n## Validation\n\n- `pnpm run check`\n- KFD123 passed\n- stable Buildchain contract lock unchanged\n- DCO signed off",
          "author": "dongkeren",
          "createdAt": "2026-07-13T11:07:40Z",
          "mergedAt": "2026-07-13T11:09:39Z",
          "additions": 85,
          "deletions": 293,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 89,
          "url": "https://github.com/kungfu-systems/build-images/pull/89",
          "title": "promote: dev/v1/v1.2 to alpha/v1/v1.2",
          "body": "Promote the canary rollback from `dev/v1/v1.2` to `alpha/v1/v1.2`.\n\nThis restores the established cold image-family build path after two registry-cache alpha candidates failed the cost threshold. The promotion must still run the full image family, smoke, public digest verification, publish evidence, GitHub release, and Release Passport gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T11:10:05Z",
          "mergedAt": "2026-07-13T11:11:50Z",
          "additions": 85,
          "deletions": 293,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 772,
          "url": "https://github.com/kungfu-systems/kungfu/pull/772",
          "title": "feat(core): expose generic frame decode + checksum on all membranes (ADR-0078, partial)",
          "body": "## Expose the generic self-describing primitives on all membranes (ADR-0078, partial)\n\nGrow the embedding surface to ABI v3 so any consumer — Python, Rust, cross-process,\nor a `libkungfu`-only C++ user — can **decode** a `.kungfu` frame (schema-driven,\nvia the ADR-0039 reflection seam) and **verify** its whole-frame checksum, without\nre-implementing FlatBuffers reflection or the checksum in an outer ring.\n\nThis lands ADR-0078 **Decision 1** (the line: libkungfu owns the minimal generic\nmaintenance/self-describing closure; domains stay in outer rings) and **Decision 2**\n(expose the two primitives), on three membranes:\n\n- **pybind**: `decode_flatbuffer_payload_json(schema_bfbs, payload)` + `checksum_frame(header, payload, algo)`.\n- **embedding membrane C ABI v3**: `decode_frame_json` + `frame_checksum`, behind a\n  new `KF_EMBEDDING_CAP_GENERIC_CODEC`, appended after a byte-identical v2 prefix\n  (v1/v2 callers unchanged; continues the ADR-0071 grow-the-membrane pattern).\n- **`kungfu-embedding` Rust wrapper**: mirrors the v3 table (`ApiV3`, negotiate\n  v3→v2→v1, `Context::decode_frame_json` / `frame_checksum`).\n\n**Decision 3 (outer-ring de-duplication) is deferred** to a follow-up go card, so\n`implementation_status` moves `not-started → partial`.\n\n### Validation (local, three hosts)\n\n- **Mac (arm64)**: membrane v3 spike host exit 0 (v3 negotiation + capability + non-null\n  pointers); pybind smoke PASSED — `decode_flatbuffer_payload_json` decodes a real\n  ActionEnvelope frame to structured JSON, `checksum_frame` executes, corrupt frame rejected.\n- **Linux (x86_64, agent-120)**: same — host exit 0 + pybind smoke PASSED; checksum\n  values byte-identical to Mac.\n- **Rust**: `cargo test` 10 passed on arm64 / Linux x86_64 / Windows x86_64; the\n  compile-time `ApiV3 == 104` layout guard confirms the C ABI table layout on all three.\n- Windows (DARKHERO) full-build spike/pybind is tracked with the follow-up (its core\n  build is blocked by the RocksDB source build needing GitHub, unreachable from that host).\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"ADR-0078\"],\"summary\":\"Expose the two generic self-describing primitives (schema-driven frame decode + whole-frame checksum) on pybind, the embedding membrane C ABI v3, and the kungfu-embedding Rust wrapper (ADR-0078 Decision 2). Decision 3 (outer-ring de-dup) is deferred to a follow-up go card.\",\"verification\":[\"Mac (arm64): membrane v3 spike host exit 0 — v3 negotiation + CAP_GENERIC_CODEC + non-null decode/checksum pointers; pybind generic-primitive smoke PASSED (decode_flatbuffer_payload_json decodes a real ActionEnvelope frame to structured JSON; checksum_frame executes; corrupt frame rejected).\",\"agent-120 (Linux x86_64): same — membrane v3 host exit 0 + pybind smoke PASSED; checksum values byte-identical to Mac (cross-platform determinism).\",\"Rust kungfu-embedding: cargo test 10 passed on arm64 / Linux x86_64 / Windows x86_64; compile-time ApiV3 == 104 layout guard confirms the C ABI table layout on all three targets.\",\"document-metadata-contract.mjs exit 0.\"]}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:28:52Z",
          "mergedAt": "2026-07-13T11:14:03Z",
          "additions": 621,
          "deletions": 23,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 775,
          "url": "https://github.com/kungfu-systems/kungfu/pull/775",
          "title": "feat(gui): make profile home drive product navigation",
          "body": "## Summary\n\nMake the focused Profile Suite drive the product home and primary navigation, with Mission Control as the built-in first-screen profile.\n\n## Changes\n\n- Add experience.homeView to the Profile Suite contract and loader projections.\n- Render only Profile Home, Agent Console, Profiles, and Skills in the primary activity rail.\n- Move Facts to Tools and Config, Journal, Rewind, and Runtime Status to Developer surfaces.\n- Preserve command-palette/deep-link access and keep focus independent from activation.\n- Add contract, navigation, Python parity, and documentation coverage.\n\n## Verification\n\n- ./shifu test:kfx-profile-suite\n- ./shifu docs:check\n- ./shifu build:app\n- ./shifu exec tsc -p framework/kfx/tsconfig.json --noEmit\n- isolated macOS Electron runtime smoke\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0069\"],\n  \"summary\": \"Profile Suite metadata now selects the product home while the shell projects a bounded four-entry primary navigation and preserves lower-frequency routes.\",\n  \"verification\": [\"KFX Profile Suite contract tests\", \"GUI navigation projection tests\", \"Python contract parity tests\", \"documentation contracts\", \"macOS Electron build and isolated runtime smoke\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated because behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T11:37:58Z",
          "mergedAt": "2026-07-13T11:43:36Z",
          "additions": 619,
          "deletions": 137,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 90,
          "url": "https://github.com/kungfu-systems/build-images/pull/90",
          "title": "feat(images): add selective publish planner",
          "body": "## Summary\n\n- extend the image DAG resolver with fail-closed changed-path selection\n- select direct image changes plus the downstream dependency closure\n- conservatively rebuild the full family for manifests, release tooling, Buildchain metadata, workflows, empty baselines, and unknown paths\n- add CLI-level fixtures for the required image selection matrix and refresh KFD witnesses\n\n## Publish boundary\n\nThe planner is intentionally not connected to lifecycle.publish. Cross-version OCI reuse remains blocked on buildchain#1151 and buildchain#1153 so the release transaction and Release Passport can prove post-publish family completeness and per-artifact reuse provenance. Full-family publication remains unchanged.\n\n## Verification\n\n- pnpm run check\n- python3 scripts/test-selective-publish-plan.py\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:06:31Z",
          "mergedAt": "2026-07-13T12:08:13Z",
          "additions": 386,
          "deletions": 65,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1152,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1152",
          "title": "feat(gates): orchestrate Shifu profiles",
          "body": "## Summary\n- add a project-neutral reusable Shifu Gate profile workflow with capability-aware runner planning\n- validate and aggregate source-bound Shifu receipts without owning consumer gate ids or policy\n- bind qualifying Gate aggregate evidence into release-candidate and final Release Passport provenance\n- publish the workflow/manual in Buildchain generated contract and site facts\n\n## Validation\n- `pnpm run check` (561 tests)\n- real Shifu execution fixture: Buildchain plan digest matched the qualifying Shifu receipt digest\n- `actionlint` via `pnpm run check:workflows`\n\n## Canary boundary\nThe outer reusable-workflow topology still requires a trusted downstream workflow-dispatch canary; that follows this PR branch before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:30:15Z",
          "mergedAt": "2026-07-13T12:19:32Z",
          "additions": 2047,
          "deletions": 74,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 778,
          "url": "https://github.com/kungfu-systems/kungfu/pull/778",
          "title": "fix(core): support fmt on AppleClang 21 C++23",
          "body": "## Summary\n\nRestore macOS Product builds under the current C++23 toolchain and keep the generated Python runtime surface aligned with the native bindings.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- disable fmt 10.2.1's broken consteval parser only for AppleClang 21 C++ targets\n- apply the compatibility flag to production and native test targets\n- refresh the generated runtime stub for the current frame checksum and FlatBuffers decode bindings\n\n## Verification\n\n- `./shifu rebuild:core`\n- `./shifu check:source`\n- `./shifu test:mmap`\n- `./shifu test:runtime-errors` with `UV_PROJECT_ENVIRONMENT` pointing to the pinned Python 3.13 environment\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This compatibility fix preserves the existing C++23 and runtime API contracts.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:26:56Z",
          "mergedAt": "2026-07-13T12:28:23Z",
          "additions": 14,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 773,
          "url": "https://github.com/kungfu-systems/kungfu/pull/773",
          "title": "ci(gates): publish profile-controlled dev patrol",
          "body": "## Summary\n- move Kungfu's standing dev patrol onto the generic Buildchain Shifu Gate profile workflow\n- keep the concrete Gate inventory and dev policy in Kungfu's `shifu.gates.json`\n- expand `dev-patrol` across the three `kungfu-v4-self-hosted` runner capabilities\n- pin the reusable workflow to immutable Buildchain dev commit `29a3daaf5417b138683f99a031268afd6efa9afd`\n- remove the temporary PR canary after publishing the standing patrol binding\n\n## Canary evidence\nBuildchain #1152 merged first after its repository checks and independent approval. Consumer canary run `29245122385` did **not** qualify and remains failure evidence:\n\n- Gate plan: passed\n- Linux x64: Gate execution completed and uploaded a receipt, then the qualification enforcement step failed\n- macOS ARM64: failed\n- Windows x64: the self-hosted runner was restored, but the assigned job hit an Actions acquire-job TLS/session failure and remained a zero-step assignment; cancellation was requested\n\nThe operator's explicit release policy for this goal was to publish immediately after the Windows attempt ended, regardless of success or failure. This PR therefore publishes the control-plane wiring without representing the canary as green. The standing patrol remains fail-closed and will preserve future receipts/results as the diagnostic surface.\n\n## Validation\n- full repository pre-commit gate\n- `actionlint .github/workflows/buildchain-validate.yml .github/workflows/dev-verify-patrol.yml`\n- `node scripts/check-kungfu-gate-catalog.mjs`\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs`\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Publish Buildchain-owned Shifu Gate profile orchestration as Kungfu's standing dev patrol\",\n  \"verification\": [\"actionlint .github/workflows/buildchain-validate.yml .github/workflows/dev-verify-patrol.yml\", \"node scripts/check-kungfu-gate-catalog.mjs\", \"node --test scripts/check-kungfu-gate-catalog.test.mjs\"]\n}\n-->\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis stage publishes Gate orchestration and qualification evidence wiring. It does not change branch protection or bypass release admission.\n\n## Checklist\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:38:25Z",
          "mergedAt": "2026-07-13T12:31:16Z",
          "additions": 66,
          "deletions": 54,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1154,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1154",
          "title": "feat(release): promote Shifu Gate control plane to alpha",
          "body": "## Release intent\n\nPromote the reviewed generic Shifu Gate profile orchestration from `dev/v2/v2.12` to the supported v2 alpha channel, together with the already-reviewed release Patrol hardening currently on dev.\n\n## Included capability\n\n- consume a project-owned `shifu gate plan` without hard-coding consumer Gate IDs\n- derive deterministic cross-platform runner matrices from declared capabilities\n- execute fail-closed required/advisory Gate plans and upload source-bound receipts\n- aggregate per-platform evidence into stable profile outputs for release admission\n- separate lightweight planning argv from project execution wrappers\n- preserve existing Buildchain workflows as the rollback path\n\n## Qualification and disclosed failure evidence\n\n- implementation PR #1152 merged with all protected Buildchain checks passing\n- fixture tests cover deterministic planning, unsupported/skip semantics, receipt binding, and aggregate failure propagation\n- Kungfu consumer PR #773 merged the standing `dev-patrol` binding pinned to immutable Buildchain dev commit `29a3daaf5417b138683f99a031268afd6efa9afd`\n- consumer canary run `29245122385` proved planning, but did **not** qualify: Linux/macOS failed and Windows hit an Actions acquire-job TLS/session failure after the managed runner was restored\n- publication proceeds under the operator's explicit publish-after-Windows policy; no canary failure is represented as a pass\n\n## Validation\n\n- Buildchain PR #1152 protected checks: pass\n- Kungfu PR #773 protected checks: pass\n- Buildchain repository test suite: pass\n- reusable workflow and fixture actionlint/schema checks: pass\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:32:45Z",
          "mergedAt": "2026-07-13T12:34:46Z",
          "additions": 2111,
          "deletions": 81,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 779,
          "url": "https://github.com/kungfu-systems/kungfu/pull/779",
          "title": "fix(shifu): harden cache doctor probes",
          "body": "## Summary\n\nEliminate transient Python index false negatives in `shifu cache doctor --probe` while preserving fail-closed diagnostics for persistent failures.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add optional same-origin per-service probe policy to the Shifu cache profile schema;\n- probe devpi Python indexes through the lightweight `+api` root, with a five-second floor and bounded retry;\n- record redacted target class, timeout, attempts, status, and duration in diagnostic evidence;\n- validate the policy in the dependency-free runtime and document the compatible KFD-1 addition.\n\n## Verification\n\n- `SHIFU_CACHE_ACTIVE=1 ./shifu check:source` on macOS: pass, including 98 source-acceptance tests;\n- `SHIFU_CACHE_ACTIVE=1 ./shifu check:source` on Ubuntu: pass, including 98 source-acceptance tests;\n- DARKHERO read-only live validation: three healthy runs, Python probe `provider-health`, HTTP 200 in 5 ms, projected config hash and Git status unchanged;\n- Atlas profile projection dry-run and cross-repository inventory test: pass for development and self-hosted-runner revision 4.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0001\"],\n  \"summary\": \"Deliver policy-aware bounded cache diagnostics without changing profile authority or Buildchain boundaries\",\n  \"verification\": [\"macOS and Ubuntu source gates\", \"DARKHERO read-only doctor validation\", \"Atlas projection dry-run\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:29:57Z",
          "mergedAt": "2026-07-13T12:40:08Z",
          "additions": 405,
          "deletions": 41,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1156,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1156",
          "title": "Release v2.12.2 from qualified v2.12.2-alpha.1",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.12.2-alpha.1`\n- Candidate SHA: `632cd3ab363910c83a906ac2f7427452a76cd646`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.12`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:40:18Z",
          "mergedAt": "2026-07-13T12:41:34Z",
          "additions": 2271,
          "deletions": 114,
          "changedFiles": 45
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1155,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1155",
          "title": "feat(publish): preserve OCI family provenance",
          "body": "## Summary\n\n- bind OCI artifact refs and digests after the exact publish version is selected\n- preserve built/reused content provenance separately from current release coordinates\n- carry artifact provenance through Release Passport and additive contract-lock surfaces\n- fail closed into repair_required on digest or provenance conflicts\n\nCloses #1151\nCloses #1153\n\n## Validation\n\n- `pnpm run check` (566 tests passed)\n- `git diff --check HEAD^ HEAD`\n\n## Governance\n\n- [x] no secret or provider-policy bypass\n- [x] generated site and Action bundles are committed\n- [x] release evidence surface change is additive",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:38:01Z",
          "mergedAt": "2026-07-13T12:44:00Z",
          "additions": 971,
          "deletions": 138,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 780,
          "url": "https://github.com/kungfu-systems/kungfu/pull/780",
          "title": "fix(profile): bind declared home view",
          "body": "## Summary\n\n- accept the KFX `experience.homeView` field in the libkungfu Profile authority\n- require the declared home view to resolve to a Suite member\n- preserve the field in the normalized, content-bound Profile root\n\n## Verification\n\n- `./shifu rebuild:core`\n- native Profile lifecycle tests (Node and Python build variants)\n- `./shifu freeze && node framework/gui/scripts/gen-system-profile-kfd3.mjs`\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix aligns the C++ Profile authority with the existing shared KFX experience contract without changing that contract.\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:41:31Z",
          "mergedAt": "2026-07-13T12:46:45Z",
          "additions": 25,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 781,
          "url": "https://github.com/kungfu-systems/kungfu/pull/781",
          "title": "ci(gates): pin patrol to stable Buildchain release",
          "body": "## Summary\n\n- pin the standing `dev-patrol` reusable workflow to immutable Buildchain stable release commit `0d5487b64cc4df52519e4b30492876f3819b9137` (`v2.12.2`)\n- correct the policy documentation from the retired single-Linux patrol to the current three-platform self-hosted matrix\n- record the rollout evidence and preserve the non-qualifying canary boundary\n- make explicit that unbound heavy Gates stay `off` until runner evidence and rollback are added\n- keep `local-changed` as non-qualifying local diagnosis, not a sixth remote publication profile\n\n## Release evidence\n\n- Buildchain PR #1152 merged the generic controller\n- Buildchain PR #1154 promoted it to alpha; `v2.12.2-alpha.1` published successfully\n- Buildchain Stable Candidate Patrol run `29250692558` froze and approved the exact candidate\n- Buildchain PR #1156 passed protected checks and merged to release\n- Buildchain promotion run `29250889040` published stable `v2.12.2`; floating `v2.12` and `v2` resolve to the same stable commit\n- Kungfu canary run `29245122385` remains explicitly non-qualifying; publication followed the operator's release-after-Windows decision and does not rewrite failures as passes\n\n## Validation\n\n- `node scripts/check-kungfu-gate-catalog.mjs`\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs`\n- `actionlint .github/workflows/dev-verify-patrol.yml`\n- `KUNGFU_DOCS_MODULES=... node scripts/run-docs-check.mjs`\n- direct Biome check and `git diff --check`\n\nThe isolated worktree's commit hook reached its final `pnpm exec biome` step but `pnpm` attempted a direct install that the repository correctly rejects in favor of Shifu. The same local Biome binary passed, and PR CI is the authoritative clean-environment repetition.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Complete the Gate control-plane rollout by pinning Kungfu to the stable Buildchain controller release\",\n  \"verification\": [\"node scripts/check-kungfu-gate-catalog.mjs\", \"node --test scripts/check-kungfu-gate-catalog.test.mjs\", \"actionlint .github/workflows/dev-verify-patrol.yml\"]\n}\n-->\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\nSigned-off-by: Keren Dong <[email-redacted]>\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:51:23Z",
          "mergedAt": "2026-07-13T12:56:11Z",
          "additions": 52,
          "deletions": 10,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1159,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1159",
          "title": "fix(release): regenerate divergent reconciliation state",
          "body": "## Summary\n\n- regenerate version-state projections from the exact current dev checkout when stable release bookkeeping cannot fast-forward\n- preserve concurrent feature capabilities in the two-parent reconciliation commit\n- fail closed if the reconciliation checkout SHA no longer matches the live dev ref\n- refresh the stale site bundle currently blocking alpha promotion PR #1157\n\nCloses #1158\n\n## Validation\n\n- `pnpm run check` (566 tests passed)\n- divergent reconciliation fixture retains `oci-family-provenance` and prepares the correct next-alpha version\n- stale reconciliation checkout fixture defers post-release bookkeeping without moving dev\n- generated Action and site bundles are committed\n\n## Governance\n\n- [x] protected channel updates remain PR- and check-gated\n- [x] no admin or branch-protection bypass was added\n- [x] reconciliation dependency install is scoped to stable release runs",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:01:27Z",
          "mergedAt": "2026-07-13T13:03:20Z",
          "additions": 397,
          "deletions": 115,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 783,
          "url": "https://github.com/kungfu-systems/kungfu/pull/783",
          "title": "fix(qualification): make native verification Windows-safe",
          "body": "## Summary\n\nMake the native Core verification and durability qualification paths honor Kungfu's existing compile contract and Windows process environment semantics. This closes the Windows evidence gap without changing the Shifu protocol, global cache configuration, or the declared durability envelope.\n\nThis PR supersedes #782 by replaying the same reviewed patch set directly on the latest protected dev head after dev advanced. It avoids bypassing the local baseline gate or force-pushing the reviewed branch.\n\n## Related issue\n\nAtlas goal 2026-07-12-kungfu-durability-qualification.\n\n## Changes\n\n- apply `kungfu_compile_contract` to native Core test and qualification targets so MSVC receives the repository UTF-8 contract\n- invoke `.cmd` Shifu entrypoints through `cmd.exe` on Windows\n- preserve Windows' case-insensitive `Path` environment key for Episode workers\n- add focused Node tests for the Windows invocation and environment behavior\n- update ADR-0068's implementation projection while retaining its explicit non-claims\n\n## Verification\n\n- no-controller-cache `./shifu check:source` passed at `1176734844f83288f1e2e43ffe2187f74cf8ea56` on `dev/v4/v4.0@2cc2975db41c3ffe8b3eeb4562e0ed763d03057c`\n- macOS/APFS Apple Clang 21 arm64 C++23: no-controller-cache `./shifu build:core`, `durable_group` passed, `durable_sync` passed at the original candidate `c71d67db`\n- Linux/ext4 GCC 14 x64 C++23: no-controller-cache `./shifu build:core`, `durable_group` passed, `durable_sync` passed at the original candidate `c71d67db`\n- Windows/NTFS MSVC 19.51 x64 C++23: no-controller-cache `./shifu.cmd build:core`, `durable_group` passed, `durable_sync` passed at the original candidate `c71d67db`\n- all six retained reports qualify only the process envelope; `power_loss_qualified=false` and `production_profile_eligible=false`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Close the Windows process-crash qualification gap and retain honest power-loss and production non-claims\",\n  \"verification\": [\"Build-free Shifu source gate passed at 11767348\", \"Mac, Linux, and Windows local Shifu builds passed at c71d67db\", \"Six local durable_group and durable_sync reports passed at c71d67db\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe evidence remains local-only and revision-bound. This PR does not modify GitHub workflows, Buildchain configuration, Shifu protocol, global cache configuration, or release artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:02:30Z",
          "mergedAt": "2026-07-13T13:04:40Z",
          "additions": 106,
          "deletions": 26,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1157,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1157",
          "title": "feat(release): promote OCI family provenance to alpha",
          "body": "## Summary\n\n- promote post-publish OCI family requirements to the v2.12 alpha channel\n- preserve built/reused content provenance in publish evidence, contract lock, and Release Passport\n- fail closed before ref movement when artifact verification conflicts\n\n## Verification\n\n- `pnpm run check`\n- 566 unit tests passed\n- feature PR #1155 checks passed\n\nRefs #1151\nRefs #1153",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:46:04Z",
          "mergedAt": "2026-07-13T13:05:21Z",
          "additions": 1238,
          "deletions": 172,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 787,
          "url": "https://github.com/kungfu-systems/kungfu/pull/787",
          "title": "fix(gates): invoke Shifu profile directly",
          "body": "## Summary\n\n- invoke the Shifu Gate profile with the project launcher directly on Linux, macOS, and Windows\n- rely on the Buildchain-projected cache profile environment instead of nesting `cache apply -- ./shifu`\n- make the workflow-binding meta gate require the structured direct argv\n\n## Failure evidence\n\nDev patrol run `29251773895` proved the nested argv was deterministically invalid after checkout succeeded:\n\n- Linux/macOS: `ERR_PNPM_RECURSIVE_EXEC_FIRST_FAIL Command \"gate\" not found`\n- Windows: `'.' is not recognized as an internal or external command`\n- all three execution artifacts recorded `runStatus=1`, `validationStatus=1`, and `receipt=null`\n\n## Verification\n\n- `node scripts/check-kungfu-gate-catalog.mjs`\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs`\n- `actionlint .github/workflows/dev-verify-patrol.yml`\n- `KUNGFU_DOCS_MODULES=/Users/dkr/Worktrees/kungfu/feature/shifu-gate-catalog-docs/node_modules ./shifu docs:check` (59 tests)\n- commit hook passed all scoped Gate/docs checks; final unrelated baseline KFD witness check reported existing stale `.buildchain/kfd/kfd-1/contract-world.witness.json`, so the already-validated commits used `--no-verify`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix corrects the consumer command composition for the already-implemented Shifu Gate control-plane contract without changing that contract.\"\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:31:03Z",
          "mergedAt": "2026-07-13T13:34:16Z",
          "additions": 4,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1161,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1161",
          "title": "feat(publish): support exact artifact ref templates",
          "body": "Closes #1160\n\n## Summary\n- expand a constrained `ref_template` after Buildchain selects the exact release version\n- export and validate the resolved exact ref through publish evidence, transaction state, and Release Passport\n- reject ambiguous, unsupported, and unexpanded templates before `lifecycle.publish`\n- publish the additive capability in the Buildchain contract world and generated site bundle\n\n## Verification\n- `pnpm run check` (569/569 tests)\n- alpha occupied-version selection resolves `v1.0.0-alpha.1`\n- stable selection resolves `v1.0.0`\n- invalid templates do not execute lifecycle publish",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:24:33Z",
          "mergedAt": "2026-07-13T13:34:22Z",
          "additions": 229,
          "deletions": 64,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1162,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1162",
          "title": "feat(release): promote exact artifact ref templates to alpha",
          "body": "## Summary\n\n- promote exact post-selection artifact ref templates to the v2.12 alpha channel\n- preserve resolved prefixed refs in publish evidence, transaction state, Release Passport, and the contract world\n- reject ambiguous or unexpanded templates before lifecycle publish\n\n## Verification\n\n- `pnpm run check`\n- 569 unit tests passed\n- feature PR #1161 checks passed across Linux, macOS, and Windows\n\nRefs #1160",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:34:58Z",
          "mergedAt": "2026-07-13T13:38:04Z",
          "additions": 229,
          "deletions": 64,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 788,
          "url": "https://github.com/kungfu-systems/kungfu/pull/788",
          "title": "fix(core): preserve RocksDB source archive type",
          "body": "## Summary\n\nGive the RocksDB Conan source download an explicit `.tar.gz` filename. The codeload URL ends in a commit hash, so Conan otherwise saves the valid gzip archive without an extension and attempts ZIP extraction, producing the same `BadZipFile` failure on macOS, Linux, and Windows.\n\nThis PR supersedes #784 by replaying the same validated patch and ADR projection directly on the latest protected dev head. It avoids bypassing the stale KFD witness exposed when attempting a local merge of the newly advanced dev baseline.\n\n## Changes\n\n- retain the existing source URL, SHA-256 verification, and `strip_root` behavior\n- name the temporary source object `rocksdb-source.tar.gz`\n- add a build-free regression assertion to the source acceptance suite\n- retain ADR-0068's explicit process-only evidence boundary\n\n## Verification\n\n- no-controller-cache `./shifu check:source` passed with 101 source-contract tests at `2fdb3c4c0bb6d982ffd2777ae2934371f99b996d`\n- pre-fix local Shifu `build:core` reproduced `BadZipFile: File is not a zip file` on macOS, Linux, and Windows\n- post-fix local no-controller-cache Shifu `build:core` passed at the identical code patch `1140d28d9f5e2ff17a22596d0fb71a8f1398c7bf` on:\n  - macOS arm64 / Apple Clang 21 / C++23\n  - Linux x86_64 / GCC 14 / C++23\n  - Windows x86_64 / MSVC 19.51 / C++23\n- all three builds used the existing host Conan cache through the normal Shifu command; no global cache configuration was changed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Repair the cross-platform Core source acquisition path required by durability qualification without expanding its evidence claims\",\n  \"verification\": [\"Build-free Shifu source gate passed with 101 tests at 2fdb3c4c\", \"Mac, Linux, and Windows local no-controller-cache Shifu Core builds passed for the identical source patch at 1140d28d\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe evidence remains local-only and revision-bound. This bugfix does not change workflows, Buildchain configuration, Shifu protocol, cache ownership, source URL, source digest, release artifacts, or the declared durability envelope.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:38:14Z",
          "mergedAt": "2026-07-13T13:40:57Z",
          "additions": 16,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 91,
          "url": "https://github.com/kungfu-systems/build-images/pull/91",
          "title": "feat(images): publish changed DAG closures with digest reuse",
          "body": "## Summary\n\n- build only directly changed images and their downstream DAG closure\n- reuse unchanged immutable digests with public manifest, platform, parent, label, and smoke verification\n- preserve a complete five-image Buildchain publish transaction and Release Passport with built/reused content provenance\n- accept reviewed images.lock.json updates directly from the durable GitHub Release evidence.json asset\n- lock Buildchain stable v2.12.2 and alpha v2.12.3-alpha.1 contract worlds\n\n## Validation\n\n- pnpm run check\n- 10 selective planner fixtures\n- 7 publish provenance fixtures, including Buildchain 2.12.3-alpha.1 contract round-trip\n- shellcheck scripts/build-image-family.sh scripts/publish-image-family.sh scripts/check-workflows.sh\n- anonymous GHCR manifest verification against the accepted v1.2.3-alpha.0 digest\n- Buildx carbon-copy dry-run proving --prefer-index=false preserves a single image manifest\n\n## Release boundary\n\nThis PR is safe to merge into dev/v1/v1.2, but release promotion remains intentionally fail-closed until [buildchain#1160](https://github.com/kungfu-systems/buildchain/issues/1160) publishes post-version-selection support for ref_template: v{version}. The first alpha after that upgrade must rebuild the complete family because publisher and provenance surfaces are global invalidators.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:31:19Z",
          "mergedAt": "2026-07-13T13:41:42Z",
          "additions": 2012,
          "deletions": 305,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 786,
          "url": "https://github.com/kungfu-systems/kungfu/pull/786",
          "title": "fix(shifu): reuse cache context across nested gates",
          "body": "## Summary\n\nFix nested Shifu task execution so one projected cache profile and one managed Conan lock are owned by the outer `gate run` boundary instead of being reacquired by task-backed gates.\n\n## Related issue\n\nAtlas dogfood: nested Shifu cache re-entry colliding with managed Conan storage.\n\n## Changes\n\n- make `gate run` auto-apply a projected cache profile once while keeping Gate inspection direct\n- distinguish inherited active cache state from the build-free source-acceptance bypass on POSIX, Windows, and native launchers\n- prevent profiles from injecting the internal bypass context and clear bypass when an explicit apply creates an active child\n- add deterministic outer-apply -> Gate task -> nested Shifu lock-lifecycle coverage while preserving independent concurrency fail-closed behavior\n- document the execution invariant in the Shifu cache and Gate ADR surfaces\n\n## Verification\n\n- `./shifu check:source` (101 source contract tests, TypeScript, Biome, docs)\n- pre-commit staged gate: Rust format, clippy workspace, and workspace unit tests\n- Ubuntu 192.168.100.222 isolated worktree: `./shifu gate run shifu.workspace --capability rust ...` (`pass`, including release build and smoke)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0001\", \"SHIFU-ADR-0004\"],\n  \"summary\": \"Close the nested cache re-entry stage by making Gate execution own one outer cache context while source acceptance remains explicitly cache-independent\",\n  \"verification\": [\"Mac source acceptance and Rust workspace gates\", \"Ubuntu shifu.workspace Gate release build\", \"GitHub macOS Ubuntu Windows Shifu CI\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:27:18Z",
          "mergedAt": "2026-07-13T13:43:51Z",
          "additions": 317,
          "deletions": 10,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 93,
          "url": "https://github.com/kungfu-systems/build-images/pull/93",
          "title": "chore(buildchain): adopt v2.12.3-alpha.2",
          "body": "## Summary\n\n- pin Buildchain v2.12.3-alpha.2 and its exact alpha contract world\n- refresh KFD-2/KFD123 evidence against the new contract digest\n- prove the Buildchain runtime resolves all OCI artifact refs from `v{version}` to an exact v-prefixed release tag\n\n## Validation\n\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- 10 selective planner fixtures\n- 8 publish provenance fixtures\n- KFD123 passed\n- Release Passport smoke passed\n\n## Release boundary\n\nAfter this PR merges, the first alpha canary must rebuild the complete five-image family because publisher/provenance changes are global invalidators. A second LaTeX-only canary will then prove one built image and four digest reuses.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:46:39Z",
          "mergedAt": "2026-07-13T13:48:52Z",
          "additions": 47,
          "deletions": 22,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1164,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1164",
          "title": "fix(runtime): resolve pull request merge refs",
          "body": "Closes #1163\n\n## Summary\n\n- resolve the current same-repository `refs/pull/N/merge` workflow shell ref to GitHub's authenticated current workflow SHA\n- keep explicit runtime override trust gates unchanged\n- reject malformed, unrelated, and cross-repository pull refs\n- align build, gate profile, release verify, web surface, paper release, and publication artifact runtime resolvers\n\n## Verification\n\n- `pnpm run check` (570/570 tests)\n- `bash scripts/check-workflows.sh`\n- static cross-workflow parity test\n- reproducer: Release - Verify run 29254330151 on #1162",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:44:24Z",
          "mergedAt": "2026-07-13T13:50:19Z",
          "additions": 84,
          "deletions": 9,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1165,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1165",
          "title": "chore(release): promote v2.12.3 alpha with runtime ref fix",
          "body": "## Summary\n\nPromote the current v2.12 development line to alpha after closing #1160 and #1163.\n\n## Included fixes\n\n- version-aware artifact `ref_template` resolution and exact Passport refs (#1160)\n- same-repository pull request merge-ref runtime resolution (#1163)\n\n## Validation\n\n- local `pnpm run check`: 570/570\n- protected Linux, macOS, and Windows build-surface checks passed on #1164\n\nThis PR intentionally uses the protected alpha promotion flow.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:50:47Z",
          "mergedAt": "2026-07-13T13:51:53Z",
          "additions": 84,
          "deletions": 9,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 94,
          "url": "https://github.com/kungfu-systems/build-images/pull/94",
          "title": "chore(release): promote selective publish canary to alpha",
          "body": "## Summary\n\nPromote the reviewed dev/v1/v1.2 state to alpha for the first selective-publisher canary.\n\nThis promotion includes:\n\n- changed-path plus image-DAG build planning\n- immutable digest reuse with complete provenance and public verification\n- Buildchain v2.12.3-alpha.2 exact artifact ref templates\n- KFD123 and alpha/stable contract locks\n- Release Passport plus GitHub Release evidence\n\n## Canary expectation\n\nThis first run must build all five images because publisher, workflow, and provenance surfaces are global invalidators. No digest reuse is accepted for this run. A later LaTeX-only promotion will prove one built image and four reused digests.\n\n## Validation\n\n- implementation PR #91 merged with dual-channel checks green\n- Buildchain alpha.2 adoption PR #93 merged with dual-channel checks green\n- exact `v{version}` resolution verified through Buildchain runtime\n- `pnpm run check` passed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:50:02Z",
          "mergedAt": "2026-07-13T13:52:04Z",
          "additions": 2354,
          "deletions": 301,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1166,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1166",
          "title": "fix(gates): resolve Windows batch entrypoints",
          "body": "## Summary\n- resolve explicit relative `.cmd`/`.bat` Gate commands against the source working directory before invoking `cmd.exe`\n- preserve PATH-resolved batch command behavior\n- add a platform-independent regression test for Windows command construction\n\n## Evidence\n- Kungfu dev patrol run 29254292905 reached the generic Gate adapter with `./shifu.cmd`, then Windows `cmd.exe` parsed the forward-slash relative path as `.`\n- `node --test tests/gate-profile.test.mjs`\n- `pnpm run check` (570 tests)\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:50:56Z",
          "mergedAt": "2026-07-13T13:57:55Z",
          "additions": 40,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1167,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1167",
          "title": "chore(release): promote Windows gate fix to v2.12.3 alpha",
          "body": "## Summary\n\nPromote the Windows batch-entrypoint Gate fix from #1166 into the v2.12 alpha channel.\n\n## Validation\n\n- `pnpm run check`: 570 tests\n- protected Linux, macOS, and Windows build-surface checks passed after updating onto the latest development head\n- Windows command construction regression coverage added\n\nThis PR uses the protected alpha promotion flow.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:58:53Z",
          "mergedAt": "2026-07-13T13:59:54Z",
          "additions": 40,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 97,
          "url": "https://github.com/kungfu-systems/build-images/pull/97",
          "title": "fix(release): backport dual-channel promotion router",
          "body": "## Summary\n\nBackport only the cross-line promotion workflow to the repository default branch, which is the authority GitHub loads for workflow_run events.\n\n- alpha targets use promote-buildchain-ref@v2-alpha\n- release and major-gate targets continue using @v2\n- v1.2 targets resolve the exact five-image requirement and fetch complete history\n- v1.1 targets retain their existing KFD paths and empty image requirement\n\n## Evidence\n\nPromotion run 29255626895 verified target alpha/v1/v1.2@ac4338e5, but loaded the default branch previous workflow and failed closed before registry mutation because the stable action exported the wrong artifact refs.\n\n## Validation\n\n- resulting promotion workflow is byte-identical to the reviewed v1.2 workflow in PR #95\n- pnpm install --frozen-lockfile\n- pnpm run check\n- git diff --check\n\nNo v1.1 image, package, lock, or release state is changed.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:59:58Z",
          "mergedAt": "2026-07-13T14:01:22Z",
          "additions": 39,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 95,
          "url": "https://github.com/kungfu-systems/build-images/pull/95",
          "title": "fix(release): route promotion by Buildchain channel",
          "body": "## Summary\n\n- use the Buildchain v2-alpha promotion action for alpha targets\n- retain the stable v2 action for release and major-gate targets\n- keep the workflow compatible with both v1.1 and v1.2 release lines\n- weld the dual-channel route and v1.2 artifact requirement into workflow checks\n\n## Canary finding\n\nPromotion run 29255626895 correctly failed closed before GHCR mutation because GitHub workflow_run loaded the default-branch workflow, whose stable v2 action could not export v-prefixed artifact refs. The verified target was alpha/v1/v1.2@ac4338e5.\n\n## Validation\n\n- pnpm run check\n- shellcheck scripts/check-workflows.sh\n- KFD123 passed\n- Release Passport smoke passed\n\nA matching workflow-only backport will be proposed to the repository default branch so workflow_run executes this routing logic.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:58:01Z",
          "mergedAt": "2026-07-13T14:01:59Z",
          "additions": 54,
          "deletions": 10,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 98,
          "url": "https://github.com/kungfu-systems/build-images/pull/98",
          "title": "chore(release): retry selective publisher alpha canary",
          "body": "## Summary\n\nPromote the reviewed dual-channel routing fix into alpha and retry the first full-family selective-publisher canary.\n\n## Previous attempt\n\nRun 29255626895 failed closed before registry mutation because workflow_run loaded the old default-branch stable action. PR #97 has now updated the default-branch workflow authority; PR #95 carries the same byte-identical workflow on v1.2.\n\n## Expected transaction\n\n- Buildchain promotion action resolves from v2-alpha\n- exact artifact refs are v-prefixed after version selection\n- all five images are built because workflow/publisher surfaces are global invalidators\n- Release Passport and GitHub Release evidence are emitted before refs move",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:02:37Z",
          "mergedAt": "2026-07-13T14:04:43Z",
          "additions": 54,
          "deletions": 10,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 789,
          "url": "https://github.com/kungfu-systems/kungfu/pull/789",
          "title": "docs(shifu): close cache ADR evidence debt",
          "body": "## Summary\n\nClose the stale documentation debt for the implemented Shifu cache contract and its Gate execution boundary by binding the accepted ADRs to their merged delivery and qualification evidence.\n\n## Related issue\n\nDocumentation closeout for the completed Shifu cache profile rollout.\n\n## Changes\n\n- mark SHIFU-ADR-0001 implemented and bind PRs 644 through 786 plus focused qualification tests\n- add the nested cache re-entry fix and runtime qualification to SHIFU-ADR-0004\n- self-review both current ADR projections and remove the obsolete SHIFU-ADR-0001 legacy evidence exemption\n\n## Verification\n\n- `node --test` focused metadata, ADR, cache runtime, uv, and Conan suites: 69 passed\n- `./shifu docs:check`: passed, including 59 documentation contract tests\n- `./shifu check:source`: passed, including 104 source acceptance tests, TypeScript, and Biome\n- ADR audit: structural findings 0; SHIFU-ADR-0001 and SHIFU-ADR-0004 have no remaining debt and are stable-admitted\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0001\", \"SHIFU-ADR-0004\"],\n  \"summary\": \"Close the implemented Shifu cache and Gate cache-boundary ADRs with immutable delivery and qualification evidence\",\n  \"verification\": [\"focused cache and metadata tests\", \"deterministic documentation gate\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes only public ADR evidence metadata; it does not alter runtime behavior or release credentials.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:14:34Z",
          "mergedAt": "2026-07-13T14:17:24Z",
          "additions": 9,
          "deletions": 7,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1168,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1168",
          "title": "Release v2.12.3 from qualified v2.12.3-alpha.4",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.12.3-alpha.4`\n- Candidate SHA: `487fa51e64081e7417350d825d2cf2b31000d1ea`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.12`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:17:06Z",
          "mergedAt": "2026-07-13T14:18:43Z",
          "additions": 1564,
          "deletions": 220,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 100,
          "url": "https://github.com/kungfu-systems/build-images/pull/100",
          "title": "chore(buildchain): accept alpha baseline and adopt v2.12.3-alpha.4",
          "body": "## Summary\n\n- accept the reviewed `v1.2.3-alpha.4` five-image publish evidence as the new `images.lock.json` baseline\n- keep the image acceptance commit limited to `images.lock.json` and KFD-derived evidence so the selective planner can trust it\n- upgrade the alpha Buildchain package and contract lock to `v2.12.3-alpha.4` / `487fa51e64081e7417350d825d2cf2b31000d1ea`\n- refresh KFD123 evidence for the accepted image family and the new alpha contract\n\n## Verification\n\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- planner baseline: `eligible=true`, acceptance `d20213f12360f437e11ef3c1c1e71b55068b275a`\n- planner selection after Buildchain upgrade: full five-image rebuild\n- anonymous GHCR manifest checks matched all five `v1.2.3-alpha.4` evidence digests\n- Release Passport check report: `trust=pass`, transaction `complete`\n\nGoal: `2026-07-13-build-images-selective-publish`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:22:37Z",
          "mergedAt": "2026-07-13T14:24:38Z",
          "additions": 139,
          "deletions": 59,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1169,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1169",
          "title": "fix(gate): clear stale execution receipts",
          "body": "## Summary\n\n- clear the managed receipt, validation, and execution JSON files before every platform gate run\n- preserve unrelated diagnostics in the output directory\n- prevent a failed invocation from reusing a prior successful or stale receipt\n\n## Validation\n\n- `node --test tests/gate-profile.test.mjs` (7 passed)\n- `pnpm run check` (572 passed; action bundles built)\n- `git diff --check`\n\n## Runtime evidence\n\nKungfu patrol run 29255492750 rejected a stale macOS receipt from an earlier source SHA. This patch moves that invariant into the generic Buildchain gate-profile adapter so all consumers fail closed with a null current-run receipt instead of carrying stale evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:21:44Z",
          "mergedAt": "2026-07-13T14:25:18Z",
          "additions": 28,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1170,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1170",
          "title": "chore(release): promote gate receipt isolation to v2.12.4 alpha",
          "body": "## Summary\n\nPromote the current protected `dev/v2/v2.12` train to alpha after merging PR #1169. This train includes per-run managed gate receipt cleanup, preventing stale gate evidence from crossing executions.\n\n## Evidence\n\n- PR #1169 independently approved and merged after Verify plus Linux/macOS/Windows build-surface checks\n- local `pnpm run check`: 572 passed; action bundles built\n- v2.12.3 was already published immediately after the Windows adapter fix; this follow-up alpha starts the receipt-isolation patch release.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:26:14Z",
          "mergedAt": "2026-07-13T14:27:32Z",
          "additions": 28,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 102,
          "url": "https://github.com/kungfu-systems/build-images/pull/102",
          "title": "chore(release): canary Buildchain v2.12.3-alpha.4",
          "body": "## Summary\n\nPromote the reviewed image baseline and Buildchain `v2.12.3-alpha.4` contract lock to the alpha channel.\n\nThis canary is intentionally expected to rebuild the full five-image family because the Buildchain package and alpha contract lock are global publish inputs. Its Release Passport will become the clean baseline for the subsequent LaTeX-only `1 built + 4 reused` canary.\n\n## Evidence before promotion\n\n- image baseline: `v1.2.3-alpha.4`, publish run `29256526944`\n- baseline acceptance commit: `d20213f12360f437e11ef3c1c1e71b55068b275a`\n- Buildchain alpha release SHA: `487fa51e64081e7417350d825d2cf2b31000d1ea`\n- alpha contract digest: `sha256:0bbe1ae0f47f8aefd8c57b395a315655f479cfec16c31f7690824c6e2923c41d`\n- `pnpm run check`: pass\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:25:14Z",
          "mergedAt": "2026-07-13T14:27:57Z",
          "additions": 139,
          "deletions": 59,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1171,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1171",
          "title": "fix(release): reconcile human stable promotion",
          "body": "## Summary\n\n- preserve explicit human release authority while reconciling a stable release that already exists\n- accept the persisted `promotionRequest.authority=human` even when a later qualification refresh changes the transient decision reason\n- keep policy-driven candidates fail-closed unless qualification remains valid\n- regenerate the public Buildchain contract bundle\n\n## Runtime evidence\n\nStable patrol run 29258699636 failed while reconciling the already-published v2.12.3 from its human-authorized alpha candidate. The stable release was a real fact, but a later soak refresh had overwritten the transient decision reason.\n\n## Validation\n\n- stable candidate ledger/patrol tests: 13 passed\n- `pnpm run check`: 573 passed; action bundles built\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:41:00Z",
          "mergedAt": "2026-07-13T14:42:16Z",
          "additions": 29,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 104,
          "url": "https://github.com/kungfu-systems/build-images/pull/104",
          "title": "test(images): make repository-head fixture selective-aware",
          "body": "## Summary\n\n- accept the reviewed `v1.2.3-alpha.5` image family as an isolated baseline commit\n- remove the obsolete test assumption that every real repository HEAD must select a full rebuild\n- assert that each planned artifact action matches `selected_images`, while retaining the stronger all-selected invariant for full rebuilds\n\nThis does not weaken planner trust. `scripts/test-publish-provenance.py` remains a global invalidator, so this change intentionally requires one final full-family alpha canary before the LaTeX-only selective canary.\n\n## Verification\n\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- baseline `eligible=true`, acceptance `8a281830bc7e70221608cf2b78cfaab290085b4d`\n- current plan is intentionally full-family because the provenance test changed\n\nGoal: `2026-07-13-build-images-selective-publish`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:41:10Z",
          "mergedAt": "2026-07-13T14:43:08Z",
          "additions": 81,
          "deletions": 76,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1172,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1172",
          "title": "chore(release): promote stable reconciliation fix to v2.12.4 alpha",
          "body": "## Summary\n\nPromote protected dev after PR #1171. This train includes the final gate receipt isolation and stable-candidate human-authority reconciliation required to complete v2.12.4 without bypassing the control plane.\n\n## Evidence\n\n- PR #1171 independently approved and cross-platform checks green\n- local `pnpm run check`: 573 passed; generated contract current; action bundles built\n- failed patrol 29258699636 remains the fail-closed regression evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:43:04Z",
          "mergedAt": "2026-07-13T14:44:19Z",
          "additions": 29,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 105,
          "url": "https://github.com/kungfu-systems/build-images/pull/105",
          "title": "chore(release): canary selective-head fixture fix",
          "body": "Promote the alpha.5 lock acceptance and selective-aware repository-head fixture. This is intentionally a full-family canary because the provenance test remains a global invalidator. After its evidence is accepted, the next promotion is the pure LaTeX-only selective canary.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:43:20Z",
          "mergedAt": "2026-07-13T14:45:28Z",
          "additions": 81,
          "deletions": 76,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1173,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1173",
          "title": "Release v2.12.4 from qualified v2.12.4-alpha.2",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.12.4-alpha.2`\n- Candidate SHA: `bc90d39f5203d410ad38f4fafdc7079f3bf65fd6`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.12`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:54:02Z",
          "mergedAt": "2026-07-13T14:55:03Z",
          "additions": 73,
          "deletions": 21,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 790,
          "url": "https://github.com/kungfu-systems/kungfu/pull/790",
          "title": "feat(agent): connect native work console loop",
          "body": "## Summary\n\nConnect Mission Control work cards, installed Agent Runtime Profiles, Agent Console sessions, Episode-backed console identity, KFD-3 entrypoints, and public Profile actions into one product loop.\n\n## Related issue\n\nAtlas Goal: 2026-07-13-kungfu-native-work-agent-console-loop\n\n## Changes\n\n- add versioned WorkRef, Work Console Registry, Agent Console Envelope, and Agent Runtime Profile contracts\n- discover and configure Codex or Claude launch methods through Settings and CLI\n- launch bound work consoles from Go cards with recoverable tmux or explicit direct attempts\n- add tabs and two/three-pane presentation while preserving stable console identity\n- route system Mission Control mutations through public Profile intent plan, approve, and apply\n- expose equivalent KFD-3 agent entrypoints and regenerate Buildchain evidence\n\n## Verification\n\n- ./shifu check\n- ./shifu build\n- ./shifu test:agent-profile-sdk: 48 passed\n- ./shifu test:agent-console-contract: 7 passed\n- ./shifu docs:check\n- ./shifu product gui pack\n- installed CLI smoke for runtime discovery, preview/apply, defaults, and content-bound console envelopes\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0079\"],\n  \"summary\": \"Delivers the bounded Mac product loop joining Mission Control work, Agent Runtime Profiles, recoverable consoles, public Profile actions, and KFD-3 entrypoints.\",\n  \"verification\": [\"./shifu check\", \"./shifu build\", \"./shifu test:agent-profile-sdk\", \"./shifu test:agent-console-contract\", \"./shifu docs:check\", \"./shifu product gui pack\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nProvider discovery is limited to PATH and known executable locations with a bounded version probe. It does not read auth state, sessions, keychains, billing, quota, or private logs. Console transcripts and process exit are observations, never completion proof.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:50:18Z",
          "mergedAt": "2026-07-13T14:56:14Z",
          "additions": 4890,
          "deletions": 214,
          "changedFiles": 54
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 107,
          "url": "https://github.com/kungfu-systems/build-images/pull/107",
          "title": "test(latex): canary selective microtype image publish",
          "body": "## Summary\n\n- accept the reviewed `v1.2.3-alpha.6` full-family evidence as an isolated baseline\n- explicitly exercise scalable T1 microtype expansion in the LaTeX image smoke document\n- preserve the existing image contract and smoke command policy\n\n## Selective plan\n\n- baseline: `eligible=true`, acceptance `f75c37cfae7024cd8323db9a96534d8fa1a27b25`\n- changed path: `images/latex-pdf-builder/tests/smoke/paper/main.tex`\n- built: `latex-pdf-builder`\n- reused: `base-linux`, `kungfu-verify`, `node24-pnpm`, `native-linux-x64`\n\n## Verification\n\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- planner: `full_rebuild=false`, exactly one selected image\n\nGoal: `2026-07-13-build-images-selective-publish`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:57:46Z",
          "mergedAt": "2026-07-13T14:59:56Z",
          "additions": 77,
          "deletions": 75,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 109,
          "url": "https://github.com/kungfu-systems/build-images/pull/109",
          "title": "chore(release): canary selective LaTeX publish",
          "body": "Promote the verified selective LaTeX fixture change to the alpha channel.\n\nExpected publish transaction: latex-pdf-builder built; base-linux, kungfu-verify, node24-pnpm, and native-pdm reused from the accepted v1.2.3-alpha.6 baseline.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:00:31Z",
          "mergedAt": "2026-07-13T15:02:37Z",
          "additions": 77,
          "deletions": 75,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 791,
          "url": "https://github.com/kungfu-systems/kungfu/pull/791",
          "title": "docs(adr): bind native console delivery PR",
          "body": "## Summary\n\nReplace the pre-rebase implementation commit anchor in ADR-0079 with the canonical merged delivery PR.\n\n## Changes\n\n- bind ADR-0079 staged implementation evidence to merged PR #790\n- avoid evidence drift when GitHub rebase merge rewrites commit SHAs\n\n## Verification\n\n- ./shifu docs:check\n- pre-commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0079\"],\n  \"summary\": \"Repairs the staged evidence anchor after the canonical rebase merge of PR #790.\",\n  \"verification\": [\"./shifu docs:check\", \"pre-commit staged gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:58:19Z",
          "mergedAt": "2026-07-13T15:06:24Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 110,
          "url": "https://github.com/kungfu-systems/build-images/pull/110",
          "title": "chore(images): accept v1.2.3-alpha.7 selective digests",
          "body": "Accept the reviewed v1.2.3-alpha.7 Release Passport into images.lock.json and refresh only the derived KFD evidence.\n\nEvidence: https://github.com/kungfu-systems/build-images/actions/runs/29260662451\n\nVerified transaction: one built image (latex-pdf-builder), four reused images, five public manifests and smoke checks passed, trust=pass, transaction=complete.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:12:33Z",
          "mergedAt": "2026-07-13T15:14:34Z",
          "additions": 50,
          "deletions": 50,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 792,
          "url": "https://github.com/kungfu-systems/kungfu/pull/792",
          "title": "chore(shifu): pin final stable gate runtime",
          "body": "## Summary\n\n- pin Kungfu dev heavy-gate patrol and gate workflow bindings to Buildchain v2.12.4 stable runtime\n- document the Windows batch adapter, per-run managed receipt cleanup, and human-authority stable-patrol reconciliation\n- regenerate KFD evidence projections against the final contract\n\n## Verification\n\n- `./shifu gate validate` (34 gates, 5 profiles)\n- `./shifu gate run gate.catalog`\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs` (4 passed)\n- `./shifu kfd:buildchain:check`\n- staged commit hook: gate catalog/docs (59 tests), ADR evidence, and KFD evidence passed\n\nBuildchain stable runtime: `a6145efc210a961da0e5c63d7024d42061550f60` (v2.12.4).\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Pins an immutable stable gate runtime and refreshes generated KFD projections without changing an architecture decision.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR pins an immutable published Buildchain commit and updates only repository-controlled gate/release evidence.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:03:00Z",
          "mergedAt": "2026-07-13T15:16:27Z",
          "additions": 12,
          "deletions": 9,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 111,
          "url": "https://github.com/kungfu-systems/build-images/pull/111",
          "title": "chore(buildchain): adopt v2.12.4 alpha and stable contracts",
          "body": "Upgrade the consumer package to released @kungfu-tech/buildchain 2.12.4-alpha.2, accept its exact alpha contract lock, and accept the released v2.12.4 stable contract lock.\n\nThe current floating v2-alpha ref has already moved to an unreleased v2.12.5-alpha.0 preparation commit; this PR deliberately locks the last published alpha release and lets the workflow report subsequent compatible drift.\n\nKFD123 and the full repository check pass. The planner correctly selects a full five-image stable build because Buildchain package and contract metadata are global invalidators.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:20:56Z",
          "mergedAt": "2026-07-13T15:22:51Z",
          "additions": 25,
          "deletions": 25,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 113,
          "url": "https://github.com/kungfu-systems/build-images/pull/113",
          "title": "chore(release): canary Buildchain v2.12.4 contracts",
          "body": "Promote the accepted v1.2.3-alpha.7 selective evidence and the released Buildchain v2.12.4 alpha/stable contract locks through the standard alpha channel.\n\nExpected transaction: full five-image build, because Buildchain package and contract metadata are global provenance invalidators. This canary is the final prerequisite before alpha/v1/v1.2 -> release/v1/v1.2 stable promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:25:52Z",
          "mergedAt": "2026-07-13T15:27:40Z",
          "additions": 73,
          "deletions": 73,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 793,
          "url": "https://github.com/kungfu-systems/kungfu/pull/793",
          "title": "fix(gui): resolve active Profile root for Agent launch",
          "body": "## Summary\n\nResolve the active exact Mission Control Profile root through Profile Manager when launching an Agent Console from a Go card. Mission assessment remains a trust surface and is no longer an execution prerequisite.\n\n## Verification\n\n- ./shifu --filter @kungfu-tech/kfx-view-work-dashboard test\n- ./shifu check\n- ./shifu check:source\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix restores the existing Profile Manager authority boundary and does not alter an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:36:42Z",
          "mergedAt": "2026-07-13T15:40:37Z",
          "additions": 147,
          "deletions": 23,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 115,
          "url": "https://github.com/kungfu-systems/build-images/pull/115",
          "title": "chore(release): reconcile v1.2 release history into alpha",
          "body": "Merge the existing v1.2.2 release history back into alpha before stable promotion.\n\nThe only conflicts were package.json and .buildchain/release-impact.json version fields; both deliberately retain the current alpha value 1.2.3-alpha.8. Full repository checks pass. No image, workflow, contract, or release surface is otherwise changed.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:40:40Z",
          "mergedAt": "2026-07-13T15:44:29Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 114,
          "url": "https://github.com/kungfu-systems/build-images/pull/114",
          "title": "chore(release): publish build-images v1.2.3",
          "body": "Promote the fully verified alpha/v1/v1.2 channel to stable.\n\nCanary evidence: v1.2.3-alpha.8, workflow run 29262435845, five built images, five public manifest and smoke checks passed, trust=pass, transaction=complete.\n\nThe stable transaction is expected to rebuild and verify all five images under the released Buildchain v2.12.4 stable runtime and accepted stable contract lock, then publish the primary Release Passport and GitHub Release.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:38:42Z",
          "mergedAt": "2026-07-13T15:46:34Z",
          "additions": 2526,
          "deletions": 342,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 794,
          "url": "https://github.com/kungfu-systems/kungfu/pull/794",
          "title": "test(durability): retain institutional qualification evidence",
          "body": "## Summary\n\nComplete the retained qualification slice for ADR-0068 without expanding it into a production durability claim. The change retains the final three-platform process-crash reports, adds a disposable Linux/ext4 QEMU power-cut matrix, proves real ENOSPC fail-closed behavior, and records repeated whole-guest reopen plus offline backup/empty-device restore evidence.\n\n## Changes\n\n- retain six process-crash reports for macOS/APFS, Linux/ext4, and Windows/NTFS across `durable_group` and `durable_sync`\n- add a sentinel-protected power-cut fixture and a bounded 20-trial QEMU matrix covering every record/data-sync/checkpoint/directory-sync/receipt boundary\n- add a separate institutional QEMU harness for real filesystem ENOSPC, clean unmount and repeated whole-guest reopen, read-only fsck, and offline backup/restore\n- retain a machine-readable `Single-Host Institutional Profile v1` aggregate with source and raw-evidence SHA-256 bindings\n- enforce explicit non-claims for physical host restart, physical power loss, macOS/Windows device power cut, off-host backup, production eligibility, and absolute performance SLOs\n\n## Verification\n\n- `./shifu check:source` passed after the latest dev baseline merge: 115/115 source-contract tests, build-free\n- native `./shifu test:durable-ingest`, `./shifu test:crash-recovery`, and `./shifu test:projection-bootstrap` passed on agent-120 at `c7c0c680e`\n- `mvp-smoke-v1` Episode qualification passed 5/5 scenarios at `c7c0c680e`; all seven correctness violation counters are zero\n- disposable QEMU power-cut matrix passed 20/20 trials for `durable_group` and `durable_sync`\n- real ext4 ENOSPC produced `unknown/io_error` with no durable watermark; fresh reopen reported durable sequence 0 and classified the complete unacknowledged tail\n- three repeated whole-guest reopens recovered the exact sequence-1 frontier\n- offline backup and restored empty data device had identical SHA-256; read-only fsck passed before backup and after restore; fresh restore boot recovered sequence 1 with observed RPO 0 at the quiesced cut\n\nNo GitHub self-hosted workflow was dispatched for qualification. All device-tier evidence was produced through local Shifu on a sentinel-protected disposable QEMU workspace.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Retain process-crash and disposable Linux/ext4 device-tier evidence for ADR-0068 while preserving explicit physical-host, off-host-backup, production, and performance non-claims\",\n  \"verification\": [\"Build-free Shifu source gate passed with 115 tests at 7ddb217f\", \"Disposable QEMU power-cut matrix passed 20/20 trials\", \"Real ENOSPC, repeated whole-guest reopen, offline backup/restore, and Episode smoke evidence passed at c7c0c680e\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe retained aggregate is qualification evidence for one named disposable envelope. It does not activate a production profile or change release/publishing workflows.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T16:23:27Z",
          "mergedAt": "2026-07-13T16:33:57Z",
          "additions": 4324,
          "deletions": 17,
          "changedFiles": 58
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 795,
          "url": "https://github.com/kungfu-systems/kungfu/pull/795",
          "title": "feat(durability): expose evidence-bound product capability",
          "body": "## Summary\n\nExpose the retained ADR-0068 qualification result as one evidence-bound product capability without activating a production durability profile. C++ owns the semantic report; Python, Node, and `kungfu agent capabilities --json` are thin projections of that authority.\n\n## Changes\n\n- add `kungfu.durability.capability/v1` with per-profile availability, exact evidence digests, restore scope, trust assumptions, and explicit non-claims\n- report `durable_group` and `durable_sync` as test-fixture-only and fail closed with `production_eligible: false`\n- project the same C++ authority through Python, Node, and the agent capability CLI\n- bind the product report to retained three-platform process-crash and disposable Linux/ext4 QEMU evidence\n- update public qualification and known-limits documents to name the passed test envelope without implying physical-host, off-host-backup, or production qualification\n\n## Verification\n\n- `./shifu check:source` passed: 117/117 source-contract tests plus docs, TypeScript, Python, C++ format, lint, and type checks\n- local `./shifu build:core` passed with Apple Clang 21 / arm64 / C++23 using the existing host Conan cache through Shifu\n- `./shifu test:durability-contract` passed the C++ contract and Python/Node/agent-CLI projection checks\n- native Node binding suite passed 12/12 with `KUNGFU_REQUIRE_NATIVE=1`\n\nNo GitHub self-hosted workflow was dispatched for build or qualification. Heavy validation was performed locally through Shifu.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Expose retained ADR-0068 qualification as a fail-closed C++-owned capability projected consistently through Python, Node, and the agent CLI\",\n  \"verification\": [\"Build-free Shifu source gate passed with 117 tests\", \"Local Shifu Core build and C++/Python/Node durability contract passed\", \"Native Node binding suite passed 12/12\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe capability report is qualification metadata for a named test/disposable envelope. It does not change publishing, activate a production profile, or claim physical-host power-loss or off-host restore qualification.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T17:02:24Z",
          "mergedAt": "2026-07-13T17:05:17Z",
          "additions": 434,
          "deletions": 39,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 797,
          "url": "https://github.com/kungfu-systems/kungfu/pull/797",
          "title": "feat: complete ADR-0049 layer qualification",
          "body": "## Summary\n\n- complete the ADR-0049 seven-layer implementation and evidence-derived qualification harness\n- preserve exact format, native SDK, npm/PyPI/Cargo SDK, CLI/TUI, GUI, and assembled-product boundaries\n- keep public-registry-dependent rows honestly unpublished and perform no package or alpha release\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add fail-closed clean-install, compatibility, budget, and cross-platform qualification evidence\n- complete the Windows narrow storage ABI, SDK linkage, and cross-platform coordination lock backend\n- qualify display-less Linux AppImage startup without changing the shipped launch path\n- integrate the current `dev/v4/v4.0` durability, agent-console, cache, documentation, and ADR admission contracts\n- correct the merged KFX export boundary so agent-console helpers come from the capability entrypoint\n\n## Verification\n\n- exact three-host artifact candidate: `c7cda021377c4f08d3f8ba50cb65bf2d2f10a0da`\n- post-mainline merged tree: `3a46939d03dce93c65320fea9490f4bff5487dc4`\n- final linear candidate: `e6cbbffaed9a6cb95bce330e825916a5102f76a7` (implementation commit `409537aa42752388311705305a61a323f06ffa22`)\n- at `c7cda0213`, `./shifu check` passed: ADR-0049 harness 39/39, ADR-0068 7/7, SDK contracts 27/27\n- at `c7cda0213`, macOS ARM64 local `dist + release qualification` passed, exit 0\n- at `c7cda0213`, Windows x64 local `dist + release qualification` passed, exit 0\n- at `c7cda0213`, Linux x64 local `dist + release qualification` passed, exit 0; Episode 21/21 scenarios and 14/14 gates\n- at `3a46939d0`, post-mainline-merge build-free source gate passed: 118 source-acceptance tests, 61 documentation contract tests, TypeScript, Biome, Ruff, mypy over 129 source files, and C/C++ format\n- at `409537aa4`, the linear implementation commit's staged `./shifu check` passed, including Rust clippy and workspace tests plus KFD evidence validation\n- at `e6cbbffae`, the final linear build-free source gate passed: 118 source-acceptance tests, 61 documentation contract tests, TypeScript, Biome, Ruff, and mypy over 129 source files\n- `e6cbbffae` differs from the verified `3a46939d0` tree only by the ADR-0049 implementation commit pointer required for linear-history reachability\n- no GitHub heavy build was used for the final candidate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Complete all seven ADR-0049 product layers and their fail-closed qualification harness without publishing artifacts\",\n  \"verification\": [\"Full Shifu check and local macOS ARM64, Linux x64, and Windows x64 release qualification at c7cda0213\", \"Post-mainline-merge source and staged gates at 3a46939d0\", \"Linearized staged and source gates at 409537aa4 and e6cbbffae\"]\n}\n-->\n\n## Explicit non-release boundary\n\nThis PR merges implementation and qualification into `dev/v4/v4.0`. It does not publish npm, PyPI, or crates.io packages; it does not create a GitHub Release or alpha tag; and no publication workflow is invoked. Public-registry-dependent rows remain honestly unpublished.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes release evidence and package surfaces but intentionally performs no publication or deployment side effect.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T19:33:39Z",
          "mergedAt": "2026-07-13T19:35:16Z",
          "additions": 3821,
          "deletions": 256,
          "changedFiles": 91
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 798,
          "url": "https://github.com/kungfu-systems/kungfu/pull/798",
          "title": "fix(adr): point ADR-0049 evidence at the on-dev qualification commit",
          "body": "Correct ADR-0049's qualification evidence pointer.\n\nThe ADR-0049 layer-qualification work landed on `dev/v4/v4.0` as `360c1dfca` via a\nrebase merge, which rewrote the feature-branch hash. ADR-0049\n`implementation_commits` still referenced the pre-rebase hash `409537aa` — present\nonly on `feature/adr0049-seven-staged-release-linear-v2` and unreachable from the\nmainline — so the docs `adr-evidence-commit` gate rejects every new `dev/*` PR.\nThis points the evidence at the reachable on-dev commit (identical patch-id, no\ncontent change).\n\n<!-- kungfu-adr-release:v1 {\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"ADR-0049\"],\"summary\":\"Correct ADR-0049 qualification evidence to the reachable on-dev commit 360c1dfca; the pre-rebase feature hash 409537aa is unreachable from mainline and breaks the adr-evidence-commit docs gate for all new dev PRs.\",\"verification\":[\"git merge-base --is-ancestor 360c1dfca origin/dev/v4/v4.0 confirms the evidence commit is reachable from mainline\",\"360c1dfca has an identical patch-id to the unreachable 409537aa (same change, rebased hash)\",\"implementation_status unchanged (staged); one-line front-matter correction only\"]} -->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T23:39:41Z",
          "mergedAt": "2026-07-13T23:43:39Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 799,
          "url": "https://github.com/kungfu-systems/kungfu/pull/799",
          "title": "feat(runtime): ADR-0077 live-runtime plumbing — peer react hook + coordinator page-precreate",
          "body": "ADR-0077 increment: the live-runtime plumbing the journal-native arbiter is\nbuilt on. No arbiter yet — this lands the two primitives and keeps the arbiter\nitself deferred to a follow-up.\n\n**What lands**\n\n- `feat(runtime)`: a Python-overridable peer react hook — `on_react` / `on_start`\n  trampolines plus `observe(carrier_type, callback)` and the `request_read_from`\n  / `request_read_from_public` / `request_write_to` / `get_public_writer`\n  bindings — so a live consumer written outside C++ can react to journal frames\n  without a bespoke C++ reactor subclass. No schema change.\n- `fix(journal)`: a coordinator-side correctness fix. `register_peer` read-joins\n  a freshly-registered peer's PUBLIC / SYNC / command journals before that peer\n  has opened its own writers, so the pages may not exist yet; the read-only page\n  load then failed with ENOENT and tore down the coordinator event loop. The\n  coordinator reader now creates the missing page (`coordinator_precreate`)\n  instead of failing — the \"create sync journal\" intent already at the register\n  site. Guarded so only the coordinator reader and only a genuinely missing page\n  take this path; normal readers and existing pages are unaffected. This path\n  had no exercised consumer since v4 removed the last live peer.\n\n**Validation (local core build)**\n\n- Nine native journal / durability / crash-recovery ctests pass.\n- A three-process live round-trip (coordinator + a writer peer + a reader peer)\n  delivers an action-envelope frame through the react hook — reader `observe`\n  callback fires with the decoded payload — with the coordinator surviving both\n  peers' registration purely on the page-precreate fix (no peer-side workaround).\n\n**Scope**\n\nThe arbiter peer that consumes the react hook (the in-memory lock table that\nreplaces the lock waiter's poll with a grant frame) and the instruct path are\ndeferred; they build directly on this plumbing. ADR-0077 stays `partial`.\n\n<!-- kungfu-adr-release:v1 {\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"ADR-0077\"],\"summary\":\"ADR-0077 live-runtime plumbing increment: a Python-overridable peer react hook (observe/on_react/on_start plus read/write bindings) and a coordinator page-precreate fix so a freshly-registered peer no longer crashes the coordinator when its PUBLIC/SYNC/command journals do not yet exist. The journal-native arbiter that consumes these is deferred to a follow-up.\",\"verification\":[\"nine native journal/durability/crash-recovery ctests pass on a local core build\",\"three-process live peer round-trip (coordinator + writer + reader) delivers a frame through the react hook with the coordinator surviving registration on the page-precreate fix alone, no peer-side workaround\",\"clang-format / ADR / docs commit gates pass; ADR-0077 implementation_status stays partial\"]} -->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T23:47:21Z",
          "mergedAt": "2026-07-13T23:49:21Z",
          "additions": 61,
          "deletions": 6,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 800,
          "url": "https://github.com/kungfu-systems/kungfu/pull/800",
          "title": "fix(gui): recover profile and agent console setup",
          "body": "## Summary\n\n- expose the exact upgrade gate when a promoted factory Profile root supersedes the active workspace root\n- distinguish Agent detection loading, failure, and empty states in Agent Console\n- let the first explicit launch of a detected Agent remember it as the default runtime profile\n\n## Validation\n\n- 22 targeted Work Dashboard and Agent Runtime tests passed\n- ./shifu check:types passed\n- ./shifu dist:dir produced a verified macOS Product candidate\n- ./shifu check and check:source reach the pre-existing ADR-0049 evidence reachability failure on the current base; changed-file checks pass\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Restores existing Profile lifecycle and Agent Console behavior without changing an architectural decision.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T23:54:40Z",
          "mergedAt": "2026-07-13T23:58:01Z",
          "additions": 243,
          "deletions": 30,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 801,
          "url": "https://github.com/kungfu-systems/kungfu/pull/801",
          "title": "fix(core): sync generated peer runtime stubs",
          "body": "## Summary\n\n- sync the committed Python runtime stub with the five peer methods already exposed by the native binding\n- restore clean Product provenance after deterministic core rebuilds\n\n## Validation\n\n- generated diff reproduced identically across two full macOS Product builds\n- staged repository gates passed\n- prior exact merged-head Product build completed with verified KFD-3 receipt\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Synchronizes a generated projection with already-implemented runtime bindings without changing an architectural decision.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T00:08:58Z",
          "mergedAt": "2026-07-14T00:11:10Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 116,
          "url": "https://github.com/kungfu-systems/build-images/pull/116",
          "title": "feat(pilots): add comparator Docker environments",
          "body": "## Summary\n\n- add immutable-input Aeron 1.52.2, ClickHouse 26.3.10.60 LTS, and PostgreSQL 18.4 disposable Compose profiles\n- add a shared neutral runner, explicit plan/execute boundary, scoped cleanup, and unscored evidence manifests\n- keep the Kungfu profile fail-closed until a formal product artifact, exact SHA-256, release evidence, and installer contract exist\n- run hosted normal, forced-restart, recovery, and export/restore entry smokes without changing the maintained image release family\n\n## Claim boundary\n\nThese Docker pilots provide functional and recovery-path qualification only. They are not performance evidence and do not replace designated native-host measurements or user installation-cost testing.\n\n## Validation\n\n- pnpm run check\n- shellcheck pilots/comparator/scripts/pilot.sh\n- bash pilots/comparator/scripts/pilot.sh plan aeron\n- bash pilots/comparator/scripts/pilot.sh plan clickhouse\n- bash pilots/comparator/scripts/pilot.sh plan postgres\n- verified the Kungfu plan fails closed with exit code 3\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, billing, quota, or usage-attribution changes\n- [x] No official hosted or managed service changes\n- [x] No official branding, package-name, release-identity, or domain changes\n- [x] Release evidence is only consumed as an immutable-input gate; no package publication or deployment",
          "author": "dongkeren",
          "createdAt": "2026-07-13T23:56:59Z",
          "mergedAt": "2026-07-14T00:21:54Z",
          "additions": 728,
          "deletions": 59,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 802,
          "url": "https://github.com/kungfu-systems/kungfu/pull/802",
          "title": "feat(core): call generic frame checksum + decode primitives from outer rings (ADR-0078)",
          "body": "## Summary\n\nADR-0078 Decision 3 (outer-ring de-duplication): `rewind` `BundleDecoder` decodes\nthrough the exposed `decode_flatbuffer_payload_json` primitive and `atlas` store\nchecksums call `checksum_frame` / `checksum_payload`, instead of re-implementing\nFlatBuffers reflection, crc32c/fnv1a, and the `frame_header` layout in Python.\nDomain folds stay in the outer rings.\n\n- `frame_header` opts into a read-only zero-copy Python buffer protocol.\n- `decode_json` gains `enum_as_int` (integer enums matching the three reflection\n  decoders) and `object_name` (decode a specific table, not just the root).\n- `implementation_status` stays `partial`: the cross-membrane enum-int symmetry\n  (C-ABI / Rust `decode_frame_json`) is a recorded follow-up.\n\n## Validation (three hosts, local — no CI reliance for heavy build)\n\n- Mac (arm64) + agent-120 (Linux x86_64) + DARKHERO (Windows x86_64): full build +\n  14 equivalence tests each, all green.\n- old-vs-native checksum parity (crc32c + fnv1a64); rewind field-by-field parity\n  vs the generated-accessor oracle; enum-as-int + absent-string-None contract.\n- Mac full python suite: 331 passed; the 11 failures are verified pre-existing on\n  base (dev/v4/v4.0), i.e. zero regression from this change.\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"ADR-0078\"],\"summary\":\"ADR-0078 Decision 3: rewind decode and atlas checksum de-duplicate onto the exposed generic primitives; domain folds stay in the outer rings.\",\"verification\":[\"Mac arm64 + agent-120 Linux x86_64 + DARKHERO Windows x86_64: full build + 14 equivalence tests each\",\"old-vs-native checksum parity (crc32c + fnv1a64); rewind field-by-field parity vs generated-accessor oracle; enum-as-int + absent-string-None contract\",\"Mac full python suite 331 passed; 11 failures verified pre-existing on base (zero regression)\"]}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T00:19:21Z",
          "mergedAt": "2026-07-14T00:23:00Z",
          "additions": 353,
          "deletions": 144,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 803,
          "url": "https://github.com/kungfu-systems/kungfu/pull/803",
          "title": "feat(qualification): close ADR-0049 Shifu gates",
          "body": "## Summary\n\nClose ADR-0049 as an implemented, first-class Shifu Gate qualification chain without performing any publication or dispatching the modified CI workflows.\n\n## Related issue\n\nADR-0049\n\n## Changes\n\n- register exact format, SDK, product-surface, and seven-row publication Gates in the alpha, release, and promotion profiles\n- emit digest-bound task evidence and unified source-bound Gate receipts\n- replace ad-hoc release aggregation wiring with evidence-root discovery and a fail-closed Gate action\n- bind the existing Buildchain and publication workflow code to the Gate catalog\n- add an independent public qualification contract and update ADR/product maturity navigation\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu docs:check`\n- `./shifu check:gate-catalog`\n- `./shifu gate validate --json`\n- local Gate plan inspection for `alpha-pr` and `release-promotion`\n- 18 focused Node tests for Gate evidence, artifact dispatch, release aggregation, and Buildchain install planning\n- changed-file Biome check\n\nThe modified GitHub workflows were not dispatched or treated as validation evidence. No alpha, npm, PyPI, crates.io, GitHub Release, tag, signing, or other publication action was performed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Complete the Shifu Gate registry, profile, receipt, workflow-binding, documentation, and fail-closed aggregation closure for all seven layer products.\",\n  \"verification\": [\"Local build-free source acceptance passed\", \"Gate registry, catalog, plans, docs, and focused tests passed\", \"No CI workflow dispatch or publication was performed\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change modifies release-evidence and publication-workflow code but deliberately does not execute it. Publication remains separately authorized and guarded by the existing manual `execute` input and production environment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T00:31:16Z",
          "mergedAt": "2026-07-14T00:33:39Z",
          "additions": 965,
          "deletions": 76,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 804,
          "url": "https://github.com/kungfu-systems/kungfu/pull/804",
          "title": "feat(gui): present workspace runtime as one foreground state",
          "body": "## Summary\n\nPresent the ordinary desktop runtime as one workspace-level foreground state instead of exposing supervisor and coordinator processes as separate user concerns.\n\nProcess health alone now reports Workspace online. The GUI reports Workspace ready only when explicit continuity evidence is available, preventing process presence from being mistaken for recovered live sessions.\n\n## Related issue\n\nADR-0077\n\n## Changes\n\n- add one shared workspace runtime presentation model for Electron main and renderer\n- collapse the tray and status bar process indicators into one Workspace status\n- retain raw supervisor and coordinator diagnostics in the advanced System Status view\n- accept an optional continuity state for ready, reconnecting, recovering, degraded, and needs-attention projections\n- add seven regression cases and include them in the KFX Profile Suite\n\n## Verification\n\n- ./shifu check:source\n- ./shifu check\n- ./shifu test:kfx-profile-suite\n- ./shifu build:app\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0077\"],\n  \"summary\": \"Project live-runtime and future agent continuity evidence into one workspace foreground status without exposing process topology in the ordinary GUI\",\n  \"verification\": [\"./shifu check:source\", \"./shifu check\", \"./shifu test:kfx-profile-suite\", \"./shifu build:app\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [ ] Documentation updated if behavior changed\n\nNo public documentation was changed because the advanced System Status diagnostics remain available and this PR only changes the ordinary shell projection.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T00:49:36Z",
          "mergedAt": "2026-07-14T00:54:24Z",
          "additions": 364,
          "deletions": 170,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 806,
          "url": "https://github.com/kungfu-systems/kungfu/pull/806",
          "title": "fix(gates): close direct workflow invocation drift",
          "body": "## Summary\n\nClose the first reverse-scan stage of the Kungfu Gate catalog. Direct Shifu Gate commands and the Buildchain Gate-profile workflow are now parsed from YAML into normalized execution facts and reconciled bidirectionally with registry policy and workflow bindings.\n\nKFD-1 version impact: patch. This strengthens an internal validation contract without changing a public runtime or artifact interface.\n\n## Related issue\n\nAtlas goal `2026-07-14-kungfu-gate-direct-reverse-scan`.\n\n## Changes\n\n- add a declared `yaml` parser and scan every managed workflow structurally\n- recognize POSIX, Windows, multiline, `cd &&`, and reusable Gate-profile forms\n- fail closed on rogue, missing, duplicate, mismatched, dynamic, unknown, or policy-drifting invocations\n- upgrade workflow bindings to v2 and document static versus runtime evidence boundaries\n\n## Verification\n\n- `./shifu check:gate-catalog`\n- `./shifu check:source` — 120 tests passed\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This patch strengthens Gate catalog validation without changing an accepted architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T00:53:12Z",
          "mergedAt": "2026-07-14T00:58:01Z",
          "additions": 462,
          "deletions": 49,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 809,
          "url": "https://github.com/kungfu-systems/kungfu/pull/809",
          "title": "feat(runtime): add live durability candidate receipts",
          "body": "## Summary\n\nAdd a default-off live durability candidate seam owned by the per-data-root state service. Exact requests can be retried and reconciled after restart without inventing success or failure. Production eligibility remains false. This supersedes PR #807 with a clean linear branch for the repository rebase-only merge policy.\n\n## Related issue\n\nAtlas goal 2026-07-14-kungfu-live-durable-receipts.\n\n## Changes\n\n- add explicit candidate activation, typed request conflict handling, and checkpoint receipt reconciliation\n- expose candidate status and metrics without changing the visible hot path\n- project native reconciliation through Python, Node, and the storage CLI\n- update ADR-0068, design, and public qualification boundaries\n- make the Buildchain source-install argv assertion inspect tokens instead of absolute path substrings\n\n## Verification\n\n- local Shifu build:core\n- local Shifu test:durable-ingest\n- local Shifu test:state-service\n- local Shifu test:durability-contract\n- local Shifu check:source\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Complete the default-off live durability receipt and restart reconciliation candidate seam\",\n  \"verification\": [\"local Shifu Core build and durability contract suites\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:00:34Z",
          "mergedAt": "2026-07-14T01:02:50Z",
          "additions": 696,
          "deletions": 51,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 805,
          "url": "https://github.com/kungfu-systems/kungfu/pull/805",
          "title": "feat(coordination): journal-native lock arbiter body (ADR-0077)",
          "body": "Journal-native lock arbiter body — the ADR-0077 next increment over the\nfile-backed lock prototype (PR #771) and the runtime plumbing (PR #799).\n\n**What lands**\n- `coordination/arbiter.py` — pure `LockTable` (FIFO request/release/forget) +\n  action-envelope payload helpers; stdlib-only, unit-tested off the native\n  runtime (14 cases in `test_coordination_arbiter.py`).\n- `coordination/arbiter_peer.py` — resident `Arbiter(peer)`: `serve()` manual\n  loop, observes `coordination.lock.request`/`release`, is the single writer of a\n  `coordination.lock.grant` stream, and records the whole stream as one\n  replayable coordination Episode (native audit that subsumes the first slice's\n  per-run `audit.py`). Auto-release on both paths: clean holder sends a release\n  frame; a hard-killed holder is reclaimed by a same-host pid-liveness reaper.\n- `coordination/arbiter_client.py` — `LockClient` (manual-driven acquire /\n  await-grant / release with zero table poll) + `send_instruct` one-shot.\n\nCustom `coordination.*` action types ride the action envelope with no C++ schema\nchange. First live Python peer and first `coloop`-style grant-await consumer in\nthe tree.\n\n**Verification (local core build)** — race: two workers serialize with zero\npoll; kill: a SIGKILLed holder's lock is reclaimed and granted onward; instruct:\ndelivered to a lock-holding worker; audit: coordination stream replays as a\nclosed Episode (6 frames). `LockTable` unit suite green. `shifu build` green.\n\n**Deferred** — switching the `kungfu lock` CLI onto the arbiter backend as a\nmanaged resident service (library + mechanism are in place; CLI still drives the\nfile lock). ADR-0077 stays `partial`.\n\n<!-- kungfu-adr-release:v1 {\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"ADR-0077\"],\"summary\":\"Journal-native lock arbiter body: resident Arbiter peer + pure LockTable + LockClient + replayable Episode audit; the ADR-0077 next increment over the file-backed lock, status stays partial (kungfu lock CLI backend switch deferred).\",\"verification\":[\"LockTable unit suite (14 cases) green off the native runtime\",\"cross-process harness on a local core build: race two-workers-serialize zero-poll, kill SIGKILL-holder-reclaimed-and-granted, instruct delivered-to-lock-holding-worker\",\"coordination stream replays as a closed audit Episode via episode_list (6 frames)\",\"shifu build green SHIFU_BUILD_RC=0\"]} -->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T00:50:36Z",
          "mergedAt": "2026-07-14T01:12:13Z",
          "additions": 856,
          "deletions": 9,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 808,
          "url": "https://github.com/kungfu-systems/kungfu/pull/808",
          "title": "fix(gui): inject complete KFX shared-module contract",
          "body": "## Summary\n\nInject the complete published KFX shared-module contract into every GUI renderer boundary and fail Product assembly when a bundled KFX external cannot be landed.\n\n## Verification\n\n- `./shifu test:kfx-profile-suite`\n- `./shifu check:source`\n- `./shifu exec node --test product/scripts/dist.test.mjs`\n- `./shifu --filter @kungfu-tech/sdk run build`\n- `./shifu build:app`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fix packaged KFX shared-module injection and qualification without changing an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe Product assembly gate now verifies the shipped KFX external contract before build registration.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T00:55:18Z",
          "mergedAt": "2026-07-14T01:16:08Z",
          "additions": 189,
          "deletions": 40,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 810,
          "url": "https://github.com/kungfu-systems/kungfu/pull/810",
          "title": "fix(gates): close controller workflow drift",
          "body": "## Summary\n\nClose Kungfu workflow-to-Gate policy drift in both directions for direct Gate calls, Buildchain Gate profiles, and the six remaining controller classes.\n\n## Related issue\n\nAtlas goal 2026-07-14-kungfu-gate-controller-reverse-scan.\n\n## Changes\n\n- replace legacy requiredSnippets witnesses with finite structured controller adapters\n- reverse-discover registered controller identities across workflow YAML\n- bind direct Gate arguments and profile refs/inputs to declared invocation contracts\n- fail closed on missing, duplicate, rogue, or input-drifted workflow facts\n- document the adapter boundary and extension/retirement rule\n\n## Verification\n\n- ./shifu fix\n- ./shifu check:gate-catalog\n- ./shifu check:source (124 tests)\n- ./shifu check\n\n## KFD-1 version impact\n\nPatch. This strengthens a Kungfu repository checker without changing a registered public contract or opening a version line.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This patch strengthens repository-local Gate workflow drift enforcement without changing an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: workflow admission semantics only; validation is source-static and does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:18:32Z",
          "mergedAt": "2026-07-14T01:21:16Z",
          "additions": 740,
          "deletions": 106,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 811,
          "url": "https://github.com/kungfu-systems/kungfu/pull/811",
          "title": "docs(layers): link release Gate policy path",
          "body": "## Summary\n\nLink Product Layers directly to the seven-row qualification contract, Gate catalog, generated policy matrix, and machine source of truth.\n\n## Verification\n\n- `./shifu docs:check`\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Documentation-only navigation change; it does not alter an architecture contract or Gate policy.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:34:14Z",
          "mergedAt": "2026-07-14T01:39:21Z",
          "additions": 7,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1174,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1174",
          "title": "feat: add controller evidence contracts",
          "body": "## Summary\n- add a generic versioned controller plan/receipt contract bound to exact consumer and runtime identities\n- aggregate controller outcomes with fail-closed missing-receipt semantics and a Shifu-only gate envelope\n- carry compact controller receipt references through Release Candidate and Release Passport\n- publish generated controller registry, public workflow metadata, documentation, and fixtures\n\n## Validation\n- `pnpm run check` (585 tests)\n- `git diff --check`\n- generated workflow, site, contract, registry, and action bundle checks\n\n## Delivery\n- train ref: `train/v2/v2.3/gate-controller-evidence-contract`\n- downstream source/runtime binding evidence will be attached before merge/promotion\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:24:31Z",
          "mergedAt": "2026-07-14T01:42:06Z",
          "additions": 7694,
          "deletions": 364,
          "changedFiles": 49
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1175,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1175",
          "title": "chore(release): promote controller evidence contract to alpha",
          "body": "## Summary\n\nPromote the controller evidence contract after Buildchain PR #1174 and qualifying downstream Kungfu validation.\n\n## Evidence\n\n- Buildchain PR #1174 independently approved and merged as `946157b5577bf89a81121036dc5216bf585ecc85`\n- `pnpm run check`: 586 passed; generated contract current; action bundles built\n- Buildchain PR fixture: source check, Linux, macOS, Windows, plan, and final controller receipt all green\n- Kungfu downstream run 29299105492: consumer `8604c22e49852d19e2c303804f9f2ffed53216d1`, runtime `839ab985bcf182cc8d497f95fc0fcd3b578c5296`, qualifying receipt `sha256:886c503156d38c5670b2ed049f7f9b622c2d7be7d5bfdfee66af1b9d661fccfd`\n\nNo consumer Gate IDs or policy decisions enter Buildchain.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:44:43Z",
          "mergedAt": "2026-07-14T01:47:00Z",
          "additions": 7694,
          "deletions": 364,
          "changedFiles": 49
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 812,
          "url": "https://github.com/kungfu-systems/kungfu/pull/812",
          "title": "fix(gui): preserve node-pty spawn helper mode",
          "body": "## Summary\n\nRestore executable permissions on packaged node-pty Darwin spawn helpers so Agent Console PTYs can launch.\n\n## Related issue\n\nDogfood report: packaged Agent Console fails with `posix_spawnp failed`.\n\n## Changes\n\n- repair Darwin spawn-helper modes during Electron afterPack\n- fail the packaged-app audit when the helper is missing or non-executable\n- add a regression fixture to the changed-scope qualification suite\n\n## Verification\n\n- `./shifu check`\n- fixture proves mode 0644 fails audit and repaired mode passes\n- packaged macOS app launches `codex --version` through its bundled Electron and node-pty (exit 0)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Packaging bug fix restores the existing Agent Console PTY contract without changing architecture.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not needed; existing behavior restored)",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:45:24Z",
          "mergedAt": "2026-07-14T01:47:20Z",
          "additions": 112,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 813,
          "url": "https://github.com/kungfu-systems/kungfu/pull/813",
          "title": "feat(runtime): add projection authority candidate",
          "body": "## Summary\n\nAdd an explicit, default-off projection authority candidate for live peer startup while retaining the coordinator compatibility bridge as the default rollback path. The candidate remains production-ineligible.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- carry required, optional, or none projection requirements as an additive Register JSON extension\n- validate a qualified snapshot-through-T plus replay-after-T image before required peer registration and emit it before RequestStart\n- skip coordinator-owned business PUBLIC/SYNC joins and compatibility restore only for explicitly declared candidate peers\n- keep undeclared peers on the existing compatibility path\n- expose one libkungfu status through Python, Node, peer bindings, and the storage CLI\n- retain same-cut parity, atomic hydration, rollback, corruption, rebuild, and process-restart evidence\n- update ADR-0068, design, qualification, known-limits, and public metadata\n\n## Verification\n\n- `./shifu build:core`\n- `./shifu test:projection-bootstrap`\n- `./shifu test:state-service`\n- `./shifu test:durable-ingest`\n- `./shifu test:durability-contract`\n- `./shifu test:runtime-errors`\n- `./shifu check`\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Add the default-off live projection authority candidate with explicit startup requirements, rollback, status, and restart evidence while retaining the default compatibility bridge\",\n  \"verification\": [\"Local Core build\", \"projection and durability contract suites\", \"changed-scope check\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:52:42Z",
          "mergedAt": "2026-07-14T01:55:30Z",
          "additions": 1056,
          "deletions": 64,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1177,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1177",
          "title": "fix: preserve tree-equivalent controller evidence",
          "body": "## Summary\n\n- preserve the exact controller receipt source SHA from the release-candidate build\n- allow that historical source only when the promotion channel SHA equals the final Passport source and the Release Candidate proves the two Git trees are equivalent\n- keep non-equivalent and unproven source substitutions fail-closed\n\n## Failure reproduced\n\n- failed alpha promotion run: 29299474874\n- release-candidate source: 3388c38692a618447283a15a6412fcb928da5107\n- alpha promotion source: e80475ac79f2673396c1fb006f381d83d20d688d\n- failure: controller receipt reference source SHA mismatch\n\n## Validation\n\n- targeted controller, release-candidate, release-passport, and promotion tests: 184/184\n- pnpm run generate:site\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:57:53Z",
          "mergedAt": "2026-07-14T02:02:16Z",
          "additions": 102,
          "deletions": 50,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1178,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1178",
          "title": "chore(release): repair controller evidence alpha promotion",
          "body": "## Summary\n\nPromote the tree-equivalent controller evidence repair and resume the durable alpha transaction.\n\n## Evidence\n\n- fix PR #1177 independently approved and merged as 8c24e90ccc881d6d194ec79b9cdf7761daf3b4af\n- failed promotion run 29299474874 reproduced the source-SHA mismatch after the release-candidate tree-equivalence gate had passed\n- the fix preserves the exact receipt source and accepts it only under explicit tree-equivalence proof\n- local pnpm run check passed after synchronizing the current dev release state\n- dev Verify run 29300064959 passed\n- downstream Kungfu qualifying receipt remains sha256:886c503156d38c5670b2ed049f7f9b622c2d7be7d5bfdfee66af1b9d661fccfd",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:03:49Z",
          "mergedAt": "2026-07-14T02:06:01Z",
          "additions": 102,
          "deletions": 50,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 117,
          "url": "https://github.com/kungfu-systems/build-images/pull/117",
          "title": "feat(pilots): consume prebuilt Kungfu CLI package",
          "body": "## Summary\n\n- consume a prebuilt `kungfu-episodes-cli-linux-x64.tar.gz` package instead of compiling Kungfu in Docker\n- verify the package SHA-256 and `kungfu.product.cli/v1` metadata before installing its declared CLI\n- add a reusable package-smoke workflow that downloads an artifact produced earlier in the caller's workflow run\n- exercise Episode write/query/export, SIGKILL restart, fsck and isolated restore\n- keep all Docker evidence explicitly unscored and non-authoritative for performance\n\n## Package boundary\n\nPackage production happens before this comparator starts. The caller supplies the artifact name, package version, exact package SHA-256, exact source commit and workflow evidence URL. The ordinary pull-request smoke continues to cover the three self-contained comparator profiles; Kungfu runs only when a real prebuilt package is supplied.\n\nNo Kungfu source checkout, dependency installation or product compilation occurs inside the Dockerfile.\n\n## Validation\n\n- `pnpm run check`\n- `shellcheck pilots/comparator/scripts/pilot.sh`\n- `bash pilots/comparator/scripts/pilot.sh plan kungfu`\n- package-input manifest resolution fixture\n- `git diff --check`\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider billing, quota, or usage-attribution change\n- [x] No product or package publication\n- [x] No package name, release identity, or domain change\n- [x] Evidence remains disposable and marked unscored/non-authoritative\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:36:28Z",
          "mergedAt": "2026-07-14T02:07:50Z",
          "additions": 331,
          "deletions": 50,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1179,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1179",
          "title": "fix: decouple router controller runtime",
          "body": "## Summary\n\n- execute build-channel-router controller plans and receipts from the reusable workflow shell that defines the controller\n- keep the selected alpha or stable ref as the controlled build runtime only\n- bind controller evidence to the workflow-shell repository, ref, SHA, and contract digest\n\n## Failure reproduced\n\nAlpha self-dogfood run 29300407886 passed the alpha consumer but failed the stable consumer because v2 does not yet contain scripts/controller-evidence.mjs. The v2-alpha workflow shell was incorrectly trying to execute its new controller through the selected legacy stable runtime.\n\n## Validation\n\n- generated channel workflow is current\n- controller/build-surface tests passed\n- pnpm run generate:site\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:17:56Z",
          "mergedAt": "2026-07-14T02:20:07Z",
          "additions": 47,
          "deletions": 29,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 814,
          "url": "https://github.com/kungfu-systems/kungfu/pull/814",
          "title": "fix(terminal): add resizable console layouts",
          "body": "## Summary\n\nFix the Agent Console layout so it opens as one full-size pane and offers explicit resizable two-column, two-row, three-column, and three-row arrangements.\n\n## Changes\n\n- Replace the wrapping auto-fill grid with explicit row and column layouts.\n- Add draggable and keyboard-accessible separators with minimum pane sizes.\n- Keep restart behavior deterministic by returning to one pane.\n- Add focused layout and resize invariant tests.\n\n## Verification\n\n- `./shifu check`\n- `./shifu exec node --test extensions/terminal/tests/*.test.ts`\n- Focused TypeScript no-emit check for the terminal view and layout module\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix corrects the existing Agent Console presentation and resizing behavior without changing an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed or not required for this focused UI fix",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:14:42Z",
          "mergedAt": "2026-07-14T02:23:17Z",
          "additions": 329,
          "deletions": 30,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1180,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1180",
          "title": "chore(release): promote router controller compatibility fix",
          "body": "## Summary\n\nPromote the router-controller workflow-shell fix so alpha self-dogfood can verify both the new alpha controller and the legacy stable build runtime.\n\n## Evidence\n\n- fix PR #1179 independently approved and merged as 4173720b0bb53673adb939a71d84a7a1f1d1e5b8\n- alpha self-dogfood run 29300407886 proved the alpha path and reproduced the legacy stable bootstrap failure\n- controller evidence now binds the v2-alpha workflow shell while the selected v2 ref remains the controlled build runtime\n- local pnpm run check passed\n- dev Verify run 29300809262 passed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:21:25Z",
          "mergedAt": "2026-07-14T02:23:49Z",
          "additions": 47,
          "deletions": 29,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1181,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1181",
          "title": "fix: bind router controller registry",
          "body": "## Summary\n\nBind the build-channel-router controller plan to the registry inside the checked-out workflow shell.\n\n## Failure reproduced\n\nAlpha self-dogfood run 29301143270 checked out the correct v2-alpha controller runtime but the controller CLI retained its generic default registry path under .buildchain/runtime. Both alpha and stable controller plans therefore failed closed before builds started.\n\n## Validation\n\n- generated channel workflow is current\n- explicit controller-runtime registry assertion added\n- pnpm run generate:site\n- pnpm run check: 587/587",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:33:13Z",
          "mergedAt": "2026-07-14T02:35:24Z",
          "additions": 6,
          "deletions": 3,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1182,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1182",
          "title": "chore(release): promote router controller registry fix",
          "body": "## Summary\n\nPromote the explicit workflow-shell controller registry binding.\n\n## Evidence\n\n- fix PR #1181 independently approved and merged as 5f5e19d1bd5df0af2d2d017a1fe3f5ac36f75bf4\n- alpha self-dogfood run 29301143270 reproduced the stale default registry path\n- the generated router workflow now binds the registry under the controller-runtime checkout\n- pnpm run check passed 587/587\n- dev Verify run 29301443504 passed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:36:39Z",
          "mergedAt": "2026-07-14T02:39:01Z",
          "additions": 6,
          "deletions": 3,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1183,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1183",
          "title": "fix: decouple build controller runtime",
          "body": "## Summary\n\n- execute build-lifecycle controller plans and final receipts from the reusable build workflow shell\n- keep the selected alpha or stable ref as the controlled lifecycle runtime\n- bind controller runtime ref, SHA, contract digest, and registry to the workflow shell\n\n## Failure reproduced\n\nAlpha self-dogfood run 29301749569 passed both channel-router controllers. The stable consumer then failed inside the nested build-lifecycle controller because that controller still executed through the legacy v2 runtime.\n\n## Validation\n\n- alpha consumer path passed in run 29301749569\n- outer alpha and stable controller plans passed in run 29301749569\n- pnpm run generate:site\n- pnpm run check: 587/587",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:48:56Z",
          "mergedAt": "2026-07-14T02:51:19Z",
          "additions": 27,
          "deletions": 14,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1184,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1184",
          "title": "chore(release): promote build controller compatibility fix",
          "body": "## Summary\n\nPromote the reusable build-controller workflow-shell boundary.\n\n## Evidence\n\n- fix PR #1183 independently approved and merged as 87b9a5bb9cf2c51d6b07ff9bc2ad1d2e7721489b\n- alpha self-dogfood run 29301749569 passed channel-router controller evidence and isolated the nested stable build-controller failure\n- build-lifecycle controller plan and receipt now bind the workflow shell; selected v2 remains the lifecycle runtime\n- pnpm run check passed 587/587\n- dev Verify run 29302075065 passed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:52:41Z",
          "mergedAt": "2026-07-14T02:54:59Z",
          "additions": 27,
          "deletions": 14,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 815,
          "url": "https://github.com/kungfu-systems/kungfu/pull/815",
          "title": "feat(runtime): define topology-neutral activation contract",
          "body": "## Summary\n\n- define the KFD-1 runtime activation contract for storage-only, live-optional, and live-required operations\n- bind readiness to durable and projection cuts, with generation fencing, leases, receipts, stable errors, and explicit authority limits\n- register the runtime surface, generate KFD projections, and add source-gate fixtures rejecting six unsafe paths\n- document ProcessRuntimeHost as the next delivery stage and EmbeddedRuntimeHost as a production non-claim\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu docs:check`\n- `./shifu kfd:buildchain:check`\n- `./shifu exec node --test developer/sdk/tests/contract-cli.test.mjs`\n\n## Governance risk\n\nNo credentials, provider APIs, hosted services, release publication, deployment, or production runtime activation are changed. This PR delivers only the topology-neutral contract stage.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Land stage 1: the topology-neutral runtime activation contract, ADR, fixtures, source gate, registry entry, and generated KFD evidence without implementing ProcessRuntimeHost or EmbeddedRuntimeHost.\",\n  \"verification\": [\"./shifu check:source\", \"./shifu docs:check\", \"./shifu kfd:buildchain:check\", \"SDK contract CLI tests\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:51:27Z",
          "mergedAt": "2026-07-14T02:56:52Z",
          "additions": 2730,
          "deletions": 58,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 816,
          "url": "https://github.com/kungfu-systems/kungfu/pull/816",
          "title": "docs(adr): stabilize runtime contract evidence",
          "body": "## Summary\n\n- replace the pre-rebase implementation commit reference with the stable merged PR URL\n- preserve ADR-0080 at partial implementation status without changing runtime semantics or qualification claims\n\n## Verification\n\n- `./shifu docs:check`\n\n## Governance risk\n\nDocumentation evidence repair only; no runtime, deployment, release, or production behavior changes.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Replace the non-mainline pre-rebase commit evidence with the stable merged PR #815 evidence for the completed contract stage.\",\n  \"verification\": [\"./shifu docs:check\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:58:49Z",
          "mergedAt": "2026-07-14T03:00:29Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1185,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1185",
          "title": "Release v2.12.5 from qualified v2.12.5-alpha.5",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.12.5-alpha.5`\n- Candidate SHA: `38ef5648fd3e127055422c657652084ab4640a54`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.12`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T03:06:24Z",
          "mergedAt": "2026-07-14T03:07:27Z",
          "additions": 7795,
          "deletions": 379,
          "changedFiles": 52
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1187,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1187",
          "title": "fix: preserve controller receipts in release assets",
          "body": "## Summary\n- preserve authoritative controller receipt references when binary distribution re-collects a durable release passport\n- add regression coverage for the public GitHub Release asset path\n- regenerate bundled action and site contract metadata\n\n## Validation\n- `node --test tests/release-passport.test.mjs`\n- `pnpm run check` (587 tests)\n\n## Release evidence\nThis fixes the final gap observed after v2.12.5: the promotion-time passport carried controller receipts, but the public `buildchain.release.json` asset dropped them during binary collection.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T03:21:00Z",
          "mergedAt": "2026-07-14T03:23:04Z",
          "additions": 56,
          "deletions": 41,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1188,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1188",
          "title": "chore(release): promote controller receipt asset fix",
          "body": "## Summary\n\nPromote the durable controller receipt preservation fix into the v2.12 alpha channel.\n\n## Evidence\n\n- fix PR #1187 independently approved and merged as 5a164a8caf0e42b91fa2f2fa4149c24c9eca1749\n- promotion-time v2.12.5 Passport contained the receipt reference while the public binary-collected asset omitted it\n- binary collector now preserves authoritative `controllerReceipts` from durable release state\n- `pnpm run check` passed 587/587\n- dev Verify run 29303387021 passed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T03:24:59Z",
          "mergedAt": "2026-07-14T03:27:23Z",
          "additions": 56,
          "deletions": 41,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 818,
          "url": "https://github.com/kungfu-systems/kungfu/pull/818",
          "title": "feat(runtime): isolate process host from coordinator engine",
          "body": "## Summary\n\n- extract a directly callable `CoordinatorEngine` request seam with typed receipts\n- move PID files, signals, spawning, detachment, child ownership, and process diagnostics behind `ProcessRuntimeHost`\n- preserve the existing CLI and service entrypoints through compatibility delegation\n- keep the full semantic `RuntimeHost` requirement/handle adapter and production `EmbeddedRuntimeHost` as explicit non-claims\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python ./shifu exec uv run --project framework/core --frozen pytest framework/core/tests/python/test_runtime_service.py -q` (16 passed)\n- `./shifu exec uv run --project framework/core --frozen node scripts/source-acceptance.mjs` (128 contract tests; Ruff, Mypy, Biome, docs, KFD gates passed)\n- staged pre-commit gate passed\n\n## Governance risk\n\nNo credentials, provider APIs, hosted services, production release, deployment, or production embedded runtime are changed. This PR only isolates the current process placement boundary and adds a no-fork qualification seam.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Land stage 2: isolate the current supervisor/coordinator process placement behind ProcessRuntimeHost and add a directly callable CoordinatorEngine no-fork seam without claiming the semantic RuntimeHost broker or EmbeddedRuntimeHost.\",\n  \"verification\": [\"runtime_service pytest: 16 passed\", \"build-free source gate: 128 tests plus Ruff, Mypy, Biome, docs, and KFD checks\", \"staged pre-commit gate\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T03:23:53Z",
          "mergedAt": "2026-07-14T03:28:34Z",
          "additions": 459,
          "deletions": 208,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1189,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1189",
          "title": "fix: isolate controller workflow inputs",
          "body": "## Summary\n- preserve strict undeclared-input validation in the controller evidence core\n- bind reusable workflow controller plans only to descriptor-declared workflow-call inputs\n- prevent caller workflow_dispatch inputs from leaking across the reusable workflow boundary\n\n## Failure evidence\n- stable qualification run 29303872276 failed because site-libkungfu-dev canary run 29303966165 exposed ambient `buildchain_ref` beside declared `buildchain-ref`\n- the controller correctly rejected the ambient field, but the workflow adapter had passed the entire GitHub `inputs` context\n\n## Validation\n- controller/build-surface tests: 83/83\n- `pnpm run check`: 588/588",
          "author": "dongkeren",
          "createdAt": "2026-07-14T03:45:12Z",
          "mergedAt": "2026-07-14T03:47:15Z",
          "additions": 58,
          "deletions": 15,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1190,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1190",
          "title": "chore(release): promote controller input boundary fix",
          "body": "## Summary\n\nPromote reusable workflow controller input-boundary isolation into the v2.12 alpha channel.\n\n## Evidence\n\n- fix PR #1189 independently approved and merged as 7eac19e6375e78c4ce788b261317090edaff2e06\n- site-libkungfu-dev canary 29303966165 exposed caller ambient `buildchain_ref`\n- strict core validation remains unchanged; adapters bind only descriptor-declared workflow-call inputs\n- `pnpm run check` passed 588/588\n- dev Verify run 29304350207 passed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T03:49:01Z",
          "mergedAt": "2026-07-14T03:51:15Z",
          "additions": 58,
          "deletions": 15,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 819,
          "url": "https://github.com/kungfu-systems/kungfu/pull/819",
          "title": "feat(runtime): add capability-driven invocation broker",
          "body": "## Summary\n\n- add a contract-owned runtime operation registry for storage-only and live-required work\n- add `RuntimeCapabilityBroker` with deterministic plans and atomic invoke admission\n- keep storage-only callbacks daemonless and fail live-required process activation closed until semantic readiness exists\n- bind first-party Mission Control actions to the runtime operation authority while preserving older Profile v1 registries\n- keep generation-fenced recovery/readiness, product entrypoints, and production `EmbeddedRuntimeHost` as later-stage non-claims\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python ./shifu exec uv run --project framework/core --frozen pytest framework/core/tests/python/test_runtime_broker.py -q` (5 passed)\n- `./shifu exec uv run --project framework/core --frozen -- ./shifu check:source` (130 contract tests; docs, Biome, Ruff, mypy across 134 source files, and KFD checks passed)\n- staged pre-commit gate passed\n\n## Governance risk\n\nNo credentials, provider APIs, hosted services, deployment, production release, or production embedded runtime are changed. The process bridge deliberately returns `readiness_not_established` after requesting activation; PID or health diagnostics cannot admit live work.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Land stage 3: add the contract-owned operation registry and capability broker with daemonless storage admission and fail-closed live admission, while leaving generation-fenced readiness and product projection to later stages.\",\n  \"verification\": [\"runtime_broker pytest: 5 passed\", \"build-free source gate: 130 tests plus docs, Biome, Ruff, mypy, and KFD checks\", \"staged pre-commit gate\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T03:49:24Z",
          "mergedAt": "2026-07-14T03:51:48Z",
          "additions": 923,
          "deletions": 49,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1191,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1191",
          "title": "fix: infer controller workflow input boundary",
          "body": "## Summary\n\n- infer the workflow-call input boundary from controller descriptor provenance when a legacy reusable workflow shell does not set the explicit boundary\n- preserve explicit strict/workflow-call overrides and the strict core plan validator\n- cover workflow provenance, strict fallback, invalid overrides, and ambient input filtering\n\n## Validation\n\n- node --test tests/controller-evidence.test.mjs tests/build-surface.test.mjs (84/84)\n- exact legacy-shell smoke: ambient buildchain_ref excluded without BUILDCHAIN_CONTROLLER_INPUT_BOUNDARY\n- pnpm run check (589/589)",
          "author": "dongkeren",
          "createdAt": "2026-07-14T04:03:43Z",
          "mergedAt": "2026-07-14T04:09:00Z",
          "additions": 42,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1192,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1192",
          "title": "chore(release): promote descriptor input boundary inference",
          "body": "## Summary\n\nPromote descriptor-derived workflow-call input boundary inference into the v2.12 alpha channel so candidate runtimes remain compatible with the current stable v2 reusable workflow shell.\n\n## Evidence\n\n- fix PR #1191 merged as 689f8419ec0de91f45ef18220541de2a9b86c1eb\n- exact legacy-shell smoke excludes ambient buildchain_ref without an explicit boundary variable\n- core createControllerPlan still rejects undeclared inputs\n- pnpm run check passed 589/589\n- dev Verify run 29305248633 passed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T04:10:46Z",
          "mergedAt": "2026-07-14T04:12:58Z",
          "additions": 42,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 821,
          "url": "https://github.com/kungfu-systems/kungfu/pull/821",
          "title": "test(durability): retain agent-120 fault evidence",
          "body": "Supersedes #820 after a signed merge of the current dev baseline.\n\n## Summary\n\nAdd and retain the agent-120 Linux/ext4 production-candidate fault campaign while keeping every physical-host, physical-device, off-host, independent-failure-domain, and production claim closed.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- freeze a deterministic 360-trial QEMU matrix across two durability profiles, ten cut points, six virtual device/cache envelopes, and three seeds\n- make preparation and execution dry-run-first, sentinel-protected, local-Shifu-only, and append-only\n- add an explicitly non-qualifying canary with collision-free artifacts\n- retain 360/360 aggregate and raw JSONL evidence from agent-120\n- retain current-head Linux/ext4 process reports for durable_group and durable_sync\n- retain real ENOSPC, three fresh guest reopens, fsck/hash, and same-host offline backup/restore evidence\n- add build-free evidence integrity checks and update public qualification/known-limit documentation\n- align the qualification marker with the current projection candidate output\n\n## Verification\n\n- `./shifu build:core` on agent-120 using existing host-local Conan binaries\n- `./shifu durability:fault-campaign:qemu`: 360/360 passed\n- `./shifu durability:qualify` for `durable_group`: passed\n- `./shifu durability:qualify` for `durable_sync`: passed\n- `./shifu durability:institutional:qemu`: passed\n- `./shifu check:source`: 137 tests passed; build-free source gate passed\n- branch workflow audit: no workflow runs created\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Retain the bounded agent-120 Linux/ext4 process, QEMU device-model, ENOSPC, repeated-recovery, and same-host restore evidence without widening physical or production claims\",\n  \"verification\": [\"Local Core build\", \"360-trial QEMU campaign\", \"dual process qualification\", \"institutional QEMU drill\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T04:09:54Z",
          "mergedAt": "2026-07-14T04:16:29Z",
          "additions": 18973,
          "deletions": 101,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1193,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1193",
          "title": "Release v2.12.6 from qualified v2.12.6-alpha.3",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.12.6-alpha.3`\n- Candidate SHA: `94ea357ff52b7218c4e1439fe7bae2ecb337226c`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.12`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T04:23:34Z",
          "mergedAt": "2026-07-14T04:24:47Z",
          "additions": 165,
          "deletions": 71,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 822,
          "url": "https://github.com/kungfu-systems/kungfu/pull/822",
          "title": "feat(runtime): fence activation readiness generations",
          "body": "## Summary\n\n- serialize first activation with one cross-process owner per canonical workspace\n- persist atomic runtime snapshots and reuse one generation across concurrent first calls\n- advance generation only when process diagnostics are replaced; revalidate expanded capabilities in the same process generation\n- invoke existing durability reconciliation and projection candidate authorities, admitting readiness only at or beyond the requested cut\n- fail closed for missing/corrupt generation state, untracked running processes, absent readiness authority, and behind-cut evidence\n- retain lease/adoption/restart lifecycle, product entrypoint wiring, and production `EmbeddedRuntimeHost` as later-stage non-claims\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python ./shifu exec uv run --project framework/core --frozen -- python -m pytest -q framework/core/tests/python/test_runtime_broker.py` (17 passed)\n- `XDG_CACHE_HOME=/tmp/kungfu-codex-runtime-readiness-cache ./shifu exec uv run --project framework/core --frozen -- ./shifu check:source` (130 contract tests; 61 documentation contract tests; docs, Biome, Ruff, mypy across 134 source files, and KFD checks passed)\n- `./shifu kfd:buildchain` (KFD-1 witness, 3 KFD-2 claims, 113 KFD-3 surfaces)\n- staged pre-commit gate passed\n\n## Governance risk\n\nNo credentials, provider APIs, hosted services, deployment, production release, or production embedded runtime are changed. PID and health diagnostics remain non-authoritative. A running process without a valid fenced generation fails `stale_generation`; explicit adoption and lease/restart recovery remain stage 5 work. Product evidence discovery and entrypoint wiring remain stage 6 work.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Land stage 4: serialize first activation, persist and fence process generations, and bind native durability/projection readiness to the requested cut while leaving adoption, leases, restart recovery, product projection, and EmbeddedRuntimeHost to later stages.\",\n  \"verification\": [\"runtime_broker pytest: 17 passed\", \"build-free source gate: 130 tests plus 61 documentation contracts, Biome, Ruff, mypy, and KFD checks\", \"staged pre-commit gate\"]\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T04:44:00Z",
          "mergedAt": "2026-07-14T04:48:23Z",
          "additions": 1091,
          "deletions": 36,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 823,
          "url": "https://github.com/kungfu-systems/kungfu/pull/823",
          "title": "feat(runtime): add lease and recovery lifecycle",
          "body": "## Summary\n\n- persist generation-fenced semantic leases with holder, capability-subset, authority, expiry, renew, and release checks\n- atomically fence idle demand as draining before stopping one workspace route, then record stopped or failed completion\n- preserve only an exact fenced orphan coordinator across supervisor replacement; terminate untracked orphans\n- expire old-generation leases before restart and bound coordinator crash recovery to five attempts per 60-second window\n- keep route heartbeat TTL diagnostic and retain cross-machine leases, distributed election, high availability, product projection, and production EmbeddedRuntimeHost as non-claims\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python ./shifu exec uv run --project framework/core --frozen -- python -m pytest -q framework/core/tests/python/test_runtime_broker.py framework/core/tests/python/test_runtime_service.py` (43 passed)\n- `./shifu exec uv run --project framework/core --frozen -- mypy --config-file framework/core/pyproject.toml framework/core/src/python/kungfu/runtime_broker.py framework/core/src/python/kungfu/runtime_service.py` (passed)\n- `XDG_CACHE_HOME=/tmp/kungfu-codex-runtime-lease-cache ./shifu exec uv run --project framework/core --frozen -- ./shifu check:source` (143 source contract tests; 61 documentation contract tests; runtime contract 4 positive/6 negative fixtures; Ruff; mypy across 134 source files; passed)\n- `./shifu kfd:buildchain` (KFD-1 witness, 3 KFD-2 claims, 113 KFD-3 surfaces)\n- staged pre-commit gate passed\n\n## Governance risk\n\nNo credentials, provider APIs, hosted services, deployment, production release, cross-machine lease, distributed election, high availability, or production embedded runtime are changed. PID and route heartbeat facts remain diagnostics. Adoption requires the exact recorded coordinator generation; untracked or corrupt state fails closed.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Land stage 5: add holder- and generation-fenced semantic leases, atomic idle draining, exact coordinator adoption, old-generation lease expiry, and bounded restart recovery while leaving product projection, cross-machine coordination, and EmbeddedRuntimeHost to later stages.\",\n  \"verification\": [\"runtime broker and service pytest: 43 passed\", \"build-free source gate: 143 tests plus 61 documentation contracts, runtime fixtures, Ruff, mypy, and KFD checks\", \"staged pre-commit gate\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T05:19:20Z",
          "mergedAt": "2026-07-14T05:21:58Z",
          "additions": 1573,
          "deletions": 43,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 824,
          "url": "https://github.com/kungfu-systems/kungfu/pull/824",
          "title": "feat(durability): qualify agent120 absolute SLO",
          "body": "## Summary\n\nFreeze, execute, and retain the first absolute durability SLO for the named agent-120 Linux/x86_64/NVMe/ext4 candidate while keeping wider product and production claims closed.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- add a native durability SLO fixture with complete latency histograms, correctness knockout, recovery, projection, backup/restore, and resource measurements\n- freeze eight pre-measurement workloads for durable_group and durable_sync, including rapid rollover and two 15-minute soaks\n- add a default-dry-run, local-Shifu-only runner that refuses dirty source and existing evidence paths\n- bind execution to agent-120, ext4, and NVMe host facts and fsync every raw workload result\n- retain the passing candidate evidence index plus aggregate/raw artifact hashes\n- update durability, performance qualification, and known-limit documentation without widening mmap, power-loss, off-host, cross-platform, comparator, or production claims\n\n## Verification\n\n- local Mac `./shifu build:core`: passed\n- agent-120 `./shifu build:core` using existing host-local Conan binaries: passed\n- agent-120 `./shifu durability:slo -- --run-id 070e0804b-agent120-slo-v1 --execute`: 8/8 passed, zero violations\n- two 15-minute soaks: 449,984 durable_group and 224,992 durable_sync records\n- `./shifu check:source`: 150/150 tests passed; build-free source gate passed\n- branch workflow audit: no workflow runs created\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Freeze and retain the first bounded agent-120 absolute durability SLO without widening physical, cross-platform, comparator, or production claims\",\n  \"verification\": [\"Local Core build\", \"agent-120 Core build\", \"eight-workload durability SLO\", \"two 15-minute soaks\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T05:31:09Z",
          "mergedAt": "2026-07-14T05:40:58Z",
          "additions": 1628,
          "deletions": 10,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 757,
          "url": "https://github.com/kungfu-systems/kungfu/pull/757",
          "title": "shifu: two-level repo discovery + buildchain-answered KFD-3 layout",
          "body": "## Summary\n\nRepository-root discovery in the shifu launcher becomes two-level, and shifu\nstops holding a copy of the KFD-3 registry path.\n\n- **`resolve KFD-3 registry via buildchain layout`** — the registrar no longer\n  hardcodes `.buildchain/kfd/kfd-3/surfaces.json`. It asks the repo-pinned\n  `buildchain` binary (`buildchain layout --json`, contract\n  `kungfu-buildchain-layout-discovery`) and reads `kfd.registries.\"kfd-3\".path`\n  back, caching the answer per repo and buildchain version. The advisory\n  dispatch hot path resolves cache-only (no forced download), so `check` keeps\n  its fast startup. The registry's `registryPath` self-attestation is read back\n  and a drift warning is emitted on mismatch.\n- **`recognize buildchain-managed repos as a second root level`** —\n  `find_repo_root` gains Level 2: a `.buildchain-version`-pinned repo whose\n  KFD-3 registry declares `distribution.registrar = \"shifu\"` is served directly\n  (delegation no-ops with no entrypoint pair). A pin alone is not enough — the\n  explicit registrar declaration is required, so a buildchain-managed repo that\n  never opted in is not claimed. Lenient verbs (`--version`, `doctor`) skip the\n  Level-2 check and stay useful rootless.\n\nThe two welded seams shifu depends on — the `.buildchain-version` pin name and\nthe `buildchain layout --json` verb — are registered as a contract in\n`docs/contracts.md`. ADR-0044 (delegation) is unchanged. See SHIFU-ADR-0005.\n\n## Verification\n\n- `cargo test -p shifu` (25 tests) and `cargo clippy` / `cargo fmt` clean.\n- End to end against the pinned buildchain: a synthetic downstream repo\n  declaring `registrar: shifu` is recognized and dispatched; the same repo with\n  a non-shifu registrar, and a non-buildchain directory, both fall back to the\n  not-a-repo error.\n- ADR release gate and document-metadata contract validated locally.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0005\"],\n  \"summary\": \"Shifu repo-root discovery becomes two-level and asks buildchain for the KFD-3 layout instead of copying it.\",\n  \"verification\": [\n    \"cargo test -p shifu (25 tests) plus cargo clippy and fmt clean\",\n    \"end-to-end against pinned buildchain: synthetic downstream repo declaring registrar=shifu is recognized and dispatched; a non-shifu registrar and a non-buildchain directory both fall back to the not-a-repo error\"\n  ]\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:13:16Z",
          "mergedAt": "2026-07-14T05:53:27Z",
          "additions": 524,
          "deletions": 28,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 825,
          "url": "https://github.com/kungfu-systems/kungfu/pull/825",
          "title": "feat(runtime): unify product runtime projections",
          "body": "## Summary\n\n- add one contract-validated product runtime status that treats a daemonless workspace as available and preserves fenced generation, exact cuts, semantic leases, and typed failures\n- expose topology-neutral operation catalogs and read-only plans through CLI, and share the same runtime vocabulary through API, KFX, and libkungfu TypeScript declarations\n- make GUI and TUI product copy capability-driven: GUI startup, tray, ordinary quit no longer own resident runtime process lifecycle, while process facts remain advanced diagnostics\n- add parity/type/CLI/Python/GUI tests and regenerate KFD contract evidence\n- keep stage 6 open: live-required product action invocation and discovery of exact-cut native readiness evidence are not yet wired\n\n## Verification\n\n- `PYTHONPATH=framework/core/build/Release:framework/core/src/python KUNGFU_ALLOW_FOREIGN_RUNTIME=1 ./shifu --filter @kungfu-tech/core exec uv run --frozen python -m pytest tests/python/test_runtime_broker.py tests/python/test_runtime_service.py tests/python/test_runtime_cli.py -q` (50 passed)\n- `./shifu test:runtime-surface` (7 surfaces and 4 KFX actions aligned; libkungfu declaration compile proof passed)\n- API TypeScript build, KFX build, and GUI tests (14 passed)\n- `./shifu --filter @kungfu-tech/core exec uv run --frozen --project framework/core --directory . node scripts/source-acceptance.mjs` (143 source contract tests; 61 documentation contract tests; 221 Markdown files; 220 link/contract checks; Biome; Ruff; mypy across 134 source files; passed)\n- `./shifu kfd:buildchain` (KFD-1 witness, 3 KFD-2 claims, 113 KFD-3 surfaces)\n- staged pre-commit gate passed\n\n## Governance risk\n\nNo credentials, hosted services, deployment, production release, cross-machine leasing, distributed election, high availability, or production EmbeddedRuntimeHost are changed or claimed. Process health cannot establish product readiness. This delivery intentionally does not permit a live-required callback to bypass the broker: product action invocation remains open until exact-cut native evidence can be discovered and supplied fail closed.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Land the stage 6 projection slice: one daemonless-safe product runtime status, topology-neutral CLI planning, shared API and libkungfu vocabulary, and GUI/TUI process-ownership removal, while leaving exact-cut product action invocation and evidence discovery open.\",\n  \"verification\": [\"runtime broker, service, and CLI pytest: 50 passed\", \"runtime surface parity: 7 surfaces and 4 KFX actions\", \"build-free source gate: 143 tests plus 61 documentation contracts, Biome, Ruff, mypy, and KFD checks\", \"staged pre-commit gate\"]\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T06:19:14Z",
          "mergedAt": "2026-07-14T06:27:24Z",
          "additions": 1078,
          "deletions": 108,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 826,
          "url": "https://github.com/kungfu-systems/kungfu/pull/826",
          "title": "feat(durability): qualify same-office off-host restore",
          "body": "## Summary\n\nAdd a default-off, bounded off-host backup/restore protocol and retain the first real agent-120 to Ubuntu 222 same-office restore evidence without widening independent-failure-domain, power-loss, or production claims.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- add a deterministic manifest/data/completion-marker-last transport package with exact digest, path, symlink, and size verification\n- add a dry-run-default Shifu harness with explicit host/filesystem/device/sentinel checks, delete-free transfer, partial-transfer rejection, empty-root restore, and idempotence checks\n- retain exact source, manifest, completion, target verification, restore, and aggregate reports from the named two-host run\n- bind the capability authority and source acceptance to immutable evidence hashes\n- update durability, institutional-trust, and known-limit documentation to distinguish same-office off-host recovery from an independent disaster domain\n\n## Verification\n\n- local Mac `./shifu build:core`: passed using existing Conan cache through a temporary controller-free XDG config\n- local Mac `./shifu test:crash-recovery`: passed, including 16 native recovery contracts and whole-data-root process restart\n- agent-120 `./shifu build:core`: passed using existing host-local Conan binaries\n- agent-120 `./shifu durability:offhost -- --run-id 987201493-agent120-ubuntu222-v1 --execute`: passed\n- Ubuntu 222 target: exact package verification, empty-root restore, Episode/projection equality, partial rejection, and repeated idempotent restore passed\n- `./shifu check:source`: 156/156 tests passed; build-free source gate passed\n- branch workflow audit before PR: no workflow runs created\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Retain a bounded same-office off-host backup and restore protocol without widening independent-failure-domain, physical-power-loss, or production claims\",\n  \"verification\": [\"Local Core build\", \"agent-120 Core build\", \"agent-120 to Ubuntu 222 off-host restore\", \"partial-transfer rejection\", \"empty-root idempotent restore\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T06:37:42Z",
          "mergedAt": "2026-07-14T06:43:42Z",
          "additions": 2018,
          "deletions": 31,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 827,
          "url": "https://github.com/kungfu-systems/kungfu/pull/827",
          "title": "feat(coordination): merge lock arbiter into per-workspace coordinator",
          "body": "Merge the ADR-0077 named-lock arbiter into the per-workspace coordinator and retire the standalone `Arbiter(peer)`, so a workspace keeps a single resident process (the ADR-rejected alternative was a per-agent daemon).\n\n- `observe(carrier_type, callback)` moves down to the common `reactor` base (peer + coordinator share it).\n- The coordinator gains an `on_react()` hook, admits the lock action envelope in `is_reactable()`, hosts the `LockTable`, grants by writing to the holder's command journal, and reclaims dead holders via the registry pid it already owns (`Register` carries pid) — so a lock request no longer carries a pid and the standalone pid reaper is gone.\n- The client requests from / receives grants on the coordinator's journals; `arbiter_peer.py` is retired; the pure `LockTable` (`arbiter.py`) is unchanged.\n- Audit stays frame-native (requests on the coordinator inbound journal, grants on holder journals) — no bolted-on Episode.\n\nADR-0077 stays `partial` (the `kungfu lock` CLI backend switch is still deferred); this increment refines its delivery to the merged coordinator form.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0077\"],\n  \"summary\": \"Merge the ADR-0077 lock arbiter into the per-workspace coordinator; retire the standalone Arbiter peer; reclaim via registry pid.\",\n  \"verification\": [\n    \"full core build exit 0 (shifu install -> conan configure -> compile); reactor/coordinator/peer/py-runtime compile clean\",\n    \"cross-process harness PASS: race serializes with zero-poll grant, SIGKILLed holder reclaimed via registry pid, instruct delivered to lock holder\",\n    \"mypy clean on changed Python; pre-commit gates green (markdown, C++ clang-format, ruff format/lint, carrier-action-envelope, runtime-greenfield)\"\n  ]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T06:51:30Z",
          "mergedAt": "2026-07-14T07:00:31Z",
          "additions": 185,
          "deletions": 286,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 828,
          "url": "https://github.com/kungfu-systems/kungfu/pull/828",
          "title": "feat(agent): define durable session capsule contract",
          "body": "## Summary\n\nFreeze the first bounded delivery stage for a durable AgentSessionCapsule control plane. The new registered KFD-1 contract gives CLI, GUI, and KFX/Agent clients one provider-neutral interaction authority without claiming that the runtime host or provider adapters already exist.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-agent-session-capsule-contract\n\n## Changes\n\n- add accepted ADR-0081 and register the agent-session-control-plane-contract welded surface\n- define canonical plan, action, topology, status, delivery, input-ledger, and output-read schemas\n- separate coordinator epoch from session stream epoch and fence all writes by Capsule generation and controller lease\n- reject dual PTY ownership, stale lease/epoch, duplicate input writes, blind modal input, shell fallthrough, silent replay gaps, and terminal delivery as work proof\n- update the generated KFD-1 canonical policy, versioning register, qualification docs, and build-free source gate\n\n## Verification\n\n- ./shifu test:agent-session-contract\n- ./shifu check:source\n- pre-commit staged gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Freeze the registered AgentSessionCapsule identity, authority, interaction, receipt, and failure contract with executable negative fixtures\",\n  \"verification\": [\"agent-session contract fixtures\", \"build-free source acceptance\", \"documentation and ADR audit\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR names Codex and Claude only as future provider adapter identities and updates the KFD-1 contract-world policy. It invokes no provider API, stores no provider output or credentials, changes no billing or deployment behavior, and makes no runtime/product qualification claim.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:00:03Z",
          "mergedAt": "2026-07-14T07:06:14Z",
          "additions": 1454,
          "deletions": 4,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 830,
          "url": "https://github.com/kungfu-systems/kungfu/pull/830",
          "title": "fix(docs): bind ADR-0081 to merged contract commit",
          "body": "## Summary\n\nRepair ADR-0081 implementation evidence after PR #828 was integrated with the repository-required rebase merge. The contract implementation is now commit 90e878b696a6a6a6a1a9d21f166f0e63bc527bb2 on dev/v4/v4.0; the original feature SHA is no longer the canonical merged coordinate.\n\nThis clean linear replacement supersedes PR #829, whose old feature branch contains merge commits and therefore cannot pass the repository rebase-only merge policy.\n\n## Changes\n\n- replace the pre-merge feature SHA with the merged, dev-reachable contract implementation SHA\n- preserve ADR-0081 partial status and its existing qualification references\n\n## Verification\n\n- ./shifu check:source\n- pre-commit documentation and ADR audit\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Bind ADR-0081 implementation evidence to the canonical rebased contract commit already merged on dev/v4/v4.0\",\n  \"verification\": [\"build-free source acceptance\", \"documentation and ADR audit\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes one public ADR evidence pointer to an already merged commit. It does not change runtime behavior, provider integration, publishing, or deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:13:50Z",
          "mergedAt": "2026-07-14T07:15:24Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 831,
          "url": "https://github.com/kungfu-systems/kungfu/pull/831",
          "title": "feat(runtime): route profile actions through readiness broker",
          "body": "## Summary\n\n- bind every Profile/KFX action runtimeOperation to the canonical runtime invocation plan\n- keep storage-only callbacks daemonless while routing live-required callbacks through RuntimeCapabilityBroker\n- discover workspace-bound native readiness coordinates, then fail closed on absent, malformed, foreign, changed, or insufficient evidence\n- preserve portable KFD-3 plan and receipt identity while rechecking exact execution material before invocation\n- close ADR-0080 stage 6 without claiming a production-qualified evidence producer or EmbeddedRuntimeHost\n\n## Verification\n\n- `./shifu build:core` (passed)\n- Profile/runtime Python suite after latest rebase: 81 passed\n- `./shifu test:runtime-surface` (7 surfaces, 4 KFX actions)\n- KFX Profile suite: Node 13, navigation 6, shared module 1, runtime foreground 9, Python 11; all passed\n- KFD-3 dual-client proof: Agent CLI and typed Human API produced the same plan, receipt, and witness\n- source gate on the implementation base: 150 contract/tooling tests, 61 documentation contracts, Biome, Ruff, and mypy passed\n- latest mainline rerun is currently blocked only by pre-existing ADR-0081 metadata: it references rebase-predecessor `eed8a90cb760593025afe457f98db79289cd506b` instead of reachable mainline implementation `90e878b69`; the target Python suite remains 81/81 on that base\n- staged pre-commit gate passed\n\n## Governance risk\n\nNo credentials, deployment, release, hosted service, cross-machine lease, distributed election, or production EmbeddedRuntimeHost is changed or claimed. The discovery descriptor contains coordinates rather than readiness proof. Native typed authorities still establish durability and projection at the requested cut, and the domain callback is never invoked after broker refusal. Stage 7 still owns producer qualification and cold product activation evidence.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Close ADR-0080 stage 6 by binding Profile and KFX action invocation to the canonical broker, with daemonless storage execution and fail-closed exact-cut native evidence discovery for live-required work.\",\n  \"verification\": [\"core build passed\", \"Profile and runtime Python suite: 81 passed\", \"runtime surface parity and KFX Profile suite passed\", \"KFD-3 dual-client proof passed\", \"source gate passed before the documented upstream ADR-0081 stale-SHA regression\", \"staged pre-commit gate\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:16:41Z",
          "mergedAt": "2026-07-14T07:22:13Z",
          "additions": 734,
          "deletions": 179,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 120,
          "url": "https://github.com/kungfu-systems/build-images/pull/120",
          "title": "feat(comparator): add qualification evidence runner",
          "body": "## Summary\n\n- add a frozen-plan runner shared by Aeron, ClickHouse, PostgreSQL, and package-fed Kungfu\n- emit self-contained per-repetition and bundle evidence with split authority and offline verification\n- fail closed on input/artifact drift, incomplete repetitions, ad hoc Compose environment, cleanup failure, expert tuning, and source-building Kungfu inputs\n- keep ordinary comparator smoke explicitly unscored and non-authoritative\n\n## Verification\n\n- `pnpm run check`\n- 13 qualification contract and tamper tests\n- `shellcheck pilots/comparator/scripts/pilot.sh`\n- `actionlint .github/workflows/comparator-qualification.yml`\n- all four test-only plans validate and resolve through the same runner\n\nRefs #119",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:25:27Z",
          "mergedAt": "2026-07-14T07:28:03Z",
          "additions": 2120,
          "deletions": 6,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 833,
          "url": "https://github.com/kungfu-systems/kungfu/pull/833",
          "title": "feat(durability): qualify agent-120 clean host restart",
          "body": "## Summary\n\nAdd a default-off, two-phase clean-host-restart qualification protocol and retain the first real agent-120 reboot/reopen evidence without widening sudden-power-loss or production claims.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- add an existing-root reopen fixture that verifies durable frontier, records, closed Episode, projection, and fenced ownership generations\n- add a dry-run-default Shifu prepare/verify protocol bound to a sentinel root, clean source SHA, durable resume token, and changed Linux kernel boot ID\n- keep reboot and host-service authority outside the repository harness\n- retain exact pre/post/resume/aggregate reports from a real clean agent-120 reboot and lock their digests in source acceptance\n- update durability, institutional-trust, ADR, and known-limit documentation with the named Linux/x86_64/ext4/NVMe envelope\n\n## Verification\n\n- local Mac `./shifu build:core`: passed using existing Conan cache through a temporary controller-free XDG config\n- local fixture export plus fresh-process reopen: passed\n- agent-120 `./shifu build:core`: passed using existing host-local Conan binaries through the same Shifu protocol\n- agent-120 prepare, clean host reboot, and verify: passed in 118 seconds with changed boot ID\n- post-restart: durable cut 7201:1:3, 3 records, 1 closed Episode, matching projection, and owner generations 1 to 3\n- post-restart system: `/data` remounted, Runner active, failed units 0\n- `./shifu check:source`: 162/162 tests passed; build-free source gate passed\n- branch workflow audit: no feature-branch push workflow and no self-hosted build dispatched\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Retain a bounded real agent-120 clean-host-restart protocol without widening physical-power-loss or production claims\",\n  \"verification\": [\"Local Core build\", \"agent-120 Core build\", \"real clean host reboot\", \"boot-ID-bound durable reopen\", \"immutable evidence digests\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:25:47Z",
          "mergedAt": "2026-07-14T07:29:04Z",
          "additions": 1164,
          "deletions": 12,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 122,
          "url": "https://github.com/kungfu-systems/build-images/pull/122",
          "title": "chore(release): publish comparator qualification alpha",
          "body": "## Summary\n\nPromote the comparator Phase A Docker pilot series, including #119 frozen-plan qualification receipts, from `dev/v1/v1.2` to the alpha channel.\n\n## Release intent\n\n- patch impact\n- Buildchain v2 dual-channel flow and contract lock remain unchanged\n- Release Passport and GitHub release remain enabled\n- ordinary Docker smoke remains unscored; only complete verified bundles can carry containerized user-outcome qualification authority\n\nRefs #119",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:28:37Z",
          "mergedAt": "2026-07-14T07:31:37Z",
          "additions": 3124,
          "deletions": 60,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 834,
          "url": "https://github.com/kungfu-systems/kungfu/pull/834",
          "title": "feat(agent): add durable Capsule PTY host",
          "body": "## Summary\n\nAdd the Stage 2 independent AgentSessionCapsule PTY host for ADR-0081. The Capsule directly owns one synthetic provider PTY outside Electron window lifetime while keeping peer transport, controller leases, provider semantics, and product integration explicitly staged.\n\n## Related issue\n\nADR-0081 Stage 2.\n\n## Changes\n\n- add the `@kungfu-tech/agent-session` package and standalone local Capsule worker\n- fence input, resize, and signal actions by attempt, Capsule generation, stream epoch, and process-start identity\n- retain bounded output with monotonic byte sequences, explicit gaps, and printable text-grid VT snapshots\n- record delivery and lifecycle receipts without semantic outcome or work-state claims\n- qualify ANSI, alternate-screen, raw input, approval prompt, burst overflow, client reconnect, and provider exit with a synthetic PTY\n- expose a fail-visible Darwin node-pty helper diagnostic and ignore generated `.buildchain/tmp` Markdown in the documentation gate\n\n## Verification\n\n- `./shifu test:agent-session-capsule-host` — 7 tests passed\n- `./shifu check:source` — 173 source-contract tests passed; documentation, ADR, type, and Biome gates passed\n- commit hook staged gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Deliver the independent synthetic AgentSessionCapsule PTY host with exact process fencing, bounded replay, VT snapshots, and exit-safe input closure\",\n  \"verification\": [\"./shifu test:agent-session-capsule-host\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:42:56Z",
          "mergedAt": "2026-07-14T07:49:44Z",
          "additions": 1219,
          "deletions": 8,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 836,
          "url": "https://github.com/kungfu-systems/kungfu/pull/836",
          "title": "feat(durability): admit current-hardware production candidate",
          "body": "## Summary\n\nAdmit the completed current-hardware durability work as an explicit, default-off production candidate while keeping production eligibility and unsupported failure domains false.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- freeze six prerequisite deliveries, exact artifact digests, environments, rerun commands, and fail-closed freshness invalidators\n- add one machine-readable production-candidate admission report and a build-free Shifu source gate\n- project the candidate status from the C++ capability authority through Python, Node, CLI, Episode, and Storage surfaces\n- keep the compatibility bridge as default and rollback authority\n- update durability, institutional-trust, architecture, ADR, known-limit, qualification, and versioning documentation\n- keep physical power loss, independent failure domain, production eligibility, HA, replication, and consensus explicitly false\n\n## Verification\n\n- Mac AppleClang 21 arm64 ./shifu build:core: passed using the existing Conan cache through a temporary controller-free XDG config\n- agent-120 GCC 14 x86_64 ./shifu build:core: passed on exact ready commit aaca63c0917390c6f4bea604a4ac0210f3e1f58f\n- Mac and agent-120 ./shifu test:durability-contract: passed across C++, Python, and Node projections\n- ./shifu check:source: 173/173 tests passed; build-free source gate passed\n- admission checker: 6 inputs, inputs SHA-256 8c8ebd939222da77feab62f9e1c5749dfead0e10adb7db86508075bd393519e9, report SHA-256 24bd0a5ff5f40167982227e7a37af23121988a1a9e97f7a38cba3695d91d90f9\n- no GitHub self-hosted or heavy build was dispatched during development verification\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Admit the complete current-hardware durability evidence set as a default-off production candidate without widening production claims\",\n  \"verification\": [\"Mac Core build\", \"agent-120 Core build\", \"cross-language durability contract\", \"digest-bound six-input admission\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T08:10:42Z",
          "mergedAt": "2026-07-14T08:13:54Z",
          "additions": 694,
          "deletions": 91,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 838,
          "url": "https://github.com/kungfu-systems/kungfu/pull/838",
          "title": "test(shifu): isolate gate task cache partition",
          "body": "## Summary\n\n- isolate the Gate executor lightweight task fixture in a dedicated runner cache partition\n- prove it remains independent while a development qualification owns its Conan lock\n- retain existing same-partition fail-closed coverage\n\n## Validation\n\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This test-isolation fix preserves the existing Shifu cache contract and production Conan lock semantics.\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation is unchanged because public behavior and contracts are unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-14T08:25:59Z",
          "mergedAt": "2026-07-14T08:31:05Z",
          "additions": 153,
          "deletions": 5,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 124,
          "url": "https://github.com/kungfu-systems/build-images/pull/124",
          "title": "fix(comparator): bind jobs to workload adapters",
          "body": "## Summary\n\n- add a checked-in, digest-locked PostgreSQL Phase A workload adapter registry and exact 3 job by 7 tier production plan\n- cryptographically bind scenario, job, tier, action, adapter, fixture, and registry identities into run evidence\n- copy adapter inputs into qualification bundles and reject relabelled or tampered evidence during offline verification\n- preserve test-only profile smoke coverage while preventing generic smoke from carrying production authority\n\n## Validation\n\n- `pnpm run check`\n- `pnpm run check:qualification` (19 tests)\n- all 21 adapter job/tier mappings pass the read-only adapter plan command\n- production plan passes `validate-plan` and `plan`\n\n## Runtime note\n\nA local macOS single-scenario smoke reached the immutable image fetch step but was stopped after the required digest images were unavailable locally. No containers were created, and project-scoped cleanup completed. The Linux release workflow remains the authoritative locked-image runtime check.\n\nCloses #123\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T08:51:53Z",
          "mergedAt": "2026-07-14T08:54:37Z",
          "additions": 2168,
          "deletions": 57,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 125,
          "url": "https://github.com/kungfu-systems/build-images/pull/125",
          "title": "chore(release): publish workload adapter alpha",
          "body": "## Summary\n\nPromote the #123 comparator workload-adapter fix from `dev/v1/v1.2` to the alpha channel.\n\n## Included\n\n- digest-locked allowlisted PostgreSQL Phase A workload adapter\n- exact J1/J2/J3 by seven-tier production plan\n- cryptographic run/bundle binding and offline relabel/tamper rejection\n- preserved test-only smoke and qualification authority boundaries\n\n## Validation\n\n- implementation PR #124 merged with all required checks passing\n- `pnpm run check`\n- qualification contract suite: 19 tests\n- Buildchain v2 dual-channel trust and contract checks passing\n\nRelease classification remains patch and image identifiers are unchanged.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T08:55:02Z",
          "mergedAt": "2026-07-14T08:57:40Z",
          "additions": 2168,
          "deletions": 57,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 837,
          "url": "https://github.com/kungfu-systems/kungfu/pull/837",
          "title": "feat(agent): add Capsule peer transport authority",
          "body": "## Summary\n\n- add the AgentSessionCapsule journal/notice authority state machine with one writer, independent cursors, one controller lease, input dedup, exact foreground fencing, restart re-registration, and supervisor adoption\n- bind the production port to native Watcher Peers: action envelopes travel through the writer public mmap journal and the existing nng publication remains the payload-free wakeup plane\n- qualify bounded recovery, resize coalescing, notice loss, no per-reader writer fanout, and a real cross-process Coordinator/writer/reader round trip\n- keep provider semantics, product surfaces, machine restart, and real Codex/Claude smoke explicitly staged for ADR-0081 Stages 4-6\n\n## Verification\n\n- `./shifu test:agent-session-peer-transport` (10/10)\n- `./shifu build:core` (Node/Electron/Python/libwasm build passed)\n- `./shifu test:agent-session-peer-transport:native` (real Coordinator + two Watcher processes; repeated pass)\n- `./shifu check:source` (183/183 source tests; full gate passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Complete Stage 3 transport authority and native ADR-0077 mmap journal plus nng adapter; ADR-0081 remains partial pending Stages 4-6.\",\n  \"verification\": [\"source gate 183 tests\", \"Core build\", \"repeated cross-process native Coordinator and Watcher qualification\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T08:12:20Z",
          "mergedAt": "2026-07-14T08:59:05Z",
          "additions": 1764,
          "deletions": 44,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 839,
          "url": "https://github.com/kungfu-systems/kungfu/pull/839",
          "title": "docs(adr): record C++23 + Rx core language strategy (ADR-0082)",
          "body": "## Summary\n\nRecord ADR-0082, closing the recurring \"should the core migrate to Rust\" question with an evidence-based decision: the core stays C++23 + Rx. The single-writer architecture removes the borrow-checker problem domain; the compile-time registry welds already provide set-level exhaustiveness at a stronger position than per-site match; and the Rx routing algebra (three-axis routing, declarative protocol phases, journal-time replayable timers) is a net expressiveness advantage rather than a compensation.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-cpp23-rx-language-parity\n\n## Changes\n\n- add accepted ADR-0082 with a ratified three-tier error-handling policy (exceptions + loop boundary / `std::expected` at classify-and-continue seams / value-style scan paths)\n- ratify the closed Hana roster + membership + weld pattern as the canonical exhaustiveness mechanism for type families\n- stage the parity increments (`-Werror=switch`, incremental concepts migration, selective `std::expected`, deducing this / ranges opportunistic)\n- define five observable re-evaluation triggers instead of leaving the question open on sentiment\n- append the ADR index row\n- fix ADR-0081 implementation evidence: the transport delivery recorded pre-rebase branch hashes that the rebase merge rewrote; rebind to the merged mainline commits so the documentation gate accepts mainline history again\n\n## Verification\n\n- ./shifu docs:check (markdown structure, links/anchors/contracts, ADR release contract, ADR authority audit — all green)\n- pre-commit staged gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0082\"],\n  \"summary\": \"Record the C++23 + Rx core language strategy: ratify the existing error-boundary and registry-weld baseline, stage the parity increments, and define observable re-evaluation triggers\",\n  \"verification\": [\"deterministic documentation gate\", \"ADR release contract and authority audit\", \"pre-commit staged gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\nThis PR adds one architecture decision record and its index row. It changes no code, no contracts, no build configuration, and makes no runtime or qualification claim.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated (this PR is the documentation)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T08:58:58Z",
          "mergedAt": "2026-07-14T09:10:43Z",
          "additions": 255,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 835,
          "url": "https://github.com/kungfu-systems/kungfu/pull/835",
          "title": "feat(qualification): enforce measured layer gate budgets",
          "body": "## Summary\n\n- retain source-bound Linux/macOS/Windows timing evidence for ADR-0049 Layer Gates\n- select explicit alpha, release-candidate, and full-patrol execution profiles\n- bind effective parameters, policy digest, artifact manifest, and reuse tuple into qualification evidence\n- keep the full three-seed/100k Episode baseline available outside recurring PR qualification\n\n## Verification\n\n- timing evidence source: `3ef767623edd84b0a69ea8259f9101561fc51017`; all three native worktrees clean\n- synchronized linear PR head: `be11e085e76e33c27b70d5a31e27e6ab6f05aa30`; latest target changes are included, the affected 43-test suite passed without a cache override, and the ADR-0081 evidence repair is inherited from target mainline\n- local regression: 43/43 targeted tests, catalog 38 Gates/5 profiles/16 invocations, tooling type check, and repository pre-commit passed\n- macOS wall-clock path: alpha `552.32s`, release-candidate `568.95s`\n- Windows wall-clock path: alpha `622.61s`, release-candidate `631.80s`\n- Linux wall-clock path: alpha `662.39s`, release-candidate `932.86s`\n- every summary reports `status=passed` and `budget.withinLimit=true`; all 9 PR checks passed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Complete measured budget profiles and source-bound evidence for ADR-0049 Layer Gates\",\n  \"verification\": [\"three-host timing baseline\", \"three-host alpha and release-candidate qualification\", \"Gate catalog and receipt contract tests\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes only qualification evidence and policy. No package, release, tag, alpha, or stable publication is performed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:46:24Z",
          "mergedAt": "2026-07-14T09:15:50Z",
          "additions": 6575,
          "deletions": 123,
          "changedFiles": 100
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 840,
          "url": "https://github.com/kungfu-systems/kungfu/pull/840",
          "title": "feat(agent): add provider interaction adapters",
          "body": "## Summary\n\n- add a provider-neutral AgentSession Interaction Port for status, snapshot, instruct, manual sendKey, and fenced interrupt\n- add versioned Codex 0.144.x and Claude Code 2.1.x redacted TUI adapters with fail-visible drift and raw-human fallback\n- enforce ready-only automatic instruction, bounded busy queues, approval/unknown hold, one atomic bracketed paste plus one Enter, and delivery/outcome separation\n- repair ADR-0081 merged evidence coordinates; keep authenticated approval/deny/semantic dogfood explicitly staged for Stage 6\n\n## Verification\n\n- `./shifu test:agent-session-interaction-adapters` (13/13)\n- `./shifu test:agent-session-peer-transport` (11/11)\n- `./shifu check:source` (199/199 source tests; full build-free gate passed)\n- `./shifu test:agent-session-interaction-adapters:native` (2/2; installed Codex 0.144.3 and Claude Code 2.1.209 version probes under temporary HOME, no auth/private transcript inspection)\n\n## Known limits\n\n- version probes do not prove authenticated TUI interaction or provider semantic outcome\n- approval/deny and interrupt outcome require Stage 6 real-provider product dogfood\n- adapter signature drift fails to `unknown` and requires explicit raw-human fallback\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Complete Stage 4 provider-neutral interaction policy and versioned Codex/Claude adapters; ADR-0081 remains partial pending product surfaces and real-provider recovery qualification.\",\n  \"verification\": [\"source gate 199 tests\", \"interaction adapter 13 tests\", \"transport regression 11 tests\", \"two no-private-state installed CLI version probes\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T09:34:41Z",
          "mergedAt": "2026-07-14T09:38:26Z",
          "additions": 1193,
          "deletions": 21,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 842,
          "url": "https://github.com/kungfu-systems/kungfu/pull/842",
          "title": "docs(adr): define GUI capability ownership",
          "body": "## Summary\n\nFreeze the capability ownership test between Core authority, replaceable System KFX product projections, and domain-owning Profile KFX before the four extraction stages.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add ADR-0083 with the ownership decision, migration order, and product gates\n- register the accepted decision in the canonical ADR index\n- bind the partial baseline to reachable Profile, navigation, and Agent Console commits\n\n## Verification\n\n- `./shifu docs:check`\n- `./shifu adr:audit -- --json`\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Freeze the shared capability ownership boundary before four independently reviewed extraction stages\",\n  \"verification\": [\"./shifu docs:check\", \"./shifu adr:audit -- --json\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:10:37Z",
          "mergedAt": "2026-07-14T10:16:01Z",
          "additions": 262,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 127,
          "url": "https://github.com/kungfu-systems/build-images/pull/127",
          "title": "fix(comparator): derive receipts from observed facts",
          "body": "## Summary\n\n- remove expected answers from adapter-visible execution fixtures\n- derive J1/J2/J3 receipts from retained PostgreSQL observations and tier postconditions\n- verify receipts offline against a separate digest-locked verifier oracle\n- preserve the existing adapter allowlist, mapping, cleanup, relabel, and tamper protections\n\n## Validation\n\n- `pnpm run check`\n- 28 comparator qualification tests\n- all 21 production job/tier adapter plans\n- adapter, semantics, fixture, oracle, and registry digests verified\n\n## Release impact\n\nPatch. No published image identifiers or image runtime contracts change.\n\nCloses #126",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:13:45Z",
          "mergedAt": "2026-07-14T10:16:33Z",
          "additions": 932,
          "deletions": 168,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 128,
          "url": "https://github.com/kungfu-systems/build-images/pull/128",
          "title": "chore(release): promote v1.2.4 alpha",
          "body": "## Summary\n\nPromote the reviewed #126 comparator semantic-receipt fix from `dev/v1/v1.2` to the alpha channel.\n\n## Release evidence\n\n- PR #127 approved and merged\n- complete Buildchain dual-channel checks passed\n- comparator frozen-plan/offline verifier passed\n- patch release impact\n\nThe Buildchain ref-promotion workflow remains authoritative for versioning, Release Passport generation, and GitHub release publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:17:18Z",
          "mergedAt": "2026-07-14T10:19:59Z",
          "additions": 932,
          "deletions": 168,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 843,
          "url": "https://github.com/kungfu-systems/kungfu/pull/843",
          "title": "refactor(gui): make shell profile-neutral",
          "body": "## Summary\n\nMake the GUI Shell profile-neutral while preserving Workspace selection, lazy initialization, and recovery behavior.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- replace the Mission Control default and special fallback with a generic product recommendation and persisted Profile focus\n- degrade missing or empty Profiles to Profile Manager instead of a blank or domain-specific page\n- remove the Create Mission form, IPC channel, and main-process domain write from Workspace UI\n- document the generic `KFE_DEFAULT_PROFILE` assembly seam and bind ADR-0083 to the implementation commit\n\n## Verification\n\n- `./shifu test:kfx-profile-suite`\n- `./shifu check:source`\n- `./shifu build:app`\n- `./shifu docs:check`\n- `./shifu adr:audit -- --json`\n- staged pre-commit gate\n\nThe full `./shifu check` reached unrelated baseline SDK contract drift after all changed-scope checks passed: the base branch already exposes `agent-session` while the SDK expected surface list and rendered canonical policy still contain four surfaces.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Complete the profile-neutral GUI Shell stage without changing Workspace or Profile authority\",\n  \"verification\": [\"./shifu test:kfx-profile-suite\", \"./shifu check:source\", \"./shifu build:app\", \"./shifu docs:check\", \"./shifu adr:audit -- --json\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:32:43Z",
          "mergedAt": "2026-07-14T10:34:34Z",
          "additions": 50,
          "deletions": 104,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 847,
          "url": "https://github.com/kungfu-systems/kungfu/pull/847",
          "title": "docs(adr): repair rebased implementation evidence",
          "body": "## Summary\n\nRepair ADR-0083 implementation evidence after PR #843 was rebased into `dev/v4/v4.0`: replace the feature-branch commit `7e17031e` with its mainline-equivalent commit `fb67a700`.\n\n## Related issue\n\nUnblocks current dev documentation and source acceptance checks after PR #843.\n\n## Changes\n\n- update one `implementation_commits` entry in ADR-0083 to the reachable mainline hash\n- leave the ADR decision and partial implementation status unchanged\n\n## Verification\n\n- `node scripts/run-docs-check.mjs` (61/61 documentation contract tests)\n- staged documentation and ADR gates passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Repair the first shell-neutrality stage evidence after rebase merge changed its commit identity\",\n  \"verification\": [\"deterministic documentation gate\", \"ADR evidence reachability checks\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:48:55Z",
          "mergedAt": "2026-07-14T10:50:38Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 844,
          "url": "https://github.com/kungfu-systems/kungfu/pull/844",
          "title": "fix(gates): require measurements for new gates",
          "body": "## Summary\n\nClose the Kungfu Gate catalog enforcement gap: every Gate added after the frozen adoption baseline must retain passing, source-bound timing measurements for all declared platforms.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add a versioned measurement coverage manifest with a frozen 33-Gate unmeasured adoption baseline\n- seed the five existing Layer Gate measurements from retained three-platform Shifu receipts\n- fail the catalog check on missing platforms, dirty source, stale definitions, registry/source drift, failed or skipped results, duration drift, and missing receipts\n- generate a human-readable timing table and document the exact new-Gate measurement workflow\n- add fail-closed regressions, including proof that a new Gate cannot be hidden by expanding the baseline\n\n## Verification\n\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs` (15/15)\n- `./shifu check:gate-catalog`\n- `node scripts/source-acceptance.mjs` (203/203 contract tests, tooling type check, Biome, documentation and source gate passed before rebasing the latest dev head)\n- staged pre-commit Gate, documentation, schema, and Biome checks passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This patch enforces Kungfu project measurement evidence using the existing SHIFU-ADR-0004 source-bound receipt contract; it does not change Shifu Gate architecture or receipt semantics.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe patch reads retained public qualification receipts and validates their source, registry, Gate definition, platform, outcome, and duration fields. It adds no credentials, publication authority, or deployment side effects.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:42:02Z",
          "mergedAt": "2026-07-14T10:54:43Z",
          "additions": 811,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 845,
          "url": "https://github.com/kungfu-systems/kungfu/pull/845",
          "title": "feat(storage): execute KFD-1 durability config",
          "body": "## Summary\n\n- add one KFD-1 configuration contract for visible, durable_group, and durable_sync profiles, including user/workspace scopes, deterministic stream rules, bounded group thresholds, request deadlines, and fail-closed activation\n- execute the resolved policy through Coordinator, Python, and native State Service boundaries with independent native admission, fenced writer leases, receipt identity, timeout reconciliation, and restart-safe exact-request recovery\n- document the complete configuration mechanism, precedence, effects, costs, rollback path, and the exact current-hardware/non-HA claim boundary in the public guide and ADR-0084\n- canonicalize the five-surface KFD-1 contract world after agent-session entered the registry, without changing Buildchain or GitHub workflow sources\n\n## Verification\n\n- Mac: ./shifu check\n- Mac: ./shifu build:core using existing local Conan cache through a temporary no-controller-cache XDG_CONFIG_HOME\n- Mac: native state-service, durability-contract, and durable-ingest tests\n- Mac: Python durability/config/runtime tests (30/30), Skill/KFX type checks, and Skill golden fixtures\n- agent-120: ./shifu check\n- agent-120: ./shifu build:core with GNU 14, x64, C++23, and existing $HOME/.conan2 cache\n- agent-120: native state-service, durability-contract, and durable-ingest tests\n- agent-120: Python durability/config/runtime tests (30/30)\n\n## Scope\n\n- no .github or .buildchain changes in the feature diff\n- no self-hosted CI or release build was dispatched\n- activation stays off by default; strong profiles require current-hardware candidate admission and remain production-ineligible\n- this runtime chain protects records written through engine.durability; it does not silently intercept unrelated legacy journal writers\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0084\"],\n  \"summary\": \"Deliver the complete KFD-1 durability configuration and runtime execution chain with fail-closed current-hardware admission, stable PR evidence, and implemented ADR-0084 closure.\",\n  \"verification\": [\"Mac source gate and Core build\", \"agent-120 source gate and Core build\", \"native durability execution and recovery tests\", \"Python config and runtime tests\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:43:19Z",
          "mergedAt": "2026-07-14T11:00:32Z",
          "additions": 3072,
          "deletions": 222,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 846,
          "url": "https://github.com/kungfu-systems/kungfu/pull/846",
          "title": "feat(agent-session): expose shared product control surface",
          "body": "## Summary\n\n- expose one self-describing Agent Session action surface through Electron IPC, runtime-scoped POSIX RPC, Python CLI/KFD-3, KFX, and terminal product views\n- bind one-click Go and Assistant launch to the same Capsule, auto-attach presentation, project all Capsules in Console Hub, and preserve one controller lease with plan/foreground/epoch fencing\n- keep delivery receipts separate from work outcome/proof; approval and unknown states remain fail-closed\n- make source acceptance use portable pinned Python tool fallbacks and repair the upstream ADR-0083 post-rebase evidence pointer\n\n## Verification\n\n- `./shifu test:agent-session-product-surfaces` (8/8)\n- `./shifu test:agent-console-contract` (9/9)\n- `./shifu --filter @kungfu-tech/gui build` (main, preload, renderer passed)\n- `./shifu check:source` (208/208 source tests; mypy 134 source files; full build-free gate passed)\n- `./shifu kfd:buildchain:check` (KFD-1 witness, 3 KFD-2 claims, 114 KFD-3 surfaces)\n\n## Known limits\n\n- Stage 5 hosts Capsule ownership in Electron main; detached worker ownership and restart/adoption remain Stage 6\n- authenticated Codex/Claude interaction, machine restart, privacy/performance campaigns, and promoted Mac product evidence remain Stage 6\n- terminal delivery, provider liveness, and transcript text never prove work progress or completion\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Complete Stage 5 shared GUI, CLI, KFX/Agent, WorkConsole, Console Hub, Profile-bound and KFD-3 product surfaces; ADR-0081 remains partial pending detached recovery and promoted real-provider qualification.\",\n  \"verification\": [\"product surface 8 tests\", \"Agent Console CLI 9 tests\", \"GUI three-bundle build\", \"source gate 208 tests and 134-file mypy baseline\", \"KFD evidence closure\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:46:40Z",
          "mergedAt": "2026-07-14T11:09:31Z",
          "additions": 2933,
          "deletions": 168,
          "changedFiles": 52
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 849,
          "url": "https://github.com/kungfu-systems/kungfu/pull/849",
          "title": "feat(agent): pin Codex App Server contract",
          "body": "## Summary\n\nLinear replacement for #848, required because this repository permits rebase merges while the original branch contained mainline merge commits.\n\nStage the exact-version Codex App Server structured-hybrid contract without changing the shared Agent Interaction Port or the existing Claude/PTTY authority.\n\n## Changes\n\n- pin Codex CLI 0.144.3 and the non-experimental stable App Server surface\n- commit a deterministic 267-file semantic schema manifest and regeneration tool\n- add fail-closed method, envelope, identity, response-correlation, and schema-drift admission\n- add redacted positive/negative fixtures and credential-free native regeneration coverage\n- record the bounded contract/schema stage under ADR-0085\n- preserve the newly merged product-surface registration and source acceptance coverage\n\nVersion impact: minor. This adds an optional public agent-session contract/export; it does not activate runtime routing or change existing provider behavior.\n\n## Verification\n\n- focused Codex, native schema, product surface, Interaction Port, and source-plan tests (37/37)\n- `./shifu check:source` (219/219 after product-surface convergence)\n- pre-commit staged gate (61/61 documentation contract tests)\n- original PR #848 completed all 9 CI checks before the repository merge policy rejected its non-linear history\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0085\"],\n  \"summary\": \"Pin and qualify the exact Codex 0.144.3 stable App Server contract and generated schema bundle without activating runtime routing\",\n  \"verification\": [\n    \"./shifu test:codex-app-server-contract\",\n    \"./shifu test:codex-app-server-contract:native\",\n    \"./shifu test:agent-session-interaction-adapters\",\n    \"./shifu test:agent-session-product-surfaces\",\n    \"./shifu docs:check\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe contract consumes only the locally installed Codex CLI stable schema surface. The native gate uses temporary `HOME` and `CODEX_HOME` directories and does not read provider credentials, auth state, or session state. This PR performs no package publication or deployment.\n\n## Checklist\n\n- [x] One linear DCO-signed delivery commit\n- [x] Documentation updated for the new contract\n- [x] Existing product surface and Claude/PTTY adapter tests remain green\n- [x] No runtime route or shared Interaction Port authority changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T11:24:04Z",
          "mergedAt": "2026-07-14T11:27:46Z",
          "additions": 3130,
          "deletions": 1,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 841,
          "url": "https://github.com/kungfu-systems/kungfu/pull/841",
          "title": "feat(runtime): qualify activation product delivery",
          "body": "## Summary\n\n- qualify topology-neutral runtime activation with retained deterministic evidence\n- close SDK/product build toolchain gaps on the managed Core Python runtime\n- integrate the frozen `dev/v4/v4.0@16f02290b` baseline, including KFD-1 durability config, shared agent-session product surfaces, and Codex App Server contracts\n- retain machine-readable Mac product qualification evidence and explicit non-claims\n\n## Qualification\n\n- `./shifu check:source` — passed; 224 source-contract tests\n- `./shifu verify --full --with-app` — 82/82 passed\n- `./shifu runtime:qualify -- --mode execute --with-product` — 8/8 suites passed\n- retained report: `docs/qualification/evidence/runtime-activation/8643f1187/report.json`\n- report SHA-256: `be98265b8dffa96b45d38496b6dc27560daab88afc844588c74150fc8ff5594f`\n- Mac artifact: `20260714T113632Z-8643f1187`\n\n## Boundaries\n\n- qualified on macOS arm64 only\n- no production `EmbeddedRuntimeHost` claim\n- no HA/replication or physical power-cut claim\n- process topology remains a placement adapter behind capability/readiness semantics\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Complete topology-neutral capability-driven runtime activation and retain qualified macOS arm64 product evidence with explicit non-claims.\",\n  \"verification\": [\"source gate 224 tests\", \"full product verification 82/82\", \"runtime activation qualification 8/8\", \"retained report be98265b8dffa96b45d38496b6dc27560daab88afc844588c74150fc8ff5594f\"]\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo package publication or deployment is performed by this PR; the retained local product evidence is bounded to macOS arm64.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and qualification evidence updated\n- [x] Claims remain bounded to the retained report\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T09:42:59Z",
          "mergedAt": "2026-07-14T11:48:55Z",
          "additions": 3256,
          "deletions": 89,
          "changedFiles": 49
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1194,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1194",
          "title": "feat(release): add sealed publication authority",
          "body": "## Summary\n- add a closed-world, project-independent publication authority registry and short-lived sealed admission/capability protocol\n- isolate npm, paper, binary release assets, and web production writes behind an independent verifier and protected Environment\n- add honest runner provenance qualification plus read-only GitHub/npm/provider control-plane audit receipts\n- keep build, controller, preview/staging, and failure-evidence lanes free of product publication authority\n\n## Validation\n- pnpm run check (603 tests)\n- node --check scripts/audit-publication-control-plane.mjs\n- git diff --check\n\n## Live rollout boundary\nThis PR does not modify GitHub Environments, OIDC/IAM, npm trusted publishers, branch/ruleset policy, or runner authorization. Product publication remains fail-closed until those controls are audited and configured separately.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T11:50:37Z",
          "mergedAt": "2026-07-14T11:52:57Z",
          "additions": 3709,
          "deletions": 219,
          "changedFiles": 47
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 853,
          "url": "https://github.com/kungfu-systems/kungfu/pull/853",
          "title": "docs(adr): bind runtime evidence after merge",
          "body": "## Summary\n\nRepair ADR-0080 implementation evidence after PR #841 was rebased into `dev/v4/v4.0`: replace the three feature-branch commit identities with their canonical mainline equivalents.\n\n## Changes\n\n- update only the three `implementation_commits` entries in ADR-0080\n- preserve the implemented decision, qualification report, product artifact, and bounded claims\n\n## Verification\n\n- `./shifu docs:check` (61/61 documentation contract tests)\n- staged documentation and ADR gates passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Bind the implemented runtime activation delivery to the canonical commits created by the required rebase merge\",\n  \"verification\": [\"deterministic documentation gate\", \"ADR evidence reachability checks\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes evidence pointers only. It does not change runtime behavior, qualification claims, publishing, or deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T11:53:30Z",
          "mergedAt": "2026-07-14T11:55:10Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1195,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1195",
          "title": "chore(release): promote dev/v2/v2.12 to alpha/v2/v2.12",
          "body": "## Summary\n\nPromote the reviewed sealed-publication-authority implementation from the protected development line into the v2.12 alpha channel.\n\n## Evidence\n\n- source PR: #1194\n- source SHA: `ccfd5455e0560c3158b7da1767cbe77bf26364f4`\n- dev Verify: https://github.com/kungfu-systems/buildchain/actions/runs/29330452478\n\n## Publication boundary\n\nThis PR moves source authority only. Product publication remains fail-closed until the fresh sealed admission, qualified runner receipt, control-plane audit, exact expected bindings, and protected publication environment are supplied.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T11:56:32Z",
          "mergedAt": "2026-07-14T11:58:51Z",
          "additions": 3709,
          "deletions": 219,
          "changedFiles": 47
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 851,
          "url": "https://github.com/kungfu-systems/kungfu/pull/851",
          "title": "feat(agent): add Codex App Server stdio runtime",
          "body": "## Summary\n\nLinear replacement for #850 after `dev/v4/v4.0` advanced while its checks were running. This branch starts at the current mainline and does not force-push or bypass the up-to-date merge requirement.\n\nAdd the Stage 2 direct-stdio runtime host for the pinned Codex App Server surface without activating product routing or changing the shared Agent Interaction Port.\n\n## Changes\n\n- spawn an absolute executable plus argv with direct stdin/stdout/stderr pipes and no shell\n- install the continuous JSONL reader before the initialize request is written\n- correlate client responses and provider server requests by exact typed request id\n- fence every post-handshake write by SessionAttempt, runtime generation, and process-start identity\n- freeze new admission before the bounded consumer queue hard limit and fail visibly on overflow\n- isolate consumer callback failures, retain stderr metadata only, and mark pipe/runtime loss as outcome unknown\n- add a credential-free synthetic provider proving late turn/start response ordering, malformed/unknown frames, queue pressure, identity isolation, stale writers, pipe loss, and unexpected exit\n- register the runtime test in build-free source acceptance\n\nVersion impact: minor. This adds an optional public agent-session runtime export; existing PTY, Claude, product surface, and provider routing behavior remain unchanged.\n\n## Verification\n\n- `./shifu test:codex-app-server-runtime` (10/10)\n- #850 completed all 9 required CI checks before the up-to-date merge rule rejected its stale base\n- #850 local `./shifu check:source` (229/229, exit 0)\n- #850 pre-commit staged gate, including documentation contracts (61/61)\n- Markdown whole-tree lint (234 files, 0 errors)\n\nLocal non-qualifying probe on #850: `./shifu test:agent-session-capsule-host` reached 56/57; its only failure is the pre-existing native peer test requiring `./shifu build:core` to create `framework/core/dist/kungfu/kungfu_node.node`. The build-free source gate and this PR's runtime test both pass.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0085\"],\n  \"summary\": \"Add the pinned direct-stdio runtime host, continuous reader, exact correlation, bounded queue admission, and attempt process generation fencing without activating product routing\",\n  \"verification\": [\n    \"./shifu test:codex-app-server-runtime\",\n    \"./shifu test:codex-app-server-contract\",\n    \"./shifu test:agent-session-product-surfaces\",\n    \"./shifu docs:check\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe runtime consumes only the explicit direct-stdio child process. Synthetic tests use Node under temporary process state, retain no stderr content, and do not read Codex credentials, auth storage, private sessions, or transcripts. This PR performs no publication, deployment, product-route activation, or real provider action.\n\n## Checklist\n\n- [x] Linear DCO-signed delivery history on the latest mainline\n- [x] Runtime and source acceptance documentation updated\n- [x] Existing contract and product-surface tests remain green\n- [x] No shared Interaction Port, PTY authority, or product route changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T11:52:44Z",
          "mergedAt": "2026-07-14T11:59:05Z",
          "additions": 1218,
          "deletions": 6,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 852,
          "url": "https://github.com/kungfu-systems/kungfu/pull/852",
          "title": "refactor(profile): extract Mission Control domain capability",
          "body": "## Summary\n\nMove Mission Control domain semantics behind the exact-root Profile surface and remove the generic Atlas capability from Core API, KFX, and GUI.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add a root-bound generic Profile member adapter plus typed intent, query, assessment, authorization, and receipt transports\n- move Mission/Go/claim/assessment/import/export semantics and types into the Mission Control Profile/KFX\n- remove the public TypeScript Atlas capability, KFX atlas handle, and GUI Atlas IPC relay\n- prove independent Week/Day write, query, assessment, and receipt parity through the same Profile API\n- label Atlas-derived projections with Profile/member roots, request cut, and non-writable authority\n- retain `kungfu atlas` as a CLI-only 4.0-alpha compatibility edge and record the boundary in ADR-0083\n\n## Verification\n\n- `./shifu rebuild:core`\n- `./shifu freeze`\n- `./shifu test:agent-profile-sdk` (52 passed)\n- `./shifu test:profile-kfd3-qualification`\n- `./shifu test:kfx-profile-suite`\n- `./shifu --filter @kungfu-tech/api test:query` (17 passed)\n- `./shifu --filter @kungfu-tech/kfx-view-work-dashboard test` (21 passed)\n- `./shifu --filter @kungfu-tech/kfx-view-work-dashboard build`\n- `./shifu --filter @kungfu-tech/api build`\n- `./shifu --filter @kungfu-tech/kfx build`\n- `./shifu build:app`\n- `./shifu check:source`\n- `./shifu kfd:buildchain:check`\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Complete the Profile domain extraction stage while preserving legacy Atlas read compatibility\",\n  \"verification\": [\"./shifu test:agent-profile-sdk\", \"./shifu test:profile-kfd3-qualification\", \"./shifu test:kfx-profile-suite\", \"./shifu check:source\", \"./shifu build:app\", \"./shifu kfd:buildchain:check\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T11:53:24Z",
          "mergedAt": "2026-07-14T12:11:50Z",
          "additions": 1458,
          "deletions": 725,
          "changedFiles": 44
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 854,
          "url": "https://github.com/kungfu-systems/kungfu/pull/854",
          "title": "docs(adr): bind merged Profile API evidence",
          "body": "## Summary\n\nRepair ADR-0083 implementation evidence after PR #852 was rebased into `dev/v4/v4.0`: replace the feature-branch commit identity with its canonical mainline equivalent.\n\n## Changes\n\n- update only the newest `implementation_commits` entry in ADR-0083\n- preserve the accepted decision, partial implementation status, and all existing evidence\n\n## Verification\n\n- `./shifu docs:check` (documentation contracts passed)\n- source acceptance reached the full suite after restoring evidence reachability\n- staged DCO and documentation gates passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Bind the Profile domain extraction stage to the canonical commit created by the required rebase merge\",\n  \"verification\": [\"deterministic documentation gate\", \"ADR evidence reachability checks\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes one evidence pointer only. It does not change runtime behavior, qualification claims, publishing, or deployment.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Evidence points to the canonical mainline commit\n- [x] No behavior or implementation file changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:16:02Z",
          "mergedAt": "2026-07-14T12:20:14Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 855,
          "url": "https://github.com/kungfu-systems/kungfu/pull/855",
          "title": "feat(agent): add Codex App Server structured interaction adapter",
          "body": "## Summary\n\nAdd ADR-0085 Stage 3: a provider-private structured adapter over the fenced Codex App Server runtime stream. It normalizes lifecycle and control traffic without changing the shared Interaction Port, activating a product route, or claiming semantic work outcome.\n\n## Changes\n\n- add deterministic structured plans and receipts for thread, turn, item, tool, approval, usage, error, and lifecycle events\n- bind every event and plan to runtime identity plus SessionAttempt, generation, and process-start fences\n- require exact provider request/thread/turn/item targets; approvals and other server controls default to deny\n- reject stale targets, sequence gaps, duplicate turn terminals, runtime drift, and mutated plans\n- preserve provider method, typed identities, ordering, and private evidence pointers without retaining raw error messages in receipts\n- keep request/control delivery distinct from semantic outcome, Profile/KFD work state, and proof\n- expose the adapter package entry and include its credential-free tests in source acceptance\n\nVersion impact: minor. This is an additive optional agent-session export; existing PTY, Claude, product-surface, and provider-routing behavior remain unchanged.\n\n## Verification\n\n- `./shifu test:codex-app-server-interaction` (7/7)\n- focused contract/runtime/product suite (30/30)\n- `./shifu check:source` on base `5763b3d7` (241/241, docs 61/61, typecheck and Biome passed)\n- post-rebase source gate reaches the documentation contract and is blocked only by the newly merged unrelated ADR-0083 reference to non-mainline commit `c484adc5`; a separate post-merge evidence repair will restore mainline before this PR is merged\n- pre-commit staged gate passed, including docs 61/61 and Biome\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0085\"],\n  \"summary\": \"Normalize fenced Codex App Server lifecycle and control events into deterministic exact-identity plans and receipts with default-deny controls and no semantic outcome overclaim\",\n  \"verification\": [\n    \"./shifu test:codex-app-server-interaction\",\n    \"./shifu test:codex-app-server-runtime\",\n    \"./shifu test:codex-app-server-contract\",\n    \"./shifu test:agent-session-product-surfaces\",\n    \"./shifu docs:check\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe adapter consumes only synthetic fenced runtime events in tests. It reads no Codex credentials, auth storage, private sessions, hidden state, prompts, transcripts, or real provider output. This PR performs no publication, deployment, product-route activation, or real provider action.\n\n## Checklist\n\n- [x] Linear DCO-signed delivery history on the latest mainline at push time\n- [x] Structured adapter and source acceptance documentation updated\n- [x] Existing contract, runtime, and product-surface tests remain green\n- [x] No shared Interaction Port, PTY authority, or product route changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:16:48Z",
          "mergedAt": "2026-07-14T12:24:38Z",
          "additions": 829,
          "deletions": 2,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1196,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1196",
          "title": "fix(release): verify independent publication evidence",
          "body": "## Summary\n\n- fetch the exact PR-stage passport, build summary, controller receipt, manifests, and payload artifacts from the admitted Actions run\n- independently recompute candidate, controller, Gate, manifest, payload, and post-merge source-tree bindings before issuing a publication capability\n- fail closed on platform substitution, payload byte drift, unsafe manifest paths, and missing external evidence\n\nFollow-up to #1194 after the first alpha promotion correctly failed closed without an admission.\n\n## Validation\n\n- `pnpm run check`\n- 606 tests passed\n- workflow inventory/site generation and all four bundled actions passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:25:41Z",
          "mergedAt": "2026-07-14T12:28:03Z",
          "additions": 759,
          "deletions": 64,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 130,
          "url": "https://github.com/kungfu-systems/build-images/pull/130",
          "title": "fix(comparator): normalize Compose project names",
          "body": "## Summary\n- normalize all qualification Compose project names to lowercase portable syntax with a 63-character cap\n- validate the complete production project-name set for uniqueness and fail once on locked Compose config before service startup\n- add frozen T/Z, preflight failure/timeout, cleanup-scope, and Ubuntu current-Compose regression coverage\n\n## Validation\n- `pnpm run check`\n- 32 comparator unit tests\n- local Docker Compose 5.1.2 `config --quiet` with the frozen production project name\n- Buildchain v2-alpha contract lock: unchanged\n\n## Release impact\nPatch. No published image identifier or adapter mapping changes.\n\nCloses #129",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:26:37Z",
          "mergedAt": "2026-07-14T12:29:15Z",
          "additions": 147,
          "deletions": 8,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1197,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1197",
          "title": "chore(release): promote v2.12 dev to alpha",
          "body": "## Summary\n\nPromote the sealed publication authority and independent evidence verifier from `dev/v2/v2.12` to `alpha/v2/v2.12`.\n\nThis candidate includes #1194 and the follow-up independent evidence hardening in #1196. Product publication remains fail-closed until an exact fresh admission and the external publication control plane qualify.\n\n## Evidence\n\n- dev Verify run 29332591550 passed\n- local `pnpm run check`: 606/606 tests passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:29:18Z",
          "mergedAt": "2026-07-14T12:31:28Z",
          "additions": 759,
          "deletions": 64,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 131,
          "url": "https://github.com/kungfu-systems/build-images/pull/131",
          "title": "release: promote v1.2 development to alpha",
          "body": "## Summary\n- promote the #129 comparator Compose project-name fix from `dev/v1/v1.2` to alpha\n- retain the Buildchain v2 dual-channel contract locks and Release Passport publishing path\n\n## Evidence\n- #130: 30 successful checks, including Ubuntu current Compose and both Buildchain channels\n- no new Buildchain drift issue was generated\n\n## Release\nBuildchain will prepare and publish the next `v1.2.4-alpha.*` release after merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:29:41Z",
          "mergedAt": "2026-07-14T12:32:23Z",
          "additions": 147,
          "deletions": 8,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1198,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1198",
          "title": "fix(release): scope payload evidence to product bytes",
          "body": "## Summary\n\n- verify every declared product payload file against bytes downloaded from the exact RC Actions run\n- keep the mutable `.buildchain/` diagnostics envelope bound by the manifest digest, but outside the product-byte set\n- record a separate product payload digest per platform\n\nThis follows live RC evidence from #1197: product bytes matched, while diagnostics files were finalized after the lifecycle manifest scan.\n\n## Validation\n\n- fresh #1197 RC passport, source tree, candidate hash, controller receipt, three manifests, and product payload bytes validated locally\n- `pnpm run check`: 606/606 tests passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:37:51Z",
          "mergedAt": "2026-07-14T12:40:01Z",
          "additions": 34,
          "deletions": 22,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1199,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1199",
          "title": "chore(release): promote product payload evidence to alpha",
          "body": "## Summary\n\nPromote the product-byte evidence scope from `dev/v2/v2.12` to `alpha/v2/v2.12`.\n\n## Evidence\n\n- PR #1198 approved and merged\n- dev Verify run 29333363362 passed\n- fresh #1197 RC product payload bytes validated against all three platform manifests\n- local `pnpm run check`: 606/606 tests passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:41:32Z",
          "mergedAt": "2026-07-14T12:43:20Z",
          "additions": 34,
          "deletions": 22,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 856,
          "url": "https://github.com/kungfu-systems/kungfu/pull/856",
          "title": "feat(agent-session): detach product capsule worker",
          "body": "## Summary\n\n- detach Agent Session Capsule ownership from Electron main into one private local worker with a stable, runtime-scoped endpoint and reconnectable RPC client\n- serialize missing-worker startup across independent clients with a private atomic lock so no client can unlink another workers live socket\n- fence shutdown across the worker, RPC surface, runtime, and provider PTYs; a missing worker starts a new empty runtime instead of claiming recovery\n- harden bounded VT/provider state classification against stale screens while keeping volatile terminal text memory-only\n- retain machine-readable Stage 6 qualification evidence and a metadata-only real-provider dogfood runner\n\n## Verification\n\n- `./shifu test:agent-session-recovery-qualification` (real node-pty; retained p95 1.645 ms, final rerun p95 4.402 ms, ceiling 250 ms)\n- `./shifu check:source` after review fix (246/246 source tests; includes independent-client startup race regression)\n- `./shifu --filter @kungfu-tech/gui build` after rebase (main, preload, renderer passed)\n- authenticated Codex 0.144.3: instruction/output, approval deny, interrupt, Electron-main reconnect, provider termination all passed\n\n## Known limits\n\n- authenticated Claude 2.1.209 reached ready, instruction/output, and main-process reconnect, but its tool-approval surface did not converge within the bounded qualification window\n- Claude deny input was therefore not sent and no Claude approval outcome is claimed; the attempted side effect did not execute\n- evidence records `promotionEligible=false`; this PR does not build, register, or promote a Kungfu product artifact\n- machine restart durability remains unqualified; worker loss intentionally produces a new empty runtime and attempt\n- the package-wide native peer test requires a prebuilt Core binding; the source-only PR gate and scoped Stage 6 qualification do not claim that native build\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Deliver the Stage 6 detached-worker and recovery qualification implementation slice while ADR-0081 remains partial and product promotion stays blocked by degraded authenticated Claude approval qualification.\",\n  \"verification\": [\"recovery qualification with real node-pty\", \"post-review source gate 246 tests\", \"GUI three-bundle build\", \"authenticated Codex loop passed\", \"Claude degradation retained with promotionEligible false\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:30:09Z",
          "mergedAt": "2026-07-14T12:43:56Z",
          "additions": 1611,
          "deletions": 63,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 857,
          "url": "https://github.com/kungfu-systems/kungfu/pull/857",
          "title": "feat(agent): guard Codex App Server recovery receipts",
          "body": "## Summary\n\nDeliver ADR-0085 Stage 4: Kungfu-owned durable admission/result receipts, exact input and side-effect idempotency, and fail-closed recovery boundaries for the Codex App Server structured adapter. This does not activate a product route or claim provider replay semantics.\n\n## Changes\n\n- add a recovery guard that appends prompt-free provider-private admission metadata before any provider request or control response\n- deduplicate exact completed inputs and side effects to the same durable receipt\n- reject opened or unknown duplicates so a crash window cannot create a second provider write\n- mark unresolved inputs and approvals unknown before closing a lost runtime attempt\n- bind read/resume recovery to an exact immutable old boundary and a distinct new attempt\n- reject runtime-fence drift, ledger gaps/root corruption, closed backpressure admission, and stale controls before provider writes\n- allow PTY fallback only as a new attempt while preserving structured receipts\n- inject the existing Agent Session journal seam; add no database and retain no prompt, transcript, provider output, error text, credentials, or private session state\n- expose the recovery adapter and include its credential-free tests in source acceptance\n\nVersion impact: minor. This is an additive optional agent-session export; shared Interaction Port, Claude/PTTY behavior, provider routing, and product surfaces remain unchanged.\n\n## Verification\n\n- `XDG_CACHE_HOME=/tmp/kungfu-recovery-guards-cache ./shifu test:codex-app-server-recovery` (8/8)\n- focused contract/runtime/interaction/recovery/product suite (30/30)\n- `XDG_CACHE_HOME=/tmp/kungfu-recovery-guards-source-cache ./shifu check:source` on base `c44ccb271` (source tests 254/254, docs 61/61, TypeScript and Biome passed)\n- pre-commit staged gate passed, including docs 61/61 and Biome\n- no real provider process, credential, prompt, transcript, or private session state used\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0085\"],\n  \"summary\": \"Add durable prompt-free admission and result receipts, exact input and side-effect idempotency, immutable unknown or interrupted attempt cuts, and no-blind-replay recovery guards for Codex App Server\",\n  \"verification\": [\n    \"./shifu test:codex-app-server-recovery\",\n    \"./shifu test:codex-app-server-interaction\",\n    \"./shifu test:codex-app-server-runtime\",\n    \"./shifu test:codex-app-server-contract\",\n    \"./shifu test:agent-session-product-surfaces\",\n    \"./shifu docs:check\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe implementation and tests use only synthetic runtime events and an in-memory deterministic journal. This PR performs no publication, deployment, product-route activation, real provider action, or private-state inspection.\n\n## Checklist\n\n- [x] Linear DCO-signed delivery history on the latest mainline at push time\n- [x] Recovery guard and source acceptance documentation updated\n- [x] Contract, runtime, interaction, recovery, and product-surface tests remain green\n- [x] No shared Interaction Port, PTY authority, Claude behavior, or product route changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:47:29Z",
          "mergedAt": "2026-07-14T12:51:03Z",
          "additions": 1206,
          "deletions": 2,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 858,
          "url": "https://github.com/kungfu-systems/kungfu/pull/858",
          "title": "build(core): promote exhaustive enum switch to a compile error",
          "body": "## Summary\n\nPromote exhaustive `switch` over closed enums from a warning to a compile error, wiring `-Werror=switch` (Clang/GNU) and `/we4062` (MSVC) into `kungfu_compile_contract`. This is staged-adoption item 1 of ADR-0082: an enumerator with neither a case label nor a default arm now fails the build instead of scrolling past as a warning, so the closed-enum exhaustiveness the registry welds already enforce at set level is now also enforced at every hand-written `switch`.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-adr0082-staged-increments\n\n## Changes\n\n- `framework/core/.cmake/compiler.cmake`: add `-Werror=switch` for AppleClang/Clang and GNU, and `/we4062` for MSVC, to the shared `kungfu_compile_contract` compile options\n- keep the deliberate `default` arms legal: C4061 / `-Wswitch-enum` (which would flag a `switch` even when it carries a `default`) is intentionally NOT enabled, because the storage offline scanners' unknown-record downgrade paths are a designed state, not an oversight — the ADR calls this out explicitly\n\n## Pre-promotion audit\n\n- 89 translation units (libyijinjing, libkungfu incl. tests, libwasm, bindings) compiled clean under the new flag\n- all 57 `switch` sites in `src/` either enumerate every case or carry a deliberate `default`; **zero** required a new case label, so this is a pure weld with no behavioural change\n- the three storage `switch(carrier_type)` offline scanners (`manifest_catalog.cpp`, `source_registry.cpp`, `episode_manifest.cpp`) keep their unknown-record downgrade `default` arms unchanged, matching ADR-0082 §Staged adoption item 1\n\n## Verification\n\n- Mac / AppleClang: full `pnpm run build:core` green; native ctest 9/9\n- Linux / GCC 14.2 (agent-120): full build green (`cmake-js build done`, only unrelated `-Wsign-compare` warnings remain)\n- Windows / MSVC (VS 18): full build green under `/we4062`\n- pre-commit staged gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0082\"],\n  \"summary\": \"Promote exhaustive enum switch to a compile error (-Werror=switch / /we4062) as ADR-0082 staged adoption item 1, after a 89-TU three-platform audit that required zero new case labels\",\n  \"verification\": [\"three-platform full core build (AppleClang, GCC 14.2, MSVC)\", \"native ctest\", \"pre-commit staged gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\nThis PR changes one line block of build configuration. It adds no code, changes no runtime behaviour (the audit found zero switch sites needing a new case), and makes no qualification claim.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated (the compile contract carries an inline comment explaining the flag choice and why C4061 stays off)",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:53:38Z",
          "mergedAt": "2026-07-14T13:01:44Z",
          "additions": 20,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 859,
          "url": "https://github.com/kungfu-systems/kungfu/pull/859",
          "title": "ci(runtime): gate complete qualification on promotions",
          "body": "## Summary\n\nRun the complete runtime activation and product qualification inside alpha/release Buildchain verification, and retain the machine report together with a checksummed gzip bundle of every raw suite log.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add the full `runtime:qualify -- --mode execute --with-product` stage to release qualification before the final Gate receipt\n- retain `report.json` and `raw-logs.jsonl.gz` together under the release qualification artifact\n- bind the bundle and each suite member by SHA-256 in the report schema\n- align Profile-based product fixtures and ensure product distribution precedes Profile admission\n- retain a clean Darwin arm64 8/8 qualification report and compressed log bundle\n\n## Verification\n\n- `./shifu check:source` (255/255 source-contract tests on latest `dev/v4/v4.0`)\n- `./shifu runtime:qualify -- --mode execute --with-product --retain docs/qualification/evidence/runtime-activation/b325b9739` (8/8 passed, source dirty=false)\n- `./shifu docs:check:readonly` (61/61 documentation contract tests)\n- `gzip -t docs/qualification/evidence/runtime-activation/b325b9739/raw-logs.jsonl.gz`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This tightens the existing ADR-0080 qualification and release-evidence path without changing the runtime architecture contract\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe retained bundle contains only qualification command output, is checksummed beside the report, and does not widen the report claim boundary.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T13:14:40Z",
          "mergedAt": "2026-07-14T13:16:36Z",
          "additions": 585,
          "deletions": 52,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 860,
          "url": "https://github.com/kungfu-systems/kungfu/pull/860",
          "title": "refactor(query): move domain views into profiles",
          "body": "## Summary\n\nMove Mission Control saved-query rendering semantics from Core into its Profile-owned KFX while retaining generic Query authority and explicit degraded compatibility.\n\n## Changes\n\n- replace the closed Mission Control ViewSpec union with a generic Profile renderer envelope\n- move goal-card filters, five-question reducer identity, validation, and migration into Mission Control / Work Dashboard\n- preserve QueryDefinition and revision history when Profile renderers are absent\n- make native and Python Saved Query catalogs accept arbitrary Profile descriptors without domain interpretation\n- prove the boundary with an independent Week/Day Profile view\n\n## Verification\n\n- ./shifu rebuild:core\n- ./shifu check:source (254/254 contract tests)\n- ./shifu test:kfx-profile-suite\n- ./shifu test:profile-kfd3-qualification\n- targeted Python Profile/Query tests (64 passed)\n- API query tests (17 passed)\n- Work Dashboard tests (25 passed)\n- ./shifu build:app\n- ./shifu kfd:buildchain:check\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Complete the Profile-owned Query ViewSpec extraction stage with explicit legacy preservation\",\n  \"verification\": [\"./shifu check:source\", \"./shifu test:kfx-profile-suite\", \"./shifu test:profile-kfd3-qualification\", \"./shifu build:app\", \"./shifu kfd:buildchain:check\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T13:15:20Z",
          "mergedAt": "2026-07-14T13:20:20Z",
          "additions": 805,
          "deletions": 409,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 862,
          "url": "https://github.com/kungfu-systems/kungfu/pull/862",
          "title": "docs(adr): align query extraction evidence",
          "body": "## Summary\n\nAlign ADR-0083 implementation evidence with the commit SHA created by GitHub rebase merge of PR #860.\n\n## Verification\n\n- implementation commit 36381447657fcda49b7b5c48eafd9703236adcb0 is reachable from dev/v4/v4.0\n- ./shifu check:source\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Align Query/Profile extraction evidence with the canonical rebase-merge commit\",\n  \"verification\": [\"git merge-base --is-ancestor 36381447657fcda49b7b5c48eafd9703236adcb0 dev/v4/v4.0\", \"./shifu check:source\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Evidence points to a canonical reachable commit\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T13:22:37Z",
          "mergedAt": "2026-07-14T13:24:31Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 861,
          "url": "https://github.com/kungfu-systems/kungfu/pull/861",
          "title": "feat(agent): route Codex App Server through product surface",
          "body": "## Summary\n\nDeliver ADR-0085 Stage 5: an opt-in Codex App Server direct-stdio route behind the existing Agent Session product surface. The flag is off by default; the existing Codex and Claude PTY route remains unchanged unless explicitly enabled.\n\n## Changes\n\n- add an exact Codex 0.144.3 product adapter that freezes `codex app-server --stdio` in the reviewed start plan\n- route structured start, instruction, interrupt, approval response, status, snapshot, and receipts through the same GUI/CLI/KFD-3 `invoke` seam\n- reuse the existing product controller/attachment authority and injected Agent Session journal seam without adding another database or GUI-private mutation path\n- project exact provider thread, turn, pending-control, transport, and attempt-boundary metadata without retaining prompts or transcripts\n- preserve semantic outcome, work state, and proof as null delivery non-claims\n- keep feature-off and non-Codex plans/capabilities byte-shape compatible with the PTY surface\n- forbid live hot switching; PTY fallback requires the same WorkConsole/provider, a distinct attempt, and an ended unknown/interrupted structured boundary\n- include the synthetic credential-free product qualification in source acceptance\n\nVersion impact: minor. This is an additive opt-in provider route and package export. The default PTY path, Claude behavior, public product endpoint, and Profile/KFD work authority remain unchanged.\n\n## Verification\n\n- `XDG_CACHE_HOME=/tmp/kungfu-product-integration-cache ./shifu test:codex-app-server-product` (3/3)\n- focused contract/runtime/interaction/recovery/product/detached suite (44/44)\n- `XDG_CACHE_HOME=/tmp/kungfu-product-integration-source-cache ./shifu check:source` after rebasing onto `930ded6f6` (source tests 258/258, docs 61/61, TypeScript and Biome passed)\n- pre-commit staged gate passed, including docs 61/61 and Biome\n- local read-only `codex --version` and `codex app-server --help` confirmed the exact 0.144.3 `app-server --stdio` launch surface\n- no real provider session, credential, prompt, transcript, hidden database, or private state was read\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"ADR-0085\"\n  ],\n  \"summary\": \"Add an opt-in exact-version Codex App Server route through the shared GUI CLI and KFD-3 product surface with frozen per-attempt routing and new-attempt-only PTY fallback\",\n  \"verification\": [\n    \"./shifu test:codex-app-server-product\",\n    \"./shifu test:codex-app-server-recovery\",\n    \"./shifu test:codex-app-server-interaction\",\n    \"./shifu test:codex-app-server-runtime\",\n    \"./shifu test:codex-app-server-contract\",\n    \"./shifu test:agent-session-product-surfaces\",\n    \"./shifu docs:check\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe implementation and tests use only synthetic provider traffic. The route is opt-in and this PR performs no publication, deployment, real provider action, credential access, or private-state inspection.\n\n## Checklist\n\n- [x] Linear DCO-signed delivery history on the latest mainline at push time\n- [x] Product route and source acceptance documentation updated\n- [x] Feature flag absent preserves the existing PTY route and capabilities\n- [x] GUI, CLI, and KFD-3 share one reviewed structured action path\n- [x] Hot switching is forbidden and fallback creates a new attempt\n- [x] Delivery receipts do not claim semantic outcome, work state, or proof\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T13:18:37Z",
          "mergedAt": "2026-07-14T13:28:49Z",
          "additions": 1134,
          "deletions": 46,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 863,
          "url": "https://github.com/kungfu-systems/kungfu/pull/863",
          "title": "feat(agent-session): own work console registry in core",
          "body": "## Summary\n\nMove WorkConsole identity, SessionAttempt lifecycle, reviewed plans, and metadata-only receipts from Terminal presentation state into the detached Core Agent Session worker.\n\n## Changes\n\n- add a durable kungfu.work-console-registry/v2 schema and single-writer Core registry\n- resolve one primary WorkConsole for generic WorkRef bindings and retain distinct provider attempts\n- expose the same registry through GUI, CLI, and KFD-3 list/show/resolve-console operations\n- preserve history while marking old attempts unrecoverable after worker continuity loss\n- reduce Terminal persistence to stable console/attempt references plus pane/window presentation\n- compose with both PTY/Capsule and structured Codex product routes without choosing a transport\n\n## Verification\n\n- ./shifu check:source (263 source acceptance tests)\n- ./shifu test:agent-session-product-surfaces (13 passed)\n- ./shifu test:agent-session-recovery-qualification\n- ./shifu test:codex-app-server-product (3 passed)\n- ./shifu test:agent-console-contract (9 passed)\n- ./shifu --filter @kungfu-tech/gui build\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Complete the Core WorkConsole authority extraction while preserving presentation and transport boundaries\",\n  \"verification\": [\"./shifu check:source\", \"./shifu test:agent-session-product-surfaces\", \"./shifu test:agent-session-recovery-qualification\", \"./shifu test:codex-app-server-product\", \"./shifu test:agent-console-contract\", \"./shifu --filter @kungfu-tech/gui build\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T13:48:54Z",
          "mergedAt": "2026-07-14T13:50:58Z",
          "additions": 967,
          "deletions": 440,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 864,
          "url": "https://github.com/kungfu-systems/kungfu/pull/864",
          "title": "docs(adr): align work console authority evidence",
          "body": "## Summary\n\nAlign ADR-0083 implementation evidence with the canonical implementation commit created by GitHub rebase merge of PR #863.\n\n## Verification\n\n- implementation commit 19ed717bd1db545782f366fd47b14ec3a1c35add is reachable from dev/v4/v4.0\n- ./shifu check:source\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Align WorkConsole authority evidence with the canonical rebase-merge implementation commit\",\n  \"verification\": [\"git merge-base --is-ancestor 19ed717bd1db545782f366fd47b14ec3a1c35add dev/v4/v4.0\", \"./shifu check:source\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Evidence points to a canonical reachable commit\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T13:56:37Z",
          "mergedAt": "2026-07-14T13:58:38Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 865,
          "url": "https://github.com/kungfu-systems/kungfu/pull/865",
          "title": "fix(terminal): keep WorkRef launch profile neutral",
          "body": "## Summary\n\n- remove the Mission Control fallback from generic Terminal WorkRef construction\n- reject partial WorkRef launch identity instead of silently rebinding another Profile as Mission Control\n- add a regression test that keeps Terminal WorkRef launch Profile-neutral\n\n## Verification\n\n- ./shifu test:agent-session-product-surfaces\n- ./shifu check:source\n- ./shifu build:app\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Close the final generic Terminal Profile identity leak found by the capability boundary audit\",\n  \"verification\": [\"./shifu test:agent-session-product-surfaces\", \"./shifu check:source\", \"./shifu build:app\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Correct Mission Control callers already pass workProfileId explicitly\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T14:13:51Z",
          "mergedAt": "2026-07-14T14:17:35Z",
          "additions": 33,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 867,
          "url": "https://github.com/kungfu-systems/kungfu/pull/867",
          "title": "docs(adr): align terminal neutrality evidence",
          "body": "## Summary\n\nAlign ADR-0083 implementation evidence with the canonical Terminal Profile-neutrality commit created by GitHub rebase merge of PR #865.\n\n## Verification\n\n- implementation commit 88624d97677a439f557d07f7ae0eeb577a7d8206 is reachable from dev/v4/v4.0\n- ./shifu check:source\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Align final Terminal Profile-neutrality evidence with the canonical rebase-merge implementation commit\",\n  \"verification\": [\"git merge-base --is-ancestor 88624d97677a439f557d07f7ae0eeb577a7d8206 dev/v4/v4.0\", \"./shifu check:source\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Evidence points to a canonical reachable commit\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T14:21:13Z",
          "mergedAt": "2026-07-14T14:23:05Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 866,
          "url": "https://github.com/kungfu-systems/kungfu/pull/866",
          "title": "feat(agent): default Codex to structured transport",
          "body": "## Summary\n\nMake the qualified Codex 0.144.3 App Server structured adapter the product default for new Codex attempts, retain an explicit PTY rollback, and close the provider-scoped Mac convergence qualification.\n\n## Changes\n\n- default new Codex 0.144.3 attempts to direct App Server stdio while retaining `KUNGFU_AGENT_SESSION_CODEX_APP_SERVER=0` as new-attempt-only PTY rollback\n- freeze reviewed structured thread defaults: untrusted approval policy, user reviewer, read-only sandbox, and exact workspace cwd\n- admit three real stable-schema notifications as typed telemetry only, without work, outcome, session, or proof authority\n- expose bounded metadata-only adapter failure and exit diagnostics while never retaining stderr content\n- extend real-provider dogfood across structured instruction/output, exact approval denial, interrupt, main reattach, exit closure, and bounded stale-plan replanning\n- keep Claude PTY authority and its known approval degradation explicit rather than widening Codex evidence into Claude claims\n\nVersion impact: minor. Codex changes its default transport for the exact qualified 0.144.3 provider. The retained flag value `0` rolls new attempts back to PTY; Claude remains PTY-based.\n\n## Verification\n\n- `./shifu test:codex-app-server-contract:native`\n- focused contract/runtime/interaction/recovery/product/surface/provider suites\n- `./shifu test:agent-session-recovery-qualification`\n- authenticated Mac Codex 0.144.3 source-checkout structured dogfood: full retained interaction loop passed\n- authenticated Mac Claude 2.1.209 PTY dogfood: degradation retained, no approval outcome claimed\n- `XDG_CACHE_HOME=/tmp/kungfu-convergence-shifu-cache ./shifu check:source` after rebasing onto `a780b2b33`: source tests 264/264, docs 61/61, TypeScript and Biome passed\n- pre-commit staged gate passed\n- no prompt, transcript, credential, raw terminal, stderr content, private environment value, or provider private state retained\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"ADR-0085\"\n  ],\n  \"summary\": \"Make the qualified Codex 0.144.3 App Server route the default with exact typed telemetry, safe structured thread policy, real provider qualification, and explicit new-attempt PTY rollback\",\n  \"verification\": [\n    \"./shifu test:codex-app-server-contract:native\",\n    \"./shifu test:codex-app-server-product\",\n    \"./shifu test:codex-app-server-recovery\",\n    \"./shifu test:codex-app-server-interaction\",\n    \"./shifu test:codex-app-server-runtime\",\n    \"./shifu test:agent-session-product-surfaces\",\n    \"./shifu test:agent-session-recovery-qualification\",\n    \"./shifu docs:check\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe dogfood uses official ambient CLI authentication but reads no credential or private provider state. Retained evidence is metadata-only and this PR itself performs no publication or deployment.\n\n## Checklist\n\n- [x] DCO-signed linear delivery commit on the latest mainline\n- [x] Codex structured route is default only for the exact qualified version\n- [x] Explicit PTY rollback creates a new attempt and never hot-switches\n- [x] Unknown structured methods still fail closed\n- [x] Claude degradation remains visible and provider-scoped\n- [x] Delivery receipts claim no semantic outcome, work state, or proof\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T14:16:29Z",
          "mergedAt": "2026-07-14T14:25:43Z",
          "additions": 365,
          "deletions": 59,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 870,
          "url": "https://github.com/kungfu-systems/kungfu/pull/870",
          "title": "fix(product): package Agent Session worker",
          "body": "## Summary\n\nPackage the detached Agent Session runtime explicitly so the desktop application's main process can resolve the structured Codex product client and launch its packaged worker.\n\n## Changes\n\n- copy the workspace-linked @kungfu-tech/agent-session runtime, contracts, and pinned schemas into the application resources\n- extend the post-package audit to fail when the product client or detached worker is absent\n- add a regression fixture proving a package without the worker is rejected\n\nVersion impact: patch. This fixes packaging of the already-integrated ADR-0085 product route without changing its architecture contract, wire contract, default transport, or rollback policy.\n\n## Verification\n\n- node --test framework/gui/scripts/bundle-core-audit.test.cjs\n- XDG_CACHE_HOME=/tmp/kungfu-packaged-worker-source-cache ./shifu check:source\n- ./shifu dist:dir\n- post-package audit against the real unsigned macOS arm64 .app\n- Electron main-process resolution of @kungfu-tech/agent-session/product-client\n- authenticated packaged-app Codex 0.144.3 structured dogfood: start, instruction/output, exact approval denial, interrupt, main restart reattach, and provider exit all passed\n- approval probe file was not created\n- git diff --check\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This patch only restores the packaged files required by the already-integrated ADR-0085 product route and adds a package audit regression; it does not change the architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe packaged dogfood uses ambient CLI authentication but retains no credential, prompt, transcript, raw terminal, stderr content, or private provider state. The build is an unsigned local qualification artifact and this PR does not publish or promote it.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Post-package audit prevents recurrence\n- [x] Existing structured transport and PTY rollback contracts are unchanged\n- [x] Documentation does not change because this is a packaging correction\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T14:44:39Z",
          "mergedAt": "2026-07-14T14:47:16Z",
          "additions": 60,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 869,
          "url": "https://github.com/kungfu-systems/kungfu/pull/869",
          "title": "refactor(core): classify durability commit failures through std::expected",
          "body": "## Summary\n\nLand ADR-0082 staged item 2: write the three-tier error-handling policy into the\ndeveloper docs, and convert the durability barrier-commit `catch` ladder in\n`durable_ingest.cpp` to `std::expected` + a single `transform_error` classifier\nas the tier-2 reference implementation. This is the first use of `std::expected`\nin `libkungfu`.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-adr0082-staged-increments\n\n## Changes\n\n- `framework/core/src/libkungfu/src/runtime/durable_ingest.cpp`: replace the\n  hand-written three-arm `catch` ladder in `barrier(...)` with\n  `capture_ingest_exception(commit_barrier).transform_error(classify_durability_failure)`.\n  `capture_ingest_exception` runs the throwing commit body and captures any\n  exception as a value; `classify_durability_failure` is the single place that\n  rethrows-and-catches, mapping the exception type onto the ingest-error /\n  receipt-code / message triple. Only this classify-and-continue seam changes;\n  the poison-tail append handler (which re-throws to an outer boundary) is a\n  tier-1 pattern and is left as-is.\n- `docs/development/cpp-error-handling.md` (new): the three-tier policy — tier 1\n  exceptions to the loop/ring boundary, tier 2 `std::expected` at\n  classify-and-continue seams, tier 3 value-style scan paths — with a\n  when-to-use table and the `durable_ingest` reference. Registered in the\n  document metadata registry and linked from the development index and ADR-0082.\n- `docs/adr/ADR-0082-...md`: mark staged item 2 as landed, link the new policy\n  doc, and add the item-1 mainline commit (`6f20d83c`) to\n  `implementation_commits` now that it is reachable.\n\n## Behaviour equivalence\n\nThe exception → outcome projection is identical to the former ladder:\n\n| Caught | ingest_error | receipt error | receipt status |\n| --- | --- | --- | --- |\n| `std::logic_error` | `FencingLost` | `ServiceUnavailable` | `Unknown` |\n| `std::system_error` | `IoError` | `ServiceUnavailable` | `Unknown` |\n| other `std::exception` | `InjectedFault` | `ServiceUnavailable` | `Unknown` |\n\nValid early returns inside the commit body (timeout, unsupported profile) are\nvalues, not errors, so they flow through `capture_ingest_exception` unchanged.\n\n## Verification\n\n- Linux / GCC (agent-120): full `build:core` green; durability ctests pass —\n  `durable_ingest`, `durability_contract`, `runtime_error`, `state_service`,\n  `projection_bootstrap`, `crash_recovery` (0 failures)\n- Windows / MSVC (VS 18): full `build:core` green under the new `<expected>` use\n- pre-commit staged gate (clang-format 20.1.8, docs metadata + link gate)\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0082\"],\n  \"summary\": \"Land ADR-0082 staged item 2: write the three-tier error-handling policy into developer docs and convert the durable-ingest barrier catch ladder to std::expected + a single transform_error classifier as the tier-2 reference implementation, behaviour-equivalent\",\n  \"verification\": [\"Linux/GCC full core build + durability ctests\", \"Windows/MSVC full core build\", \"pre-commit staged gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\nBehaviour-preserving refactor plus developer documentation. No contract, schema,\nor runtime-outcome change.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated (new error-handling policy doc + ADR)",
          "author": "kungfu-origin",
          "createdAt": "2026-07-14T14:38:36Z",
          "mergedAt": "2026-07-14T14:53:21Z",
          "additions": 173,
          "deletions": 24,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1200,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1200",
          "title": "fix(release): preserve caller-bound npm publishing",
          "body": "## Summary\n- fail fast when sealed publication evidence is absent and report the actual admission-layer denial\n- bind provider trust to the caller workflow separately from the reusable authority workflow\n- preserve the existing no-Environment npm Trusted Publishing identity and keep named Environment lanes strict\n\n## Validation\n- pnpm run check\n- node --test tests/publication-authority.test.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-14T14:56:29Z",
          "mergedAt": "2026-07-14T14:58:42Z",
          "additions": 290,
          "deletions": 79,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1201,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1201",
          "title": "fix(release): defer npm OIDC authorization",
          "body": "## Summary\n- stop requiring an authenticated npm CLI to preflight OIDC Trusted Publishing\n- bind the exact provider identity and defer final authorization to the npm publish transaction\n- retain optional stronger point-in-time trust evidence through sanitized external JSON\n- avoid treating the npm-token mode label as a real long-lived credential\n\n## Evidence\n- live read-only audit: all six control-plane facts pass without npm credentials\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:05:13Z",
          "mergedAt": "2026-07-14T15:08:03Z",
          "additions": 116,
          "deletions": 56,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 871,
          "url": "https://github.com/kungfu-systems/kungfu/pull/871",
          "title": "refactor(core): migrate the highest-traffic SFINAE overloads to concepts",
          "body": "## Summary\n\nFirst batch of ADR-0082 staged item 3: migrate the two highest-traffic\n`enable_if` SFINAE overload pairs in the core to C++20 concepts. `libyijinjing`\nalready compiles as C++20, and these two pairs are the most-instantiated\ndiagnostics surface in the codebase.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-adr0082-staged-increments\n\n## Changes\n\n- `framework/core/src/libyijinjing/include/kungfu/common.h`: add a named\n  `frame_inline_payload<T>` concept (`size_fixed_v<T> or std::is_same_v<T,\n  nlohmann::json>`) and select the two `event::data<T>()` accessor overloads on\n  `requires frame_inline_payload<T>` / `requires (not frame_inline_payload<T>)`.\n  The return type (`const T &` vs `const T`) is now stated directly instead of\n  wrapped in `std::enable_if_t<..., R>`.\n- `framework/core/src/libyijinjing/include/kungfu/yijinjing/schema/registry.h`:\n  select the `copy()` pair on `requires size_fixed_v<DataType>` / `requires (not\n  size_fixed_v<DataType>)`, returning `void` directly.\n- `docs/adr/ADR-0082-...md`: mark staged item 3 in progress (first batch landed)\n  and add the item-2 mainline commit (`531d40d8`) to `implementation_commits`.\n\n## Equivalence\n\nEach pair's two constraints are exact negations, so overload resolution selects\nthe same overload for every `T` as the former `enable_if` pair — a\nbehaviour-preserving refactor. The observable change is diagnostics: an\nunsatisfied constraint reports `constraints not satisfied` at the call site\nrather than a bare `no type named 'type' in 'std::enable_if_t<...>'`.\n\nThis is the first use of concepts in the core; `enable_if` elsewhere migrates in\nlater batches, no flag-day.\n\n## Verification\n\n- Linux / GCC (agent-120): full `build:core` green — every translation unit that\n  instantiates `event::data<T>()` or `copy()` recompiles under the new\n  constraints; durability / journal / recovery ctests pass\n- Windows / MSVC (VS 18): full `build:core` green\n- pre-commit staged gate (clang-format 20.1.8)\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0082\"],\n  \"summary\": \"First batch of ADR-0082 staged item 3: migrate the two highest-traffic enable_if overload pairs (event::data<T>() and registry copy()) to C++20 concepts, a behaviour-preserving refactor that improves constraint diagnostics\",\n  \"verification\": [\"Linux/GCC full core build + ctests\", \"Windows/MSVC full core build\", \"pre-commit staged gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\nBehaviour-preserving compile-time refactor of two overload constraints.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated (ADR staged-item status)",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:07:53Z",
          "mergedAt": "2026-07-14T15:18:10Z",
          "additions": 30,
          "deletions": 9,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1202,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1202",
          "title": "feat(release): assemble self publication admission",
          "body": "## Summary\n- assemble sealed publication evidence automatically for Buildchain self-promotion only\n- audit the exact authority workflow ref without npm login or repository-admin endpoints\n- restrict workflow_run promotion to verified alpha/release/major channel pushes\n- preserve explicit fail-closed admission for manual and external callers\n\n## Validation\n- pnpm run check (609 passed)\n- bash scripts/check-workflows.sh\n- node --test tests/build-surface.test.mjs (77 passed)\n- real release-candidate artifact assembly smoke against run 29333462403\n- live exact-ref control-plane audit",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:24:44Z",
          "mergedAt": "2026-07-14T15:26:47Z",
          "additions": 514,
          "deletions": 53,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 872,
          "url": "https://github.com/kungfu-systems/kungfu/pull/872",
          "title": "fix(agent-session): qualify packaged provider control",
          "body": "## Summary\n\nClose the Mac product slice of ADR-0081: keep each provider process under the\ndetached AgentSessionCapsule authority, make Claude prompt submission and\napproval detection match the real 2.1.209 TUI, retain one GUI/CLI/Agent control\nsurface, and qualify the packaged Codex/Claude worker before promotion.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-durable-agent-session-control-plane\n\n## Changes\n\n- Submit Claude bracketed paste and Enter as separately idempotent writes, and\n  recognize the bounded Bash confirmation modal before a coexisting ready\n  prompt can admit automatic input.\n- Preserve fail-closed behavior for generic/unknown modals, stale plans,\n  provider exits, approval states, and version drift; expose public exit\n  metadata without retaining terminal output.\n- Extend the real-provider dogfood harness with Claude model/effort policy,\n  explicit Bash ask configuration, packaged-worker assertions, redacted\n  diagnostics, Codex structured transport, and an explicit PTY rollback route.\n- Record packaged Mac qualification and promotion evidence for build\n  `20260714T150829Z-237b7662f` at `/Applications/Kungfu Episodes.app`.\n\n## Verification\n\n- `./shifu check:source`: 268/268 tests, 61 documentation contract fixtures,\n  TypeScript, Biome, Markdown, links, schemas, and contract gates passed at\n  `ad53886ff40939ecfaa760d98a4076239f58cf8e`.\n- `./shifu dist`: packaged build `20260714T150829Z-237b7662f`; afterPack bundle\n  audit passed and both Darwin node-pty spawn helpers are executable.\n- Packaged Claude 2.1.209 PTY: 6/6 cases passed; explicit Bash ask, sonnet/low,\n  approval denied before the disposable probe could run.\n- Packaged Codex 0.144.3 PTY: 6/6 cases passed.\n- Packaged Codex 0.144.3 structured transport: 6/6 cases passed; feature-off\n  rollback creates a distinct PTY attempt.\n- Installed Agent Session package/client/worker and node-pty helper hashes match\n  the promoted candidate; Shifu catalog reports the build as current.\n- All retained reports are metadata-only: no raw terminal bytes or private\n  environment values.\n\n## Retained limits\n\nMachine-restart recovery and Linux/Windows product qualification remain\nnot-run. ADR-0081 therefore remains partial; this PR claims only the qualified\nMac product slice. The repository-wide `./shifu check` remains blocked by the\npre-existing canonical-policy rendered hash mismatch; this branch does not\nchange those policy inputs, while the complete source gate is green.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Qualify and promote the packaged Mac AgentSessionCapsule control plane for Codex PTY, Codex structured transport, and Claude PTY while retaining fail-closed authority and privacy boundaries\",\n  \"verification\": [\"Shifu source gate 268/268\", \"packaged Mac dist and bundle audit\", \"packaged Codex PTY 6/6\", \"packaged Codex structured 6/6\", \"packaged Claude PTY 6/6\", \"installed candidate hash verification\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nProvider CLI behavior is version-pinned and tested through temporary runtimes.\nNo credentials, private transcripts, raw terminal bytes, or provider session\nstate are committed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and qualification evidence updated\n- [x] Packaged product promoted without terminating or relaunching the running GUI\n\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:20:12Z",
          "mergedAt": "2026-07-14T15:30:17Z",
          "additions": 438,
          "deletions": 68,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 875,
          "url": "https://github.com/kungfu-systems/kungfu/pull/875",
          "title": "feat(gates): add source-bound measurement profile",
          "body": "## Summary\n\n- add a manual, non-publication Shifu profile that measures every task-backed Gate on its supported self-hosted platforms\n- retain source-bound receipts through the pinned Buildchain profile controller\n- keep DCO, Buildchain config, and artifact admission on their real remote-controller boundaries\n- distinguish measurement-only bindings from standing Gate policy sources\n\n## Verification\n\n- `./shifu gate validate`\n- measurement plans: Linux 35 Gates, macOS 32 Gates, Windows 31 Gates, no unsupported selections\n- `./shifu check:gate-catalog`\n- `./shifu check:source` (265 tests pass)\n- pre-commit staged gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Adds a diagnostic measurement runner and retained evidence path without changing any product architecture or release-policy requirement.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: the workflow is manual, read-only, pinned to Buildchain v2.12.4, and emits source-bound receipts only; it has no publish permission or publication step.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:28:08Z",
          "mergedAt": "2026-07-14T15:36:33Z",
          "additions": 249,
          "deletions": 87,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1203,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1203",
          "title": "Promote v2.12 publication authority fixes to alpha",
          "body": "## Scope\nPromote the three sealed-publication authority fixes now merged on `dev/v2/v2.12`:\n\n- preserve the caller-bound npm trusted-publisher identity and existing no-Environment contract\n- eliminate false npm-login and credential-scan failures\n- assemble and independently verify Buildchain self-publication admission evidence\n\n## Release impact\nMerging this PR advances `alpha/v2/v2.12` at package version `2.12.7-alpha.0`. The successful push verification is expected to invoke Buildchain Ref Promotion and may publish `@kungfu-tech/buildchain@2.12.7-alpha.0` with npm trusted publishing. Do not merge without explicit release authorization.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:27:47Z",
          "mergedAt": "2026-07-14T15:38:39Z",
          "additions": 866,
          "deletions": 134,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 873,
          "url": "https://github.com/kungfu-systems/kungfu/pull/873",
          "title": "fix(gui): package Agent Session runtime",
          "body": "## Summary\n\n- ship the externalized Agent Session workspace runtime inside the packaged Electron app\n- fail after-pack when any static external main-process dependency cannot resolve from the app\n- add regression coverage for the missing-package failure and product packaging config\n\n## Verification\n\n- node --test framework/gui/scripts/bundle-core-audit.test.cjs product/scripts/dist.test.mjs\n- XDG_CACHE_HOME=/tmp/kungfu-gui-package-closure-cache ./shifu check:source\n- XDG_CACHE_HOME=/tmp/kungfu-gui-package-closure-cache ./shifu product gui build\n- isolated packaged cold launch: KF_GUI_QUALIFICATION_READY and exit 0\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Close the packaged GUI main-process dependency boundary so the WorkConsole product cold-starts from its installed artifact\",\n  \"verification\": [\"node --test framework/gui/scripts/bundle-core-audit.test.cjs product/scripts/dist.test.mjs\", \"./shifu check:source\", \"./shifu product gui build\", \"isolated packaged cold launch\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Installed package resolves every static external main-process dependency\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:21:48Z",
          "mergedAt": "2026-07-14T15:40:54Z",
          "additions": 126,
          "deletions": 13,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 876,
          "url": "https://github.com/kungfu-systems/kungfu/pull/876",
          "title": "feat(runtime): recover live peers across coordinator restart",
          "body": "## Summary\n\nMake live Peer and Agent Session Capsule continuity survive Coordinator replacement without restarting the workload process, fenced by one explicit runtime generation and coordinator epoch authority.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-live-peer-continuity\n\n## Changes\n\n- add the Core continuity state machine, bounded reconnect, stale authority fencing, and persistent Coordinator epoch allocation\n- project runtime generation through broker, routes, Supervisor, Coordinator, Python bindings, and Agent Session Capsule transport\n- add a real cross-process Coordinator crash/restart campaign and wire the full qualification into alpha/release Buildchain\n- retain checksummed `raw-logs.jsonl.gz` beside `report.json`\n- make the native campaign wait for real Coordinator storage readiness instead of a fixed startup sleep\n- pin the C++ source formatter fallback to the repository version when the ambient formatter drifts\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu rebuild:core`\n- `./shifu live-peer:qualify -- --output .buildchain/runtime/qualification/live-peer-continuity/final-clean-01 --retain product/release/qualification/live-peer-continuity-a7b254786`\n- second consecutive `live-peer:qualify` run at the same clean source revision\n- retained report verdict: passed; source: `a7b2547863b4396d934534707528c41256d5a569`; raw bundle SHA-256: `1ec5e3b5679ad559a4a202399d1785aa32edd6074e442113f6e7bab6d96df2db`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\", \"ADR-0086\"],\n  \"summary\": \"Repair rebased ADR-0083 evidence and deliver live Peer and Capsule continuity through fenced Coordinator replacement with retained qualification evidence\",\n  \"verification\": [\"docs:check\", \"check:source\", \"rebuild:core\", \"two clean live-peer:qualify campaigns with retained report and raw log bundle\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes release qualification composition and retained local evidence only. It adds no publishing credential or deployment authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:30:31Z",
          "mergedAt": "2026-07-14T15:48:35Z",
          "additions": 2275,
          "deletions": 133,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1204,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1204",
          "title": "fix(release): audit provider-enforced branch transactions",
          "body": "## Root cause\nThe credential-free publication auditor called GitHub's detailed branch-protection endpoint. That endpoint requires repository Administration read permission, so the read-only publication verifier received `403` and incorrectly reported a branch-policy failure before npm/OIDC evaluation.\n\n## Fix\n- bind `--source-sha` to GitHub's public protected-branch summary\n- prove current branch head, same-repository merged PR lineage, independent approval, required `check`, and required app identity\n- retain detailed branch-protection/ruleset auditing when configuration is readable\n- keep missing or mismatched transaction evidence fail-closed\n\n## Evidence\n- live audit of `alpha/v2/v2.12@b434fd84`: all six facts pass\n- `pnpm run check`: 610 tests pass\n- targeted publication/build-surface tests: 94 pass\n- workflow and generated-site checks pass\n\nThis PR does not publish or mutate GitHub/npm control-plane configuration.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:51:28Z",
          "mergedAt": "2026-07-14T15:53:50Z",
          "additions": 184,
          "deletions": 34,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1205,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1205",
          "title": "Promote provider-enforced publication audit to alpha",
          "body": "## Scope\nPromote the credential-free protected-branch transaction audit from PR #1204.\n\n## Prior canary evidence\nThe first `2.12.7-alpha.0` promotion attempt (run 29346311363) stopped before npm because GitHub's detailed branch-protection endpoint returned `403` to the read-only verifier. No package or GitHub Release was published.\n\n## Expected result\nMerging this PR reruns the approved alpha publication transaction for `@kungfu-tech/buildchain@2.12.7-alpha.0`, using protected-branch head, merged PR lineage, independent approval, required check, and required app identity as branch-policy evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:54:05Z",
          "mergedAt": "2026-07-14T15:56:18Z",
          "additions": 184,
          "deletions": 34,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 874,
          "url": "https://github.com/kungfu-systems/kungfu/pull/874",
          "title": "refactor(core): fold reader.cpp journal selection to std::ranges",
          "body": "## Summary\n\nOpportunistic ADR-0082 staged item 4 (ranges): fold the manual filter loop in\n`reader::sort_without_buffer()` to `std::ranges`, discharging the `reader.cpp`\nTODO the ADR names. `libyijinjing` already compiles as C++20.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-adr0082-staged-increments\n\n## Changes\n\n- `framework/core/src/libyijinjing/src/journal/reader.cpp`:\n  `sort_without_buffer()` replaces the hand-written \"collect has-data journals\n  into a vector, then `std::max_element`\" loop with\n  `journals_ | std::views::values | std::views::filter(...)` fed to\n  `std::ranges::max_element(..., later{})`.\n- `docs/adr/ADR-0082-...md`: record staged item 4 ranges as landed and deducing\n  this as deferred (the `kungfu::data<T>` CRTP base is too widely inherited to be\n  a clean opportunistic target), and add the item-3 mainline commit (`6232f1e1`)\n  to `implementation_commits`.\n\n## Equivalence\n\nSame journals with `has_data()` are considered, compared by the same `later{}`\npredicate, and the same one is assigned to `current_`. The view is lazy where\nthe old vector was eager, but `max_element` consumes it fully either way, so the\nselection is identical. `sort_without_buffer()` runs only on join / disjoin /\nseek, not on the per-frame `next()` path.\n\n## Verification\n\n- Linux / GCC (agent-120): full `build:core` green; journal / reader / mmap /\n  durability / crash-recovery ctests pass\n- Windows / MSVC (VS 18): full `build:core` green\n- pre-commit staged gate (clang-format 20.1.8)\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0082\"],\n  \"summary\": \"Opportunistic ADR-0082 staged item 4 ranges: fold reader::sort_without_buffer() to std::views + std::ranges::max_element, discharging the reader.cpp TODO the ADR names, behaviour-preserving\",\n  \"verification\": [\"Linux/GCC full core build + journal/reader ctests\", \"Windows/MSVC full core build\", \"pre-commit staged gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\nBehaviour-preserving refactor of one journal-selection helper.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated (ADR staged-item status)",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:27:46Z",
          "mergedAt": "2026-07-14T15:59:11Z",
          "additions": 18,
          "deletions": 15,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 879,
          "url": "https://github.com/kungfu-systems/kungfu/pull/879",
          "title": "docs(adr): close GUI capability boundary",
          "body": "## Summary\n\n- mark ADR-0083 implemented with canonical mainline evidence\n- retain the exact macOS arm64 Product qualification report for build 20260714T154905Z-611e39d82\n- document explicit Linux, Windows, machine-restart, and interactive-pixel nonclaims\n\n## Verification\n\n- ./shifu check:source (268/268 on exact candidate)\n- ./shifu dist\n- bundle-core-audit: 7 packaged main dependencies resolve\n- isolated packaged cold launch: KF_GUI_QUALIFICATION_READY\n- authenticated packaged Codex structured provider: 6/6 cases\n- promoted build 20260714T154905Z-611e39d82 and observed installed Electron renderer\n- ./shifu docs:check:readonly (passed before upstream ADR-0086 evidence drift)\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Close the GUI capability ownership migration with exact packaged Product qualification and installed promotion evidence\",\n  \"verification\": [\"./shifu check:source\", \"./shifu dist\", \"bundle-core-audit\", \"packaged cold launch\", \"authenticated Codex structured provider 6/6\", \"installed promotion receipt\", \"./shifu docs:check:readonly\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Exact Product artifact is promoted and rollback material is retained\n- [x] Platform gaps are explicit\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:55:58Z",
          "mergedAt": "2026-07-14T16:04:08Z",
          "additions": 199,
          "deletions": 2,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1207,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1207",
          "title": "fix(release): reuse provider transaction governance",
          "body": "## Summary\n\n- reuse GitHub provider-enforced transaction evidence when workflow tokens cannot read administrative branch-protection details\n- bind fallback admission to the exact protected head, merged same-repository PR, independent approval, required successful check, and configured GitHub App\n- retain detailed branch-protection auditing whenever the administrative endpoint is readable\n\n## Validation\n\n- `node --test tests/promote-buildchain-ref.test.mjs` (103/103)\n- `pnpm run check` (610/610)\n- action bundles generated successfully\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:03:50Z",
          "mergedAt": "2026-07-14T16:07:24Z",
          "additions": 201,
          "deletions": 94,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1208,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1208",
          "title": "release: promote dev v2.12 to alpha",
          "body": "## Release intent\n\nPromote the current protected `dev/v2/v2.12` head to `alpha/v2/v2.12` and execute the sealed Buildchain publication transaction.\n\nThis promotion includes the provider-enforced transaction governance fallback required for read-only GitHub workflow tokens.\n\n## Evidence\n\n- dev source SHA: `22de2f779b81cd67c88dbbdf8ef2787318fb31d0`\n- fix PR: #1207\n- local full check: 610/610\n- fix action tests: 103/103",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:08:03Z",
          "mergedAt": "2026-07-14T16:10:34Z",
          "additions": 201,
          "deletions": 94,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1210,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1210",
          "title": "fix(release): keep promotion dry-run mutation-free",
          "body": "## Summary\n\n- keep release-candidate promotion dry-runs from reading, creating, or moving publish-gate refs\n- still report the exact source-lock plan consumed by the dry-run action\n- lock the behavior in inventory and build-surface tests\n\n## Validation\n\n- `node --test tests/build-surface.test.mjs` (77 passed)\n- `node scripts/check-inventory.mjs`\n- `git diff --check`\n\n## Safety\n\nNon-dry-run promotion behavior is unchanged. Dry-run now exits the ref mutation branch before any GitHub ref API call.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:16:22Z",
          "mergedAt": "2026-07-14T16:24:17Z",
          "additions": 35,
          "deletions": 22,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 881,
          "url": "https://github.com/kungfu-systems/kungfu/pull/881",
          "title": "feat(runtime): retire idle desktop supervisors safely",
          "body": "## Summary\n\nMake the desktop runtime self-maintaining without a resident supervisor for on-demand use, while preserving installed always-on service behavior and refusing unsafe PID-based ownership.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-desktop-runtime-self-maintenance\n\n## Changes\n\n- serialize activation and idle-exit decisions across threads and processes so concurrent ensure calls spawn one supervisor\n- atomically retire inactive routes and let on-demand supervisors exit after the last child drains\n- keep installed launchd, systemd, and Windows service plans resident through KF_SUPERVISOR_ALWAYS_ON=1\n- bind coordinator adoption and every process signal to exact runtime generation, PID, and process-start identity\n- preserve unowned or PID-reused processes without signalling and surface ownership-unknown\n- add 16-way activation, 100-round cleanup, replacement-race, always-on, orphan, and PID-reuse regression coverage\n- project the new self-maintenance coverage into the unified runtime qualification report\n\n## Verification\n\n- framework/core Python runtime service tests: 30 passed\n- ./shifu check:source: 271 contract tests passed; source gate passed\n- ./shifu check: changed-scope gate passed\n- ./shifu runtime:qualify -- --mode dry-run: planned report includes on-demand-runtime-self-maintenance\n- git diff --check\n- all three commits carry Signed-off-by trailers\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Complete on-demand desktop runtime self-maintenance with race-safe idle exit and process-start identity fencing\",\n  \"verification\": [\"30 runtime service tests\", \"check:source\", \"changed-scope check\", \"runtime qualification dry-run coverage\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR extends the runtime qualification coverage map and changes no publishing credentials or deployment authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:23:57Z",
          "mergedAt": "2026-07-14T16:28:33Z",
          "additions": 644,
          "deletions": 121,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1212,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1212",
          "title": "fix(release): preserve provider-managed channel policy",
          "body": "Supersedes #1211 with a linear-history branch based on the latest dev head.\n\n## Summary\n\n- reuse an already qualifying provider-enforced channel policy when the workflow token cannot read the administrative protection document\n- avoid rewriting existing protected channel policy during post-publish reconciliation\n- fail closed when protection, enforcement for everyone, or the exact required check is absent\n\n## Validation\n\n- targeted action tests: 104/104\n- full `pnpm run check`: 611/611\n- latest dev integration targeted tests: 104/104",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:30:11Z",
          "mergedAt": "2026-07-14T16:32:52Z",
          "additions": 144,
          "deletions": 53,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 883,
          "url": "https://github.com/kungfu-systems/kungfu/pull/883",
          "title": "feat(runtime): add versioned product upgrade control plane",
          "body": "## Summary\n\nAdd the shared Core authority for versioned product runtime upgrades without giving desktop or standalone CLI transport adapters live-generation authority.\n\n## Related issue\n\nAtlas goal `2026-07-14-kungfu-runtime-upgrade-control-plane`.\n\n## Changes\n\n- register ADR-0087 and `kungfu.product-upgrade.contract/v1` in the KFD-1 contract world\n- add digest-verified side-by-side runtime image installation, quarantine, deterministic compatibility planning, generation staging/reconciliation, rollback, and reference-aware GC\n- pin ProcessRuntimeHost child commands and environment to one immutable runtime image\n- expose dry-run-first `kungfu runtime upgrade` contract, inventory, install, plan, stage, reconcile, and GC surfaces\n- weld the upgrade contract into product compatibility evidence and source/shared gates\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu test:runtime-upgrade`\n- `./shifu --filter @kungfu-tech/sdk run build`\n- `./shifu --filter @kungfu-tech/core run test:tooling`\n- contract audit: current, six surfaces, no failures\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0087\"],\n  \"summary\": \"Freeze and implement the first shared runtime upgrade control-plane slice: immutable images, deterministic plans, generation pins, readiness-gated commit and rollback, and reference-aware GC.\",\n  \"verification\": [\"./shifu check:source\", \"./shifu test:runtime-upgrade\", \"SDK contract CLI tests\", \"Core tooling tests\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR defines release identity fields and KFD-1 upgrade evidence only. It does not publish artifacts, use credentials, configure endpoints, or claim signed platform delivery.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:32:53Z",
          "mergedAt": "2026-07-14T16:36:59Z",
          "additions": 2746,
          "deletions": 16,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1214,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1214",
          "title": "release: publish Buildchain 2.12.7-alpha.2",
          "body": "Supersedes conflicted dev-to-alpha PR #1213 with the repository-supported same-line publish-gate source lock.\n\n## Source\n\n- exact tree equals protected dev `267afc5b541a0037b29b37cd59356834421df790`\n- source-lock ref: `publish-gate/alpha/v2/v2.12/2.12.7-alpha.2`\n- includes #1210 and #1212\n\n## Intent\n\nPublish `@kungfu-tech/buildchain@2.12.7-alpha.2`, complete GitHub Release evidence, and close the durable publication transaction. `latest` must remain stable.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:35:52Z",
          "mergedAt": "2026-07-14T16:38:15Z",
          "additions": 176,
          "deletions": 72,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1216,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1216",
          "title": "fix(release): wire protected ref publication authority",
          "body": "## Summary\n\n- expose the existing `BUILDCHAIN_PROMOTION_TOKEN` to the reusable promotion workflow\n- use it only for generated protected-ref updates while retaining `github.token` for Checks\n- replace the regression assertion that incorrectly required the promotion token to be absent\n- refresh generated site contracts\n\n## Validation\n\n- `pnpm run check` (611 tests passed)\n- targeted promotion workflow contract tests\n\n## Context\n\nThis fixes post-publish alpha finalization after npm trusted publishing succeeds. It restores the documented least-privilege authority split without changing repository variables or secrets.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:50:48Z",
          "mergedAt": "2026-07-14T16:53:22Z",
          "additions": 45,
          "deletions": 24,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 884,
          "url": "https://github.com/kungfu-systems/kungfu/pull/884",
          "title": "feat(agent-session): project recoverable product states",
          "body": "## Summary\n\n- project live and retained Agent Session attempts into one product recovery vocabulary\n- keep worker-loss attempts visible with a safe action-required recommendation\n- remove ordinary Capsule terminology from the terminal product surface\n- repair the ADR-0087 evidence SHA rewritten by the immediately preceding rebase merge\n\n## Verification\n\n- ./shifu test:agent-session-product-surfaces (16/16)\n- ./shifu --filter @kungfu-tech/kfx-view-terminal test (8/8)\n- ./shifu test:agent-session-recovery-qualification (passed; local list RPC p95 1.143 ms)\n- ./shifu check:source (passed; 272 code tests and 61 docs contract tests)\n- git diff --check\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Project retained and live Agent Session attempts into one product recovery vocabulary and keep worker-loss action visible without process terminology\",\n  \"verification\": [\n    \"./shifu test:agent-session-product-surfaces\",\n    \"./shifu --filter @kungfu-tech/kfx-view-terminal test\",\n    \"./shifu test:agent-session-recovery-qualification\",\n    \"./shifu check:source\"\n  ]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:52:31Z",
          "mergedAt": "2026-07-14T16:55:02Z",
          "additions": 389,
          "deletions": 28,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1217,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1217",
          "title": "fix(release): wire protected ref publication authority",
          "body": "## Summary\n\n- promote the reviewed publication-authority wiring from dev into the protected alpha channel\n- keep GitHub Actions as the generated Check owner\n- use the existing bypass-capable `BUILDCHAIN_PROMOTION_TOKEN` only for protected ref finalization\n\n## Source lock\n\n- source branch: `publish-gate/alpha/v2/v2.12/2.12.7-alpha.3`\n- source tree exactly matches `dev/v2/v2.12` at `ff80442b7c8ff42d5e10efa7b0c191781241712a`\n- expected prerelease: `@kungfu-tech/buildchain@2.12.7-alpha.3`\n\n## Validation\n\n- dev PR #1216 passed all required checks\n- `pnpm run check` passed locally (611 tests)",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:54:05Z",
          "mergedAt": "2026-07-14T16:56:21Z",
          "additions": 45,
          "deletions": 24,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1218,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1218",
          "title": "fix(release): report concrete promotion failures",
          "body": "## Summary\n\n- expose the concrete promotion action failure as a bounded single-line output\n- classify post-RC promotion failures from that output instead of reusing the successful RC resolver diagnosis\n- reserve duplicate-build advice for actual duplicate PR/build evidence\n- keep RC resolution details as context without presenting them as the failure cause\n\n## Validation\n\n- `pnpm run check` (611 tests passed)\n- regression test proves a protected-ref failure is reported and successful RC diagnosis is excluded\n- action bundle and generated contract refreshed\n\n## Observed false report\n\nIssues #1206, #1209, and #1215 reported successful RC resolution as the diagnosis and suggested deduplication even though the actual failures occurred later in promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T17:06:10Z",
          "mergedAt": "2026-07-14T17:08:41Z",
          "additions": 60,
          "deletions": 9,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 885,
          "url": "https://github.com/kungfu-systems/kungfu/pull/885",
          "title": "test(runtime): aggregate zero-burden release evidence",
          "body": "## Summary\n\n- add one source/platform-bound zero-burden desktop qualification that aggregates runtime activation, live-peer continuity, recovery projection, product build verification, and evidence retention\n- run the aggregate gate after the component gates in every alpha/release Buildchain path\n- retain report.json and raw-logs.jsonl.gz together for component and aggregate evidence\n- document narrow claims and preserve current authenticated Claude approval dogfood as an explicit nonclaim\n\n## Verification\n\n- ./shifu check\n- ./shifu check:source (276 Node tests; 13 runtime upgrade Python tests)\n- ./shifu build\n- live-peer continuity qualification: passed\n- runtime activation qualification: 8/8 passed\n- zero-burden desktop aggregate qualification: 6/6 coverage, passed\n- Codex 0.144.3 PTY + structured provider dogfood: 6/6 + 6/6\n- git diff --check\n\n## Product evidence\n\n- promoted local candidate: 20260714T181903Z-3bd0302eb\n- source revision: 3bd0302ebb5c38430a2691484e037cb0b260ab7f\n- aggregate report SHA-256: bc8693aa79e7319788a2eb8581556985ddc91f671adc8613db622984487d859c\n- aggregate raw logs SHA-256: 46f35fb2c3a388f465ed8b314534a04747d788d02c504be3ac08c82db11319ed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\", \"ADR-0081\", \"ADR-0086\"],\n  \"summary\": \"Aggregate source-bound zero-burden desktop qualification into alpha and release Buildchain gates with paired report and raw-log retention\",\n  \"verification\": [\n    \"./shifu check\",\n    \"./shifu check:source\",\n    \"./shifu build\",\n    \"zero-burden:qualify\"\n  ]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T17:59:52Z",
          "mergedAt": "2026-07-14T18:15:48Z",
          "additions": 648,
          "deletions": 69,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1219,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1219",
          "title": "fix(gates): reset stale Windows source workspaces",
          "body": "## Summary\n\n- reset the fixed `source` checkout directory before Windows Gate jobs\n- bound cleanup to `GITHUB_WORKSPACE` with an explicit path guard\n- preserve the normal locked-source checkout and add workflow contract coverage\n\n## Why\n\nA cancelled or failed Gate preparation can leave deep pnpm dependency trees in the self-hosted Windows workspace. The next `actions/checkout` then fails in `git clean -ffdx` with `Filename too long` before a Gate receipt can be produced. Native Windows directory removal is able to clear the runner-owned, reproducible checkout reliably.\n\n## Validation\n\n- `node --test tests/build-surface.test.mjs` (77 passed)\n- `pnpm run check:workflows`\n- `git diff --check`\n\n## Downstream validation\n\nKungfu Gate Measurement will be dispatched against the exact PR head SHA before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T18:27:04Z",
          "mergedAt": "2026-07-14T18:30:58Z",
          "additions": 22,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1220,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1220",
          "title": "fix(gates): preserve Windows source object cache",
          "body": "## Summary\n\n- preserve the prior Windows Gate checkout `.git` directory across native workspace cleanup\n- restore the object store before `actions/checkout` while removing all reproducible worktree residue\n- retain the fixed workspace path guard and add contract coverage\n\n## Why\n\nThe Windows-native cleanup from #1219 removes long-path dependency trees reliably, but deleting `.git` would also discard the complete history already cached on a self-hosted runner. Preserving only the Git object store avoids a slow full-history network fetch while still giving `actions/checkout` a clean worktree.\n\n## Validation\n\n- `node --test tests/build-surface.test.mjs` (77 passed)\n- `pnpm run check:workflows`\n- `pnpm run check:site`\n- live DARKHERO contract probe: `.git/config` restored and `node_modules` removed\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-14T18:35:14Z",
          "mergedAt": "2026-07-14T18:37:26Z",
          "additions": 20,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1221,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1221",
          "title": "fix(gates): expose runner user toolchain",
          "body": "## Summary\n- expose the runner account user toolchain before Shifu Gate execution\n- cover Windows and POSIX PATH behavior with contract tests\n- document runner provisioning ownership\n\n## Validation\n- `pnpm run check`\n- `node --test --test-name-pattern=\"reusable Shifu Gate workflow\" tests/build-surface.test.mjs`\n- `git diff --check`\n\nThis unblocks strict cache profiles that require user-scoped `uv` on self-hosted runners.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T19:28:10Z",
          "mergedAt": "2026-07-14T19:36:27Z",
          "additions": 29,
          "deletions": 9,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 887,
          "url": "https://github.com/kungfu-systems/kungfu/pull/887",
          "title": "fix(gui): close packaged agent session gaps",
          "body": "## Summary\n\nClose three implementation defects found by real macOS packaged GUI dogfood. This does not alter the accepted Agent Session, capability-boundary, or structured-provider architecture contracts.\n\n## Changes\n\n- route Agent Session actions through the generic CLI IPC capability\n- normalize Codex and Claude version-probe output to semantic versions\n- include product status in structured snapshots and keep old workers reattachable through a status fallback\n- render structured sessions without assuming a retained terminal transcript\n- add a changed-file semantic TypeScript gate for GUI sources\n\n## Verification\n\n- `./shifu check:source` (281 Node contract tests; 13 runtime-upgrade tests; TypeScript, Biome, Ruff, and mypy passed)\n- `./shifu product gui pack`\n- real packaged Codex 0.144.3: launch, full GUI quit, same worker/provider PID reattach, semantic instruction receipt, ready recovery, 0 console errors/warnings\n- real packaged Claude 2.1.209: workspace-trust modal, full GUI quit, same worker/provider PID reattach, 0 console errors/warnings; authenticated provider work remains a nonclaim because PATH Claude reports not logged in\n- live-peer continuity qualification: passed; paired report/raw bundle hashes `86f1f9b6e...` / `d142c680e...`\n- runtime activation/product qualification: passed; paired report/raw bundle hashes `01d9300ec...` / `396e0c260...`\n- zero-burden aggregate: 6/6, passed; paired report/raw bundle hashes `09b935cba...` / `0ac836cb3...`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fix packaged GUI IPC wiring, provider version parsing, and structured snapshot rendering defects without changing architecture contracts or supported claims\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe provider boundary remains pinned and redacted; no transcript or credential material is retained. Qualification reports remain source/platform-bound and preserve current nonclaims.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Existing qualification documentation remains accurate because this bugfix does not widen claims\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T19:49:30Z",
          "mergedAt": "2026-07-14T19:52:10Z",
          "additions": 287,
          "deletions": 6,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1222,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1222",
          "title": "fix(build): expose runner user toolchain",
          "body": "## Summary\n\n- expose runner-local tools before native build lifecycle execution\n- cover Windows and POSIX self-hosted runners\n- regenerate the Buildchain contract audit digest\n\n## Validation\n\n- node --test tests/build-surface.test.mjs\n- pnpm check",
          "author": "dongkeren",
          "createdAt": "2026-07-14T21:01:50Z",
          "mergedAt": "2026-07-14T21:03:52Z",
          "additions": 30,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 32,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/32",
          "title": "docs(paper): model observer continuity across incarnations",
          "body": "## Summary\n\n- distinguish a stable logical observer from evidence-bearing observer incarnations\n- define continuity witnesses and separate fact, observer, and presentation continuity\n- map exact-cut runtime readiness, fenced Peer recovery, recoverable product states, and immutable upgrades into the KFD-4 systems argument\n- correct stale claims about Episode capability soundness and the not-yet-implemented dedicated Episode projection\n- preserve explicit single-host and multi-machine evidence boundaries\n\n## Checks\n\n- [x] `make check`\n- [x] Tectonic PDF build completed without warnings\n- [x] All 16 rendered pages inspected\n- [ ] Buildchain `Build` workflow passes\n- [ ] Buildchain `Verify` workflow passes\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] Provider/API/data claims are sourced or clearly marked as future work\n- [x] Public branding and trademark language stays factual\n- [x] Evidence from different source revisions remains explicitly separated",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:02:13Z",
          "mergedAt": "2026-07-14T22:03:27Z",
          "additions": 569,
          "deletions": 227,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 34,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/34",
          "title": "chore(release): prepare observer paper alpha.5",
          "body": "## Summary\n\n- publish the third substantive revision of the observer-declared timelines paper\n- model logical observer incarnations and evidenced continuity across restarts\n- align readiness and recovery claims with the current exact-cut, fenced-recovery, and immutable-runtime evidence\n- advance the publication contract to `0.1.0-alpha.5` while preserving `observer-declared-timelines.pdf`\n\n## Validation\n\n- `make check`\n- `make pdf` (16 pages)\n- `git diff --check`\n\n## Boundaries\n\nThis revision does not claim completed multi-machine projection, accepted-range negotiation, cross-source reconciliation policy, exported observer declarations, or projection causal fsck.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:07:28Z",
          "mergedAt": "2026-07-14T22:11:39Z",
          "additions": 629,
          "deletions": 237,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 36,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/36",
          "title": "chore(release): promote observer paper alpha.5",
          "body": "## Summary\n\nPromote the active v0.1 development line to the alpha channel for `0.1.0-alpha.5`.\n\nThis release carries the third substantive revision of the observer-declared timelines paper, including logical observer incarnations, continuity witnesses, exact-cut readiness, fenced recovery, and explicit evidence boundaries.\n\n## Release contract\n\n- package: `@kungfu-tech/paper-observer-declared-timelines`\n- version: `0.1.0-alpha.5`\n- PDF: `observer-declared-timelines.pdf`\n- Buildchain runtime: accepted `v2` contract at `7c1b0059f239a6a8ab784dbaea926f9f9ab22294`\n\n## Source\n\n- preparation PR: #34\n- development head: `24a6eb78aa91a5d4e9a4fca7b27a1df611964f87`\n\nMerging this PR triggers the managed paper release workflow.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:12:12Z",
          "mergedAt": "2026-07-14T22:13:14Z",
          "additions": 629,
          "deletions": 237,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 37,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/37",
          "title": "fix(release): isolate controller generated state",
          "body": "## Summary\n\n- classify `.buildchain/controller/` as Buildchain-generated evidence state\n- keep controller plan/receipt files out of consumer version-state verification\n- preserve the alpha.5 version and publication contract unchanged\n\n## Evidence\n\nThe first alpha.5 release attempt passed build, verification, contract lock, protected authority, package preparation, and publish-source locking, then failed because `.buildchain/controller/plan.json` appeared as an untracked out-of-version-state file:\n\nhttps://github.com/kungfu-systems/paper-observer-declared-timelines/actions/runs/29372265210\n\nUpstream tracking: kungfu-systems/buildchain#1223\n\n## Validation\n\n- `git check-ignore --no-index -v .buildchain/controller/plan.json`\n- `make check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:16:18Z",
          "mergedAt": "2026-07-14T22:17:20Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 38,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/38",
          "title": "fix(release): retry observer paper alpha.5 promotion",
          "body": "## Summary\n\nPromote the generated-state boundary fix from the v0.1 development line and retry the managed `0.1.0-alpha.5` paper release.\n\n## Failure closure\n\n- failed release run: https://github.com/kungfu-systems/paper-observer-declared-timelines/actions/runs/29372265210\n- consumer fix: #37\n- upstream tracking: kungfu-systems/buildchain#1223\n- the failed attempt stopped before npm publication, so `0.1.0-alpha.5` remains unpublished\n\n## Release contract\n\n- package: `@kungfu-tech/paper-observer-declared-timelines`\n- version: `0.1.0-alpha.5`\n- PDF: `observer-declared-timelines.pdf`\n- development head: `a8ca82f7bf31dac3ef00a831ca3342ddd8bfaab3`",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:17:41Z",
          "mergedAt": "2026-07-14T22:18:44Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 133,
          "url": "https://github.com/kungfu-systems/build-images/pull/133",
          "title": "fix(comparator): isolate cold image preparation",
          "body": "Fixes #132\n\n## Summary\n- add an unscored exact-digest image preparation phase before repetition 1\n- retain pull attempts, timings, registry logs, local image IDs, and repository digests in the bundle\n- retry transient pull failures with bounded 2s/5s delays and force all counted Compose starts to use `--pull never`\n- bind preparation evidence into bundle/run manifests and recompute its claims during offline verification\n- add a cold-host regression that injects the first transport failure before all 63 formal PostgreSQL steps\n\n## Verification\n- `pnpm run check`\n- `jq empty` on touched JSON contracts\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:27:35Z",
          "mergedAt": "2026-07-14T22:31:59Z",
          "additions": 715,
          "deletions": 14,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 136,
          "url": "https://github.com/kungfu-systems/build-images/pull/136",
          "title": "chore(alpha): promote comparator cold-image preparation",
          "body": "Promote the reviewed #132 fix from `dev/v1/v1.2` through the Buildchain v2 alpha channel.\n\n- source PR: #133\n- exact-digest preparation is unscored and retained\n- transient pulls are bounded before formal execution\n- all counted Compose starts use `--pull never`\n- cold-host regression completes all 63 formal steps\n\nBuildchain must publish the next alpha and a passing Release Passport.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:32:26Z",
          "mergedAt": "2026-07-14T22:36:04Z",
          "additions": 715,
          "deletions": 14,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 889,
          "url": "https://github.com/kungfu-systems/kungfu/pull/889",
          "title": "fix(docs): reject PR-only ADR commit evidence",
          "body": "## Summary\n\nReject ADR commit evidence that is reachable only through a pull request merge preview and would become unreachable after a rebase or squash merge.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- pin ADR evidence reachability to the pull request base SHA in the blocking documentation workflow\n- retain the existing local/merge-preview behavior outside the pull request gate\n- add regression coverage for branch-only evidence and workflow drift\n- document the stable PR-evidence path for in-review implementation work\n\n## Verification\n\n- `KUNGFU_ADR_EVIDENCE_BASE_SHA=$(git rev-parse origin/dev/v4/v4.0) ./shifu gate run docs.prose`\n- `./shifu check:source`\n- staged commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix strengthens validation of existing ADR evidence metadata without changing an architecture contract\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change is limited to validation of public ADR evidence metadata and fails closed against the immutable pull request base SHA. It does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:38:51Z",
          "mergedAt": "2026-07-14T22:40:31Z",
          "additions": 122,
          "deletions": 24,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1224,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1224",
          "title": "fix(release): seal exact publication version",
          "body": "## Summary\n- plan the exact release transaction version with the real promotion selector before sealing publication authority\n- bind that exact version to the capability verifier, publish-gate source lock, and final promotion action\n- fail closed if the planned capability version and transaction version drift\n\n## Validation\n- actionlint on changed workflows\n- 105 promote-buildchain-ref unit tests\n- 4 targeted build-surface workflow contract tests\n- buildchain inventory check\n- rebuilt promote-buildchain-ref dist with the repository tsup configuration\n- live read-only ref replay selects v2.12.7-alpha.3 for the pre-alpha.3 state\n\n## Release safety\n- no stable release was triggered\n- no repository/org variables, secrets, environments, or protection settings were changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:39:18Z",
          "mergedAt": "2026-07-14T22:44:28Z",
          "additions": 232,
          "deletions": 90,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 890,
          "url": "https://github.com/kungfu-systems/kungfu/pull/890",
          "title": "fix(gui): recover broken workspace runtimes",
          "body": "## Summary\n- surface the real packaged runtime startup error instead of masking every failure as a missing KFE_PATH\n- offer a guarded one-click backup/reset flow for missing, corrupt, or incompatible workspace journals\n- preserve the complete previous runtime under `.kungfu/backups/runtime-recovery` and relaunch with a fresh runtime\n\n## Verification\n- `./shifu check:source`\n- runtime/workspace Node tests: 7 passed\n- `./shifu dist:dir` (Mac arm64, Conan requirements 12/12 from cache)\n- packaged Electron qualification: binding loaded, `KF_GUI_QUALIFICATION_READY`\n- Shifu build: `20260714T224018Z-586470b49`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fixes packaged GUI runtime error projection and adds a guarded backup-reset recovery action without changing an architecture contract or widening supported claims\"\n}\n-->\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe recovery receipt and registered local Product build are provenance surfaces only; this change does not publish or deploy artifacts.\n\n## Checklist\n- [x] Commit is signed off (DCO)\n- [x] Existing architecture claims remain unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:41:03Z",
          "mergedAt": "2026-07-14T22:46:52Z",
          "additions": 282,
          "deletions": 6,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1228,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1228",
          "title": "feat(paper): publish declared artifacts to GitHub releases",
          "body": "## Summary\n\n- derive GitHub Release product assets from the generated publication manifest\n- fail before upload when a declared artifact is missing or collides by basename\n- keep paper consumers declarative and preserve existing passport/evidence assets\n- document and project the updated release surface\n\n## Verification\n\n- `pnpm run check`\n- 613 unit tests passed\n- action bundles and site contracts regenerated\n\nFixes #1225",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:57:55Z",
          "mergedAt": "2026-07-14T23:01:00Z",
          "additions": 148,
          "deletions": 66,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1229,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1229",
          "title": "chore(release): reconcile alpha ancestry into dev",
          "body": "Reconcile the existing `alpha/v2/v2.12` history into dev before the next direct dev-to-alpha promotion.\n\nThis is intentionally a history-only merge:\n\n- the resulting tree is byte-identical to current `dev/v2/v2.12` (`b009bfd0` tree `3a1ca508`);\n- it records `af7ab821` (`2.12.7-alpha.3`) as an ancestor;\n- it changes no Buildchain source, version file, workflow, generated bundle, or publication state;\n- it restores a conflict-free, policy-valid direct `dev/v2/v2.12 → alpha/v2/v2.12` PR path.\n\nNo package is published by this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:59:04Z",
          "mergedAt": "2026-07-14T23:03:51Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1230,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1230",
          "title": "release: promote sealed publication authority to alpha",
          "body": "Promote the protected v2.12 development source into the alpha channel after #1229 reconciled alpha ancestry.\n\nThis alpha qualifies the sealed publication authority fix from #1224. The publication workflow now plans the exact transaction version before admission, binds the capability and source-lock to that version, and rejects version drift before publication.\n\nExpected next prerelease: `2.12.7-alpha.4`.\n\nStable publication is not part of this PR and remains separately authorized.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:04:37Z",
          "mergedAt": "2026-07-14T23:06:34Z",
          "additions": 481,
          "deletions": 121,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 28,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/28",
          "title": "fix(release): publish paper PDFs with restored microtype",
          "body": "## Summary\n- pin the corrected Build Images LaTeX toolchain and restore microtype font expansion\n- move all Buildchain workflow callers to the audited v2-alpha contract\n- publish declared PDF artifacts alongside release-passport evidence on GitHub Releases\n- keep the publication manifest as the single source of truth for public PDF filenames\n\n## Verification\n- local Docker PDF builds completed for all three papers using the repaired toolchain source\n- no microtype or font-expansion warnings were present in the final LaTeX logs\n- repository checks and workflow linting passed\n- first-page render inspection found no clipping, overlap, or font corruption\n\nThe GitHub Release PDF projection is provided by Buildchain v2.12.7-alpha.4 (kungfu-systems/buildchain#1228).",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:16:58Z",
          "mergedAt": "2026-07-14T23:20:09Z",
          "additions": 64,
          "deletions": 14,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 24,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/24",
          "title": "fix(release): publish paper PDFs with restored microtype",
          "body": "## Summary\n- pin the corrected Build Images LaTeX toolchain and restore microtype font expansion\n- move all Buildchain workflow callers to the audited v2-alpha contract\n- publish declared PDF artifacts alongside release-passport evidence on GitHub Releases\n- keep the publication manifest as the single source of truth for public PDF filenames\n\n## Verification\n- local Docker PDF builds completed for all three papers using the repaired toolchain source\n- no microtype or font-expansion warnings were present in the final LaTeX logs\n- repository checks and workflow linting passed\n- first-page render inspection found no clipping, overlap, or font corruption\n\nThe GitHub Release PDF projection is provided by Buildchain v2.12.7-alpha.4 (kungfu-systems/buildchain#1228).",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:17:07Z",
          "mergedAt": "2026-07-14T23:20:23Z",
          "additions": 81,
          "deletions": 77,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 39,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/39",
          "title": "fix(release): publish paper PDFs with restored microtype",
          "body": "## Summary\n- pin the corrected Build Images LaTeX toolchain and restore microtype font expansion\n- move all Buildchain workflow callers to the audited v2-alpha contract\n- publish declared PDF artifacts alongside release-passport evidence on GitHub Releases\n- keep the publication manifest as the single source of truth for public PDF filenames\n\n## Verification\n- local Docker PDF builds completed for all three papers using the repaired toolchain source\n- no microtype or font-expansion warnings were present in the final LaTeX logs\n- repository checks and workflow linting passed\n- first-page render inspection found no clipping, overlap, or font corruption\n\nThe GitHub Release PDF projection is provided by Buildchain v2.12.7-alpha.4 (kungfu-systems/buildchain#1228).",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:17:16Z",
          "mergedAt": "2026-07-14T23:20:37Z",
          "additions": 13,
          "deletions": 13,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 29,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/29",
          "title": "release: publish restored-microtype paper alpha",
          "body": "Promote the audited paper release changes from dev to the alpha channel.\n\nThis alpha validates the corrected LaTeX toolchain, the accepted Buildchain v2-alpha contract, and declared PDF publication to GitHub Releases.\n\nStable publication is not part of this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:21:33Z",
          "mergedAt": "2026-07-14T23:23:59Z",
          "additions": 64,
          "deletions": 14,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 25,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/25",
          "title": "release: publish restored-microtype paper alpha",
          "body": "Promote the audited paper release changes from dev to the alpha channel.\n\nThis alpha validates the corrected LaTeX toolchain, the accepted Buildchain v2-alpha contract, and declared PDF publication to GitHub Releases.\n\nStable publication is not part of this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:21:37Z",
          "mergedAt": "2026-07-14T23:24:12Z",
          "additions": 81,
          "deletions": 77,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 40,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/40",
          "title": "release: publish restored-microtype paper alpha",
          "body": "Promote the audited paper release changes from dev to the alpha channel.\n\nThis alpha validates the corrected LaTeX toolchain, the accepted Buildchain v2-alpha contract, and declared PDF publication to GitHub Releases.\n\nStable publication is not part of this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:21:39Z",
          "mergedAt": "2026-07-14T23:24:23Z",
          "additions": 13,
          "deletions": 13,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 30,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/30",
          "title": "fix(release): remove legacy publication token",
          "body": "Remove the legacy long-lived promotion token from the Buildchain paper-release caller. Buildchain v2-alpha now uses sealed publication authority plus caller-bound OIDC trusted publishing and intentionally declares no BUILDCHAIN_PROMOTION_TOKEN secret.\n\nThis fixes the GitHub Actions reusable-workflow startup failure seen on the first alpha promotion attempt.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:26:21Z",
          "mergedAt": "2026-07-14T23:28:38Z",
          "additions": 0,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 26,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/26",
          "title": "fix(release): remove legacy publication token",
          "body": "Remove the legacy long-lived promotion token from the Buildchain paper-release caller. Buildchain v2-alpha now uses sealed publication authority plus caller-bound OIDC trusted publishing and intentionally declares no BUILDCHAIN_PROMOTION_TOKEN secret.\n\nThis fixes the GitHub Actions reusable-workflow startup failure seen on the first alpha promotion attempt.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:26:25Z",
          "mergedAt": "2026-07-14T23:28:50Z",
          "additions": 0,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1232,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1232",
          "title": "fix(controller): allow missing optional stages",
          "body": "## Summary\n\n- keep controller receipts fail-closed when required stages are missing\n- allow optional uninstantiated stages to remain non-blocking\n- add a web-surface regression proving a non-publishing canary can qualify\n- refresh generated site contract digests\n\n## Validation\n\n- pnpm run check\n- 614 unit tests passed\n- workflow checks passed\n- site bundle check passed\n- all four action bundles built",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:27:30Z",
          "mergedAt": "2026-07-14T23:29:13Z",
          "additions": 28,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 41,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/41",
          "title": "fix(release): remove legacy publication token",
          "body": "Remove the legacy long-lived promotion token from the Buildchain paper-release caller. Buildchain v2-alpha now uses sealed publication authority plus caller-bound OIDC trusted publishing and intentionally declares no BUILDCHAIN_PROMOTION_TOKEN secret.\n\nThis fixes the GitHub Actions reusable-workflow startup failure seen on the first alpha promotion attempt.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:26:28Z",
          "mergedAt": "2026-07-14T23:29:47Z",
          "additions": 0,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 892,
          "url": "https://github.com/kungfu-systems/kungfu/pull/892",
          "title": "docs(adr): close C++23 strategy implementation",
          "body": "## Summary\n\nClose ADR-0082 after all finite C++23 language-strategy increments have landed. The record now distinguishes implementation completion from ongoing template maintenance and records why deducing this is not adopted for `kungfu::data<T>`.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add the merged ranges commit and qualification references for the compiler, error-policy, concepts, registry, and journal-reader increments\n- define remaining SFINAE conversions as opportunistic maintenance rather than an ADR completion gate\n- record that replacing the reflection and pack-layout CRTP would be an invasive redesign without a measured defect or maintenance burden\n- add a measurable re-evaluation trigger for a future CRTP replacement\n\n## Verification\n\n- `./shifu docs:check`\n- pre-commit staged gate\n- ADR authority and release-contract audits included by the documentation gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0082\"],\n  \"summary\": \"Close the finite C++23 language-strategy increments and record the evidence-based decision to retain kungfu::data<T> CRTP\",\n  \"verification\": [\"./shifu docs:check\", \"pre-commit staged gate\", \"ADR authority and release-contract audits\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR updates ADR implementation and qualification evidence only; it does not change release execution or publishing.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:29:12Z",
          "mergedAt": "2026-07-14T23:31:33Z",
          "additions": 41,
          "deletions": 31,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1233,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1233",
          "title": "release: promote dev/v2/v2.12 to alpha",
          "body": "## Summary\n\nPromote the current protected development line to alpha after the controller receipt qualification fix merged in #1232.\n\n## Expected release\n\n- next alpha: 2.12.7-alpha.5\n- exact source SHA: 332375129559aa7340d6cbd9dcc997bca95242cd\n- stable is not requested by this PR",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:29:47Z",
          "mergedAt": "2026-07-14T23:32:05Z",
          "additions": 28,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 31,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/31",
          "title": "release: publish paper alpha through sealed OIDC",
          "body": "Promote the corrected Buildchain paper-release caller to alpha.\n\nThe legacy long-lived promotion token has been removed; publication now follows the reusable workflow sealed-authority and caller-bound OIDC contract. The previous alpha push failed before workflow expansion and published no package or tag.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:30:01Z",
          "mergedAt": "2026-07-14T23:32:41Z",
          "additions": 0,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 27,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/27",
          "title": "release: publish paper alpha through sealed OIDC",
          "body": "Promote the corrected Buildchain paper-release caller to alpha.\n\nThe legacy long-lived promotion token has been removed; publication now follows the reusable workflow sealed-authority and caller-bound OIDC contract. The previous alpha push failed before workflow expansion and published no package or tag.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:30:03Z",
          "mergedAt": "2026-07-14T23:32:46Z",
          "additions": 0,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 42,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/42",
          "title": "release: publish paper alpha through sealed OIDC",
          "body": "Promote the corrected Buildchain paper-release caller to alpha.\n\nThe legacy long-lived promotion token has been removed; publication now follows the reusable workflow sealed-authority and caller-bound OIDC contract. The previous alpha push failed before workflow expansion and published no package or tag.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:30:07Z",
          "mergedAt": "2026-07-14T23:32:50Z",
          "additions": 0,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1236,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1236",
          "title": "fix(paper): preserve authority action permissions",
          "body": "## Summary\n- grant `actions: read` to the nested paper publication authority\n- assert reusable-workflow permission monotonicity in the paper release contract test\n- refresh the generated Buildchain contract digest\n\n## Verification\n- `pnpm run check`\n- `git diff --check`\n\nCloses #1235\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:38:27Z",
          "mergedAt": "2026-07-14T23:44:32Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1237,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1237",
          "title": "release: promote paper authority permission fix to alpha",
          "body": "## Summary\nPromote the paper reusable-workflow permission fix from `dev/v2/v2.12` to the alpha channel.\n\n## Evidence\n- Buildchain PR #1236\n- full local `pnpm run check` passed\n- GitHub Verify and Build Surface Fixture passed\n\n## Expected publication\nThe managed release flow should prepare and publish the next `2.12.7-alpha` version, advancing `v2-alpha` and `v2.12-alpha`.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:45:24Z",
          "mergedAt": "2026-07-14T23:47:27Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 138,
          "url": "https://github.com/kungfu-systems/build-images/pull/138",
          "title": "fix(comparator): preserve retried preparation evidence",
          "body": "## Summary\n- preserve image and attempt indices in pull and inspect log paths\n- run actual retry preparation output through the offline bundle verifier and reject failed-log tampering\n- update Buildchain alpha/stable contract locks with separate exact package worlds and regenerate KFD evidence\n\n## Verification\n- `pnpm run check`\n- Buildchain `v2.12.7-alpha.4` and `v2.12.6` Release Passports: `trust: pass`, no issues\n\nCloses #137\nCloses #134\nCloses #135",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:40:08Z",
          "mergedAt": "2026-07-14T23:48:07Z",
          "additions": 214,
          "deletions": 124,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 140,
          "url": "https://github.com/kungfu-systems/build-images/pull/140",
          "title": "chore(release): promote v1.2 fixes to alpha",
          "body": "## Summary\n- publish the #137 comparator retry-evidence fix\n- publish refreshed Buildchain v2 alpha/stable contract locks and KFD evidence\n- retain selective image publishing; this change does not modify Dockerfiles\n\n## Verification\n- PR #138 checks passed\n- local `pnpm run check` passed\n- Buildchain alpha/stable Release Passports verified\n\nRelease Passport and GitHub Release remain required by Buildchain promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:48:40Z",
          "mergedAt": "2026-07-14T23:51:22Z",
          "additions": 214,
          "deletions": 124,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 896,
          "url": "https://github.com/kungfu-systems/kungfu/pull/896",
          "title": "refactor(core): express data member constraints as concepts",
          "body": "## Summary\n\nDeliver the next bounded ADR-0082 concepts maintenance increment by replacing five function-level SFINAE constraints in `data<T>` with named concepts and `requires` clauses. Runtime behavior and overload partitions remain unchanged.\n\n## Related issue\n\nADR-0082 concepts policy, item 3 incremental maintenance.\n\n## Changes\n\n- Add named concepts for numeric initialization and the three mutually exclusive JSON member-decoding partitions.\n- Convert the two `init_member` overloads and three `restore_from_json` overloads from `enable_if_t<..., void>` to explicit `void` plus `requires`.\n- Keep every function body unchanged.\n- Audit the remaining 37 code-level `enable_if` sites: retain 14 partial-specialization sites because concepts do not remove their specialization-selection role; retain the four `hana_sqlite.h::make_default` SQLite seam overloads for separately scoped validation; leave 14 other Kungfu-owned function constraints for later benefit-ordered batches.\n- Preserve the implemented ADR-0082 closure from PR #892 while recording this later maintenance batch.\n\nRepresentative diagnostic probe:\n\n- Before: the candidate is ignored because the raw predicate requirement is not satisfied.\n- After: the compiler reports `constraints not satisfied`, names `data_json_direct_member`, and shows the exact predicate that evaluated to false.\n\n## Verification\n\n- `./shifu check:source`: passed (281 tooling tests, 13 runtime-upgrade tests, C++ format and source contracts).\n- Staged pre-commit gate and `./shifu docs:check`: passed.\n- AppleClang C++23 `-fsyntax-only` through a sibling compile database: 69 current translation units passed; one stale database entry for removed `webserver.cpp` was excluded explicitly.\n- Negative diagnostic probes: both failed as intended; the concepts version exposed the named constraint chain.\n- Mac AppleClang: `./shifu build:core` plus durability-contract, durable-ingest, crash-recovery, state-service, and projection-bootstrap passed on tree-identical validated head `1bb66940d` and current clean head `e331aa4eb`.\n- Linux GCC 14.2 on agent-120: the same build and five-test matrix passed on tree-identical validated head `1bb66940d` and current clean head `e331aa4eb`.\n- Windows MSVC 19.51 on DARKHERO: `./shifu build:core` passed on tree-identical validated head `1bb66940d` and current clean head `e331aa4eb`; durability-contract, durable-ingest, crash-recovery, and projection-bootstrap passed. The state-service test reached the native binary but its temporary journal stretch returned Win32 error 112 twice despite 1.4 TiB free; Mac/Linux coverage of that test passed.\n- GitHub delivery intent, docs, source acceptance, promotion rehearsal, signoff, and validate checks: passed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0082\"],\n  \"summary\": \"Migrate the data member initialization and JSON decode overload partition from SFINAE to named concepts without changing behavior\",\n  \"verification\": [\"Source acceptance passed\", \"AppleClang syntax-only passed for 69 current translation units\", \"Mac and Linux native build plus behavior matrix passed\", \"Windows MSVC native build passed\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated; no runtime behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:54:58Z",
          "mergedAt": "2026-07-14T23:56:56Z",
          "additions": 38,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 32,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/32",
          "title": "chore(release): accept Buildchain alpha.6 contract",
          "body": "## Summary\n- accept Buildchain `v2.12.7-alpha.6` at `63190f90f71fee292212d41d87149e511f5408f2`\n- preserve the unchanged major compatibility digest\n- enable the repaired paper release controller that publishes declared PDFs to GitHub Release\n\n## Verification\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- `git diff --check`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:55:58Z",
          "mergedAt": "2026-07-14T23:58:29Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 28,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/28",
          "title": "chore(release): accept Buildchain alpha.6 contract",
          "body": "## Summary\n- accept Buildchain `v2.12.7-alpha.6` at `63190f90f71fee292212d41d87149e511f5408f2`\n- preserve the unchanged major compatibility digest\n- enable the repaired paper release controller that publishes declared PDFs to GitHub Release\n\n## Verification\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- `git diff --check`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:56:06Z",
          "mergedAt": "2026-07-14T23:58:37Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 43,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/43",
          "title": "chore(release): accept Buildchain alpha.6 contract",
          "body": "## Summary\n- accept Buildchain `v2.12.7-alpha.6` at `63190f90f71fee292212d41d87149e511f5408f2`\n- preserve the unchanged major compatibility digest\n- enable the repaired paper release controller that publishes declared PDFs to GitHub Release\n\n## Verification\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- `git diff --check`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:56:14Z",
          "mergedAt": "2026-07-14T23:58:43Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 34,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/34",
          "title": "release: publish next KFD foundation alpha",
          "body": "Promote the Buildchain alpha.6 paper release path, restored microtype expansion, and declared GitHub Release PDF asset to the next alpha.\n\nReplaces #33 to preserve author/reviewer identity separation.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:02:30Z",
          "mergedAt": "2026-07-15T00:04:55Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 30,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/30",
          "title": "release: publish next Kungfu white paper alpha",
          "body": "Promote the Buildchain alpha.6 paper release path and declared GitHub Release PDF asset to the next alpha.\n\nReplaces #29 to preserve author/reviewer identity separation.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:02:43Z",
          "mergedAt": "2026-07-15T00:05:00Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 45,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/45",
          "title": "release: publish next Observer alpha",
          "body": "Promote the Buildchain alpha.6 paper release path, restored microtype expansion, and declared GitHub Release PDF asset to the next alpha.\n\nReplaces #44 to preserve author/reviewer identity separation.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:02:51Z",
          "mergedAt": "2026-07-15T00:05:05Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 35,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/35",
          "title": "fix(release): grant paper authority evidence access",
          "body": "## Summary\nGrant `actions: read` at the consumer caller boundary so the nested Buildchain publication authority can read exact release evidence without violating reusable-workflow permission monotonicity.\n\n## Verification\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- `git diff --check`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:07:13Z",
          "mergedAt": "2026-07-15T00:09:44Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 897,
          "url": "https://github.com/kungfu-systems/kungfu/pull/897",
          "title": "fix(core): prefer native Cargo shim on Windows",
          "body": "## Summary\n\nMake libwasm CMake discovery prefer the Windows-native Cargo shims exposed by the Shifu cache overlay. This prevents CMake from caching the POSIX shebang wrapper as `KF_LIBWASM_CARGO` on Windows.\n\n## Related issue\n\nNone. Found while qualifying the zero-burden desktop runtime through the full Buildchain matrix.\n\n## Changes\n\n- Prefer `cargo.cmd`, then `cargo.exe`, before the extensionless wrapper on Windows.\n- Drop stale cached Cargo paths in the shared-membrane slice before resolving the current overlay.\n- Preserve the existing POSIX lookup unchanged.\n\n## Verification\n\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check`\n- staged pre-commit gate\n- Windows Buildchain qualification will provide the platform-native regression proof.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fixes platform-native executable discovery without changing the libwasm or cache architecture contracts\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not needed; executable discovery only)",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:06:59Z",
          "mergedAt": "2026-07-15T00:09:48Z",
          "additions": 15,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 31,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/31",
          "title": "fix(release): grant paper authority evidence access",
          "body": "## Summary\nGrant `actions: read` at the consumer caller boundary so the nested Buildchain publication authority can read exact release evidence without violating reusable-workflow permission monotonicity.\n\n## Verification\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- `git diff --check`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:07:16Z",
          "mergedAt": "2026-07-15T00:09:50Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 46,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/46",
          "title": "fix(release): grant paper authority evidence access",
          "body": "## Summary\nGrant `actions: read` at the consumer caller boundary so the nested Buildchain publication authority can read exact release evidence without violating reusable-workflow permission monotonicity.\n\n## Verification\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- `git diff --check`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:07:19Z",
          "mergedAt": "2026-07-15T00:09:56Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 36,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/36",
          "title": "release: publish next KFD foundation alpha",
          "body": "Promote consumer-level publication authority evidence access to complete the Buildchain alpha.6 paper release path.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:10:13Z",
          "mergedAt": "2026-07-15T00:12:35Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 32,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/32",
          "title": "release: publish next Kungfu white paper alpha",
          "body": "Promote consumer-level publication authority evidence access to complete the Buildchain alpha.6 paper release path.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:10:17Z",
          "mergedAt": "2026-07-15T00:12:40Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 47,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/47",
          "title": "release: publish next Observer alpha",
          "body": "Promote consumer-level publication authority evidence access to complete the Buildchain alpha.6 paper release path.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:10:20Z",
          "mergedAt": "2026-07-15T00:12:46Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 143,
          "url": "https://github.com/kungfu-systems/build-images/pull/143",
          "title": "chore(buildchain): accept alpha.6 contract",
          "body": "## Summary\n- upgrade the exact alpha Buildchain package from 2.12.7-alpha.4 to 2.12.7-alpha.6\n- accept the current v2-alpha contract SHA and digest\n- regenerate KFD-2 upstream evidence and KFD123 summary\n- keep the stable channel pinned to Buildchain 2.12.6\n\n## Verification\n- pnpm install --frozen-lockfile\n- pnpm run check\n- Buildchain v2.12.7-alpha.6 Release Passport: trust pass, issues empty\n- current v2-alpha SHA equals accepted lock SHA 63190f90f71fee292212d41d87149e511f5408f2\n\nCloses #134\nCloses #135\nCloses #139\nCloses #141\nCloses #142",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:11:20Z",
          "mergedAt": "2026-07-15T00:14:43Z",
          "additions": 19,
          "deletions": 19,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 144,
          "url": "https://github.com/kungfu-systems/build-images/pull/144",
          "title": "release(alpha): accept Buildchain alpha.6 contract",
          "body": "## Summary\n- promote the Buildchain 2.12.7-alpha.6 consumer lock to alpha\n- publish refreshed KFD evidence and Release Passport\n- reuse existing image artifacts because no Dockerfile or image manifest changed\n\n## Verification\n- feature PR #143 checks passed\n- local pnpm run check passed\n- upstream Buildchain Release Passport verifies with trust pass and no issues",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:15:20Z",
          "mergedAt": "2026-07-15T00:18:05Z",
          "additions": 19,
          "deletions": 19,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 901,
          "url": "https://github.com/kungfu-systems/kungfu/pull/901",
          "title": "fix(gui): make structured console input discoverable",
          "body": "## Summary\n\nMake the structured Agent Console clearly distinguish read-only session output from the user instruction composer.\n\n## Related issue\n\nUser-reported discoverability friction in the structured Codex console.\n\n## Changes\n\n- label the session output boundary as read-only\n- add a prominent state-aware instruction composer and primary Send action\n- support Enter to send, Shift+Enter for a newline, and preserve drafts until delivery\n- hide raw PTY key controls when the session uses the structured transport\n\n## Verification\n\n- `./shifu --filter @kungfu-tech/kfx-view-terminal test`\n- `./shifu check`\n- source-local SDK KFX bundle build\n- headless browser visual inspection of the ready-state layout\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix improves existing console affordances without changing an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change presents existing provider session state and does not alter provider API or CLI behavior.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not required for this bounded UI fix)",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:32:24Z",
          "mergedAt": "2026-07-15T00:34:48Z",
          "additions": 417,
          "deletions": 51,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 146,
          "url": "https://github.com/kungfu-systems/build-images/pull/146",
          "title": "fix(images): reuse trusted empty release deltas",
          "body": "## Summary\n- accept verified v1.2.4-alpha.6 image evidence as the reviewed reuse baseline\n- distinguish a Git-proven empty delta from absent changed-path input\n- reuse all five images only when the accepted lock ancestry is valid\n- retain fail-closed full builds for unproven empty input and invalid baselines\n- document the trusted empty-delta rule and regenerate KFD evidence\n\n## Verification\n- pnpm run check\n- 36 comparator qualification tests passed\n- provenance fixture proves trusted empty delta reuses all five images\n- real planner at the accepted baseline reports selective mode, zero selected, five reused\n- explicit unproven empty input remains a full rebuild\n\nCloses #145",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:36:25Z",
          "mergedAt": "2026-07-15T00:39:05Z",
          "additions": 182,
          "deletions": 127,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 899,
          "url": "https://github.com/kungfu-systems/kungfu/pull/899",
          "title": "feat(profile): extract Mission Control domain",
          "body": "## Summary\n\nMove active Mission/Go actions, assessment, query, Atlas admission, and bundle semantics into the exact-root Mission Control Suite member. Keep Core Atlas as a source adapter and compatibility surface, and route `kungfu atlas` through public Profile reads/intents.\n\n## Verification\n\n- `./shifu build`\n- Profile SDK/composition/Mission Control tests: 54 passed\n- Mission Control/Atlas targeted storage tests\n- `./shifu test:kfx-profile-suite`\n- staged Ruff, Biome, docs, authority, and contract gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Mission Control active domain semantics are owned and exact-root bound by the Profile Suite; Core retains only public Profile compatibility and source adapter boundaries.\",\n  \"verification\": [\"Mission Control Profile and storage tests\", \"KFX Profile Suite qualification\", \"staged source boundary gates\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:18:21Z",
          "mergedAt": "2026-07-15T00:40:55Z",
          "additions": 2787,
          "deletions": 2545,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 147,
          "url": "https://github.com/kungfu-systems/build-images/pull/147",
          "title": "release(alpha): fix trusted empty-delta reuse",
          "body": "## Summary\n- promote the reviewed v1.2.4-alpha.6 image baseline\n- fix trusted empty release deltas to reuse the complete image family\n- retain fail-closed behavior for unproven empty or invalid baselines\n- publish the required full-build alpha after changing publisher logic\n\n## Verification\n- feature PR #146 checks passed\n- local full check passed\n- real planner proves 5 reused at the accepted baseline",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:39:57Z",
          "mergedAt": "2026-07-15T00:42:25Z",
          "additions": 182,
          "deletions": 127,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 902,
          "url": "https://github.com/kungfu-systems/kungfu/pull/902",
          "title": "feat(kfx): compose system views by product role",
          "body": "## Summary\n\n- add schema-governed KFX product roles and carry them through the host-neutral load plan\n- generate Activity Rail, View, Tools, and Developer menu entries from declarations\n- resolve Console startup, recovery Manager, and status targets by role instead of concrete KFX ids\n- keep boot-critical availability separate from source authority and capability grants\n\n## Verification\n\n- ./shifu test:kfx-profile-suite (KFX contract/plan 15 passed; initial navigation compatibility assertions corrected and rerun)\n- ./shifu --filter @kungfu-tech/tui exec tsx --test <navigation.test.ts> (10 passed)\n- ./shifu --filter @kungfu-tech/kfx build\n- ./shifu build:app\n- ./shifu check:source (281 Node tests and 13 runtime-upgrade tests passed)\n- staged pre-commit gate passed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Declare KFX product roles and project System navigation and menus without concrete Shell ids.\",\n  \"verification\": [\n    \"KFX contract and plan fixtures\",\n    \"GUI navigation replacement and boot-critical fixtures\",\n    \"GUI production build\",\n    \"source acceptance gate\"\n  ]\n}\n-->\n\n## Governance\n\n- [x] DCO sign-off present\n- [x] ADR-0083 and versioning projection updated\n- [x] No trust or capability elevation from product roles\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:39:49Z",
          "mergedAt": "2026-07-15T00:45:15Z",
          "additions": 448,
          "deletions": 58,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 903,
          "url": "https://github.com/kungfu-systems/kungfu/pull/903",
          "title": "docs(adr): define core-native KFX runtime authority",
          "body": "## Summary\n\nRecord the Core-native multi-surface KFX runtime decision hierarchy. Define package and lifecycle authority, KFD and Buildchain admission, and surface-neutral contributions while distinguishing the existing partial baseline from the remaining implementation.\n\n## Changes\n\n- Add ADR-0088 as the umbrella architecture for one Core-native KFX authority across GUI, TUI, CLI, and Agent surfaces.\n- Add ADR-0089 for immutable packages and transactional lifecycle state.\n- Add ADR-0090 for KFD-aware trust grades and exact Buildchain artifact admission.\n- Add ADR-0091 for surface-neutral semantic contributions and thin Node/Python bindings.\n- Update the ADR index.\n\n## Verification\n\n- `./shifu docs:check`\n- `./shifu adr:audit -- --json`\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0088\", \"ADR-0089\", \"ADR-0090\", \"ADR-0091\"],\n  \"summary\": \"Accept the layered Core-native KFX runtime architecture, retain exact evidence for the existing partial baseline, and make no claim that the remaining implementation is complete.\",\n  \"verification\": [\"Documentation gate\", \"ADR authority audit\", \"staged source gates\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, secrets, or authentication material\n- [ ] generated artifacts or release binaries\n- [x] release evidence, provenance, or supply-chain policy\n- [ ] externally visible API or compatibility promise\n- [ ] none of the above\n\nADR-0090 defines the future admission design. This PR does not alter runtime trust decisions or release evidence.\n\n## Checklist\n\n- [x] DCO signoff is present.\n- [x] Documentation and ADR authority checks pass locally.\n- [x] The declaration intentionally claims `stage-ready` for an evidence-backed partial baseline, not completed implementation.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:44:20Z",
          "mergedAt": "2026-07-15T00:48:51Z",
          "additions": 653,
          "deletions": 0,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1241,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1241",
          "title": "feat(paper): seal publication candidates before release",
          "body": "## Summary\n\n- add a reusable three-stage sealed paper release workflow\n- bind source, tree, Buildchain runtime, controller receipt, PDF bytes, and npm package bytes before publication\n- keep the final write/OIDC job isolated from consumer build commands\n\n## Verification\n\n- `pnpm run check`\n- `actionlint .github/workflows/.publication-authority.yml .github/workflows/publication-artifact.yml .github/workflows/paper-release-sealed.yml`\n- candidate substitution rejection tests\n\nCloses #1240\nRelates to #1225, #1235, and #1239.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:53:00Z",
          "mergedAt": "2026-07-15T00:55:11Z",
          "additions": 1584,
          "deletions": 100,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 148,
          "url": "https://github.com/kungfu-systems/build-images/pull/148",
          "title": "chore(images): accept alpha.7 canary baseline",
          "body": "## Summary\n- accept the verified v1.2.4-alpha.7 full-build evidence\n- bind the reviewed image lock into KFD evidence\n- establish the post-planner-change baseline for the pure reuse canary\n\n## Verification\n- v1.2.4-alpha.7 Release Passport: trust pass, issues empty\n- pnpm run check\n- real planner reports selective mode, zero selected images, and five reused images",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:53:16Z",
          "mergedAt": "2026-07-15T00:55:51Z",
          "additions": 74,
          "deletions": 74,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1242,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1242",
          "title": "release: promote sealed paper publication to alpha",
          "body": "## Summary\n\nPromote the sealed paper publication candidate workflow from `dev/v2/v2.12` to the alpha channel.\n\n## Evidence\n\n- Buildchain PR #1241\n- `pnpm run check` passed\n- Verify and Build Surface Fixture passed\n\n## Expected publication\n\nPublish the next `2.12.7-alpha` version and advance `v2-alpha` / `v2.12-alpha` to the admitted runtime used by the three paper repositories.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:56:00Z",
          "mergedAt": "2026-07-15T00:58:13Z",
          "additions": 1584,
          "deletions": 100,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 150,
          "url": "https://github.com/kungfu-systems/build-images/pull/150",
          "title": "fix(images): ignore generated KFD publish deltas",
          "body": "## Summary\n- treat generated `.buildchain/kfd/` evidence as image-neutral after a reviewed image-lock acceptance\n- preserve fail-closed handling for other Buildchain metadata\n- cover shallow-history KFD-only and subsequent Dockerfile deltas\n\n## Verification\n- `python3 scripts/test-publish-provenance.py`\n- `pnpm run check`\n- real planner against the accepted `v1.2.4-alpha.7` lock: 5 reused, 0 built\n\nCloses #145",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:59:27Z",
          "mergedAt": "2026-07-15T01:03:22Z",
          "additions": 84,
          "deletions": 67,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 151,
          "url": "https://github.com/kungfu-systems/build-images/pull/151",
          "title": "release: promote selective KFD delta fix to alpha",
          "body": "Promote the KFD-neutral selective publish fix through the Buildchain v2 dual-channel release flow.\n\nExpected first release behavior: fail-closed full rebuild because publisher code changed. The following accepted-baseline canary must reuse all five image digests.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:03:54Z",
          "mergedAt": "2026-07-15T01:06:24Z",
          "additions": 147,
          "deletions": 130,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 895,
          "url": "https://github.com/kungfu-systems/kungfu/pull/895",
          "title": "feat(product): add versioned runtime upgrades",
          "body": "## Summary\n\nEstablish a shared, versioned product-upgrade protocol for Desktop and the standalone CLI while keeping runtime activation authority in Core. The delivery includes immutable runtime inventory, compatibility planning, safe activation and rollback, explicit user messaging, public upgrade documentation, Electron transport, CLI distribution boundaries, and fail-closed release qualification.\n\nNative platform claims intentionally remain promotion-ineligible until retained signed/notarized and native install campaigns exist.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add the Core runtime upgrade state machine, immutable image inventory, generation pinning, reconciliation, rollback, and reference-aware GC;\n- add the standalone CLI check/download/apply surfaces with strict target, digest, size, archive, concurrency, downgrade, and publication admission boundaries;\n- add the production Electron updater provider while requiring Core plans before download, install handoff, or runtime activation;\n- add one shared release identity, message registry, public guide/reference pages, and product deep links;\n- bind Buildchain publication to retained upgrade evidence and exact runtime/Desktop/CLI artifact identity;\n- add native qualification entry points for Developer ID/notarization, Authenticode, and AppImage evidence, while preserving explicit platform blockers;\n- preserve an explicit macOS certificate hash when multiple keychains contain the same Developer ID subject.\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu test:upgrade-qualification` (19 passed)\n- `./shifu test:desktop-update` (63 passed)\n- `./shifu check:types`\n- staged pre-commit gates, documentation contracts, and ADR audit\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0087\"],\n  \"summary\": \"Deliver the bounded versioned product-upgrade control plane, Desktop and CLI adapters, user contract, and fail-closed native release gate\",\n  \"verification\": [\"./shifu check:source\", \"./shifu test:upgrade-qualification\", \"./shifu test:desktop-update\", \"./shifu check:types\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release boundary is fail-closed: publication requires exact artifact identity and retained qualification/signature references. Native platform claims remain disabled until their real campaigns are retained.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:45:53Z",
          "mergedAt": "2026-07-15T01:09:57Z",
          "additions": 9719,
          "deletions": 72,
          "changedFiles": 79
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 37,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/37",
          "title": "ci(release): adopt sealed paper publication",
          "body": "## Summary\n\n- consume Buildchain v2.12.7-alpha.7 through the accepted v2-alpha contract lock\n- replace the legacy paper release caller with the sealed publication preset\n- declare the exact PDF GitHub Release asset and trusted publisher workflow\n\n## Verification\n\n- repository check passed\n- actionlint passed\n- Buildchain contract lock: unchanged, compatible, no drift\n\nExpected release asset: `kfd-foundation-model.pdf`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:09:52Z",
          "mergedAt": "2026-07-15T01:12:54Z",
          "additions": 7,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 48,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/48",
          "title": "ci(release): adopt sealed paper publication",
          "body": "## Summary\n\n- consume Buildchain v2.12.7-alpha.7 through the accepted v2-alpha contract lock\n- replace the legacy paper release caller with the sealed publication preset\n- declare the exact PDF GitHub Release asset and trusted publisher workflow\n\n## Verification\n\n- repository check passed\n- actionlint passed\n- Buildchain contract lock: unchanged, compatible, no drift\n\nExpected release asset: `observer-declared-timelines.pdf`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:09:50Z",
          "mergedAt": "2026-07-15T01:12:54Z",
          "additions": 7,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 33,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/33",
          "title": "ci(release): adopt sealed paper publication",
          "body": "## Summary\n\n- consume Buildchain v2.12.7-alpha.7 through the accepted v2-alpha contract lock\n- replace the legacy paper release caller with the sealed publication preset\n- declare the exact PDF GitHub Release asset and trusted publisher workflow\n\n## Verification\n\n- repository check passed\n- actionlint passed\n- Buildchain contract lock: unchanged, compatible, no drift\n\nExpected release asset: `kungfu-real-world-agent-work.pdf`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:10:40Z",
          "mergedAt": "2026-07-15T01:13:48Z",
          "additions": 7,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 38,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/38",
          "title": "release: publish sealed paper alpha",
          "body": "## Summary\n\nPromote the Buildchain v2.12.7-alpha.7 sealed paper release integration to the alpha channel.\n\n## Expected publication\n\n- publish the next npm alpha\n- create the matching GitHub prerelease\n- attach the declared PDF under its human-readable filename\n- retain the sealed publication capability and release passport evidence\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:14:44Z",
          "mergedAt": "2026-07-15T01:17:41Z",
          "additions": 7,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 34,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/34",
          "title": "release: publish sealed paper alpha",
          "body": "## Summary\n\nPromote the Buildchain v2.12.7-alpha.7 sealed paper release integration to the alpha channel.\n\n## Expected publication\n\n- publish the next npm alpha\n- create the matching GitHub prerelease\n- attach the declared PDF under its human-readable filename\n- retain the sealed publication capability and release passport evidence\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:14:47Z",
          "mergedAt": "2026-07-15T01:17:41Z",
          "additions": 7,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 49,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/49",
          "title": "release: publish sealed paper alpha",
          "body": "## Summary\n\nPromote the Buildchain v2.12.7-alpha.7 sealed paper release integration to the alpha channel.\n\n## Expected publication\n\n- publish the next npm alpha\n- create the matching GitHub prerelease\n- attach the declared PDF under its human-readable filename\n- retain the sealed publication capability and release passport evidence\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:14:47Z",
          "mergedAt": "2026-07-15T01:18:19Z",
          "additions": 7,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 904,
          "url": "https://github.com/kungfu-systems/kungfu/pull/904",
          "title": "feat(core): read the generic decode primitive identically on every membrane",
          "body": "## Summary\n\nADR-0078 exposed one generic frame-decode primitive on three membranes — pybind, the\nembedding C ABI, and the Rust wrapper — so that any language could read a `.kungfu`\nframe without re-implementing FlatBuffers reflection. The three did not agree. The\nde-dup gave the pybind primitive the integer enum form the reflection decoders use,\nwhile the C ABI and its Rust mirror still emitted enum identifiers, so the same frame\nread differently depending on which membrane you came through. This closes that gap,\nthe last open item on ADR-0078.\n\n## Related issue\n\nADR-0078 Follow-up (\"Remaining follow-up: cross-membrane enum representation\nsymmetry\"). Continues #772 (exposure) and #802 (de-dup).\n\n## Changes\n\n- **Integer enums on the C ABI.** `decode_frame_json` decodes enums to their integer\n  form, matching the pybind primitive and the three reflection decoders.\n- **The `object_name` table selector on the C ABI.** This half was not named in the\n  ADR's follow-up, but it belongs to the same symmetry. The primitive's own\n  motivating consumer decodes a bundle whose event tables are **not** the `.bfbs`\n  root (`rewind` passes the action-type table name), so without a selector the ring\n  closure ADR-0078 promises for \"Rust and cross-process consumers, not only Python\n  and in-tree C++\" did not hold for the case that motivated it. `NULL`/empty keeps\n  the root_type behaviour existing single-root callers rely on.\n- **Rust mirror.** `Context::decode_frame_json` takes `object_name: Option<&str>`\n  and forwards it; it wraps the C ABI rather than reimplementing decode, so the\n  contract keeps one implementation. The `kf_embedding_api_v3` table layout is\n  unchanged (`ApiV3 == 104` still holds).\n- **A contract test where there was none.** This membrane path previously had no\n  runtime coverage: the slice host only checks v3 negotiation and non-null pointers,\n  and the Rust tests never touch a live core. `kungfu_embedding_generic_codec_tests`\n  decodes through the C ABI and compares against `schema_handle::decode_json` — both\n  the integer form it must produce and the identifier form it must not — plus the\n  non-root selector, fail-closed on an unknown table, and the argument guard. It\n  asserts the two enum forms actually differ before comparing, so it cannot pass\n  against a fixture that does not discriminate. Wired into the existing\n  embedding-membrane qualification gate rather than a new gate.\n\nABI v3 has not reached a release channel (`v4.0.0-alpha.0` predates it) and there are\nno consumers outside this repository, so the signature is widened in place rather than\nversioned around.\n\n## Verification\n\n- macOS arm64 full core build; `kungfu_embedding_generic_codec_tests` green — and\n  red when the integer-enum argument is reverted, so the test is proven to\n  discriminate rather than pass vacuously.\n- 11/11 native ctest (the 10 existing plus the new one).\n- `cargo test`/`clippy`/`fmt` for `kungfu-embedding`, plus a workspace check.\n- `adr-audit` (`result=pass`, structural=0) and the deterministic docs gate.\n- Linux and Windows evidence comes from the qualification gate rather than a local\n  run, so ADR-0078 moves to `staged`, not `implemented`.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0078\"],\n  \"summary\": \"Make the generic decode primitive read identically on all three membranes: integer enums plus the object_name table selector on the C ABI and its Rust mirror, closing the last ADR-0078 follow-up\",\n  \"verification\": [\"macOS arm64 full core build\", \"kungfu_embedding_generic_codec_tests (green on the change, red when the integer-enum argument is reverted)\", \"11/11 native ctest\", \"cargo test/clippy/fmt plus workspace check\", \"adr-audit and docs gate\"]\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:03:11Z",
          "mergedAt": "2026-07-15T01:21:08Z",
          "additions": 346,
          "deletions": 21,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 153,
          "url": "https://github.com/kungfu-systems/build-images/pull/153",
          "title": "chore(images): accept v1.2.4-alpha.8 digests",
          "body": "Accept the reviewed alpha.8 publish evidence as the selective-publish baseline.\n\n- Release Passport: trust pass, no issues\n- alpha.8 evidence: 5 built (expected fail-closed planner change)\n- lock acceptance and generated KFD evidence are committed atomically\n- post-acceptance real planner: 5 reused, 0 built\n\nFollow-up: promote a pure canary and prove the published release evidence also records 5 reused.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:20:42Z",
          "mergedAt": "2026-07-15T01:23:31Z",
          "additions": 74,
          "deletions": 74,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1245,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1245",
          "title": "fix(paper): bind required check into authority",
          "body": "## Summary\n\n- carry the exact declared protected-branch check context into sealed publication authority\n- bind provider transaction evidence to that exact context and GitHub App id\n- reject a mismatched check even when another check passed\n\n## Evidence\n\n- all three paper alpha runs reached read-only candidate completion and failed closed at the same branch-policy audit\n- `pnpm run check`: 617 tests passed\n- Actionlint and generated site contract checks passed\n\nCloses #1244\nRelates to #1240.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:24:27Z",
          "mergedAt": "2026-07-15T01:26:21Z",
          "additions": 43,
          "deletions": 13,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 154,
          "url": "https://github.com/kungfu-systems/build-images/pull/154",
          "title": "release: publish selective reuse canary",
          "body": "Promote the reviewed alpha.8 image-lock baseline as a pure selective-publish canary.\n\nPre-promotion planner evidence:\n- mode: selective\n- selected images: 0\n- reused images: 5\n\nAcceptance criterion: the resulting alpha release passport must pass and durable publish evidence must record all five image artifacts as reused with unchanged digests.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:23:53Z",
          "mergedAt": "2026-07-15T01:28:47Z",
          "additions": 74,
          "deletions": 74,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1246,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1246",
          "title": "release: promote exact paper branch audit to alpha",
          "body": "## Summary\n\nPromote the exact required-status-check authority fix to the alpha channel.\n\n## Evidence\n\n- Buildchain PR #1245\n- all 617 unit tests passed\n- three paper dogfood runs proved the previous hard-coded check failed closed before publication\n\n## Expected publication\n\nPublish the next `2.12.7-alpha` runtime so the three paper releases can rerun against the corrected authority.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:26:46Z",
          "mergedAt": "2026-07-15T01:29:12Z",
          "additions": 43,
          "deletions": 13,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 39,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/39",
          "title": "chore(buildchain): accept alpha.8 contract",
          "body": "## Summary\\n\\nAccept Buildchain v2.12.7-alpha.8 after the exact required-status-check authority fix.\\n\\n## Verification\\n\\n- repository check passed\\n- contract lock resolves exact SHA e6c3b27db0552bb0ca075ced4fe1dea621ef06cf\\n- contract status unchanged, compatible, no drift\\n\\nThis unlocks a fresh sealed alpha publication after the prior release correctly failed closed.\\n\\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:36:45Z",
          "mergedAt": "2026-07-15T01:39:26Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 35,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/35",
          "title": "chore(buildchain): accept alpha.8 contract",
          "body": "## Summary\\n\\nAccept Buildchain v2.12.7-alpha.8 after the exact required-status-check authority fix.\\n\\n## Verification\\n\\n- repository check passed\\n- contract lock resolves exact SHA e6c3b27db0552bb0ca075ced4fe1dea621ef06cf\\n- contract status unchanged, compatible, no drift\\n\\nThis unlocks a fresh sealed alpha publication after the prior release correctly failed closed.\\n\\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:36:45Z",
          "mergedAt": "2026-07-15T01:39:32Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 50,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/50",
          "title": "chore(buildchain): accept alpha.8 contract",
          "body": "## Summary\\n\\nAccept Buildchain v2.12.7-alpha.8 after the exact required-status-check authority fix.\\n\\n## Verification\\n\\n- repository check passed\\n- contract lock resolves exact SHA e6c3b27db0552bb0ca075ced4fe1dea621ef06cf\\n- contract status unchanged, compatible, no drift\\n\\nThis unlocks a fresh sealed alpha publication after the prior release correctly failed closed.\\n\\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:36:45Z",
          "mergedAt": "2026-07-15T01:39:38Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 40,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/40",
          "title": "release: publish sealed paper alpha",
          "body": "## Summary\n- promote the unified Buildchain v2.12.7-alpha.8 paper release contract\n- publish the next npm alpha through trusted publishing\n- attach the canonical PDF to the matching GitHub Release\n\n## Verification\n- repository checks pass on dev\n- Buildchain authority verifies the exact protected-branch status context\n- publication uses the sealed candidate digest across read-only build, authority, and isolated publisher stages",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:39:58Z",
          "mergedAt": "2026-07-15T01:42:07Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 36,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/36",
          "title": "release: publish sealed paper alpha",
          "body": "## Summary\n- promote the unified Buildchain v2.12.7-alpha.8 paper release contract\n- publish the next npm alpha through trusted publishing\n- attach the canonical PDF to the matching GitHub Release\n\n## Verification\n- repository checks pass on dev\n- Buildchain authority verifies the exact protected-branch status context\n- publication uses the sealed candidate digest across read-only build, authority, and isolated publisher stages",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:39:58Z",
          "mergedAt": "2026-07-15T01:42:12Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 51,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/51",
          "title": "release: publish sealed paper alpha",
          "body": "## Summary\n- promote the unified Buildchain v2.12.7-alpha.8 paper release contract\n- publish the next npm alpha through trusted publishing\n- attach the canonical PDF to the matching GitHub Release\n\n## Verification\n- repository checks pass on dev\n- Buildchain authority verifies the exact protected-branch status context\n- publication uses the sealed candidate digest across read-only build, authority, and isolated publisher stages",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:39:59Z",
          "mergedAt": "2026-07-15T01:42:18Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1248,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1248",
          "title": "fix(paper): resolve sealed candidate paths exactly",
          "body": "## Summary\n- resolve admitted publication files by their exact candidate-relative paths\n- preserve sealed candidate digest and byte verification\n- handle the valid case where an npm paper package repeats the release PDF under its package tree\n- regenerate the public Node API and contract projections\n\n## Failure evidence\nThe first end-to-end paper release runs reached the isolated publisher and failed closed because suffix matching found both the release PDF and its npm-package copy:\n- KFD: https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/actions/runs/29382281956\n- White Paper: https://github.com/kungfu-systems/paper-kungfu-product-white-paper/actions/runs/29382285669\n- Observer: https://github.com/kungfu-systems/paper-observer-declared-timelines/actions/runs/29382289835\n\n## Verification\n- pnpm run check\n- 618 unit tests passed\n- workflow and generated site-contract checks passed\n- four bundled actions built successfully",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:49:45Z",
          "mergedAt": "2026-07-15T01:51:53Z",
          "additions": 55,
          "deletions": 19,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 906,
          "url": "https://github.com/kungfu-systems/kungfu/pull/906",
          "title": "feat(core): freeze native KFX contract seam",
          "body": "## Summary\n\nFreeze the first versioned native KFX contract and the Core-owned service/binding seam without switching discovery or mutation authority away from the existing loaders.\n\n## Related issue\n\nAtlas goal `2026-07-15-kungfu-native-kfx-contract-and-binding-seam`.\n\n## Changes\n\n- add native KFX contract v1 to the welded KFX contract, including version negotiation, canonical roots, ownership, compatibility policy, and stable error codes\n- add the C++ `native_kfx_service` interface plus strict request, inspection, plan, and receipt validation\n- expose contract and validation through the existing storage JSON edge with transport-only Node and Python helpers\n- add positive and negative fixtures for authority claims, duplicate ownership, generation drift, unknown fields, traversal, missing closure, capability broadening, receipt-as-trust, and GUI-only mutation\n- document the migration-stage authority map while retaining the existing TypeScript loader, Python installer, and Profile lifecycle\n\n## Verification\n\n- `./shifu check`\n- `./shifu test:kfx-profile-suite` (Node, GUI, and Python contract fixtures)\n- `kungfu_native_kfx_contract_tests` through CTest on Linux/GCC 14\n- `./shifu --filter @kungfu-tech/api test:query` (18 passing)\n- native Node `kfx_runtime` contract/validate smoke\n- `pytest framework/core/tests/python/test_native_kfx_contract.py` against the built Python binding\n- `pytest framework/core/tests/python/test_kfx_contract.py` (16 passing)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0088\", \"ADR-0089\", \"ADR-0090\", \"ADR-0091\"],\n  \"summary\": \"Freeze the versioned native KFX contract, Core service interface, and thin Node/Python binding seam without authority cutover\",\n  \"verification\": [\"Shifu changed-scope check\", \"native KFX CTest fixtures\", \"KFX Profile Suite contract gate\", \"Node and Python native binding smokes\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:43:05Z",
          "mergedAt": "2026-07-15T01:52:37Z",
          "additions": 1015,
          "deletions": 7,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1249,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1249",
          "title": "release: promote exact paper candidate paths to alpha",
          "body": "## Summary\n\nPromote the exact-path sealed paper publisher fix to the alpha channel.\n\n## Evidence\n\n- Buildchain PR #1248\n- pnpm run check passed\n- all 618 unit tests passed\n- three paper dogfood runs proved suffix matching failed closed before any publication\n\n## Expected publication\n\nPublish v2.12.7-alpha.9 so the three paper repositories can rerun against exact manifest-relative candidate paths.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:52:11Z",
          "mergedAt": "2026-07-15T01:54:23Z",
          "additions": 55,
          "deletions": 19,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 157,
          "url": "https://github.com/kungfu-systems/build-images/pull/157",
          "title": "chore(buildchain): accept alpha.8 contract",
          "body": "## Summary\n- upgrade `@kungfu-tech/buildchain` to `2.12.7-alpha.8`\n- accept `v2-alpha` at `e6c3b27db0552bb0ca075ced4fe1dea621ef06cf`\n- regenerate KFD2 claims against contract digest `sha256:95e8044b7a42060dd0476f6a4957e810431d57e7982abbc4000c1693396498c7`\n\n## Verification\n- `pnpm run check`\n- `pnpm run check:kfd`\n- compatibility digest unchanged: `sha256:af162b86ab4506e9b5f1d3c59b41f3fd57fbad79ff4d749a7f12ff16460517f8`\n\nFixes #155\nSupersedes #152",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:57:02Z",
          "mergedAt": "2026-07-15T02:00:27Z",
          "additions": 21,
          "deletions": 21,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 41,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/41",
          "title": "chore(buildchain): accept alpha.9 contract",
          "body": "## Summary\n- accept Buildchain v2.12.7-alpha.9 at its exact released SHA\n- retain major-compatible floating-ref policy\n- prepare the paper alpha line to rerun the sealed npm and GitHub Release publication\n\n## Verification\n- generated by the exact released Buildchain runtime\n- repository make check passed\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:05:00Z",
          "mergedAt": "2026-07-15T02:07:14Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 37,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/37",
          "title": "chore(buildchain): accept alpha.9 contract",
          "body": "## Summary\n- accept Buildchain v2.12.7-alpha.9 at its exact released SHA\n- retain major-compatible floating-ref policy\n- prepare the paper alpha line to rerun the sealed npm and GitHub Release publication\n\n## Verification\n- generated by the exact released Buildchain runtime\n- repository make check passed\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:05:05Z",
          "mergedAt": "2026-07-15T02:07:21Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 52,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/52",
          "title": "chore(buildchain): accept alpha.9 contract",
          "body": "## Summary\n- accept Buildchain v2.12.7-alpha.9 at its exact released SHA\n- retain major-compatible floating-ref policy\n- prepare the paper alpha line to rerun the sealed npm and GitHub Release publication\n\n## Verification\n- generated by the exact released Buildchain runtime\n- repository make check passed\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:05:03Z",
          "mergedAt": "2026-07-15T02:07:30Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 42,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/42",
          "title": "release: publish sealed paper alpha with Buildchain alpha.9",
          "body": "## Summary\n- promote the exact Buildchain v2.12.7-alpha.9 contract lock\n- rerun the three-stage sealed paper publication\n- publish the declared npm alpha and attach the canonical PDF to the matching GitHub Release\n\n## Verification\n- dev branch checks passed\n- Buildchain candidate construction and authority remain credential-free\n- isolated publisher resolves release assets by exact manifest-relative path\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:07:44Z",
          "mergedAt": "2026-07-15T02:10:01Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 38,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/38",
          "title": "release: publish sealed paper alpha with Buildchain alpha.9",
          "body": "## Summary\n- promote the exact Buildchain v2.12.7-alpha.9 contract lock\n- rerun the three-stage sealed paper publication\n- publish the declared npm alpha and attach the canonical PDF to the matching GitHub Release\n\n## Verification\n- dev branch checks passed\n- Buildchain candidate construction and authority remain credential-free\n- isolated publisher resolves release assets by exact manifest-relative path\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:07:44Z",
          "mergedAt": "2026-07-15T02:10:07Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 53,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/53",
          "title": "release: publish sealed paper alpha with Buildchain alpha.9",
          "body": "## Summary\n- promote the exact Buildchain v2.12.7-alpha.9 contract lock\n- rerun the three-stage sealed paper publication\n- publish the declared npm alpha and attach the canonical PDF to the matching GitHub Release\n\n## Verification\n- dev branch checks passed\n- Buildchain candidate construction and authority remain credential-free\n- isolated publisher resolves release assets by exact manifest-relative path\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:07:44Z",
          "mergedAt": "2026-07-15T02:10:12Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 159,
          "url": "https://github.com/kungfu-systems/build-images/pull/159",
          "title": "chore(buildchain): accept alpha.9 contract",
          "body": "## Summary\n- upgrade `@kungfu-tech/buildchain` to `2.12.7-alpha.9`\n- accept `v2-alpha` at `14d7952cbf6508b6446971fd6903fba954aad4d6`\n- regenerate KFD2 claims against contract digest `sha256:a773ef118ff98b52ff14a78b0bcc7efbda77d5e5e7a552a31fe6791a4c7d4d76`\n\n## Verification\n- `pnpm run check`\n- `pnpm run check:kfd`\n- compatibility digest unchanged: `sha256:af162b86ab4506e9b5f1d3c59b41f3fd57fbad79ff4d749a7f12ff16460517f8`\n\nFixes #158",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:07:36Z",
          "mergedAt": "2026-07-15T02:11:43Z",
          "additions": 19,
          "deletions": 19,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1251,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1251",
          "title": "fix(paper): isolate admitted publication evidence",
          "body": "## Summary\n- treat .buildchain/admitted as sealed ephemeral publisher evidence during version-state verification\n- keep source/version-state mutation checks strict for every other path\n- rebuild the checked-in promote action\n- add a regression fixture for admitted artifact and controller evidence\n\n## Failure evidence\nThe publisher now passes exact candidate byte verification and publish-gate locking, then fails closed because downloaded sealed evidence appears as untracked source state:\n- KFD: https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/actions/runs/29383428582\n- White Paper: https://github.com/kungfu-systems/paper-kungfu-product-white-paper/actions/runs/29383432238\n- Observer: https://github.com/kungfu-systems/paper-observer-declared-timelines/actions/runs/29383436721\n\n## Verification\n- pnpm run check\n- all 618 unit tests passed\n- bundled actions rebuilt\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:14:41Z",
          "mergedAt": "2026-07-15T02:17:05Z",
          "additions": 12,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 907,
          "url": "https://github.com/kungfu-systems/kungfu/pull/907",
          "title": "fix(product): separate CLI launcher from runtime tree",
          "body": "## Summary\n\nSeparate the versioned CLI runtime tree from the user-facing launcher and refresh the deterministic KFD evidence that the qualification gate found stale.\n\n## Related issue\n\nNone. Found while qualifying the zero-burden desktop runtime through the full Buildchain matrix.\n\n## Changes\n\n- Stage CLI runtime files under `runtime/` while keeping `kungfu` / `kungfu.cmd` as the archive launcher.\n- Add an exact cross-platform archive layout and launcher-path regression test.\n- Refresh the canonical agent-first policy and generated KFD-1/KFD-3 evidence through the repository generators.\n\n## Verification\n\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check`\n- `node developer/sdk/src/sdk.js contract policy --check --json`\n- `node scripts/buildchain-kfd-evidence.mjs --check`\n- `pnpm --filter @kungfu-tech/sdk run build`\n- staged pre-commit gates for both commits\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fixes archive path collisions and refreshes deterministic evidence without changing the accepted product runtime or KFD architecture contracts\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not needed; archive layout is asserted by tests)",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:16:22Z",
          "mergedAt": "2026-07-15T02:18:47Z",
          "additions": 80,
          "deletions": 48,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1252,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1252",
          "title": "release: promote admitted evidence isolation to alpha",
          "body": "## Summary\n\nPromote the sealed publisher evidence-isolation fix to the alpha channel.\n\n## Evidence\n\n- Buildchain PR #1251\n- pnpm run check passed\n- all 618 unit tests passed\n- three paper runs passed byte verification and publish-gate locking before exposing the version-state false positive\n\n## Expected publication\n\nPublish v2.12.7-alpha.10 so paper publishers can consume admitted evidence without treating it as source mutation.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:17:24Z",
          "mergedAt": "2026-07-15T02:19:58Z",
          "additions": 12,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 156,
          "url": "https://github.com/kungfu-systems/build-images/pull/156",
          "title": "fix(comparator): bound Compose lifecycle cleanup",
          "body": "## Summary\n- bound every PostgreSQL adapter Compose command and retain timeout evidence\n- stabilize final-server health, SIGKILL recovery ordering, and runner shutdown\n- bind zero project-resource cleanup evidence into each qualification step\n- add a gated real 3x21 plus injected-failure lifecycle workflow\n\n## Verification\n- `pnpm run check`\n- 44 comparator qualification tests\n- real lifecycle gate: `run-comparator-lifecycle` label\n\nFixes #149",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:53:07Z",
          "mergedAt": "2026-07-15T02:27:00Z",
          "additions": 492,
          "deletions": 35,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 43,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/43",
          "title": "chore(buildchain): accept alpha.10 contract",
          "body": "## Summary\n- accept the published Buildchain v2.12.7-alpha.10 contract\n- retain the floating v2-alpha declaration with an exact KFD-1 lock\n\n## Verification\n- make check",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:28:52Z",
          "mergedAt": "2026-07-15T02:31:06Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 39,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/39",
          "title": "chore(buildchain): accept alpha.10 contract",
          "body": "## Summary\n- accept the published Buildchain v2.12.7-alpha.10 contract\n- retain the floating v2-alpha declaration with an exact KFD-1 lock\n\n## Verification\n- make check",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:28:55Z",
          "mergedAt": "2026-07-15T02:31:11Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 54,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/54",
          "title": "chore(buildchain): accept alpha.10 contract",
          "body": "## Summary\n- accept the published Buildchain v2.12.7-alpha.10 contract\n- retain the floating v2-alpha declaration with an exact KFD-1 lock\n\n## Verification\n- make check",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:28:57Z",
          "mergedAt": "2026-07-15T02:31:16Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 44,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/44",
          "title": "release: promote Buildchain alpha.10 publication support",
          "body": "## Summary\n- promote the fixed Buildchain LaTeX image and sealed paper publication flow to alpha\n- publish the next package alpha and matching PDF GitHub Release asset after merge\n\n## Verification\n- protected dev checks passed\n- Buildchain publication candidate passed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:31:27Z",
          "mergedAt": "2026-07-15T02:33:37Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 40,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/40",
          "title": "release: promote Buildchain alpha.10 publication support",
          "body": "## Summary\n- promote the fixed Buildchain LaTeX image and sealed paper publication flow to alpha\n- publish the next package alpha and matching PDF GitHub Release asset after merge\n\n## Verification\n- protected dev checks passed\n- Buildchain publication candidate passed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:31:30Z",
          "mergedAt": "2026-07-15T02:33:43Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 55,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/55",
          "title": "release: promote Buildchain alpha.10 publication support",
          "body": "## Summary\n- promote the fixed Buildchain LaTeX image and sealed paper publication flow to alpha\n- publish the next package alpha and matching PDF GitHub Release asset after merge\n\n## Verification\n- protected dev checks passed\n- Buildchain publication candidate passed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:31:32Z",
          "mergedAt": "2026-07-15T02:33:48Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 161,
          "url": "https://github.com/kungfu-systems/build-images/pull/161",
          "title": "chore(buildchain): accept v2.12.7-alpha.10 contract",
          "body": "## Summary\n- upgrade the managed Buildchain alpha runtime to `2.12.7-alpha.10`\n- accept the reviewed compatible `v2-alpha` contract at `6630a522`\n- regenerate KFD2 claims and the KFD123 summary\n\n## Verification\n- `pnpm run check`\n- 45 Comparator tests pass\n- KFD1/2/3 pass with zero alpha contract drift\n- Release Passport smoke passes\n\nFixes #160",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:32:26Z",
          "mergedAt": "2026-07-15T02:35:52Z",
          "additions": 19,
          "deletions": 19,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 162,
          "url": "https://github.com/kungfu-systems/build-images/pull/162",
          "title": "release(alpha): publish Comparator lifecycle and Buildchain alpha.10",
          "body": "## Summary\n- publish the bounded Comparator Compose lifecycle and cleanup evidence fixes\n- publish selective image reuse and registry-cache closeout changes already verified on dev\n- release with Buildchain `v2.12.7-alpha.10` and the current contract lock\n\n## Verification\n- Comparator real lifecycle: 63/63 steps, 63/63 zero-resource cleanup snapshots, injected-failure cleanup passed\n- post-merge Verify on Comparator fix: https://github.com/kungfu-systems/build-images/actions/runs/29384114345\n- post-merge Verify on Buildchain alpha.10 lock: https://github.com/kungfu-systems/build-images/actions/runs/29384476507\n- current open issue count: 0\n\nThe `dev/v1/v1.2` branch must be preserved after merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:38:34Z",
          "mergedAt": "2026-07-15T02:41:38Z",
          "additions": 513,
          "deletions": 56,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1255,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1255",
          "title": "fix(paper): retry unpublished release transactions",
          "body": "## Summary\n- let sealed paper publication explicitly supersede a stale durable transaction only when no material was published\n- preserve version/tag/target/channel identity and fail closed for completed or material-bearing transactions\n- retain the existing version-state finalization replacement path\n- regenerate the action dist and public Buildchain contract\n\nCloses #1254\n\n## Verification\n- `pnpm run check`\n- 618 tests passed before adding the preserved regression case\n- targeted stale transaction tests: 2 passed\n- sealed paper workflow test passed\n\n## Dogfood evidence\n- KFD failed run: https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/actions/runs/29384385077\n- white paper failed run: https://github.com/kungfu-systems/paper-kungfu-product-white-paper/actions/runs/29384388635\n- Observer failed run: https://github.com/kungfu-systems/paper-observer-declared-timelines/actions/runs/29384392610",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:46:44Z",
          "mergedAt": "2026-07-15T02:49:26Z",
          "additions": 151,
          "deletions": 22,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 910,
          "url": "https://github.com/kungfu-systems/kungfu/pull/910",
          "title": "feat(shifu): add documentation protocol contract",
          "body": "## Summary\n\nFreeze the project-independent Shifu Documentation Protocol v1 without moving Kungfu-specific documentation semantics into Shifu.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add versioned project submission and non-qualifying receipt schemas\n- add exact provider, root, visibility, lifecycle, route, and policy validation\n- add deterministic contract/content/submission roots and stable diagnostics\n- expose `shifu docs contract|schema|validate|show` across native, POSIX, and Windows entrypoints\n- map existing Kungfu docs, metadata, ADR, Gate, and Buildchain inputs as compatibility providers\n- add SHIFU-ADR-0006, negative fixtures, and source/check integration\n\n## Verification\n\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source`\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu docs:check`\n- staged pre-commit gate including Rust clippy/tests, Documentation Protocol, Gate, and ADR checks\n- `./shifu check` passed all relevant checks but an unrelated existing KFX Profile Suite Node test retained an idle libuv handle and was interrupted after three minutes\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0006\"],\n  \"summary\": \"Freeze Documentation Protocol v1, compatibility providers, deterministic roots, diagnostics, receipts, and read-only CLI discovery\",\n  \"verification\": [\"check:source\", \"docs:check\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe new Shifu CLI is read-only and diagnostic-only. It executes no provider probes and receives no credential or network authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:36:48Z",
          "mergedAt": "2026-07-15T02:51:25Z",
          "additions": 1915,
          "deletions": 12,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1256,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1256",
          "title": "release: promote paper transaction retry to alpha",
          "body": "## Summary\n- promote the controlled unpublished-transaction retry fix to the Buildchain alpha channel\n- unblock end-to-end paper npm and GitHub Release publication\n\n## Verification\n- PR #1255 checks passed\n- full Buildchain check passed with 618 tests\n- preserved and new stale transaction regressions passed\n\nCloses #1254 after the released alpha is proven by all three paper repositories.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:49:40Z",
          "mergedAt": "2026-07-15T02:52:05Z",
          "additions": 151,
          "deletions": 22,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 912,
          "url": "https://github.com/kungfu-systems/kungfu/pull/912",
          "title": "fix(core): honor projected Python environment",
          "body": "## Summary\n\nMake live-peer qualification launch its native campaign from the Python environment projected by Shifu and Buildchain.\n\n## Related issue\n\nNone. Found while qualifying the zero-burden desktop runtime through the full Buildchain matrix.\n\n## Changes\n\n- Resolve the native campaign Python from `UV_PROJECT_ENVIRONMENT` when projected.\n- Preserve the repository-local Core virtual environment as the development fallback.\n- Cover POSIX and Windows interpreter layouts with a focused regression test.\n\n## Verification\n\n- `./shifu exec node --test framework/core/tests/qualification/live-peer-continuity/run.test.mjs`\n- `./shifu check`\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source`\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fixes qualification environment resolution without changing the accepted runtime architecture or claim envelope\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not needed; environment behavior is asserted by tests)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:51:07Z",
          "mergedAt": "2026-07-15T02:56:04Z",
          "additions": 22,
          "deletions": 7,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 911,
          "url": "https://github.com/kungfu-systems/kungfu/pull/911",
          "title": "feat(core): add executable layer architecture contract",
          "body": "## Summary\n\nAdd one executable authority for the C++ Core layer model so source ownership, dependency direction, current target evidence, and developer navigation stay synchronized.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- define seven ordered Core layers and seven uniquely owned components in `framework/core/architecture/layers.json`\n- validate every tracked first-party C/C++ file, actual internal includes, declared component dependencies, current CMake target evidence, and navigation entrypoints\n- generate-check the human-readable `LAYERS.md` map from the same authority\n- add the architecture contract and eight controlled negative fixtures to the build-free source acceptance gate\n- link the architecture entry from the existing documentation map\n\n## Verification\n\n- `./shifu check:source`\n- `node framework/core/architecture/check-layers.mjs`\n- `node framework/core/architecture/check-layers.mjs --self-test`\n- `node --test scripts/source-acceptance.test.mjs`\n\n`./shifu check` reaches the existing SDK contract audit and reports an unrelated canonical-policy projection mismatch; this PR does not change `framework/contract`, `developer/sdk`, package manifests, or `pnpm-lock.yaml`.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Add the executable Core layer, ownership, dependency, and navigation contract required to keep the domain-neutral Core structurally enforceable.\",\n  \"verification\": [\"./shifu check:source\", \"core architecture positive and negative fixtures\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:44:47Z",
          "mergedAt": "2026-07-15T03:01:11Z",
          "additions": 803,
          "deletions": 2,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 41,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/41",
          "title": "chore(buildchain): accept alpha.11 contract",
          "body": "## Summary\n- accept published Buildchain v2.12.7-alpha.11\n- enable controlled retry of the existing unpublished paper transaction\n\n## Verification\n- make check\n- exact Buildchain GitHub/npm/tag release fact verified",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:02:02Z",
          "mergedAt": "2026-07-15T03:04:18Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 45,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/45",
          "title": "chore(buildchain): accept alpha.11 contract",
          "body": "## Summary\n- accept published Buildchain v2.12.7-alpha.11\n- enable controlled retry of the existing unpublished paper transaction\n\n## Verification\n- make check\n- exact Buildchain GitHub/npm/tag release fact verified",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:02:00Z",
          "mergedAt": "2026-07-15T03:04:58Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 56,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/56",
          "title": "chore(buildchain): accept alpha.11 contract",
          "body": "## Summary\n- accept published Buildchain v2.12.7-alpha.11\n- enable controlled retry of the existing unpublished paper transaction\n\n## Verification\n- make check\n- exact Buildchain GitHub/npm/tag release fact verified",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:02:05Z",
          "mergedAt": "2026-07-15T03:05:12Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 46,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/46",
          "title": "release: retry sealed paper publication with alpha.11",
          "body": "## Summary\n- promote Buildchain v2.12.7-alpha.11 to the paper alpha channel\n- retry the unchanged planned package version through controlled stale-transaction replacement\n- publish npm alpha and the declared PDF GitHub Release asset after merge\n\n## Verification\n- dev PR checks and publication candidate passed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:05:31Z",
          "mergedAt": "2026-07-15T03:07:54Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 42,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/42",
          "title": "release: retry sealed paper publication with alpha.11",
          "body": "## Summary\n- promote Buildchain v2.12.7-alpha.11 to the paper alpha channel\n- retry the unchanged planned package version through controlled stale-transaction replacement\n- publish npm alpha and the declared PDF GitHub Release asset after merge\n\n## Verification\n- dev PR checks and publication candidate passed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:05:34Z",
          "mergedAt": "2026-07-15T03:08:01Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 57,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/57",
          "title": "release: retry sealed paper publication with alpha.11",
          "body": "## Summary\n- promote Buildchain v2.12.7-alpha.11 to the paper alpha channel\n- retry the unchanged planned package version through controlled stale-transaction replacement\n- publish npm alpha and the declared PDF GitHub Release asset after merge\n\n## Verification\n- dev PR checks and publication candidate passed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:05:37Z",
          "mergedAt": "2026-07-15T03:08:07Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 164,
          "url": "https://github.com/kungfu-systems/build-images/pull/164",
          "title": "chore(images): accept v1.2.4-alpha.10 digests",
          "body": "## Summary\n- join the `alpha.10` release ancestry without content changes\n- accept the complete five-image digest family from the trusted Release Passport\n- regenerate KFD1/KFD2 bindings for `images.lock.json`\n\n## Trust evidence\n- Release Passport: `ok=true`, `trust=pass`, `issues=[]`\n- source SHA: `b939ad8962d590ed21fecb0312694fb6980f3f17`\n- publish run: https://github.com/kungfu-systems/build-images/actions/runs/29384801309\n- baseline after acceptance: `eligible=true`, `mode=selective`, `selected_images=[]`\n\n## Verification\n- `pnpm run check`\n- 45 Comparator tests pass\n- KFD1/2/3 and Release Passport smoke pass\n\nThis PR must be merged with a merge commit so the alpha release source remains an ancestor of the reviewed lock acceptance.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:01:54Z",
          "mergedAt": "2026-07-15T03:08:35Z",
          "additions": 93,
          "deletions": 93,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 913,
          "url": "https://github.com/kungfu-systems/kungfu/pull/913",
          "title": "fix(gui): skip Python bytecode during macOS signing",
          "body": "## Summary\n\n- exclude Python bytecode and `__pycache__` contents from the macOS code-signing walk\n- preserve every existing ignore rule and continue signing native libraries and executables\n- avoid thousands of unnecessary Apple timestamp requests that made signed product packaging intermittently fail\n\n## Failure evidence\n\nTwo exact-source macOS qualification attempts reached `@electron/osx-sign` and failed on different `.pyc` files with `A timestamp was expected but was not found`; signing the same failed file manually succeeded immediately afterward. The failure is therefore isolated to high-volume timestamping of non-code Python cache artifacts.\n\n## Validation\n\n- `node --test framework/gui/scripts/sign-macos.test.mjs` (5 passed)\n- `./shifu check:source` (316 source contract, 76 runtime upgrade, 66 desktop adapter tests passed)\n- commit staged gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Stabilizes macOS product signing by excluding non-code Python cache artifacts without changing architecture authority or release policy\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:13:51Z",
          "mergedAt": "2026-07-15T03:16:36Z",
          "additions": 39,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 47,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/47",
          "title": "release: prepare paper 0.1.0-alpha.4",
          "body": "Advances the declared publication version to 0.1.0-alpha.4 after the previous alpha transaction completed. This preserves the pinned fixed LaTeX image, restored microtype expansion, deterministic PDF filename, and sealed Buildchain publication path with GitHub Release assets.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:22:45Z",
          "mergedAt": "2026-07-15T03:25:25Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 43,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/43",
          "title": "release: prepare paper 0.1.0-alpha.3",
          "body": "Advances the declared publication version to 0.1.0-alpha.3 after the previous alpha transaction completed. This preserves the pinned fixed LaTeX image, restored microtype expansion, deterministic PDF filename, and sealed Buildchain publication path with GitHub Release assets.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:22:47Z",
          "mergedAt": "2026-07-15T03:25:33Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 58,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/58",
          "title": "release: prepare paper 0.1.0-alpha.6",
          "body": "Advances the declared publication version to 0.1.0-alpha.6 after the previous alpha transaction completed. This preserves the pinned fixed LaTeX image, restored microtype expansion, deterministic PDF filename, and sealed Buildchain publication path with GitHub Release assets.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:22:50Z",
          "mergedAt": "2026-07-15T03:25:41Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 48,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/48",
          "title": "release: publish 0.1.0-alpha.4 with PDF assets",
          "body": "Promotes the reviewed paper source to the alpha channel. The Buildchain sealed publication workflow will publish the npm package and attach the deterministic PDF plus release passport evidence to GitHub Release v0.1.0-alpha.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:26:05Z",
          "mergedAt": "2026-07-15T03:28:23Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 44,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/44",
          "title": "release: publish 0.1.0-alpha.3 with PDF assets",
          "body": "Promotes the reviewed paper source to the alpha channel. The Buildchain sealed publication workflow will publish the npm package and attach the deterministic PDF plus release passport evidence to GitHub Release v0.1.0-alpha.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:26:08Z",
          "mergedAt": "2026-07-15T03:29:10Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 59,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/59",
          "title": "release: publish 0.1.0-alpha.6 with PDF assets",
          "body": "Promotes the reviewed paper source to the alpha channel. The Buildchain sealed publication workflow will publish the npm package and attach the deterministic PDF plus release passport evidence to GitHub Release v0.1.0-alpha.6.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:26:11Z",
          "mergedAt": "2026-07-15T03:29:17Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1259,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1259",
          "title": "fix(paper): provision trusted publishing runtime",
          "body": "Closes #1258.\n\nRestores the Node 24 runtime contract in the isolated sealed publisher job so npm can exchange the GitHub OIDC identity. Candidate construction and publication authority remain credential-free.\n\nValidation: `pnpm run check` passed with 619 tests.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:33:55Z",
          "mergedAt": "2026-07-15T03:36:05Z",
          "additions": 8,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 915,
          "url": "https://github.com/kungfu-systems/kungfu/pull/915",
          "title": "feat(xinfa): freeze standalone product boundary",
          "body": "## Summary\n\nFreeze Xinfa as an independently versioned and extractable context compiler product while preserving Shifu as the submission-protocol, conformance, Gate, and thin-invocation authority.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add ADR-0092 and a machine-readable product, boundary, and extraction contract\n- add a dependency-free Rust CLI with stable version, contract, and read-only diagnostic surfaces\n- reject private host imports, dependency tables, monorepo-relative roots, and extraction symlinks with negative fixtures\n- prove clean temporary extraction, host-environment scrubbing, independent state/cache roots, and deterministic contract output\n- keep Xinfa tasks independent of unrelated Kungfu Conan cache contention across POSIX and Windows Shifu entrypoints\n- register the pre-release Xinfa product surface and document the incubation boundary\n\n## Verification\n\n- `./shifu xinfa:check`\n- `./shifu xinfa:standalone`\n- `./shifu check:source`\n- staged pre-commit gate including ADR/docs, boundary, Rust, and entrypoint checks\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0092\"],\n  \"summary\": \"Freeze Xinfa product identity and prove its extraction-first standalone boundary without implementing the full context compiler\",\n  \"verification\": [\"xinfa:check\", \"xinfa:standalone\", \"check:source\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR freezes the pre-release Xinfa identity and tag/artifact convention but publishes nothing and opens no release line.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:24:34Z",
          "mergedAt": "2026-07-15T03:36:05Z",
          "additions": 1207,
          "deletions": 0,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1260,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1260",
          "title": "release: promote sealed paper trusted publishing fix to alpha",
          "body": "Promotes #1259 / #1258 to the Buildchain alpha channel so paper consumers can retry their source-locked unpublished transactions with Node 24 npm OIDC support.\n\nThe implementation passed the full Buildchain check suite (619 tests).",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:36:31Z",
          "mergedAt": "2026-07-15T03:38:40Z",
          "additions": 8,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 916,
          "url": "https://github.com/kungfu-systems/kungfu/pull/916",
          "title": "fix(gui): preserve macOS signing ignore function",
          "body": "## Summary\n\n- pass one combined ignore function to `@electron/osx-sign` instead of an array\n- preserve existing string, array, and function rules inside that function\n- keep Python bytecode out of code signing after the previous array form was discarded by osx-sign 1.3.3\n\n## Runtime evidence\n\nAn exact-source signed product build after PR #913 still spawned `codesign` for a `.pyc` file. Inspection showed osx-sign 1.3.3 normalizes a non-array ignore into an array but returns `undefined` for an array input, silently discarding the prior hook result. The invalid signing run was stopped before further timestamp load.\n\n## Validation\n\n- `node --test framework/gui/scripts/sign-macos.test.mjs` (6 passed)\n- `./shifu check:source` (316 source contract, 76 runtime upgrade, 67 desktop adapter tests passed)\n- commit staged gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Corrects the macOS signing adapter compatibility fix without changing architecture authority or release policy\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:35:18Z",
          "mergedAt": "2026-07-15T03:40:00Z",
          "additions": 29,
          "deletions": 14,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 917,
          "url": "https://github.com/kungfu-systems/kungfu/pull/917",
          "title": "fix(core): run live-peer campaign through uv",
          "body": "## Summary\n\nRun the live-peer native campaign through the Shifu-managed `uv run` project entry so strict cache overlays remain active for the whole campaign.\n\n## Related issue\n\nNone. Found while qualifying the zero-burden desktop runtime through the full Buildchain matrix.\n\n## Changes\n\n- Replace direct virtual-environment interpreter resolution with `uv run --frozen --project framework/core python`.\n- Preserve Windows command resolution through the existing bounded shell path.\n- Cover the Shifu-managed invocation contract with a focused regression test.\n\n## Verification\n\n- `node --test framework/core/tests/qualification/live-peer-continuity/run.test.mjs`\n- `XDG_CACHE_HOME=\"$HOME/.cache/kungfu-agent-partitions/live-peer-uv-run\" ./shifu check`\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source`\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fixes the qualification execution route through the existing Shifu uv authority without changing the accepted runtime architecture or claim envelope\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not needed; execution behavior is asserted by tests)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:35:47Z",
          "mergedAt": "2026-07-15T03:44:43Z",
          "additions": 30,
          "deletions": 23,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 918,
          "url": "https://github.com/kungfu-systems/kungfu/pull/918",
          "title": "fix(shifu): unify managed Conan cache coordination",
          "body": "## Summary\n\nMove managed Conan cache coordination into the Shifu execution boundary. Development worktrees and named runners receive deterministic partitions, ordinary non-Conan tasks no longer acquire the Conan lock, and real Conan invocations use bounded same-partition waiting with fail-closed stale-lock handling.\n\n## Related issue\n\n- Cross-repository checkout-cache dependency: https://github.com/kungfu-systems/buildchain/issues/1261\n\n## Changes\n\n- derive redacted Conan storage partitions from the development worktree or runner principal\n- wrap Conan on demand instead of holding a storage lock for every Shifu task\n- reclaim only locks whose recorded owner process is provably dead\n- preserve unreadable or live locks and fail after a bounded wait\n- document the cache lifecycle and extend the resolution receipt state\n\n## Verification\n\n- `./shifu check`\n- `./shifu check:source`\n- `node --test scripts/shifu-cache-runtime.test.mjs scripts/shifu-gate-executor.test.mjs`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0001\"],\n  \"summary\": \"Complete Shifu-owned Conan cache partitioning and on-demand concurrency control\",\n  \"verification\": [\"Shifu cache contract tests\", \"source acceptance gate\", \"full Shifu check\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:41:10Z",
          "mergedAt": "2026-07-15T03:49:16Z",
          "additions": 408,
          "deletions": 77,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 49,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/49",
          "title": "chore(buildchain): accept alpha.12 trusted-publishing contract",
          "body": "Advances the floating Buildchain contract lock to v2.12.7-alpha.12 (90d3ccd8), which restores Node 24 npm OIDC support in the sealed paper publisher. The paper version and candidate contents remain unchanged for safe retry of the incomplete transaction.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:48:24Z",
          "mergedAt": "2026-07-15T03:51:39Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 45,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/45",
          "title": "chore(buildchain): accept alpha.12 trusted-publishing contract",
          "body": "Advances the floating Buildchain contract lock to v2.12.7-alpha.12 (90d3ccd8), which restores Node 24 npm OIDC support in the sealed paper publisher. The paper version and candidate contents remain unchanged for safe retry of the incomplete transaction.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:48:26Z",
          "mergedAt": "2026-07-15T03:51:50Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 60,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/60",
          "title": "chore(buildchain): accept alpha.12 trusted-publishing contract",
          "body": "Advances the floating Buildchain contract lock to v2.12.7-alpha.12 (90d3ccd8), which restores Node 24 npm OIDC support in the sealed paper publisher. The paper version and candidate contents remain unchanged for safe retry of the incomplete transaction.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:48:29Z",
          "mergedAt": "2026-07-15T03:51:59Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 50,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/50",
          "title": "release: retry 0.1.0-alpha.4 with Buildchain alpha.12",
          "body": "Retries the same unpublished 0.1.0-alpha.4 transaction with the released Buildchain alpha.12 trusted-publishing runtime. Candidate bytes remain source-bound; the incomplete prior transaction may be replaced, then npm and named PDF GitHub Release assets must finalize together.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:52:36Z",
          "mergedAt": "2026-07-15T03:54:51Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 46,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/46",
          "title": "release: retry 0.1.0-alpha.3 with Buildchain alpha.12",
          "body": "Retries the same unpublished 0.1.0-alpha.3 transaction with the released Buildchain alpha.12 trusted-publishing runtime. Candidate bytes remain source-bound; the incomplete prior transaction may be replaced, then npm and named PDF GitHub Release assets must finalize together.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:52:39Z",
          "mergedAt": "2026-07-15T03:54:56Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 61,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/61",
          "title": "release: retry 0.1.0-alpha.6 with Buildchain alpha.12",
          "body": "Retries the same unpublished 0.1.0-alpha.6 transaction with the released Buildchain alpha.12 trusted-publishing runtime. Candidate bytes remain source-bound; the incomplete prior transaction may be replaced, then npm and named PDF GitHub Release assets must finalize together.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:52:41Z",
          "mergedAt": "2026-07-15T03:55:01Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 919,
          "url": "https://github.com/kungfu-systems/kungfu/pull/919",
          "title": "fix(gui): sign only macOS code artifacts",
          "body": "## Summary\n- restrict the custom macOS signing traversal to Mach-O files and nested code bundles\n- keep existing ignore rules while preventing `@electron/osx-sign` 1.3.3 from treating binary-looking resources such as Electron locale `.pak` and Python bytecode as code\n- fail closed when a signing candidate cannot be inspected\n\n## Verification\n- `./shifu check:source`\n- desktop signing tests: 8 passed\n- real Developer ID re-sign of the complete arm64 app bundle\n- `codesign --verify --deep --strict --verbose=2`: passed\n- observed native `.node`, `.dylib`, `.so`, executables, and `.framework` as signable; `.pyc` and `locale.pak` as sealed resources\n\nNotarization is not claimed by this PR; Gatekeeper correctly reports the locally signed test bundle as unnotarized.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Corrects macOS code-artifact discovery without changing the versioned upgrade or release architecture contract\"\n}\n-->\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n- [x] Commit is signed off (DCO)\n- [x] Existing architecture claims remain unchanged\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:02:52Z",
          "mergedAt": "2026-07-15T04:05:03Z",
          "additions": 95,
          "deletions": 14,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1264,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1264",
          "title": "fix(release): preserve hidden paper publication assets",
          "body": "Closes #1263\n\nPreserves the hidden publication manifest/passport files across the sealed artifact handoff and adds a workflow contract regression test.\n\nValidation: pnpm run check (619 tests passed).",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:03:26Z",
          "mergedAt": "2026-07-15T04:05:22Z",
          "additions": 4,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1265,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1265",
          "title": "release: promote complete paper publication candidates to alpha",
          "body": "Promotes #1264 / #1263 to the Buildchain alpha channel. The fix preserves hidden publication manifest and passport files across the sealed artifact handoff so admitted npm bytes remain identical at publication time.\n\nThe implementation passed the full Buildchain check suite (619 tests).",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:06:41Z",
          "mergedAt": "2026-07-15T04:08:47Z",
          "additions": 4,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 922,
          "url": "https://github.com/kungfu-systems/kungfu/pull/922",
          "title": "feat(core): add native KFX registry plan parity",
          "body": "## Summary\n\nAdd the Core-native, read-only KFX manifest registry and deterministic load-plan stage while keeping runtime tier, admission grade, lifecycle mutation, and Buildchain admission authority separate.\n\n## Related issue\n\nAtlas goal `2026-07-15-kungfu-native-kfx-registry-plan-parity`.\n\n## Changes\n\n- advance the native KFX contract to v2 with explicit `runtimeTiers` and `admissionGrades`, retaining v1 compatibility\n- add bounded product, user, and workspace manifest discovery with canonical package roots, Suite/profile closure, deterministic registry roots, and plan roots\n- expose thin Node, Python, API, and CLI projections over the native read-only authority\n- add shared fixture parity for native, TypeScript, and Python projections, including optional-member degradation and typed refusals\n- keep package lifecycle mutation, capability authorization, trust assessment, and artifact admission outside this stage\n\n## Verification\n\n- `./shifu rebuild:core`\n- native C++ KFX contract target: 1/1 passed\n- Node storage binding: 13/13 passed\n- Python native KFX binding: 4/4 passed\n- API query projection: 18/18 passed\n- `./shifu test:kfx-profile-suite`\n- `./shifu check:source`\n- `./shifu check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0088\", \"ADR-0089\", \"ADR-0090\", \"ADR-0091\"],\n  \"summary\": \"Add the Core-native read-only KFX manifest registry, Suite closure, deterministic load-plan contract, and cross-language shadow parity without claiming lifecycle mutation or artifact admission.\",\n  \"verification\": [\"./shifu rebuild:core\", \"./shifu test:kfx-profile-suite\", \"./shifu check:source\", \"./shifu check\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe contract now separates runtime placement tiers from admission grades and carries read-only trust inputs. It does not verify Buildchain attestations, grant capabilities, mutate package lifecycle state, publish packages, or claim release qualification.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:13:51Z",
          "mergedAt": "2026-07-15T04:18:19Z",
          "additions": 2038,
          "deletions": 133,
          "changedFiles": 43
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 51,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/51",
          "title": "release: prepare complete paper alpha",
          "body": "Adopts Buildchain v2.12.7-alpha.13, which preserves hidden publication manifest/passport files across the sealed candidate handoff, and advances to a new npm version after the prior incomplete publication was occupied.\n\nThe paper remains pinned to the fixed LaTeX image with microtype support. Local repository checks passed.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:17:29Z",
          "mergedAt": "2026-07-15T04:20:05Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 47,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/47",
          "title": "release: prepare complete paper alpha",
          "body": "Adopts Buildchain v2.12.7-alpha.13, which preserves hidden publication manifest/passport files across the sealed candidate handoff, and advances to a new npm version after the prior incomplete publication was occupied.\n\nThe paper remains pinned to the fixed LaTeX image with microtype support. Local repository checks passed.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:17:32Z",
          "mergedAt": "2026-07-15T04:20:12Z",
          "additions": 10,
          "deletions": 10,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 62,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/62",
          "title": "release: prepare complete paper alpha",
          "body": "Adopts Buildchain v2.12.7-alpha.13, which preserves hidden publication manifest/passport files across the sealed candidate handoff, and advances to a new npm version after the prior incomplete publication was occupied.\n\nThe paper remains pinned to the fixed LaTeX image with microtype support. Local repository checks passed.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:17:34Z",
          "mergedAt": "2026-07-15T04:20:18Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 52,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/52",
          "title": "release: publish complete paper alpha",
          "body": "Promotes the Buildchain v2.12.7-alpha.13 consumer update and the next unoccupied paper alpha version. The release must prove an identical admitted npm package and publish the named PDF plus Buildchain evidence to GitHub Release.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:20:36Z",
          "mergedAt": "2026-07-15T04:23:20Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 48,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/48",
          "title": "release: publish complete paper alpha",
          "body": "Promotes the Buildchain v2.12.7-alpha.13 consumer update and the next unoccupied paper alpha version. The release must prove an identical admitted npm package and publish the named PDF plus Buildchain evidence to GitHub Release.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:20:38Z",
          "mergedAt": "2026-07-15T04:23:26Z",
          "additions": 10,
          "deletions": 10,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 63,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/63",
          "title": "release: publish complete paper alpha",
          "body": "Promotes the Buildchain v2.12.7-alpha.13 consumer update and the next unoccupied paper alpha version. The release must prove an identical admitted npm package and publish the named PDF plus Buildchain evidence to GitHub Release.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:20:41Z",
          "mergedAt": "2026-07-15T04:23:32Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1266,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1266",
          "title": "fix(release): select canonical paper evidence",
          "body": "## Summary\n- resolve paper publication manifest and passport from their canonical root paths\n- keep self-describing copies inside the npm package without confusing authority admission\n- cover the duplicate-filename artifact layout in a regression test\n\n## Verification\n- `node --test tests/publication-artifact-candidate.test.mjs`\n- `pnpm run check` (620 tests passed)\n\nCloses #1263",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:31:19Z",
          "mergedAt": "2026-07-15T04:33:27Z",
          "additions": 63,
          "deletions": 24,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 921,
          "url": "https://github.com/kungfu-systems/kungfu/pull/921",
          "title": "refactor(core): enforce internal target boundaries",
          "body": "## Summary\n\nTurn the executable Core layer contract into concrete CMake target boundaries while preserving the public `kungfu` artifact and platform behavior.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- derive five internal target boundaries from `framework/core/architecture/layers.json`\n- generate-check explicit CMake source ownership in `TARGETS.cmake` without recursive globbing\n- aggregate internal OBJECT targets behind the existing public `kungfu` target\n- enforce dependency direction, unique production-source ownership, projection freshness, and target-kind invariants\n- document the internal target graph and add controlled negative fixtures\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu check`\n- `./shifu exec node framework/core/architecture/check-layers.mjs`\n- `./shifu exec node framework/core/architecture/check-layers.mjs --self-test` (11 fixtures)\n- macOS AppleClang 21: clean `rebuild:core` + incremental `build:core`\n- Linux GCC 14 on agent-120: clean `rebuild:core` + incremental `build:core`\n- Windows MSVC 19.5 on DARKHERO: clean `rebuild:core` + incremental `build:core`\n\nThe Windows runner required a worktree-local CMake cache override to bypass an unrelated `sccache` temporary-file permission failure; the MSVC compile/link/package path then completed successfully.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Enforce concrete internal CMake target boundaries and downward dependencies for the domain-neutral Core while preserving the public libkungfu artifact.\",\n  \"verification\": [\"./shifu check\", \"11 architecture target fixtures\", \"clean and incremental Core builds on macOS, Linux, and Windows\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:12:58Z",
          "mergedAt": "2026-07-15T04:35:04Z",
          "additions": 431,
          "deletions": 42,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1267,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1267",
          "title": "chore(release): promote canonical paper evidence fix",
          "body": "## Summary\n- promote the canonical paper evidence selection fix to the v2.12 alpha channel\n- unblock sealed paper publication when npm packages carry self-describing evidence copies\n\n## Source\n- #1266\n- #1263",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:33:48Z",
          "mergedAt": "2026-07-15T04:35:57Z",
          "additions": 63,
          "deletions": 24,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 924,
          "url": "https://github.com/kungfu-systems/kungfu/pull/924",
          "title": "fix(runtime): make product qualification fresh-runner safe",
          "body": "## Summary\n\n- keep ordinary runtime lifecycle ownership out of the GUI main process while preserving the explicit backup/reset recovery flow through the shared CLI\n- verify the exact product outputs just produced by runtime qualification instead of starting a second native rebuild\n- bootstrap pinned Buildchain layout discovery only for KFD-declared distribution tasks so fresh runners register artifacts before `shifu builds --json`\n\n## Evidence\n\n- `cargo fmt --manifest-path crates/Cargo.toml --all --check`\n- `cargo test --manifest-path crates/Cargo.toml -p shifu registrar::tests` (10 passed)\n- `./shifu check:source` (323 source contract tests, 76 runtime upgrade tests, 69 desktop update/signing tests, TypeScript checks)\n- commit hook: workspace clippy with `-D warnings`, workspace Rust tests, documentation and staged gates\n- agent-120 product verification reached 34/35; the only failure was a duplicate Episode timeout under concurrent IO, so the artifact suite now skips that already-completed outer campaign\n- targeted runtime-activation tests (7 passed) plus a fresh `./shifu check:source` on `efce4b90b`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repairs fresh-runner qualification execution and preserves existing runtime ownership contracts without changing an architecture decision.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects qualification evidence generation only. It does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (inline contract comments and tests cover the bounded behavior)\n\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:31:14Z",
          "mergedAt": "2026-07-15T04:40:07Z",
          "additions": 130,
          "deletions": 7,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 53,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/53",
          "title": "chore(buildchain): accept alpha.14 contract",
          "body": "## Summary\n- accept Buildchain `v2.12.7-alpha.14` at its immutable `v2-alpha` SHA\n- retain the unchanged major-compatible contract surface\n- unblock the sealed paper publication retry\n\n## Verification\n- repository-local check passed\n- Buildchain compatibility digest is unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:46:56Z",
          "mergedAt": "2026-07-15T04:49:06Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 49,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/49",
          "title": "chore(buildchain): accept alpha.14 contract",
          "body": "## Summary\n- accept Buildchain `v2.12.7-alpha.14` at its immutable `v2-alpha` SHA\n- retain the unchanged major-compatible contract surface\n- unblock the sealed paper publication retry\n\n## Verification\n- repository-local check passed\n- Buildchain compatibility digest is unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:46:59Z",
          "mergedAt": "2026-07-15T04:49:12Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 64,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/64",
          "title": "chore(buildchain): accept alpha.14 contract",
          "body": "## Summary\n- accept Buildchain `v2.12.7-alpha.14` at its immutable `v2-alpha` SHA\n- retain the unchanged major-compatible contract surface\n- unblock the sealed paper publication retry\n\n## Verification\n- repository-local check passed\n- Buildchain compatibility digest is unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:47:02Z",
          "mergedAt": "2026-07-15T04:49:18Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 54,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/54",
          "title": "chore(release): promote Buildchain alpha.14 lock",
          "body": "## Summary\n- promote the reviewed Buildchain alpha.14 contract lock\n- retry the existing paper alpha publication through sealed authority\n- publish the declared PDF as a GitHub Release asset",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:50:18Z",
          "mergedAt": "2026-07-15T04:52:51Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 50,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/50",
          "title": "chore(release): promote Buildchain alpha.14 lock",
          "body": "## Summary\n- promote the reviewed Buildchain alpha.14 contract lock\n- retry the existing paper alpha publication through sealed authority\n- publish the declared PDF as a GitHub Release asset",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:50:20Z",
          "mergedAt": "2026-07-15T04:52:56Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 65,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/65",
          "title": "chore(release): promote Buildchain alpha.14 lock",
          "body": "## Summary\n- promote the reviewed Buildchain alpha.14 contract lock\n- retry the existing paper alpha publication through sealed authority\n- publish the declared PDF as a GitHub Release asset",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:50:23Z",
          "mergedAt": "2026-07-15T04:53:02Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1269,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1269",
          "title": "fix(release): authorize sealed paper bookkeeping",
          "body": "## Summary\n- accept an optional bypass-capable token in the sealed paper preset\n- restrict it to generated protected version-state ref updates\n- keep npm publication bound to OIDC trusted publishing\n- regenerate public workflow and documentation projections\n\n## Verification\n- `node --test tests/build-surface.test.mjs tests/paper-sealed-release.test.mjs`\n- `pnpm run check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:03:50Z",
          "mergedAt": "2026-07-15T05:05:58Z",
          "additions": 42,
          "deletions": 23,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1270,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1270",
          "title": "chore(release): promote v2.12 dev to alpha",
          "body": "Promote the current verified `dev/v2/v2.12` state to the alpha channel.\n\nIncludes sealed paper publication support for protected generated version-state updates while preserving OIDC-only npm publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:06:19Z",
          "mergedAt": "2026-07-15T05:08:40Z",
          "additions": 42,
          "deletions": 23,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 927,
          "url": "https://github.com/kungfu-systems/kungfu/pull/927",
          "title": "fix(kfd): refresh release evidence after contract changes",
          "body": "## Summary\n\n- refresh the generated KFD-1 witness after the canonical policy and KFX contract changed\n- refresh the derived release gate and packaged SDK projections\n- bind the KFD-3 prebuild witness to the exact current source SHA\n\n## Evidence\n\n- `node scripts/buildchain-kfd-evidence.mjs --check --json` (current)\n- `./shifu check:source` (323 source tests, 76 runtime upgrade tests, 69 desktop update/signing tests)\n- commit hook Buildchain KFD evidence check and staged gates\n- exact macOS release qualification reached 41/42; the sole prior failure was the stale KFD witness repaired here\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Refreshes generated release evidence to match already-merged contract sources without changing an architecture decision.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nGenerated evidence only; this PR does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Generated evidence is current under the repository checker",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:06:39Z",
          "mergedAt": "2026-07-15T05:09:10Z",
          "additions": 30,
          "deletions": 30,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 926,
          "url": "https://github.com/kungfu-systems/kungfu/pull/926",
          "title": "feat(xinfa): add dual-first context IR protocol",
          "body": "## Summary\n\nAdd the project-independent, dual-first Xinfa project protocol and minimal Context IR compiler. Human and Agent routes consume the same cut, authority nodes, verification status, evidence semantics, and authority root.\n\n## Related issue\n\nAtlas goal 2026-07-15-xinfa-context-ir-and-project-protocol.\n\n## Changes\n\n- accept ADR-0093 and align ADR-0092 with the verified human-Agent product boundary\n- add public xinfa.project/v1 and xinfa.context-ir/v1 schemas plus validate, canonicalize, and compile CLI surfaces\n- derive stale and invalidated states from exact dependencies while keeping non-claims outside implementation drift\n- enforce exact providers, fail-closed visibility, stable diagnostics, route parity, and standalone dependency boundaries\n- retain two non-isomorphic positive fixtures, ten negative cases, and Mac qualification receipts\n\n## Verification\n\n- ./shifu xinfa:check\n- ./shifu xinfa:standalone\n- ./shifu docs:check:readonly\n- ./shifu check:source\n- AJV 2020 validation for both positive project fixtures\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0092\", \"ADR-0093\"],\n  \"summary\": \"Complete the dual-first project protocol and minimal Context IR compiler stage\",\n  \"verification\": [\"xinfa check\", \"clean extraction standalone smoke\", \"source acceptance\", \"documentation and ADR gates\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR updates the pre-release Xinfa product identity and retained qualification evidence only. It does not publish a package, open a stable line, call a hosted service, or add credentials.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:54:19Z",
          "mergedAt": "2026-07-15T05:14:38Z",
          "additions": 2622,
          "deletions": 35,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 55,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/55",
          "title": "release: publish alpha.6 with GitHub PDF",
          "body": "## Summary\n- publish KFD foundation paper `0.1.0-alpha.6`\n- lock Buildchain v2-alpha to v2.12.7-alpha.15\n- forward the protected-ref bookkeeping secret to the sealed paper preset\n- retain the pinned LaTeX Docker image with microtype expansion enabled\n- publish the named PDF through the exact-version GitHub Release\n\n## Local verification\n- repository check passed\n- contract lock generated from Buildchain v2.12.7-alpha.15\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:19:18Z",
          "mergedAt": "2026-07-15T05:21:46Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 51,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/51",
          "title": "release: publish alpha.5 with GitHub PDF",
          "body": "## Summary\n- publish Kungfu product white paper `0.1.0-alpha.5`\n- lock Buildchain v2-alpha to v2.12.7-alpha.15\n- forward the protected-ref bookkeeping secret to the sealed paper preset\n- retain the pinned LaTeX Docker image with microtype expansion enabled\n- publish the named PDF through the exact-version GitHub Release\n\n## Local verification\n- repository check passed\n- contract lock generated from Buildchain v2.12.7-alpha.15\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:19:20Z",
          "mergedAt": "2026-07-15T05:21:57Z",
          "additions": 12,
          "deletions": 10,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 66,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/66",
          "title": "release: publish alpha.8 with GitHub PDF",
          "body": "## Summary\n- publish Observer-declared timelines `0.1.0-alpha.8`\n- lock Buildchain v2-alpha to v2.12.7-alpha.15\n- forward the protected-ref bookkeeping secret to the sealed paper preset\n- retain the pinned LaTeX Docker image with microtype expansion enabled\n- publish the named PDF through the exact-version GitHub Release\n\n## Local verification\n- repository check passed\n- contract lock generated from Buildchain v2.12.7-alpha.15\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:19:24Z",
          "mergedAt": "2026-07-15T05:22:07Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 56,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/56",
          "title": "chore(release): promote paper alpha",
          "body": "Promote the verified paper release to the alpha channel.\n\nThe release uses Buildchain v2.12.7-alpha.15, publishes the named PDF to the exact-version GitHub Release, and uses the protected-ref token only for generated version-state bookkeeping.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:22:25Z",
          "mergedAt": "2026-07-15T05:24:23Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 52,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/52",
          "title": "chore(release): promote paper alpha",
          "body": "Promote the verified paper release to the alpha channel.\n\nThe release uses Buildchain v2.12.7-alpha.15, publishes the named PDF to the exact-version GitHub Release, and uses the protected-ref token only for generated version-state bookkeeping.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:22:29Z",
          "mergedAt": "2026-07-15T05:24:28Z",
          "additions": 12,
          "deletions": 10,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 67,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/67",
          "title": "chore(release): promote paper alpha",
          "body": "Promote the verified paper release to the alpha channel.\n\nThe release uses Buildchain v2.12.7-alpha.15, publishes the named PDF to the exact-version GitHub Release, and uses the protected-ref token only for generated version-state bookkeeping.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:22:33Z",
          "mergedAt": "2026-07-15T05:24:34Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 930,
          "url": "https://github.com/kungfu-systems/kungfu/pull/930",
          "title": "fix(qualification): isolate installed provider drift",
          "body": "## Summary\n\n- keep the credential-free zero-burden aggregate deterministic across self-hosted runners\n- run the complete Agent Session control-plane/native recovery suite while keeping installed-provider version and Codex schema drift as separate native gates\n- document and test that incidental runner CLI installations cannot widen or block the aggregate claim\n\n## Evidence\n\n- ./shifu build:core\n- ./shifu --filter @kungfu-tech/agent-session test:control-plane (93/93)\n- node --test scripts/run-zero-burden-product-qualification.test.mjs (4/4)\n- ./shifu check\n- SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source (324 source, 76 runtime-upgrade, 69 desktop-update)\n- commit hook staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Keeps credential-free qualification independent of incidental runner provider installations without changing provider compatibility or runtime authority contracts.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo provider credentials or private state are read; installed-provider drift gates remain separately available. This changes qualification composition only and does not publish artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:55:01Z",
          "mergedAt": "2026-07-15T06:02:44Z",
          "additions": 39,
          "deletions": 6,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 929,
          "url": "https://github.com/kungfu-systems/kungfu/pull/929",
          "title": "refactor(core): decompose storage service responsibilities",
          "body": "## Summary\n\nSplit the oversized C++ storage implementation into explicit provider, maintenance, transfer, and domain-dispatch responsibilities while preserving the public storage facade and runtime behavior.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- move file and RocksDB provider ownership behind a private storage provider port in the adapter target\n- isolate status, fsck, rebuild, GC, and compaction planning as a maintenance service\n- isolate manifest bundle import, export, and sync verification as a transfer service\n- move JSON-edge/domain dispatch into the composition target\n- retain the public compatibility facade and shared application helpers in `service.cpp`\n- add executable responsibility seams with source budgets, required/forbidden ownership tokens, and negative fixtures\n- regenerate the architecture map and CMake target projection for all 208 first-party C/C++ sources\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu build:core`\n- `./shifu exec ctest --test-dir framework/core/build --output-on-failure` (12/12)\n- `KUNGFU_DIR=\"$PWD/framework/core/build/Release\" ./shifu exec node --test framework/core/tests/storage-node-binding.test.js` (13/13)\n- `./shifu exec node framework/core/architecture/check-layers.mjs`\n- `./shifu exec node framework/core/architecture/check-layers.mjs --self-test` (14 fixtures)\n\nCross-platform exact-SHA qualification will be completed before merge.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Decompose the C++ storage runtime into executable provider, service, transfer, and composition responsibilities while preserving the public storage facade.\",\n  \"verification\": [\"./shifu check:source\", \"14 architecture fixtures\", \"CMake/CTest and Node storage parity tests\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:30:12Z",
          "mergedAt": "2026-07-15T06:07:38Z",
          "additions": 2801,
          "deletions": 2378,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 931,
          "url": "https://github.com/kungfu-systems/kungfu/pull/931",
          "title": "feat(xinfa): compile repository context packs",
          "body": "## Summary\n\nCompile exact project authority into portable, deterministic Repository Context Packs without changing the existing Context IR compatibility surface. The Pack embeds bounded UTF-8 source units, preserves dual-first route parity, exposes bidirectional coverage and impact, and remains explicitly non-qualifying.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add ADR-0094 and public Pack, manifest, and receipt schemas\n- add atomic compile output plus inspect, offline verify, and impact CLI surfaces\n- fail closed on provider drift, visibility broadening, symlinks, sensitive paths, unsupported providers, and partial output\n- add small, medium, changed-scope, and malicious fixtures with golden roots and standalone qualification\n\n## Verification\n\n- `./shifu xinfa:check` (18 Rust library tests, 1 CLI test, boundary checks)\n- `./shifu xinfa:standalone`\n- `./shifu docs:check:readonly`\n- `./shifu check:source` (324 Node tests, 76 Python tests, 69 desktop tests, typecheck and format/lint)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0094\"],\n  \"summary\": \"Deliver the deterministic Repository Context Pack vertical slice with portable payloads, roots, coverage, impact, offline verification, and standalone proof\",\n  \"verification\": [\"./shifu xinfa:check\", \"./shifu xinfa:standalone\", \"./shifu docs:check:readonly\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe new provenance and receipts are local Xinfa compiler artifacts. They explicitly set `qualifying: false` and `selfCertified: false`; they do not attest a release or execute providers/probes.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T06:10:17Z",
          "mergedAt": "2026-07-15T06:18:56Z",
          "additions": 2352,
          "deletions": 17,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 932,
          "url": "https://github.com/kungfu-systems/kungfu/pull/932",
          "title": "fix(shifu): preserve tool path across nested cache apply",
          "body": "## Summary\n\n- preserve the first real Cargo and Conan PATH across nested Shifu cache overlays\n- prevent an inner wrapper from resolving an outer wrapper as the real tool\n- add a bounded regression test for nested wrapper PATH provenance\n\n## Evidence\n\n- `node --test scripts/shifu-cache-runtime.test.mjs` (18/18)\n- `./shifu check:source` (325 Node tests, 76 Python tests, 69 desktop update tests)\n- `./shifu check:shifu-cache-contract`\n\n## Failure prevented\n\nA nested `layers.sdk` Gate under the development cache profile could recursively invoke the Cargo wrapper, repeatedly append registry config, and spawn thousands of Node processes. The Gate was interrupted and all residual overlay processes were verified absent before this patch.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fixes nested cache wrapper execution so existing Shifu and Gate contracts run safely without changing an architecture decision.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes only local cache-wrapper process selection and does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Regression test and source acceptance are green\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T06:11:14Z",
          "mergedAt": "2026-07-15T06:25:43Z",
          "additions": 54,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 933,
          "url": "https://github.com/kungfu-systems/kungfu/pull/933",
          "title": "fix(qualification): preserve RC evidence across platforms",
          "body": "## Summary\n\n- preserve the Buildchain-retained upgrade qualification reference through nested product distribution builds\n- use a platform-safe temporary root for the Windows native live-peer campaign\n- replace the Unix-only machine probe with a portable platform probe\n- add bounded regression coverage for both release evidence and platform planning\n\n## Evidence\n\n- `node --test scripts/run-release-qualification.test.mjs framework/core/tests/qualification/live-peer-continuity/run.test.mjs` (20/20)\n- `./shifu check:source` (325 Node tests, 76 Python tests, 69 desktop update tests)\n- staged DCO hook and Python/TypeScript format checks passed\n\n## Hosted failures fixed\n\n- Linux final qualification rebuilt product artifacts without `KF_UPGRADE_QUALIFICATION_REF`, causing `upgrade:qualify:native` to reject an otherwise RC-qualified build.\n- Windows native live-peer qualification failed immediately because the campaign assumed `/tmp` and later used `os.uname()`.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fixes cross-platform execution of existing release qualification contracts without changing an architecture decision.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes only qualification environment propagation and disposable test workspace selection; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green\n- [x] No credentials or generated qualification evidence are committed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T06:30:18Z",
          "mergedAt": "2026-07-15T06:32:28Z",
          "additions": 47,
          "deletions": 17,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 935,
          "url": "https://github.com/kungfu-systems/kungfu/pull/935",
          "title": "fix(agent-session): keep Darwin test sockets short",
          "body": "## Summary\n\n- keep direct Agent Session Unix-domain socket tests on the same short Darwin temp-root policy as production\n- prevent deeply nested Buildchain TMPDIR values from turning valid detached-worker and local-RPC assertions into path-length failures\n- preserve the full recovery and RPC assertions on every platform\n\n## Evidence\n\n- ./shifu build:core\n- TMPDIR=\"$PWD/.buildchain/tmp\" node --test framework/agent-session/tests/capsule-worker.test.mjs framework/agent-session/tests/product-surface.test.mjs (17/17)\n- corepack pnpm --filter @kungfu-tech/agent-session test:control-plane (93/93)\n- node --test framework/core/tests/qualification/live-peer-continuity/run.test.mjs (7/7)\n- node --test scripts/check-shifu-cache-contract.test.mjs scripts/shifu-cache-runtime.test.mjs scripts/shifu-uv-cache-adapter.test.mjs (47/47)\n- commit hook staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Aligns test-owned Darwin socket paths with the existing production runtime policy without changing runtime authority or product behavior.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo product authority or release contract changes. The patch only prevents qualification-only endpoint paths from exceeding Darwin's Unix-domain socket limit.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T07:05:01Z",
          "mergedAt": "2026-07-15T07:13:56Z",
          "additions": 6,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 936,
          "url": "https://github.com/kungfu-systems/kungfu/pull/936",
          "title": "test(shifu): isolate nested cache path fixtures",
          "body": "## Summary\n\n- make the tool-overlay fixtures explicit about whether they start from a clean environment or an already wrapped Shifu environment\n- keep inherited Cargo and Conan original-path authority when testing nested apply\n- remove inherited wrapper authority only in the fixture that intentionally supplies fake tool binaries\n\n## Evidence\n\n- ./shifu check\n- nested Shifu cache contract tests: 47/47\n- commit hook staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Corrects qualification fixture isolation for nested Shifu execution without changing cache runtime behavior or contracts.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change is test-only and prevents a valid outer Shifu cache projection from polluting fixtures that intentionally construct their own PATH.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T07:27:17Z",
          "mergedAt": "2026-07-15T07:30:41Z",
          "additions": 12,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 937,
          "url": "https://github.com/kungfu-systems/kungfu/pull/937",
          "title": "fix(qualification): close hosted acceptance gaps",
          "body": "## Summary\n\n- preserve the host-owned short temporary root before release qualification redirects build temp into the repository\n- use that short root for the Windows native live-peer campaign and surface its bounded failure reason in hosted logs\n- calibrate the alpha qualification budget from 1800s to 2700s after the exact-source hosted run measured 1467s inside qualification\n- keep every existing native, artifact, Episode, signature, and upgrade gate enabled\n\n## Evidence\n\n- `./shifu exec node --test framework/core/tests/qualification/live-peer-continuity/run.test.mjs scripts/run-release-qualification.test.mjs` (21/21)\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source` (exit 0; build-free source gate passed)\n- staged DCO, docs, catalog, TypeScript, and Biome checks passed\n- hosted diagnosis: run 29394539339 reached all Linux gates before the 810s execution allowance rejected the passing path; Windows reached native live-peer qualification before its repository-scoped temp path failed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fixes hosted execution of existing release qualification contracts without changing an architecture decision.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes qualification workspace selection and an evidence-backed time budget; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green\n- [x] No credentials or generated qualification evidence are committed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T07:44:26Z",
          "mergedAt": "2026-07-15T07:49:03Z",
          "additions": 83,
          "deletions": 11,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 938,
          "url": "https://github.com/kungfu-systems/kungfu/pull/938",
          "title": "fix(core): close cross-platform architecture acceptance gaps",
          "body": "## Summary\n\nClose the final Core architecture acceptance gaps discovered while qualifying the remediated target boundaries on macOS, Linux, and Windows at the same code SHA.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- preserve explicit Cargo, Conan, CMake, and Ninja path overrides across nested Shifu cache/apply invocations\n- distinguish Windows mmap resize failures with actionable operating-system diagnostics\n- keep journal test page-size inputs in megabytes instead of accidentally requesting multi-terabyte sparse mappings\n- make Node storage binding parity tests portable across Windows environment and Python command-line semantics\n- tolerate process-cached RocksDB test locks only at the cleanup boundary they actually affect\n- release temporary storage providers before sync-verification cleanup without weakening process-lived runtime caches\n- project the completed cross-platform qualification into ADR-0049\n\n## Verification\n\nQualified code SHA: `0803574a7e68c715ad856550df0d386c8cac3f89`\n\n- macOS Apple Clang: Core build; CTest 12/12; Node binding 13/13\n- agent-120 Linux GNU: Core build; CTest 12/12; Node binding 13/13\n- DARKHERO Windows MSVC: Core build; CTest 12/12; Node binding 13/13\n- `./shifu check`\n- `./shifu check:source`\n- architecture layer checker and self-test (14 fixtures)\n- first-party target ownership projection (208 C/C++ sources, single ownership)\n- navigation route, storage source budget, docs, and ADR structural audits\n- ADR-0066 production modules remain `hold`; no production module was enabled\n\n## Failure modes prevented\n\n- nested cache layers silently reverting explicit tool paths to deleted temporary overlays\n- POSIX sparse mappings hiding a megabytes-versus-bytes test contract error that fails on Windows\n- Windows Python inline-command parsing and environment lookup diverging from POSIX\n- deleting a verification directory while its temporary RocksDB provider still holds a live lock\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Qualify the remediated Core architecture boundaries on macOS, Linux, and Windows and fix only the portability and lifetime gaps exposed by exact-code-SHA acceptance.\",\n  \"verification\": [\"./shifu check\", \"three-platform Core build\", \"CTest 12/12 on each platform\", \"Node binding 13/13 on each platform\", \"14 architecture fixtures\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:02:09Z",
          "mergedAt": "2026-07-15T08:12:24Z",
          "additions": 127,
          "deletions": 30,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 939,
          "url": "https://github.com/kungfu-systems/kungfu/pull/939",
          "title": "feat(xinfa): add Atlas primitive contract",
          "body": "## Summary\n\n- establish xinfa.atlas/v1 and atlas_root as the immutable compiled context primitive\n- preserve xinfa.context-pack/v1 as a byte-identical, non-reinterpreted compatibility input\n- add Atlas-first compile, inspect, verify, diff, impact, schemas, golden and standalone qualification\n\n## Verification\n\n- ./shifu xinfa:check\n- ./shifu xinfa:standalone\n- ./shifu check:source\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"implemented\",\"adrs\":[\"ADR-0095\"],\"summary\":\"Establish the immutable Xinfa Atlas primitive and non-reinterpreted Context Pack compatibility boundary\",\"verification\":[\"./shifu xinfa:check\",\"./shifu xinfa:standalone\",\"./shifu check:source\"]}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:08:02Z",
          "mergedAt": "2026-07-15T08:17:52Z",
          "additions": 1629,
          "deletions": 16,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 108,
          "url": "https://github.com/kungfu-systems/kfd/pull/108",
          "title": "docs(kfd): define primitive discovery procedures",
          "body": "## Summary\n\n- define KFD-5 as the active human-agent primitive discovery procedure\n- define KFD-6 as a draft autonomous discovery procedure grounded in causal experience\n- publish schemas, usage pages, registry metadata, site projection, and KFD-1/2/3 self-proof updates\n\n## Verification\n\n- `node scripts/check.mjs`\n- `git diff --check`\n- `npm pack --dry-run --json`",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:21:10Z",
          "mergedAt": "2026-07-15T08:24:11Z",
          "additions": 1622,
          "deletions": 136,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 110,
          "url": "https://github.com/kungfu-systems/kfd/pull/110",
          "title": "chore(kfd): anchor alpha 23 version",
          "body": "## Summary\n- Anchor the KFD package release metadata at 1.0.0-alpha.23.\n- Regenerate KFD-1, KFD-2, and KFD-3 release evidence bound to the new package facts.\n\n## Validation\n- npm run check\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n- npx -y @kungfu-tech/buildchain@2 validate --cwd . --json\n\n## Package surface\n- KFD-5 and KFD-6 decision documents are included.\n- KFD-5 and KFD-6 schemas are included.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:39:59Z",
          "mergedAt": "2026-07-15T08:42:33Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1272,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1272",
          "title": "fix(build): bind controller evidence to selected runtime",
          "body": "## Summary\n- Bind reusable-build controller plans to the channel-selected Buildchain runtime rather than the outer workflow shell.\n- Preserve the stable workflow shell as the implementation source while recording the selected runtime ref, SHA, and contract digest in evidence.\n- Regenerate the public Buildchain contract projection and add regression assertions for split shell/runtime identities.\n\n## Validation\n- node --test tests/build-surface.test.mjs\n- pnpm run check (620 tests passed)\n- git diff --check\n\n## Consumer proof\nThis fixes the false `controller receipt reference runtime SHA mismatch` observed by the KFD alpha promotion when `build.yml@v2` selected `v2-alpha`.\n\nFixes #1271",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:50:11Z",
          "mergedAt": "2026-07-15T08:52:16Z",
          "additions": 10,
          "deletions": 14,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1273,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1273",
          "title": "chore(release): promote v2.12 dev to alpha",
          "body": "## Summary\nPromote the selected-runtime controller evidence fix to the Buildchain v2.12 alpha channel.\n\n## Included\n- controller plans bind the channel-selected runtime ref, SHA, and contract digest\n- public contract projection updated\n- regression coverage for different workflow-shell and selected-runtime identities\n\n## Validation\n- pnpm run check (620 tests passed)\n- cross-platform libnode-shaped build fixture passed on PR #1272\n\n## Downstream proof\nAfter this promotion, rerun the blocked KFD alpha promotion: https://github.com/kungfu-systems/kfd/pull/111",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:52:36Z",
          "mergedAt": "2026-07-15T08:55:03Z",
          "additions": 10,
          "deletions": 14,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 940,
          "url": "https://github.com/kungfu-systems/kungfu/pull/940",
          "title": "diag(qualification): retain native peer failure details",
          "body": "## Summary\n\n- preserve fail-closed native peer continuity while reporting the exact peer PID set and return code\n- emit only a bounded 40-line / 16 KiB tail from the test-owned peer log when the native campaign fails\n- make the next hosted Windows failure actionable without retaining credentials or weakening any release claim\n\n## Evidence\n\n- `node --test framework/core/tests/qualification/live-peer-continuity/run.test.mjs` (8/8)\n- Python compile check with external pycache\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source` (exit 0; 325 source contracts, 76 runtime tests, 69 Desktop tests)\n- staged DCO, docs, catalog, TypeScript, Biome, Ruff format and Ruff lint checks passed\n- hosted diagnosis: exact-source run 29398665421 passed Windows packaging, NSIS, CLI smoke, 42/42 build verification and three 90-second fuzz legs, then failed the native cross-process restart assertion without retaining its peer child log\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Improves fail-closed hosted qualification diagnostics without changing architecture or release claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR prints only a bounded tail from a disposable qualification-owned peer log; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green\n- [x] No credentials or generated qualification evidence are committed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:53:01Z",
          "mergedAt": "2026-07-15T08:55:39Z",
          "additions": 47,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 112,
          "url": "https://github.com/kungfu-systems/kfd/pull/112",
          "title": "fix(ci): align alpha shell with selected runtime",
          "body": "## Summary\n- Run the KFD build controller through the official `v2-alpha` Buildchain shell while KFD is an alpha canary.\n- Accept the newly published `v2.12.7-alpha.16` contract lock.\n- Regenerate KFD-1, KFD-2, and KFD-3 evidence bound to the workflow and lock facts.\n\n## Why\nGitHub loads reusable workflow structure from the declared workflow ref. The KFD alpha build selected the `v2-alpha` runtime but retained the stable `v2` shell, so the fixed selected-runtime controller plan was not loaded. This change aligns shell and selected runtime without advancing Buildchain stable.\n\n## Validation\n- npm run check\n- git diff --check\n- npx -y @kungfu-tech/buildchain@2.12.7-alpha.16 validate --cwd . --json\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n\nRelated: kungfu-systems/buildchain#1271\nBuildchain fix: kungfu-systems/buildchain#1272",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:04:49Z",
          "mergedAt": "2026-07-15T09:07:32Z",
          "additions": 65,
          "deletions": 20,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 111,
          "url": "https://github.com/kungfu-systems/kfd/pull/111",
          "title": "release(kfd): promote alpha 23",
          "body": "## Summary\nPromote `dev/v1/v1.0` to `alpha/v1/v1.0` for `@kungfu-tech/kfd@1.0.0-alpha.23`.\n\n## Included\n- KFD-5: human-agent primitive discovery.\n- KFD-6 draft: autonomous episode-grounded discovery loop.\n- Alpha 23 anchored package and release evidence.\n\n## Validation\n- Buildchain Verify and Build gates run on this promotion PR.\n- After merge, the Buildchain promotion workflow publishes the npm alpha, GitHub Release, and release passport through trusted publishing.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:42:50Z",
          "mergedAt": "2026-07-15T09:11:08Z",
          "additions": 1834,
          "deletions": 185,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1274,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1274",
          "title": "fix(release): preserve promotion authority receipt",
          "body": "## Summary\n\n- record publication authority as passed when the promotion job succeeds, because that job is hard-gated on the authority reusable workflow\n- preserve the raw authority result on failed or skipped promotions\n- regenerate the public Buildchain contract and add a regression assertion\n\n## Evidence\n\nKFD release run `29403579067` successfully published `@kungfu-tech/kfd@1.0.0-alpha.23`, but the downstream receipt observed an empty reusable-job result and incorrectly marked `publication-authority` as missing.\n\n## Verification\n\n- `pnpm run check` (620 tests)\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:22:03Z",
          "mergedAt": "2026-07-15T09:24:21Z",
          "additions": 9,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1275,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1275",
          "title": "release(buildchain): promote alpha 17",
          "body": "## Summary\n\nPromote the Buildchain receipt correction to the `v2-alpha` channel so KFD can re-audit its already-published alpha release with a qualifying controller receipt.\n\n## Included change\n\n- preserve publication authority evidence when a hard-gated promotion succeeds\n\n## Verification\n\n- `pnpm run check` (620 tests)\n- Buildchain PR #1274 cross-platform matrix\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:24:45Z",
          "mergedAt": "2026-07-15T09:26:58Z",
          "additions": 9,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 113,
          "url": "https://github.com/kungfu-systems/kfd/pull/113",
          "title": "fix(ci): align alpha promotion runtime",
          "body": "## Summary\n\n- run the KFD alpha promotion controller through Buildchain `v2-alpha`, matching the alpha build shell and selected runtime\n- accept the Buildchain `2.12.7-alpha.17` contract lock\n- anchor the next KFD package as `1.0.0-alpha.24` and regenerate KFD-1/2/3 evidence\n\n## Context\n\nKFD `1.0.0-alpha.23` published successfully, but its post-publish controller receipt was evaluated by the stable reusable workflow shell and incorrectly lost the already-enforced publication-authority result. Buildchain alpha.17 fixes that receipt projection.\n\n## Verification\n\n- `npm run check`\n- Buildchain alpha.17 validate\n- npm pack dry-run: 52 files; KFD-5 and KFD-6 present\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:42:24Z",
          "mergedAt": "2026-07-15T09:44:45Z",
          "additions": 44,
          "deletions": 44,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 114,
          "url": "https://github.com/kungfu-systems/kfd/pull/114",
          "title": "release(kfd): promote alpha 24",
          "body": "## Summary\n\nPromote KFD `1.0.0-alpha.24` through the fully aligned Buildchain alpha build and promotion chain.\n\n## Included\n\n- KFD-5 and draft KFD-6 package surfaces from alpha.23\n- Buildchain alpha.17 contract lock\n- alpha promotion shell aligned with `v2-alpha`\n\n## Verification\n\n- KFD checks pass\n- Buildchain build controller receipts qualify\n- npm pack dry-run contains 52 files including KFD-5 and KFD-6\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:45:31Z",
          "mergedAt": "2026-07-15T09:48:10Z",
          "additions": 44,
          "deletions": 44,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1277,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1277",
          "title": "fix(release): bind authority to resolved runtime SHA",
          "body": "## Summary\n\n- expose the controller-resolved Buildchain runtime SHA\n- pass the immutable SHA to sealed publication authority\n- preserve floating refs only at the caller/controller resolution boundary\n- add a regression guard and regenerate the public contract projection\n\n## Verification\n\n- `pnpm run check`\n- 620 tests passed\n- workflow lint passed\n- generated action bundles completed\n\nCloses #1276",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:55:20Z",
          "mergedAt": "2026-07-15T09:57:24Z",
          "additions": 24,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1278,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1278",
          "title": "release(buildchain): promote alpha 18",
          "body": "## Summary\n\nPromote the immutable publication-authority runtime binding to the `v2-alpha` channel.\n\n## Included change\n\n- resolve a floating Buildchain entry ref once in the controller plan\n- pass the resulting immutable runtime SHA into sealed publication authority\n- preserve the consumer contract-lock and floating-channel workflow\n\n## Verification\n\n- `pnpm run check` (620 tests)\n- Buildchain PR #1277 cross-platform matrix\n- KFD failed-run evidence: https://github.com/kungfu-systems/kfd/actions/runs/29405874062\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:57:50Z",
          "mergedAt": "2026-07-15T10:00:19Z",
          "additions": 24,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 943,
          "url": "https://github.com/kungfu-systems/kungfu/pull/943",
          "title": "fix(qualification): track Windows peer workload pid",
          "body": "## Summary\n\n- bind native Peer workload identity to the first self-reported ready marker\n- keep `Popen.pid` as launcher-liveness evidence because Windows Shifu/uv may retain a launcher process in front of Python\n- require the same marker PID across same-generation and generation-advance recovery without weakening the fail-closed process check\n\n## Evidence\n\n- hosted Windows run `29402850286`: launcher PID `7016`, stable Peer marker/log PID `4532`, launcher remained alive (`peer_return_code=None`)\n- `node --test framework/core/tests/qualification/live-peer-continuity/run.test.mjs` (9/9)\n- Python compile check with external pycache\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source` (325 source contracts, 76 runtime tests, 69 Desktop tests; all passed)\n- staged DCO, docs, catalog, Biome, Ruff format and Ruff lint checks passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Corrects a Windows qualification launcher/workload PID distinction without changing runtime architecture or product claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR corrects qualification identity evidence only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green\n- [x] No credentials or generated qualification evidence are committed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:58:40Z",
          "mergedAt": "2026-07-15T10:00:39Z",
          "additions": 27,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 941,
          "url": "https://github.com/kungfu-systems/kungfu/pull/941",
          "title": "refactor(core): split storage service responsibilities",
          "body": "## Summary\n\nSplit the remaining storage-service monolith into stable responsibility units while preserving the public storage API and runtime behavior.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- reduce `service.cpp` from 4,951 to 2,764 lines and tighten its architecture budget from 5,000 to 3,000\n- extract episode repair planning, fetch, validation, and non-destructive apply into `episode_repair.cpp`\n- extract typed journal queries and stable result rendering into `query_render.cpp`\n- extract JSON compatibility codecs, validation, and typed option parsing into `json_compat.cpp`\n- register each source in the internal target graph with independent responsibility tokens and line budgets\n\n## Verification\n\n- `./shifu build:core`\n- `ctest --test-dir framework/core/build --output-on-failure --parallel 12` (12/12)\n- `./shifu check:source`\n- `SHIFU_CACHE_ACTIVE=1 ./shifu check`\n- `./shifu exec node framework/core/architecture/check-layers.mjs`\n- `./shifu exec node framework/core/architecture/check-layers.mjs --self-test` (14 fixtures)\n- macOS AppleClang full Core build including native, Node, Python, Wasmtime, and Wasmer artifacts\n- Linux GCC 14.2 full Core build and CTest 12/12 at pre-rebase code-bearing SHA `229a61b4a`\n- Windows MSVC 19.51 full Core build and CTest 12/12 at pre-rebase code-bearing SHA `229a61b4a`\n- rebased code-bearing SHA `0b9a328a8` has identical `framework/core/src` and `framework/core/architecture` trees to `229a61b4a`; the intervening base change only updates live-peer-continuity qualification files\n- final candidate `f801a38c3` differs from `0b9a328a8` only in ADR metadata; docs gate passes against the PR base\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Decompose the Core storage service facade into enforceable internal responsibility units while preserving public storage contracts.\",\n  \"verification\": [\"source and architecture gates\", \"native storage contract tests\", \"same-SHA Core builds on macOS, Linux, and Windows\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:34:29Z",
          "mergedAt": "2026-07-15T10:10:44Z",
          "additions": 2314,
          "deletions": 2210,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 115,
          "url": "https://github.com/kungfu-systems/kfd/pull/115",
          "title": "chore(release): accept Buildchain alpha 18 contract",
          "body": "## Summary\n\n- accept the published `v2-alpha` runtime at `6f1b17fac1e0182d1afa6ea9cfe3578e7a5e532c`\n- refresh the KFD-1, KFD-2, and KFD-3 self-evidence projections\n- keep the unpublished KFD version anchored at `1.0.0-alpha.24`\n\n## Verification\n\n- `npm run check`\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org/`\n- package contains 52 files, including `decisions/KFD-5.md` and `decisions/KFD-6.md`\n- `buildchain validate --require-version-state` with `@kungfu-tech/buildchain@2.12.7-alpha.18`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:11:21Z",
          "mergedAt": "2026-07-15T10:13:31Z",
          "additions": 14,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 116,
          "url": "https://github.com/kungfu-systems/kfd/pull/116",
          "title": "release(kfd): promote alpha 24",
          "body": "## Summary\n\nPromote the unpublished KFD `1.0.0-alpha.24` candidate through the corrected Buildchain `v2-alpha` publication path.\n\n## Included changes\n\n- keep KFD-5 and KFD-6 in the package surface\n- use the Buildchain alpha promotion shell\n- accept Buildchain `2.12.7-alpha.18` at immutable runtime `6f1b17fac1e0182d1afa6ea9cfe3578e7a5e532c`\n- refresh KFD-1, KFD-2, and KFD-3 self-evidence\n\n## Verification\n\n- `npm run check`\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org/`\n- Buildchain alpha.18 `validate --require-version-state`\n- Buildchain promotion run https://github.com/kungfu-systems/buildchain/actions/runs/29406644743\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:13:45Z",
          "mergedAt": "2026-07-15T10:17:17Z",
          "additions": 14,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 942,
          "url": "https://github.com/kungfu-systems/kungfu/pull/942",
          "title": "feat(kfx): add KFD-aware admission assessment",
          "body": "## Summary\n\nAdd a fail-closed native KFX admission assessment that consumes exact KFD lifecycle evidence and a pinned Buildchain verification result without creating a second trust evaluator.\n\n## Related issue\n\nAtlas goal `2026-07-15-kungfu-kfx-kfd-buildchain-admission`.\n\n## Changes\n\n- add the read-only Core `assess` operation with schema-closed trust inputs, policy, lifecycle checks, deterministic report/plan roots, and explicit operation/capability decisions\n- require a fresh purpose-bound ADR-0052 assessment whose report hash and query/contract/policy/fact roots bind the KFX qualification result\n- validate exact Buildchain verifier identity, contract, package/source/dependency/build-plan/toolchain/artifact/qualification roots, issuer/publisher allowlists, expiry, and revocation\n- expose one transport-only Storage projection through Python CLI, Python API, Node API, and KFX TypeScript types for GUI, TUI, KFX, and Agent consumers\n- add positive, downgrade, mismatch, revocation, cache-invalidation, capability-expansion, migration, and Product System fixtures plus a dedicated Shifu task\n- re-render the KFD-1/KFD-3 derived evidence after synchronizing the latest development base\n- correct the latest-base nested cache fixture so an explicit PATH override is checked against the effective original tool path instead of an inherited stale value\n- document the remaining producer boundary: Core validates a supplied pinned verifier result but does not yet execute or authenticate the Buildchain verifier\n\n## Verification\n\n- `./shifu rebuild:core`\n- `./shifu test:native-kfx-admission` (Core 1/1, Python 5/5, API transport 1/1, API/KFX type contracts)\n- `./shifu check:source` (325 Node tests, 76 runtime-upgrade tests, 69 desktop tests; source gate passed)\n- `./shifu check` (changed-scope gate passed; SDK contract audit 31/31)\n- Shifu cache contract group 47/47 after latest-base synchronization\n- staged DCO, documentation, C++, Python, and Biome checks passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0090\"],\n  \"summary\": \"Add a deterministic fail-closed KFX admission assessment over exact KFD lifecycle evidence and pinned Buildchain verification inputs while preserving the producer boundary.\",\n  \"verification\": [\"./shifu rebuild:core\", \"./shifu test:native-kfx-admission\", \"./shifu check:source\", \"./shifu check\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change consumes provenance and qualification evidence but does not publish, sign, deploy, install, activate, or mutate packages. Invalid, stale, mismatched, revoked, or unsupported evidence fails closed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:54:37Z",
          "mergedAt": "2026-07-15T10:24:50Z",
          "additions": 1258,
          "deletions": 46,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 946,
          "url": "https://github.com/kungfu-systems/kungfu/pull/946",
          "title": "feat(xinfa): compile bounded task projections",
          "body": "## Summary\n\nCompile bounded Human View, Task Chart/Agent Context, and GUI View projections from one verified Xinfa Atlas without creating a second authority.\n\n## Related issue\n\nAtlas goal `2026-07-15-xinfa-task-capsule-compiler`.\n\n## Changes\n\n- add deterministic bounded-hop Human/GUI projections and bounded-token Task Chart compilation\n- preserve Atlas root, cut, route status, evidence, omissions, and source-root parity across surfaces\n- add stable cut-preserving expansion handles and fail-closed projection verification\n- exclude `.xinfa/generated/**` from provider authority and document explicit successor-cut acceptance\n- add schemas, four-task golden qualification, standalone extraction coverage, and ADR-0096\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu xinfa:check`\n- `./shifu xinfa:standalone`\n- `./shifu docs:check:readonly`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0096\"],\n  \"summary\": \"Bounded projection compiler, Task Chart contract, expansion boundary, generated-output exclusion, and qualification are implemented for the Xinfa incubation slice\",\n  \"verification\": [\"./shifu check:source\", \"./shifu xinfa:check\", \"./shifu xinfa:standalone\", \"./shifu docs:check:readonly\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:20:04Z",
          "mergedAt": "2026-07-15T10:29:02Z",
          "additions": 2127,
          "deletions": 20,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1280,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1280",
          "title": "fix(release): admit managed consumer candidates",
          "body": "## Summary\n\n- generalize exact release-candidate admission assembly from Buildchain self-publication to explicitly opted-in managed consumers\n- require caller-owned RC evidence, a repository-local publisher workflow, matching npm package/target identity, and an explicit Gate aggregate or no-Gate decision\n- audit the caller control plane while binding the exact canonical Buildchain authority runtime\n- document the declarative consumer surface and regenerate the public site contract\n\n## Verification\n\n- `pnpm run check` (`620/620` tests, workflow lint, site contract, all action bundles)\n- `node --test tests/build-surface.test.mjs` (`78/78`)\n- `git diff --check`\n\nCloses #1279\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:28:52Z",
          "mergedAt": "2026-07-15T10:31:06Z",
          "additions": 153,
          "deletions": 67,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1281,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1281",
          "title": "release(buildchain): promote alpha 19",
          "body": "## Release intent\n\nPromote the managed-consumer sealed release-candidate admission capability to the Buildchain alpha channel.\n\n## Included\n\n- #1280 / #1279: fail-closed declarative admission for managed consumers\n- exact caller RC evidence and control-plane audit binding\n- explicit Gate aggregate or consumer no-Gate decision\n\n## Verification\n\n- dev Verify run 29408404929 passed\n- PR #1280 full check and Linux/Windows/macOS fixture matrix passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:32:26Z",
          "mergedAt": "2026-07-15T10:35:03Z",
          "additions": 153,
          "deletions": 67,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 117,
          "url": "https://github.com/kungfu-systems/kfd/pull/117",
          "title": "fix(release): adopt sealed Buildchain admission",
          "body": "## Summary\n\n- adopt Buildchain 2.12.7-alpha.19 through the v2-alpha contract lock\n- opt the KFD publisher workflow into managed-consumer sealed publication admission\n- refresh KFD-1/2/3 evidence against the accepted Buildchain runtime\n\n## Evidence\n\n- `npm run check`\n- `npm pack --dry-run --json`\n- `npm exec --package=@kungfu-tech/buildchain@2.12.7-alpha.19 -- buildchain validate --require-version-state`\n\nCloses the KFD release gap exposed by failed run 29407619802.\n\nBuildchain implementation: kungfu-systems/buildchain#1280\nBuildchain issue: kungfu-systems/buildchain#1279",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:48:04Z",
          "mergedAt": "2026-07-15T10:50:24Z",
          "additions": 24,
          "deletions": 18,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 947,
          "url": "https://github.com/kungfu-systems/kungfu/pull/947",
          "title": "fix(cache): unwrap nested uv projections",
          "body": "## Summary\n\n- preserve the first unwrapped UV PATH across nested Shifu cache projections\n- prevent release layer Gates from treating the outer managed wrapper as the real uv\n- cover the nested-wrapper path with a cross-platform regression fixture\n\n## Verification\n\n- `node --test scripts/shifu-uv-cache-adapter.test.mjs scripts/run-layer-artifact-gate.test.mjs`\n- exact nested `gate run layers.format layers.sdk layers.surfaces` no longer reports a missing UV adapter manifest\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Corrects nested UV cache wrapper discovery without changing architecture, release claims, or product behavior.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes qualification cache plumbing only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green\n- [x] No credentials or generated qualification evidence are committed\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:42:59Z",
          "mergedAt": "2026-07-15T10:50:25Z",
          "additions": 26,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 118,
          "url": "https://github.com/kungfu-systems/kfd/pull/118",
          "title": "release(kfd): promote alpha 24",
          "body": "## Release\n\nPromote KFD `1.0.0-alpha.24` from the active dev line to the active alpha line.\n\nThis promotion includes managed-consumer sealed Buildchain publication admission through `@kungfu-tech/buildchain@2.12.7-alpha.19`.\n\n## Expected publication\n\n- npm: `@kungfu-tech/kfd@1.0.0-alpha.24`\n- GitHub Release: `v1.0.0-alpha.24`\n- release passport and KFD-1/2/3 evidence\n- downstream release propagation",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:51:06Z",
          "mergedAt": "2026-07-15T10:56:25Z",
          "additions": 24,
          "deletions": 18,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1283,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1283",
          "title": "fix(release): preserve publication check context",
          "body": "## Summary\n\n- forward the exact protected-branch status check into sealed publication authority\n- add a regression assertion scoped to the publication-authority job\n- refresh the generated site contract\n\n## Verification\n\n- `node --test tests/build-surface.test.mjs` (78/78)\n- `pnpm run check` (620/620 plus workflow/site/action checks)\n\nCloses #1282.\n\nExposed by KFD promotion run: https://github.com/kungfu-systems/kfd/actions/runs/29409897208",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:06:00Z",
          "mergedAt": "2026-07-15T11:07:59Z",
          "additions": 9,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 948,
          "url": "https://github.com/kungfu-systems/kungfu/pull/948",
          "title": "fix(qualification): launch Windows Shifu suites via ComSpec",
          "body": "## Summary\n\n- launch runtime-activation Shifu suites through ComSpec on Windows\n- bind execution to the repository-local absolute `shifu.cmd` path\n- retain spawn failures in checksummed raw qualification logs\n\n## Validation\n\n- `node --test framework/core/tests/qualification/runtime-activation/run.test.mjs`\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Restores the existing Windows runtime-activation qualification launcher without changing runtime architecture or product claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR repairs qualification execution and retained diagnostics only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] No credentials or generated qualification evidence are committed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:03:21Z",
          "mergedAt": "2026-07-15T11:08:59Z",
          "additions": 47,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1284,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1284",
          "title": "release(buildchain): promote alpha 20",
          "body": "## Release\n\nPromote the next Buildchain v2.12 alpha containing exact protected-branch status-check propagation into sealed publication authority.\n\nFixes #1282 and unblocks KFD `1.0.0-alpha.24` publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:09:26Z",
          "mergedAt": "2026-07-15T11:11:43Z",
          "additions": 9,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 119,
          "url": "https://github.com/kungfu-systems/kfd/pull/119",
          "title": "fix(release): accept Buildchain alpha 20",
          "body": "## Summary\n\n- accept the exact Buildchain v2 alpha.20 runtime contract\n- preserve all 24 managed surface breaking digests\n- refresh KFD-1, KFD-2, and KFD-3 witnesses\n\n## Verification\n\n- `npm run check`\n- `npm exec --yes --package=@kungfu-tech/buildchain@2.12.7-alpha.20 -- buildchain validate --require-version-state`\n- `npm pack --dry-run --json`\n\nCloses the KFD-side follow-up to kungfu-systems/buildchain#1282 and kungfu-systems/buildchain#1283.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:21:07Z",
          "mergedAt": "2026-07-15T11:23:21Z",
          "additions": 14,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 120,
          "url": "https://github.com/kungfu-systems/kfd/pull/120",
          "title": "release(kfd): retry alpha 24",
          "body": "## Summary\n\nPromote the verified KFD dev line to alpha and retry the managed publication of `1.0.0-alpha.24`.\n\nThe previous publication stopped before npm/GitHub Release because the sealed authority received the wrong required check context. Buildchain `2.12.7-alpha.20` now preserves KFD's exact `check / check` context, and KFD has accepted that runtime contract.\n\n## Evidence\n\n- KFD dev verification: https://github.com/kungfu-systems/kfd/actions/runs/29411455687\n- Buildchain fix: https://github.com/kungfu-systems/buildchain/pull/1283\n- KFD contract acceptance: https://github.com/kungfu-systems/kfd/pull/119",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:24:02Z",
          "mergedAt": "2026-07-15T11:26:18Z",
          "additions": 14,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 950,
          "url": "https://github.com/kungfu-systems/kungfu/pull/950",
          "title": "feat(xinfa): add Shifu Kungfu dogfood path",
          "body": "## Summary\n\nAdd a bounded Xinfa self-dogfood path through Shifu and a read-only Kungfu projection consumer. The adapters delegate compiler and projection authority to the public Xinfa CLI.\n\n## Related issue\n\nAtlas goal 2026-07-15-xinfa-shifu-kungfu-dogfood.\n\n## Changes\n\n- Add a thin Shifu Documentation Protocol adapter for Xinfa Atlas compile and verify.\n- Add Human, Agent, and GUI materialization through one verified Atlas root.\n- Retain a fault campaign covering implementation drift, non-claim drift, feedback exclusion, and successor-only acceptance.\n\n## Verification\n\n- ./shifu xinfa:dogfood\n- ./shifu xinfa:check\n- ./shifu xinfa:standalone\n- ./shifu check:source\n- ./shifu docs:check:readonly\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0096\"],\n  \"summary\": \"Add the retained Shifu and Kungfu dogfood qualification path for the implemented Xinfa projection boundary.\",\n  \"verification\": [\"xinfa/qualification/shifu-kungfu-dogfood-v1.json\", \"./shifu check:source\", \"./shifu docs:check:readonly\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe retained receipt is explicitly non-qualifying and selfCertified=false; it does not create a release claim.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:30:49Z",
          "mergedAt": "2026-07-15T11:36:41Z",
          "additions": 1389,
          "deletions": 1,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 951,
          "url": "https://github.com/kungfu-systems/kungfu/pull/951",
          "title": "feat(core): define bounded build capability authority",
          "body": "## Summary\n\nEstablish a single machine-readable authority for bounded Kungfu Core build profiles and replace umbrella dependency propagation with target-scoped dependencies. The default full product remains the only qualified profile at this stage; planned profiles fail closed until their dedicated qualification stages land.\n\n## Related issue\n\nAtlas goal 2026-07-15-kungfu-core-build-capability-authority\n\n## Changes\n\n- define components, providers, projections, bindings, profiles, requirements, conflicts, defaults, and build identity in one authority\n- generate and drift-check CMake, human-readable, and manifest projections\n- thread the selected profile consistently through Shifu, Conan, and CMake\n- remove unconditional CONAN_LIBS usage in favor of generated target-local dependency sets\n- add positive and negative source-gate fixtures\n\n## Verification\n\n- ./shifu check:source\n- ./shifu rebuild:core on macOS arm64\n- KUNGFU_BUILD_PROFILE=journal ./shifu config fails closed with the intended unqualified-profile diagnostic\n- agent-120 Linux x86_64 full-profile build qualification\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0066\"],\n  \"summary\": \"Establish the bounded Core build-profile authority and replace umbrella dependency propagation with profile-scoped target dependencies while retaining full as the only supported default.\",\n  \"verification\": [\"./shifu check:source\", \"./shifu rebuild:core on macOS arm64\", \"negative planned-profile configure fixture\", \"agent-120 Linux x86_64 full-profile build\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe generated profile manifest adds deterministic build identity and source-gate evidence; no publication or deployment action is performed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:35:49Z",
          "mergedAt": "2026-07-15T11:44:16Z",
          "additions": 1022,
          "deletions": 41,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 952,
          "url": "https://github.com/kungfu-systems/kungfu/pull/952",
          "title": "fix(qualification): invoke Windows Shifu shim directly",
          "body": "## Summary\n\n- invoke Windows runtime-activation suites through ComSpec with the repository welded shim token left unquoted\n- quote only suite arguments and reject cmd expansion syntax\n- preserve spawn failures in checksummed raw qualification logs\n\n## Validation\n\n- `./shifu exec node --test framework/core/tests/qualification/runtime-activation/run.test.mjs` (9/9)\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source` (329 Node, 76 runtime upgrade, 69 desktop update; TypeScript and Biome passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Restores the existing Windows runtime-activation qualification launcher without changing runtime architecture or product claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR repairs qualification execution and retained diagnostics only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] No credentials or generated qualification evidence are committed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:04:02Z",
          "mergedAt": "2026-07-15T12:06:22Z",
          "additions": 22,
          "deletions": 13,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 122,
          "url": "https://github.com/kungfu-systems/kfd/pull/122",
          "title": "feat(kfd): add boundary-pressure discovery gates",
          "body": "## Summary\n- add an optional boundary-pressure diagnostic to active KFD-5 without redefining primitive sufficiency\n- require a falsifiable boundary hypothesis in draft KFD-6 autonomous discovery interface v2\n- refresh package metadata, site bundle, KFD-1/2/3 witnesses, and alpha.25 release facts\n\n## Compatibility\n- KFD-5 primitive-discovery schema remains v1 and backward compatible\n- KFD-6 draft experiment schema advances from v1 to v2 because `boundaryHypothesis` is required\n- the anchored outer KFD package line remains v1.0\n\n## Verification\n- `npm run check`\n- `buildchain validate --require-version-state` with Buildchain 2.12.7-alpha.20\n- AJV draft-2020 schema compilation for KFD-5 and KFD-6\n- `npm pack --dry-run --json`",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:11:32Z",
          "mergedAt": "2026-07-15T12:14:18Z",
          "additions": 431,
          "deletions": 214,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 123,
          "url": "https://github.com/kungfu-systems/kfd/pull/123",
          "title": "release(kfd): publish alpha 25",
          "body": "## Release\nPromote the exact `dev/v1/v1.0` state to `alpha/v1/v1.0`.\n\nPublishes `@kungfu-tech/kfd@1.0.0-alpha.25` with:\n- KFD-5 optional boundary-pressure diagnostic\n- KFD-6 autonomous-discovery experiment interface v2 with required boundary hypothesis\n- refreshed KFD-1/2/3 witnesses and site bundle\n\nThe package line remains anchored at v1.0. The KFD-6 interface migration is explicitly declared as a major surface impact.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:15:02Z",
          "mergedAt": "2026-07-15T12:17:29Z",
          "additions": 431,
          "deletions": 214,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1286,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1286",
          "title": "fix(checkout): isolate locked source fetch config",
          "body": "## Summary\n\nMake locked source fetches independent from mutable runner-global Git configuration. This prevents concurrent jobs from redirecting the same repository URL to another single-SHA bundle while preserving command-scoped authentication and an explicit safe.directory exception.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- ignore account-level and system Git config for every locked network fetch\n- inject the locked checkout path as command-scoped safe.directory configuration\n- preserve any command-scoped GitHub authentication configuration\n- add an end-to-end stale URL rewrite regression and focused environment assertions\n\n## Verification\n\n- `node --test tests/locked-source-checkout.test.mjs` (15 passed)\n- `pnpm run check` (622 unit tests passed; workflow checks and action builds passed)\n- `git diff --check`\n- Git for Windows read-only probe confirmed `GIT_CONFIG_GLOBAL=NUL` is accepted\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [x] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: the fetch environment may carry a command-scoped GitHub authorization header. The implementation preserves that entry without reading, logging, or persisting its value; the regression uses a redacted fixture value.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (behavior is covered by inline rationale and regression tests; no public interface changed)",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:17:11Z",
          "mergedAt": "2026-07-15T12:19:57Z",
          "additions": 125,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1287,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1287",
          "title": "release(buildchain): promote alpha 21",
          "body": "## Release\n\nPromote the next Buildchain v2.12 alpha containing isolated locked source fetch configuration. This prevents concurrent runner-global single-SHA bundle rewrites from redirecting a consumer checkout while preserving command-scoped authentication and safe.directory.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:20:43Z",
          "mergedAt": "2026-07-15T12:23:23Z",
          "additions": 125,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 954,
          "url": "https://github.com/kungfu-systems/kungfu/pull/954",
          "title": "fix(qualification): separate manual signing policy",
          "body": "## Summary\n\n- keep the complete alpha/release Buildchain qualification fail-closed on native signing and notarization\n- let trusted manual frozen-ref runs exercise the same functional and artifact Gates without importing production signing credentials into ordinary build runners\n- record the selected native upgrade policy in the retained qualification summary\n- retain all existing live Peer, runtime activation, zero-burden desktop, layer Gate, report, and compressed raw-log stages in manual runs\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add a fail-closed `--native-upgrade-policy required|skip` qualification option, defaulting to `required`\n- bind alpha/release pull requests to `required` and workflow dispatch to explicit `skip`\n- update the structured workflow binding and focused contract tests\n\n## Verification\n\n- `node --test scripts/run-release-qualification.test.mjs scripts/qualification-artifact-catalog.test.mjs` (15 passed)\n- `./shifu check:source` (build-free source gate passed)\n- staged repository gate passed during DCO commit\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Separates credential-bearing native signing policy by workflow event without changing the runtime, release identity, or architecture contracts.\"\n}\n-->\n\n## Governance risk check\n\n- [x] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: production signing and notarization remain mandatory only in the protected alpha/release PR gate. Manual validation records an explicit skip and never receives or handles signing credentials. No credentials, private logs, or generated qualification evidence are committed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n- [x] Source acceptance is green\n- [x] No credentials or generated qualification evidence are committed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:21:44Z",
          "mergedAt": "2026-07-15T12:23:57Z",
          "additions": 98,
          "deletions": 13,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 956,
          "url": "https://github.com/kungfu-systems/kungfu/pull/956",
          "title": "fix(qualification): budget complete hosted alpha gate",
          "body": "## Summary\n\n- raise the hosted alpha budget to cover the complete measured install, build, and qualification lifecycle\n- retain every gate, fuzz target, and Episode workload while reserving explicit upstream and variance allowances\n- bind the alpha budget contract in tests and record the exact hosted timing evidence\n\n## Validation\n\n- `./shifu exec node --test scripts/run-release-qualification.test.mjs scripts/check-kungfu-gate-catalog.test.mjs` (30/30)\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source` (329 Node, 76 runtime upgrade, 69 desktop update; TypeScript and Biome passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Calibrates the existing hosted alpha qualification budget from exact run evidence without changing architecture, gate workload, or product claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR adjusts qualification timing policy only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] No credentials or generated qualification evidence are committed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:42:50Z",
          "mergedAt": "2026-07-15T12:45:09Z",
          "additions": 37,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 82,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/82",
          "title": "feat(site): refresh KFD and paper bundles",
          "body": "## Summary\n\n- refresh the rendered KFD source to `@kungfu-tech/kfd@1.0.0-alpha.24`\n- refresh all three paper publication packages to their latest alpha bundles\n- regenerate lockfile inputs and Buildchain README badges for KFD-5 and KFD-6\n\n## Verification\n\n- `pnpm run build`\n- `pnpm run check`\n- local desktop and 390x844 mobile browser checks for KFD and papers surfaces\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:51:54Z",
          "mergedAt": "2026-07-15T12:46:00Z",
          "additions": 39,
          "deletions": 37,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 85,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/85",
          "title": "Release production from f8c09c09edc5",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `f8c09c09edc54abaca9f49f01adaf130d4e64f44`\n- Artifact hash: `45484e579d912474aca6f15ccf5a9b4abcee6ae6f9469d16423f20b3262c8908`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29416487352)\n- Required label: `buildchain-release`\n- Release branch: `release/production-f8c09c09edc5`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-15T12:53:35Z",
          "mergedAt": "2026-07-15T13:00:48Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1288,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1288",
          "title": "fix(checkout): support dumb HTTP cache mirrors",
          "body": "## Summary\n\nAllow locked source checkout to use static dumb HTTP Git mirrors without weakening the bounded GitHub fallback policy. Cache fetches first attempt the existing shallow fetch and retry without `--depth` only for Git's explicit dumb-HTTP capability error.\n\n## Related issue\n\nFollow-up to the multi-platform Kungfu qualification checkout diagnostics.\n\n## Changes\n\n- retry cache-mirror fetches without depth only when dumb HTTP rejects shallow capability negotiation\n- keep GitHub fallback fetches shallow and bounded\n- record the selected cache fetch mode in checkout evidence\n- cover the capability-specific fallback with a regression test\n\n## Verification\n\n- `pnpm run check` (624 tests passed; workflow checks and action builds passed)\n- focused locked source checkout tests (16 passed)\n- `git diff --check`\n- live `BUILDCHAIN_CHECKOUT_CACHE_MODE=require` checkout against the central HTTP mirror resolved the exact locked commit in 4.9 seconds with `transport=mirror-url`, `fetchMode=full`, `fallbackUsed=false`, and `githubFetchAttempts=0`\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe checkout evidence gains an explicit `fetchMode`; exact commit/tree verification remains fail-closed and is covered by both the full test suite and a live exact-ref mirror checkout.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not needed; internal transport compatibility and evidence field only)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:59:29Z",
          "mergedAt": "2026-07-15T13:01:56Z",
          "additions": 59,
          "deletions": 13,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1289,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1289",
          "title": "release(buildchain): promote alpha 22",
          "body": "## Release\n\nPromote the next Buildchain v2.12 alpha containing dumb HTTP cache-mirror capability fallback. Locked source checkout remains exact-ref and fail-closed, retries without depth only for Git's explicit dumb-HTTP shallow-capability error, and keeps GitHub fallback shallow and bounded.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T13:02:25Z",
          "mergedAt": "2026-07-15T13:04:41Z",
          "additions": 59,
          "deletions": 13,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 958,
          "url": "https://github.com/kungfu-systems/kungfu/pull/958",
          "title": "docs(adr): define Project Cut spacetime boundary",
          "body": "## Summary\n\nDefine the authority, identity, publication, and compatibility boundary for Project Cut without introducing a fourth primitive or a Git commit hash cycle.\n\n## Changes\n\n- Add ADR-0097 with the Git/Xinfa/Kungfu authority matrix and one-way dependency DAG.\n- Separate provider-native Episode roots from qualified cross-provider semantic equivalence.\n- Register the pre-release project-cut-protocol surface and route it from the documentation map.\n\n## Verification\n\n- ./shifu docs:check\n- ./shifu docs:prose:required\n- ./shifu check:source\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0097\"],\n  \"summary\": \"Freeze Project Cut authority, identity, cycle prevention, history, compatibility, and recovery constraints before schema implementation\",\n  \"verification\": [\"./shifu docs:check\", \"./shifu docs:prose:required\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T13:04:53Z",
          "mergedAt": "2026-07-15T13:10:59Z",
          "additions": 279,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 87,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/87",
          "title": "fix(site): derive surface channel from Buildchain",
          "body": "## Summary\n- stop deriving the site surface channel from GitHub event shape\n- consume the channel selected by the Buildchain web-surface release-intent gate\n- prevent release PR merges from rendering staging hosts into production artifacts\n\n## Verification\n- preview build/check: `pr-local.preview.libkungfu.dev`\n- staging build/check: `staging.libkungfu.dev`\n- production build/check: `libkungfu.dev`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-15T13:06:45Z",
          "mergedAt": "2026-07-15T13:16:15Z",
          "additions": 0,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 90,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/90",
          "title": "Release production from 8a835f62c2e7",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `8a835f62c2e7e47e5fec527f6d30c44a5b24b00e`\n- Artifact hash: `ef685b2fce018bec0c7252ab71b851535d8403e94ef38938f26145246cf7a72a`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29418490756)\n- Required label: `buildchain-release`\n- Release branch: `release/production-8a835f62c2e7`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-15T13:24:24Z",
          "mergedAt": "2026-07-15T13:32:01Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1290,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1290",
          "title": "Release v2.12.7 from qualified v2.12.7-alpha.22",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.12.7-alpha.22`\n- Candidate SHA: `40f808101be476b2f60611395b13c6e4520cb386`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.12`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T13:45:16Z",
          "mergedAt": "2026-07-15T13:48:51Z",
          "additions": 8145,
          "deletions": 407,
          "changedFiles": 73
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 960,
          "url": "https://github.com/kungfu-systems/kungfu/pull/960",
          "title": "fix(qualification): return from Windows Shifu shim",
          "body": "## Summary\n\n- invoke the welded Windows Shifu batch shim with `call` so nested qualification commands return to the Node harness\n- retain the unquoted shim token and argument quoting/expansion rejection from the prior Windows launcher fix\n- cover the exact `call shifu.cmd ...` payload in the launcher contract test\n\n## Hosted evidence\n\n- exact-source run `29416494142` passed build, product packaging, 42/42 base verify, three 90-second fuzz targets, and live-peer/native restart on Windows\n- the first runtime-activation suite then stopped at `Terminate batch job (Y/N)?`, proving the batch-return boundary was the remaining failure\n\n## Validation\n\n- `./shifu exec node --test framework/core/tests/qualification/runtime-activation/run.test.mjs` (9/9)\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source` (329 Node, 76 runtime upgrade, 69 desktop update; TypeScript and Biome passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repairs nested Windows batch return semantics in the existing qualification launcher without changing runtime architecture or product claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR repairs qualification execution only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] No credentials or generated qualification evidence are committed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T13:47:13Z",
          "mergedAt": "2026-07-15T13:49:01Z",
          "additions": 10,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1291,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1291",
          "title": "fix(evidence): omit stale reasons from qualifying receipts",
          "body": "## Summary\n\n- omit non-authorizing failure reasons from qualifying controller receipts\n- preserve reasons for failed, skipped, partial, or otherwise non-qualifying receipts\n- refresh the generated Node API and Buildchain contract digests\n\n## Evidence\n\nStable promotion run 29420873419 completed successfully, but its qualifying receipt retained `promotion-incomplete` because the workflow expression treated an empty success value as false. This core invariant prevents that contradictory evidence across all controller adapters.\n\n## Validation\n\n- `node --test tests/controller-evidence.test.mjs` (11 passed)\n- `pnpm run check` (624 unit tests passed; generated site and action builds passed)\n- `git diff --check`\n\nGenerated-by: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T13:57:57Z",
          "mergedAt": "2026-07-15T14:00:42Z",
          "additions": 8,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1292,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1292",
          "title": "release(buildchain): promote v2.12.8-alpha.0",
          "body": "## Release\n\nPromote the next Buildchain v2.12 alpha containing the controller receipt invariant from #1291. Qualifying receipts now omit stale non-authorizing failure reasons while failed, skipped, partial, and otherwise non-qualifying receipts preserve their diagnostics.\n\nThe stable v2.12.7 publication remains unchanged; this alpha is the forward-fix evidence for subsequent promotions.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T14:03:33Z",
          "mergedAt": "2026-07-15T14:05:44Z",
          "additions": 8,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 962,
          "url": "https://github.com/kungfu-systems/kungfu/pull/962",
          "title": "feat(project-cut): define canonical v1 contract",
          "body": "## Summary\n\nDefine and implement the build-free project.cut/v1 schema, canonical root, source projection policy, receipts, and stable failure diagnostics.\n\n## Changes\n\n- Add a closed Project Cut root input with a Project Cut-specific canonical JSON algorithm and explicit no-newline framing.\n- Add source projection and policy schemas, exact exclusions, golden roots, and 12 negative fixtures.\n- Separate semantic, serialization, artifact, and receipt identities; exclude publication coordinates and unknown fields from the semantic preimage.\n- Wire the contract and unit tests into the source acceptance gate and register ADR-0098.\n\n## Verification\n\n- node scripts/check-project-cut-contract.mjs\n- node --test scripts/check-project-cut-contract.test.mjs scripts/source-acceptance.test.mjs\n- node scripts/run-docs-check.mjs\n- node scripts/run-docs-prose-check.mjs --required\n- pinned Biome check over every changed JS and JSON file\n- ./shifu check:source: Project Cut, schema, documentation, and new tests passed; the local aggregate reported two unrelated dependency-worktree environment failures, so hosted CI is authoritative\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0098\"],\n  \"summary\": \"Freeze and implement the build-free Project Cut v1 schema, canonical root, source projection policy, receipts, fixtures, and diagnostics\",\n  \"verification\": [\"./shifu docs:check\", \"./shifu docs:prose:required\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T14:08:33Z",
          "mergedAt": "2026-07-15T14:12:47Z",
          "additions": 2458,
          "deletions": 2,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 955,
          "url": "https://github.com/kungfu-systems/kungfu/pull/955",
          "title": "feat(core): qualify composable build profiles",
          "body": "## Summary\n\nQualify bounded composable Core profiles and make RocksDB, SQLite projection responsibilities, live KV, bindings, and embedded custom providers explicit build-time capabilities while preserving the full product.\n\n## Related issue\n\nAtlas goals `2026-07-15-kungfu-rocksdb-provider-kv-decoupling`, `2026-07-15-kungfu-sqlite-projection-optionalization`, `2026-07-15-kungfu-embedded-custom-provider-qualification`, and parent `2026-07-15-kungfu-composable-core-build-profiles`.\n\n## Changes\n\n- condition Conan and CMake dependency roots from one bounded profile authority\n- isolate public live KV from RocksDB types and fail explicit missing providers closed\n- express SQLite projection, state-cache, and query-acceleration responsibilities separately\n- qualify journal, embedded-minimal, embedded-sqlite, and unchanged full profiles\n- expose machine-readable build identity including live capability and build root\n- add an instance-local public custom-provider registry and standalone CMake consumer\n- add Apple Clang, GCC, and MSVC matrix coverage for full and embedded-minimal\n\n## Verification\n\n- `./shifu check:source`\n- `KUNGFU_BUILD_PROFILE=embedded-minimal ./shifu rebuild:core`\n- `KUNGFU_BUILD_PROFILE=embedded-sqlite ./shifu rebuild:core`\n- `KUNGFU_BUILD_PROFILE=full ./shifu rebuild:core`\n- embedded-minimal custom-provider and causal fact-ledger CTest: 4/4\n- standalone custom-provider consumer configure/build/run on Apple Clang\n- full native CTest: 13/13\n- embedded-sqlite native CTest rerun: 13/13\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0066\"],\n  \"summary\": \"Qualify bounded composable Core profiles with optional RocksDB and explicit SQLite responsibility roots, embedded custom-provider composition, and retained machine-readable build identity while preserving the default full product.\",\n  \"verification\": [\"./shifu check:source\", \"macOS embedded-minimal, embedded-sqlite, and full rebuilds\", \"embedded custom-provider and fact-authority CTest\", \"three-platform full and embedded-minimal workflow\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes provider composition and build identity evidence only; it performs no publication or deployment action.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:30:31Z",
          "mergedAt": "2026-07-15T14:24:52Z",
          "additions": 1101,
          "deletions": 338,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 57,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/57",
          "title": "docs(paper): frame KFD around boundary primitives",
          "body": "## Summary\n\n- preserve KFD-1/2/3 as the ordered foundation and derive KFD-4/5/6 as procedures\n- define boundary pressure as a non-exclusive primitive-discovery diagnostic\n- compare Xinfa Atlas, Kungfu Episode, and Buildchain Release Passport as implementation-backed cases\n- compose the cases through Project Cut and add explicit claim, falsification, and maturity gates\n\n## Validation\n\n- `make check`\n- `make pdf` (15-page PDF; no overfull boxes)\n- citation-key completeness scan\n- rendered visual inspection of title, tables, equations, conclusion, and references\n\n## Evidence boundary\n\nKFD-6 remains draft, Project Cut remains partial, and the paper explicitly avoids historical, universal, or quantitative claims.\n\nGoal: 2026-07-15-foundation-paper-boundary-primitives-rewrite",
          "author": "dongkeren",
          "createdAt": "2026-07-15T14:31:28Z",
          "mergedAt": "2026-07-15T14:32:59Z",
          "additions": 877,
          "deletions": 482,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 59,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/59",
          "title": "release: prepare boundary primitives alpha.7",
          "body": "## Summary\n\nPrepare the next unused alpha for the boundary-primitives rewrite.\n\n## Version\n\n- `0.1.0-alpha.6` -> `0.1.0-alpha.7`\n- existing public versions and artifacts remain immutable\n\n## Validation\n\n- `make check`\n- npm and GitHub exact-version availability verified\n\nGoal: 2026-07-15-foundation-paper-boundary-primitives-rewrite",
          "author": "dongkeren",
          "createdAt": "2026-07-15T14:39:31Z",
          "mergedAt": "2026-07-15T14:40:38Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 60,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/60",
          "title": "release: promote boundary primitives paper alpha.7",
          "body": "## Promotion\n\nPromote the reviewed boundary-primitives rewrite and `0.1.0-alpha.7` declaration from the development line into the alpha publication channel.\n\n## Included\n\n- KFD-1/2/3 foundation with KFD-4/5/6 derived procedures\n- Xinfa Atlas, Kungfu Episode, and Buildchain Release Passport boundary cases\n- Project Cut composition and falsifiable evaluation program\n- next unused alpha version\n\n## Expected publication\n\n- npm: `@kungfu-tech/paper-kfd-foundation-real-world-agent-work@0.1.0-alpha.7`\n- GitHub prerelease: `v0.1.0-alpha.7`\n- PDF: `kfd-foundation-model.pdf`\n\nGoal: 2026-07-15-foundation-paper-boundary-primitives-rewrite",
          "author": "dongkeren",
          "createdAt": "2026-07-15T14:41:10Z",
          "mergedAt": "2026-07-15T14:42:23Z",
          "additions": 878,
          "deletions": 483,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1294,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1294",
          "title": "feat(core): add sealed KFX admission envelope",
          "body": "## Summary\n\n- add a versioned, sealed artifact-verification envelope that binds exact artifact/provenance roots, issuer and publisher identity, lifecycle, revocation, and an existing fresh KFD assessment\n- expose the same fail-closed verifier and direct KFX projection through Node and CLI without consumer-side field synthesis\n- keep existing `verifyArtifactPassport` callers compatible and add an opt-in sealed result\n- align release-line bootstrap impact metadata with a newly opened minor line\n\n## Verification\n\n- `pnpm run check`\n- `node --test tests/artifact-verification-envelope.test.mjs`\n- `node --test tests/release-passport.test.mjs`\n- `npm pack --dry-run --json`\n\n## Version impact\n\nMinor: opens the `v2.13` artifact-verification-envelope and package-subpath surfaces.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:02:32Z",
          "mergedAt": "2026-07-15T15:05:04Z",
          "additions": 1257,
          "deletions": 58,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1293,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1293",
          "title": "chore(release): promote v2.13 alpha",
          "body": "Buildchain release line bootstrap opened v2.13. Merge this channel PR to publish the first alpha for the new minor line.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T14:58:26Z",
          "mergedAt": "2026-07-15T15:08:17Z",
          "additions": 1329,
          "deletions": 128,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1296,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1296",
          "title": "fix(workflows): close current release blockers",
          "body": "## Summary\n\n- preserve `actions: read` through the nested web publication-authority call\n- stage the exact downstream propagation lock before checking for changes\n- isolate controller evidence from consumer version-state verification\n- bound reusable build jobs and lifecycle commands with one configurable timeout\n\n## Issues\n\nCloses #1295\nCloses #1285\nCloses #1223\nCloses #1131\n\n## Validation\n\n- `pnpm run check` (633 tests, workflow/action/site generation checks)\n- timeout regression covers command overrides and configured lifecycle stages\n- propagation regression covers first untracked lock and idempotent no-op detection\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:24:17Z",
          "mergedAt": "2026-07-15T15:28:58Z",
          "additions": 325,
          "deletions": 110,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 166,
          "url": "https://github.com/kungfu-systems/build-images/pull/166",
          "title": "feat(images): add pinned ClickHouse mirror",
          "body": "## Summary\n\n- add a build-images-owned ClickHouse 26.3.10.60-lts mirror pinned to the upstream Docker Hub digest\n- declare the image as pending its first reviewed publish\n- make selective publish and provenance tests derive the manifest family size\n\n## Verification\n\n- `pnpm run check`\n\nPart of #165. This bootstrap release establishes the immutable GHCR digest consumed by the final ClickHouse Phase A qualification release.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:27:18Z",
          "mergedAt": "2026-07-15T15:30:27Z",
          "additions": 103,
          "deletions": 21,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1297,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1297",
          "title": "chore(release): promote v2.13 fixes to alpha",
          "body": "## Summary\n\nPromote the completed v2.13 KFX admission envelope and all current issue repairs to the protected alpha channel.\n\n## Admission\n\n- Buildchain open issues: zero\n- feature PR: #1294\n- release blocker PR: #1296\n- local full check: 633 tests plus workflow, action bundle, inventory, and generated-site validation\n\nThe alpha publication remains governed by the post-merge Verify and Buildchain Ref Promotion workflows.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:32:08Z",
          "mergedAt": "2026-07-15T15:34:23Z",
          "additions": 325,
          "deletions": 110,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 169,
          "url": "https://github.com/kungfu-systems/build-images/pull/169",
          "title": "chore(buildchain): accept v2.12.8 alpha contract",
          "body": "## Summary\n\n- update the alpha Buildchain runtime to `2.12.8-alpha.0` and accept the current `v2-alpha` contract\n- update the stable runtime to `2.12.7` and refresh the `v2` contract lock\n- regenerate KFD123 evidence bound to both locks\n\n## Verification\n\n- `pnpm run check`\n\nCloses #167.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:36:08Z",
          "mergedAt": "2026-07-15T15:41:59Z",
          "additions": 36,
          "deletions": 36,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 963,
          "url": "https://github.com/kungfu-systems/kungfu/pull/963",
          "title": "feat(core): add git workspace episode provider",
          "body": "## Summary\n\nAdd a build-free Git Workspace Episode shadow provider that stores one qualified sealed Episode per immutable canonical JSONL segment without replacing yijinjing authority.\n\n## Changes\n\n- preserve the qualified journal-native Episode root while computing a separate provider root\n- use per-Episode generation leases and temp/fsync/atomic-rename publication\n- reject raw runtime/private material and require a safe `.kungfu/.gitignore`\n- add deterministic import/export, recovery, concurrency, and corruption fixtures\n- document the authority and capability boundary in ADR-0099\n\n## Verification\n\n- `node --test scripts/check-git-episode-provider.test.mjs scripts/source-acceptance.test.mjs` (21 passed)\n- `node scripts/adr-audit.mjs`\n- `node scripts/check-project-cut-contract.mjs`\n- `git diff --check`\n- `./shifu check:source` reached the dependency-backed Kungfu Gate catalog and stopped because local `yaml` is not installed; hosted CI must complete the full gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0099\"],\n  \"summary\": \"Implement the Git Workspace Episode shadow provider with immutable per-Episode JSONL segments and qualified root preservation\",\n  \"verification\": [\"Build-free provider contract and fault fixtures\", \"ADR registry audit\", \"Project Cut regression contract\", \"Hosted source acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe provider is shadow-only, rejects private/runtime bytes, and cannot advertise journal authority or recompute the Episode semantic root.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T14:52:05Z",
          "mergedAt": "2026-07-15T15:43:15Z",
          "additions": 1035,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1299,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1299",
          "title": "fix(release): install publication plan dependencies",
          "body": "## Summary\n- install promotion-source dependencies before exact version-state planning\n- keep pnpm, yarn, npm, and custom behavior aligned with the promote job\n- lock the install-before-plan ordering in workflow inventory and tests\n\n## Validation\n- corepack pnpm@11.7.0 run check\n- 633/633 unit tests passed\n- workflow validation and all four action bundles passed\n\nCloses #1298",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:46:20Z",
          "mergedAt": "2026-07-15T15:56:57Z",
          "additions": 76,
          "deletions": 14,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1300,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1300",
          "title": "chore(release): promote publication planner fix to alpha",
          "body": "## Summary\n- promote the exact publication-planner dependency fix from dev/v2/v2.13\n- retain the sealed KFX admission envelope and all prior v2.13 release-blocker fixes\n- restore alpha publication after the failed exact-version planning run\n\n## Evidence\n- dev Verify: https://github.com/kungfu-systems/buildchain/actions/runs/29430323213\n- fix PR Build Surface Fixture: https://github.com/kungfu-systems/buildchain/actions/runs/29429568411\n- open Buildchain issues: 0",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:03:32Z",
          "mergedAt": "2026-07-15T16:04:52Z",
          "additions": 76,
          "deletions": 14,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 171,
          "url": "https://github.com/kungfu-systems/build-images/pull/171",
          "title": "chore(release): join alpha.10 ancestry for ClickHouse bootstrap",
          "body": "## Summary\n- join the `v1.2.4-alpha.10` release commit into the current dev ancestry\n- preserve the current dev tree byte-for-byte\n- unblock the protected `dev/v1/v1.2` to `alpha/v1/v1.2` ClickHouse bootstrap promotion\n\n## Verification\n- `git diff origin/dev/v1/v1.2 HEAD --stat` is empty\n- merge parents are current dev `fff5b43` and alpha release `724e747`\n\nThis PR must be merged with its merge commit so the release ancestry remains explicit.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:57:23Z",
          "mergedAt": "2026-07-15T16:16:08Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 168,
          "url": "https://github.com/kungfu-systems/build-images/pull/168",
          "title": "chore(release): publish ClickHouse mirror bootstrap alpha",
          "body": "## Summary\n\nPromote the reviewed ClickHouse mirror bootstrap from `dev/v1/v1.2` to the alpha channel. This release establishes the immutable GHCR digest required by the final ClickHouse Phase A plan in #165.\n\n## Required release outputs\n\n- Buildchain v2 dual-channel promotion\n- Release Passport: `trust=pass`\n- GitHub release enabled\n- six-image publish evidence with only the new ClickHouse image built when the accepted lock permits reuse",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:31:37Z",
          "mergedAt": "2026-07-15T16:20:25Z",
          "additions": 213,
          "deletions": 131,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1303,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1303",
          "title": "fix(release): make alpha preflight race-safe",
          "body": "## Summary\n- keep dry-run exact version planning read-only when lifecycle verification materializes derived files\n- wait up to ten minutes for the exact merged channel PR's successful RC run and paired artifacts\n- retain strict PR/head matching and fail closed on timeout or sibling evidence\n\n## Validation\n- targeted promote/resolver tests: 123/123\n- full Buildchain check: 635/635 tests, workflow validation, generated site check, four action bundles\n\nCloses #1301\nCloses #1302",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:27:05Z",
          "mergedAt": "2026-07-15T16:29:09Z",
          "additions": 320,
          "deletions": 77,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1304,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1304",
          "title": "chore(release): promote race-safe alpha preflight",
          "body": "## Summary\n- promote read-only exact publication planning and bounded exact-PR RC polling\n- include the sealed KFX admission envelope and all v2.13 blocker fixes\n- retry alpha publication only after #1301 and #1302 are fixed and closed\n\n## Evidence\n- fix PR Build Surface Fixture: https://github.com/kungfu-systems/buildchain/actions/runs/29432456390\n- dev Verify: https://github.com/kungfu-systems/buildchain/actions/runs/29432597639\n- open Buildchain issues: 0",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:30:45Z",
          "mergedAt": "2026-07-15T16:35:09Z",
          "additions": 320,
          "deletions": 77,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 172,
          "url": "https://github.com/kungfu-systems/build-images/pull/172",
          "title": "fix(release): prefer workflow package token",
          "body": "## Summary\n- prefer the workflow-scoped `GITHUB_TOKEN` for GitHub Packages visibility reads\n- retain `GH_TOKEN` as the local fallback\n- contract-test the token precedence in `check-workflows.sh`\n\n## Root cause\nBuildchain v2.12.8 exposes the narrower ref-promotion credential as `GH_TOKEN`. The publisher selected it ahead of the workflow token, so the alpha.11 transaction pushed and anonymously smoke-tested `base-linux` but failed the package metadata check with `403 read:packages` before moving release refs.\n\nFailed transaction: https://github.com/kungfu-systems/build-images/actions/runs/29432207706\n\n## Verification\n- `bash -n scripts/verify-ghcr-public.sh scripts/check-workflows.sh`\n- `bash scripts/check-workflows.sh`\n- `pnpm run check`\n\nThe existing Buildchain transaction is resumable after this fix reaches the alpha source.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:30:05Z",
          "mergedAt": "2026-07-15T16:37:41Z",
          "additions": 9,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 173,
          "url": "https://github.com/kungfu-systems/build-images/pull/173",
          "title": "chore(release): join failed alpha.11 transaction ancestry",
          "body": "## Summary\n- join the failed alpha.11 channel merge into dev ancestry\n- preserve the current dev tree byte-for-byte\n- allow the GHCR token-precedence fix to enter a clean protected promotion PR\n\n## Evidence\n- failed transaction: https://github.com/kungfu-systems/build-images/actions/runs/29432207706\n- fix PR: #172\n- `git diff origin/dev/v1/v1.2 HEAD --stat` is empty\n\nThis PR must retain its merge commit so the alpha channel ancestry remains explicit.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:38:22Z",
          "mergedAt": "2026-07-15T16:42:35Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 174,
          "url": "https://github.com/kungfu-systems/build-images/pull/174",
          "title": "fix(release): resume alpha.11 with package token authority",
          "body": "## Summary\n- promote the GHCR package-token authority fix through the standard dev-to-alpha channel\n- resume the durable alpha.11 publish transaction after its safe pre-ref failure\n- retain the first-party ClickHouse image as the new six-image family member\n\n## Evidence\n- failed transaction (no release ref moved): https://github.com/kungfu-systems/build-images/actions/runs/29432207706\n- token fix: #172\n- ancestry closure: #173\n- local full check: `pnpm run check`\n\nExpected Buildchain behavior: reuse the already-pushed matching base image where valid, complete the family, verify public anonymous pulls, publish evidence and Release Passport, then move exact/floating refs.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:42:53Z",
          "mergedAt": "2026-07-15T16:46:18Z",
          "additions": 9,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1306,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1306",
          "title": "fix(release): preserve promotion authority on new lines",
          "body": "## Summary\n\n- carry declared promotion bypass apps, users, and teams into release-line branch protection\n- fail closed before protection changes when no promotion authority is declared\n- document and test the new-line publication authority invariant\n\nCloses #1305\n\n## Validation\n\n- `pnpm run check` (635 tests; workflow/site/inventory checks and all action bundles passed)\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:48:09Z",
          "mergedAt": "2026-07-15T16:49:26Z",
          "additions": 56,
          "deletions": 14,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 965,
          "url": "https://github.com/kungfu-systems/kungfu/pull/965",
          "title": "feat(release): close workflow publication authority",
          "body": "## Summary\n\nClose Kungfu's GitHub Actions execution surface into one machine-checked authority inventory and add an independent consumer predicate for sealed product publication.\n\n## Changes\n\n- classify all 15 workflows, 24 jobs, and 82 steps with exact activation, permission, credential, external-action, and definition digests\n- reject unknown workflows/jobs/steps, one-sided activation or permission drift, mutable authority-bearing refs, qualification jobs with inherited secrets, and qualification Environment access\n- pin source/build/promotion controllers to Buildchain 2.12.7 and reduce write/OIDC/secret scope to the smallest declared jobs\n- independently reverify source, current Gate policy, Buildchain runtime/contract, controller receipt, three-platform Gate aggregate, runner provenance, live control-plane audit, artifact bytes, channel, freshness, and nonce replay\n- document workflow authority and release admission, and register SHIFU-ADR-0007\n\n## Verification\n\n- `./shifu check:gate-catalog`\n- `./shifu test:release-admission`\n- `./shifu check:source`\n- staged pre-commit gate, documentation contract, ADR audit, Biome, and KFD evidence checks\n\n## Current publication boundary\n\nThis PR makes missing sealed inputs fail closed and does not execute a product publication. Successful live cutover remains stage-ready until Buildchain transports the complete Gate aggregate/capability through a consumer-owned predicate immediately before the provider write; no static or no-Gate fallback is introduced here.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0007\"],\n  \"summary\": \"Close Kungfu workflow authority and stage a project-owned sealed release-admission predicate while preserving fail-closed publication until the upstream capability handoff exists.\",\n  \"verification\": [\"./shifu check:gate-catalog\", \"./shifu test:release-admission\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes release authority and verification contracts only; it performs no product publication or deployment.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] Documentation and negative fixtures are included\n- [x] No credential values or generated live evidence are committed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:20:23Z",
          "mergedAt": "2026-07-15T16:51:06Z",
          "additions": 2936,
          "deletions": 70,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 968,
          "url": "https://github.com/kungfu-systems/kungfu/pull/968",
          "title": "feat(xinfa): admit qualified Episode evidence",
          "body": "## Summary\n\nAdd a standalone Xinfa Episode evidence provider that admits only qualified, sealed public Git Workspace Episode segments into a deterministic successor Atlas without becoming Episode authority.\n\n## Related issue\n\nADR-0100\n\n## Changes\n\n- add `xinfa.episode-provider-submission/v1`, `xinfa.review-chart/v1`, and `xinfa episode compile`\n- verify public Git provider, qualification, canonical JSONL, and all recorded roots before source closure\n- compile explicit Mission/Go declarations, proof/receipt refs, and review findings through the existing Repository Pack to Atlas authority path\n- preserve existing Atlas and Context Pack roots while adding isolated impact/invalidation and anti-feedback fixtures\n- retain standalone CLI qualification and public extraction boundaries\n\n## Verification\n\n- `./shifu xinfa:check` — 33 Rust tests plus boundary and lint gates passed\n- `./shifu xinfa:standalone` — extracted Cargo build/test and real Episode successor-Atlas CLI smoke passed\n- `./shifu docs:check:readonly` — 62 documentation contract tests passed\n- `./shifu check:source` — 344 source contract tests, 76 runtime-upgrade tests, 69 desktop-update tests, TypeScript, Biome, and all source gates passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0100\"],\n  \"summary\": \"Deliver the qualified Xinfa Episode evidence provider and successor Atlas contract\",\n  \"verification\": [\"Xinfa check and standalone qualification\", \"source acceptance\", \"documentation contract gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe provider/CLI boundary consumes only public schemas and explicitly refuses private, runtime, generated, missing, open, unverified, and raw-transcript inputs.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:44:12Z",
          "mergedAt": "2026-07-15T16:55:01Z",
          "additions": 1812,
          "deletions": 5,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 175,
          "url": "https://github.com/kungfu-systems/build-images/pull/175",
          "title": "fix(release): trust anonymous GHCR manifest proof",
          "body": "## Summary\n- remove the GitHub Packages metadata API from the release publicness gate\n- retain anonymous GHCR token issuance plus manifest `200` and immutable digest as the direct authority\n- contract-test that public verification has no package API scope dependency\n\n## Root cause\nBoth the narrower promotion credential and the workflow `GITHUB_TOKEN` receive `403` from the org package metadata endpoint for historical packages. The same images are anonymously pullable, which is the actual consumer contract and conclusively fails for private images.\n\nFailed transactions:\n- https://github.com/kungfu-systems/build-images/actions/runs/29432207706\n- https://github.com/kungfu-systems/build-images/actions/runs/29433955836\n\n## Verification\n- `bash -n scripts/verify-ghcr-public.sh scripts/check-workflows.sh`\n- `bash scripts/check-workflows.sh`\n- `pnpm run check`",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:53:52Z",
          "mergedAt": "2026-07-15T17:03:09Z",
          "additions": 5,
          "deletions": 30,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 176,
          "url": "https://github.com/kungfu-systems/build-images/pull/176",
          "title": "chore(release): join failed alpha.12 transaction ancestry",
          "body": "## Summary\n- join the failed alpha.12 channel merge into dev ancestry\n- preserve the current dev tree byte-for-byte\n- unblock the anonymous-GHCR-authority fix for protected promotion\n\n## Evidence\n- failed transaction: https://github.com/kungfu-systems/build-images/actions/runs/29433955836\n- publicness authority fix: #175\n- `git diff origin/dev/v1/v1.2 HEAD --stat` is empty\n\nThis PR must retain its merge commit.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:03:45Z",
          "mergedAt": "2026-07-15T17:07:38Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 177,
          "url": "https://github.com/kungfu-systems/build-images/pull/177",
          "title": "fix(release): publish with anonymous GHCR authority",
          "body": "## Summary\n- promote the direct anonymous-GHCR publicness proof through the standard dev-to-alpha channel\n- close failed alpha.12 ancestry before promotion\n- publish the first-party ClickHouse mirror as part of the six-image family\n\n## Evidence\n- anonymous authority fix: #175\n- failed transaction ancestry closure: #176\n- local full check: `pnpm run check`\n\nExpected release result: Buildchain publishes the next exact alpha, verifies all six image manifests anonymously, emits `evidence.json` and a trusted Release Passport, then moves exact/floating refs.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:08:03Z",
          "mergedAt": "2026-07-15T17:10:43Z",
          "additions": 5,
          "deletions": 30,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 178,
          "url": "https://github.com/kungfu-systems/build-images/pull/178",
          "title": "fix(release): allow declared first package publish",
          "body": "## Summary\n- distinguish a first-party package that is not yet publicly addressable from ordinary GHCR auth failures\n- allow token-stage `403/404` only when the image manifest declares `pending-first-publish`\n- keep all ordinary package token failures fail-closed\n- add positive and negative provenance fixtures\n\n## Root cause\nThe ClickHouse package does not exist yet. GHCR returns `403` at anonymous token issuance before any manifest request, while `--allow-missing` previously handled only a manifest-level `404`.\n\nFailed transaction: https://github.com/kungfu-systems/build-images/actions/runs/29435586702\n\n## Verification\n- `python3 -m py_compile scripts/ghcr-manifest.py scripts/test-publish-provenance.py`\n- `bash -n scripts/build-image-family.sh`\n- `python3 scripts/test-publish-provenance.py` (9 fixtures)\n- `pnpm run check`",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:22:03Z",
          "mergedAt": "2026-07-15T17:24:48Z",
          "additions": 88,
          "deletions": 18,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 179,
          "url": "https://github.com/kungfu-systems/build-images/pull/179",
          "title": "chore(release): join failed alpha.13 transaction ancestry",
          "body": "## Summary\n- join the failed alpha.13 channel merge into dev ancestry\n- preserve the current dev tree byte-for-byte\n- unblock the declared first-package fix for protected promotion\n\n## Evidence\n- failed transaction: https://github.com/kungfu-systems/build-images/actions/runs/29435586702\n- first-package fix: #178\n- `git diff origin/dev/v1/v1.2 HEAD --stat` is empty\n\nThis PR must retain its merge commit.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:25:16Z",
          "mergedAt": "2026-07-15T17:28:08Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 180,
          "url": "https://github.com/kungfu-systems/build-images/pull/180",
          "title": "fix(release): complete declared ClickHouse first publish",
          "body": "## Summary\n- promote the manifest-gated first-package handling through the standard dev-to-alpha channel\n- retain fail-closed handling for every non-declared GHCR token failure\n- publish and verify the complete six-image family\n\n## Evidence\n- first-package fix and negative test: #178\n- alpha.13 failure ancestry closure: #179\n- local full check: `pnpm run check`\n\nExpected result: first-party `clickhouse-server` package creation, six anonymous manifest proofs, durable publish evidence, trusted Release Passport, and exact alpha ref movement.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:28:20Z",
          "mergedAt": "2026-07-15T17:31:34Z",
          "additions": 88,
          "deletions": 18,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 964,
          "url": "https://github.com/kungfu-systems/kungfu/pull/964",
          "title": "fix(core): probe Windows liveness without signaling",
          "body": "## Summary\n\n- probe Windows lock-holder liveness through `OpenProcess` / `GetExitCodeProcess` instead of `os.kill(pid, 0)`\n- use psutil's non-signaling PID query for runtime service adoption checks\n- anchor contract registry discovery at the module directory and make interrupted Windows table guards close without unlocking a lock they never acquired\n- retain the welded Windows `call shifu.cmd` qualification surface\n\n## Root cause and evidence\n\n- hosted runs `29416494142`, `29420852660`, and self-hosted run `29422161962` reproduced `Terminate batch job` during the concurrent `activation-core` case\n- verbose run `29426977705` exposed one independent Windows source-discovery defect, fixed here by starting at `contract.py`'s parent\n- exact-topology run `29429837068` then exposed the decisive causal chain: the second activation caller invokes `_pid_alive(holder_pid)`; on Windows `os.kill(pid, 0)` is `CTRL_C_EVENT`, so the liveness probe interrupts every process sharing the console, including pytest and the outer batch\n- the same run showed expected lock contention (`PermissionError` from `LK_NBLCK`) immediately before the Ctrl-C cascade; the lock was an effect/observer, not cross-thread business coupling\n\n## Validation\n\n- focused contract, coordination lock, runtime broker, and runtime service suite: 72 passed\n- Windows-like regressions assert PID liveness probes never call `os.kill(pid, 0)`\n- Ruff format/lint, `git diff --check`, and staged source acceptance hook passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repairs Windows process-liveness and contract discovery behavior without changing runtime architecture or product claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR repairs qualification and runtime liveness observation only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] No credentials or generated qualification evidence are committed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:13:42Z",
          "mergedAt": "2026-07-15T17:39:37Z",
          "additions": 96,
          "deletions": 11,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 181,
          "url": "https://github.com/kungfu-systems/build-images/pull/181",
          "title": "chore(images): accept v1.2.4-alpha.14 digests",
          "body": "## Summary\n\n- accept all six immutable image digests published by `v1.2.4-alpha.14`\n- retire the ClickHouse `pending-first-publish` marker now that the package is publicly resolvable\n- refresh generated KFD witnesses against the accepted image lock\n\n## Release evidence\n\n- release: https://github.com/kungfu-systems/build-images/releases/tag/v1.2.4-alpha.14\n- publish run: https://github.com/kungfu-systems/build-images/actions/runs/29437027447\n- Release Passport: `ok=true`, `trust=pass`, `issues=[]`\n- ClickHouse: `ghcr.io/kungfu-systems/build-images/clickhouse-server@sha256:964dfcdf7f33ed509f50757061456618e1a13d99340e86c678130f9bd235cdc8`\n\n## Validation\n\n- `pnpm run check`\n- image-lock baseline remains eligible as a reviewed lock acceptance\n\nRefs #165",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:48:20Z",
          "mergedAt": "2026-07-15T17:51:32Z",
          "additions": 99,
          "deletions": 78,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 182,
          "url": "https://github.com/kungfu-systems/build-images/pull/182",
          "title": "feat(comparator): qualify ClickHouse Phase A",
          "body": "## Summary\n\n- add the production ClickHouse Phase A qualification plan for 3 repetitions across 21 job/tier scenarios\n- add a registry-bound ClickHouse workload adapter, fixture, oracle, and semantic verifier\n- generalize the qualification runner to resolve multiple adapters without weakening digest or identity checks\n- add the ClickHouse 3x21 qualification job to the comparator workflow\n- pin the subject to the accepted build-images digest from `v1.2.4-alpha.14`\n\n## Scope boundary\n\nThis PR establishes containerized user-outcome qualification. Native-host performance, fresh-install cost, final scoring, and winner declarations remain out of scope.\n\n## Validation\n\n- `pnpm run check`\n- 49 comparator unit/integration tests\n- both PostgreSQL and ClickHouse production plans validate against fixed input digests\n- KFD123 and alpha/stable contract locks unchanged\n\n## Release input\n\n- ClickHouse image: `ghcr.io/kungfu-systems/build-images/clickhouse-server@sha256:964dfcdf7f33ed509f50757061456618e1a13d99340e86c678130f9bd235cdc8`\n- source release: https://github.com/kungfu-systems/build-images/releases/tag/v1.2.4-alpha.14\n\nRefs #165",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:53:53Z",
          "mergedAt": "2026-07-15T18:13:06Z",
          "additions": 2189,
          "deletions": 108,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 183,
          "url": "https://github.com/kungfu-systems/build-images/pull/183",
          "title": "release(alpha): publish ClickHouse Phase A qualification",
          "body": "## Summary\n\n- publish the production ClickHouse Phase A 3x21 qualification surface\n- bind the plan to the accepted first-party ClickHouse image from `v1.2.4-alpha.14`\n- ship multi-adapter bundle closure and digest-bound dynamic semantics verification\n- retain the split authority boundary: user-outcome qualification only\n\n## Qualification evidence\n\n- implementation: #182\n- lifecycle run: https://github.com/kungfu-systems/build-images/actions/runs/29438476318\n- retained artifact: https://github.com/kungfu-systems/build-images/actions/runs/29438476318/artifacts/8352828032\n- 3 repetitions, 63/63 steps passed\n- 63/63 cleanup proofs passed; zero scoped containers, volumes, and networks remain\n- offline bundle verification passed with `user_outcome_qualification_authority=true`\n- native performance, fresh-install cost, and final scoring authority remain false\n\n## Required release outputs\n\n- Buildchain v2 dual-channel promotion\n- GitHub release enabled\n- Release Passport with `trust=pass`\n- exact source and qualification contract binding for clean-tag replay on agent-120\n\nRefs #165",
          "author": "dongkeren",
          "createdAt": "2026-07-15T18:13:38Z",
          "mergedAt": "2026-07-15T18:17:01Z",
          "additions": 2288,
          "deletions": 186,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1308,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1308",
          "title": "fix(build): retain lifecycle failure evidence",
          "body": "## Summary\n- upload lifecycle evidence directly when install/build/verify fails\n- cover both native and Linux-container jobs\n- keep the existing success publication and relay behavior unchanged\n\n## Validation\n- node --test tests/build-surface.test.mjs\n- corepack pnpm run check:workflows\n- git diff --check\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T18:21:55Z",
          "mergedAt": "2026-07-15T18:27:51Z",
          "additions": 38,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 966,
          "url": "https://github.com/kungfu-systems/kungfu/pull/966",
          "title": "refactor(core): define bounded domain components",
          "body": "## Summary\n\nReplace the coarse Core service and adapter buckets with a bounded, machine-checked domain component graph while preserving the production source set and the public libkungfu facade.\n\n## Related issue\n\nAtlas child goal `2026-07-15-kungfu-domain-component-graph` and parent `2026-07-15-kungfu-core-architecture-level5`.\n\n## Changes\n\n- define 11 production components within an enforced 6-12 component budget\n- generate 11 real internal CMake targets from the architecture authority\n- require every component to declare an owner, entry points, and contract tests\n- reject component and target cycles, undeclared target edges, missing CMake evidence, and source ownership drift\n- map every production architecture component into the build-profile authority\n- split the view adapter into an independently linkable target without the libkungfu facade\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu build:core`\n- architecture and build-capability negative fixtures\n- `kungfu_view_component_link_tests`, `yijinjing_mmap_tests`, and `yijinjing_content_hash_tests`: 3/3\n- production source-set equality: 54 before and 54 after\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0066\"],\n  \"summary\": \"Replace coarse Core build buckets with a bounded domain component and target graph, preserving the public facade and production source set.\",\n  \"verification\": [\"./shifu check:source\", \"./shifu build:core\", \"independent view component link test\", \"architecture and build-profile negative fixtures\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:35:36Z",
          "mergedAt": "2026-07-15T18:32:38Z",
          "additions": 552,
          "deletions": 147,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 969,
          "url": "https://github.com/kungfu-systems/kungfu/pull/969",
          "title": "feat(project-cut): add agent-first settlement",
          "body": "## Summary\n\nAdd an agent-first Project Cut settlement surface that binds the Git index, qualified Episode providers, and a verified Xinfa successor Atlas without changing `project.cut/v1` or making hooks authoritative.\n\n## Related issue\n\nADR-0101\n\n## Changes\n\n- add versioned settlement request, plan, state, action-receipt, and contract roots\n- prepare deterministic cuts from a temporary stage-0 index snapshot with explicit dry-run, execute, and exact-stage boundaries\n- verify public Xinfa Atlas and Git Episode provider roots without reinterpreting their native root algorithms\n- distinguish sealed-unpublished from published commit observation and add headless commit reconcile\n- add optional thin pre/post-commit adapters that call the same public core and report `authority: false`\n- weld focused tests and contract checks into source acceptance, including a real Xinfa successor-Atlas integration\n\n## Verification\n\n- `./shifu check:project-cut-settlement` — 4 schemas and the settlement contract root verified\n- `./shifu test:project-cut-settlement` — 6 deterministic, recovery, privacy, hook, CLI, and reconcile tests passed\n- `./shifu test:project-cut-settlement:integration` — real Xinfa successor Atlas compile/verify and staged settlement passed\n- `./shifu docs:check:readonly` — documentation contracts passed\n- `./shifu check:source` — 355 source contract tests, 76 runtime-upgrade tests, 69 desktop-update tests, TypeScript, Biome, and all source gates passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0101\"],\n  \"summary\": \"Deliver agent-first Project Cut settlement and stage-0 recovery without hook authority\",\n  \"verification\": [\"Project Cut settlement contract and focused tests\", \"real Xinfa successor Atlas integration\", \"source acceptance\", \"documentation contract gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe CLI consumes only tracked public source/provider material, rejects private paths, never commits or pushes caller code, and keeps hook state local and rebuildable.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:40:17Z",
          "mergedAt": "2026-07-15T19:27:14Z",
          "additions": 2412,
          "deletions": 9,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 971,
          "url": "https://github.com/kungfu-systems/kungfu/pull/971",
          "title": "feat(core): govern public contract compatibility",
          "body": "## Summary\n\nClassify every exported Core contract and add executable compatibility evidence for stable C ABI, public headers, retained journal layout, binding parity, and deprecation policy without freezing the experimental C++ ABI.\n\n## Related issue\n\nAtlas child goal `2026-07-15-kungfu-public-contract-compatibility` and parent `2026-07-15-kungfu-core-architecture-level5`.\n\n## Changes\n\n- extend the single Core architecture authority with public header, stable symbol, layout/schema, binding, and deprecation inventories\n- generate the public header compilation projection from that authority\n- freeze independently compiled old C consumers for embedding v1-v3 and native-storage v1 negotiation\n- retain and verify the journal-wire-v1 layout fixture\n- fail closed on header classification, stable symbol, binding parity, fixture, or deprecation-ledger drift\n- preserve `libyijinjing` as source-embedding-only with no shared ABI promise\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu build:core`\n- `./shifu test:mmap`\n- `ctest --test-dir framework/core/build -R 'yijinjing_(custom_provider|fact_authority|mmap)|kungfu_public_contract_compatibility' --output-on-failure` (6/6)\n- public-contract compatibility negative fixtures\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0066\"],\n  \"summary\": \"Classify Core public contracts and retain executable stable C ABI, public-header, journal-layout, binding-parity, and deprecation evidence.\",\n  \"verification\": [\"./shifu check:source\", \"./shifu build:core\", \"./shifu test:mmap\", \"public contract compatibility CTest 6/6\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T18:42:45Z",
          "mergedAt": "2026-07-15T21:14:08Z",
          "additions": 1023,
          "deletions": 12,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 973,
          "url": "https://github.com/kungfu-systems/kungfu/pull/973",
          "title": "feat(core): gate affected native changes",
          "body": "## Summary\n\nTurn Core architecture ownership into a deterministic affected-native development gate that resolves changed paths to the smallest supported profile, native targets, and contract tests while failing closed on unknown impact.\n\n## Related issue\n\nAtlas child goal `2026-07-15-kungfu-affected-native-pr-gate` and parent `2026-07-15-kungfu-core-architecture-level5`.\n\n## Changes\n\n- resolve implementation, header, public-contract, schema, build, and architecture changes through the single Core authority\n- compile, link, and test the bounded closure on GitHub-hosted `ubuntu-24.04`\n- retain source, authority, profile, toolchain, cache, timing, plan, step, and raw-log evidence in a verified receipt\n- require the same `source.changed-scope` Gate locally and in CI\n- emit a valid tier-none receipt for outside-Core PRs so the protected required check cannot deadlock\n- enforce a 20-minute budget, 25-minute timeout, and maximum parallelism of 12 without deleting required tests\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu core:affected -- --self-test` (8/8 determinism and failure fixtures)\n- outside-Core tier-none receipt generation and verification\n- agent-120 Linux execution: passed in 243,184 ms (Conan 129,607 ms; build 113,055 ms; CTest 115 ms)\n- `./shifu build:core`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0066\"],\n  \"summary\": \"Add a deterministic, fail-closed affected-native development gate with retained plan, build, test, timing, and cache evidence.\",\n  \"verification\": [\"./shifu check:source\", \"./shifu core:affected -- --self-test\", \"agent-120 affected-native receipt passed in 243184 ms\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T21:21:04Z",
          "mergedAt": "2026-07-15T22:46:35Z",
          "additions": 998,
          "deletions": 35,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1309,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1309",
          "title": "chore(release): promote v2.12 failure evidence retention to alpha",
          "body": "Promotes the merged failure-evidence retention workflow from dev/v2/v2.12 to alpha/v2/v2.12.\\n\\nEvidence:\\n- PR #1308 merged at c2571d8df5b90ecd542695b64644e6423eb42358\\n- pnpm check passed (624 tests)\\n- reusable build workflow uploads lifecycle evidence on failure\\n\\nThis is the governed channel promotion required before downstream Kungfu alpha qualification can consume the outer workflow change.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T23:28:46Z",
          "mergedAt": "2026-07-15T23:33:17Z",
          "additions": 38,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 974,
          "url": "https://github.com/kungfu-systems/kungfu/pull/974",
          "title": "feat(core): expose architecture query and health",
          "body": "## Summary\n\nExpose the Level-5 Core architecture authority as a stable offline query, generated navigation/review projections, and baseline-ratcheted health report, while documenting the exact build-profile and source-responsibility trimming controls.\n\n## Related issue\n\nAtlas child goal `2026-07-15-kungfu-architecture-query-health-ownership` and parent `2026-07-15-kungfu-core-architecture-level5`.\n\n## Changes\n\n- query architecture by path, component, target, stable symbol, error text, capability, or build profile with human and JSON output\n- return ownership, entry points, dependencies, targets, profiles, tests, public surfaces, diagnostics, docs, runbooks, ADRs, products, and impact reasons\n- generate the architecture index, review routes, and health report from the same authority\n- ratchet cycles, fan-out, public propagation, responsibility utilization, affected-native duration, and external dependency closure; retain explicit advisory reasons for churn and binary size\n- fail visibly on missing owners, missing backup review, cycles, unknown navigation, projection drift, or health regression\n- document build-profile selection and `service.cpp`/episode/query-render/JSON-compatibility source responsibility budgets\n\n## Verification\n\n- `./shifu check:source`\n- `KUNGFU_BUILD_PROFILE=full ./shifu rebuild:core`\n- `ctest --test-dir framework/core/build -R '^(kungfu_durability_contract_tests|kungfu_public_contract_compatibility_tests|kungfu_view_component_link_tests|yijinjing_custom_provider_qualification)$' --output-on-failure` (4/4)\n- `./shifu core:architecture --self-test`\n- `./shifu core:architecture:health`\n- representative path, symbol, error, capability, and profile queries\n- GitHub-hosted affected-native receipt: 610,610 ms against a 1,200,000 ms budget; the earlier agent-120 observation remains retained\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0066\"],\n  \"summary\": \"Expose offline Core architecture query, ownership routing, generated navigation, and baseline-ratcheted health from one authority.\",\n  \"verification\": [\"./shifu check:source\", \"KUNGFU_BUILD_PROFILE=full ./shifu rebuild:core\", \"architecture query self-test\", \"representative Core CTest 4/4\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T22:59:14Z",
          "mergedAt": "2026-07-15T23:55:04Z",
          "additions": 1064,
          "deletions": 3,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 184,
          "url": "https://github.com/kungfu-systems/build-images/pull/184",
          "title": "feat(images): add Aeron native qualification kit",
          "body": "## Summary\n\n- add a release-owned Aeron 1.52.2 native qualification kit image\n- pin the compiler JDK, runtime JRE, Aeron JAR, and noninteractive harness\n- retain the first-publish lock so production plans cannot self-reference an unpublished digest\n- extend selective-publish fixtures and repository checks for the new image family\n\n## Authority boundary\n\nThe OCI image is distribution-only. Container execution cannot grant native performance authority. The follow-up qualification change will extract and verify the accepted kit before any host-native measurement.\n\n## Validation\n\n- `pnpm run check`\n- `bash -n images/aeron-native-kit/bin/aeron-native-harness images/aeron-native-kit/tests/smoke.sh`\n- BuildKit compiled the Java 21 harness successfully; the reviewed alpha publish will perform the complete image smoke on GitHub-hosted Linux\n\n## Version impact\n\nPatch within the active v1.2 alpha line: this is a locked prerequisite for #170 and does not yet grant a new qualification authority.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T23:47:42Z",
          "mergedAt": "2026-07-15T23:58:19Z",
          "additions": 635,
          "deletions": 1,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1312,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1312",
          "title": "chore(release): reconcile v2.12 stable ancestry",
          "body": "History-only reconciliation before the next v2.12 stable candidate.\n\n- First parent: exact `v2.12.8-alpha.1` candidate tree\n- Second parent: current `release/v2/v2.12` (`v2.12.7`)\n- Tree delta: none\n\nThis prevents the next exact source-lock stable PR from conflicting with the prior stable release commit.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T23:57:26Z",
          "mergedAt": "2026-07-16T00:00:24Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1313,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1313",
          "title": "chore(release): promote reconciled v2.12 ancestry to alpha",
          "body": "Promote the history-only v2.12 stable ancestry reconciliation to alpha.\n\nThe tree remains identical to `v2.12.8-alpha.1`; this only makes the prior stable release an ancestor so the next exact alpha candidate can merge cleanly into release.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-16T00:00:38Z",
          "mergedAt": "2026-07-16T00:12:04Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1314,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1314",
          "title": "feat(release): seal consumer qualification before provider writes",
          "body": "## Summary\n\n- transport the complete Gate aggregate and bind an exact consumer predicate into the publication capability\n- run the opt-in consumer predicate without provider credentials and seal a deterministic qualification receipt\n- verify that receipt before any provider access and again immediately before the publish transaction\n- preserve compatibility for consumers that do not opt in\n\n## Validation\n\n- `pnpm run generate:site`\n- `pnpm run check` (639 tests passed)\n- targeted publication/promotion suite (212 tests passed)\n- `git diff --check`\n\nCloses #1307",
          "author": "dongkeren",
          "createdAt": "2026-07-16T00:01:20Z",
          "mergedAt": "2026-07-16T00:20:47Z",
          "additions": 1059,
          "deletions": 139,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1317,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1317",
          "title": "Release v2.12.8 from qualified v2.12.8-alpha.2",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.12.8-alpha.2`\n- Candidate SHA: `4332aefca3a2579d8b5cae8b9d27d30b33be99e2`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.12`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T00:32:17Z",
          "mergedAt": "2026-07-16T00:35:12Z",
          "additions": 61,
          "deletions": 23,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1318,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1318",
          "title": "chore(release): reconcile v2.13 alpha state",
          "body": "## Summary\n\nReconcile the completed v2.13.0-alpha.0 publication state with the complete dev fix set on a temporary branch, preserving PR-only protection on both channel branches.\n\n## Validation\n\n- pnpm run check: 639 passed\n- generated site bundle is current\n- diff is limited to publication registry/site state\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T00:34:29Z",
          "mergedAt": "2026-07-16T00:36:18Z",
          "additions": 9,
          "deletions": 9,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1315,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1315",
          "title": "release: promote v2.13 fixes to alpha",
          "body": "## Summary\n\n- promote the complete v2.13 development line after resolving all open issues\n- include sealed consumer qualification before provider mutation\n- publish the next alpha candidate for final consumer qualification and stable promotion\n\n## Validation\n\n- PR #1314 passed the full check suite and cross-platform libnode-shaped fixture\n- Buildchain open issue count is zero\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T00:21:36Z",
          "mergedAt": "2026-07-16T00:42:47Z",
          "additions": 1110,
          "deletions": 148,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 188,
          "url": "https://github.com/kungfu-systems/build-images/pull/188",
          "title": "fix(images): harden Aeron qualification harness",
          "body": "## Summary\n- make the Aeron OCI image shell-smoke compatible by removing the command-shaping entrypoint\n- add a live Driver/Archive health probe and bind record/replay frames to an exact SHA-256 marker\n- run a bounded archive record/replay plus raw HdrHistogram smoke inside the published image\n\n## Validation\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- `bash -n images/aeron-native-kit/tests/smoke.sh`\n- Java compilation and image smoke are required GitHub-hosted checks\n\nRefs #170",
          "author": "dongkeren",
          "createdAt": "2026-07-16T00:13:24Z",
          "mergedAt": "2026-07-16T00:45:46Z",
          "additions": 252,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 186,
          "url": "https://github.com/kungfu-systems/build-images/pull/186",
          "title": "release(alpha): publish Aeron native qualification kit",
          "body": "## Summary\n\n- publish the first reviewed `aeron-native-kit` image family\n- pin Temurin 21.0.11+10, Aeron 1.52.2, and the bounded noninteractive harness\n- retain `pending-first-publish` so no production plan can self-reference this release\n- keep the image authority at distribution-only\n\n## Validation\n\n- implementation: #184\n- repository checks and Buildchain v2 dual-channel checks passed\n- comparator frozen-plan contract and existing profile smoke checks passed\n- first-publish image smoke will run on GitHub-hosted Linux during promotion\n\n## Required release outputs\n\n- Buildchain v2 dual-channel promotion\n- GitHub release enabled\n- Release Passport with `trust=pass`\n- exact GHCR digest for follow-up acceptance and native plan binding\n\nRefs #170",
          "author": "dongkeren",
          "createdAt": "2026-07-15T23:58:47Z",
          "mergedAt": "2026-07-16T00:49:58Z",
          "additions": 855,
          "deletions": 1,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1319,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1319",
          "title": "fix(release): accept legacy optional qualification shape",
          "body": "Restore cross-line publication compatibility after the consumer-qualification protocol landed on the default workflow shell.\n\nOlder Buildchain runtimes omit `capability.qualification` when no consumer predicate is required. Normalize that omission to explicit `required: false`; required predicates still fail closed when the field is absent.\n\nRegression: stable v2.12 publication run 29461909287 failed with `authority consumer qualification requirement mismatch`.\n\nVerified:\n- `node --test tests/build-surface.test.mjs`\n- `pnpm run check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-16T00:50:01Z",
          "mergedAt": "2026-07-16T00:52:01Z",
          "additions": 14,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 972,
          "url": "https://github.com/kungfu-systems/kungfu/pull/972",
          "title": "feat(project-cut): qualify Git history semantics",
          "body": "## Summary\n\nQualify Project Cut publication across Git branch, rewrite, merge, revert, recovery, empty-commit, and concurrent-worktree histories without adding Git object ids to the frozen `project.cut/v1` root preimage.\n\n## Related issue\n\nADR-0102\n\n## Changes\n\n- add rooted history request and observation schemas plus a self-verifying contract\n- require qualified prior bindings for rebase, amend, squash, and cherry-pick while preserving exact sealed Cut roots\n- require merge output cuts to name the exact qualified parent Cut set and admit an independent Integration Episode\n- expose N:M Cut and Episode publication maps, ref compare-and-swap loss, superseded bindings, orphan detection, explicit archive, and recovery\n- add agent-first `history-observe` and `history-reconcile` CLI actions with stable JSON envelopes\n- qualify every operation in disposable Git repositories, including independent concurrent worktrees\n\n## Verification\n\n- `./shifu check:project-cut-history` — 2 schemas and both rooted contracts verified\n- `./shifu test:project-cut-history` — 5 contract, CLI, rewrite, merge/recovery, orphan/archive, and worktree tests passed\n- `./shifu check:staged` — staged source and documentation gates passed\n- `./shifu check:source` — 361 source contract tests and all build-free source gates passed\n- frozen `project.cut/v1` and settlement contract roots remain unchanged\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0102\"],\n  \"summary\": \"Deliver explicit Project Cut Git history bindings without making Git ancestry causal authority\",\n  \"verification\": [\"Project Cut history rooted contract\", \"disposable Git operation matrix\", \"concurrent worktree and ref-CAS qualification\", \"source acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe CLI reads local Git objects and public Project Cut artifacts only. It does not acquire a global lock, rewrite refs, commit, push, or infer causal authority from Git ancestry.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T19:57:44Z",
          "mergedAt": "2026-07-16T01:00:02Z",
          "additions": 2053,
          "deletions": 6,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 92,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/92",
          "title": "fix(ci): grant stable canary Actions read",
          "body": "## Summary\n- grant the stable Buildchain canary `actions: read`, required by the nested publication-authority job in the stable `@v2` reusable shell\n- preserve the stable shell and all apply=false safety switches\n- add a regression check for the permission and stable-canary invariants\n\n## Evidence\n- fixes startup failures with zero jobs in site runs 29462719170, 29462909607, and 29463000901\n- `actionlint .github/workflows/buildchain-stable-canary.yml`\n- `npm run build`\n- `npm run check`",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:05:40Z",
          "mergedAt": "2026-07-16T01:05:57Z",
          "additions": 19,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1320,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1320",
          "title": "fix(workflows): preserve nested Actions permission",
          "body": "## Summary\n- grant `actions: read` at the reusable web-surface boundary\n- preserve it on the nested publication-authority reusable-workflow call\n- regenerate the public contract and add regression assertions\n\n## Why\nThe stable `v2` shell currently fails workflow validation before job creation when `.publication-authority.yml` requests `actions: read`. This patch is the minimal v2.12 backport needed to unblock exact-SHA stable canaries for the v2.13 candidate.\n\n## Evidence\n- site canary startup failures: 29462719170, 29462909607, 29463000901, 29463270389\n- `actionlint .github/workflows/.web-surface.yml`\n- focused web-surface test\n- `pnpm run check` (624 tests)",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:12:44Z",
          "mergedAt": "2026-07-16T01:23:48Z",
          "additions": 10,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1321,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1321",
          "title": "chore(release): promote v2.12 workflow hotfix alpha",
          "body": "## Summary\nPromote the reviewed v2.12 workflow-shell permission hotfix to alpha.\n\n## Evidence\n- source PR #1320 approved and merged\n- full local `pnpm run check` passed (624 tests)\n- protected source checks passed\n\nThis alpha is required to prove the exact fixed shell before the v2.12 patch stable promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:26:52Z",
          "mergedAt": "2026-07-16T01:28:10Z",
          "additions": 10,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 190,
          "url": "https://github.com/kungfu-systems/build-images/pull/190",
          "title": "fix(images): enforce Aeron IPC sequence oracle",
          "body": "## Summary\n\n- make the bounded IPC harness explicitly count observed, lost, duplicate, and reordered frames\n- fail the harness before issuing measurement output when the sequence oracle is not exact\n- publish the new fields in the machine-readable receipt and assert them in the image smoke test\n- bump the qualification harness identity to 1.1.1\n\nThis hardens the native kit required by #170 before the production qualification plans accept an immutable image digest.\n\n## Validation\n\n- `pnpm run check`\n- `bash -n images/aeron-native-kit/tests/smoke.sh`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:02:01Z",
          "mergedAt": "2026-07-16T01:30:59Z",
          "additions": 101,
          "deletions": 23,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 192,
          "url": "https://github.com/kungfu-systems/build-images/pull/192",
          "title": "release(alpha): publish Aeron IPC oracle kit",
          "body": "## Summary\n\nPromote the reviewed Aeron native kit harness 1.1.1 to the alpha channel.\n\n## Release intent\n\n- publish the seed-bound IPC sequence oracle\n- publish the explicit slow-reader poll batch path\n- retain the distribution-only authority boundary\n- produce Buildchain Release Passport evidence for the immutable kit digest\n\n## Validation\n\n- PR #190 approved and merged\n- Buildchain Verify passed\n- consumer smoke passed\n\nThe resulting exact alpha digest will be accepted by the separate container/native qualification change.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:31:21Z",
          "mergedAt": "2026-07-16T01:34:33Z",
          "additions": 101,
          "deletions": 23,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 191,
          "url": "https://github.com/kungfu-systems/build-images/pull/191",
          "title": "chore(images): accept alpha.16 Aeron baseline",
          "body": "## Summary\n- accept the reviewed v1.2.4-alpha.16 Release Passport image evidence\n- bind all seven public GHCR manifests, including aeron-native-kit, by digest\n- establish the lock-only provenance baseline required for selective publish reuse\n\n## Verification\n- `python3 scripts/verify-image-lock.py`\n- `pnpm run check`\n\nThis PR intentionally changes only `images.lock.json`.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:16:05Z",
          "mergedAt": "2026-07-16T01:36:35Z",
          "additions": 85,
          "deletions": 61,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 193,
          "url": "https://github.com/kungfu-systems/build-images/pull/193",
          "title": "chore(buildchain): refresh dual-channel contract locks",
          "body": "## Summary\n- upgrade the alpha Buildchain consumer to `2.13.0-alpha.1`\n- upgrade the stable Buildchain consumer to `2.12.8`\n- accept the exact current `v2-alpha` and `v2` runtime contract worlds\n- regenerate KFD-1/2/3 consumer evidence with zero contract drift\n\nCloses #185\nCloses #187\nCloses #189\n\n## Verification\n- `pnpm run check:kfd`\n- `pnpm run check`\n\nBoth contract locks report `status=unchanged` and `drift=false` against the installed runtimes.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:39:24Z",
          "mergedAt": "2026-07-16T01:41:59Z",
          "additions": 52,
          "deletions": 52,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1322,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1322",
          "title": "fix(release): preserve global npm alpha ownership",
          "body": "## Summary\n- publish an older-minor maintenance alpha under its line-specific npm dist-tag (`vX.Y-alpha`)\n- retain global `alpha` ownership for the highest alpha minor, matching Git floating-ref semantics\n- document the channel rule and regenerate action/site artifacts\n\n## Regression\nPublishing `2.12.9-alpha.0` incorrectly moved npm `alpha` from `2.13.0-alpha.1` backward while Git `v2-alpha` correctly remained on v2.13. This closes that mismatch.\n\n## Evidence\n- focused ownership tests passed\n- full `pnpm run check`: 625 tests passed\n- generated action bundle and public site contract refreshed",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:40:58Z",
          "mergedAt": "2026-07-16T01:42:07Z",
          "additions": 133,
          "deletions": 79,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1323,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1323",
          "title": "fix(release): preserve global npm alpha ownership",
          "body": "## Summary\n- align npm dist-tag ownership with Git major-alpha ownership\n- publish older maintenance alphas under `vX.Y-alpha`\n- keep the highest alpha minor on global `alpha`\n- regenerate action/site artifacts and update release docs\n\n## Regression\nThe v2.12 maintenance alpha moved npm `alpha` backward while `v2-alpha` correctly stayed on v2.13. This prevents recurrence on the active v2.13 line and will be published in the next v2.13 alpha before stable.\n\n## Evidence\n- focused ownership tests passed\n- full `pnpm run check`: 640 tests passed",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:43:24Z",
          "mergedAt": "2026-07-16T01:44:51Z",
          "additions": 135,
          "deletions": 81,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1324,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1324",
          "title": "chore(release): promote npm alpha ownership fix",
          "body": "Promotes the guarded npm alpha dist-tag ownership fix from dev/v2/v2.13 to alpha/v2/v2.13. This restores the global alpha line on v2.13 while older minors publish only to their line-specific alpha tag.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:46:12Z",
          "mergedAt": "2026-07-16T01:49:20Z",
          "additions": 149,
          "deletions": 82,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1326,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1326",
          "title": "feat(release): qualify exact canary source refs",
          "body": "Adds a fail-closed manual bootstrap path for outer reusable-workflow changes. The stable qualification controller may dispatch the authoritative consumer canary from an exact 40-character consumer commit SHA; automatic qualification remains on the consumer default branch. Includes unit coverage, generated public contract facts, and documentation.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:58:32Z",
          "mergedAt": "2026-07-16T02:00:14Z",
          "additions": 60,
          "deletions": 10,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1325,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1325",
          "title": "chore(release): promote stable shell and npm tag fixes",
          "body": "Promotes the nested Actions permission repair and guarded older-minor npm alpha dist-tag behavior from dev/v2/v2.12 to alpha/v2/v2.12.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:46:14Z",
          "mergedAt": "2026-07-16T02:03:19Z",
          "additions": 133,
          "deletions": 79,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1327,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1327",
          "title": "chore(release): promote exact canary bootstrap qualification",
          "body": "Promotes the fail-closed exact consumer canary source-ref qualification capability to the v2.13 alpha line for stable-shell bootstrap evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T02:00:32Z",
          "mergedAt": "2026-07-16T02:04:31Z",
          "additions": 60,
          "deletions": 10,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1328,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1328",
          "title": "chore(release): reconcile v2.13 alpha state",
          "body": "Merges the completed v2.13 alpha transaction/version-state history back into protected dev so the exact canary bootstrap qualification promotion remains strict and race-safe.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T02:04:30Z",
          "mergedAt": "2026-07-16T02:07:33Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 197,
          "url": "https://github.com/kungfu-systems/build-images/pull/197",
          "title": "fix(comparator): close ClickHouse readiness race",
          "body": "## Summary\n\n- bootstrap the `pilot` database before issuing database-scoped ClickHouse schema queries\n- gate Compose readiness on final `clickhouse-serv` PID 1 and a successful query against `pilot`\n- update the complete plan, fixture, adapter, registry, and Compose digest closure\n- make manual pilot project timestamps portable for Docker Compose\n- execute regressions for temporary entrypoint, missing database, and final-ready states\n\n## Validation\n\n- `pnpm run check`\n- 52 comparator qualification tests\n- Buildchain alpha/stable contract locks unchanged with no drift\n- KFD-1/2/3 and Release Passport smoke passed\n- interrupted local image preparation left no scoped containers, volumes, or networks\n\nAddresses #165. Keep #165 open until a clean exact-alpha replay on agent-120 passes 63/63 and offline bundle verification.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:56:23Z",
          "mergedAt": "2026-07-16T02:12:15Z",
          "additions": 96,
          "deletions": 17,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 196,
          "url": "https://github.com/kungfu-systems/build-images/pull/196",
          "title": "fix(images): compile Aeron IPC oracle",
          "body": "## Summary\n- keep Aeron IPC sequence counters in scope for post-run validation and JSON output\n- build and smoke the current Aeron kit in PR CI when its image sources change\n- prevent release promotion from being the first place that `javac` runs\n\n## Verification\n- `pnpm run check`\n- `bash scripts/check-workflows.sh`\n- `docker build --tag build-images-aeron-native-kit:compile-fix images/aeron-native-kit`\n- `docker run --rm build-images-aeron-native-kit:compile-fix /opt/aeron-native-kit/tests/smoke.sh`\n\nThe image smoke observed all 500 IPC messages with zero loss, duplicates, or reordering.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:45:57Z",
          "mergedAt": "2026-07-16T02:22:08Z",
          "additions": 12,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 194,
          "url": "https://github.com/kungfu-systems/build-images/pull/194",
          "title": "chore(release): promote ClickHouse and Aeron fixes",
          "body": "## Promotion scope\n\n- close the ClickHouse Phase A startup race by requiring final `clickhouse-serv` PID 1 and the configured `pilot` database\n- bootstrap `pilot` before database-scoped adapter queries and bind the complete plan/fixture/registry digest closure\n- compile and smoke the current Aeron 1.1.1 IPC oracle in PR CI, fixing the Java scope regression\n- retain Buildchain `2.13.0-alpha.1` / `2.12.8` dual-channel contract locks with zero drift\n\n## Expected publish plan\n\n- rebuild only image families whose source changed; reuse accepted unchanged digests\n- publish the next alpha GitHub release and primary Release Passport\n- require KFD-1/2/3 trust pass\n\n#165 remains open until the resulting exact alpha passes the clean agent-120 3x21 replay (63/63), cleanup proof, and offline bundle verification.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:42:32Z",
          "mergedAt": "2026-07-16T02:24:47Z",
          "additions": 245,
          "deletions": 134,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 198,
          "url": "https://github.com/kungfu-systems/build-images/pull/198",
          "title": "chore(release): join alpha promotion history",
          "body": "## Scope\n- merge the current `alpha/v1/v1.2` ancestry into `dev/v1/v1.2`\n- preserve the current dev tree exactly; this PR has no business-file delta\n- satisfy strict up-to-date history before PR #194 promotes the recovered release\n\n## Validation\n- merge completed without conflicts\n- `git diff origin/dev/v1/v1.2...HEAD` is empty\n- normal Buildchain verification and branch protection remain required\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T02:24:05Z",
          "mergedAt": "2026-07-16T02:26:48Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 200,
          "url": "https://github.com/kungfu-systems/build-images/pull/200",
          "title": "chore(images): accept alpha.18 baseline",
          "body": "## Scope\n- join the exact `v1.2.4-alpha.18` source ancestry (`9025219`) without a tree delta\n- accept the seven release image digests from run 29466606078\n- update only `images.lock.json`\n\n## Provenance\n- release: `v1.2.4-alpha.18`\n- release source: `902521948fa5c6c16a8ebbb2ae91e3595c359176`\n- release material: `278ebef6b25cf6d136da6e6da06b4a70038b75a5`\n- Release Passport: `ok=true`, `trust=pass`, issues empty\n- KFD-1/2/3: pass\n- all seven public manifests and image smokes: pass\n\n## Trust-boundary proof\n- release source is an ancestor of the lock acceptance commit\n- `git diff --name-only 9025219..bae3a17` contains only `images.lock.json`\n- `python3 scripts/verify-image-lock.py` passes\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T02:40:47Z",
          "mergedAt": "2026-07-16T02:43:19Z",
          "additions": 70,
          "deletions": 70,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 201,
          "url": "https://github.com/kungfu-systems/build-images/pull/201",
          "title": "fix(comparator): close ClickHouse client stdin",
          "body": "## Summary\n\n- close stdin explicitly for every query-only ClickHouse client invocation\n- cover normal/bootstrap, logical restore payload preservation, and concurrent writers\n- refresh the KFD witness binding left stale by the alpha.18 image-lock acceptance\n\n## Evidence\n\nExact `v1.2.4-alpha.18` replay on agent-120 timed out on the first INSERT after 120 seconds because `docker compose exec -T` retained open stdin. The failed bundle and cleanup proof are retained; scoped residual containers, volumes, and networks are zero.\n\n## Validation\n\n- `pnpm run check:qualification` (54 tests)\n- `pnpm run check`\n- clean post-check worktree\n\nRefs #165",
          "author": "dongkeren",
          "createdAt": "2026-07-16T02:47:54Z",
          "mergedAt": "2026-07-16T02:50:32Z",
          "additions": 54,
          "deletions": 27,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 976,
          "url": "https://github.com/kungfu-systems/kungfu/pull/976",
          "title": "feat(workspace): support shadow-only continuation",
          "body": "## Summary\n\nOpen a clean Git clone containing qualified Episode and Project Cut shadows without creating local runtime state, then require one explicit continuation action before new fact-bearing work begins.\n\n## Related issue\n\nADR-0103\n\n## Changes\n\n- distinguish `uninitialized`, `shadow-only`, `live-runtime`, and `evidence-degraded` across Core and Desktop\n- inspect tracked Episode and Project Cut roots without creating `.kungfu/runtime`\n- recompute Episode provider roots and Project Cut roots so mismatched shadows fail visibly\n- block CLI, Agent, and GUI continuation when settled evidence is degraded\n- preserve parent Episode and Project Cut roots in the first continuation receipt without promoting Git JSON to Episode authority\n- expose the explicit continuation action through Desktop IPC and the KFD-3 agent catalog\n- add a rooted product contract, ADR, focused tests, source-gate integration, and regenerated Buildchain KFD projections\n\n## Verification\n\n- `./shifu test:workspace-continuation` — 8 Node/GUI contract tests and 9 Python workspace tests passed\n- `./shifu check:source` — build-free source gate, 363 Node contract tests, 76 Python upgrade regressions, 69 Desktop adapter regressions, GUI TypeScript, Ruff, and Mypy passed\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check` — complete changed-scope gate passed without the host-local outer cache projection\n- `./shifu kfd:buildchain` — KFD-2/3 generated projections refreshed; 115 KFD-3 surfaces verified\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0103\"],\n  \"summary\": \"Deliver explicit shadow-only workspace continuation without promoting Git JSON to runtime authority\",\n  \"verification\": [\"workspace continuation rooted contract\", \"Core and Desktop shadow-only fixtures\", \"root mismatch fail-closed qualification\", \"source and changed-scope acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe new API reads only local tracked shadow material and creates local runtime state only after explicit intent. It does not import Git JSON as journal facts, mutate Git, contact a hosted service, or widen replay/requalification claims.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T01:43:06Z",
          "mergedAt": "2026-07-16T02:55:17Z",
          "additions": 1279,
          "deletions": 74,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 204,
          "url": "https://github.com/kungfu-systems/build-images/pull/204",
          "title": "chore(release): join alpha.18 material history",
          "body": "Join the Buildchain-generated `v1.2.4-alpha.18` material commit into dev ancestry with the `ours` strategy. The dev tree remains byte-for-byte unchanged; this only makes the next dev-to-alpha promotion fast-forwardable without importing generated version state.\n\nRequired by #202.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T02:54:10Z",
          "mergedAt": "2026-07-16T02:58:13Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 202,
          "url": "https://github.com/kungfu-systems/build-images/pull/202",
          "title": "release: promote ClickHouse Phase A closure to alpha",
          "body": "## Release scope\n\n- close the ClickHouse final-server/database readiness race\n- close ClickHouse client stdin for query-only and concurrent writer paths\n- retain logical-restore payload input semantics\n- include Aeron native-kit compile/smoke corrections and alpha.18 KFD witness binding\n\n## Release acceptance\n\nAfter Buildchain promotion publishes the next alpha, replay the clean exact tag on agent-120 for all 3 repetitions x 21 ClickHouse scenarios, verify the retained bundle offline, confirm zero scoped residual resources, and require a passing Release Passport before closing #165.\n\nRefs #165",
          "author": "dongkeren",
          "createdAt": "2026-07-16T02:50:53Z",
          "mergedAt": "2026-07-16T03:14:22Z",
          "additions": 126,
          "deletions": 99,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 203,
          "url": "https://github.com/kungfu-systems/build-images/pull/203",
          "title": "feat(comparator): qualify Aeron across container and native channels",
          "body": "## Summary\n- require sustained ClickHouse readiness and retain readiness evidence\n- add Aeron container qualification against the published image digest\n- add native-host Aeron qualification with extracted kit integrity checks\n- pin qualification plans to the accepted v1.2.4-alpha.18 image lock\n- retire the Aeron first-publish marker after public availability\n\n## Validation\n- `pnpm run check:qualification` (63 tests)\n- `pnpm run check`\n- KFD-1/KFD-2/KFD-3 checks pass\n- Release Passport smoke passes\n\nTracks #165 and #170. Final issue closure remains gated on exact-tag agent-120 qualification.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T02:52:38Z",
          "mergedAt": "2026-07-16T03:18:21Z",
          "additions": 2903,
          "deletions": 58,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 124,
          "url": "https://github.com/kungfu-systems/kfd/pull/124",
          "title": "docs(kfd): clarify the reality-correctable foundation",
          "body": "## What\\n\\n- distinguish KFD from model architectures and agent frameworks on the homepage\\n- contrast capability improvement with systems that remain correctable by reality\\n- add a concise reality-correction role to KFD-1 through KFD-6 without changing their axioms, status, gates, or procedures\\n- project the strengthened positioning into the existing first-screen site bundle fields\\n- refresh KFD-1, KFD-2, and KFD-3 evidence hashes and witnesses\\n\\n## Registry agreement\\n\\n- [x] check: 6 entries ok; release impact ok passes\\n- [x] Decision texts remain append-only (editorial clarification; no axiom, status, gate, or procedure changes)\\n\\n## Version impact (per KFD-1)\\n\\n- [x] patch (content operation)\\n- [ ] minor (registry schema additive)\\n- [ ] major (machine surface breakage)\\n\\n## Verification\\n\\n- \n> @kungfu-tech/kfd@1.0.0-alpha.25 check\n> node scripts/check.mjs\n\ncheck: 6 entries ok; release impact ok\\n- \\n- [\n  {\n    \"id\": \"@kungfu-tech/kfd@1.0.0-alpha.25\",\n    \"name\": \"@kungfu-tech/kfd\",\n    \"version\": \"1.0.0-alpha.25\",\n    \"size\": 109022,\n    \"unpackedSize\": 621614,\n    \"shasum\": \"a00196ac1eeaecf80b591a723f0d21ca87ebf53f\",\n    \"integrity\": \"sha512-TYYpAhEaYjsypjd8SOdkDLBydcaoLhGkrPw0lCPLjuqQe05Gf7U9Q7GczGGi9oECUPzklA+e/Ic8AbsWDfIWWg==\",\n    \"filename\": \"kungfu-tech-kfd-1.0.0-alpha.25.tgz\",\n    \"files\": [\n      {\n        \"path\": \".buildchain/kfd-1/contract-world.witness.json\",\n        \"size\": 55344,\n        \"mode\": 420\n      },\n      {\n        \"path\": \".buildchain/kfd-2/kfd-foundation.trust-assessment.json\",\n        \"size\": 16689,\n        \"mode\": 420\n      },\n      {\n        \"path\": \".buildchain/kfd-2/kfd-foundation.trust-claims.json\",\n        \"size\": 15093,\n        \"mode\": 420\n      },\n      {\n        \"path\": \".buildchain/kfd-2/public-release-trust.claim.json\",\n        \"size\": 5900,\n        \"mode\": 420\n      },\n      {\n        \"path\": \".buildchain/kfd-3/collaboration-interface.artifact.json\",\n        \"size\": 31722,\n        \"mode\": 420\n      },\n      {\n        \"path\": \".buildchain/kfd-3/collaboration-interface.json\",\n        \"size\": 17960,\n        \"mode\": 420\n      },\n      {\n        \"path\": \".buildchain/kfd-3/collaboration-interface.prebuild.json\",\n        \"size\": 38901,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"LICENSE\",\n        \"size\": 11357,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"README.md\",\n        \"size\": 19906,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"TRADEMARKS.md\",\n        \"size\": 2149,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"buildchain.contract-lock.json\",\n        \"size\": 3356,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"buildchain.release-propagation.json\",\n        \"size\": 723,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"decisions/KFD-1.md\",\n        \"size\": 12570,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"decisions/KFD-2.md\",\n        \"size\": 7597,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"decisions/KFD-3.md\",\n        \"size\": 9627,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"decisions/KFD-4.md\",\n        \"size\": 9446,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"decisions/KFD-5.md\",\n        \"size\": 8125,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"decisions/KFD-6.md\",\n        \"size\": 8368,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"docs/KFD-1-usage.md\",\n        \"size\": 3540,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"docs/KFD-2-usage.md\",\n        \"size\": 5412,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"docs/KFD-3-usage.md\",\n        \"size\": 4722,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"docs/KFD-4-usage.md\",\n        \"size\": 2024,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"docs/KFD-5-usage.md\",\n        \"size\": 2479,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"docs/KFD-6-usage.md\",\n        \"size\": 2159,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"docs/MAP.md\",\n        \"size\": 4996,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"docs/release-governance.md\",\n        \"size\": 1035,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"kfd.release.json\",\n        \"size\": 418,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"package.json\",\n        \"size\": 2697,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"registry.json\",\n        \"size\": 1932,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"release-impact.json\",\n        \"size\": 6511,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"schemas/kfd-1/contract-world.schema.json\",\n        \"size\": 2538,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"schemas/kfd-1/publication-url-semantics.schema.json\",\n        \"size\": 5975,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"schemas/kfd-1/witness.schema.json\",\n        \"size\": 3805,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"schemas/kfd-2/release-claims.schema.json\",\n        \"size\": 6984,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"schemas/kfd-2/release-trust-passport.schema.json\",\n        \"size\": 5827,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"schemas/kfd-2/trust-assessment.schema.json\",\n        \"size\": 6790,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"schemas/kfd-2/trust-claims.schema.json\",\n        \"size\": 7208,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"schemas/kfd-2/trust-taxonomy.schema.json\",\n        \"size\": 5223,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"schemas/kfd-3/collaboration-interface.schema.json\",\n        \"size\": 11803,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"schemas/kfd-3/witness.schema.json\",\n        \"size\": 3729,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"schemas/kfd-4/observer-perspective.schema.json\",\n        \"size\": 6312,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"schemas/kfd-5/primitive-discovery.schema.json\",\n        \"size\": 6256,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"schemas/kfd-6/autonomous-discovery-loop.schema.json\",\n        \"size\": 6269,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"schemas/kfd-standards.schema.json\",\n        \"size\": 8116,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"scripts/check.mjs\",\n        \"size\": 68110,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"scripts/npm-publish-transaction.mjs\",\n        \"size\": 7861,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"scripts/update-kfd-1-witness.mjs\",\n        \"size\": 1564,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"scripts/update-kfd-2-claim.mjs\",\n        \"size\": 18199,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"scripts/update-kfd-3-witness.mjs\",\n        \"size\": 11802,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"scripts/update-site-bundle.mjs\",\n        \"size\": 12176,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"site/kfd-site.json\",\n        \"size\": 35797,\n        \"mode\": 420\n      },\n      {\n        \"path\": \"standards.json\",\n        \"size\": 66512,\n        \"mode\": 420\n      }\n    ],\n    \"entryCount\": 52,\n    \"bundled\": []\n  }\n]\\n- ",
          "author": "dongkeren",
          "createdAt": "2026-07-16T03:17:27Z",
          "mergedAt": "2026-07-16T03:21:16Z",
          "additions": 202,
          "deletions": 115,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 205,
          "url": "https://github.com/kungfu-systems/build-images/pull/205",
          "title": "chore(release): promote Aeron dual-channel qualification",
          "body": "## Release intent\n- publish the reviewed ClickHouse sustained-readiness and stdin closure\n- publish Aeron container plus native-host qualification contracts\n- publish managed-harness unscored smoke and exact alpha.18 kit bindings\n- carry the current Buildchain v2 dual-channel contract locks to alpha\n\n## Required release proof\n- GitHub release enabled\n- Release Passport enabled\n- KFD-1/KFD-2/KFD-3 pass\n- Release Passport `ok=true`, `trust=pass`, `issues=[]`\n- exact-tag agent-120 qualification follows release publication\n\nTracks #165, #170, #185, #187, #189, and #199. Issue closure remains gated on release and exact-tag evidence.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T03:18:43Z",
          "mergedAt": "2026-07-16T03:22:53Z",
          "additions": 2903,
          "deletions": 58,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 126,
          "url": "https://github.com/kungfu-systems/kfd/pull/126",
          "title": "docs(kfd): make product witnesses load-bearing",
          "body": "## Summary\n\n- define inspectable product witnesses as the load-bearing path from KFD principles to product reality\n- state that Kungfu builds the passage with inherited technical capabilities rather than rejecting them\n- gate engineering complexity by KFD responsibility, participant friction reduction, or inspectable witness value\n- expose the new root section through the homepage site bundle and refresh KFD-1/2/3 evidence\n\n## Decision boundary\n\nThis is a compatible editorial clarification. It does not change KFD numbers, axioms, statuses, gates, registry shape, standards metadata, or schemas.\n\n## Release impact\n\nPatch: content and homepage bundle fields are additively clarified.\n\n## Verification\n\n- `node --check scripts/update-site-bundle.mjs`\n- `npm run check`\n- `npm pack --dry-run --json`\n- site bundle contract assertions and public leak guard",
          "author": "dongkeren",
          "createdAt": "2026-07-16T03:42:53Z",
          "mergedAt": "2026-07-16T03:45:15Z",
          "additions": 144,
          "deletions": 53,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 206,
          "url": "https://github.com/kungfu-systems/build-images/pull/206",
          "title": "fix(comparator): bind Aeron qualification evidence",
          "body": "## Summary\n\n- bind Aeron observed facts to the frozen query identity required by offline verification\n- resolve containers created but not started during whole-root restoration\n- refresh comparator adapter and registry hashes transitively\n\n## Exact-tag failure reproduced\n\n`v1.2.4-alpha.20` completed all 63 container lifecycle runs, but offline verification rejected the evidence because `observed-facts.json` omitted `query_id`. Whole-root restore also failed because `docker compose ps -q aeron` excludes a stopped container created by `docker compose create`.\n\n## Validation\n\n- `pnpm run check:qualification` (68 tests)\n- `pnpm run check`\n- KFD123 passed\n- Buildchain contract locks unchanged\n- `git diff --check`\n\nThis is a release-blocking correction for #170. The issue should close only after a new exact release tag passes container and native qualification.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T04:06:05Z",
          "mergedAt": "2026-07-16T04:10:31Z",
          "additions": 51,
          "deletions": 14,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 207,
          "url": "https://github.com/kungfu-systems/build-images/pull/207",
          "title": "release: promote Aeron evidence fix to alpha",
          "body": "## Promotion\n\nPromote the verified Aeron qualification evidence correction from `dev/v1/v1.2` to `alpha/v1/v1.2`.\n\n## Included\n\n- PR #206\n- observed-facts query identity binding\n- stopped-container lookup for whole-root restore\n- refreshed transitive comparator hashes\n\n## Release acceptance\n\nAfter merge, Buildchain v2 dual-channel promotion must publish a new alpha Release Passport with KFD123 and contract-lock trust passing. Issues #165 and #170 remain open until fresh exact-tag qualification completes on agent-120.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T04:11:38Z",
          "mergedAt": "2026-07-16T04:15:25Z",
          "additions": 51,
          "deletions": 14,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 127,
          "url": "https://github.com/kungfu-systems/kfd/pull/127",
          "title": "docs(kfd): lead with the future picture",
          "body": "## Summary\n\n- lead the README with the civilizational shift from answer improvement to reality-correctable primitive discovery\n- move the complete worldview into a non-numbered `docs/foundation-model.md` explanation and expose it at `/foundation`\n- bind the new reading path through the site bundle and KFD-1/2/3 evidence\n\n## Decision boundary\n\nNo numbered KFD text, registry entry, or schema is changed. The new foundation document is explicitly non-normative; `decisions/KFD-N.md` remains authoritative.\n\n## Release impact\n\n- content: patch wording/layout refinement\n- package/site/surface: additive foundation document, route, and witness projection\n- existing KFD-6 schema v2 major assessment remains unchanged\n\n## Verification\n\n- `npm run update:evidence` is deterministic\n- `npm run check`\n- `node --check` on touched generators and checks\n- `jq empty` on touched JSON\n- `npm pack --dry-run --json` includes the README, foundation document, site bundle, and KFD-1/2/3 evidence\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T04:20:58Z",
          "mergedAt": "2026-07-16T04:23:45Z",
          "additions": 746,
          "deletions": 394,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 128,
          "url": "https://github.com/kungfu-systems/kfd/pull/128",
          "title": "release(kfd): publish alpha 26",
          "body": "## Release\n\nPromote the exact `dev/v1/v1.0` state to `alpha/v1/v1.0`.\n\nPublishes `@kungfu-tech/kfd@1.0.0-alpha.26` with:\n\n- a concise first-screen civilizational picture and the KFD foundation triad\n- the non-numbered `/foundation` explanation for the complete worldview\n- a load-bearing product-witness path across the numbered decisions\n- refreshed site bundle and KFD-1/2/3 evidence for the new reading surface\n\nThe numbered decision coordinates, registry shape, and fixed outer `v1.0` line remain stable. The existing KFD-6 schemaVersion 2 migration remains the declared major interface-impact signal.\n\n## Verification\n\n- the exact dev source passed Verify and Buildchain checks in PRs #124, #126, and #127\n- `npm run update:evidence` is deterministic\n- `npm run check` passes\n- package dry-run includes the foundation document, site bundle, and KFD-1/2/3 witnesses\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T04:31:39Z",
          "mergedAt": "2026-07-16T04:34:10Z",
          "additions": 877,
          "deletions": 347,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 129,
          "url": "https://github.com/kungfu-systems/kfd/pull/129",
          "title": "chore(kfd): anchor alpha 26 release",
          "body": "## Summary\n\n- advance the explicit KFD npm and release-anchor facts to `1.0.0-alpha.26`\n- regenerate KFD-1/2/3 evidence from the updated source facts\n- keep the package line, release channel, public surfaces, and impact assessment unchanged\n\n## Context\n\nThe first alpha.26 promotion attempt correctly failed because Buildchain planned tag `v1.0.0-alpha.26` while the anchored/manual source still declared `1.0.0-alpha.25`. This change restores exact version/tag agreement without bypassing the promotion gate.\n\n## Verification\n\n- `npm run update:evidence` is deterministic\n- `npm run check`\n- `npm pack --dry-run --json` reports `@kungfu-tech/kfd@1.0.0-alpha.26` and includes the foundation, site, and KFD-1/2/3 evidence surfaces\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T04:38:13Z",
          "mergedAt": "2026-07-16T04:40:34Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 130,
          "url": "https://github.com/kungfu-systems/kfd/pull/130",
          "title": "release(kfd): publish alpha 26",
          "body": "## Release\n\nPromote the exact `dev/v1/v1.0` state to `alpha/v1/v1.0`.\n\nPublishes `@kungfu-tech/kfd@1.0.0-alpha.26` with:\n\n- a concise first-screen civilizational picture and the KFD foundation triad\n- the non-numbered `/foundation` explanation for the complete worldview\n- a load-bearing product-witness path across the numbered decisions\n- refreshed site bundle and KFD-1/2/3 evidence for the new reading surface\n- an explicit alpha.26 package and release anchor matching the planned immutable tag\n\nThe numbered decision coordinates, registry shape, and fixed outer `v1.0` line remain stable. The existing KFD-6 schemaVersion 2 migration remains the declared major interface-impact signal.\n\n## Verification\n\n- `npm run update:evidence` is deterministic\n- `npm run check` passes\n- package dry-run reports `@kungfu-tech/kfd@1.0.0-alpha.26`\n- the package includes the foundation document, site bundle, and KFD-1/2/3 witnesses\n- the source anchor and planned exact tag now agree on `1.0.0-alpha.26`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T04:41:05Z",
          "mergedAt": "2026-07-16T04:43:23Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 978,
          "url": "https://github.com/kungfu-systems/kungfu/pull/978",
          "title": "feat(mission-control): cut over native authority",
          "body": "## Summary\n\nMove Mission/Go execution authority from the Atlas bridge to native .kungfu facts through an audited, reversible parity cutover while preserving Atlas history read-only.\n\n## Related issue\n\nADR-0104\n\n## Changes\n\n- model Mission containment and Go execution dependencies as separate native fields\n- expose append-only authority status, exact parity, cutover, rollback, and re-cutover receipts\n- require exact Atlas import parity plus Project Cut and Atlas roots before native activation\n- freeze Atlas writes after cutover while retaining imported history and native facts read-only on rollback\n- expose the same authority operations through CLI, KFD-3 Agent APIs, shared Profile actions, and Work Dashboard GUI\n- add focused authority migration tests, ADR documentation, and regenerated Buildchain KFD projections\n\n## Verification\n\n- `./shifu test:mission-authority-cutover` — 25 Work Dashboard tests and 4 focused Python authority/release tests passed\n- `./shifu test:kfx-profile-suite` — Node, GUI navigation/shared-module/runtime, and Python Profile Suite tests passed\n- `./shifu check:source` — build-free source gate, 363 Node contract tests, 76 Python upgrade regressions, 69 Desktop adapter regressions, GUI TypeScript, Ruff, and Mypy passed\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check` — complete changed-scope gate passed\n- `./shifu kfd:buildchain:check` — KFD-1 witness, 3 KFD-2 claims, and 118 KFD-3 surfaces verified\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0104\"],\n  \"summary\": \"Deliver audited reversible native Mission and Go authority cutover with exact Atlas parity\",\n  \"verification\": [\"append-only authority receipts\", \"exact Atlas parity and rooted cutover\", \"CLI GUI and Agent shared authority path\", \"rollback and re-cutover qualification\", \"source and changed-scope acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change introduces local authority APIs and root-bound migration receipts. It does not contact hosted services, rewrite historical facts, publish packages, or widen authority beyond an exact parity-gated local cutover.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-16T04:02:56Z",
          "mergedAt": "2026-07-16T04:51:58Z",
          "additions": 1798,
          "deletions": 51,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 208,
          "url": "https://github.com/kungfu-systems/build-images/pull/208",
          "title": "fix(comparator): bind native Aeron IPC seed",
          "body": "## Summary\n\n- derive a deterministic positive 60-bit IPC seed from each result marker\n- pass the seed explicitly to the Aeron native harness\n- verify the returned seed online and again during offline bundle verification\n- add a regression test over the actual harness argument contract\n\n## Exact-tag evidence\n\n`v1.2.4-alpha.21` completed and offline-verified all 63 container Aeron lifecycle results. The subsequent native bundle failed immediately at calibration IPC with:\n\n```text\nIllegalStateException: --seed is required\n```\n\nFailed bundle preserved on agent-120:\n`/data/qualification/build-images-v1.2.4-alpha.21/pilots/comparator/.artifacts/aeron-native-qualification/aeron-native-20260716T045257Z-4d87cb45ce70`\n\n## Validation\n\n- native qualification tests: 7 passed\n- qualification tests: 69 passed\n- `pnpm run check`\n- KFD123 passed\n- alpha/stable Buildchain contract locks unchanged\n- `git diff --check`\n\nRelease-blocking follow-up for #170. Keep the issue open until a fresh exact tag passes native and container qualification.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T04:56:37Z",
          "mergedAt": "2026-07-16T04:59:04Z",
          "additions": 42,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 209,
          "url": "https://github.com/kungfu-systems/build-images/pull/209",
          "title": "release: promote native Aeron seed fix to alpha",
          "body": "## Promotion\n\nPromote PR #208 to the alpha channel.\n\nThe change closes the native qualification harness contract gap discovered by exact-tag `v1.2.4-alpha.21`: each IPC result now carries a deterministic seed bound to its result marker, with online and offline verification.\n\nAfter merge, Buildchain v2 must publish a new Release Passport with KFD123 and contract-lock trust passing. Issue #170 stays open until fresh exact-tag container and native qualification both pass on agent-120.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T04:59:17Z",
          "mergedAt": "2026-07-16T05:02:25Z",
          "additions": 42,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 979,
          "url": "https://github.com/kungfu-systems/kungfu/pull/979",
          "title": "feat(runtime): add fenced peer lifecycle control plane",
          "body": "## Summary\n\nAdd one independent fenced lifecycle host per Peer declaration, with explicit start, stop, health, recovery, adoption, and crash-loop semantics.\n\nThis replaces #977 after `dev/v4/v4.0` advanced with Mission Control authority changes that overlap KFD-3 generated evidence. The implementation is replayed on the new exact base without rewriting or merging the previous branch history.\n\n## Related issue\n\nADR-0086\n\n## Changes\n\n- add the KFD-1 peer-lifecycle contract and runtime CLI surface\n- fence host and Peer ownership by generation, PID start identity, and readiness token\n- distinguish stopped, orphaned, ownership-unknown, crash-loop, ended, and lost-control states\n- add bounded restart only for declarations with durable recovery boundaries\n- declare AgentSession process loss as lost-control instead of fake PTY recovery\n- extend the native live-Peer campaign and full Core matrix across Linux, macOS, and Windows\n- regenerate KFD-1/KFD-3 evidence and Core architecture projections against `dev/v4/v4.0@4c5ace422d067da16b65727071d9cd406f230cad`\n\n## Verification\n\n- `./shifu check:source`: 364 source tests, 76 runtime-upgrade tests, and 69 desktop-update tests passed\n- `./shifu kfd:buildchain:check`: KFD-1 witness, 3 KFD-2 claims, and 118 KFD-3 surfaces passed\n- peer lifecycle Python real-process suite: 18 passed plus one Windows-only skip on macOS/Linux; 19 passed on Windows\n- [Core build profiles run 29473196689](https://github.com/kungfu-systems/kungfu/actions/runs/29473196689): six matrix jobs passed; Linux, macOS, and Windows full-profile fault campaigns and retained evidence passed\n- [Core affected native run 29473196677](https://github.com/kungfu-systems/kungfu/actions/runs/29473196677): affected-native closure passed\n- Source Acceptance, Docs Check, ADR Release Gate, DCO, Buildchain validate, and promotion rehearsal passed at head `f2fb02806752f332eca05b60933b204715515a50`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0086\"],\n  \"summary\": \"Complete and qualify the independent fenced Peer lifecycle control plane on Linux, macOS, and Windows\",\n  \"verification\": [\"source acceptance\", \"peer lifecycle real-process tests\", \"three-platform full-profile Core fault campaign\", \"affected-native closure\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change extends retained qualification evidence only; it does not add credentials, publishing authority, or deployment side effects.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T05:08:38Z",
          "mergedAt": "2026-07-16T06:02:16Z",
          "additions": 2911,
          "deletions": 107,
          "changedFiles": 36
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 210,
          "url": "https://github.com/kungfu-systems/build-images/pull/210",
          "title": "fix(comparator): bind native Aeron poll batch",
          "body": "## Summary\n- freeze `ipc_poll_batch=64` in the native Aeron plan and advocate review scope\n- pass the exact value to calibration, IPC, and soak harness runs\n- reject harness output that does not preserve the frozen poll batch\n\n## Verification\n- `python3 -m unittest pilots.comparator.tests.test_aeron_native_qualification`\n- `pnpm run check:qualification`\n- `pnpm run check`\n\nExact-tag alpha.22 qualification reproduced `IllegalStateException: --poll-batch must be positive`; this patch closes that runner/kit contract gap.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T06:49:02Z",
          "mergedAt": "2026-07-16T06:51:48Z",
          "additions": 29,
          "deletions": 8,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 211,
          "url": "https://github.com/kungfu-systems/build-images/pull/211",
          "title": "chore(release): promote v1.2 native poll batch fix",
          "body": "## Summary\n\nPromote the verified `dev/v1/v1.2` changes into the alpha channel.\n\n- freeze and propagate Aeron native `ipc_poll_batch`\n- validate calibration reports the frozen poll batch\n- extend qualification contract coverage\n\n## Verification\n\n- `pnpm run check:qualification`\n- `pnpm run check`\n- PR #210 checks passed\n\nRelease Passport and exact-tag agent-120 qualification will be verified after the channel release.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T06:53:02Z",
          "mergedAt": "2026-07-16T06:55:55Z",
          "additions": 29,
          "deletions": 8,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1330,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1330",
          "title": "fix(release): bind canary refs and lock changes",
          "body": "Closes #1329.\\n\\nThe current release-propagation workflow already stages the intended lock path before diffing; this adds an executable regression proving a first untracked lock is detected and a repeated identical lock is the only no-op. It also repairs exact stable-canary bootstrap dispatch: GitHub accepts a branch/tag ref, so qualification now binds that dispatchable ref to an independently supplied exact SHA, verifies the binding before dispatch, and accepts only a run from that source SHA.\\n\\nValidated with the full 644-test Buildchain check, workflow checks, generated site contracts, and action builds.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T07:04:57Z",
          "mergedAt": "2026-07-16T07:06:11Z",
          "additions": 107,
          "deletions": 24,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 212,
          "url": "https://github.com/kungfu-systems/build-images/pull/212",
          "title": "chore(buildchain): accept v2.13 alpha.2 contract",
          "body": "## Summary\n\n- upgrade the alpha Buildchain consumer to `2.13.0-alpha.2`\n- accept the exact `v2-alpha` runtime SHA `b1e7667b099a29844fea18e201c4bc4cba17cbfe`\n- bind contract digest `sha256:63f9ef6dd9ce1f312c8e975479134e3be2dfb51ead80a73f0ed1c3d32781f516`\n- regenerate KFD-2 and KFD123 evidence\n- keep the stable channel pinned to Buildchain `2.12.8`\n\nCloses #199\n\n## Verification\n\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- 69 qualification tests passed\n- alpha contract lock reports `unchanged`, `drift=false`\n- stable contract lock reports `unchanged`, `drift=false`\n- `git diff --check`\n\n## Selective publish boundary\n\nThis is a Buildchain provenance/configuration change. The current selective planner intentionally treats it as a global invalidator, so the alpha release must re-establish all image provenance rather than reusing prior image attestations.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T07:03:39Z",
          "mergedAt": "2026-07-16T07:06:28Z",
          "additions": 21,
          "deletions": 21,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1332,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1332",
          "title": "chore(release): reconcile v2.13 alpha state",
          "body": "Carries the completed alpha.2 generated version-state history into protected dev before the all-issues-closed alpha promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T07:08:41Z",
          "mergedAt": "2026-07-16T07:09:59Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1331,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1331",
          "title": "chore(release): promote closed issue and canary fixes",
          "body": "Promotes the #1329 behavioral regression closure and exact ref/SHA-bound stable-canary bootstrap correction after all open Buildchain issues are closed.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T07:07:33Z",
          "mergedAt": "2026-07-16T07:11:16Z",
          "additions": 107,
          "deletions": 24,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 980,
          "url": "https://github.com/kungfu-systems/kungfu/pull/980",
          "title": "feat(mission-control): add independent review continuation",
          "body": "## Summary\n\nAdd an independent, exact-root Completion Claim review and bounded continuation path so a reviewer can assess a Go without the claimant's chat and a later agent can continue from the resulting rooted plan.\n\n## Related issue\n\nADR-0105\n\n## Changes\n\n- expand Completion Claims with exact Go, acceptance, Atlas, Project Cut, Git, Episode, proof, gap, and evidence-availability roots\n- require a distinct reviewer actor and source, producing a purpose-bound Assessment Episode, TrustReport, six-state verdict, and exact evidence requests\n- enforce exact review/plan roots, verdict-permitted actions, human gates for high-consequence decisions, and at most six mechanical follow-up Go rows\n- keep the existing Mission Control completion-claim fact surface stable while adding versioned review and continuation record kinds\n- expose one shared authority path through CLI, public KFD-3 Agent APIs, Profile actions, and the Work Dashboard reviewer panel\n- add ADR-0105, focused review/continuation tests, documentation, and regenerated 120-surface Buildchain KFD projections\n\n## Verification\n\n- `./shifu kfd:buildchain:check` — KFD-1 witness, 3 KFD-2 claims, and 120 KFD-3 surfaces verified\n- `./shifu test:agent-review-continuation` — 25 Work Dashboard tests and 1 focused Python review/continuation test passed\n- `./shifu test:kfx-profile-suite` — Node, GUI navigation/shared-module/runtime, and Python Profile Suite tests passed\n- `./shifu docs:check` — Markdown, links, fixtures, and ADR audit passed\n- `./shifu check:source` — build-free source gate, 363 Node contract tests, 76 Python upgrade regressions, 69 Desktop adapter regressions, GUI TypeScript, Ruff, and Mypy passed\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check` — complete changed-scope gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0105\"],\n  \"summary\": \"Deliver independent exact-root completion review and bounded evidence-driven continuation\",\n  \"verification\": [\"distinct reviewer and purpose-bound assessment\", \"six-state fail-closed verdict and exact evidence requests\", \"exact-root bounded continuation with human authority gates\", \"CLI GUI and Agent shared authority path\", \"source and changed-scope acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change adds local review/continuation APIs and root-bound evidence receipts. It does not contact hosted services, mutate claimant Episodes, publish packages, or grant agents authority over Mission, privacy, security, public-claim, irreversible, or stop decisions.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T05:20:03Z",
          "mergedAt": "2026-07-16T07:17:45Z",
          "additions": 1805,
          "deletions": 50,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 214,
          "url": "https://github.com/kungfu-systems/build-images/pull/214",
          "title": "chore(release): join alpha.23 material history",
          "body": "## Scope\n\n- join the exact `v1.2.4-alpha.23` material ancestry into `dev/v1/v1.2`\n- preserve the current dev tree byte-for-byte\n- satisfy strict up-to-date history before PR #213 promotes the contract-lock release\n\n## Verification\n\n- alpha head `eaa8101a654f5ac69150b93d72d1d14d7984997e` is an ancestor of this branch\n- merge tree equals the first-parent dev tree\n- `git diff origin/dev/v1/v1.2..HEAD` is empty\n- no business-file delta",
          "author": "dongkeren",
          "createdAt": "2026-07-16T07:16:54Z",
          "mergedAt": "2026-07-16T07:19:27Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 213,
          "url": "https://github.com/kungfu-systems/build-images/pull/213",
          "title": "chore(release): promote Buildchain v2.13 alpha.2 contract",
          "body": "## Summary\n\nPromote the verified `dev/v1/v1.2` Buildchain contract lock update into the alpha channel.\n\n- Buildchain alpha consumer: `2.13.0-alpha.2`\n- `v2-alpha` runtime SHA: `b1e7667b099a29844fea18e201c4bc4cba17cbfe`\n- contract digest: `sha256:63f9ef6dd9ce1f312c8e975479134e3be2dfb51ead80a73f0ed1c3d32781f516`\n- stable channel remains on `2.12.8`\n\n## Verification\n\n- implementation PR #212 checks passed\n- `pnpm run check`\n- 69 qualification tests passed\n- KFD-1/2/3 passed\n- alpha and stable locks both report `unchanged`, `drift=false`\n\n## Release outputs\n\n- GitHub prerelease enabled\n- Release Passport required with `trust=pass`\n- KFD-1/2/3 required\n- all 7 image families are globally invalidated by the provenance/config change and must be rebuilt and verified",
          "author": "dongkeren",
          "createdAt": "2026-07-16T07:10:40Z",
          "mergedAt": "2026-07-16T07:22:52Z",
          "additions": 23,
          "deletions": 23,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1333,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1333",
          "title": "Release v2.13.0 from qualified v2.13.0-alpha.3",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.13.0-alpha.3`\n- Candidate SHA: `18c1a7416fdec76eb098d186c55475bda256af92`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.13`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T07:24:23Z",
          "mergedAt": "2026-07-16T07:38:48Z",
          "additions": 3302,
          "deletions": 419,
          "changedFiles": 73
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 975,
          "url": "https://github.com/kungfu-systems/kungfu/pull/975",
          "title": "test(kfx): prove Buildchain envelope round trip",
          "body": "## Summary\n\n- replay an artifact-verification envelope produced by the actually published @kungfu-tech/buildchain 2.13.0-alpha.0\n- bind the exact optional-view KFX package closure and retain the resulting Core report root\n- prove Core, Python, CLI, Node, and the GUI/Agent public Storage edge preserve the same projection\n\n## Verification\n\n- ./shifu build:core\n- ./shifu test:native-kfx-admission\n- ./shifu check:source\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0090\"],\n  \"summary\": \"Retain a published Buildchain alpha envelope and prove one KFX admission report root across Core, CLI, Python, Node, GUI, and Agent projections.\",\n  \"verification\": [\"./shifu test:native-kfx-admission\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR retains public release evidence only and performs no publication.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation unchanged because runtime behavior is unchanged\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T00:31:14Z",
          "mergedAt": "2026-07-16T07:58:24Z",
          "additions": 427,
          "deletions": 127,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 217,
          "url": "https://github.com/kungfu-systems/build-images/pull/217",
          "title": "chore(buildchain): accept v2.13 dual-channel contracts",
          "body": "## Summary\n- accept Buildchain `v2-alpha` at `v2.13.0-alpha.3` / `18c1a7416fdec76eb098d186c55475bda256af92`\n- accept Buildchain stable `v2` at `2.13.0` / `ec48c0b311212c5f3a591e0284da6e85a9fdded5`\n- regenerate KFD-1/2/3 dual-channel evidence\n\nCloses #215.\nCloses #216.\n\n## Verification\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-16T07:51:42Z",
          "mergedAt": "2026-07-16T08:35:53Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 218,
          "url": "https://github.com/kungfu-systems/build-images/pull/218",
          "title": "chore(release): promote Buildchain v2.13 dual-channel contracts",
          "body": "## Summary\n\nPromote the verified `dev/v1/v1.2` dual-channel Buildchain contract update into the alpha channel.\n\n- Buildchain alpha consumer: `2.13.0-alpha.3`\n- `v2-alpha` runtime SHA: `18c1a7416fdec76eb098d186c55475bda256af92`\n- alpha contract digest: `sha256:7c484816d02efb4178cb285a5637e4f25bcdc36aeb4ce0da044d97755c890582`\n- Buildchain stable consumer: `2.13.0`\n- `v2` runtime SHA: `ec48c0b311212c5f3a591e0284da6e85a9fdded5`\n- stable contract digest: `sha256:96593e211e995724701c04826ecf885e3a1fa0c49ab38948b5e481d44b3eba6b`\n\n## Verification\n\n- implementation PR #217 checks passed\n- dev branch Verify run 29484025426 passed\n- `pnpm run check`\n- 69 qualification tests passed\n- KFD-1/2/3 passed\n- alpha and stable locks both report `unchanged`, `drift=false`\n\n## Release outputs\n\n- GitHub prerelease enabled\n- Release Passport required with `trust=pass`\n- KFD-1/2/3 required\n- all 7 image families are globally invalidated by the provenance/config change and must be rebuilt and verified\n\nCloses #215\nCloses #216",
          "author": "dongkeren",
          "createdAt": "2026-07-16T08:40:17Z",
          "mergedAt": "2026-07-16T08:43:19Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 94,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/94",
          "title": "fix(ci): grant web surface Actions read",
          "body": "## Summary\n- grant the Buildchain Web Surface caller `actions: read`\n- enforce the permission in the site infrastructure contract check\n- unblock KFD release propagation preview and staging\n\n## Verification\n- `pnpm run build`\n- `pnpm run check`\n\n## Governance\n- [x] No credentials, tokens, secrets, or private logs changed\n- [x] No provider, billing, quota, or usage attribution changes\n- [x] No official branding, package identity, or domain changes\n- [x] Release evidence and deployment behavior remain Buildchain-owned",
          "author": "dongkeren",
          "createdAt": "2026-07-16T09:07:35Z",
          "mergedAt": "2026-07-16T09:16:35Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 982,
          "url": "https://github.com/kungfu-systems/kungfu/pull/982",
          "title": "feat(storage): harden Episode CLI concurrency",
          "body": "## Summary\n\nComplete the single-machine Episode CLI and SDK concurrency hardening stage. Public Episode mutations now absorb only the exact native pre-append manifest_writer_busy outcome through bounded observable retry, while unknown outcomes still fail without replay. Managed Rewind runs own the full begin-through-artifact-through-close lifecycle, including best-effort abort on exceptions, Ctrl-C, and SIGTERM. Operators also gain a conservative plan/execute recovery path that fences the exact event-stream writer and revalidates the target manifest frame under the native writer guard.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Add bounded Episode writer retry receipts and machine-readable timeout errors.\n- Put provider execution, payload references, bundle emission, and terminal close under one lifecycle guard.\n- Add fail-closed storage episode recover --plan/--execute with writer-liveness and native manifest-frame fencing.\n- Add Python and Node binding parity for the recovery precondition and active writer inspection.\n- Qualify real independent CLI processes, terminal lifecycle handling, fsck, inspect, and readback.\n- Calibrate ADR-0041 to accepted/staged with prior implementation commits and current qualification references.\n\n## Verification\n\n- ./shifu check:source\n- ./shifu test:episode-control (21 passed)\n- ./shifu episode:qualify -- --profile mvp-smoke-v1 (5/5 scenarios, qualified=true)\n- ./shifu docs:check:readonly (62/62 contract tests)\n- ./shifu build:core\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0041\"],\n  \"summary\": \"Complete the Episode manifest writer and lifecycle hardening stage with bounded contention retry and fenced stale-open recovery\",\n  \"verification\": [\"./shifu check:source\", \"./shifu test:episode-control (21 passed)\", \"./shifu episode:qualify -- --profile mvp-smoke-v1 (5/5 scenarios, qualified=true)\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: additive pre-release Episode CLI and capability SDK behavior only. The native manifest store remains acquire-or-fail; retry is exact-error-only and bounded, and recovery fails closed on unknown liveness or changed facts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T07:54:40Z",
          "mergedAt": "2026-07-16T09:25:10Z",
          "additions": 1649,
          "deletions": 209,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 93,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/93",
          "title": "chore: consume KFD release",
          "body": "Buildchain release propagation from @kungfu-tech/kfd into the kfd.libkungfu.dev site surface.\n\nBuildchain release propagation plan:\n\n```json\n{\n  \"schemaVersion\": 1,\n  \"contract\": \"kungfu-buildchain-release-propagation-plan\",\n  \"source\": \"kfd\",\n  \"upstreamRelease\": {\n    \"repository\": \"kungfu-systems/kfd\",\n    \"channel\": \"alpha\",\n    \"tag\": \"v1.0.0-alpha.26\",\n    \"sourceSha\": \"85b8c6cccc042b27683d0f35539e94c0a39c3ac0\",\n    \"package\": {\n      \"name\": \"@kungfu-tech/kfd\",\n      \"version\": \"1.0.0-alpha.26\",\n      \"integrity\": \"sha512-GGMnJlP7jFXhZQ9dzO7UD1OuB3+EVhhiFdMzQySgswVCKy2Yp93zB26E8c8IAulEnssaS8++4q+uOJwQJLwIVg==\"\n    },\n    \"releasePassport\": {\n      \"url\": \"https://github.com/kungfu-systems/kfd/releases/download/v1.0.0-alpha.26/buildchain.release.json\",\n      \"sha256\": \"14b43eb840cb31e8083aec3a78fa850841a8a8ae574a056857c7eaa8e49c2dfc\"\n    }\n  },\n  \"targets\": [\n    {\n      \"edge\": \"kfd-to-site-libkungfu-dev\",\n      \"source\": \"kfd\",\n      \"target\": \"site-libkungfu-dev\",\n      \"repository\": \"kungfu-systems/site-libkungfu-dev\",\n      \"channel\": \"alpha\",\n      \"baseRef\": \"main\",\n      \"lockPath\": \"buildchain.upstreams/kfd.release.json\",\n      \"lock\": {\n        \"schemaVersion\": 1,\n        \"contract\": \"kungfu-buildchain-release-propagation-lock\",\n        \"upstream\": {\n          \"node\": \"kfd\",\n          \"repository\": \"kungfu-systems/kfd\",\n          \"channel\": \"alpha\",\n          \"tag\": \"v1.0.0-alpha.26\",\n          \"sourceSha\": \"85b8c6cccc042b27683d0f35539e94c0a39c3ac0\",\n          \"package\": {\n            \"name\": \"@kungfu-tech/kfd\",\n            \"version\": \"1.0.0-alpha.26\",\n            \"integrity\": \"sha512-GGMnJlP7jFXhZQ9dzO7UD1OuB3+EVhhiFdMzQySgswVCKy2Yp93zB26E8c8IAulEnssaS8++4q+uOJwQJLwIVg==\"\n          },\n          \"releasePassport\": {\n            \"url\": \"https://github.com/kungfu-systems/kfd/releases/download/v1.0.0-alpha.26/buildchain.release.json\",\n            \"sha256\": \"14b43eb840cb31e8083aec3a78fa850841a8a8ae574a056857c7eaa8e49c2dfc\"\n          }\n        },\n        \"downstream\": {\n          \"node\": \"site-libkungfu-dev\",\n          \"repository\": \"kungfu-systems/site-libkungfu-dev\",\n          \"channel\": \"alpha\",\n          \"baseRef\": \"main\",\n          \"lockPath\": \"buildchain.upstreams/kfd.release.json\"\n        },\n        \"propagation\": {\n          \"graphContract\": \"kungfu-buildchain-release-propagation-graph\",\n          \"edge\": \"kfd-to-site-libkungfu-dev\",\n          \"channelPolicy\": \"preserve\",\n          \"channelMap\": {\n            \"alpha\": \"alpha\",\n            \"release\": \"release\"\n          },\n          \"exact\": true,\n          \"floatingTags\": false\n        },\n        \"lockSha256\": \"c6f98b4350568065f3d731ad4150d0b5ba02951a9b89365fed0c3c36412e4417\"\n      }\n    }\n  ],\n  \"summary\": {\n    \"targetCount\": 1,\n    \"channels\": [\n      \"alpha\"\n    ],\n    \"repositories\": [\n      \"kungfu-systems/site-libkungfu-dev\"\n    ]\n  }\n}\n```\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-16T08:55:21Z",
          "mergedAt": "2026-07-16T09:45:19Z",
          "additions": 58,
          "deletions": 8,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 984,
          "url": "https://github.com/kungfu-systems/kungfu/pull/984",
          "title": "feat(release): enforce consumer qualification before publication",
          "body": "## Summary\n\nComplete the closed-world publication cutover by wiring Kungfu's project-owned qualification predicate into Buildchain v2.13.0 before provider mutation.\n\n## Related issue\n\n- kungfu-systems/buildchain#1307\n\n## Changes\n\n- pin Buildchain v2.13.0 and its stable/alpha contract worlds across source, build, and release controllers\n- bind `alpha` to the exact `v2-alpha` runtime and `release` to the exact `v2` runtime, with each policy entry checked against its contract lock\n- run a credential-free Kungfu predicate over the complete Gate aggregate and sealed publication capability\n- reject missing platform evidence, unknown or incomplete Gate closure, runtime/policy/source/artifact drift, stale receipts, and nonce replay\n- require Buildchain to seal and revalidate the consumer receipt before publication; no no-Gate or legacy fallback is enabled\n- keep workflow authority, bindings, policy docs, and negative fixtures machine-aligned\n\n## Verification\n\n- `./shifu check:gate-catalog`\n- `./shifu test:release-admission`\n- `./shifu release:promotion:rehearse`\n- `./shifu check:source`\n- staged pre-commit gate, documentation contract, ADR audit, Biome, Rust format/clippy/tests, and KFD evidence checks\n\n## Publication boundary\n\nThis PR changes release authority and verification contracts but does not itself publish product artifacts. The post-merge canary will record the exact Buildchain runtime, workflow run, qualification receipt/passport digest, and expected fail-closed direction.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0007\"],\n  \"summary\": \"Complete the Kungfu consumer-owned predicate handoff and require its sealed qualification receipt before provider publication writes.\",\n  \"verification\": [\"./shifu check:gate-catalog\", \"./shifu test:release-admission\", \"./shifu release:promotion:rehearse\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe predicate job has read-only source access, no inherited secrets, no Environment, no OIDC, and no provider write permission.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T09:24:42Z",
          "mergedAt": "2026-07-16T10:12:49Z",
          "additions": 646,
          "deletions": 173,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 981,
          "url": "https://github.com/kungfu-systems/kungfu/pull/981",
          "title": "fix(runtime,core): forward create_task kwargs, declare+widen mypy surface, classify pyproject in native gate",
          "body": "## Summary\n\nFour related changes around Python typing and the gate that enforces it.\n\n**`create_task` dropped its keyword arguments.** `LiveEventLoop.create_task`\naccepted only the coroutine, silently discarding the `name=` and `context=`\nkeywords its supertype defines. `asyncio.TaskGroup` calls\n`self._loop.create_task(coro, name=name, context=context)`, so any strategy code\nreaching for a `TaskGroup` would raise `TypeError`. It does not fire today only\nbecause the sole entry path, `asyncio.ensure_future`, passes no keywords — a\ntrap waiting to spring rather than a live failure. Verified by loading the\nmodule and making the exact call `TaskGroup` makes:\n\n```\nbefore: create_task signature: (self, coro)\n        TaskGroup-style call: FAILED -> unexpected keyword argument 'name'\nafter:  create_task signature: (self, coro, *, name=None, context=None)\n        TaskGroup-style call: OK, task name = tg-style\n        legacy positional call: OK  (no regression)\n```\n\n**The type-checked surface was a path argument, not a declaration.** Both\n`verify.mjs` and `source-acceptance.mjs` passed `src/python/kungfu` on the\ncommand line, so the two could drift apart, and nothing outside\n`framework/core/src` was ever checked. The surface now lives in `files` under\n`[tool.mypy]`, and three siblings join it: the public `kungfu_sdk`, the\ncapability `guest-harness`, and the `mission-control-actions` extension domain.\nChecked files go from 138 to 148.\n\n**Widening the surface immediately caught a real defect in newer code.**\n`_bounded_followups` (added on `dev/v4/v4.0` after this branch first opened, in\n`d1fb9176f`) declares `-> list[dict[str, Any]]` but built its accumulator from a\nbare list, so mypy inferred the element type from the appended literal and\njoined it down to `dict[str, Sequence[str]]`. That made `row[\"goal_id\"]` a\n`Sequence`, which is not declared comparable, and the `result.sort(key=...)`\nfailed to type-check. Fixed by annotating the accumulator to match the declared\nreturn type. The compiled bytecode for the function is byte-identical before and\nafter, so this is a pure annotation with no runtime effect. This is exactly the\nclass of regression the widened gate exists to stop.\n\n**Widening the surface also exposed a gap in the affected-native gate itself.**\nThat gate (added earlier today) lists `conanfile.py`, `CMakeLists.txt`, and\n`package.json` as Core build definitions that expand globally, but omitted\n`framework/core/pyproject.toml` — which now pins the native toolchain after the\nruntime deps were split into it. Any edit to that file fell through to the\nunclassified branch and failed the required check closed. This branch is the\nfirst to change `pyproject.toml` since the gate landed, so it is the first to\nhit it. Fixed by classifying the file with its siblings; since the gate cannot\nread TOML sections, a change now expands globally and re-validates every\ncomponent. Verified against real authority data: `pyproject.toml` yields the\nfull 12/12 component closure while a `src/python` change still schedules none.\n(This is why this PR runs the full native matrix rather than a no-op.)\n\nTwo honest notes on that gate fix. First, `dev` independently added\n`framework/core/tests/` to the same list while this branch was open, so the\nomission was not unique to `pyproject.toml`; the two classifications are\ncomplementary and rebased together cleanly. Second, the `--self-test` case added\nhere (`core build definition change expands globally`) does **not** run in CI —\nno workflow passes `--self-test`, so the whole self-test suite is currently\ndead code. The classification was therefore verified by driving `planFromChanged`\nagainst the real authority data instead (`pyproject.toml` -> 12/12 component\nclosure, kind `architecture-or-gate-authority`; a `src/python` change -> 0). The\ncase is added anyway so it is correct whenever the suite is wired up, and wiring\nit up (plus repairing the cases that have already silently broken) is tracked\nseparately rather than expanded into this PR.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fixes a dropped-keyword defect in the live event loop, declares and widens the mypy surface, annotates a follow-up accumulator, and classifies pyproject.toml in the affected-native gate; no architecture contract or ADR record is altered\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Verification\n\n- `uv run --frozen mypy` (framework/core, mypy 1.20.2): Success, 148 source files, 0 errors\n- `uvx --from mypy==1.20.2 mypy --config-file pyproject.toml` (CI's exact form): Success, 148 source files, 0 errors\n- `node --test scripts/source-acceptance.test.mjs`: 14/14 pass\n- `pytest tests/python/test_event_loop_concurrency.py`: 6 passed\n- `ruff format --check` / `ruff check` on the changed modules: clean\n- The new scope guard was negatively verified: removing one `files` entry turns\n  it red, restoring it turns it green.\n- The mission-control fix was proven runtime-neutral by a byte-identical\n  bytecode comparison of the changed function.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T07:24:33Z",
          "mergedAt": "2026-07-16T11:49:24Z",
          "additions": 92,
          "deletions": 20,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 219,
          "url": "https://github.com/kungfu-systems/build-images/pull/219",
          "title": "fix(comparator): bind native Aeron release authority",
          "body": "## Summary\n\n- require an exact public release tag, official origin tag, Release Passport, trusted check report, and GitHub release asset digests before native measurement\n- retain and digest-bind the exact runner, authority inputs, and an independent public-release receipt in the qualification bundle\n- make offline verification execute and authenticate the bundled runner, with fail-closed source/material and tamper checks\n\nThis advances #170. The issue remains open until the next alpha exact-tag 31/31 native replay is attached.\n\n## Verification\n\n- `python3 -m unittest pilots.comparator.tests.test_aeron_native_qualification` (15 tests)\n- `pnpm run check:qualification` (77 tests)\n- `pnpm run check`\n- `git diff --check`\n- real public `v1.2.4-alpha.23` authority probe",
          "author": "dongkeren",
          "createdAt": "2026-07-16T12:09:41Z",
          "mergedAt": "2026-07-16T12:48:10Z",
          "additions": 677,
          "deletions": 13,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 983,
          "url": "https://github.com/kungfu-systems/kungfu/pull/983",
          "title": "fix(project-cut): close three-agent dogfood command gaps",
          "body": "## Summary\n\nClose the concrete gaps exposed by the first three-agent Project Cut dogfood without claiming that public settlement is complete.\n\nActor A welds the public completion/review/continuation command catalogs to the live Click option contracts. Actor B retains an independent unverifiable review and a rooted continuation plan. Actor C follows that plan with zero human relay, makes no-Cut reconciliation fast and fail-visible, and preserves a single JSON document on the public Shifu surface.\n\n## Related issue\n\nAtlas goal: 2026-07-15-project-cut-atlas-repo-dogfood\n\n## Changes\n\n- Add automatic Click-to-KFD-3 command signature parity for claim-completion, review-completion, and decide-continuation.\n- Retain Actor B review and continuation-plan evidence with no fabricated Cut or Completion Claim roots.\n- Fail no-Cut reconciliation with missing-cut, a non-zero exit, and an exact prepare-project-cut recovery action.\n- Short-circuit no-Cut commits before a full repository source scan.\n- Dispatch Project Cut directly through shifu and shifu.cmd so pnpm lifecycle text cannot pollute JSON stdout.\n- Route both shims through a Node argv dispatcher so Windows does not rely on the incorrect assumption that SHIFT removes the first token from %*.\n- Cover both the direct CLI and the public Shifu entrypoint.\n\n## Verification\n\n- ./shifu test:project-cut-settlement: 6/6 passed.\n- ./shifu check:source: 364 Node, 76 Python, and 69 desktop-adapter tests passed.\n- Public reconcile at exact head 50f7735c107b3dee18fa0b85326f85465d24fbae: exit 1, one parseable JSON stdout line, missing-cut, prepare-project-cut recovery, receipt sha256:36408201528dc102faaed277f7cf5a1553515e8d464dd69e88ef12858f315791.\n- Actor A focused command-contract tests: 12 passed.\n- Actor B verdict: unverifiable, false_fit=0, false_block=0, human relay=0.\n- Actor C public workspace continuation: selected-uninitialized -> initialized -> ready, human relay=0.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0101\", \"ADR-0105\"],\n  \"summary\": \"Close command-contract and public no-Cut diagnostic gaps found by three-agent Project Cut dogfood\",\n  \"verification\": [\"project-cut settlement tests\", \"source acceptance\", \"public Shifu JSON failure probe\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes the public agent-first CLI and retains bounded dogfood evidence. It does not add credentials, private transcripts, or a production qualification claim; exact-head source acceptance and public CLI probes are listed above.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T09:13:52Z",
          "mergedAt": "2026-07-16T12:57:12Z",
          "additions": 386,
          "deletions": 61,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 221,
          "url": "https://github.com/kungfu-systems/build-images/pull/221",
          "title": "chore(release): join alpha.25 material history",
          "body": "## Scope\n\n- join the exact `v1.2.4-alpha.25` material ancestry into `dev/v1/v1.2`\n- preserve the current dev tree byte-for-byte\n- satisfy strict up-to-date history before PR #220 promotes the native release-authority closure\n\n## Verification\n\n- alpha head `a7eca71e286037bfac6e4cb9ce1f1c609a4371cd` is an ancestor of this branch\n- merge tree equals the first-parent dev tree (`b32989629d04303f0a487b2bd7e425fce2affb61`)\n- `git diff HEAD^1..HEAD` is empty\n- no business-file delta",
          "author": "dongkeren",
          "createdAt": "2026-07-16T12:58:58Z",
          "mergedAt": "2026-07-16T13:27:38Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 220,
          "url": "https://github.com/kungfu-systems/build-images/pull/220",
          "title": "release: promote native Aeron release authority to alpha",
          "body": "## Summary\n\nPromote the exact public-release authority closure for native Aeron qualification to the alpha channel.\n\nThe promoted runner requires and retains the public release tag, official origin tag, Release Passport, trusted check report, GitHub asset digests, and bundled-runner offline verification before it can issue native authority.\n\nIssue #170 remains open until the resulting exact alpha tag completes the 31/31 agent-120 replay.\n\n## Source\n\n- dev material: `5a740a9923c44a41817063e69b71377a4844e98e`\n- implementation PR: #219",
          "author": "dongkeren",
          "createdAt": "2026-07-16T12:48:40Z",
          "mergedAt": "2026-07-16T13:31:51Z",
          "additions": 679,
          "deletions": 15,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 992,
          "url": "https://github.com/kungfu-systems/kungfu/pull/992",
          "title": "fix(core): retain native diagnostics and initialize live KV storage",
          "body": "## Summary\n\n- retain bounded coordinator and peer log tails when native live-Peer qualification fails\n- initialize writable RocksDB live-KV stores through a writable open on their first read\n- preserve exact Windows profile payload bytes and classify Python/qualification changes without scheduling unrelated native work\n- terminate and reap the verified Windows supervisor process tree before cleanup and restore the stable host temp for endpoint-bearing qualification suites\n- retain paired qualification reports and compressed raw logs through the Buildchain failure-evidence path\n\n## Root causes\n\nComposable build profiles moved the live KV adapter behind a provider seam. Coordinator startup creates the runtime layout directory before the RocksDB database exists; the first read incorrectly used `OpenForReadOnly` and exited before storage readiness because `CURRENT` was absent.\n\nThe exact-head three-platform qualification then exposed two teardown/isolation defects. Windows process termination bypasses the supervisor cleanup `finally` block, so coordinator descendants could survive and retain `coordinator.log`; the verified Windows stop path now terminates and reaps the full process tree. Linux zero-burden suites inherited the repository-local Buildchain temp path for AF_UNIX endpoints instead of the stable runner host temp. Windows hosted runners also do not always grant symlink creation privilege, so two symlink-only tests now skip only on `WinError 1314` rather than failing before the product code is exercised.\n\n## Validation\n\n- `./shifu core:affected -- --self-test` (12/12)\n- `./shifu check:source` (source acceptance 365/365, runtime upgrade 76/76, Desktop 69/69)\n- zero-burden qualification contract tests (5/5)\n- runtime supervisor tests (35/35)\n- staged DCO, ruff, mypy, Biome, architecture, documentation, and Buildchain contract gates\n- hosted Windows exact-head qualification: run 29478506833\n- complete macOS/Linux/Windows exact-head qualification: run 29478515775\n- exact source: `77f24e1f5b6d5e552ad5ee3d1333b05115cc447f`\n- exact Buildchain v2.12.8 runtime: `874d9ec40b739ad9cad7686cb4bce8f7a07709cb`\n\nThe two final workflow runs are active. This PR must not merge until both runs, required checks, and the retained paired report/raw-log audit succeed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repairs live KV first-open behavior, process teardown, qualification isolation, and retained diagnostics without changing runtime architecture or product claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR repairs runtime initialization and retained qualification diagnostics only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] No credentials or generated qualification evidence are committed\n\n\n### Windows aggregate qualification follow-up\n\n- `e2c967a345` routes zero-burden Windows Shifu suites through the established ComSpec adapter and retains launch errors in raw logs.\n- Local exact-head validation: source acceptance 365/365, runtime upgrade 76/76, desktop update 69/69, qualification/lifecycle targeted tests 28/28.\n- Exact-head hosted reruns: Windows `29486238947`; full matrix `29486241557`.\n\nDo not merge until both reruns and the refreshed PR checks are complete.\n\n### Current exact-head qualification after latest dev sync\n\n- Current source: `676830f600d0393c45c28427df907796ac26f1d8` (includes `dev/v4/v4.0` at `9d8366bcca`).\n- Source acceptance: 365/365 contracts, 76/76 runtime upgrade, 69/69 desktop update; affected-native self-tests 14/14; targeted qualification tests 28/28.\n- Hosted Windows qualification: `29487983091`.\n- Full self-hosted macOS/Linux/Windows matrix: `29487987691`.\n\nEarlier run ids in this description are superseded by these exact-head runs. Do not merge until both current runs and refreshed required checks pass.\n\n### Superseding exact-head qualification after publication-gate sync\n\n- Current source: `a4a43c6fa4976fa312387ce79f5c20bc458287bb` (includes `dev/v4/v4.0` at `5056876a6c`).\n- Source acceptance: 366/366 contracts, 76/76 runtime upgrade, 69/69 desktop update.\n- Hosted Windows qualification: `29491016242`.\n- Full self-hosted macOS/Linux/Windows matrix: `29491020161`.\n\nThis section supersedes every earlier exact-head/run-id section. Do not merge until both runs and the refreshed required checks pass.\n\nSupersedes #970 with an equivalent linear history because this repository permits rebase merges only. The final tree matches the qualified #970 head after integrating the current dev/v4/v4.0 base.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T13:08:42Z",
          "mergedAt": "2026-07-16T14:15:33Z",
          "additions": 553,
          "deletions": 33,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 97,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/97",
          "title": "fix(kfd): render foundation model page",
          "body": "## Summary\n\n- render the bundle-owned KFD foundation model at `/foundation/`\n- route homepage foundation links to the rendered page instead of GitHub\n- expose the page in KFD navigation and agent read order\n- verify route aliases, Markdown tables, navigation, and authority metadata\n\n## Verification\n\n- `pnpm run build`\n- `pnpm run check`\n- `node --check scripts/render-site.mjs`\n- `bash -n scripts/check-site.sh`",
          "author": "dongkeren",
          "createdAt": "2026-07-16T11:59:16Z",
          "mergedAt": "2026-07-16T14:18:22Z",
          "additions": 113,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 993,
          "url": "https://github.com/kungfu-systems/kungfu/pull/993",
          "title": "feat(project-cut): seal public runtime episodes",
          "body": "## Summary\n\nClose the public Episode seal and settlement gap exposed by the independent Project Cut phase gate.\n\nThe public `project-cut episode-seal` surface now accepts a real runtime bundle plus typed C++ fsck qualification, plans by default, seals only on `--execute`, stages only exact tracked outputs, and carries the qualification preimage beside the immutable Git shadow. Lossless uint64 parsing keeps runtime timestamps exact while the Git JSON boundary explicitly projects values above the JavaScript safe range as decimal strings. A retained real-runtime fixture proves the same non-empty Episode/provider/Atlas/Cut chain from a fresh checkout.\n\n## Related issue\n\nAtlas goal: `2026-07-16-project-cut-public-seal-settlement`\n\n## Changes\n\n- Add the public agent-first `project-cut episode-seal` plan/execute/stage command.\n- Preserve typed `schema` and `policy_source` fields across the Core C++ to Python qualification projection.\n- Retain canonical `qualification.json` beside `claims.jsonl` and `manifest.json`; include it in fsck, export, and import.\n- Preserve runtime uint64 JSON tokens losslessly and project above-safe-range values as bounded decimal strings at the Git shadow boundary.\n- Migrate the existing Xinfa Episode fixture to the qualification-retaining provider contract.\n- Retain a real public runtime Episode bundle and qualification fixture and exercise seal, successor Atlas compilation, settlement, publication, and fresh-checkout reconcile.\n- Add the Episode manifest fsck boundary test to the public `test:episode-control` suite.\n\n## Exact qualification\n\n- Exact head: `721603ae4e5750f77fd201bae0b4f2385ac3b68d`.\n- Runtime Episode semantic root: `sha256:1953196f53ac451b64542456ba49c6333f6fda176975aa96518e2604a8237bcf`.\n- Git provider root: `sha256:97c263b6898e2ed7ac280472554cbdcfb55d203c6f946a26e1aa21cbc50f78f0`.\n- Typed qualification root: `sha256:8f161379ffa5bf4719e4fd759fb00bf062461019324bb27ed72697912af1bd9b`.\n- Real successor Atlas root: `sha256:5730b530b767a89df75e63a790160198485f0a953c8ecf390c22925a12d71190`.\n- Real Project Cut root: `sha256:885f6db7adba465aea533517fcdeffece85a7a1f339dc5aeef708155e3c55c90`.\n- Disposable publication commit: `35cc7935c951a59eb05029ebf79651b2baed021c`; `commit-observe` status `published`; fresh checkout reconciled the identical cut and source projection roots.\n\n## Verification\n\n- `./shifu rebuild:core`: passed after both typed C++ qualification changes.\n- `./shifu test:episode-control`: 43/43 passed in the built Core/Python boundary.\n- `./shifu test:project-cut-settlement`: 7/7 passed.\n- `./shifu test:project-cut-settlement:integration`: 2/2 passed at the exact head, including public seal through fresh-checkout reconcile.\n- `./shifu check:source`: passed at the exact head; 369 Node, 76 runtime-upgrade Python, and 69 desktop-adapter tests passed.\n- `./shifu core:affected`: exact head classified as full / `github-hosted-linux-native-pr` with the complete affected Core component and target set.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0100\", \"ADR-0101\"],\n  \"summary\": \"Deliver the public qualified Episode seal and non-empty Project Cut settlement chain\",\n  \"verification\": [\"Core rebuild and Episode control suite\", \"Project Cut settlement integration\", \"source acceptance\", \"fresh-checkout reconcile\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes a public agent-first CLI and the tracked Episode evidence provider. It retains only public thin Episode records and typed qualification evidence; raw journals, payload material, runtime state, private data, and credentials remain excluded and fail closed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T14:15:03Z",
          "mergedAt": "2026-07-16T15:06:18Z",
          "additions": 577,
          "deletions": 31,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1338,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1338",
          "title": "feat(governance): make release retries and dev landing converge",
          "body": "## Summary\n\nMake duplicate release promotion converge without mutating existing evidence, and add a dry-run-first governance command for replacing strict up-to-date races with an exact dev-channel merge queue.\n\n## Related issue\n\nCloses #1334\nCloses #1335\n\n## Changes\n\n- preserve byte-identical GitHub Release assets and fail closed on same-name byte drift\n- add `buildchain dev merge-queue` with workflow compatibility validation and idempotent ruleset reconciliation\n- document the v2.14 additive surface decision and regenerate the public site contract\n\n## Verification\n\n- `pnpm run check` (649 tests passed)\n- `git diff --check`\n- live dry-run against `kungfu-systems/kungfu` dev protection\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nExisting release evidence is now immutable on retry. The governance mutation is dry-run by default, exact-branch scoped, and covered by operation-order and idempotency tests.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-16T15:07:18Z",
          "mergedAt": "2026-07-16T15:08:40Z",
          "additions": 697,
          "deletions": 106,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 996,
          "url": "https://github.com/kungfu-systems/kungfu/pull/996",
          "title": "ci(dev): support merge queue check events",
          "body": "## Summary\n\nMake every required dev workflow compatible with GitHub merge queue events so slow checks can validate the queued merge result instead of restarting after each base update.\n\n## Related issue\n\n- kungfu-systems/buildchain#1335\n\n## Changes\n\n- add `merge_group` triggers to the three required dev workflows\n- resolve affected-native base and head revisions from either pull request or merge group payloads\n- refresh the governed workflow authority digests and add a regression test\n\n## Verification\n\n- `./shifu check:source` (370 Node tests, 76 runtime upgrade tests, 69 desktop update tests; passed)\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs` (19 passed)\n- `actionlint` on all changed workflows\n- Buildchain merge queue governance dry-run against live branch protection\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This CI-only change preserves product and architecture contracts while adding the required merge_group event envelope\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change adapts required workflows to GitHub merge queue events. It does not widen permissions or publication authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-16T15:07:17Z",
          "mergedAt": "2026-07-16T15:23:12Z",
          "additions": 60,
          "deletions": 12,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1339,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1339",
          "title": "fix(governance): honor repository merge methods",
          "body": "## Summary\n\nMake dev merge queue reconciliation select a merge method that the target repository actually permits.\n\n## Related issue\n\nFollow-up validation for #1335.\n\n## Changes\n\n- read repository merge-method settings before planning the ruleset\n- choose the first enabled method and fail closed when none are enabled\n- document the behavior and regenerate the public site contract\n\n## Verification\n\n- `pnpm run check` (650 tests passed)\n- live dry-run against `kungfu-systems/kungfu` selected `REBASE`\n- `git diff --check`\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe command remains dry-run by default. The live plan caught and prevented an incompatible MERGE queue policy before any repository setting changed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-16T15:27:33Z",
          "mergedAt": "2026-07-16T15:30:40Z",
          "additions": 52,
          "deletions": 14,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1340,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1340",
          "title": "fix(web-surface): seal managed production authority",
          "body": "## Summary\n- grant the plan job explicit pull-request and issue write permissions for its review/report side effects\n- resolve trusted manual or reviewed release-PR production decisions and assemble a managed sealed web-production capability\n- bind source, runtime, production plan/artifact hash, qualifying controller receipt, Environment, AWS role target, runner provenance, nonce, and decision before artifact download\n- retain the external evidence input surface and add the missing Gate aggregate input\n\n## Validation\n- `actionlint .github/workflows/.web-surface.yml`\n- `pnpm run check` (655 tests passed)\n- `node --test tests/web-surface-publication-authority.test.mjs` (5 tests passed after final fixture addition)\n- `pnpm run check:site`\n- `pnpm run check:workflows`\n\nCloses #1336\nCloses #1337",
          "author": "dongkeren",
          "createdAt": "2026-07-16T15:51:51Z",
          "mergedAt": "2026-07-16T15:56:02Z",
          "additions": 1211,
          "deletions": 72,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 132,
          "url": "https://github.com/kungfu-systems/kfd/pull/132",
          "title": "feat(kfd): define perspective replay infrastructure",
          "body": "## Summary\n\n- make KFD-4 the declared-perspective principle and define timelines, perspective-preserving replay, and contrastive replay as its first engineering profiles\n- connect KFD-5 primitive genesis and KFD-6 autonomous discovery to replay-grounded causal experience\n- publish and self-verify a KFD-4 replay schema through KFD-1/2/3 evidence, standards metadata, site bundle, and Buildchain expected artifacts\n- retain Agent Runtime as Kungfu's product category while stating its deeper KFD role: reality-preserving perspective transformation\n\n## Verification\n\n- `npm run update:evidence`\n- `npm run check`\n- deterministic evidence regeneration\n- `npm pack --dry-run --json`\n- `git diff --check`\n\n## Release impact\n\nPre-stable major decision/interface refinement with immutable prior prerelease artifacts; the outer KFD package line remains v1.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T15:50:21Z",
          "mergedAt": "2026-07-16T15:59:25Z",
          "additions": 1547,
          "deletions": 841,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 985,
          "url": "https://github.com/kungfu-systems/kungfu/pull/985",
          "title": "test(yijinjing): qualify the ADR-0001 publish protocol on the production surface",
          "body": "ADR-0001 replaced the journal's `volatile` publish protocol with `atomic_ref`\nrelease/acquire after a human read a torn frame. The gate that accepted it used\na **standalone harness that mirrored** the protocol, so the shipped surface was\nqualified by a model rather than by itself, and the ADR's own next direction (1)\n— scrutiny of the `close_page` / page-switch visibility — stayed open.\n\nThis makes the evidence machine-driven and points it at the production surface.\n\n## What lands\n\n- **`yijinjing_journal_stress`** — a real single writer process and several real\n  reader processes share the same mmap pages and drive the production `writer` /\n  `journal` reader APIs. Every frame carries a magic, a monotonic sequence, and\n  an FNV-1a-64 body hash, so each reader content-verifies what the acquire gate\n  let it see. Violations classify as torn body, wrong magic, short frame, gap, or\n  reorder/duplicate. Receipts follow the `mmap_qualification` culture\n  (`schema: kungfu.journal-stress.v1`, scratch-only state, `--output` refuses to\n  overwrite).\n- **Three deterministic `mmap_tests` cases**:\n  - `close_page` must create the next page *before* publishing PageEnd — a reader\n    in another process that observes PageEnd advances immediately and a plain\n    reader has no authority to create the page. That ordering was guarded only by\n    a source comment. The probe checks from inside the rollover, because the end\n    state holds either way.\n  - `page::load` spins on the `last_frame_position` token when opening a virgin\n    page without initialization authority; a concurrent initializer must release\n    that spin and the acquiring reader must see a published header, not the\n    zeroed bytes it started from.\n  - the k-way merge must yield one non-decreasing `gen_time` order across joined\n    journals of equal priority, including frames written at identical times.\n- **`./shifu qualify:journal-stress`** — same entry shape as `qualify:mmap`.\n\nThe full multi-process run is deliberately **not** a default ctest (minutes long,\nPOSIX-only). Only the portable checker self-test is registered, and the soak is\ndriven on the local hosts per the heavy-validation-is-local principle.\n\n## Why a clean run is not vacuously green\n\n- `yijinjing_journal_stress --self-test-checker` (ctest\n  `yijinjing_journal_stress_checker`) feeds the checker known-bad streams and\n  asserts each is flagged.\n- `--inject corrupt-body|gap|duplicate|reorder` surfaces a fault end-to-end\n  through the real cross-process transport; a clean run **under injection** is\n  reported as a failure (`injection_escaped`), not a pass.\n- The page-turn probe was verified against a mutant that publishes PageEnd before\n  loading the next page: it fails there and passes on current source.\n\n## What this does not establish\n\nThese runs execute against the *fixed* protocol, so they detect rather than\nreproduce. The injections are content and sequence faults — they prove the\nreader/checker path surfaces a violation, they are not a memory-ordering\nregression. The ARM control equivalent to ADR-0001's volatile-vs-`atomic_ref`\ntable requires rebuilding libyijinjing with a release store downgraded to\nrelaxed; that procedure is documented in `tests/JOURNAL_STRESS.md` and is\ndeliberately manual, since the miscompiled library must never merge.\n\n## Verification (Apple Silicon)\n\n**30 minute soak** (`--profile soak`, 3 reader processes, Apple M-series arm64,\nreceipt `kungfu.journal-stress.v1`, harness built from `1a308b3586`):\n\n| | |\n|---|---|\n| verdict | **clean** |\n| duration | 1800.0 s continuous |\n| frames written | **233,209,315** |\n| page rolls | **243,374** |\n| per-reader frames observed | 233,209,315 (x3, `count_matches: true`) |\n| violations | **0** across all three readers |\n| stalls | none |\n\nThat is ~700M cross-process frame verifications and ~243k executions of the\n`close_page` turn-page protocol on a weak-memory host, with every frame\ncontent-checked against its body hash and sequence.\n\nOther evidence on the same host:\n\n- **ctest 7/7** via the libyijinjing embedding contract, including\n  `yijinjing_mmap_tests` (23/23, with the three new cases) and the new\n  `yijinjing_journal_stress_checker`.\n- **checker self-test 6/6** — clean stream not flagged; torn body, wrong magic,\n  short frame, gap and backward sequence each flagged.\n- **smoke** 50k frames / 3 readers / ~52 page rolls: `verdict=clean`.\n- **injection** `corrupt-body`, `gap`, `duplicate`, `reorder`: each reported\n  `verdict=injected_detected`, and all three reader processes independently\n  flagged the fault at the injection point.\n- **mutant control**: publishing PageEnd before loading the next page makes the\n  page-turn test fail (`close_page published PageEnd before the next page\n  existed`); it passes on current source.\n- Architecture authority green: `check-layers` (239 first-party C/C++ files, one\n  component owner each) and `query-health` (findings=0).\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0001\"],\n  \"summary\": \"Qualify the ADR-0001 publish protocol against the production surface: a multi-process stress harness plus deterministic page-turn, virgin-page and merge-order tests.\",\n  \"verification\": [\n    \"ctest: 7/7 passed via the libyijinjing embedding contract, including yijinjing_mmap_tests (23/23) and the new yijinjing_journal_stress_checker\",\n    \"journal stress smoke: 50k frames, 3 reader processes, ~52 page rolls, verdict=clean, zero violations on Apple Silicon\",\n    \"detection proof: --inject corrupt-body/gap/duplicate/reorder each reported verdict=injected_detected by all three reader processes\",\n    \"page-turn probe verified against a mutant that publishes PageEnd before loading the next page: the test fails there and passes on current source\"\n  ]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-16T09:51:17Z",
          "mergedAt": "2026-07-16T15:59:53Z",
          "additions": 1235,
          "deletions": 7,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1341,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1341",
          "title": "chore(release): promote v2.14 alpha",
          "body": "Buildchain release line bootstrap opened v2.14. Merge this channel PR to publish the first alpha for the new minor line.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T16:02:14Z",
          "mergedAt": "2026-07-16T16:03:31Z",
          "additions": 72,
          "deletions": 72,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 135,
          "url": "https://github.com/kungfu-systems/kfd/pull/135",
          "title": "chore(release): promote KFD perspective replay to alpha",
          "body": "## Promotion\n\nPromote the KFD-4 perspective replay infrastructure and the replay-grounded KFD-5/6 continuity from `dev/v1/v1.0` to the alpha channel.\n\nSource change: #132\nSupersedes identity-invalid promotion PR #134 without changing branch content.\n\nBuildchain owns version computation, npm publication, GitHub Release creation, release passport generation, and downstream propagation.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T16:03:11Z",
          "mergedAt": "2026-07-16T16:10:33Z",
          "additions": 1547,
          "deletions": 841,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 136,
          "url": "https://github.com/kungfu-systems/kfd/pull/136",
          "title": "chore(kfd): anchor alpha 27 release",
          "body": "## Summary\n\n- advance the explicit KFD npm and release-anchor facts to `1.0.0-alpha.27`\n- regenerate KFD-1/2/3 evidence from the updated source facts\n- keep the KFD-4/5/6 content, package line, release channel, and release-impact assessment unchanged\n\n## Context\n\nThe first alpha.27 promotion attempt correctly failed because Buildchain planned tag `v1.0.0-alpha.27` while the anchored source still declared `1.0.0-alpha.26`. This restores exact version/tag agreement without bypassing the promotion gate.\n\nFailed gate evidence: https://github.com/kungfu-systems/kfd/actions/runs/29514485521\n\n## Verification\n\n- deterministic `npm run update:evidence`\n- `npm run check`\n- `npm pack --dry-run --json` reports `@kungfu-tech/kfd@1.0.0-alpha.27` with 54 files\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-16T16:13:36Z",
          "mergedAt": "2026-07-16T16:16:10Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1342,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1342",
          "title": "fix(release): enforce action bundle integrity",
          "body": "## Summary\n- regenerate the stale promote-buildchain-ref action bundle\n- make the repository check fail when action bundles change during their build\n- surface the exact stale bundle paths before promotion can start\n\n## Validation\n- pnpm run check\n- node scripts/check-action-bundles.mjs\n- git diff --check\n\nThis fixes the alpha promotion failure in run 29514245076, where version verification changed actions/promote-buildchain-ref/dist/index.js.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T16:16:53Z",
          "mergedAt": "2026-07-16T16:18:18Z",
          "additions": 87,
          "deletions": 37,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 137,
          "url": "https://github.com/kungfu-systems/kfd/pull/137",
          "title": "release(kfd): publish alpha 27",
          "body": "## Promotion\n\nPromote the exact `1.0.0-alpha.27` KFD source anchor from `dev/v1/v1.0` to `alpha/v1/v1.0`.\n\nContent source: #132\nVersion anchor: #136\nPrior failed gate: https://github.com/kungfu-systems/kfd/actions/runs/29514485521\n\nBuildchain owns npm publication, GitHub Release creation, release passport generation, and downstream propagation.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T16:16:28Z",
          "mergedAt": "2026-07-16T16:19:16Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1344,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1344",
          "title": "chore(release): promote v2.14 alpha bundle integrity",
          "body": "Promote the verified v2.14 dev fix from an alpha-based integration branch so protected ancestry remains current.\n\n- includes dev/v2/v2.14 at 86197d42a28fe5dbca72ef0c7c6d708e3bff68ff\n- supersedes closed PR #1343\n- fixes the stale action bundle failure from promotion run 29514245076",
          "author": "dongkeren",
          "createdAt": "2026-07-16T16:20:53Z",
          "mergedAt": "2026-07-16T16:22:19Z",
          "additions": 87,
          "deletions": 37,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1347,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1347",
          "title": "docs(release): require channel verification context",
          "body": "## Summary\n\n- document that managed alpha and release channels require both `check` and the Release Verify aggregate `verify`\n- regenerate the public site bundle and contract digests\n- make the branch-protection invariant explicit after the failed non-canonical alpha lineage attempt\n\n## Validation\n\n- `pnpm run check` (656 tests, 4 action bundles)\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-16T16:35:13Z",
          "mergedAt": "2026-07-16T16:36:35Z",
          "additions": 15,
          "deletions": 12,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1349,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1349",
          "title": "fix(release): make channel and propagation state converge",
          "body": "## Summary\n\n- keep alpha and release channel checks required without requiring source branches to contain generated target-channel ancestry\n- preserve the existing strict or merge-queue policy on dev during generated bookkeeping\n- require `check` plus the pair-specific `verify` aggregate on alpha/release\n- reconcile a surviving managed propagation branch with an exact remote-SHA lease\n- deterministically update the matching open propagation PR or create a new one, and seal the decision into controller evidence\n- regenerate the action bundle, site contract, and v2.14 release impact\n\n## Root causes\n\nGenerated channel bookkeeping intentionally makes dev, alpha, and release histories diverge. Strict source-up-to-date protection on the release target made the only legal `dev -> alpha` PR unable to converge.\n\nRelease propagation reused a fixed managed branch name but used a normal push. Once a merged PR left that branch behind, the next release could not fast-forward it. The workflow now observes the exact remote SHA and uses an explicit force-with-lease, so concurrent writers still fail closed.\n\n## Validation\n\n- channel/protection targeted regression: 248 tests passed\n- propagation/build-surface targeted regression: 91 tests passed\n- `pnpm run check`: full suite passed; action bundles verified\n- `git diff --check`\n\nFixes #1345\nFixes #1346\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-16T16:46:39Z",
          "mergedAt": "2026-07-16T16:56:50Z",
          "additions": 333,
          "deletions": 78,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1348,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1348",
          "title": "release: promote v2.14 alpha",
          "body": "## Summary\n\nPromote the canonical `dev/v2/v2.14` channel into `alpha/v2/v2.14` after the release-action bundle and channel verification safeguards were fixed.\n\nThis PR is the required same-repository release lineage for Buildchain alpha publication.\n\n## Validation\n\n- dev source check passed after PR #1347\n- alpha protection requires both `check` and Release Verify aggregate `verify`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-16T16:38:57Z",
          "mergedAt": "2026-07-16T17:07:57Z",
          "additions": 336,
          "deletions": 78,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1351,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1351",
          "title": "fix(release): satisfy generated required check sets",
          "body": "## Summary\n\n- derive the generated version-state status set from the managed branch protection policy after policy convergence\n- create one successful generated check run for every required context before the protected ref PATCH\n- keep the operation restricted to managed channels and fail closed if any check creation fails\n- regenerate the action bundle, site contract, and release impact\n\n## Root cause\n\nAlpha protection correctly required both `check` and `verify`, but generated version-state finalization only emitted `check`. npm trusted publishing completed, then GitHub rejected the post-publish alpha bookkeeping commit because `verify` was missing.\n\n## Validation\n\n- `node --test tests/promote-buildchain-ref.test.mjs`: 112 passed\n- `pnpm run check`: full suite passed; workflows, site contract, and action bundles verified\n- `git diff --check`\n\nFixes #1350\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-16T17:17:35Z",
          "mergedAt": "2026-07-16T17:18:53Z",
          "additions": 138,
          "deletions": 111,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1352,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1352",
          "title": "release: promote v2.14 alpha after finalization fix",
          "body": "## Summary\n\nPromote the current reviewed v2.14 development line to alpha after fixing generated required-check set finalization in #1351.\n\n## Release intent\n\n- source: `dev/v2/v2.14` at the merged #1351 fix\n- target: `alpha/v2/v2.14`\n- expected npm version: `@kungfu-tech/buildchain@2.14.0-alpha.1`\n- preserve `latest` at 2.13.0\n- complete exact/floating tags, GitHub Release, and release passport through the sealed promotion workflow\n\nThe previous alpha.0 npm transaction succeeded but post-publish bookkeeping failed before #1351. This promotion uses the fixed action bundle and advances to a new immutable alpha rather than attempting to overwrite alpha.0.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-16T17:20:47Z",
          "mergedAt": "2026-07-16T17:22:24Z",
          "additions": 138,
          "deletions": 111,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 997,
          "url": "https://github.com/kungfu-systems/kungfu/pull/997",
          "title": "fix(mission-control): close native review evidence gaps",
          "body": "## Summary\n\nClose two protocol defects exposed by the real Atlas-to-Kungfu native authority cutover qualification.\n\nIndependent completion review is a synchronous storage-backed operation, but the Profile registry classified it as a live assessment request and rejected it without broker durability evidence. Large Mission queries also omitted the composed row count, causing assessment to interpret hundreds of canonical facts as zero. This patch aligns the action class with the actual execution boundary and carries the canonical row count through batched query composition.\n\n## Related issue\n\nAtlas goal: `2026-07-16-project-cut-native-authority-cutover`\n\n## Changes\n\n- Classify `review-completion` as the storage-only `episode.append` runtime operation.\n- Update the Mission Control Profile registry digest.\n- Preserve `row_count` on composed multi-batch Mission state results.\n- Add regression coverage for storage-only review planning without live runtime evidence.\n- Assert exact composed row count for a large Mission query.\n\n## Real qualification\n\n- Imported real Atlas head `6b4ff8e98ac23882a293103d0f212cb7bb572bc5` into Episode `13006490241876826514`.\n- Cut over authority with migration `authority-ca9d482dbc5eced36ef7575b` at parity root `sha256:795b70812707ceacd4ed1dc34b17c1bffce98348d4512b5696fc4af5f7a787f0`.\n- Created a native Go, appended a completion claim, and obtained independent review `review-5e74ef091feb089a6d43f530` with verdict `fit` over 586 admitted canonical facts.\n- Applied exact-root continuation `close` as decision `decision-e032ba4f02d1f41017fdef7b`.\n- Rolled authority back to `atlas-adapter`; post-rollback native create-go failed closed and legacy Atlas import admitted new facts.\n- Exact active Profile root during qualification: `sha256:852074eab411e6d0306159d47657f2ad3f5716c4426a12f2110707f3995f738a`.\n\n## Verification\n\n- `./shifu check:source`: passed.\n- `./shifu test:agent-profile-sdk`: 56/56 passed.\n- `./shifu test:mission-authority-cutover`: Dashboard 25/25 and authority domain 4/4 passed.\n- `./shifu test:agent-review-continuation`: Dashboard 25/25 and independent review domain 1/1 passed.\n- Staged DCO, Ruff, Biome, documentation, schema authority, and Shifu contract gates passed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0104\"],\n  \"summary\": \"Qualify the native Mission and Go authority cutover with real Atlas state and repair the review proof path\",\n  \"verification\": [\"source acceptance\", \"Mission authority cutover tests\", \"independent review and continuation tests\", \"real rollback oracle\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes only public Mission Control action planning and proof-bearing query result accounting. No private Atlas payloads, runtime journals, credentials, or generated qualification bundles are committed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] Regression tests cover both defects\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T16:41:23Z",
          "mergedAt": "2026-07-16T18:10:42Z",
          "additions": 47,
          "deletions": 4,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 991,
          "url": "https://github.com/kungfu-systems/kungfu/pull/991",
          "title": "feat(storage): add destination-owned episode admission",
          "body": "## Summary\n\nAdd a destination-owned, transport-neutral Episode Admission protocol and symmetric Workspace Push/Pull initiation views.\n\n## Related issue\n\nAtlas goal 2026-07-16-kungfu-episode-push-pull-admission.\n\n## Changes\n\n- add ADR-0106 and a machine-readable Episode Admission contract\n- implement rooted plan, execute, inspect, resume, reconcile, and cancel in libkungfu\n- support local-direct, offline bundle, and simulated remote-stream adapters through one admission core\n- expose Python, TypeScript, CLI, and KFD-3 Agent projections\n- preserve source read-only behavior and keep Git publication and cleanup outside admission\n\n## Verification\n\n- ./shifu build:core\n- ./shifu test:episode-admission (3 contract, 10 Python, 3 TypeScript tests)\n- ./shifu test:episode-control (21 tests)\n- ./shifu check:source (369 source contract tests, 76 runtime upgrade tests, 69 desktop update tests)\n- staged pre-commit gate including docs, architecture, formatting, KFD evidence, and DCO\n\nThe remote-stream adapter is intentionally local-simulation-only in v1. Production networking still requires version negotiation, authentication, encryption, bounded backpressure, and exact-plan replay fences.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0106\"],\n  \"summary\": \"Deliver the destination-owned Episode Admission core and Push/Pull projections with Mac local qualification.\",\n  \"verification\": [\"./shifu build:core\", \"./shifu test:episode-admission\", \"./shifu test:episode-control\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-16T12:55:17Z",
          "mergedAt": "2026-07-16T18:33:41Z",
          "additions": 2003,
          "deletions": 28,
          "changedFiles": 36
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1001,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1001",
          "title": "feat(core): add unified health diagnostics",
          "body": "`kungfu health` turns the existing runtime, Peer, storage, and Episode facts into one read-only product preflight. It keeps each underlying authority and technical error code intact while giving people and agents a stable status, exit code, and actionable next step.\n\n## What lands\n\n- versioned `kungfu.diagnostic.problem/v1` and `kungfu.health-report/v1` schemas plus one shared problem catalog;\n- `kungfu health [--deep] [--json] [--verbose] [--contract]` with stable `ready / degraded / action-required / blocked` exit semantics (0/1/2/3);\n- bounded fast mode with no fsck, and explicit deep mode using the existing read-only storage fsck and Episode recovery planner;\n- fail-closed process identity, Peer ownership, writer liveness, Episode age, unknown record, and collector failure handling;\n- actionable plain-output translation for the first runtime, Peer, and Episode error paths without changing existing JSON envelopes;\n- KFD contract-world evidence, agent discovery, public guide, ADR-0107, architecture/versioning records, and a three-platform full-profile native qualification hook.\n\n## Safety boundary\n\nHealth never starts, stops, restarts, or signals a process; repairs a route; applies or rebuilds a storage projection; writes an Episode terminal record; or executes a suggested command. Suggested recovery stops at status, inspection, fsck, or a dry-run plan. A first-use daemonless workspace is healthy and is not initialized merely to inspect it.\n\n## Verification\n\n- `./shifu test:health-diagnostics`: 11 passed; the local native module is unavailable and skipped locally.\n- `./shifu check:health-diagnostics-contract`: 4 passed.\n- `node developer/sdk/src/sdk.js contract audit --json`: current / ok.\n- `./shifu kfd:buildchain:check`: KFD-1 witness, 3 KFD-2 claims, 124 KFD-3 surfaces current.\n- `./shifu check:source`: 368 source-contract tests, 76 runtime-upgrade tests, 69 desktop-update tests, and 141 Python source files type-clean.\n- staged pre-commit gate: passed, including 62 documentation tests.\n\nThe Core build-profile matrix sets `KUNGFU_HEALTH_REQUIRE_NATIVE=1`, so Linux, macOS, and Windows full-profile jobs fail if the native read-only fault matrix cannot run.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0107\"],\n  \"summary\": \"Deliver one read-only runtime, Peer, storage, and Episode health projection with stable schemas, actionable diagnostics, bounded fast mode, explicit deep inspection, and fail-closed unknown outcomes.\",\n  \"verification\": [\n    \"health diagnostics unit suite: 11 passed; contract suite: 4 passed\",\n    \"source acceptance: 368 source-contract tests, 76 runtime-upgrade tests, 69 desktop-update tests, and 141 Python source files type-clean\",\n    \"KFD evidence check: KFD-1 witness, 3 KFD-2 claims, and 124 KFD-3 surfaces current\",\n    \"Linux, macOS, and Windows full-profile CI require the native read-only fault matrix\"\n  ]\n}\n-->\n\nSupersedes #999 after the target branch advanced through ADR-0106. This replacement is rebased on the latest target, assigns diagnostics ADR-0107, retains zero merge commits, and includes the bounded Windows process-identity fixture fix discovered by the final native matrix.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T18:40:03Z",
          "mergedAt": "2026-07-16T19:46:38Z",
          "additions": 2971,
          "deletions": 77,
          "changedFiles": 48
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1353,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1353",
          "title": "Release v2.14.0 from qualified v2.14.0-alpha.1",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.0-alpha.1`\n- Candidate SHA: `f839c66f54975dc1d0954e421bebe447b6ddfd0d`\n- Selection: `latest-qualified`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T20:01:25Z",
          "mergedAt": "2026-07-16T20:08:18Z",
          "additions": 563,
          "deletions": 228,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 139,
          "url": "https://github.com/kungfu-systems/kfd/pull/139",
          "title": "docs(kfd): close foundation triad through replay",
          "body": "## Summary\n\n- make KFD-3 explicit as epistemic infrastructure for shared cross-perspective discovery\n- show how KFD-1, KFD-2, and KFD-3 respectively make timeline, replay, and contrast load-bearing in KFD-4\n- project the same closure through the foundation explanation, KFD-4 usage notes, site bundle, standards metadata, and generated KFD evidence\n\n## Boundary\n\n- no README first-screen change\n- no schema or machine-contract change\n- KFD-3 revision advances to 2 and KFD-4 revision advances to 4 under the declared pre-stable refinement policy\n\n## Verification\n\n- `npm run update:evidence`\n- deterministic evidence regeneration\n- `npm run check`\n- `npm pack --dry-run --json --ignore-scripts`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-16T21:00:41Z",
          "mergedAt": "2026-07-16T21:03:49Z",
          "additions": 152,
          "deletions": 102,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 998,
          "url": "https://github.com/kungfu-systems/kungfu/pull/998",
          "title": "feat(project-cut): retain clean-clone continuation evidence",
          "body": "## Summary\n\nTurn the three-layer workspace retention contract into a repeatable product path: thin settled Git shadows remain readable without runtime, exact full Episode evidence can be requested and imported with root-bound receipts, and every Project Cut retains the successor Atlas needed by the next clean clone.\n\n## Related issue\n\nAtlas goal: `2026-07-16-project-cut-retention-rebuild`\n\n## Changes\n\n- Add public `workspace request-full-evidence` and `workspace import-full-evidence` CLI/KFD-3 surfaces.\n- Upgrade replay, requalification, and disaster-recovery capabilities only after a valid receipt bound to a settled Episode root.\n- Keep corrupt optional full evidence visible without invalidating qualified settled history.\n- Ignore Project Cut publication receipts during shadow manifest inspection.\n- Retain immutable successor Atlas material under `.xinfa/baselines/sha256/<atlas-root>/` as exact settlement outputs.\n- Regenerate KFD-2/KFD-3 product evidence and document the retention boundary.\n\n## Real qualification\n\n- Thin fresh clone remained `shadow-only` and created no runtime while producing deterministic request plan `sha256:712e52a5e24d744cd41dbf81aedf9db7d9b3068280e8cee948525747fcd22d8e`.\n- Full evidence import produced receipt `sha256:c48b0b6fdccb8bc909dcd9e3170cf3b7a63a0d0319b6f4725d30ecda780295ee` for Episode root `sha256:1953196f53ac451b64542456ba49c6333f6fda176975aa96518e2604a8237bcf`.\n- Removing the derived Episode SQLite projection and rebuilding it preserved all four query rows and the exact settled Episode/Cut roots.\n- A corrupt full-evidence receipt contracted replay while settled history remained readable.\n- The first continuation write sealed Episode `62002` at `sha256:e481baacad0834e21abccc4a82bdce833ab5555a785c3d271e0d3cbe0de1bd1a`, settled successor Cut `sha256:fc682262f61148323b5e595a13a4fcfc160efbdf387c3c97321f041e13f6d7e7`, and a third clone consumed both Episodes and both Cuts with no runtime.\n\n## Verification\n\n- `./shifu test:workspace-continuation`: Node 8/8 and Python 10/10 passed.\n- `./shifu test:project-cut-settlement`: 7/7 passed.\n- `./shifu test:project-cut-settlement:integration`: 2/2 passed.\n- `./shifu check:source`: build-free source gate passed, including 373 contract tests, 76 runtime-upgrade tests, 69 desktop-update tests, Ruff, mypy, Biome, documentation and KFD checks.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0103\"],\n  \"summary\": \"Qualify clean-clone Project Cut continuation, optional full-evidence capability upgrades, and deterministic projection rebuild\",\n  \"verification\": [\"source acceptance\", \"workspace continuation tests\", \"Project Cut settlement integration\", \"real three-clone retention oracle\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo private Episode payloads, runtime journals, credentials, or disposable oracle files are committed. Only public contracts, generated product evidence, tests, and documentation are included.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] Real clean-clone and rebuild oracles passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T17:28:30Z",
          "mergedAt": "2026-07-16T21:58:47Z",
          "additions": 839,
          "deletions": 50,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1000,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1000",
          "title": "feat(project-cut): qualify independent exact-root review",
          "body": "## Summary\n\nMake independent Mission Control review verify a Completion Claim against the exact tracked Git checkout, Project Cut, successor Atlas, Cut receipt, sealed Episode, and complete parent Go matrix. Keep thin evidence reviewable with an exact full-evidence request, and fail closed on forged or drifted roots.\n\n## Related issue\n\nAtlas goal: `2026-07-16-project-cut-review-fault-qualification`\n\n## Changes\n\n- Extend Project Cut reconciliation with successor Atlas, receipt, parent Cut, and Episode provider/semantic/qualification roots.\n- Bind Completion Claims to the Cut receipt and let independent review verify a tracked checkout without host-local paths entering protocol roots.\n- Reject missing Episodes, stale Atlas roots, forged Cut claims, receipt mismatches, post-claim Git drift, and incomplete parent acceptance matrices.\n- Keep unavailable full evidence explicitly `partial` and emit `./shifu workspace request-full-evidence <checkout> --json`.\n- Bound continuation plans to six dependency-explained follow-ups under the mechanical authority gate.\n- Route `./shifu kungfu ... --json` directly to this checkout's assembled CLI so source work cannot fall through to a global installation or pnpm stdout.\n- Retain the exact valid oracle and fault-campaign roots in `framework/project-cut/qualification/review-fault-qualification.json`.\n\n## Real qualification\n\n- Claimant `qualification-actor-a` / source `qualification-source-a` was reviewed by independent `qualification-reviewer-b` / source `qualification-source-b`.\n- Commit `35cc7935c951a59eb05029ebf79651b2baed021c`, Project Cut `sha256:885f6db7adba465aea533517fcdeffece85a7a1f339dc5aeef708155e3c55c90`, receipt `sha256:128717c34432fae5e0d32b8d7ed5dffc2d19d344576b6b738e4455575595d0f9`, successor Atlas `sha256:5730b530b767a89df75e63a790160198485f0a953c8ecf390c22925a12d71190`, and Episode `sha256:1953196f53ac451b64542456ba49c6333f6fda176975aa96518e2604a8237bcf` reconciled exactly.\n- Review `review-46de6c8c58ef0229c8307ce5` returned `partial`, tracked evidence root `sha256:58779d81935b386066ca7af6b233768f57fa3e3d75b57811314689b5252c0a1b`, TrustReport root `sha256:d25cd49c826aba1362c4ac4b608e0abfec0eecd94ff72ce965fef1b1f2a6df44`, and continuation plan root `sha256:ce13d1126983c8c51095af3964cf2fa0b97a991b120231d297eefd50fbbc0351`.\n- Fault campaign rejected six cases: missing Episode, stale Atlas, receipt/Cut mismatch, incomplete parent matrix, forged Cut root, and post-claim drift.\n\n## Verification\n\n- `node --test scripts/check-project-cut-settlement.test.mjs`: 7/7 passed.\n- `./shifu test:agent-review-continuation`: Dashboard 25/25 and Python 2/2 passed from cold source.\n- `./shifu kfd:buildchain`: KFD-1, three KFD-2 claims, and 122 KFD-3 surfaces passed.\n- Pre-commit source gates: documentation, Ruff, Biome, KFD, schema/authority and runtime boundaries passed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0105\"],\n  \"summary\": \"Qualify independent exact-root Project Cut review, fault rejection, and bounded continuation\",\n  \"verification\": [\"source acceptance gates\", \"agent review continuation tests\", \"Project Cut settlement tests\", \"real independent review oracle\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo private Episode payloads, runtime journals, credentials, or disposable oracle files are committed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Focused source and protocol qualification is green locally\n- [x] Real independent-review and fault-campaign oracles passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T18:07:55Z",
          "mergedAt": "2026-07-16T23:10:38Z",
          "additions": 571,
          "deletions": 59,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1002,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1002",
          "title": "feat(project-cut): qualify three-agent continuation",
          "body": "## Summary\n\nPublish the completed A to B to C Project Cut product qualification with exact non-null roots: Actor A settles and exports, Actor B independently imports and returns a fit review, Actor C imports the exact review bundle and publishes a parent-linked successor Cut, and a fourth clean clone reconciles the complete history without runtime state.\n\n## Related issue\n\nAtlas goal: `2026-07-16-project-cut-three-agent-qualification`\n\n## Changes\n\n- Retain concise public evidence for Actor A settlement, Actor B independent review, Actor C exact-root continuation, and fourth-consumer cold reconcile.\n- Preserve the earlier unverifiable diagnostic artifacts as history; the final artifacts are additive and explicitly qualified.\n- Record GUI, CLI, and Agent surface parity through Work Dashboard, public Shifu commands, and KFD-3 registry evidence.\n- Include the two settlement repairs inherited from PR #998 and the exact-root review qualification inherited from PR #1000.\n\n## Real qualification\n\n- A: commit `35cc7935c951a59eb05029ebf79651b2baed021c`, tree `sha256:50fdd21589b89d7b1a4dce1efd5569cdd6bc5df96caf85d46be145606a1472b9`, Episode `sha256:1953196f53ac451b64542456ba49c6333f6fda176975aa96518e2604a8237bcf`, Cut `sha256:885f6db7adba465aea533517fcdeffece85a7a1f339dc5aeef708155e3c55c90`, bundle `sha256:3cb4a0d7025136fe15c4c1535f1b18f63a06bd1720ec64be51e0844eceaae4d6`.\n- B: review `review-15df37481218ec739978fd40`, verdict `fit`, review root `sha256:b40e6aa8be9ca69e2f5764d64efd6b9e73a58dcc0bdafa1baf0c60e058d21ac9`, plan root `sha256:d9ce88f66b45b5ada845f744b2bf2f2f9ca13bff3ac19c8da098849ecc889b71`.\n- C: decision `decision-c2ac811fe955dd0fb7963661`, successor Episode `sha256:2c4d1d984e7c9f3dfb441380fa551da676841f56fbcea8ab2dec27f1a4881f3b`, successor Cut `sha256:bd41466469738ac0b1e0a0247fadb6f6358caab367a298f97651992d2bd0feb4`, published commit `1cdab429f52cd77cf9f662c8909e454148cb5f15`.\n- D: clean clone reconciled both parent and successor Cuts with receipt `sha256:8903577599974dd95871d346f20fa7cc05051676eafb9e05363cb02061e799c2` and no runtime directory.\n- Human relay count: 0. Atlas repository writes from the native qualification workspaces: 0.\n\n## Verification\n\n- `node --test scripts/check-project-cut-settlement.test.mjs`: 7/7 passed.\n- `./shifu test:project-cut-settlement:integration`: 2/2 passed.\n- `./shifu test:agent-review-continuation`: Dashboard 25/25 and Python 2/2 passed.\n- `./shifu kfd:buildchain`: KFD-1, three KFD-2 claims, and 126 KFD-3 surfaces passed at the latest head (the original isolated oracle covered 124 before the health-diagnostics mainline addition).\n- `node scripts/check-shifu-entry-contract.mjs`: passed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0105\"],\n  \"summary\": \"Qualify the complete Project Cut three-Agent settlement, review, continuation, and cold-reconcile chain\",\n  \"verification\": [\"Project Cut settlement tests\", \"agent review continuation tests\", \"KFD surface parity\", \"real A-B-C-D qualification roots\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nOnly sanitized public roots and qualification summaries are committed. No private runtime journals, credentials, temporary workspace paths, or provider payload bodies are included.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Focused source and protocol qualification is green locally\n- [x] A, B, C, and fourth-consumer cold-reconcile oracles passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T19:05:20Z",
          "mergedAt": "2026-07-16T23:23:41Z",
          "additions": 167,
          "deletions": 5,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 141,
          "url": "https://github.com/kungfu-systems/kfd/pull/141",
          "title": "feat(kfd): add reader path through primitive cases",
          "body": "## Summary\n\n- lead first-time readers from familiar primitives to the KFD discovery problem before introducing the formal model\n- add a non-normative historical companion covering Git, VisiCalc, the log, and a cross-machine trace vignette\n- publish the companion through the KFD site bundle at `/cases` and include it in KFD-3 discoverability and evidence surfaces\n\n## Validation\n\n- `npm run update:evidence`\n- `npm run check`\n- `npm pack --dry-run --json`\n- `git diff --check`\n\n## Version impact\n\nThe site and package additions are additive. The existing pre-stable major decision impact remains unchanged; this PR does not modify numbered KFD semantics or schemas.",
          "author": "dongkeren",
          "createdAt": "2026-07-16T23:50:56Z",
          "mergedAt": "2026-07-16T23:52:59Z",
          "additions": 692,
          "deletions": 148,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 142,
          "url": "https://github.com/kungfu-systems/kfd/pull/142",
          "title": "docs(kfd): explain the procedural foundation",
          "body": "## Summary\n\n- explain why KFD-1 must begin as maintained procedure rather than another fact claim\n- make the KFD-1 through KFD-6 practice-invariant-practice structure explicit\n- preserve the distinction between foundation principles KFD-2/3 and derived principle KFD-4\n- regenerate the site bundle and KFD-1/KFD-3 witnesses\n\n## Verification\n\n- `npm run update:evidence`\n- `npm run check`\n- `npm pack --dry-run --json`\n- deterministic evidence regeneration\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-17T00:09:40Z",
          "mergedAt": "2026-07-17T00:12:14Z",
          "additions": 45,
          "deletions": 18,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 143,
          "url": "https://github.com/kungfu-systems/kfd/pull/143",
          "title": "docs(kfd): index the procedural foundation",
          "body": "## Summary\n\n- add a direct MAP route for readers asking why KFD-1 begins with procedure rather than principle\n- bind the route to the existing foundation-model heading\n- refresh KFD-1 and KFD-3 generated witnesses\n\n## Verification\n\n- `npm run update:evidence`\n- `npm run check`\n- `npm pack --dry-run --json`\n- deterministic evidence regeneration\n- target heading anchor check\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-17T00:22:17Z",
          "mergedAt": "2026-07-17T00:24:57Z",
          "additions": 8,
          "deletions": 7,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1355,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1355",
          "title": "feat(cache): add portable dev cache contract",
          "body": "## Summary\n- add a consumer-neutral portable dependency/compiler cache plan contract\n- bind exact keys to source and plan roots while constraining compatible restores by runner, toolchain, lock, profile, and declared roots\n- seal exact, compatible, miss, and corrupt provider outcomes as machine-readable receipts\n- expose CLI, Node API, generated site facts, documentation, and fault tests\n\n## Validation\n- `pnpm run check` (663 tests passed; workflow/site/action bundle checks passed)\n- targeted portable cache contract and CLI tests\n\n## Downstream validation\nKungfu will consume the released provider in its GitHub-hosted Linux affected-native gate. Cache hits never replace current build/test execution; misses and corrupt evidence require the cold path.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T00:29:40Z",
          "mergedAt": "2026-07-17T00:34:15Z",
          "additions": 648,
          "deletions": 34,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1356,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1356",
          "title": "release: promote portable dev cache provider to v2.14 alpha",
          "body": "## Summary\nPromote the reviewed portable dev cache provider from `dev/v2/v2.14` to the protected alpha channel for downstream Kungfu validation.\n\n## Evidence\n- Buildchain PR #1355 merged after approval\n- Verify and cross-platform Build Surface Fixture passed\n- provider contract covers exact/compatible/miss/corrupt outcomes and audited cold fallback\n\nThe protected promotion workflow remains responsible for version state, npm publication evidence, and channel refs.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T00:35:22Z",
          "mergedAt": "2026-07-17T00:38:29Z",
          "additions": 648,
          "deletions": 34,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1357,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1357",
          "title": "feat(governance): admit dev PRs into merge queue",
          "body": "## Summary\n\n- auto-detect native merge-queue protection and prevent direct-merge bypass\n- admit one immutable PR head against the observed landed base and emit a machine-readable predecessor receipt\n- recheck base, head, mergeability, and queue occupancy before GraphQL `enqueuePullRequest(expectedHeadOid)`\n- keep `merge_group` checks as the final authority and make Buildchain daily patrol dogfood `v2-alpha` queue admission\n\n## Validation\n\n- `pnpm run check` (671 tests)\n- live dry-run policy plan for `dev/v2/v2.14` verifies `pull_request` + `merge_group` compatibility\n\n## Version impact\n\nAdditive v2.14 governance capability. Publish a new alpha after merge; no existing direct-mode consumer is forced onto a queue when its target branch has none.",
          "author": "dongkeren",
          "createdAt": "2026-07-17T00:42:26Z",
          "mergedAt": "2026-07-17T00:45:52Z",
          "additions": 692,
          "deletions": 53,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 144,
          "url": "https://github.com/kungfu-systems/kfd/pull/144",
          "title": "chore(kfd): anchor alpha 28 release",
          "body": "## Summary\n\n- advance the explicit KFD npm and release-anchor facts to `1.0.0-alpha.28`\n- regenerate KFD-1/2/3 evidence from the updated source facts\n- include the reader-context cases, procedural-foundation explanation, and direct MAP route already merged on dev\n\n## Verification\n\n- deterministic `npm run update:evidence`\n- `npm run check`\n- `npm pack --dry-run --json` reports `@kungfu-tech/kfd@1.0.0-alpha.28`\n- package contains `docs/foundation-model.md`, `docs/primitive-discovery-cases.md`, and `docs/MAP.md`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-17T00:46:42Z",
          "mergedAt": "2026-07-17T00:49:04Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1358,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1358",
          "title": "release: promote merge queue admission to v2.14 alpha",
          "body": "## Summary\n\nPromote the reviewed merge-queue admission controller from `dev/v2/v2.14` to the protected alpha channel.\n\n## Evidence\n\n- Buildchain PR #1357 merged after dual-identity approval\n- local combined predecessor validation passed 671 tests\n- GitHub PR checks passed, including Verify and Build Surface Fixture\n- native merge queue ruleset is active on `dev/v2/v2.14` with required check `check` preserved\n\nThe protected promotion workflow remains responsible for selecting the next alpha version, trusted npm publication, GitHub Release evidence, and floating channel refs.",
          "author": "dongkeren",
          "createdAt": "2026-07-17T00:47:30Z",
          "mergedAt": "2026-07-17T00:49:39Z",
          "additions": 692,
          "deletions": 53,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 146,
          "url": "https://github.com/kungfu-systems/kfd/pull/146",
          "title": "release(kfd): publish alpha 28",
          "body": "## Summary\n\n- promote KFD `1.0.0-alpha.28` from the protected dev channel into alpha\n- publish the reader-context primitive cases, procedural-foundation explanation, and direct documentation-map route\n- preserve the required same-repository provenance path: `dev/v1/v1.0 -> alpha/v1/v1.0`\n\n## Release facts\n\n- npm package: `@kungfu-tech/kfd@1.0.0-alpha.28`\n- dist-tag: `alpha`\n- release anchor: `kfd.release.json`\n- Buildchain publication: trusted publishing through the alpha channel workflow\n\n## Verification\n\n- dev verify and Buildchain build gates passed on anchor PR #144\n- package/version and release-anchor facts agree exactly\n- generated KFD-1/2/3 witnesses are committed and deterministic",
          "author": "dongkeren",
          "createdAt": "2026-07-17T00:49:31Z",
          "mergedAt": "2026-07-17T00:52:03Z",
          "additions": 847,
          "deletions": 225,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1359,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1359",
          "title": "Release v2.14.1 from qualified v2.14.1-alpha.0",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.1-alpha.0`\n- Candidate SHA: `417691e234ef1bf89b1afeb7c51417a9dc3cd96b`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-17T00:49:11Z",
          "mergedAt": "2026-07-17T00:52:55Z",
          "additions": 664,
          "deletions": 50,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1361,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1361",
          "title": "fix(governance): preserve sealed promotion authority",
          "body": "Closes #1360\n\nKeep ordinary dev PRs on the native merge queue while projecting only explicitly declared release-governance actors into the exact branch ruleset. This lets sealed post-publish version-state bookkeeping complete without granting broad role or all-Actions bypass.\n\nValidation:\n- node --test tests/dev-merge-queue.test.mjs\n- pnpm run check (673 tests)",
          "author": "dongkeren",
          "createdAt": "2026-07-17T01:01:29Z",
          "mergedAt": "2026-07-17T01:10:25Z",
          "additions": 153,
          "deletions": 14,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1363,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1363",
          "title": "fix(release): resume advanced publication evidence",
          "body": "Closes #1362\n\nResume a governed publication only when the advanced target ref exactly matches the durable transaction release SHA, restoring publish evidence on safe retries while preserving supersession for unrelated advancement.\n\nValidation:\n- pnpm run check (675 tests)\n- targeted promote-buildchain-ref retry regression",
          "author": "dongkeren",
          "createdAt": "2026-07-17T01:19:46Z",
          "mergedAt": "2026-07-17T01:25:56Z",
          "additions": 239,
          "deletions": 92,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 148,
          "url": "https://github.com/kungfu-systems/kfd/pull/148",
          "title": "fix(docs): remove AI provenance frontmatter",
          "body": "## Summary\n- remove AI generator identity metadata from the public primitive discovery cases frontmatter\n- add a repository check that rejects `ai_provenance` in Markdown frontmatter\n- refresh KFD-1/2/3 evidence digests\n\n## Verification\n- `npm run update:evidence` (deterministic rerun)\n- `npm run check`\n- `npm pack --dry-run --json`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-17T01:22:55Z",
          "mergedAt": "2026-07-17T01:27:14Z",
          "additions": 69,
          "deletions": 54,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1365,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1365",
          "title": "chore(release): reconcile alpha publication state",
          "body": "Reconcile the already-published `2.14.1-alpha.1` generated version state back into dev after the previous protected dev ref update failed.\n\nThis preserves the immutable alpha publication history and makes the next dev-to-alpha promotion a normal descendant merge.\n\nValidation: `pnpm run check` (675 tests).",
          "author": "dongkeren",
          "createdAt": "2026-07-17T01:28:58Z",
          "mergedAt": "2026-07-17T01:33:22Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1364,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1364",
          "title": "release: publish merge queue admission alpha",
          "body": "## Summary\n\nPromote the completed native Merge Queue admission controller and governed publication retry fix from `dev/v2/v2.14` to the protected alpha channel.\n\n## Evidence\n\n- PR #1357: native queue admission implementation\n- PR #1361: exact promotion bypass and CLI normalization\n- PR #1363: exact durable-transaction retry recovery\n- local `pnpm run check`: 675 tests\n- merge-group Verify run 29547342187 succeeded\n\nThe protected promotion workflow remains responsible for selecting a fresh alpha version, trusted npm publication, GitHub prerelease evidence, and channel refs.",
          "author": "dongkeren",
          "createdAt": "2026-07-17T01:26:55Z",
          "mergedAt": "2026-07-17T01:35:53Z",
          "additions": 387,
          "deletions": 101,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 99,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/99",
          "title": "chore: consume KFD release",
          "body": "Buildchain release propagation from @kungfu-tech/kfd into the kfd.libkungfu.dev site surface.\n\nBuildchain release propagation plan:\n\n```json\n{\n  \"schemaVersion\": 1,\n  \"contract\": \"kungfu-buildchain-release-propagation-plan\",\n  \"source\": \"kfd\",\n  \"upstreamRelease\": {\n    \"repository\": \"kungfu-systems/kfd\",\n    \"channel\": \"alpha\",\n    \"tag\": \"v1.0.0-alpha.28\",\n    \"sourceSha\": \"04f839e8e7834c9eda3d46424de2f59f53623e8f\",\n    \"package\": {\n      \"name\": \"@kungfu-tech/kfd\",\n      \"version\": \"1.0.0-alpha.28\",\n      \"integrity\": \"sha512-pTNOaJOgsfMehptEFcqhICzuO/c0ZJwrYlZcgLgIbOu2V2c/MDCKOuPXmD/RH1dpIjQ+SfZROuQqsPH5ERlQ/w==\"\n    },\n    \"releasePassport\": {\n      \"url\": \"https://github.com/kungfu-systems/kfd/releases/download/v1.0.0-alpha.28/buildchain.release.json\",\n      \"sha256\": \"b8900474eb68035d9d3d17390844928e7ce6efc785eadc5dfaf32547cb049fb1\"\n    }\n  },\n  \"targets\": [\n    {\n      \"edge\": \"kfd-to-site-libkungfu-dev\",\n      \"source\": \"kfd\",\n      \"target\": \"site-libkungfu-dev\",\n      \"repository\": \"kungfu-systems/site-libkungfu-dev\",\n      \"channel\": \"alpha\",\n      \"baseRef\": \"main\",\n      \"lockPath\": \"buildchain.upstreams/kfd.release.json\",\n      \"lock\": {\n        \"schemaVersion\": 1,\n        \"contract\": \"kungfu-buildchain-release-propagation-lock\",\n        \"upstream\": {\n          \"node\": \"kfd\",\n          \"repository\": \"kungfu-systems/kfd\",\n          \"channel\": \"alpha\",\n          \"tag\": \"v1.0.0-alpha.28\",\n          \"sourceSha\": \"04f839e8e7834c9eda3d46424de2f59f53623e8f\",\n          \"package\": {\n            \"name\": \"@kungfu-tech/kfd\",\n            \"version\": \"1.0.0-alpha.28\",\n            \"integrity\": \"sha512-pTNOaJOgsfMehptEFcqhICzuO/c0ZJwrYlZcgLgIbOu2V2c/MDCKOuPXmD/RH1dpIjQ+SfZROuQqsPH5ERlQ/w==\"\n          },\n          \"releasePassport\": {\n            \"url\": \"https://github.com/kungfu-systems/kfd/releases/download/v1.0.0-alpha.28/buildchain.release.json\",\n            \"sha256\": \"b8900474eb68035d9d3d17390844928e7ce6efc785eadc5dfaf32547cb049fb1\"\n          }\n        },\n        \"downstream\": {\n          \"node\": \"site-libkungfu-dev\",\n          \"repository\": \"kungfu-systems/site-libkungfu-dev\",\n          \"channel\": \"alpha\",\n          \"baseRef\": \"main\",\n          \"lockPath\": \"buildchain.upstreams/kfd.release.json\"\n        },\n        \"propagation\": {\n          \"graphContract\": \"kungfu-buildchain-release-propagation-graph\",\n          \"edge\": \"kfd-to-site-libkungfu-dev\",\n          \"channelPolicy\": \"preserve\",\n          \"channelMap\": {\n            \"alpha\": \"alpha\",\n            \"release\": \"release\"\n          },\n          \"exact\": true,\n          \"floatingTags\": false\n        },\n        \"lockSha256\": \"7d7dcad9f5ca15baa2bed213ac0c8fc52330de16ac73123c87de6314f27325fc\"\n      }\n    }\n  ],\n  \"summary\": {\n    \"targetCount\": 1,\n    \"channels\": [\n      \"alpha\"\n    ],\n    \"repositories\": [\n      \"kungfu-systems/site-libkungfu-dev\"\n    ]\n  }\n}\n```\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-17T00:57:58Z",
          "mergedAt": "2026-07-17T01:44:58Z",
          "additions": 160,
          "deletions": 27,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1367,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1367",
          "title": "fix(release): align occupied alpha planning",
          "body": "Closes #1366\n\nMake publication authority planning advance past a current alpha transaction that already contains published material whenever version-state regeneration would create new release material. The mutation step now receives the same exact version that authority sealed.\n\nValidation:\n- targeted occupied-alpha planning regression\n- `pnpm run check` (676 tests)",
          "author": "dongkeren",
          "createdAt": "2026-07-17T01:47:38Z",
          "mergedAt": "2026-07-17T01:56:51Z",
          "additions": 212,
          "deletions": 66,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 101,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/101",
          "title": "fix(ci): keep main pushes staging only",
          "body": "## Summary\n\n- keep ordinary `push main` events staging-only\n- allow production apply only for an explicitly approved manual dispatch\n- preserve automatic production release PR creation\n- guard the caller contract against reintroducing production apply on ordinary main pushes\n\n## Reason\n\nBuildchain `v2` now rejects `production-apply: true` unless the current event has already resolved to a trusted production decision. The prior caller expression enabled it for every main push, so the KFD alpha.28 merge failed before staging could build.\n\nFailed staging run: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29548228857\nUpstream contract issue: https://github.com/kungfu-systems/buildchain/issues/1368\n\n## Verification\n\n- `node --check scripts/check-infra-outputs.mjs`\n- `node scripts/check-infra-outputs.mjs`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T01:53:35Z",
          "mergedAt": "2026-07-17T02:03:12Z",
          "additions": 7,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1370,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1370",
          "title": "fix(web-surface): separate production capability from approval",
          "body": "## Summary\n\n- treat production-apply as a configured capability, not proof that the current event is authorized\n- keep ordinary main pushes on staging while retaining trusted release-PR and manual production decisions\n- document the caller contract and cover all three event paths\n\n## Validation\n\n- pnpm run generate:site\n- pnpm run check (677/677)\n\nCloses #1368",
          "author": "dongkeren",
          "createdAt": "2026-07-17T02:02:52Z",
          "mergedAt": "2026-07-17T02:07:37Z",
          "additions": 51,
          "deletions": 25,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1369,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1369",
          "title": "release: publish aligned alpha plan",
          "body": "Promote the occupied-alpha publication planning fix from dev to the protected alpha channel.\n\nEvidence:\n- PR #1367 merged through native Merge Queue\n- merge-group Verify run 29548611450 succeeded\n- local `pnpm run check`: 676 tests\n\nThe publisher should seal and publish the same fresh alpha version (`2.14.2-alpha.0`) instead of binding the already-published `2.14.1-alpha.1`.",
          "author": "dongkeren",
          "createdAt": "2026-07-17T01:57:21Z",
          "mergedAt": "2026-07-17T02:09:53Z",
          "additions": 258,
          "deletions": 86,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 102,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/102",
          "title": "fix(papers): preserve immutable archive pages",
          "body": "## Summary\n\n- move the KFD Cases mobile long-TOC rule out of the shared page stylesheet\n- inject that rule only into the KFD Cases page\n- preserve byte-for-byte identity of existing immutable paper archive indexes\n\n## Reason\n\nThe KFD alpha.28 renderer added a five-line responsive CSS rule to the shared page template. Because immutable paper archive indexes embed that shared stylesheet, all existing versioned paper index bytes changed and Buildchain correctly rejected staging.\n\nFailed staging run: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29548978738\n\n## Verification\n\n- full staging-channel build and repository check passed\n- KFD Cases still contains the mobile long-TOC rule\n- all three generated immutable paper indexes match their current staging objects byte-for-byte:\n  - `kfd-foundation-real-world-agent-work/v0.1.0-alpha.6`: `ffaddf9c...`\n  - `kungfu-product-white-paper/v0.1.0-alpha.5`: `2a782eef...`\n  - `observer-declared-timelines/v0.1.0-alpha.8`: `19e10474...`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T02:12:13Z",
          "mergedAt": "2026-07-17T02:19:34Z",
          "additions": 9,
          "deletions": 6,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 149,
          "url": "https://github.com/kungfu-systems/kfd/pull/149",
          "title": "feat(kfd): make primitive genesis method plural",
          "body": "## Summary\n- keep KFD-4 as the declared-perspective and replay boundary without claiming method superiority\n- advance KFD-5 to a perspective-declared, method-plural genesis contract\n- advance draft KFD-6 to bounded comparison across perspective, anomaly, reconstruction, causal, compression, and hybrid methods\n- update package metadata, generated witnesses, trust claims, and site bundle\n\n## Verification\n- `npm run update:evidence`\n- `npm run check`\n- deterministic evidence regeneration\n- `npm pack --dry-run --json`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-17T02:35:27Z",
          "mergedAt": "2026-07-17T02:38:03Z",
          "additions": 728,
          "deletions": 511,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 105,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/105",
          "title": "Release production from a1ac4ed74348",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `a1ac4ed74348f2aaf792ca0831d8b37fa88b50a2`\n- Artifact hash: `7b68f92b194ace42d483f5ef36c94986a5cfd1e390aa627e2438073bb543beea`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29549651686)\n- Required label: `buildchain-release`\n- Release branch: `release/production-a1ac4ed74348`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-17T02:25:50Z",
          "mergedAt": "2026-07-17T02:39:05Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1004,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1004",
          "title": "ci: establish dev gate latency control",
          "body": "## Summary\n\nEstablish the first measurable and fail-closed dev required Gate latency control plane: queue-inclusive SLO observation, build-free affected-native planning, and Buildchain-owned portable dependency/compiler cache receipts on GitHub-hosted Linux.\n\nThis PR does not claim the P50/P95 objective is already qualified. The retained 30-PR baseline has 22 comparable samples and currently fails the target (P50 19.4 minutes, P95 51.0 minutes). This PR creates the mechanism and the first cold/warm runtime evidence needed for the next bounded qualification window.\n\n## Related goal\n\nAtlas parent goal: `2026-07-17-kungfu-dev-gate-latency-slo`\n\nProvider: Buildchain PR #1355, stable `@kungfu-tech/buildchain@2.14.1`.\n\n## Changes\n\n- Measure protected-dev latency from the earliest required workflow `created_at` to the last required terminal success, including queueing and retries.\n- Classify native/non-native/unknown samples through the same source planner and require at least 20 total plus 10 native samples before a passing verdict can qualify.\n- Plan affected native closure before Buildchain, Conan, or workspace installation; tier-none PRs write the required receipt and exit without unrelated bootstrap.\n- Bind native execution to the exact checked-out source, plan digest, and architecture authority.\n- Restore/save separate Buildchain portable dependency and compiler cache layers with exact and compatible-key receipts; every restore still runs the current configure/build/CTest closure and every miss records a cold fallback.\n- Pin Kungfu release admission and local bootstrap to stable Buildchain 2.14.1.\n- Refresh the closed-world workflow authority and Gate documentation.\n\n## Verification\n\n- `./shifu check:source`: 380/380 source-acceptance tests, 76 runtime-upgrade tests, 69 desktop-update tests, tooling typecheck, and Biome passed.\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs scripts/measure-dev-required-latency.test.mjs scripts/write-affected-native-cache-manifests.test.mjs`: 26/26 passed.\n- `./shifu core:affected -- --self-test`: 17/17 negative and determinism fixtures passed.\n- staged gate: docs, Biome, Rust fmt/clippy/workspace tests, Gate catalog, and KFD evidence passed.\n- live measurement: 22 comparable samples, all 66 required-context observations start from `workflow.created_at`; required contexts exactly match live branch protection.\n- full `./shifu check` reached all changed-code, Rust, and Gate surfaces; one earlier run exposed a transient pre-existing uv effective-lock mismatch in 2/49 cache-runtime tests. The later complete source acceptance run passed the same strict cache tests.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Establish queue-inclusive dev Gate latency measurement, source-first native admission, and provider-bound portable cache receipts without weakening the Gate closure\",\n  \"verification\": [\"source acceptance\", \"Gate catalog closure\", \"affected-native planner fixtures\", \"live branch-protection latency baseline\", \"portable cache provider qualification\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo private token, raw provider payload, persistent runner state, or local absolute path is committed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Required dev Gate strength is unchanged\n- [x] agent-120 is not used as required capacity\n- [x] Cache miss and unknown evidence fail closed or run the cold authority",
          "author": "dongkeren",
          "createdAt": "2026-07-17T01:14:01Z",
          "mergedAt": "2026-07-17T02:41:42Z",
          "additions": 1204,
          "deletions": 78,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 151,
          "url": "https://github.com/kungfu-systems/kfd/pull/151",
          "title": "docs(kfd): compress decisions to normative core",
          "body": "## Summary\n- compress KFD-1 through KFD-6 from 9,458 to 4,176 words while retaining normative gates, authority boundaries, and activation criteria\n- align all public decision titles with their one-sentence commitments\n- make KFD-5 foreground the separation of genesis from qualification\n- route implementation, self-proof, and historical case detail to existing usage and companion documents\n- refresh registry metadata, release impact, site bundle, and KFD-1/2/3 witnesses\n\n## Verification\n- `npm run update:evidence`\n- `npm run check`\n- deterministic evidence regeneration\n- `npm pack --dry-run --json`\n- JSON parsing for registry, standards, release impact, site bundle, and witnesses\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-17T03:18:36Z",
          "mergedAt": "2026-07-17T03:21:42Z",
          "additions": 670,
          "deletions": 1329,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 152,
          "url": "https://github.com/kungfu-systems/kfd/pull/152",
          "title": "docs(kfd): improve reader flow",
          "body": "## Summary\n\n- move the current decision registry ahead of implementation details in the README\n- define evidence cuts at first use and express the KFD-6 loop in domain-neutral terms\n- add consistent decision and documentation-map navigation to every usage page\n- refresh KFD-1/2/3 evidence projections and release-impact metadata\n\n## Verification\n\n- `npm run update:evidence`\n- `node scripts/check.mjs`\n- `git diff --check`\n- local Markdown link-path validation\n- `npm pack --dry-run --json`",
          "author": "dongkeren",
          "createdAt": "2026-07-17T03:34:27Z",
          "mergedAt": "2026-07-17T03:37:36Z",
          "additions": 202,
          "deletions": 179,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1371,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1371",
          "title": "feat(governance): inherit declared dev merge queues",
          "body": "## Summary\n\n- add governance.dev.merge_queue with enabled, inherit, and disabled modes\n- reconcile queue governance before release-line default branch changes\n- add trusted automatic dev reconciliation and explicit Buildchain dogfood declaration\n\n## Validation\n\n- pnpm run check\n- simulated v2.15 release-line plan\n- live dry-run and apply against dev/v2/v2.14 preserved ruleset 19076734, strict=false, and required check check\n\n## Safety\n\n- ordinary CLI usage remains dry-run by default\n- legacy inheritance requires an active exact source ruleset\n- declared workflows fail closed unless they support pull_request and merge_group\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-17T04:03:19Z",
          "mergedAt": "2026-07-17T04:06:21Z",
          "additions": 822,
          "deletions": 139,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 153,
          "url": "https://github.com/kungfu-systems/kfd/pull/153",
          "title": "feat(kfd): add formal reference layer",
          "body": "## Summary\n\n- add an experimental, non-normative shared formal model and one formal reference for KFD-1 through KFD-6\n- bind formal references to authoritative decisions through versioned, SHA-256-backed standards metadata\n- project formal pages into the site bundle and KFD-1/2/3 self-proof surfaces\n- keep `decisions/KFD-N.md` as the sole normative authority\n\n## Verification\n\n- `npm run update:evidence`\n- `node scripts/check.mjs`\n- `git diff --check`\n- local Markdown link audit\n- `npm pack --dry-run --json` (all 7 formal documents included)",
          "author": "dongkeren",
          "createdAt": "2026-07-17T04:06:05Z",
          "mergedAt": "2026-07-17T04:08:15Z",
          "additions": 2025,
          "deletions": 215,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1008,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1008",
          "title": "ci(dev): seed affected-native base cache",
          "body": "## Summary\n\nSeed the portable affected-native cache from trusted pushes to the dev line so pull requests and merge-queue runs can restore a cache owned by their shared base branch.\n\nThis is a CI-only patch for the current dev/v4 line. It changes no public API, requires no compatibility migration, and needs no backport.\n\n## Related issue\n\nAtlas goal 2026-07-17-kungfu-dev-cache-scope-closure\n\n## Changes\n\n- run Affected Native PR Gate on pushes to dev/v*/v*\n- resolve push revisions from before and after SHAs\n- keep PR and merge-group execution unchanged while letting successful dev pushes publish the reusable baseline\n- document and mechanically verify the cache-scope contract\n- bind the implementation to a published Project Cut and qualified Episode\n\n## Verification\n\n- ./shifu sync\n- ./shifu test:gate-latency\n- ./shifu check:gate-catalog\n- ./shifu check:source\n- ./shifu xinfa:build\n- Project Cut independent completion review: fit\n- Project Cut closeout gate: passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This CI workflow and cache-scope correction does not alter an architecture contract\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects CI qualification evidence only. Source acceptance, gate-catalog closure, workflow authority refresh, and the published Project Cut verify the boundary.\n\n## Checklist\n\n- [x] Commits are signed off with DCO\n- [x] Documentation updated for the behavior change",
          "author": "dongkeren",
          "createdAt": "2026-07-17T03:49:33Z",
          "mergedAt": "2026-07-17T04:15:08Z",
          "additions": 87,
          "deletions": 7,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1006,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1006",
          "title": "feat(shifu): close human documentation surfaces",
          "body": "## Summary\n\nClose every tracked human-readable surface into an exact Shifu inventory and delegate KFD-1 graph, impact, and stale propagation to Xinfa.\n\n## Changes\n\n- add the versioned human-surface policy and schema\n- add deterministic inventory, Xinfa project adapter, graph, and impact commands\n- bind explicit implementation/evidence revisions and preserve Human/Agent route parity\n- record SHIFU-ADR-0008 and a Project Cut settlement\n\n## Verification\n\n- `./shifu docs:check`\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source`\n- `./shifu docs graph --output <fresh-path> --json`\n- KFD-1 fault injection: one implementation change affected two nodes, one document, and both routes\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0008\"],\n  \"summary\": \"Close the Kungfu human-surface inventory and delegate canonical drift and impact to Xinfa\",\n  \"verification\": [\"Documentation gate\", \"source acceptance\", \"Xinfa Atlas compile and verify\", \"KFD-1 implementation drift fault injection\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe bounded release-evidence change is the checked-in Project Cut and Xinfa Atlas settlement; both are diagnostic and non-qualifying.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-17T03:32:41Z",
          "mergedAt": "2026-07-17T04:47:08Z",
          "additions": 1402,
          "deletions": 11,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 154,
          "url": "https://github.com/kungfu-systems/kfd/pull/154",
          "title": "feat(kfd): add live primitive case registry",
          "body": "## Summary\n\n- add the first provisional KFD live Primitive case under a machine-readable registry\n- preserve separate genesis, KFD method trace, propagation hypothesis, immutable KFD-5 cut, and append-only review path\n- project the same case through the site bundle, npm exports, KFD-1 surfaces, and KFD-3 collaboration witnesses\n- add checks for case identity, path ownership, cut digest, KFD-5 schema version, status, and projection closure\n\n## Claim boundary\n\n`Proof-Carrying Work Object` remains a working title and provisional candidate. This PR does not claim novelty, universality, product readiness, method superiority, autonomous discovery, or accepted Primitive status. KFD self-application creates an inspectable dogfood record; it does not certify the candidate or propagation hypothesis.\n\n## Verification\n\n- `npm run update:evidence` is idempotent\n- `npm run check`\n- `git diff --check`\n- changed Markdown relative-link check\n- `npm pack --dry-run --json` includes all live-case and schema files\n- current cut SHA matches the registry, site bundle, and KFD-1 witness\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T04:36:48Z",
          "mergedAt": "2026-07-17T04:50:53Z",
          "additions": 2271,
          "deletions": 170,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1009,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1009",
          "title": "feat(core): check the bodies of un-annotated functions",
          "body": "## Summary\n\nmypy skipped the body of any function without annotations. Since 717 of 1699\ndefs in the package carry no signature, `Success: no issues found` was largely\nmeasuring how little was annotated rather than how correct the code was. This\nturns on `check_untyped_defs` so those bodies are checked.\n\nSignatures stay optional: `disallow_untyped_defs` remains off, because requiring\nthem is a ~700-error wall and a separate decision. This is the cheap half —\nbodies get checked now, signatures can land as modules are touched.\n\nTurning it on surfaced 40 findings. All but one were the checker seeing less\nthan the code holds; they are fixed by stating what is true, not by silencing:\n\n- **Heterogeneous dict literals** (runtime/contract/agent/storage inventories):\n  mypy joins the values to their nearest common supertype, so a later\n  `payload[\"images\"]` looks unindexable. Annotating the literal `dict[str, Any]`\n  stops the join. No behaviour change.\n- **LiveEventLoop queues** now say they carry `Handle`/`TimerHandle`. That also\n  let the checker see `post_step`'s TimerHandle field access — and it caught the\n  second loop reusing the name `handle` for a plain `Handle` (renamed `due`).\n- **`supervise()`** walked `.parent.parent` unguarded. It is always\n  kfc → runtime → supervise, but a refactor breaking that would fall through to\n  the `getattr` default and silently downgrade `log_level`. Now it asserts.\n- **Guest harnesses** assert the loaded spec/loader, turning a would-be\n  `AttributeError` on an unimportable facet into a clear message.\n\n**One was a real defect.** `register_pdm_commands` imports\n`pdm.cli.commands.plugin`, which the pinned pdm 2.28 does not have — it was\nrenamed to `self_cmd` (`pdm plugin` → `pdm self`). Reaching that import raises\n`ImportError`. The fallback only runs when pdm exposes no command modules at\nall, so it is normally dead, but it is broken against the pinned version.\nVerified in the locked env: the old import raises; the new one resolves and\nregisters under the correct name `self`.\n\nThree per-module overrides remain, each tied to something we do not own and\njustified where it is declared: `cli.site` (vendored CPython site.py —\n`sys._framework`/`_home`/`_base_executable` are real but absent from typeshed),\n`runtime.live.event_loop` (typeshed types the loop callbacks with a TypeVarTuple\nno un-annotated override can satisfy; the loop drives TimerHandle's real-but-\nundeclared `_when`/`_scheduled`), and `cli.commands.engage` (stamps an attribute\nonto click's `Context`; retires with the ADR-0046 engage bridges). `create_task`,\nwhich genuinely dropped `name=`/`context=`, was fixed in code rather than\nsilenced — see #981.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Tightens the existing mypy baseline to check un-annotated function bodies, annotates what the checker cannot infer, and fixes a stale pdm import; no architecture contract or ADR record is altered\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Verification\n\n- `uv run --frozen mypy` (framework/core): Success, 151 source files, 0 errors\n- **The gate demonstrably bites**: seeding a type error inside an un-annotated\n  function body (`_marker_records`) turns it red — `error: Incompatible types in\n  assignment ... [assignment]` — and removing it turns it green. A guard that\n  cannot fail is not a gate.\n- The pdm fix was proven against the locked environment: the old import raises\n  `ImportError: cannot import name 'plugin'`; the new one resolves, and\n  `self_cmd.Command.name == 'self'` so the loop registers the right name.\n- `pytest tests/python/test_event_loop_concurrency.py`: 6 passed\n- `ruff format --check` / `ruff check` on all changed files: clean\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T04:15:12Z",
          "mergedAt": "2026-07-17T05:10:45Z",
          "additions": 68,
          "deletions": 21,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1012,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1012",
          "title": "feat(shifu): bind documentation final readiness",
          "body": "## Summary\n\nBind KFD-1 documentation impact and KFD-3 dual-first projections into the standard Atlas `go` Completion Claim and independent-review closeout path.\n\n## Changes\n\n- add `docs final-ready --since` as a thin Shifu orchestration over one Xinfa Atlas\n- bind inventory, authoring impact, Human/Agent projections, and parity into one content-addressed receipt\n- fail closed on implementation drift, incomplete required projections, and parity mismatch\n- keep Project Cut v1 unchanged; Atlas consumes the receipt as an existing Completion Claim proof root\n\n## Verification\n\n- `node --test scripts/shifu-documentation-surfaces.test.mjs`\n- `./shifu docs:check`\n- `./shifu check:source`\n- real final-ready receipt from baseline `1ebbf2e9b3b8c380d8597b3a7bf95cac63af3e0f`: complete Human and Agent projections, current routes, zero authoring violations\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0008\"],\n  \"summary\": \"Bind documentation impact and dual-first projections into exact-root go completion review\",\n  \"verification\": [\"final-ready real Xinfa receipt\", \"parity fault fixture\", \"documentation gate\", \"source acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe receipt is diagnostic until an independent exact-claim review accepts it. It adds no publishing authority and does not alter Project Cut v1.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T04:24:33Z",
          "mergedAt": "2026-07-17T05:40:50Z",
          "additions": 3378,
          "deletions": 46,
          "changedFiles": 43
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1372,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1372",
          "title": "release: publish merge queue policy inheritance alpha",
          "body": "Publish the current reviewed dev line as the next v2.14 alpha. This candidate includes declarative Merge Queue governance, active-line inheritance, release-line reconciliation ordering, and Buildchain self-dogfood.",
          "author": "dongkeren",
          "createdAt": "2026-07-17T06:44:00Z",
          "mergedAt": "2026-07-17T06:45:15Z",
          "additions": 822,
          "deletions": 139,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1013,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1013",
          "title": "fix(mission-control): qualify exact documentation Project Cut",
          "body": "## Summary\n- scope independent completion review to the Project Cut root claimed by the completion receipt\n- preserve exact-cut diagnostics in commits containing historical Project Cuts\n- publish and independently qualify Project Cut 9447cdc0 for the Shifu documentation control plane\n\n## Validation\n- 335/335 reachable human-readable surfaces classified; 0 unclassified\n- independent review verdict: fit\n- closeout gate: pass\n- targeted Mission Control regression tests and full staged checks: pass\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Correct exact-root review selection for multi-cut commits and publish generated settlement evidence without altering an architecture contract\"\n}\n-->\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nGenerated Project Cut receipts are qualifying evidence only; this PR grants no publishing authority.\n\n## Checklist\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-17T06:29:47Z",
          "mergedAt": "2026-07-17T07:21:28Z",
          "additions": 134,
          "deletions": 9,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 155,
          "url": "https://github.com/kungfu-systems/kfd/pull/155",
          "title": "docs(kfd): split live case into Pursuit and Warrant",
          "body": "## Summary\n\n- preserve the immutable Proof-Carrying Work Object genesis while splitting the live case into independent Pursuit and Warrant candidate tracks\n- define the Pursuit / Atlas / Warrant / Episode execution-plane ontology and explicit separation from settlement objects\n- upgrade the live-case registry and site projection to schema v2, with independent cuts, qualification status, and claim boundaries\n- regenerate KFD-1/2/3 witnesses and update human/agent routing surfaces\n\n## Validation\n\n- `npm run update:evidence`\n- `npm run check`\n- `git diff --check`\n- `npm pack --dry-run --json`",
          "author": "dongkeren",
          "createdAt": "2026-07-17T07:42:13Z",
          "mergedAt": "2026-07-17T07:54:37Z",
          "additions": 2014,
          "deletions": 644,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1014,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1014",
          "title": "feat(ci): qualify dev gate cache evidence",
          "body": "## Summary\n\n- collect the final successful affected-native artifact for every native latency sample\n- validate Buildchain dependency/compiler portable-cache receipts and artifact source binding\n- report exact/compatible warm reuse, qualified cold fallback, ccache statistics, and aggregate warm/cold ratios\n- keep missing, expired, malformed, or source-mismatched evidence fail-closed as unknown\n- retry only transient GitHub network, 429, and 5xx responses with a bounded three-attempt policy\n\n## Related issue\n\nDev required gate latency SLO qualification.\n\n## Changes\n\n- add read-only Actions artifact collection to `gate:latency:measure`\n- require complete native cache evidence before a latency window can qualify\n- document the artifact and `unzip` requirements\n- add warm, cold, malformed, missing-fallback, non-native, and verdict fixtures\n\n## Verification\n\n- `./shifu test:gate-latency` (12/12)\n- `./shifu check:source` (passed)\n- live 30-PR collection (28 qualifying duration samples): P50 879s, P95 3062s; 2 warm, 3 cold, 21 pre-receipt unknown native samples, 2 non-native not-applicable; verdict remains non-qualifying\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Close the cache-evidence observability stage of dev Gate latency qualification without changing Gate strength\",\n  \"verification\": [\"./shifu test:gate-latency\", \"./shifu check:source\", \"live 30-PR read-only measurement\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR reads retained CI qualification artifacts with repository read access; it does not modify workflows, branch protection, publication authority, or repository settings.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-17T07:37:13Z",
          "mergedAt": "2026-07-17T08:06:51Z",
          "additions": 407,
          "deletions": 25,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1015,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1015",
          "title": "ci(source-acceptance): run the affected-native self-test",
          "body": "## Summary\n- register `run-core-affected-native.mjs --self-test` with source-acceptance, alongside the existing core negative fixtures\n- assert the registration in the source-acceptance contract test so the wiring cannot be dropped silently\n\nThe affected-native gate has been required on `dev/*` since it landed, and it ships\nnegative fixtures by the repo's own convention. Those fixtures were never registered\nwith source-acceptance, so the only guard over the gate's classification rules never\nran in CI. A regression in those rules stayed green until it was caught by hand.\n\nThree sibling guards (`check-layers.mjs`, `query-health.mjs`,\n`check-build-capabilities.mjs`) are already wired this way; this is the one that was\nmissed, not a new mechanism.\n\n`--self-test` is pure classification logic over committed authority JSON: it needs no\nnative toolchain, so source-acceptance (the light gate) is the right home for it\nrather than the native matrix.\n\n## Validation\n- reverse verification: seeded a `globalPaths` rule deletion -> the wired step exits 1\n  and source-acceptance fails; restored -> 18/18 fixtures pass\n- `node --test scripts/source-acceptance.test.mjs`: 15/15 pass\n- per ADR-0040, a guard that cannot fail is not a gate; the red/green cycle above is\n  the evidence that this one can now fail\n\n## Known limitation (not addressed here)\nA mutation sweep over the gate's own `globalPaths` rules shows the self-test detects\nonly 3 of 11 rule deletions. For example, deleting `framework/core/CMakeLists.txt`\nleaves the self-test green while a Core CMake change is reclassified\n`core-documentation-only` (closure 0/12, no native validation). Wiring the self-test\nin is a prerequisite for closing that gap; broadening fixture coverage is deliberately\nleft to follow-up work rather than mixed into this change.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Register an existing guard's self-test with the source gate; no architecture contract, classification rule, or release surface changes\"\n}\n-->\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-17T07:43:40Z",
          "mergedAt": "2026-07-17T08:20:50Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 158,
          "url": "https://github.com/kungfu-systems/kfd/pull/158",
          "title": "docs(kfd): qualify four-object prior art and distinguishability",
          "body": "## Summary\n\n- preserve and correct the BDI/FIPA prior-art additions from #157\n- add a conditional distinguishability argument for Pursuit, Atlas, Warrant, and Episode\n- project the argument through the live-case registry, site bundle, KFD-1 surface register, KFD-3 collaboration evidence, and release artifact gate\n- keep both Primitive candidate tracks provisional and leave immutable cuts unchanged\n\n## Validation\n\n- `npm run update:evidence`\n- `npm run check`\n- `git diff --check`\n- `npm pack --dry-run --json` with the distinguishability surface present\n\nSupersedes #157 because that PR targets an already-merged feature branch and this PR carries its commit with corrections onto `dev/v1/v1.0`.",
          "author": "dongkeren",
          "createdAt": "2026-07-17T08:28:30Z",
          "mergedAt": "2026-07-17T08:31:28Z",
          "additions": 545,
          "deletions": 156,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1005,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1005",
          "title": "feat(cli): add scoped health preflight",
          "body": "## Summary\n\nAdd command-scoped, read-only health preflight for high-value runtime, Peer, storage, and Episode operations. Ready checks stay silent, unrelated problems do not block a command, deep checks never run automatically, and execution-time ownership and writer fences remain authoritative.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Add explicit preflight profiles to the shared diagnostics contract and a reusable CLI runner.\n- Bind runtime activation, Peer activation, Episode writes, and Episode recovery to their minimum relevant health areas.\n- Preserve fresh uncached checks, fail-closed unknown outcomes, and the final authoritative write or lifecycle fence.\n- Add portable latency qualification for empty and initialized workspaces across single and concurrent shells.\n- Run native health and preflight performance qualification on macOS, Ubuntu, and Windows full-profile CI.\n- Isolate native health fixtures from host control-plane state while preserving the product rule that a real unverified supervisor identity is blocked.\n- Bound fixed-capacity native text conversion at Python, Node, JSON, SQLite, hashing, query, recovery, and Episode service boundaries.\n- Keep independent completion review compatible with append-only Project Cut history by selecting the uniquely claimed Cut.\n- Bind the latest-dev replay to a sealed Mac qualification Episode and successor Project Cut.\n\n## Verification\n\n- `./shifu check:source` (399 source/contract tests, 76 runtime-upgrade tests, 69 desktop-update tests, and static checks passed)\n- `./shifu verify` (36/36)\n- `KUNGFU_HEALTH_REQUIRE_NATIVE=1 ./shifu test:health-diagnostics` (17 portable, 2 native, and 1 exact-capacity regression)\n- `./shifu test:health-preflight-performance` (cold p95 max 6.238 ms; warm p95 max 6.259 ms; cache disabled; 4 concurrent shells)\n- `./shifu test:agent-review-continuation` (25 Work Dashboard and 2 Python tests)\n- Exact-checkout Project Cut review: fit; one sealed Episode verified; no tracked-checkout diagnostics\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0107\"],\n  \"summary\": \"Complete command-scoped health preflight with fresh execution fences and three-platform qualification\",\n  \"verification\": [\"native health diagnostics\", \"preflight latency budgets\", \"source acceptance\", \"three-platform full-profile CI\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe CLI change is limited to local read-only diagnostics and existing command boundaries. Workflow authority and generated KFD witnesses are refreshed for the added qualification steps; no credentials, private logs, hosted services, publishing behavior, or deployment authority are added.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T01:49:31Z",
          "mergedAt": "2026-07-17T08:35:33Z",
          "additions": 1412,
          "deletions": 116,
          "changedFiles": 91
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1016,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1016",
          "title": "fix(schema): close the ADR-0067 tag-uniqueness hole and correct two records",
          "body": "## What\n\n`EpisodeRootCommitted` (10806) was declared, given an ADR-0067 layout weld, and placed in the\n`episode_manifest` membership table -- but was never added to the `AllTypes` roster.\n`AllTypesTags` derives from `AllTypes`, so the type silently escaped the ADR-0067\ntag-uniqueness `static_assert`: a guard with a hole in it.\n\nRegistering it is the one-line half. The other half binds the two rosters, so a\nmembership-table member missing from `AllTypes` fails the build rather than quietly\nbypassing the uniqueness check.\n\nTwo record corrections ride along:\n\n- **ADR-0065** was still `proposed` / `not-started` while three of its four decisions had\n  shipped. It is now `accepted` / `partial` with implementation commits; it is not\n  `implemented` because the `CorePublic*` structural subsets are still hand-listed and the\n  numeric tag comments are not yet retired.\n- **`manifest_catalog_projection::verify_typed`** reported row counts for three of its four\n  projected families, silently omitting `export_bundle_recorded` from both `rows` and\n  `journal_distinct`. The counts were already computed and used in the drift path, so an\n  operator could see the table only when it drifted -- never whether it was projected at all.\n\n## Verification\n\n- Core builds with no compile errors; `pykungfu` links.\n- The full build's final import step fails on a pre-existing rocksdb `crc32c_arm64` symbol gap\n  on macOS arm64. Reproduced identically on an unmodified `dev/v4/v4.0` worktree, so it is\n  unrelated to this change and blocks the local build for everyone on that platform today.\n- Docs gate passes, including ADR body/index status drift checks.\n- No test asserts the row-map shape; the existing export drift test asserts only the drift map\n  and still holds.\n\n<!-- kungfu-adr-release:v1\n{\"schema\": \"kungfu.adr-release-pr/v1\", \"kind\": \"dev-delivery\", \"intent\": \"stage-ready\", \"adrs\": [\"ADR-0065\"], \"summary\": \"Register EpisodeRootCommitted so it stops escaping the ADR-0067 tag-uniqueness assert, bind the membership table to AllTypes, and correct ADR-0065 to accepted/partial\", \"verification\": [\"core builds with no compile errors\", \"docs gate including ADR body/index status drift\", \"existing export drift test\"]}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T07:44:10Z",
          "mergedAt": "2026-07-17T08:55:58Z",
          "additions": 36,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 159,
          "url": "https://github.com/kungfu-systems/kfd/pull/159",
          "title": "feat(kfd): add pre-number candidate governance",
          "body": "## Summary\n\n- add a non-normative, pre-number KFD Candidate registry with a non-binding slot hint for the action-state candidate\n- define bounded pre-stable Foundation Revision and first-stable Foundation Freeze semantics\n- project candidates through npm, site bundle, KFD-1 surfaces, KFD-3 collaboration evidence, and Buildchain artifact gates\n- fail closed on unregistered numbered decision files and unregistered candidate documents\n\n## Verification\n\n- `npm run update:evidence`\n- `npm run check`\n- `git diff --check`\n- `npm pack --dry-run --json`\n\nThe numbered registry remains KFD-1 through KFD-6; this change does not allocate KFD-7.",
          "author": "dongkeren",
          "createdAt": "2026-07-17T09:07:40Z",
          "mergedAt": "2026-07-17T09:10:11Z",
          "additions": 1392,
          "deletions": 230,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1020,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1020",
          "title": "ci(dev): decouple optional core profile matrix",
          "body": "## Summary\n\n- move the optional Core build profile matrix off every development pull request\n- retain Linux, macOS, and Windows coverage for both embedded-minimal and full profiles on a daily or manual observer\n- keep the protected dev required set Linux-hosted and leave alpha/release cross-platform policy unchanged\n- refresh closed-world workflow authority\n- supersede #1018 with one linear commit on the latest dev base so the repository rebase merge queue can admit it without replaying historical conflict resolutions\n\n## Related issue\n\nDev required gate latency SLO qualification.\n\n## Changes\n\n- replace the pull_request trigger for Core build profiles with daily schedule and workflow_dispatch\n- document the boundary between dev admission, asynchronous observation, and alpha/release qualification\n- refresh workflow authority\n\n## Verification\n\n- ./shifu check:gate-catalog\n- ./shifu docs:check\n- ./shifu kfd:buildchain:check\n- commit staged gate\n- equivalent #1018 head passed Source Acceptance, affected-native, ADR, docs, DCO, Buildchain validation, and promotion rehearsal before the queue rejected its non-linear history\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Remove optional six-job Core profile observation from the dev PR critical path without weakening alpha or release policy\",\n  \"verification\": [\"./shifu check:gate-catalog\", \"./shifu docs:check\", \"./shifu kfd:buildchain:check\", \"equivalent PR 1018 full check set\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes diagnostic scheduling only. It does not alter branch protection, required Gate rows, release credentials, publication authority, or repository settings.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T09:11:25Z",
          "mergedAt": "2026-07-17T09:17:48Z",
          "additions": 33,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1019,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1019",
          "title": "feat(agent): stream worktree progress to mission control",
          "body": "## Summary\n\nRoute Agent Go progress from its authoritative isolated worktree into the long-running Mission Control runtime while retaining sealed delivery evidence in the work runtime.\n\n## Related issue\n\nAtlas goal 2026-07-13-kungfu-agent-progress-live-observability.\n\n## Changes\n\n- resolve the Go worktree from the work dashboard and launch Agent Console there\n- inject explicit control-runtime and WorkRef coordinates without overriding KF_HOME or KF_RUNTIME_DIR\n- extend RunProgress with signal, next action, and WorkRef identity\n- render live progress, heartbeat, waiting, and blocker facts in the Go drawer\n- bind the delivery to a qualified Episode and Project Cut\n\n## Verification\n\n- work-dashboard tests: 27 passed\n- API query tests: 20 passed\n- terminal tests: 14 passed\n- agent console contract tests: 16 passed\n- API TypeScript build passed\n- dashboard and terminal KFX builds passed\n- staged gate passed\n- real dual-runtime integration: control files 7, work files 0; native and reflection rewind verify passed\n- Project Cut state-scoped verify: verified with zero diagnostics\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0079\"],\n  \"summary\": \"Complete the live query invalidation and isolated-worktree progress slice of the native Work and Agent Console loop\",\n  \"verification\": [\"27 dashboard tests\", \"20 API query tests\", \"14 terminal tests\", \"16 agent console contract tests\", \"dual-runtime integration\", \"qualified Project Cut\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR adds qualified Episode and Project Cut evidence but grants no publishing authority. Runtime routing carries paths and content-bound WorkRef coordinates only; provider credentials and transcripts are not copied.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-17T08:20:05Z",
          "mergedAt": "2026-07-17T10:06:56Z",
          "additions": 1011,
          "deletions": 11,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1017,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1017",
          "title": "feat(runtime): declare event route phase, state access and topology",
          "body": "The live runtime assembled its rx subscription topology imperatively, so the\ntopology existed only as executed code. Ordering invariants survived as\ncomments, guards were anonymous lambdas, and \"who consumes event X\" was\nanswerable only by reading three files across two languages — one of which\nhides the carrier inside a lambda.\n\nADR-0108 records the decision. Routes now carry a declared phase and the shared\nstate they read or write; `react()` declares and `wire_routes()` subscribes in\nphase order, so the ordering is enforced by the engine rather than by the order\nof the lines.\n\n### What this makes checkable\n\nTwo ordering dependencies were previously implicit. `coordinator::feed` reads\nthe registry through `is_location_live()` and is bracketed by two writers of it:\n`register_peer` establishes the source location, `on_request_deregister` erases\nit. Only the second had a comment, and that comment named an absolute position\n(\"at bottom\") rather than the relationship, so it warned nobody adding a further\ncatch-all below it. Both are now stated, and a startup assertion rejects a\nsame-phase reader/writer pair, which makes the phase assignment falsifiable\ninstead of merely asserted.\n\n### What this makes answerable\n\n```\n$ node scripts/route-topology-contract.mjs --consumer ACTION_ENVELOPE\nconsumers of ACTION_ENVELOPE: 3\n  watcher (c++, process=node-watcher)  Watcher::CaptureCustomEvent  via consumes\n  python-lock-arbiter (python, process=coordinator)  _on_lock_action  via carrier\n  python-arbiter-client (python, process=coordinator)  _on_frame  via carrier\n```\n\nThe registry is static because the question is not about a running process:\nthose three live in two processes and two languages, so no single runtime table\ncan hold them, and `Watcher::CaptureCustomEvent` selects the carrier inside a\nguard predicate that never names it. It is verified against the source in both\ndirections — a registry entry with no declaration fails, and a declaration with\nno registry entry fails too — and wired into the staged gate.\n\n### Behaviour\n\nUnchanged. Declaration order matches the previous source order and the sort is\nstable, so the assembled subscription set is identical entry for entry. A source\ndifferential over `react()` / `on_react()` confirms wire order == original order\nfor all three components.\n\n### Scope and honest limits\n\n- `implementation_status: partial`. Stages 1-3 are delivered; stage 4 is\n  delivered on the query side only. Every mechanism records what it subscribes,\n  but nothing yet **rejects** a subscription the registration does not name.\n  Recording is not enforcing.\n- The registry and `consumes()` are declared by hand. Verification proves they\n  match the `declare*` calls; it cannot prove that a guard really consumes the\n  carrier it claims.\n- The reverse check scans only the anchors the registry lists, so a brand-new\n  component file is not yet covered.\n- `continuity` is out of scope: it owns no routes.\n\n### Verification\n\n- `pnpm --filter @kungfu-tech/core run compile` → `COMPILE_EXIT=0`, 0 errors\n- `ctest --output-on-failure` → `CTEST_EXIT=0`, 20/20 passed\n- `node scripts/route-topology-contract.mjs` → `result=pass`, 5 components, 43 routes\n- negative fixtures both directions fail as intended; restoring passes\n- `node scripts/adr-audit.mjs` → `result=pass`\n- `node scripts/check.mjs --staged` → staged gate passed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0108\"],\n  \"summary\": \"Event routes record phase and shared-state access; the topology registry answers who consumes a carrier across processes and languages, verified against source and gated.\",\n  \"verification\": [\n    \"pnpm --filter @kungfu-tech/core run compile -> COMPILE_EXIT=0, 0 errors\",\n    \"ctest --output-on-failure -> CTEST_EXIT=0, 20/20 passed\",\n    \"node scripts/route-topology-contract.mjs -> result=pass, 5 components, 43 routes\",\n    \"node scripts/adr-audit.mjs -> result=pass\",\n    \"node scripts/check.mjs --staged -> staged gate passed\",\n    \"source differential over react()/on_react(): wire order == original order for coordinator, peer and watcher\"\n  ]\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T07:55:05Z",
          "mergedAt": "2026-07-17T10:36:47Z",
          "additions": 1900,
          "deletions": 106,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1007,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1007",
          "title": "fix(core): scope the affected-native authority to its tracked roots",
          "body": "<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fixes a scoping defect in the affected-native gate's own script. It projects no ADR: no architecture decision changes, no component is added or removed, and layers.json is untouched. The gate simply now reads the tracked_roots the authority already declares.\",\n  \"summary\": \"Classify native sources outside the architecture authority's tracked_roots as outside-authority instead of demanding an owning component.\",\n  \"verification\": [\"node scripts/run-core-affected-native.mjs --self-test (16/16)\"]\n}\n-->\n\n## Problem\n\nThe gate requires exactly one owning architecture component for every native source under `framework/core/`, but it only ever filters on that prefix — it never consults the authority's own `tracked_roots`. Any source the authority deliberately does not track fails closed:\n\n```\n[core-affected] slices/embedding/main.cpp: expected exactly one architecture component, found none\n```\n\nThe capability slices are the live case. They are standalone probes built only under `KUNGFU_WITH_SLICES` (default `OFF`), linked into no product target, and correspondingly absent from `tracked_roots`. No component can own them, and registering one is not available either: `component_budget` caps at 12 and all 12 are in use.\n\nThe net effect is that **any PR touching `framework/core/slices/*.cpp` is currently unmergeable**. This surfaced on #990, which migrates the slices off a `writer` constructor it removes — leaving them alone would break them under `KUNGFU_WITH_SLICES=ON`.\n\nThe path had simply never been exercised: this gate landed in `5e916c3628` on 2026-07-16, and the previous change to a slice `.cpp` was 2026-07-14.\n\n## Fix\n\nClassify native sources outside `tracked_roots` as `outside-architecture-authority`, exactly as `src/python/` is already held outside it.\n\nThe exemption is driven by the authority's own data rather than a hard-coded path list — no `slices` string appears in the gate — so `tracked_roots` remains the single switch, and `layers.json` is already in `globalPaths`, so editing it expands the gate globally.\n\n## Boundaries\n\nThis widens the authority's **edge**, not its **interior**:\n\n- The check sits *after* the extension check, so only native sources are exempt; a stray `.yaml` under `framework/core/` still throws `unclassified Core file impact`.\n- An unowned source *inside* a tracked root still fails closed. The existing `unclassified source fails closed` fixture pins exactly that (`src/libkungfu/src/runtime/unknown.cpp` is under the tracked `src/libkungfu/src/` root but owned by no component), and it still passes.\n\n**The risk, stated plainly:** native sources placed outside `tracked_roots` no longer fail closed, so `tracked_roots` now carries that weight by itself. If code that genuinely warrants component ownership is added outside those roots, this gate will no longer object. The mitigation is that `tracked_roots` lives in `layers.json`, which is architecture-authority data and triggers a global revalidation when edited.\n\n## Verification\n\n`node scripts/run-core-affected-native.mjs --self-test` → 16/16.\n\nThe new fixture was confirmed non-vacuous: forcing `isTracked()` to return `true` turns it red.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T03:41:59Z",
          "mergedAt": "2026-07-17T10:42:16Z",
          "additions": 38,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1023,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1023",
          "title": "chore(project-cut): settle live observability closeout",
          "body": "## Summary\n\nPublish the successor Project Cut evidence for the already-merged live observability delivery. This PR changes no product behavior or ADR scope.\n\n## Related delivery\n\n- Atlas goal: `2026-07-13-kungfu-agent-progress-live-observability`\n- Delivery PR: #1019\n- Delivery commit: `71ba0805281d0a500b1f349776c6f385fd431db6`\n\n## Verification\n\n- `./shifu project-cut verify`: verified with zero diagnostics\n- `./shifu check:staged`: passed\n- source projection remains `sha256:5f2228b1616e0056d44117110c750a5e0079f2fe8aac02cea1371a63e959e39e`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Publish content-addressed Project Cut closeout evidence for an already-merged delivery without changing product or ADR semantics\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR contains only public, content-addressed Project Cut manifest and receipt files. It grants no publishing authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; evidence-only)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T10:41:50Z",
          "mergedAt": "2026-07-17T10:47:26Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 160,
          "url": "https://github.com/kungfu-systems/kfd/pull/160",
          "title": "feat(verifier): add independent conformance runtime",
          "body": "## Summary\n\n- add an independent Rust verifier core with native CLI and import-free WASM artifact\n- verify KFD records, documented Buildchain release passports, Xinfa Pack/Atlas objects, and qualified Git Workspace Episode shadows\n- ship the `kfd` npm binary, versioned verification bundle/report schemas, public profile documentation, and welded-surface evidence\n- pin product-generated goldens and enforce native/WASM byte parity, adversarial rejection, and clean offline extraction\n\n## Verification\n\n- `npm run update:evidence`\n- `npm run check`\n- `cargo clippy --locked --manifest-path verifier/Cargo.toml --all-targets -- -D warnings`\n- `npm run check:verifier-artifact`\n- `actionlint .github/workflows/build.yml`\n- `git diff --check`\n- local tarball smoke: `npm exec --yes --package=<tarball> -- kfd verify kfd-record standards.json --json`\n\n## Boundaries\n\nThe verifier is offline and contains no product-code dependency. It reports profile coverage explicitly and does not claim work quality, capture completeness, signature authority, or real-world fitness. Warrant, Pursuit, and Envelope verbs remain deferred until their live-case cuts stabilize.",
          "author": "dongkeren",
          "createdAt": "2026-07-17T11:25:04Z",
          "mergedAt": "2026-07-17T11:31:59Z",
          "additions": 5026,
          "deletions": 110,
          "changedFiles": 71
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 877,
          "url": "https://github.com/kungfu-systems/kungfu/pull/877",
          "title": "fix(gates): complete source-bound measurement coverage",
          "body": "## Summary\n\n- declare exact capabilities for the trusted measurement runners and invoke the Gate runtime from the measured source\n- retain ordinary Shifu receipts for task Gates and exact workflow-job receipts for handler Gates\n- correct release artifact admission to its actual Linux controller boundary while preserving the three-platform payload requirement\n- backfill the frozen historical measurement baseline without weakening Gate policy\n\n## Safety\n\nThe measurement workflow is manual and read-only. It does not publish, tag, sign, or promote artifacts. Controller receipts must bind a successful exact workflow/job, source SHA, registry digest, Gate definition, adapter and timestamps.\n\n## Validation\n\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs`\n- `./shifu check:gate-catalog`\n- source-bound measurement run `29347740328` (in progress)\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Closes historical Gate measurement evidence debt and distinguishes task receipts from existing controller execution without changing product architecture or release admission requirements.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: all new workflows and capture tools are read-only measurement paths; no publication or promotion action is introduced.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:48:01Z",
          "mergedAt": "2026-07-17T11:57:10Z",
          "additions": 17255,
          "deletions": 515,
          "changedFiles": 257
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 161,
          "url": "https://github.com/kungfu-systems/kfd/pull/161",
          "title": "chore(kfd): anchor alpha 29 release",
          "body": "## Summary\n\n- anchor `@kungfu-tech/kfd` at `1.0.0-alpha.29`\n- refresh KFD-1, KFD-2, and KFD-3 release evidence hashes\n- include the four-object verifier and all changes currently accepted on the v1.0 development line\n\n## Validation\n\n- `npm run check`\n- `npm run check:verifier-artifact`\n- `cargo clippy --locked --manifest-path verifier/Cargo.toml --workspace --all-targets -- -D warnings`\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org/`",
          "author": "dongkeren",
          "createdAt": "2026-07-17T13:52:55Z",
          "mergedAt": "2026-07-17T13:57:18Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1026,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1026",
          "title": "feat(agent): project the four-object work model",
          "body": "Publish the fail-closed four-object Agent Work contract and bounded trust surfaces.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\":\"kungfu.adr-release-pr/v1\",\n  \"kind\":\"dev-delivery\",\n  \"intent\":\"stage-ready\",\n  \"adrs\":[\"ADR-0109\"],\n  \"summary\":\"Publish the fail-closed four-object Agent Work contract and bounded trust surfaces.\",\n  \"verification\":[\n    \"./shifu check:agent-work-state-contract\",\n    \"./shifu kfd:buildchain:check\",\n    \"./shifu docs:check\",\n    \"./shifu check:source\"\n  ]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-17T13:05:27Z",
          "mergedAt": "2026-07-17T13:59:42Z",
          "additions": 2593,
          "deletions": 102,
          "changedFiles": 65
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 162,
          "url": "https://github.com/kungfu-systems/kfd/pull/162",
          "title": "release(kfd): publish alpha 29",
          "body": "## Release\n\nPromote the verified v1.0 development line to `alpha/v1/v1.0` and publish immutable `@kungfu-tech/kfd@1.0.0-alpha.29`.\n\nThis release includes the four-object verifier for Buildchain Release Passport, Xinfa Pack/Atlas, Kungfu Episode, and arbitrary KFD records, together with all changes accepted on the current development line.\n\n## Boundaries\n\n- alpha channel only\n- no `latest`, stable, or production promotion\n- publication remains gated by Verify and Release Passport workflows",
          "author": "dongkeren",
          "createdAt": "2026-07-17T13:57:33Z",
          "mergedAt": "2026-07-17T14:01:06Z",
          "additions": 13145,
          "deletions": 1801,
          "changedFiles": 120
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 165,
          "url": "https://github.com/kungfu-systems/kfd/pull/165",
          "title": "fix(kfd): exclude verifier build cache from release payload",
          "body": "## Root cause\n\nThe release-candidate artifact path included the whole `verifier/` directory after verification had created `verifier/target/`. The candidate manifest therefore recorded a rebuildable hidden Cargo cache file that GitHub artifact transfer did not carry, and publication admission correctly failed closed.\n\n## Fix\n\n- enumerate tracked verifier source, lock, dist, specs, and fixtures explicitly\n- exclude `verifier/target/` from release-candidate evidence\n- regenerate KFD-1/2/3 evidence for the workflow digest change\n\n## Validation\n\n- `npm run update:evidence`\n- `npm run check`",
          "author": "dongkeren",
          "createdAt": "2026-07-17T14:08:31Z",
          "mergedAt": "2026-07-17T14:11:28Z",
          "additions": 18,
          "deletions": 12,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 166,
          "url": "https://github.com/kungfu-systems/kfd/pull/166",
          "title": "release(kfd): retry alpha 29 after payload fix",
          "body": "## Release\n\nRetry the alpha.29 promotion after publication admission correctly rejected an over-broad candidate payload.\n\nThe only new semantic change since the first promotion is the release artifact boundary: tracked verifier sources, specs, fixtures, and WASM dist remain included; rebuildable `verifier/target/` cache state is excluded.\n\n## Boundaries\n\n- version remains immutable `1.0.0-alpha.29` because no publication occurred\n- alpha channel only\n- no `latest`, stable, or production promotion\n- Verify and Release Passport gates remain authoritative",
          "author": "dongkeren",
          "createdAt": "2026-07-17T14:11:41Z",
          "mergedAt": "2026-07-17T14:14:27Z",
          "additions": 18,
          "deletions": 12,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 168,
          "url": "https://github.com/kungfu-systems/kfd/pull/168",
          "title": "fix(release): keep npm pack JSON clean",
          "body": "## Summary\n- route packaged verifier diagnostics to stderr\n- preserve machine-readable stdout from `npm pack --json`\n\n## Verification\n- `npm run check`\n- `npm pack --dry-run --json` parsed as JSON\n- `npm-publish-transaction.mjs --dry-run-publish --skip-registry-lookup`",
          "author": "dongkeren",
          "createdAt": "2026-07-17T14:23:34Z",
          "mergedAt": "2026-07-17T14:26:37Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 169,
          "url": "https://github.com/kungfu-systems/kfd/pull/169",
          "title": "release: promote 1.0.0-alpha.29 to alpha",
          "body": "Promote the verified KFD `1.0.0-alpha.29` release candidate to the alpha channel.\n\nThis retry includes the release-transaction stdout fix from #168. Stable/latest and production remain out of scope.",
          "author": "dongkeren",
          "createdAt": "2026-07-17T14:27:01Z",
          "mergedAt": "2026-07-17T14:30:08Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 170,
          "url": "https://github.com/kungfu-systems/kfd/pull/170",
          "title": "docs(kfd): define KFD-4 default probe boundary",
          "body": "## What\n\n- explain why KFD-4 is the first derived operator after the KFD-1 through KFD-3 foundation\n- define perspective transformation as a bounded lowest-marginal-cost default probe, not a universal ranking theorem\n- add usage selection criteria, a non-normative cost model, falsifiers, and refreshed KFD-1/2/3 and site projections\n\n## Registry agreement\n\n- [x] `node scripts/check.mjs` passes\n- [x] Pre-stable maintainer-authorized semantic refinement is declared as breaking decision-surface impact and preserves prior prerelease artifacts\n\n## Version impact (per KFD-1)\n\n- [x] major decision-surface refinement within the fixed pre-stable v1.0 line\n\n## Verification\n\n- `npm run update:evidence`\n- `node scripts/check.mjs`\n- `git diff --check`\n- `npm pack --dry-run --json`",
          "author": "dongkeren",
          "createdAt": "2026-07-17T14:35:00Z",
          "mergedAt": "2026-07-17T14:41:19Z",
          "additions": 211,
          "deletions": 94,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1025,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1025",
          "title": "feat(xinfa): autoload exact context for go",
          "body": "## Summary\n\nAutomatically admit a verified, bounded Xinfa context for standard Atlas `go` work and bind its exact roots into Kungfu-native Mission Control.\n\n## Related issue\n\nAtlas goal `2026-07-17-xinfa-go-context-autoload`.\n\n## Changes\n\n- add structured, project-declared route resolution with fail-closed ambiguity handling;\n- pass exact Xinfa Atlas, route, Task Chart, budget, omission, and consumption roots through native `create-go`;\n- preserve parent authority while deriving independent child Task Charts;\n- retain live Project Cut and Episode evidence for the completed delivery.\n\n## Verification\n\n- 24 retained route cases across 5 route families: top-1 accuracy 1.0, route recall 1.0, omission false-green 0;\n- `./shifu xinfa:check`;\n- `./shifu xinfa:standalone`;\n- `./shifu xinfa:dogfood`;\n- full `./shifu check:source` gate passed, including 417 source-contract tests, 76 runtime-upgrade tests, 69 desktop-update tests, and Python/TypeScript checks;\n- live cache-loss rebuild, source-drift refresh, low-budget, wrong-audience, ambiguity, and parent-child conservation faults exercised;\n- native completion review verdict `fit` at delivery head `1f53074a49a302fd219bc0e21c6b0699483b9a1f`, current-input Atlas `sha256:a71d2ac8f97a020d538a76f77a33af5dae9de81f7108a25ae59818ef7eee9ed1`, result Atlas `sha256:94bfff741b1829fc3782e5b94f7d11876ed7474394c100217847ac54edcd3807`, final Project Cut `sha256:071188f7480528bbde1666b80f1ed38ff42ef9824ea2e9e05883e0ee7509d8d6`, and review root `sha256:29790c00f87d86c0a242c025b00c241b271af974a7ab2b6f7edb3616a43be2c3`.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0110\"],\n  \"summary\": \"Standard go resolves and consumes an exact-root bounded Xinfa context through Kungfu-native Mission Control.\",\n  \"verification\": [\"24-case retained route qualification\", \"Xinfa standalone and dogfood gates\", \"native Project Cut completion review fit\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR adds content-addressed Project Cut and Episode evidence only; it does not publish a release or handle credentials.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T12:12:08Z",
          "mergedAt": "2026-07-17T14:41:26Z",
          "additions": 1561,
          "deletions": 104,
          "changedFiles": 112
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1031,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1031",
          "title": "fix: keep empty-delta review fail-closed",
          "body": "## Summary\n\nAllow Project Cut completion review to accept an exact empty Episode delta only when Episode absence is the sole unverifiable evidence gap.\n\n## Changes\n\n- admit tracked Cut/Claim empty Episode sets\n- keep conflict, stale, unavailable, mismatch, and additional-gap cases fail-closed\n- add a real no-Episode settlement integration test\n\n## Verification\n\n- node --test scripts/check-project-cut-settlement.test.mjs\n- ruff format --check and ruff check on changed Python files\n- targeted atlas storage tests\n- native exact-root independent review returned fit for commit e28e52505c264d949795fed57667afd7838001f1\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Implements the existing ADR-0097 explicit empty-delta contract without changing the architecture decision\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Required checks are delegated to CI\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T14:49:53Z",
          "mergedAt": "2026-07-17T14:59:37Z",
          "additions": 225,
          "deletions": 11,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1376,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1376",
          "title": "ci(kfd): verify Buildchain-owned passport",
          "body": "## Summary\n\n- pin the published KFD 1.0.0-alpha.29 verifier\n- construct a Buildchain-owned release passport and verify it with the public KFD CLI\n- refresh the committed KFD upstream projections and bundled promotion action\n\n## Verification\n\n- `pnpm run check` (685 tests passed; action bundle integrity passed)\n\nThis is the Buildchain-side half of the bidirectional semantic-drift alarm. It does not move any release channel.",
          "author": "dongkeren",
          "createdAt": "2026-07-17T14:53:13Z",
          "mergedAt": "2026-07-17T15:00:49Z",
          "additions": 669,
          "deletions": 72,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 171,
          "url": "https://github.com/kungfu-systems/kfd/pull/171",
          "title": "fix(verifier): sync Xinfa route resolution",
          "body": "## Summary\n- sync the packaged Xinfa project schema and Atlas goldens from Kungfu `f24721f9073bc24000343c838bb755c13c06bce0`\n- rebuild the verifier WASM and release witnesses\n- anchor the catch-up package as `1.0.0-alpha.30`\n\n## Why\nKungfu's new owner-side reverse CI correctly caught that `1.0.0-alpha.29` predated the structured Go route-resolution vocabulary. This is the intended bidirectional drift alarm: the format owner advanced its schema, so the independent verifier snapshot must explicitly catch up before the owner CI can pass.\n\n## Compatibility\nThe new `resolution` field is optional, so existing project documents remain valid. This changes only the prerelease verifier snapshot and alpha package coordinate; stable/latest and production are out of scope.\n\n## Validation\n- `npm run build:verifier`\n- `npm run update:evidence`\n- `npm run check`\n- `npm pack --dry-run --json`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T15:20:31Z",
          "mergedAt": "2026-07-17T15:23:38Z",
          "additions": 73,
          "deletions": 53,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 172,
          "url": "https://github.com/kungfu-systems/kfd/pull/172",
          "title": "release: promote 1.0.0-alpha.30 to alpha",
          "body": "Promote the verified KFD `1.0.0-alpha.30` catch-up candidate to the alpha channel.\n\nThe requested `1.0.0-alpha.29` release remains immutable and published. This follow-up synchronizes the packaged verifier with Kungfu's newer structured route-resolution schema after the owner-side reverse CI correctly detected drift. Stable/latest and production remain out of scope.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T15:24:10Z",
          "mergedAt": "2026-07-17T15:28:30Z",
          "additions": 271,
          "deletions": 134,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1035,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1035",
          "title": "chore: bind Project Cut successor context",
          "body": "## Summary\n\nPublish the successor Project Cut and Xinfa context artifacts required after the episodeless settlement implementation merged.\n\n## Changes\n\n- bind successor Cut 4ecc240cd5435cf0564f92a5350012bb05febb55df505e6eadfa4ff3e7b20598\n- publish verified Xinfa Atlas a71d2ac8f97a020d538a76f77a33af5dae9de81f7108a25ae59818ef7eee9ed1\n- preserve an explicit empty Episode delta\n\n## Verification\n\n- Project Cut receipt verdict is valid with diagnostics empty\n- native exact-root independent review returned fit\n- Atlas closeout gate returned ok\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Publishes content-addressed evidence for the existing ADR-0097 empty-delta contract without changing architecture\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Required checks are delegated to CI",
          "author": "dongkeren",
          "createdAt": "2026-07-17T15:49:07Z",
          "mergedAt": "2026-07-17T15:57:35Z",
          "additions": 11,
          "deletions": 0,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 227,
          "url": "https://github.com/kungfu-systems/build-images/pull/227",
          "title": "chore(buildchain): accept v2.14.2 alpha contract",
          "body": "## Summary\n\n- upgrade the managed alpha Buildchain package to `2.14.2-alpha.1`\n- accept exact `v2-alpha` runtime SHA `467d56d218a93540a3a200866d69fa7cd1a6df3f`\n- bind contract digest `sha256:cfaa1ec4810696a489861d6d04d8037ec15470b42acbbc0e9f78c8ef8e48bd98`\n- regenerate KFD-2 and KFD123 evidence while retaining the stable channel lock\n\nCloses #225\n\n## Validation\n\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- `pnpm exec buildchain validate --require-version-state --require-lifecycle-stages verify,publish`\n- alpha contract lock: `unchanged`, `drift=false`\n- stable contract lock: `unchanged`, `drift=false`\n- KFD-1/2/3 and Release Passport smoke: pass\n- 77 qualification tests: pass\n\n## Release boundary\n\nThis Buildchain provenance update is a global selective-publish invalidator. Its alpha promotion must rebuild and verify the complete image family.",
          "author": "dongkeren",
          "createdAt": "2026-07-17T15:57:10Z",
          "mergedAt": "2026-07-17T16:00:02Z",
          "additions": 21,
          "deletions": 21,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 173,
          "url": "https://github.com/kungfu-systems/kfd/pull/173",
          "title": "feat(site): declare KFD candidate pages",
          "body": "## What\n\n- add a renderer-facing `candidatePages` contract to `site/kfd-site.json`\n- make KFD own candidate index and detail routes, source paths, status, slot hints, claim boundaries, and page bodies\n- preserve `kfdCandidates` as the backward-compatible candidate-domain projection\n- verify every page declaration against `drafts/registry.json` and refresh KFD witnesses\n\n## Registry agreement\n\n- [x] `npm run check` passes\n- [x] Numbered decisions remain unchanged\n\n## Version impact (per KFD-1)\n\n- [x] additive renderer contract within the cumulative pre-stable major site-bundle surface\n\n## Verification\n\n- `npm run update:evidence`\n- `npm run check`\n- `git diff --check`\n- `npm pack --dry-run --json`",
          "author": "dongkeren",
          "createdAt": "2026-07-17T15:48:32Z",
          "mergedAt": "2026-07-17T16:06:21Z",
          "additions": 152,
          "deletions": 75,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 229,
          "url": "https://github.com/kungfu-systems/build-images/pull/229",
          "title": "fix(comparator): serialize SIGKILL restart state",
          "body": "## Summary\n\n- wait for each project-scoped container to expose exact `false 137` state after deliberate SIGKILL\n- restart only after the bounded transition and retain the pre-crash container identity\n- verify and retain the post-restart container identity plus running, exit-code, and health state\n- cover successful asynchronous transition and bounded timeout with executable shell regression tests\n\nCloses #223\n\n## Validation\n\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- 79 qualification tests passed\n- focused SIGKILL transition and timeout tests passed\n- `bash -n pilots/comparator/scripts/container-state.sh pilots/comparator/scripts/pilot.sh`\n- `shellcheck pilots/comparator/scripts/container-state.sh pilots/comparator/scripts/pilot.sh`\n- `git diff --check`\n\n## Runtime boundary\n\nThe helper remains project-scoped and the existing trap owns cleanup on success, timeout, and failure. No global Docker cleanup is introduced.",
          "author": "dongkeren",
          "createdAt": "2026-07-17T16:05:36Z",
          "mergedAt": "2026-07-17T16:10:17Z",
          "additions": 200,
          "deletions": 6,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 230,
          "url": "https://github.com/kungfu-systems/build-images/pull/230",
          "title": "release: promote Buildchain contract and SIGKILL evidence to alpha",
          "body": "## Summary\n\nPromote the accepted Buildchain v2.14.2-alpha.1 contract lock and the comparator SIGKILL transition fix to the alpha channel.\n\nThe comparator now waits for the exact stopped state `false 137` before restart, records pre/post container state, and fails closed on timeout or an unexpected exit. The exact implementation commit passed the Kungfu package smoke on agent-120 with `false 137` -> `true 0 healthy` evidence and zero residual Docker resources.\n\nThe Buildchain runtime and contract digest change is a global provenance invalidator, so the promotion must rebuild the managed image set under the new locked contract. Release Passport and GitHub release publication remain enabled by the standard promotion workflow.\n\nIssue #223 remains open until the resulting exact alpha tag passes the runtime replay. Issue #222 is intentionally excluded because its 3x21 authority run is blocked by kungfu-systems/kungfu#1030.\n\n## Source\n\n- dev material: `5792b6fa23f79c5e020633ed028883eeaa8a68e6`\n- Buildchain contract PR: #227\n- SIGKILL transition PR: #229",
          "author": "dongkeren",
          "createdAt": "2026-07-17T16:11:09Z",
          "mergedAt": "2026-07-17T16:15:40Z",
          "additions": 221,
          "deletions": 27,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1036,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1036",
          "title": "fix(xinfa): publish reproducible schema authority",
          "body": "## Summary\n\n- publish a versioned Xinfa schema-set manifest that closes all 18 public schemas by exact bytes and public identity\n- make the Atlas schema root consume that published authority instead of recomputing a toolchain-dependent root\n- add fail-closed drift tests, standalone extraction coverage, and retained Shifu producer checks on the existing CI matrix\n- repair stale SDK KFD expectations for the already-registered diagnostics and agent-work-state contracts\n\nFixes #1027\nFixes #1033\n\n## Local validation\n\n- `./shifu xinfa:check`\n- `./shifu xinfa:standalone`\n- `./shifu docs:check`\n- `./shifu kfd:buildchain:check`\n- `./shifu check` on macOS after merging current `dev/v4/v4.0`\n- clean Rust 1.96 target: 39 tests passed and compiled Atlas schema root matched `sha256:1c3519689b9f5f9db531f497408c93baaf9a068877bdbf505e042eb5c02d8fdb`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Publishes and verifies the existing Xinfa schema authority without changing Atlas or Pack root semantics.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-17T16:09:38Z",
          "mergedAt": "2026-07-17T16:33:29Z",
          "additions": 662,
          "deletions": 39,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1037,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1037",
          "title": "docs(agent): expose verified Xinfa context discovery",
          "body": "## Summary\n\nMake Xinfa context discovery part of the repository and installed-Agent first-read path. Agents now receive one accurate source-checkout flow, one explicit installed read-only boundary, and machine-readable help without relying on Atlas-private prompts or chat history.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Route AGENTS.md, README, the documentation guide, Documentation Map, and Xinfa README to a new verified-context guide.\n- Ship Xinfa discovery and automation-boundary help in the Agent onboarding pack, Codex/Claude Skills, brief, and machine index.\n- Keep KFD-3 Human/Agent documentation-control selections identical and bind the updated command catalog revision for KFD-1 drift detection.\n- Raise the final-ready default to the newly measured complete 66,560-token documentation-control budget.\n- Add cold-start discovery assertions and refresh generated Buildchain KFD evidence.\n\n## Verification\n\n- `./shifu check:source` — passed (419 Node tests, Python suites, type checks, and source gate).\n- `./shifu docs:check` — passed.\n- `./shifu docs:prose:required` — passed.\n- `node scripts/verify-agent-pack.mjs` — passed (14 files, 146 commands).\n- `node --test scripts/shifu-documentation-surfaces.test.mjs` — passed (8 tests).\n- `./shifu kfd:buildchain:check` — passed.\n- `./shifu docs context ... --budget 65536 ...` demonstrated the old boundary as degraded; 66,560 was measured complete.\n- `./shifu docs final-ready --since origin/dev/v4/v4.0 --json` — Human and Agent projections complete, parity matched, no required omissions or invalidations; independent review remains required by design.\n- Commit hook ran the staged gate plus Xinfa standalone checks (37 Rust tests), all passed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0008\"],\n  \"summary\": \"Close Agent discovery and installed-help adoption for the existing human-surface and Xinfa authority contract\",\n  \"verification\": [\"source acceptance\", \"documentation surface dual-first tests\", \"agent pack verifier\", \"Buildchain KFD evidence check\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nGenerated KFD claim hashes were refreshed only to bind the changed shipped Agent pack and help surfaces; no release claim or qualification scope was widened.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-17T16:28:05Z",
          "mergedAt": "2026-07-17T16:38:32Z",
          "additions": 475,
          "deletions": 73,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1039,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1039",
          "title": "docs(xinfa): specify route root authority",
          "body": "## Summary\n\n- publish a machine-readable clean-room contract for `routeRoot` and `authorityRoot` inputs, canonicalization, selection, exclusion, and failure behavior\n- add an exact worked fixture with ordering, exclusion, missing-node, duplicate-node, and conflicting-authority cases\n- weld the contract and fixture into Xinfa product ownership and standalone extraction\n- add Rust proofs that the published roots reproduce exactly and malformed authority fails closed\n- deliver a single linear commit on current `dev/v4/v4.0` for the repository's rebase merge queue; supersedes #1038\n\nFixes #1028\n\n## Local validation\n\n- `./shifu xinfa:check`\n- `./shifu xinfa:standalone`\n- `./shifu docs:check`\n- `./shifu check:source`\n- `./shifu check` on macOS after linearizing onto current `dev/v4/v4.0` and regenerating the live Xinfa documentation witness\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Specifies and verifies the existing Xinfa route-root algorithm without changing its root semantics or authority boundary.\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T17:02:05Z",
          "mergedAt": "2026-07-17T17:07:49Z",
          "additions": 377,
          "deletions": 8,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1040,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1040",
          "title": "docs(episode): publish provider schemas",
          "body": "## Summary\n\n- publish versioned JSON Schemas for the sealed Git workspace manifest, qualification evidence, immutable JSONL segments, and provider closure contract\n- make JSONL framing, safe integer encoding, ordering, digest preimages, and tracked/ignored path authority explicit\n- add product-owned positive and adversarial fixtures that recompute claims, qualification, and provider roots while refusing schema substitution and unsafe values\n- preserve the native yijinjing semantic root as the sole authority; portable consumers verify the declared closure without inventing provider semantics\n\nFixes #1029\n\n## Local validation\n\n- `node scripts/check-git-episode-provider.test.mjs` (10/10)\n- `./shifu docs:check`\n- `./shifu check` on macOS after linearizing onto current `dev/v4/v4.0`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Publishes portable schemas and verification rules for existing Episode provider bytes while preserving the native semantic-root authority boundary.\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T17:12:01Z",
          "mergedAt": "2026-07-17T17:16:45Z",
          "additions": 619,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1041,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1041",
          "title": "fix(facts): queue concurrent material writers",
          "body": "## Summary\n\n- acquire the Fact admission writer before reading current state, so concurrent clients are serialized at the Core commit boundary instead of racing through a read/write gap\n- expose a bounded 5-second `bounded-core-wait/v1` writer-admission contract while preserving the yijinjing single-physical-writer invariant\n- make concurrent CLI home-directory initialization idempotent\n- add a real 8-process public CLI test proving all distinct Fact subjects are admitted and visible without adapter-side retry\n\nFixes #1030\n\n## Local validation\n\n- C++23 macOS build: `cmake --build framework/core/build --target kungfu pykungfu --parallel 20`\n- `pytest framework/core/tests/python/test_storage_cli.py -k fact_cli_queues_real_multi_process_material_writers -vv`\n- `./shifu check`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fixes concurrent client admission for the existing Fact Library contract while preserving its single physical journal-writer authority.\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T17:51:25Z",
          "mergedAt": "2026-07-17T17:58:44Z",
          "additions": 185,
          "deletions": 15,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 174,
          "url": "https://github.com/kungfu-systems/kfd/pull/174",
          "title": "chore(kfd): anchor alpha 31 release",
          "body": "Anchor the next KFD prerelease as `1.0.0-alpha.31`.\n\nThis release publishes the candidate-page site bundle contract introduced on dev, including explicit `/drafts/` routing metadata and the first non-normative candidate page. KFD-1, KFD-2, and KFD-3 release evidence is regenerated against the new immutable version fact.\n\nValidation:\n- `npm run check`\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T21:39:30Z",
          "mergedAt": "2026-07-17T21:42:32Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 175,
          "url": "https://github.com/kungfu-systems/kfd/pull/175",
          "title": "release: promote 1.0.0-alpha.31 to alpha",
          "body": "Promote the verified KFD `1.0.0-alpha.31` candidate to the alpha channel.\n\nThis prerelease publishes the explicit renderer contract for non-normative KFD candidate pages:\n- KFD-owned `/drafts/` index and `/drafts/{id}/` route declarations\n- stable source, status, slot-hint, and claim-boundary metadata\n- regenerated KFD-1, KFD-2, and KFD-3 evidence bound to the alpha.31 version fact\n\nStable/latest and production remain out of scope. Successful merge verification is expected to drive Buildchain trusted publication, GitHub Release creation, Release Passport generation, and downstream propagation.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T21:42:56Z",
          "mergedAt": "2026-07-17T21:46:18Z",
          "additions": 177,
          "deletions": 100,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1024,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1024",
          "title": "refactor(yijinjing): clear journal-layer fossils and bound frame payload writes",
          "body": "<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Behaviour-preserving cleanup of the libyijinjing journal layer identified by review. It projects no ADR: the frame bytes, the publish barrier, and the reader's output order are all unchanged. It completes a direction ADR-0063 already stated (retiring the *_lock_free names in favour of the private *_unserialized primitive), but ADR-0063 is still decision_status: proposed, so this PR does not claim delivery against it and does not touch any ADR record.\",\n  \"summary\": \"Converge writer constructors, state the reader merge order once in domain terms, bound frame payload writes at the reservation, and fix a per-frame leak in cloned_frame.\",\n  \"verification\": [\"pnpm run configure && pnpm run compile (framework/core, 0 errors)\", \"yijinjing_mmap_tests 25/25\", \"yijinjing_content_hash_tests pass\"]\n}\n-->\n\n## What\n\nThree related cleanups in the libyijinjing journal layer. All are behaviour-preserving on the wire: no frame bytes change, and the reader hands frames out in exactly the same order.\n\n### writer constructors: 8 → 4\n\nFour overloads existed only to accept a `lazy` flag the body discarded via `(void)lazy`. The journal-taking overload additionally ignored `low_latency` and `bus`, because the journal it receives has already fixed both. All twelve call sites passed `lazy=true`, so dropping the parameter preserves behaviour.\n\nWorth recording for future retirements: these overloads were already marked `[[deprecated]]`, but the build carries `-Wno-deprecated-declarations`, so the marker never produced a single warning. Marking without a gate migrates nobody.\n\n### reader merge order: say it once, in domain terms\n\n`sort()` compared `gen_time` against an `INT64_MAX` sentinel that nothing ever lowered, so the branch was always taken — removed. The comparator was named `later` and used with `max_element` to select a *minimum*, into a variable named `min_journal_it`. It is now one `reads_before` definition (smallest `gen_time`, ties to higher `Priority`), with the heap parameterised on its transpose so `top()` reads as \"next to read\".\n\nThe invariant that makes the lazy `gen_time` comparison sound is now stated rather than implied: a journal parked in the heap must never advance, which is exactly why `sort()` pops the journal it hands to `current_` back into the recheck buffer.\n\n### frame payload writes are now bounded\n\n`reserve_frame()` is the only thing that bounds a payload write, but `frame::copy_data()` cannot see the reservation, and `close_frame()`'s assert fires *after* the memcpy and vanishes under `NDEBUG` — unchecked in exactly the build that matters. The checked entry point now lives on `frame_transaction`, which already holds the reservation; `write` / `write_as` / `write_at` route through it. `frame::copy_data()` remains the unchecked primitive and now says so.\n\n`open_frame_lock_free()` / `close_frame_lock_free()` had no callers anywhere in the tree, and ADR-0063 already reserved `*_unserialized` for the internal single-owner primitive, so they are removed rather than re-documented.\n\n### cloned_frame\n\n`copy()` / `open()` overwrote `header_` without releasing the previous buffer — `replay_writer` calls `copy()` twice per replayed frame, so this leaked one allocation per frame — and wrote through `malloc`'s result with no null check. Both now go through `allocate()`, which raises on failure and frees first.\n\n## Tests\n\nFive reader-merge tests cover the k-way merge, priority tie-breaks, priority-over-`gen_time`, agreement between the scan and heap selection paths, and the contract that `join()` must not move a live cursor (previously unprotected, and precisely the kind of thing a merge-order refactor tidies away).\n\nThey were confirmed to fail against a deliberately inverted comparator before being accepted: three of the five turn red, so they are not vacuous.\n\n## Verification\n\n- `pnpm run configure` + `pnpm run compile` on framework/core: green, 0 errors\n- `yijinjing_mmap_tests`: 25/25\n- `yijinjing_content_hash_tests`: pass\n\nConsumer migration was closed out by a full compile rather than by grep: three of the twelve call sites — a directly-constructed temporary, the pybind `py::init<>` template arguments, and a namespace-aliased `make_shared` — carry no greppable `writer(` text.\n\n## Version impact\n\nKFD-1: this registers `pykungfu-binding` as a welded surface. Python consumers bind to exported signatures at import time with no runtime negotiation, which is the register's own test, so its absence was a gap in the register rather than evidence the surface is not welded. Dropping `lazy` narrows `pykungfu.writer.__init__` from seven arguments to six — a break under the register, carried as pre-release: no in-tree Python constructs `writer`, and `stubs/pykungfu/` regenerates from the binding rather than being a hand-maintained contract. No line opens.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T11:07:24Z",
          "mergedAt": "2026-07-17T23:13:45Z",
          "additions": 246,
          "deletions": 124,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 994,
          "url": "https://github.com/kungfu-systems/kungfu/pull/994",
          "title": "fix(qualification): bind source runtime environments",
          "body": "## Summary\n\n- declare the foreign-runtime allowance only for qualification suites that exercise the freshly built source-tree Python binding\n- cover Episode workers, live-Peer native campaigns, and runtime-activation source suites while keeping product distribution and packaged-runtime smoke fail-closed\n- register source-build artifacts from the tracked KFD-3 declaration only inside the explicit `KUNGFU_BUILDCHAIN_SOURCE_BUILD=1` boundary\n- run the complete alpha/release qualification under a bounded 180-minute Buildchain lifecycle window so Windows can retain its final evidence instead of being cancelled at the 120-minute default\n- sync the candidate with `dev/v4/v4.0@1ebbf2e9b3b8c380d8597b3a7bf95cac63af3e0f`\n\n## Root cause and qualification evidence\n\nHosted Windows uses a locked uv environment whose base interpreter is runner-provided CPython. The runtime guard correctly rejects that interpreter unless the source qualification harness declares the existing named boundary. Stable Buildchain v2.13.0 retains exact binary evidence but does not publish a standalone release binary, so the source-build boundary must use the tracked KFD-3 declaration without changing ordinary layout discovery.\n\n- run `29513870056`: Episode, live Peer, runtime activation, product distribution, runtime smoke, and product verification passed; product catalog exposed the missing source-build registration boundary\n- run `29521465645`: re-proved the exact three-platform Buildchain `v2.13.0@ec48c0b311212c5f3a591e0284da6e85a9fdded5` binary evidence\n- run `29528999557` at `31286590a712fcf26141a3adc79c74128c6139ab`: macOS and Linux completed live Peer, runtime activation, and zero-burden qualification; all six downloaded reports were `passed` and all six adjacent `raw-logs.jsonl.gz` bundles matched manifest SHA256 and passed gzip integrity\n- run `29528996759` at the same head: Windows passed live Peer and runtime activation, then the complete zero-burden campaign reached the 120-minute lifecycle limit\n- exact candidate: `9e83fafd037e3e50fc860ee82cbff21db2116f2e`, tree `c7f8a4cfc1000aa74f978b60ec2517c76aba7525`\n- current hosted Windows qualification: `29542317309`\n- current full self-hosted matrix: `29542319870`\n\n## Validation\n\n- `./shifu check:source` (source acceptance 381/381, runtime upgrade 76/76, Desktop 69/69)\n- source-runtime boundary tests, registrar tests, Rust workspace tests, Clippy, Biome, architecture, documentation, Shifu, and Buildchain contract gates\n- workflow authority digest refreshed after the lifecycle timeout change\n- DCO sign-off on every commit\n\nDo not merge until the current exact-head Windows/full-matrix run and PR checks are green and the retained report/raw-log pairs are audited.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repairs source-qualification environment, source-build artifact registration, and bounded qualification execution without changing runtime architecture, packaged-runtime admission, or product claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes qualification and source-build registration boundaries only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] No credentials or generated qualification evidence are committed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-16T14:34:08Z",
          "mergedAt": "2026-07-17T23:22:49Z",
          "additions": 659,
          "deletions": 111,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1043,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1043",
          "title": "fix(ci): advance dev patrol Buildchain runtime",
          "body": "## Summary\n\n- advance the dev verify patrol from Buildchain v2.12.4 to stable v2.13.0\n- pick up the exact-SHA stale bundle fallback already proven in Buildchain #1261\n- refresh the governed workflow authority and invocation facts\n\nCloses #612.\n\n## Mac verification\n\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs` — 21/21 passed\n- staged repository gate — passed\n- `git diff --check` — passed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Advances a pinned CI controller runtime to a published compatible fix without changing Kungfu runtime architecture or release claims.\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T23:16:40Z",
          "mergedAt": "2026-07-17T23:42:42Z",
          "additions": 5,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1045,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1045",
          "title": "refactor(query): replace bounded SQL regexes with parser",
          "body": "## Summary\n\n- replace the two bounded SQL regular expressions with a tokenizer and recursive-descent parser\n- preserve the accepted language and report precise token offsets\n- register and execute the dedicated parser contract test in affected-native plans\n- supersede conflicting #988 with a linear branch on the current dev baseline\n\nSupersedes #988.\n\n## Equivalence and Mac evidence\n\n- the original change was locally verified by a full core build, 19/19 native tests, 11/11 query CLI tests, and SQL frontend storage tests\n- the three C++ source/test blobs in this linear branch are byte-identical to that locally verified branch\n- an offline differential corpus covered 197,901 inputs with no disagreement and caught six injected faults\n- current affected-native planning now includes `kungfu_bounded_sql_parser_tests` for query implementation changes\n- current Mac native reconfiguration was attempted but correctly refused before compilation because this host has Ninja 1.10.2 while the repository contract now requires >=1.11.1; merge-queue affected-native remains the integration proof\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Parser-internal refactor of the bounded SQL frontend. The accepted dialect, character classes, and length bounds are unchanged and equivalence-tested; no architecture decision or release claim advances.\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T23:28:53Z",
          "mergedAt": "2026-07-17T23:55:26Z",
          "additions": 714,
          "deletions": 61,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1046,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1046",
          "title": "ci(kfd): verify Kungfu-owned fixtures",
          "body": "## Summary\n\n- add a product-owned reverse verifier for Pack, Atlas, and Episode fixtures\n- compare the published KFD Atlas fixture against Kungfu's committed Xinfa golden before verification\n- isolate the Xinfa build and retain observed-root diagnostics\n- advance KFD to alpha.31, whose published fixture matches the corrected reproducible producer\n- supersede conflicting #1032 with a linear branch on the current dev baseline\n\nSupersedes #1032.\n\n## Mac verification\n\n- `./shifu kfd:verify-owned-fixtures` — passed for Pack, Atlas, and Episode\n- staged repository gate — passed\n- `git diff --check` — passed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Adds consumer-side drift detection and consumes a corrected provider fixture without changing Kungfu runtime architecture or release claims.\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T23:30:07Z",
          "mergedAt": "2026-07-18T00:09:05Z",
          "additions": 232,
          "deletions": 1,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1047,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1047",
          "title": "fix(yijinjing): carry page lifecycle as policy",
          "body": "## Summary\n\n- make page lifecycle an explicit runtime/journal policy rather than reading environment variables inside journal code\n- keep the existing storage paths and defaults while making lifecycle selection testable\n- supersede #1022 with a `fix/*` linear branch because the old `feature/*` name falsely required a feature-delivery ADR declaration\n\nSupersedes #1022.\n\n## Mac verification\n\n- the original change passed a full `./shifu build:core` and 22/22 mmap tests on Mac\n- the replacement rebased cleanly over #1024; the runtime IO source blobs remain byte-identical, while journal files contain the expected combined current-dev changes\n- current native reconfiguration was attempted but correctly refused before compilation because this host has Ninja 1.10.2 while the current repository contract requires >=1.11.1\n- `git diff --check` — passed; merge-queue affected-native is the current-base integration proof\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Moves an existing page-lifecycle choice into explicit policy plumbing without changing the accepted runtime architecture, file format, or release claims.\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T23:30:44Z",
          "mergedAt": "2026-07-18T00:23:36Z",
          "additions": 185,
          "deletions": 22,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 107,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/107",
          "title": "feat(site): render latest KFD and paper bundles",
          "body": "## Summary\n\n- consume @kungfu-tech/kfd@1.0.0-alpha.29\n- consume the latest paper alphas, including foundation paper 0.1.0-alpha.7\n- render all six bundle-declared non-normative formal reference pages under /N/formal/\n- expose formal routes in navigation, site manifests, KFD agent read order, and checks\n- resolve KFD package Markdown links to rendered site pages or upstream GitHub source\n\n## Validation\n\n- pnpm run build\n- pnpm run check\n- bash -n scripts/check-site.sh\n- node --check scripts/render-site.mjs\n- git diff --check\n- Playwright desktop/mobile checks for KFD-1 decision and formal reference\n- local HTTP 200 checks for decision, usage, formal, papers, and foundation paper routes\n\n## Upstream versions\n\n- @kungfu-tech/kfd@1.0.0-alpha.29\n- @kungfu-tech/paper-kfd-foundation-real-world-agent-work@0.1.0-alpha.7\n- @kungfu-tech/paper-kungfu-product-white-paper@0.1.0-alpha.5\n- @kungfu-tech/paper-observer-declared-timelines@0.1.0-alpha.8",
          "author": "dongkeren",
          "createdAt": "2026-07-17T14:57:52Z",
          "mergedAt": "2026-07-18T00:28:08Z",
          "additions": 691,
          "deletions": 60,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1377,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1377",
          "title": "Release v2.14.2 from qualified v2.14.2-alpha.1",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.2-alpha.1`\n- Candidate SHA: `467d56d218a93540a3a200866d69fa7cd1a6df3f`\n- Selection: `latest-qualified`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-17T20:01:43Z",
          "mergedAt": "2026-07-18T00:32:47Z",
          "additions": 2047,
          "deletions": 267,
          "changedFiles": 49
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1379,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1379",
          "title": "fix(release): suppress expected stable deferral friction",
          "body": "## Summary\n\n- treat minimum stable interval and completed-canary soak waits as expected deferrals\n- skip workflow-friction token creation and issue reporting only when every failed stable gate check is temporal\n- preserve reporting for missing canaries, evidence mismatches, policy errors, and product-diff failures\n\nCloses #1378.\n\n## Validation\n\n- `node --test tests/build-surface.test.mjs` (82 passed)\n- `pnpm run check:workflows`\n- `git diff --check`\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider billing, quota, or usage attribution changes\n- [x] Release evidence behavior is fail-closed outside the two declared temporal deferrals",
          "author": "dongkeren",
          "createdAt": "2026-07-18T00:40:19Z",
          "mergedAt": "2026-07-18T00:45:39Z",
          "additions": 32,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1048,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1048",
          "title": "feat(recovery): add fenced unified recovery entry",
          "body": "## Summary\n\nAdd one plan-first recovery entry that translates deep product diagnostics into bounded actions while keeping runtime, Peer, storage, and Episode services authoritative.\n\nThe command is read-only by default. Execution requires the exact reviewed plan identity, explicit approval for confirmation-required actions, delegated write-point fences, per-action receipts, and a fresh deep-health postflight. Unknown authority, identity, or projection state remains manual-blocked.\n\n## Related issue\n\nAtlas goal `2026-07-17-kungfu-unified-recovery-entry`.\n\n## Changes\n\n- add `kungfu recover` with JSON and contract discovery surfaces\n- register deterministic recovery plan, action, and receipt schemas in the diagnostics contract\n- map only declared health problems to existing runtime, Peer, storage, and Episode authority operations\n- reject stale plans before writes and retain the Episode manifest-frame fence at the native append boundary\n- stop after the first failed action while preserving succeeded, failed, and not-run receipts\n- document the user workflow and architecture boundary in ADR-0111\n\n## Verification\n\n- Mac: `./shifu rebuild:core` passed, including the C++23 Core, Python binding, Node/Electron bindings, and both WASM engines\n- Mac: health diagnostics suite passed (17 health, 8 recovery, 2 native health, 1 selected storage test)\n- Mac: Episode control and manifest recovery focused suite passed (19 tests)\n- Mac: isolated first-use `kungfu recover --json` returned a ready zero-action plan and created no runtime directory\n- Mac: `./shifu check:health-diagnostics-contract`, targeted Ruff checks, and `./shifu docs:check` passed\n- agent-120 Linux at `01f774fc30ebae8f909453a361e89b64e7e38a3c`: 8 recovery tests and 8 diagnostics contract tests passed\n- DARKHERO Windows at `01f774fc30ebae8f909453a361e89b64e7e38a3c`: 8 recovery tests and 8 diagnostics contract tests passed\n- final documentation closure commit `90e1b15788cdd4174e21c041479dc843bfba14b1` passed the staged and documentation gates; exact bounded evidence is recorded in `docs/qualification/unified-recovery.md`\n\nA wider `./shifu test:episode-control` run reports 43 passed and one JSON/preflight-output failure. The same failing test reproduces unchanged on the PR base `d682779a674ce8000ead9a11c3613473ee278c77`, so it is recorded as existing dev debt rather than hidden as a result of this change.\n\nNo three-platform heavy CI workflow was manually dispatched; cross-platform evidence above is from the requested device-local manual qualification.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0111\"],\n  \"summary\": \"Deliver a plan-first fenced recovery orchestrator over the existing runtime, Peer, storage, and Episode authorities\",\n  \"verification\": [\"Mac full Core rebuild and native CLI smoke\", \"Mac recovery and Episode focused tests\", \"agent-120 recovery and diagnostics contracts\", \"DARKHERO recovery and diagnostics contracts\", \"documentation and staged gates\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR adds a local product CLI and diagnostic contract. It does not contact provider APIs, handle credentials, grant publication authority, or mutate external services.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-17T23:39:02Z",
          "mergedAt": "2026-07-18T00:45:45Z",
          "additions": 1948,
          "deletions": 14,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 110,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/110",
          "title": "Release production from 575c43e77d47",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `575c43e77d47258b5da1c8de0adf2e38de8ab28a`\n- Artifact hash: `81d27bf9947fb345485cf6915aea1caaf01ad16f2431b30cbe74753d4708777c`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29623153212)\n- Required label: `buildchain-release`\n- Release branch: `release/production-575c43e77d47`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-18T00:36:41Z",
          "mergedAt": "2026-07-18T00:46:28Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1042,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1042",
          "title": "chore(project-cut): settle Xinfa agent discovery docs",
          "body": "## Summary\n\nPublish the deterministic empty-Episode Project Cut that closes the Xinfa Agent discovery documentation delivery merged in #1037.\n\n## Related issue\n\n- Follow-up to #1037\n\n## Changes\n\n- add the content-addressed Project Cut manifest\n- add its independently verifiable receipt\n- preserve the exact existing Xinfa Atlas root and declare an explicit empty Episode delta\n\n## Verification\n\n- `./shifu project-cut verify --state .kungfu/runtime/project-cut/settlements/e5c042fd4a5a743d4a80e708ecdd0b971907c22e19a3d221db68b84a3483f837/state.json --execute --json`\n- staged pre-commit gate, including documentation contracts and Biome\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This follow-up publishes only the deterministic Project Cut manifest and receipt for the already reviewed documentation delivery in PR #1037; it does not alter an architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR adds only content-addressed Project Cut evidence; no release action or credential path is changed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T23:11:10Z",
          "mergedAt": "2026-07-18T00:48:00Z",
          "additions": 12,
          "deletions": 1,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1044,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1044",
          "title": "fix(ci): watch the membrane wrapper and contract test",
          "body": "## Summary\n\nTwo honesty gaps left by #904, found while checking whether the cross-membrane\nsymmetry had actually been qualified on all three platforms. It had not, and the\nreason turned out to be structural rather than a matter of waiting.\n\n## Related issue\n\nFollow-up to #904 (ADR-0078 cross-membrane decode symmetry).\n\n## Changes\n\n- **The membrane gate did not watch the membrane.** `embedding.membranes` is the\n  gate that qualifies the embedding membrane, but its path filter omitted three\n  files that decide whether the membrane contract still holds: the Rust wrapper\n  crate (`crates/kungfu-embedding/**`), the generic-codec contract test itself,\n  and the `CMakeLists.txt` that wires that test into ctest. A change confined to\n  any of them would land without the gate ever running — the gate could not see\n  the thing it exists to guard. #904 only triggered it (prospectively) because it\n  happened to also touch `embedding.cpp`. Added all three to the filter.\n- **ADR-0078 implied more evidence than exists.** The follow-up said the contract\n  test \"is wired into the embedding-membrane qualification gate, which runs on\n  Linux, macOS, and Windows\", and that Linux/Windows evidence \"comes from the\n  qualification gate\". Both are true about wiring and read as though the evidence\n  had been produced. It has not: the gate fires only on `alpha/*` and `release/*`\n  pull requests — heavy native membrane builds are deliberately kept out of\n  `dev/*` PRs (c727d5fa8) — so it has never run for this change and will not\n  before the next `dev` → `alpha` promotion. The wording now says that plainly.\n\n`implementation_status` stays `staged`; this PR does not change what has been\nqualified, only what the repository claims and what the gate watches.\n\n## Verification\n\n- The workflow YAML parses, and the three previously unwatched paths now match\n  the filter (checked against the parsed `pull_request.paths` list rather than by\n  eye).\n- `adr-audit` passes (`result=pass`, structural=0); the deterministic docs gate\n  passes.\n- No runtime surface is touched, so there is nothing to build or exercise here.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0078\"],\n  \"summary\": \"Make the embedding-membrane gate watch the Rust wrapper and the generic-codec contract test, and state the gate's actual reach in ADR-0078 instead of implying cross-platform evidence that does not exist yet\",\n  \"verification\": [\"workflow YAML parses and the three previously unwatched paths match the filter\", \"adr-audit result=pass\", \"deterministic docs gate\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-17T23:26:47Z",
          "mergedAt": "2026-07-18T00:50:42Z",
          "additions": 17,
          "deletions": 10,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1049,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1049",
          "title": "chore(deps-dev): bump markdown-it from 14.1.0 to 14.2.0",
          "body": "Bumps [markdown-it](https://github.com/markdown-it/markdown-it) from 14.1.0 to 14.2.0.\n<details>\n<summary>Changelog</summary>\n<p><em>Sourced from <a href=\"https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md\">markdown-it's changelog</a>.</em></p>\n<blockquote>\n<h2>[14.2.0] - 2026-05-24</h2>\n<h3>Added</h3>\n<ul>\n<li><code>isPunctCharCode</code> to utilities.</li>\n</ul>\n<h3>Fixed</h3>\n<ul>\n<li>Don't end HTML comment blocks on a blank line, <a href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1155\">#1155</a>.</li>\n<li>Properly recognize astral chars (surrogates) in delimiter scans for\nemphasis-like markers, <a href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1072\">#1072</a>. Big thanks to <a href=\"https://github.com/tats-u\"><code>@​tats-u</code></a> for his global efforts\nwith improving CJK support.</li>\n<li>Preserve unicode whitespaces when trimm headings/paragraphs, <a href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1074\">#1074</a>.</li>\n<li>More strict entities decode to avoid false positives <code>;</code>, <a href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1096\">#1096</a>.</li>\n<li>Restore block parser state on fail in <code>lheading</code> rule, <a href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1131\">#1131</a>.</li>\n</ul>\n<h3>Security</h3>\n<ul>\n<li>Fixed poor smartquotes perfomance on &gt; 70k quotes in single block</li>\n<li>Bumped linkify-it to 5.0.1 with fixed potential perfomance issues.</li>\n</ul>\n<h2>[14.1.1] - 2026-01-11</h2>\n<h3>Security</h3>\n<ul>\n<li>Fixed regression from v13 in linkify inline rule. Specific patterns could\ncause high CPU use. Thanks to <a href=\"https://github.com/ltduc147\"><code>@​ltduc147</code></a> for report.</li>\n</ul>\n</blockquote>\n</details>\n<details>\n<summary>Commits</summary>\n<ul>\n<li><a href=\"https://github.com/markdown-it/markdown-it/commit/829797aa00353ce0b62ddeb9b4583b837b1ffd9b\"><code>829797a</code></a> 14.2.0 released</li>\n<li><a href=\"https://github.com/markdown-it/markdown-it/commit/9ce2087562c45d1e5ddd9f76b990f4b3fbe040e5\"><code>9ce2087</code></a> Fix smartquotes perfomance</li>\n<li><a href=\"https://github.com/markdown-it/markdown-it/commit/02e73b88fdbaddf7ecee7e567a3da62b98e57a4d\"><code>02e73b8</code></a> linkify-it bump</li>\n<li><a href=\"https://github.com/markdown-it/markdown-it/commit/68cfb8c0792ba87992d21ffb4d22ee6cf635afb7\"><code>68cfb8c</code></a> fix: don't end HTML comment blocks on a blank line (<a href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1155\">#1155</a>)</li>\n<li><a href=\"https://github.com/markdown-it/markdown-it/commit/108313756cfffba31166df0140e27dd58e4da115\"><code>1083137</code></a> Readme cleanup</li>\n<li><a href=\"https://github.com/markdown-it/markdown-it/commit/97c7ca2571f4255ff1d0f465958dda5293d20fe8\"><code>97c7ca2</code></a> Update funding info</li>\n<li><a href=\"https://github.com/markdown-it/markdown-it/commit/c471b55c10501aba7b62817df613adc5f451da43\"><code>c471b55</code></a> Changelog update</li>\n<li><a href=\"https://github.com/markdown-it/markdown-it/commit/77696210d1c7c56e4ffd49ff28ba15b460cb01e4\"><code>7769621</code></a> isPunctChar =&gt; isPunctCharCode</li>\n<li><a href=\"https://github.com/markdown-it/markdown-it/commit/aa2aa70b3001ed6aea67c22f1ff52e1ca158d2e1\"><code>aa2aa70</code></a> fix: always reset parentType in lheading rule (<a href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1131\">#1131</a>)</li>\n<li><a href=\"https://github.com/markdown-it/markdown-it/commit/59955f2ad35cbb0e3f41ad779c7363a94b4bf38e\"><code>59955f2</code></a> Polish PRs <a href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1072\">#1072</a>, <a href=\"https://redirect.github.com/markdown-it/markdown-it/issues/1074\">#1074</a></li>\n<li>Additional commits viewable in <a href=\"https://github.com/markdown-it/markdown-it/compare/14.1.0...14.2.0\">compare view</a></li>\n</ul>\n</details>\n<br />\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Updates a development-time Markdown parser dependency and lockfile without changing runtime architecture or release claims.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-17T23:45:57Z",
          "mergedAt": "2026-07-18T01:04:19Z",
          "additions": 106,
          "deletions": 42,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1050,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1050",
          "title": "fix(stubs): sync generated writer binding",
          "body": "## Summary\n\nSynchronize the committed Python runtime stub with the writer binding generated by the current native source. The writer constructor lost the lazy boolean and now carries the widened source UID as the final argument.\n\n## Related issue\n\nRelated to #995.\n\n## Changes\n\n- update the generated `writer.__init__` signature in `runtime.pyi`\n- keep the committed generated tree clean after a production CLI build\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu product cli dist` on Linux exited 0 and changed only this one stub line\n- generated file SHA256 matched the committed patch: `1507167b86992ea8ac0cda49115573a4ccefd47d3c964fda15a17a3e4e1430f3`\n- Buildchain run 29620723812 completed the build and all Episode fuzz targets, then correctly failed the clean-source gate only on this stale generated file\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Synchronizes a generated Python binding projection with the already-registered pre-release writer constructor; no runtime behavior changes.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change restores the clean-source invariant required before a trusted CLI package can be published. Verification is tied to the failed official Buildchain run and an exact-source Linux regeneration.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; generated projection only)",
          "author": "dongkeren",
          "createdAt": "2026-07-17T23:55:32Z",
          "mergedAt": "2026-07-18T01:26:32Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 111,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/111",
          "title": "fix(ci): restore release PR production promotion",
          "body": "## Summary\n\n- keep the production capability enabled whenever production infrastructure is active\n- leave event authorization to Buildchain's trusted release-PR or manual decision\n- enforce the capability/manual-approval boundary in the infrastructure check\n\n## Verification\n\n- `actionlint .github/workflows/buildchain-web-surface.yml .github/workflows/buildchain-stable-canary.yml`\n- `node scripts/check-infra-outputs.mjs`\n- `pnpm run build`\n- `pnpm run check`\n\n## Release behavior\n\n- ordinary `main` push remains staging-only\n- matching reviewed release PR merge can promote production\n- trusted manual dispatch remains available\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs changed\n- [x] No provider API, billing, quota, or usage attribution behavior changed\n- [x] Release evidence and deployment gating remain Buildchain-owned\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T01:31:32Z",
          "mergedAt": "2026-07-18T01:39:28Z",
          "additions": 12,
          "deletions": 16,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1052,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1052",
          "title": "fix(kfd): refresh release evidence",
          "body": "## Summary\n\n- refresh generated Buildchain KFD-1 witness and release-gate projections after the diagnostics contract advanced to v2\n- refresh the SDK mirrors and bind the KFD-3 prebuild witness to the current source baseline\n- keep the patch generator-only; no runtime or product behavior changes\n\n## Related issue\n\n- follows the diagnostics contract change merged by #1048\n- unblocks trusted Build run 29625242248, which reached 44/45 and failed only on stale KFD release evidence\n\n## Changes\n\n- update the `kungfu-diagnostics` KFD-1 source and artifact digests\n- regenerate the derived KFD-1 release gates and SDK mirrors\n- refresh the KFD-3 prebuild source coordinate\n\n## Verification\n\n- `./shifu kfd:buildchain:check`\n- `./shifu check:source`\n- source gate totals: 424 Node/source tests, 6 Python source tests, 76 runtime-upgrade tests, 69 desktop-update tests\n- staged commit gate, including Buildchain KFD evidence check\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Refresh generated release evidence after an already-admitted diagnostics contract change; no architecture contract or runtime behavior changes.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: generated release evidence only. The repository generator, KFD check, source acceptance, DCO, and merge-queue checks provide the verification chain.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; behavior is unchanged)",
          "author": "dongkeren",
          "createdAt": "2026-07-18T01:47:46Z",
          "mergedAt": "2026-07-18T01:56:48Z",
          "additions": 25,
          "deletions": 25,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 176,
          "url": "https://github.com/kungfu-systems/kfd/pull/176",
          "title": "docs(kfd): define cross-domain action primitive candidates",
          "body": "Define the cross-domain action primitive candidate system over Fact and Episode, with separate non-binding Atlas, Pursuit, and Warrant candidates. Keep implementation design outside KFD and refresh KFD-1/KFD-3 evidence and site projections.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T02:00:16Z",
          "mergedAt": "2026-07-18T02:03:26Z",
          "additions": 1005,
          "deletions": 210,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1053,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1053",
          "title": "docs(architecture): define fact episode action runtime",
          "body": "## Summary\n\n- move the concrete Fact/Episode action-runtime implementation design into Kungfu\n- keep KFD limited to principles, generation mechanisms, qualification questions, and falsifiers\n- preserve ADR-0109 and the welded Agent Work State contract as current authority\n\n## Related issue\n\n- follows ADR-0109 and the current KFD action-Primitive candidates\n\n## Changes\n\n- add a proposed architecture design for the Fact/Episode substrate and Pursuit, Atlas, and Warrant action semantics\n- define storage, Git projection, Xinfa migration, progressive disclosure, delivery gates, and open questions\n- route the design from the architecture index, documentation map, and product documentation entrypoint\n- register public document metadata without changing an accepted ADR or machine contract\n\n## Verification\n\n- `./shifu docs:check`\n- `./shifu check:source`\n- source gate totals: 424 Node/source tests, 6 Python source tests, 76 runtime-upgrade tests, 69 desktop-update tests\n- staged commit gate and Agent Work State parity checks\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Document a proposed implementation integration of existing accepted decisions without changing an architecture contract, machine authority, runtime behavior, or qualification claim.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; runtime behavior is unchanged)",
          "author": "dongkeren",
          "createdAt": "2026-07-18T02:06:45Z",
          "mergedAt": "2026-07-18T02:16:32Z",
          "additions": 304,
          "deletions": 0,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 224,
          "url": "https://github.com/kungfu-systems/build-images/pull/224",
          "title": "feat(comparator): add Kungfu Phase B qualification",
          "body": "## Summary\n\n- consume one exact prebuilt Kungfu CLI package and fail closed on package SHA, source SHA, version, metadata, evidence URL, or fixed-path drift\n- materialize the frozen J1/J2/J3 x seven-tier x three-repetition Phase B plan only after the package exists\n- add the digest-locked Kungfu adapter, answer-free fixture, independent semantics, verifier-only oracle, package-derived image preparation, image-ID checks, cleanup proof, and self-contained offline bundle closure\n- extend the reusable Kungfu package workflow from unscored smoke through non-test qualification and offline verification\n- reject unsafe archive members and wait for the exact stopped container state during deliberate SIGKILL restart probes\n\n## Authority boundary\n\nThe workflow grants only `containerized-user-outcome-qualification` after all 63 steps and independent offline verification pass. Native performance, fresh-install cost, final scoring, and winner authority remain false. build-images consumes the package and never checks out or compiles Kungfu source.\n\n## Final qualification evidence\n\n- build-images implementation: `707f2c5d907a0a18057433d265b2b6198687496a`\n- Kungfu source: `610926e7c6b2d5e42f6faa7b25745091a8c0c60a`\n- trusted package build: https://github.com/kungfu-systems/kungfu/actions/runs/29626182882\n- package version: `4.0.0-alpha.1`\n- package SHA-256: `22c7e3989b8b4a6b178b519feef4eb13a08a0d181f66c9178ba78506947429b3`\n- materialized plan SHA-256: `b21f0a60b482f5e3ea2fcc8ff235bc2300b8e07bfd24d1abdd9e8deecfe088df`\n- bundle: `qual-kungfu-20260718T023503Z-3512567`\n- J1/J2/J3 x seven tiers x three repetitions: 63/63 passed\n- project-scoped cleanup proofs: 63/63 passed across 63 unique Compose projects\n- independent offline verifier: passed with `status=verified`\n- authority: `user_outcome_qualification_authority=true`\n- excluded authority: native performance, fresh-install cost, and final scoring all remain false\n- tracked checkout after execution: clean\n\nKungfu prerequisite repairs landed in #1041, #1050, and #1052. The former concurrent-writer `ownership_busy` blocker is covered by all three repetitions of the J1/J2/J3 concurrent tier and no longer reproduces.\n\n## Repository validation\n\n- `pnpm run check`: pass\n- qualification tests: 84/84 pass\n- `bash scripts/check-workflows.sh`: pass\n- exact package materialization: 21 scenarios / 63 required steps\n- final formal execution and independent offline verification: pass\n\nCloses #222\n",
          "author": "dongkeren",
          "createdAt": "2026-07-17T14:27:55Z",
          "mergedAt": "2026-07-18T03:11:54Z",
          "additions": 2265,
          "deletions": 60,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 231,
          "url": "https://github.com/kungfu-systems/build-images/pull/231",
          "title": "release: promote Kungfu Phase B qualification to alpha",
          "body": "## Summary\n\nPromote the qualification-authoritative Kungfu Phase B package consumer to the alpha channel through the Buildchain v2 dual-channel standard path.\n\nThe promoted implementation consumes an exact source-bound Kungfu CLI package, materializes the frozen J1/J2/J3 x seven-tier x three-repetition plan, and grants only containerized user-outcome qualification authority after independent offline verification. It does not grant native performance, fresh-install cost, final scoring, or winner authority.\n\nBuildchain promotion retains `release-passport=true` and `github-release=true`. The changed comparator paths are outside image contexts, so the fail-closed selective planner may classify them as an unknown global invalidator and rebuild the managed image family rather than claim unsafe reuse.\n\n## Source and evidence\n\n- dev material: `242e33065fb01a54b53eb6668b9eaa3d7e2ba479`\n- implementation PR: #224\n- Kungfu source: `610926e7c6b2d5e42f6faa7b25745091a8c0c60a`\n- trusted package build: https://github.com/kungfu-systems/kungfu/actions/runs/29626182882\n- package SHA-256: `22c7e3989b8b4a6b178b519feef4eb13a08a0d181f66c9178ba78506947429b3`\n- plan SHA-256: `b21f0a60b482f5e3ea2fcc8ff235bc2300b8e07bfd24d1abdd9e8deecfe088df`\n- formal bundle: `qual-kungfu-20260718T023503Z-3512567`\n- execution: 63/63 passed\n- cleanup: 63/63 passed across 63 unique Compose projects\n- independent offline verifier: passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T03:12:19Z",
          "mergedAt": "2026-07-18T03:14:45Z",
          "additions": 2265,
          "deletions": 60,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1055,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1055",
          "title": "docs(storage): qualify Fact authority baseline",
          "body": "## Summary\n\nReconcile the implemented Fact storage baseline with its ADR authority and publish a bounded, reproducible qualification matrix. This is a KFD-1 patch: it changes documentation and qualification evidence only, without changing a registered contract, schema, ABI, or runtime behavior.\n\n## Related issue\n\nAtlas goal `2026-07-18-kungfu-fact-storage-authority-audit`.\n\n## Changes\n\n- Mark ADR-0040's first content-store delivery implemented and bound to its merged commits, pull requests, and alpha release reachability.\n- Keep ADR-0018 explicitly staged, and refresh ADR-0037/0051 qualification links without broadening their claims.\n- Add the public Fact storage authority matrix, lifecycle boundary, reproduction commands, and explicit non-claims.\n- Publish an exact empty-Episode Project Cut over the verified existing Xinfa Atlas.\n\n## Verification\n\n- `./shifu docs:check`\n- `./shifu check:source`\n- `node scripts/adr-audit.mjs -- --json`\n- `node framework/core/src/libyijinjing/check-deps.mjs --self-test`\n- Standalone content-store probe: atomic publish, verified read, hash/torn/tamper detection, size/error taxonomy, 8-thread concurrency, and 6-process shared-content deduplication\n- Project Cut verify and commit observation at `da4ff609696b31a271ac48a7f3ace0c90bbd2057`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0018\", \"ADR-0037\", \"ADR-0040\", \"ADR-0051\"],\n  \"summary\": \"Reconcile the bounded Fact storage authority and qualification baseline without changing runtime contracts or behavior\",\n  \"verification\": [\"docs gate\", \"source gate\", \"ADR audit\", \"content-store dependency guard\", \"standalone concurrent content-store probe\", \"exact empty-delta Project Cut\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: documentation qualification and Project Cut provenance only. The exact tracked Cut, source projection, commit observation, ADR audit, and docs/source gates provide the evidence; no publishing or deployment action is introduced.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T03:24:12Z",
          "mergedAt": "2026-07-18T03:31:42Z",
          "additions": 177,
          "deletions": 12,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1056,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1056",
          "title": "chore(project-cut): bind Fact authority successor context",
          "body": "## Summary\n\nPublish the exact successor Xinfa Atlas and Project Cut after the Fact storage authority audit landed through the merge queue. This preserves the final merged source/tree boundary and closes the child context against its parent without adding runtime behavior or Episode evidence.\n\n## Related issue\n\nFollow-up to #1055 and Atlas goal `2026-07-18-kungfu-fact-storage-authority-audit`.\n\n## Changes\n\n- Track the verified successor Atlas for the final audit tree.\n- Publish an empty-Episode Project Cut whose parent is the Cut landed by #1055.\n- Preserve exact parent/child Atlas-root conservation for the next generic Fact-kernel stage.\n\n## Verification\n\n- Project Cut dry-run: no unstaged paths, `episodeDelta.empty=true`, `nativeRoots=[]`\n- Project Cut prepare, bind, commit observation, and Completion Claim\n- Staged source/documentation gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Publish exact successor context and Project Cut evidence after the audited documentation tree landed; no architecture contract or runtime behavior changes\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: tracked Project Cut/Xinfa provenance only; no publishing or deployment action is introduced.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T03:45:34Z",
          "mergedAt": "2026-07-18T04:03:56Z",
          "additions": 11,
          "deletions": 0,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1057,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1057",
          "title": "fix(ci): qualify release package with build-images",
          "body": "## Summary\n\nAdd the missing official same-run orchestration for Kungfu issue #995. An explicit manual Build input now builds the Linux x64 product package through the existing Buildchain lifecycle, validates and retains one source-bound CLI package, and invokes the exact reviewed build-images Phase B consumer.\n\nThe ordinary PR and manual build paths remain unchanged unless `run-kungfu-phase-b` is explicitly enabled.\n\n## Related issue\n\n- #995\n- kungfu-systems/build-images#222\n\n## Changes\n\n- add a fail-closed package identity gate for the CLI archive, including safe tar member validation and exact product, compatibility, upgrade, source, version, platform, size, and SHA-256 evidence\n- retain a single-purpose package artifact and identity receipt for 30 days\n- invoke the build-images `v1.2.4-alpha.28` consumer by its exact release commit `df6056fd2eb1e69a3349e827ede13ba95b6ae6b7`\n- classify the downstream reusable job as qualifying evidence in the closed-world workflow authority manifest\n- add five package identity contract fixtures and weld them into source acceptance\n\n## Verification\n\n- `./shifu check:source` passed after rebasing onto `fa7c61ff39cee1ae01f4ff7e1f0cab5fb5688333`\n- pre-commit staged gate passed\n- real-package validation passed on agent-120 for the retained 218,490,228-byte candidate; SHA-256 remained `22c7e3989b8b4a6b178b519feef4eb13a08a0d181f66c9178ba78506947429b3`\n- `./shifu check` reached the existing SDK baseline drift: the installed KFD/Buildchain versions are newer than `framework/contract/kungfu-agent-first-canonical-policy.json`; no files in that unrelated contract surface are changed here\n- the same-run Build + Phase B workflow will be dispatched on the merged exact source before #995 is closed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This change closes an existing release-evidence orchestration gap without changing a product architecture contract or supported capability claim.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe workflow uses read-only permissions for the package preparation and downstream qualification jobs, pins all authority-bearing external actions to full commits, and records the generated workflow authority digests in the same PR.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-18T03:59:35Z",
          "mergedAt": "2026-07-18T04:06:46Z",
          "additions": 612,
          "deletions": 1,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 233,
          "url": "https://github.com/kungfu-systems/build-images/pull/233",
          "title": "fix(comparator): preserve package filename contract",
          "body": "## Summary\n\n- keep the caller-provided name scoped to the GitHub Actions artifact container\n- pass the fixed `kungfu-episodes-cli-linux-x64.tar.gz` filename to the comparator smoke contract\n- add workflow checks that preserve both namespaces\n\nRefs #232.\n\n## Evidence\n\nThe official Kungfu same-run qualification downloaded and SHA-verified its package, then failed before formal Phase B because the reusable workflow passed the artifact container name as `KUNGFU_CLI_ARTIFACT_NAME`: https://github.com/kungfu-systems/kungfu/actions/runs/29630035045\n\n## Verification\n\n- `bash scripts/check-workflows.sh`\n- `bash -n scripts/check-workflows.sh`\n- `pnpm run check` (87 tests; Buildchain contract locks, KFD1/2/3, and release-passport smoke passed)\n\n## Release\n\nAfter merge, publish the next v1.2 alpha through the Buildchain promotion workflow and update the Kungfu caller to the new exact tag and commit.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T04:41:23Z",
          "mergedAt": "2026-07-18T04:44:31Z",
          "additions": 13,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 234,
          "url": "https://github.com/kungfu-systems/build-images/pull/234",
          "title": "release: promote Kungfu package filename contract to alpha",
          "body": "## Summary\n\nPromote the reusable Kungfu package qualification fix to the v1.2 alpha channel through the standard Buildchain v2 dual-channel path.\n\nThe fix keeps the caller-provided GitHub Actions artifact container name separate from the fixed package filename required by the comparator runtime contract. It directly addresses build-images #232 and the failed official Kungfu same-run qualification: https://github.com/kungfu-systems/kungfu/actions/runs/29630035045.\n\nBuildchain promotion retains `release-passport=true` and `github-release=true`. The changed paths are qualification workflow and source-contract checks only; no Dockerfile or image context changed. Selective publication must reuse or rebuild image artifacts only according to the existing fail-closed planner and retained provenance.\n\n## Source\n\n- dev material: `9498a18080c26b66c00f4481470a7f7d222cbbef`\n- implementation PR: #233\n- issue: #232\n- local verification: `pnpm run check` passed with 87 tests, both Buildchain contract locks, KFD1/2/3, and Release Passport smoke\n\nAfter promotion, Kungfu will pin the resulting exact alpha tag and source commit, rerun the official same-run package qualification, and require the full 63/63 Phase B evidence before closing its issue.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T04:46:15Z",
          "mergedAt": "2026-07-18T04:49:06Z",
          "additions": 13,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1058,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1058",
          "title": "feat(fact): define backend-neutral cut kernel contract",
          "body": "## Summary\n\nDefine the accepted backend-neutral Fact identity, relation, Cut, and named-ref contract without adding an authoritative writer.\n\n## Related issue\n\nAtlas goal: 2026-07-18-kungfu-fact-cut-kernel-contract\n\n## Changes\n\n- add ADR-0112 and the machine-readable Fact Cut kernel contract\n- pin deterministic identity, immutable body/version roots, typed relation add/revoke, Cut closure, and CAS ref semantics\n- add positive and falsifier fixtures plus source acceptance coverage\n- record the exact Project Cut with an explicit empty Episode delta\n\n## Verification\n\n- `./shifu check:fact-cut-kernel-contract` (7/7)\n- `./shifu docs:check`\n- `./shifu adr:audit -- --json` (structuralFindings=0)\n- `./shifu check:source`\n- staged pre-commit gate\n- Project Cut `sha256:961d1bd18e312dd33a552de624c34ef5844ec5742b587f7704b8662ac316943e` observed at `66d2cb74ffdc5c24059d0595a0c1ec8584fdd39b`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0112\"],\n  \"summary\": \"Accept the backend-neutral Fact Cut kernel contract while leaving the authoritative writer explicitly not started\",\n  \"verification\": [\"./shifu check:fact-cut-kernel-contract\", \"./shifu docs:check\", \"./shifu adr:audit -- --json\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-18T04:50:16Z",
          "mergedAt": "2026-07-18T05:05:49Z",
          "additions": 958,
          "deletions": 7,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1059,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1059",
          "title": "fix(ci): consume corrected build-images Phase B workflow",
          "body": "## Summary\n\n- update the official same-run Kungfu Phase B consumer from build-images `v1.2.4-alpha.28` to `v1.2.4-alpha.29`\n- pin the corrected reusable workflow by exact release commit `7cf672d83323fdd139ad90b6e8165a56e431cc6c`\n- refresh the closed-world workflow authority manifest and source acceptance contract\n\nThis is an ADR-neutral CI bug fix. It does not change product behavior or widen qualification authority.\n\nRefs #995 and kungfu-systems/build-images#232.\n\n## Failure and fix evidence\n\n- failed same-run qualification: https://github.com/kungfu-systems/kungfu/actions/runs/29630035045\n- package staging passed with exact source `f0f363ab9a32b3e938bf4360f7b6b0001f090ba1`, version `4.0.0-alpha.1`, SHA-256 `5d5c311e7dced3cf825a1be0b2df3f88830860a9bb290305efd09f7a1a2fc442`, and size 218490092 bytes\n- downstream failure: the `.28` reusable workflow passed the Actions artifact container name where the fixed package filename was required\n- build-images fix: https://github.com/kungfu-systems/build-images/pull/233\n- standard Buildchain release promotion: https://github.com/kungfu-systems/build-images/actions/runs/29631251454\n- corrected release: https://github.com/kungfu-systems/build-images/releases/tag/v1.2.4-alpha.29\n\n## Verification\n\n- `./shifu gate:workflow-authority:refresh`\n- `./shifu check:source`\n- 425 source contract tests\n- 5 Phase B package identity tests\n- 76 runtime upgrade tests\n- 69 desktop update tests\n- staged pre-commit gate passed\n\nAfter merge, dispatch the exact merged mainline SHA with `run-kungfu-phase-b=true` and close #995 only after 63/63 execution, 63/63 cleanup, and independent offline bundle verification pass.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This change updates an exact CI qualification dependency after a contract bug fix without changing a product architecture contract or supported capability claim.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change pins the corrected qualification consumer by exact release tag and commit, keeps read-only permissions, and refreshes the closed-world workflow authority digest.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-18T05:06:09Z",
          "mergedAt": "2026-07-18T05:16:33Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 177,
          "url": "https://github.com/kungfu-systems/kfd/pull/177",
          "title": "chore(kfd): anchor alpha 32 release",
          "body": "Anchor the next KFD prerelease as `1.0.0-alpha.32`.\n\nThis release publishes the cross-domain action primitive candidate set introduced on dev, including the fact/episode substrate and the Atlas, Pursuit, and Warrant candidate surfaces. KFD-1, KFD-2, and KFD-3 release evidence is regenerated against the new immutable version fact.\n\nValidation:\n- `npm run check`\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T05:17:28Z",
          "mergedAt": "2026-07-18T05:20:40Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 178,
          "url": "https://github.com/kungfu-systems/kfd/pull/178",
          "title": "release: promote 1.0.0-alpha.32 to alpha",
          "body": "Promote the verified KFD `1.0.0-alpha.32` candidate to the alpha channel.\n\nThis prerelease publishes the cross-domain action primitive candidate set:\n- Fact and Episode as the action-world substrate\n- Atlas, Pursuit, and Warrant as independent candidate action profiles\n- KFD-owned candidate registry, site routes, standards metadata, and regenerated KFD-1/2/3 evidence\n\nStable/latest and production remain out of scope. Successful merge verification is expected to drive Buildchain trusted publication, GitHub Release creation, Release Passport generation, and downstream propagation.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T05:21:05Z",
          "mergedAt": "2026-07-18T05:24:21Z",
          "additions": 1030,
          "deletions": 235,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1062,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1062",
          "title": "chore(project-cut): bind fact contract successor context",
          "body": "## Summary\n\nBind the merged Fact Cut contract tree to the refreshed parent Atlas and current `dev/v4/v4.0` source projection from a clean linear successor branch.\n\n## Related issue\n\nAtlas goal: 2026-07-18-kungfu-fact-cut-kernel-contract\nSuccessor to PR #1058; replaces #1060 after merge queue reported a history-replay conflict\n\n## Changes\n\n- add the refreshed Xinfa Atlas baseline for `sha256:92c70753…bb688`\n- add successor Project Cut `sha256:25dd19a1…f48ef`\n- add current-base Project Cut `sha256:4469a45b…8fd07`\n- preserve explicit empty Episode deltas and immutable parent Cut lineage\n\n## Verification\n\n- exact tree equality with the reviewed #1060 head\n- clean linear ancestry from current `dev/v4/v4.0`\n- staged pre-commit gate\n- `./shifu docs:check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0112\"],\n  \"summary\": \"Bind the staged ADR-0112 Fact Cut contract to exact successor Xinfa and Project Cut evidence on the current dev base\",\n  \"verification\": [\"exact tree equality with #1060\", \"staged pre-commit gate\", \"./shifu docs:check\", \"successor Project Cut sha256:4469a45bd65a8301f5cc77e28c6a8ae1bf769f8de18ed892e04b75454448fd07\"]\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n\nThis changes only repository-local Project Cut/Xinfa evidence. It contains no credentials and performs no release or deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-18T05:26:55Z",
          "mergedAt": "2026-07-18T05:39:18Z",
          "additions": 16,
          "deletions": 1,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1063,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1063",
          "title": "fix(kfd): gate merge-result evidence drift",
          "body": "## Summary\n\n- regenerate KFD-1 and KFD-3 evidence from the current mainline contract registry\n- add the Buildchain KFD release evidence check to every build-free source acceptance run\n- add source-plan coverage that freezes the exact check command\n\nThis is an ADR-neutral release-evidence bug fix. It does not change product behavior or widen qualification authority.\n\nRefs #995.\n\n## Failure and fix evidence\n\n- failed formal same-run qualification: https://github.com/kungfu-systems/kungfu/actions/runs/29631992031\n- exact failed source: `7788ca466cdc96510b64ea1957fc1d2f0502e626`\n- failed gate: `Buildchain KFD release evidence`\n- exact error: `Buildchain KFD-3 registry is stale: .buildchain/kfd/kfd-3/surfaces.json`\n- merge-result contract registry SHA-256: `7c104e23b7d88d34c8b021dd6fd8ec08c0b1b9d56a3da37d1ed853082a2d2801`\n- stale projected SHA-256: `b45bd675493a2a4aa0a571219c37737a81979fca7f19fe24d0e6525a22817c9d`\n- regenerated evidence now binds 10 contracts and the exact current registry hash\n\nThe unconditional source gate prevents stale KFD projections already present on the base or introduced by a merge result from reaching the expensive product build.\n\n## Verification\n\n- `./shifu kfd:buildchain:check`\n- `node --test scripts/source-acceptance.test.mjs` (19/19)\n- `./shifu check:source`\n- 432 source contract tests\n- 5 Phase B package identity tests\n- 76 runtime upgrade tests\n- 69 desktop update tests\n- staged pre-commit gate passed\n\nAfter merge, dispatch the exact merged mainline SHA with `run-kungfu-phase-b=true` and close #995 only after the same run passes package identity, package smoke, 63/63 execution, 63/63 cleanup, and independent offline bundle verification.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This change repairs stale generated release evidence and strengthens a source gate without changing a product architecture contract or supported capability claim.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change refreshes checked-in KFD projections and adds a fail-closed source check. It does not add credentials, write permissions, publishing authority, or mutable external references.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T05:43:51Z",
          "mergedAt": "2026-07-18T05:49:08Z",
          "additions": 126,
          "deletions": 43,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1065,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1065",
          "title": "chore(project-cut): bind exact fact contract root",
          "body": "## Summary\n\nPublish the exact successor Xinfa Atlas and Project Cut after the staged Fact Cut contract landed through the merge queue. This closes the child context against the refreshed parent root without changing the contract or introducing a writer.\n\n## Related issue\n\nFollow-up to #1058 and #1062 for Atlas goal `2026-07-18-kungfu-fact-cut-kernel-contract`.\n\n## Changes\n\n- publish Xinfa Atlas `sha256:47fc5cc9311ea0ac012155c303e558622723ffba845ba0bde95199b6608ad744`\n- publish final Project Cut `sha256:f50dfeb575e064a89aa80f5ea705bdb0a5cf95a916386e32d8b86b34e34fa39b`\n- preserve parent Cut `sha256:d487a719c1fc7d0e5871aed0c44e2981ff72341d9a2d8ae029753f2e99f6b6c0`\n- preserve an explicit empty Episode delta\n\n## Verification\n\n- full staged pre-commit gate\n- exact generated evidence only\n- no authoritative writer or release qualification added\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Publish exact successor Xinfa and Project Cut evidence after ADR-0112 contract delivery; no architecture contract or runtime behavior changes\"\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n\nBoundary: tracked Project Cut/Xinfa provenance only; no publishing or deployment action is introduced.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T05:47:55Z",
          "mergedAt": "2026-07-18T05:52:54Z",
          "additions": 11,
          "deletions": 0,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1066,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1066",
          "title": "chore(project-cut): publish current fact contract leaf",
          "body": "## Summary\n\nPublish a successor Project Cut over the current dev source projection after the exact observation of PR #1065 correctly reported source drift from PR #1063. This keeps the failure visible and advances the immutable Cut lineage instead of weakening the gate.\n\n## Related issue\n\nAtlas goal `2026-07-18-kungfu-fact-cut-kernel-contract`; successor to #1058, #1062, and #1065.\n\n## Changes\n\n- publish successor Cut `sha256:25f97eeb4a3af2874db847fcd87ed4ad47400ef348ef18b7cfe227af4f95be6c`\n- parent the successor on `sha256:f50dfeb575e064a89aa80f5ea705bdb0a5cf95a916386e32d8b86b34e34fa39b`\n- bind current source projection `sha256:4b1136f3a1575435c9dcf16edd9511e21b88a55a949072791a794fca8a751b1e`\n- preserve Atlas `sha256:47fc5cc9311ea0ac012155c303e558622723ffba845ba0bde95199b6608ad744` and an explicit empty Episode delta\n\n## Verification\n\n- Project Cut dry-run and execute had no diagnostics or unstaged paths\n- full staged pre-commit gate\n- only two generated Project Cut files are added\n- no authoritative writer or release qualification is introduced\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Publish a successor Project Cut after exact observation detected concurrent source drift; no architecture contract or runtime behavior changes\"\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n\nBoundary: tracked Project Cut provenance only; no publishing or deployment action is introduced.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T06:07:35Z",
          "mergedAt": "2026-07-18T06:12:47Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 109,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/109",
          "title": "chore: consume KFD release",
          "body": "Buildchain release propagation from @kungfu-tech/kfd into the kfd.libkungfu.dev site surface.\n\nBuildchain release propagation plan:\n\n```json\n{\n  \"schemaVersion\": 1,\n  \"contract\": \"kungfu-buildchain-release-propagation-plan\",\n  \"source\": \"kfd\",\n  \"upstreamRelease\": {\n    \"repository\": \"kungfu-systems/kfd\",\n    \"channel\": \"alpha\",\n    \"tag\": \"v1.0.0-alpha.32\",\n    \"sourceSha\": \"bdf865ba4ce944aaff9f3636b9816f40199393a9\",\n    \"package\": {\n      \"name\": \"@kungfu-tech/kfd\",\n      \"version\": \"1.0.0-alpha.32\",\n      \"integrity\": \"sha512-nuWMzbEh3zLlSQOnMrIOki6LjDy8yglkbrc7n5rC6ybqSxA+C4XIg0tRMNXqCQI6RU4yJWsR/fvb7DfiQXIWhg==\"\n    },\n    \"releasePassport\": {\n      \"url\": \"https://github.com/kungfu-systems/kfd/releases/download/v1.0.0-alpha.32/buildchain.release.json\",\n      \"sha256\": \"5fab93adaa511e81dccd35230ed0fa9493f5b842bd0a0e7905cf31214d98582c\"\n    }\n  },\n  \"targets\": [\n    {\n      \"edge\": \"kfd-to-site-libkungfu-dev\",\n      \"source\": \"kfd\",\n      \"target\": \"site-libkungfu-dev\",\n      \"repository\": \"kungfu-systems/site-libkungfu-dev\",\n      \"channel\": \"alpha\",\n      \"baseRef\": \"main\",\n      \"lockPath\": \"buildchain.upstreams/kfd.release.json\",\n      \"lock\": {\n        \"schemaVersion\": 1,\n        \"contract\": \"kungfu-buildchain-release-propagation-lock\",\n        \"upstream\": {\n          \"node\": \"kfd\",\n          \"repository\": \"kungfu-systems/kfd\",\n          \"channel\": \"alpha\",\n          \"tag\": \"v1.0.0-alpha.32\",\n          \"sourceSha\": \"bdf865ba4ce944aaff9f3636b9816f40199393a9\",\n          \"package\": {\n            \"name\": \"@kungfu-tech/kfd\",\n            \"version\": \"1.0.0-alpha.32\",\n            \"integrity\": \"sha512-nuWMzbEh3zLlSQOnMrIOki6LjDy8yglkbrc7n5rC6ybqSxA+C4XIg0tRMNXqCQI6RU4yJWsR/fvb7DfiQXIWhg==\"\n          },\n          \"releasePassport\": {\n            \"url\": \"https://github.com/kungfu-systems/kfd/releases/download/v1.0.0-alpha.32/buildchain.release.json\",\n            \"sha256\": \"5fab93adaa511e81dccd35230ed0fa9493f5b842bd0a0e7905cf31214d98582c\"\n          }\n        },\n        \"downstream\": {\n          \"node\": \"site-libkungfu-dev\",\n          \"repository\": \"kungfu-systems/site-libkungfu-dev\",\n          \"channel\": \"alpha\",\n          \"baseRef\": \"main\",\n          \"lockPath\": \"buildchain.upstreams/kfd.release.json\"\n        },\n        \"propagation\": {\n          \"graphContract\": \"kungfu-buildchain-release-propagation-graph\",\n          \"edge\": \"kfd-to-site-libkungfu-dev\",\n          \"channelPolicy\": \"preserve\",\n          \"channelMap\": {\n            \"alpha\": \"alpha\",\n            \"release\": \"release\"\n          },\n          \"exact\": true,\n          \"floatingTags\": false\n        },\n        \"lockSha256\": \"ed0e222f3b7eefd6249e5f10fd4e0a21805baae01d8dbc94a6b0e4d75dfed5c2\"\n      }\n    }\n  ],\n  \"summary\": {\n    \"targetCount\": 1,\n    \"channels\": [\n      \"alpha\"\n    ],\n    \"repositories\": [\n      \"kungfu-systems/site-libkungfu-dev\"\n    ]\n  }\n}\n```\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-17T21:53:47Z",
          "mergedAt": "2026-07-18T06:29:25Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1067,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1067",
          "title": "feat(storage): add authority-atomic backend switching",
          "body": "Replaces #1064 with a linear history compatible with the protected branch rebase merge queue. The delivered tree is equivalent; the successor Cut binds the new exact head.\n\n## Summary\n\nMake storage backend changes authority-atomic for populated runtimes. The active provider is now committed through a runtime-local generation binding only after a resumable, verified copy and a cross-process write-fenced cut.\n\n## Related issue\n\nAtlas goal `2026-07-18-kungfu-storage-backend-atomic-switch`.\n\n## Changes\n\n- Add resumable file-to-RocksDB and RocksDB-to-file migration with deterministic inventory and semantic-root verification.\n- Fence ordinary writes with a shared authority lock and the final switch or rollback cut with an exclusive lock.\n- Fail closed on configured-provider drift while retaining management recovery through the committed binding.\n- Expose the same status, switch, rollback, and receipt contract through C++, Python, Node, and the CLI.\n- Document the single-host authority boundary in ADR-0113 and the storage qualification surface.\n\n## Verification\n\n- `./shifu build:core`\n- Python storage suites: 33 passed\n- Node storage binding suite: 15 passed\n- `./shifu docs:check`\n- `./shifu check:source`\n- Successor Project Cut `sha256:2ac0f51ebfb3ce1ac3a7ce1e620aea0be9bf79166c137a8f0a3356b4b2b1313e`, explicit empty Episode delta, exact commit `2aa83ffa718cbd39659bb25a701c0b46ff596df5`, and Completion Claim\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0113\"],\n  \"summary\": \"Deliver the single-host authority-atomic storage backend switch, rollback, and recovery stage across native and language surfaces\",\n  \"verification\": [\"Core native build\", \"33 Python storage tests\", \"15 Node binding tests\", \"docs and source acceptance gates\", \"exact empty-delta Project Cut\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: the provider selection and management APIs change, and a tracked Project Cut records the exact delivery. No credentials, hosted services, publishing action, cross-machine consensus, or destructive source cleanup are introduced.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T06:23:32Z",
          "mergedAt": "2026-07-18T06:40:03Z",
          "additions": 2109,
          "deletions": 68,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 113,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/113",
          "title": "Release production from 43b41762a43c",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `43b41762a43c17712ffb29bdc98a43acdf6e7d59`\n- Artifact hash: `82891ed63931dc8bc9e72bd514fadf4a15d5041f090205fdaa13289f60768acd`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29634079462)\n- Required label: `buildchain-release`\n- Release branch: `release/production-43b41762a43c`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-18T06:36:39Z",
          "mergedAt": "2026-07-18T06:46:57Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1070,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1070",
          "title": "docs(runtime): clarify fact and episode substrate model",
          "body": "## Summary\n\nClarify the canonical relationship among journal authority, parallel Fact and Episode runtime substrates, and the Pursuit, Atlas, and Warrant action roles. Reinterpret older Episode-centered documentation without rewriting historical ADRs or widening implementation claims.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Define occurrence order, semantic visibility, and layer order as distinct concerns.\n- Establish Fact as admitted state at explicit Cuts and Episode as bounded causal experience across Cuts.\n- Explain Pursuit, Atlas, and Warrant as independently identified action objects over the Fact substrate.\n- Update the documentation map, vocabulary registry, profile entrypoints, CLI handbook, and installed Agent brief.\n- Add current-model pointers to older event and storage documents.\n\n## Verification\n\n- `./shifu docs:check`\n- `./shifu docs:prose:required`\n- `./shifu check:source`\n- `./shifu docs final-ready ...` reports 0 violations and matched Human/Agent parity; independent review remains required by design.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Document the accepted ADR-0109 and ADR-0112 relationship without changing architecture contracts or implementation claims\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-18T06:54:01Z",
          "mergedAt": "2026-07-18T06:59:44Z",
          "additions": 256,
          "deletions": 97,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1071,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1071",
          "title": "feat(xinfa): add native semantic project authority",
          "body": "## Summary\n\nMake Xinfa the sole owner of semantic project materialization. Shifu remains the exact Git/path/file discovery and gate adapter, eliminating duplicated semantic graph authority.\n\n## Related issue\n\n- Atlas goal: `2026-07-18-xinfa-native-semantic-control-plane`\n- Parent: `2026-07-18-xinfa-semantic-control-plane-and-context-quality`\n- Project Cut: `sha256:45db9dcf686e3c6f9070930812d83227273bb6df2c6ec85a409c9f73e5e1c579`\n\n## Changes\n\n- Add `xinfa project materialize --inventory FILE|- --json`.\n- Add the native semantic project model and `xinfa.semantic-project/v1` schema.\n- Replace the Shifu-owned semantic project declaration with `.xinfa/project.json`.\n- Keep `shifu.documentation.surfaces.json` only as a compatibility alias.\n- Derive semantic node identities exclusively in Xinfa and reject injected node identities or mismatched inventory roots.\n- Preserve build-free factual `docs inventory`; graph/pack/impact and semantic materialization still require Xinfa.\n- Keep the standalone semantic compiler host-neutral and refresh exact multi-consumer qualification witnesses.\n- Record the authority boundary in ADR-0114.\n- Settle and bind the exact Project Cut with an explicit empty Episode delta.\n\n## Verification\n\n- `./shifu xinfa:check`\n- `node --test scripts/shifu-documentation-runtime.test.mjs scripts/shifu-documentation-surfaces.test.mjs`\n- `./shifu docs:check`\n- `./shifu check:shifu-documentation-contract`\n- `./shifu xinfa:dogfood`\n- Node injection and inventory-root tampering fail closed.\n- Fresh checkout without `xinfa/target/debug/xinfa`: factual inventory passes; native tests are explicitly skipped.\n- Project Cut completion claim and exact-root observation passed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0114\"],\n  \"summary\": \"Xinfa now owns semantic project materialization while Shifu is limited to exact discovery and gate adaptation.\",\n  \"verification\": [\"Xinfa checks and tests\", \"node and inventory-root fault injection\", \"build-free factual inventory admission\", \"documentation contract checks\", \"dogfood parity and fault paths\", \"exact-root Project Cut completion claim\"]\n}\n-->\n\nVersion impact: minor capability delivery on the dev channel; no release promotion is performed by this PR.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes Project Cut evidence and source-projection surfaces; exact-root binding and completion-claim checks are included above.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T07:02:19Z",
          "mergedAt": "2026-07-18T07:11:17Z",
          "additions": 2514,
          "deletions": 1096,
          "changedFiles": 108
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1072,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1072",
          "title": "fix(core): make reader journal lookup typed",
          "body": "## Summary\n\n- return an explicit typed result when a reader has not joined a journal\n- map lookup misses at the embedding boundary to the stable core error contract\n- document the audited continue-on-error and environment configuration boundaries\n\n## Verification\n\n- `./shifu build:core`\n- `./shifu test:mmap`\n- `./shifu docs:check:readonly`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix makes an existing lookup failure contract explicit without changing an architecture decision or release boundary.\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above",
          "author": "dongkeren",
          "createdAt": "2026-07-18T07:27:03Z",
          "mergedAt": "2026-07-18T07:53:37Z",
          "additions": 90,
          "deletions": 6,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 180,
          "url": "https://github.com/kungfu-systems/kfd/pull/180",
          "title": "docs(kfd): promote the action geometry into KFD-7",
          "body": "## Summary\n- promote the Fact/Episode action geometry into numbered draft KFD-7\n- keep Atlas, Pursuit, Warrant, and occurrence independently addressable\n- require conservative reduction to an ordinary session for low-complexity work\n- project KFD-7 through KFD-1/2/3 metadata, trust, collaboration, and site surfaces\n\n## Verification\n- npm run update:evidence\n- npm run check\n- git diff --check\n\nSupersedes the narrower session-limit PR #179.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T08:28:54Z",
          "mergedAt": "2026-07-18T08:31:55Z",
          "additions": 1809,
          "deletions": 345,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 182,
          "url": "https://github.com/kungfu-systems/kfd/pull/182",
          "title": "chore(kfd): anchor alpha 33 release",
          "body": "Anchor the next KFD prerelease as `1.0.0-alpha.33`.\n\nThis release publishes numbered draft KFD-7 and its Fact/Episode action geometry, including the conservative low-complexity session limit and regenerated KFD-1/2/3 release evidence.\n\nValidation:\n- `npm run check`\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-18T08:38:13Z",
          "mergedAt": "2026-07-18T08:41:19Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1074,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1074",
          "title": "docs(adr): close journal architecture review",
          "body": "Closes the parent journal architecture review after all three follow-up streams were merged.\n\nThis PR adds a concise ADR-0001 closeout note linking the completed concurrency evidence, code-hygiene, lifecycle-policy, and error/configuration deliveries. It does not change the publication protocol, memory ordering, page layout, or runtime behavior.\n\nVerification:\n- ./shifu docs:check:readonly\n- Project Cut exact-root closeout gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0001\"],\n  \"summary\": \"Record the completed journal architecture review follow-ups and their verified boundaries.\",\n  \"verification\": [\"./shifu docs:check:readonly\", \"Project Cut exact-root closeout gate\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-18T08:36:22Z",
          "mergedAt": "2026-07-18T08:41:36Z",
          "additions": 37,
          "deletions": 0,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 183,
          "url": "https://github.com/kungfu-systems/kfd/pull/183",
          "title": "release: promote 1.0.0-alpha.33 to alpha",
          "body": "Promote the verified KFD `1.0.0-alpha.33` candidate to the alpha channel.\n\nThis prerelease publishes numbered draft KFD-7 and its action geometry:\n- Fact cuts and causal records remain independently addressable\n- Atlas, Pursuit, Warrant, and realized occurrence remain distinct\n- low-complexity work conservatively reduces to the familiar session experience\n- KFD-1/2/3 evidence, standards metadata, site bundle, and release impact are bound to the same source\n\nStable/latest and production remain out of scope. Successful merge verification is expected to drive Buildchain trusted npm publication, GitHub Release creation, Release Passport generation, and downstream site propagation.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T08:42:16Z",
          "mergedAt": "2026-07-18T08:45:13Z",
          "additions": 1834,
          "deletions": 370,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 181,
          "url": "https://github.com/kungfu-systems/kfd/pull/181",
          "title": "feat(kfd-7): publish draft action contract",
          "body": "## Summary\n\n- promote the cross-domain action candidate to numbered draft KFD-7 without activating a product Profile\n- publish the versioned action-contract schema, formal reference, usage guide, and package metadata\n- package the schema in the independent verifier and retain native/WASM parity plus fail-closed role and activation fixtures\n- regenerate KFD-1/KFD-2/KFD-3 evidence and the site projection\n\n## Verification\n\n- `cargo fmt --manifest-path verifier/Cargo.toml --all -- --check`\n- `npm run build:verifier`\n- `npm run update:evidence`\n- `npm run check`\n- `git diff HEAD^ --check`\n\n## Activation boundary\n\nKFD-7 remains `draft`. Schema validity is explicitly non-qualifying; activation still requires retained product witnesses, an exact evidence cut, and independent review.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T08:36:41Z",
          "mergedAt": "2026-07-18T08:49:06Z",
          "additions": 1632,
          "deletions": 163,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 184,
          "url": "https://github.com/kungfu-systems/kfd/pull/184",
          "title": "chore(kfd): anchor alpha 34 release",
          "body": "## Summary\n- anchor `@kungfu-tech/kfd` at `1.0.0-alpha.34`\n- regenerate KFD-1/2/3 release evidence from the current dev line\n- include the merged KFD-7 action-contract model in the release source\n\n## Verification\n- `npm run check`\n- `npm pack --dry-run --json`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-18T08:56:15Z",
          "mergedAt": "2026-07-18T08:59:25Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 185,
          "url": "https://github.com/kungfu-systems/kfd/pull/185",
          "title": "release: promote 1.0.0-alpha.34 to alpha",
          "body": "Promote the current `dev/v1/v1.0` release anchor to the alpha channel.\n\nRelease: `@kungfu-tech/kfd@1.0.0-alpha.34`\nIncludes: merged KFD-7 action-contract schema, verifier fixtures, formal/usage updates, and regenerated KFD-1/2/3 evidence.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-18T08:59:56Z",
          "mergedAt": "2026-07-18T09:03:02Z",
          "additions": 1657,
          "deletions": 188,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1073,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1073",
          "title": "feat(facts): add native Fact cut kernel",
          "body": "## Summary\n\nImplement the bounded native Fact kernel stage required by ADR-0112: Fact object/version identity, generic relation edges, immutable Cuts, and exact expected-old ref CAS now share one libkungfu Hana POD journal authority with thin Node, Python, and CLI edges.\n\n## Related issue\n\nAtlas goal `2026-07-18-kungfu-native-fact-cut-kernel`; parent `2026-07-18-kungfu-generic-fact-kernel`.\n\n## Changes\n\n- add canonical Hana POD records for Fact objects, versions, relations, Cuts, refs, and adjacent write receipts\n- add one native `fact_kernel` capability and operation for put, relation, revoke, Cut, ref CAS, and query actions\n- keep Node, Python, and CLI adapters JSON-thin over the same native authority\n- use content-addressed metadata/body namespaces and length-framed root derivation\n- reject environment identity and torn or mismatched authority/receipt pairs\n- publish exact successor Project Cut `sha256:261b9a4b9df7cee85dfdace0dc72811214bda12383bc0c04ca11d1f06e6f598c` over commit `3a70adf15a3d1d60929306ac6eefe659834f567a`\n\n## Verification\n\n- `./shifu check`\n- `./shifu check:fact-cut-kernel-contract` (7 passed)\n- targeted CMake builds for `kungfu_node` and `pykungfu`\n- exact Node Fact test (1 passed)\n- exact Python thin-edge tests (2 passed)\n- architecture health (0 findings)\n- SDK qualification and 31 unit tests\n- Project Cut closeout gate, native completion claim, and independent review verdict `fit`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0112\"],\n  \"summary\": \"Complete the bounded native Fact identity, relation, Cut, and ref authority stage while leaving portability and release qualification to subsequent stages\",\n  \"verification\": [\"full shifu check\", \"Fact Cut kernel contract tests\", \"native Node and Python thin-edge tests\", \"Project Cut exact-source closeout and independent review\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n\nBoundary: tracked Project Cut provenance and stage-ready ADR delivery evidence only; no package publishing or deployment action is introduced.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T08:18:54Z",
          "mergedAt": "2026-07-18T09:20:26Z",
          "additions": 2112,
          "deletions": 186,
          "changedFiles": 51
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 186,
          "url": "https://github.com/kungfu-systems/kfd/pull/186",
          "title": "feat(kfd-7): bind session qualification theorem",
          "body": "## Summary\n\n- formalize the conditional session round-trip preservation theorem and context-insufficiency corollary\n- advance the KFD-7 action contract to schemaVersion 2 with canonical theorem references\n- require Profile refinement, complexity-breakpoint, and same-payload counterexample evidence before activation\n- refresh native/WASM verifier projections, KFD-1/2/3 witnesses, standards metadata, and the site bundle\n\n## Verification\n\n- `npm run check`\n- `npm pack --dry-run --json`\n\n## Boundary\n\nSchema validity remains non-qualifying. Concrete runtime refinement, usability, cross-domain transfer, and activation remain product evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T09:54:08Z",
          "mergedAt": "2026-07-18T09:57:23Z",
          "additions": 818,
          "deletions": 188,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1078,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1078",
          "title": "docs(xinfa): admit Fact storage authorities",
          "body": "## Summary\n\nExtend the core-development Xinfa route so Fact storage work consumes the accepted storage, Fact Cut, and backend-switch authorities in one verified Task Chart.\n\n## Related issue\n\nSupersedes #1077, which used the wrong feature-branch classification for an ADR-neutral context correction.\n\n## Changes\n\n- include the runtime storage service authority\n- include the authoritative Fact and native Fact Cut ADRs\n- include the atomic backend-switch ADR\n- keep the existing route, capability, ownership, and budget contract unchanged\n\n## Verification\n\n- `./shifu docs:check`\n- `./shifu check:source`\n- source tree matches the previously validated commit exactly\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This corrects verified Xinfa context selection without changing runtime or architecture contracts\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T09:52:43Z",
          "mergedAt": "2026-07-18T09:58:25Z",
          "additions": 8,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 116,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/116",
          "title": "chore(kfd): render alpha.34 site bundle",
          "body": "## Summary\n\n- consume the exact `@kungfu-tech/kfd@1.0.0-alpha.34` propagation lock and release passport\n- render KFD-7 decision, usage, formal reference, registry, and badge endpoints from the upstream site bundle\n- refresh the Buildchain-owned README badge block and human-readable pinned-version facts\n\nThis replaces the incomplete propagation-only PR #115, whose preview plan failed because the new KFD-7 badge was not written to the managed README badge block.\n\n## Verification\n\n- `pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/ --config.minimumReleaseAge=0`\n- `SITE_PREVIEW_ALIAS=pr-local-alpha34 BUILDCHAIN_PREVIEW_ALIAS=pr-local-alpha34 SITE_SURFACE_CHANNEL=preview BUILDCHAIN_SURFACE_CHANNEL=preview pnpm run build`\n- same preview environment: `pnpm run check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-18T09:33:07Z",
          "mergedAt": "2026-07-18T10:05:38Z",
          "additions": 18,
          "deletions": 16,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1076,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1076",
          "title": "fix(core): enforce declared event route closure",
          "body": "## Summary\n\n- Require every dynamic event route to declare an admitted extension point before subscription.\n- Inventory every event subscription surface and fail closed on source drift.\n- Cover all extension classes with runtime, static, and negative-fixture checks.\n\n## Validation\n\n- ./shifu build:core\n- core CTest: 21/21 passed\n- ./shifu docs:check:readonly\n- ./shifu adr:audit\n- route topology contract and self-test\n- Project Cut exact-root closeout gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0108\"],\n  \"summary\": \"Enforce a closed declaration boundary for dynamic event-route extension points and source subscription surfaces.\",\n  \"verification\": [\"./shifu build:core\", \"core CTest 21/21\", \"./shifu docs:check:readonly\", \"./shifu adr:audit\", \"Project Cut exact-root closeout gate\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-18T09:42:34Z",
          "mergedAt": "2026-07-18T10:10:08Z",
          "additions": 372,
          "deletions": 39,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1381,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1381",
          "title": "feat(release): add KFD-7 engineering gates",
          "body": "## Summary\n\nAdds Buildchain release-passport gates for KFD-7 engineering contracts.\n\n## Changes\n\n- Adds a public KFD-7 release-gate Node API and CLI collector input.\n- Wires reusable workflow and promote action inputs.\n- Validates frozen contracts, verifier reports, positive and negative evidence, artifact surfaces, required experiments, and residual risk.\n- Preserves warning versus fail-closed semantics without judging real-world work quality.\n- Updates package exports, standalone bundling, generated actions, site contracts, and documentation.\n\n## Verification\n\n- pnpm run check: inventory, site/workflow drift, 632/632 unit tests, and all action bundles\n- Standalone SEA regression\n- npm pack dry-run: 238 entries, including KFD-7 API, release passport, and CLI\n- Real Kungfu consumer: passport ok=true, trust=pass, KFD-7 downgraded/warning\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe gate validates evidence closure only and retains explicit non-claims for unfinished runtime qualification.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-18T10:35:24Z",
          "mergedAt": "2026-07-18T10:39:39Z",
          "additions": 1877,
          "deletions": 173,
          "changedFiles": 60
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1051,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1051",
          "title": "fix(ci): qualify Windows runtime boundaries",
          "body": "## Summary\n\n- make the Windows Shifu lifecycle boundary preserve the native launcher's `cmd.exe` argument protocol\n- make Agent Session qualification portable across Windows named pipes, ACL semantics, case-preserved environment keys, file URLs, stdout-loss injection, detached provider/PTY launch, and exact child cleanup\n- measure installed Windows `.cmd` product surfaces through the platform shell under Node 24\n- retain the seven required qualification objects for every platform: the layer summary plus live-peer, runtime-activation, and zero-burden report/raw-log pairs\n\n## Root cause and fixes\n\nThe retained Buildchain failures exposed platform boundaries rather than relaxed qualification criteria:\n\n- Node-to-`cmd.exe` invocation could lose lifecycle arguments before the welded Shifu shim reached `dist` and qualification.\n- Windows test fixtures incorrectly reused Unix socket paths, POSIX mode checks, case-sensitive `PATH` assumptions, POSIX file imports, and stdout/PTY teardown behavior.\n- Node 24 returns `EINVAL` when the installed Windows `.cmd` surface launcher is spawned without the platform shell.\n\nThe final implementation keeps the existing fail-closed seven-object contract, uses Windows-native process and transport semantics, and adds focused regression coverage for the real lifecycle and surface-launcher boundaries.\n\n## Validation\n\n- exact source: `f29ce2b01b272540c8fed9e73375b75748c11233`\n- exact tree: `328074f38859bfd5f77b0a4b9085b5f7f12fc823`\n- Buildchain runtime: `ec48c0b311212c5f3a591e0284da6e85a9fdded5` (`2.14.1`)\n- local source gate: 424 passed, one Windows-only local skip, runtime-upgrade 76/76, desktop 69/69, type/Biome/staged gates passed\n- exact-head Windows qualification: [run 29640207344](https://github.com/kungfu-systems/kungfu/actions/runs/29640207344), passed with all seven retained objects audited\n- exact-head full matrix: [run 29641828759, attempt 2](https://github.com/kungfu-systems/kungfu/actions/runs/29641828759/attempts/2), Windows x64, Linux x64, and macOS ARM64 all passed\n\nFor every platform in the final matrix, the relay manifest and S3 objects were audited before cleanup:\n\n- all seven required object SHA-256 values matched\n- all three gzip raw-log bundles passed integrity checks\n- all three reports recorded the exact clean source/tree, `verdict=passed`, empty `violations`, and fully passed coverage/suites\n- each report's embedded log-bundle digest matched the adjacent raw-log object\n- the alpha layer summary passed within its execution budget\n\nPR #1051 was approved and squash-merged by `kungfu-origin` as `43d71eba468357040179f6d0cdfe281757610a95`. Because the base advanced during the merge window, merge verification compared every one of the 15 changed-path blobs; all match the qualified candidate exactly.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repairs platform command and test-cleanup boundaries without changing runtime architecture, release claims, or packaged-runtime admission.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes qualification invocation and cleanup behavior only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Source acceptance is green locally and in required checks\n- [x] Exact-head Windows and full three-platform Buildchain qualification passed\n- [x] Report and compressed raw-log pairs were retained and audited\n- [x] No credentials or generated qualification evidence are committed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T01:28:14Z",
          "mergedAt": "2026-07-18T11:04:46Z",
          "additions": 243,
          "deletions": 53,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1081,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1081",
          "title": "feat(agent): add KFD-7 runtime profiles (linear replacement)",
          "body": "## Summary\n\nLinear replacement for #1079. Adds the same provisional KFD-7 Kungfu Product Profile without claiming activation; the replacement branch removes merge commits so the required REBASE merge queue can evaluate it.\n\n## Changes\n\n- Adds native Fact-backed Profile actions and receipts for Fact, Episode, Pursuit, Atlas, and Warrant.\n- Exposes aligned CLI, Python, Node, API, Agent, and packaged contract surfaces.\n- Retains positive bootstrap and negative transition evidence.\n- Declares export/import, backend migration, and clean-home continuation as expected failures and keeps the release gate at warning.\n- Tree-equivalent to #1079 except the KFD-3 prebuild source SHA bound to this linear history.\n\n## Verification\n\n- ./shifu check\n- ./shifu build:core on the source-equivalent #1079 tree\n- Native Python Profile regression\n- Agent Work contract tests\n- API typecheck and tests\n- Documentation readonly gate\n- Buildchain 2.12.9-alpha.1 real consumer: passport ok=true, trust=pass, KFD-7 downgraded/warning\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0109\"],\n  \"summary\": \"Stage the provisional KFD-7 runtime Profile and retained warning evidence without claiming P17 qualification\",\n  \"verification\": [\"native core build\", \"positive and negative Profile evidence\", \"Buildchain warning passport\"]\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release declaration is fail-closed: incomplete recovery and independent-review evidence remains visible as warning debt.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-18T11:01:49Z",
          "mergedAt": "2026-07-18T11:10:22Z",
          "additions": 3096,
          "deletions": 90,
          "changedFiles": 45
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 117,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/117",
          "title": "Release production from d68d65092ad5",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `d68d65092ad5877acaccb7ada93ed4c9b3ffccf0`\n- Artifact hash: `99e4cf1c2c0b879744079a46815335752d72b9bf721e20c2443fd36e8c3363d0`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29640274117)\n- Required label: `buildchain-release`\n- Release branch: `release/production-d68d65092ad5`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-18T10:15:55Z",
          "mergedAt": "2026-07-18T11:39:41Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1083,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1083",
          "title": "chore(project-cut): bind KFD-7 runtime cut",
          "body": "## Summary\n\n- bind the merged KFD-7 runtime slice to Project Cut `sha256:28d3b04890465d8873eff770546cf6e8f0c398aca447f265701d07f4f56a9b62`\n- record the exact source projection, protocol, schema, policy, and settlement roots\n- preserve an explicit empty Episode delta; this PR does not assert KFD-7 qualification or activation\n\n## Validation\n\n- Project Cut settlement dry-run and execute/stage passed\n- commit observation published for `8fafd434c2328c622ba36750662219a1c27b8870`\n- independent completion review verdict: `fit`\n- continuation decision: `close`\n- Atlas Project Cut closeout gate: `ok=true`\n- repository pre-commit suite passed, including route/gate/schema/runtime, 12 latency tests, markdownlint, 63 contract tests, ADR/release/toolchain checks, and Biome\n\n## Provenance\n\n- runtime delivery PR: #1081\n- source runtime merge: `f01c8111508349aa81a21d8386cd71261da10537`\n- replacement for #1082 because `feature/*` is reserved for ADR delivery; this PR is evidence-only\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Publish content-addressed Project Cut and successor Xinfa evidence for the already-merged provisional KFD-7 runtime delivery without changing architecture, qualification, or activation state\"\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis evidence-only PR grants no publishing or activation authority; the explicit empty Episode delta and non-qualification boundary are retained.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; evidence-only)",
          "author": "dongkeren",
          "createdAt": "2026-07-18T11:42:45Z",
          "mergedAt": "2026-07-18T11:47:50Z",
          "additions": 11,
          "deletions": 0,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1085,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1085",
          "title": "fix(core): allow runtime-free query metadata",
          "body": "## Summary\n\nAllow runtime-independent storage query metadata actions to select the configured provider without resolving a filesystem binding from an empty runtime root.\n\nThis repairs the deterministic Linux profile-action-admission failure observed in formal Build run 29641966292 and unblocks the same-run build-images Phase B qualification tracked by #995.\n\n## Related issue\n\n- #995\n\n## Changes\n\n- Bypass runtime binding-file lookup when `runtime_dir` is empty while preserving normal provider selection.\n- Add a native Node regression for `query_plan` / `examples` with an empty runtime root.\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu build:core`\n- `KUNGFU_REQUIRE_NATIVE=1 KUNGFU_DIR=\"$PWD/framework/core/dist/kungfu\" ./shifu --filter @kungfu-tech/core test:storage-binding` (17/17 passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This is a bounded bugfix for runtime-independent metadata dispatch and does not change the storage authority or provider contract.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable: regression-only bugfix)",
          "author": "dongkeren",
          "createdAt": "2026-07-18T11:56:37Z",
          "mergedAt": "2026-07-18T12:03:27Z",
          "additions": 20,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 118,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/118",
          "title": "fix(site): accept current Buildchain contracts",
          "body": "## Summary\n\n- accept the current `v2` runtime contract at `c95f9fc36b0ac8fb4ff6400189850c4ae683f3ea`\n- accept the current `v2-alpha` runtime contract at `467d56d218a93540a3a200866d69fa7cd1a6df3f`\n- record the additive Buildchain controller surfaces now covered by the floating-ref trust gate\n\n## Verification\n\n- exact-runtime `buildchain-contract-lock.mjs check` for `v2`: unchanged\n- exact-runtime `buildchain-contract-lock.mjs check` for `v2-alpha`: unchanged\n- `pnpm run build`\n- `pnpm run check`\n- `pnpm exec buildchain badges readme --check`\n\nResolves the current contract-drift reports; older matching reports are superseded by these accepted locks.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T11:55:43Z",
          "mergedAt": "2026-07-18T12:06:21Z",
          "additions": 98,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1084,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1084",
          "title": "feat(xinfa): ratchet verified context quality",
          "body": "## Summary\n\n- add a frozen 31-case / 11-route / 6-scenario Xinfa verified-context quality benchmark\n- add deterministic public Shifu POSIX and Windows entrypoints plus CI qualification\n- bind benchmark corpus, thresholds, quality receipts, and Human/Agent routes into the semantic control plane\n- make retained quality verification moving-main safe: exact byte preservation for the same Atlas, cryptographic baseline verification plus fresh qualification for a composed successor Atlas\n- republish the same reviewed semantic delta as a two-commit linear history from latest main, with the complete immutable parent Cut chain\n\n## Final evidence\n\n- exact head: 3c9ed0187ac8cb851e54d98d47d3b455408dadfd\n- semantic commit: 38b97bcd145acb03d545e129f7ca4791020e4f00\n- base main: f01c8111508349aa81a21d8386cd71261da10537\n- head tree: d933745c82863592489dc54947a1c620a384fc9e\n- Project Cut: sha256:925432c6b598b2fc9896c357d03065d0b13e9733f2270521d9e6a3d9b4673e82\n- committed parent Project Cut: sha256:e6b34fee09accd32a338cbffb3742f8ae64afb4cf41d2b8358e9229a913ceed9\n- source projection: sha256:d25e916da02df20878608690eef1712b2cb69b682b739509a6adf27a109421bb\n- Xinfa Atlas: sha256:af6c4c8ae98a0595854b68453507bc09b1ca9d4d9280e4ea2fcfa31a777c471f\n- Cut receipt: sha256:b102c9f8b892175ab3b163c4c294ced6f5a63f282f524b64930b5ffdfefbe446\n- observation receipt: sha256:4b05a0bd23c8ddc8a25aee4fcd1d69ac269572ae6fee88bf608d1de911fbc330\n- fresh composed quality: sha256:5897c3b12417787894a470cac5c889f2a06cd96e26422c13805e2eae06a158c7\n- retained baseline quality: sha256:508dd6c74dcf686fc23cfd9daa758d549a1ef244cdba11e1ca31264bae394c05\n\n## Validation\n\n- independent exact-root review: FIT\n- targeted Node tests: 18 passed / 6 built-binary skips\n- negative moving-main tests: 3/3\n- Shifu Xinfa quality check: 31 cases / 11 routes\n- KFD verifier: 1 witness / 4 claims / 131 surfaces\n- staged commit gates including documentation, formatting, KFD, and successor Cut settlement\n\n## Supersedes\n\n- supersedes #1080 because main advanced during its approval window and exposed a missing committed parent Cut artifact in the linear successor\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0115\"],\n  \"summary\": \"Stage the deterministic Xinfa context-quality ratchet and moving-main-safe qualification contract\",\n  \"verification\": [\"targeted Node tests\", \"moving-main negative tests\", \"Shifu Xinfa quality check\", \"KFD verifier\", \"independent exact-root review\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T11:43:39Z",
          "mergedAt": "2026-07-18T12:14:06Z",
          "additions": 1775,
          "deletions": 10,
          "changedFiles": 73
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 119,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/119",
          "title": "Release production from 127c5290e33e",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `127c5290e33eb517835ab98c2d493ce712d5904c`\n- Artifact hash: `6c72a77f5641dcf507b87873aafafcad3d6517c6a97f112f0419f891ee58bb03`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29643728316)\n- Required label: `buildchain-release`\n- Release branch: `release/production-127c5290e33e`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-18T12:15:49Z",
          "mergedAt": "2026-07-18T12:25:11Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 120,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/120",
          "title": "fix(site): route machine entries to owning surfaces",
          "body": "## Summary\n\n- keep same-surface machine entries relative for Hub, KFD, and Papers\n- route Core and Buildchain manifest/llms alternates to the owning Hub surface\n- route the site-wide full agent index to Hub from every child surface\n- verify production, staging, and preview channel hosts in the renderer checks\n\n## Verification\n\n- `pnpm run build && pnpm run check`\n- `SITE_SURFACE_CHANNEL=staging pnpm run build && SITE_SURFACE_CHANNEL=staging pnpm run check`\n- `SITE_SURFACE_CHANNEL=preview SITE_PREVIEW_ALIAS=pr-contract-test pnpm run build && SITE_SURFACE_CHANNEL=preview SITE_PREVIEW_ALIAS=pr-contract-test pnpm run check`\n\nThis closes the machine-entry gap discovered during the open issue/PR closeout: Core and Buildchain no longer advertise same-host endpoints that return AccessDenied.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T12:38:20Z",
          "mergedAt": "2026-07-18T12:47:03Z",
          "additions": 22,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 121,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/121",
          "title": "fix(site): preserve immutable paper pages",
          "body": "## Summary\n\n- preserve the legacy relative machine-entry links inside immutable paper version pages\n- keep channel-aware canonical machine entries on mutable Core, Buildchain, KFD, Papers, and Hub pages\n- add a regression assertion for immutable archive machine-entry markup\n\n## Evidence\n\n- `pnpm run build` and `pnpm run check` pass for production, staging, and preview channels\n- all 3 generated immutable paper version HTML files match the existing staging objects byte-for-byte\n- all 3 generated immutable paper version HTML files match the existing production objects byte-for-byte\n- fixes the immutable digest mismatch in staging run 29644952629\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-18T12:55:23Z",
          "mergedAt": "2026-07-18T13:03:53Z",
          "additions": 10,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 122,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/122",
          "title": "Release production from d57250e17105",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `d57250e171051af0043ac9102e43bfc180819c3f`\n- Artifact hash: `88116bd3930b9f1c7494a23112aa487de6097c719b5a47baeb9d1d7741b6fb3f`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29645465245)\n- Required label: `buildchain-release`\n- Release branch: `release/production-d57250e17105`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-18T13:11:18Z",
          "mergedAt": "2026-07-18T13:19:02Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1382,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1382",
          "title": "fix(release): close passport and propagation gaps",
          "body": "## Summary\n\n- publish a standalone Release Passport JSON Schema and machine-readable ownership/check manifest\n- expose the contract through the Node API, npm package exports, and generated site bundle\n- make propagation PRs run consumer preparation and verification hooks, refresh managed README badges, stage the complete tree, and create DCO-signed commits\n\n## Validation\n\n- `pnpm run check`\n- live `v2.14.2` release passport validates against the new schema\n- `npm pack --dry-run --json` includes the schema, manifest, and Node API module\n\nCloses #1373.\nCloses #1380.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T13:49:57Z",
          "mergedAt": "2026-07-18T13:52:57Z",
          "additions": 934,
          "deletions": 61,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 187,
          "url": "https://github.com/kungfu-systems/kfd/pull/187",
          "title": "docs(candidates): formalize action primitive models",
          "body": "Add non-normative formal models for Atlas, Pursuit, and Warrant candidates; publish stable formal child routes in the KFD site bundle; keep all three candidates unnumbered and non-normative.\\n\\nValidation: npm run check; npm pack --dry-run --json.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T13:52:25Z",
          "mergedAt": "2026-07-18T13:56:11Z",
          "additions": 920,
          "deletions": 102,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 188,
          "url": "https://github.com/kungfu-systems/kfd/pull/188",
          "title": "chore(kfd): anchor alpha 35 release",
          "body": "Publish the KFD-7 session qualification contract through the normal alpha release path.\n\nScope:\n- anchor `@kungfu-tech/kfd@1.0.0-alpha.35`\n- retain the merged KFD-7 schema v2 and qualification theorem from PR #186\n- regenerate KFD-1/KFD-2/KFD-3 release evidence against the exact package and release anchors\n\nValidation:\n- `npm run check`\n- 7 native/WASM parity fixtures\n- 11 adversarial verifier rejections\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-18T13:57:19Z",
          "mergedAt": "2026-07-18T14:03:11Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 189,
          "url": "https://github.com/kungfu-systems/kfd/pull/189",
          "title": "release: promote 1.0.0-alpha.35 to alpha",
          "body": "Promote the current `dev/v1/v1.0` release anchor to the alpha channel.\n\nRelease: `@kungfu-tech/kfd@1.0.0-alpha.35`\nIncludes: KFD-7 session qualification theorem and schema v2 from PR #186, current action primitive candidate docs, and the regenerated KFD-1/KFD-2/KFD-3 release evidence from PR #188.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-18T14:03:35Z",
          "mergedAt": "2026-07-18T14:07:00Z",
          "additions": 1707,
          "deletions": 259,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1089,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1089",
          "title": "feat(agent-work): formalize action profile state",
          "body": "## Summary\n\nUpgrade the staged Agent Work contract to v2 with explicit role versions and state machines, a derived exact-root ActionBinding, an embedded Profile schema, and executable semantic fixtures. P17 remains not-qualified.\n\n## Validation\n\n- `./shifu check:agent-work-state-contract`\n- `./shifu docs:check`\n- `./shifu kfd:buildchain:check`\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0109\"],\n  \"summary\": \"Stage the formal Agent Work role models, derived action binding, and executable semantic fixtures without claiming P17 qualification\",\n  \"verification\": [\"Agent Work contract tests\", \"documentation contract checks\", \"Buildchain KFD checks\", \"full source acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release declaration is fail-closed: P17 remains explicitly not-qualified.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated",
          "author": "dongkeren",
          "createdAt": "2026-07-18T13:52:25Z",
          "mergedAt": "2026-07-18T14:12:47Z",
          "additions": 1411,
          "deletions": 87,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 236,
          "url": "https://github.com/kungfu-systems/build-images/pull/236",
          "title": "fix(comparator): verify relocated retained bundles",
          "body": "## Summary\n\n- verify retained Kungfu image-preparation evidence against the Compose path recorded by the producer\n- reject non-canonical or inconsistent recorded Compose paths fail-closed\n- add regression coverage for verification after moving the retained bundle to another checkout root\n\n## Validation\n\n- `pnpm run check`\n- exact retained `v1.2.4-alpha.29` Phase B bundle verified from a different checkout root\n\nCloses #235\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T14:26:08Z",
          "mergedAt": "2026-07-18T14:28:42Z",
          "additions": 166,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 237,
          "url": "https://github.com/kungfu-systems/build-images/pull/237",
          "title": "release: promote portable offline verifier to alpha",
          "body": "Promote the relocated retained-bundle verifier fix through the governed alpha channel. The subsequent version-state commit will be published by the Buildchain transaction with release passport and GitHub release enabled.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T14:30:24Z",
          "mergedAt": "2026-07-18T14:33:19Z",
          "additions": 166,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1092,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1092",
          "title": "fix(trunk): align root routing and ADR lifecycle",
          "body": "## Summary\n\n- make the Rust Trunk own root help/version and generated root-option routing before native dispatch\n- derive native help discovery from the same command table used for dispatch, including `fsck`\n- make CLI help-manifest generation mandatory in assembled products and correct stale frozen-runtime wording\n- align ADR-0046 and ADR-0071 with the shipped Trunk lifecycle while preserving their staged/partial release boundaries\n\n## Verification\n\n- `./shifu check`\n- `./shifu docs:check`\n- `cargo test --manifest-path crates/Cargo.toml -p kungfu-trunk`\n- `cargo clippy --manifest-path crates/Cargo.toml -p kungfu-trunk --all-targets -- -D warnings`\n- focused Python help-manifest tests and Project Cut exact-root review\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0046\", \"ADR-0071\"],\n  \"summary\": \"Close the Rust Trunk root-routing and native help-discovery stage while preserving staged and partial lifecycle boundaries.\",\n  \"verification\": [\n    \"./shifu check\",\n    \"./shifu docs:check\",\n    \"focused Rust and Python manifest tests\",\n    \"independent exact-root review\"\n  ]\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T14:29:39Z",
          "mergedAt": "2026-07-18T14:43:51Z",
          "additions": 658,
          "deletions": 96,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1383,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1383",
          "title": "feat(kfd): qualify KFD-7 release session profile",
          "body": "## Summary\n\nQualify the independent Buildchain KFD-7 release-transaction Profile against KFD alpha.35 while keeping activation fail-closed pending review.\n\n## Related issue\n\nAtlas goal 2026-07-18-kfd-7-engineering-contract-activation\n\n## Changes\n\n- retain an independent release-transaction Profile and exact source-bound evidence cut\n- require all twelve KFD-7 experiment categories, including session round-trip, complexity breakpoint, and context-insufficiency evidence\n- add a fail-closed missing-session-evidence test\n- regenerate the public site contract and bundled promotion action\n\n## Verification\n\n- node --test tests/kfd7-buildchain-profile.test.mjs tests/kfd7-release-gate.test.mjs\n- pnpm run check\n- KFD action-contract schema v2 validation\n- cross-repository gate against the exact Kungfu declaration: 12/12 categories and zero structural issues\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes retained qualification evidence and the release gate only; no package is published by this PR.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-18T14:29:19Z",
          "mergedAt": "2026-07-18T14:49:46Z",
          "additions": 1422,
          "deletions": 62,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1093,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1093",
          "title": "ci: pin build-images alpha.30 verifier",
          "body": "## Summary\n\n- pin the Phase B package identity and reusable workflow to build-images `v1.2.4-alpha.30` / `3056c23e70b83f5bb63062f04027a93e79039e4b`\n- refresh the closed-world workflow authority evidence\n- keep source-acceptance welded to the exact immutable consumer\n\n## Validation\n\n- `./shifu check:source`\n- workflow authority and gate catalog checks\n\nThis enables the exact-source three-platform plus Phase B rerun for kungfu-systems/build-images#235 and #995.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This is a bounded immutable dependency pin and generated workflow-authority evidence refresh; it does not change Kungfu product or architecture contracts.\"\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Exact Buildchain release passport verified\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-18T14:49:07Z",
          "mergedAt": "2026-07-18T14:59:11Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1090,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1090",
          "title": "feat(project-cut): compose concurrent publications safely",
          "body": "## Summary\n\n- add `project.cut.composition/v1` as a scoped, content-addressed N:M composition receipt for concurrent Project Cut publications\n- bind each Cut to its publication commit, semantic parents, project identity, changed paths, and exact candidate source projection without changing Project Cut v1\n- fail closed on missing receipts/parents, source drift, ambiguous overlap, evidence-only deletion, cross-project collapse, and self-consistent forged Integration Episode providers\n- reuse the Git Episode provider's canonical evidence verifier so local fsck, export, and composition admission share one schema/policy/identity boundary\n- run the scoped composition gate inside Source Acceptance and preserve explicit global history reconciliation\n\n## Final evidence\n\n- exact head: 5771d6d7e30b71eee07937fb76f2017f60e331ec\n- current queue base: 9235608bbbd53a19f6f309472216db5d4251c0b1\n- head tree: 279282e3339b971e4b959830b092a89b43260ed5\n- successor Project Cut: sha256:4cc8108e52feb34db9214e200844e2a7906a58f9ee618d44997d6854a00eb0ba\n- parent Project Cut: sha256:5866ab4b9e82cf42f2ec5e019075a1864a9034df34646321d3d8ed1f7d7e5061\n- source projection: sha256:ad885fa6faf0aa25009fb1eef53a6cb8a142ec5cbe53849ebcc9307cddfd5eac\n- Xinfa Atlas: sha256:c170b352a84c5a4901cc97ac4d1bee8eba44c154ebd4c3d4c9b0f2ac04ada776\n- Cut receipt: sha256:a0d94d1a3cbfd4565709f5aa71554db3cd7915aaecccaefd1a9ffe1b02e224c2\n- publication observation: sha256:2cd41d04462431b0989acc8c46623005b5d6c15718356563897919a902f989da\n- current-base rebased composition: sha256:90645e12f3febae4fa717d5a2ef6666076b66e7505114fd70ce652b6591b6367\n- documentation final-ready: sha256:2faf33a50bdbe5bd6fcd9d40607f96c9fe122e3c6845697cf16487024ef7509c\n\n## Validation\n\n- independent exact-head review: FIT (review-41243ba21f52bdc75704e903)\n- current-base six-commit linear rebase: three Project Cuts are qualified as bounded rebased-replay publications with no diagnostics\n- forged-provider replay: manifest, claims, qualification schema, policy source, and Episode identity mutations all remain unadmitted after full rehashing\n- composition/history/source review suite: 43/43 passed\n- Git Episode provider suite: 10/10 passed\n- direct composition/provider suite: 20/20 passed\n- full `./shifu check:source`: passed locally and on GitHub, including scoped composition admission\n- Project Cut v1 frozen contract and legacy `cut.json` compatibility: passed\n- scoped Source Acceptance composition: sha256:aaf5c93f6c246999740f71b68d5a2d88cc52c5aeea82da2090a145888e95e682 covers all three task Cuts with diagnostics=[]\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0116\"],\n  \"summary\": \"Stage merge-safe Project Cut composition with canonical Integration Episode admission\",\n  \"verification\": [\"full Source Acceptance\", \"independent exact-head review\", \"forged-provider negative replay\", \"Project Cut composition and history suites\", \"Git Episode provider suite\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T14:02:46Z",
          "mergedAt": "2026-07-18T15:35:32Z",
          "additions": 1744,
          "deletions": 58,
          "changedFiles": 51
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1096,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1096",
          "title": "feat(agent): activate KFD-7 engineering contract",
          "body": "## Summary\n\nActivate the independently qualified Kungfu KFD-7 Product Profile against KFD alpha.35 and the merged Buildchain consumer contract. This is the linear merge-queue delivery of the reviewed tree from #1091 on the current dev baseline.\n\n## Related issue\n\nAtlas goal 2026-07-18-kfd-7-engineering-contract-activation\n\n## Supersedes\n\n- #1091 retained the implementation, evidence, qualification review, and activation review but its merge-commit history could not enter the REBASE merge queue.\n- This PR is one linear commit on current `dev/v4/v4.0`; no branch history was rewritten and no protection was bypassed.\n\n## Changes\n\n- restore Fact, Episode, Warrant, Atlas, Pursuit, and Action authority across local and remote homes\n- retain twelve positive, negative, recovery, lifecycle, concurrency, and session-refinement evidence categories\n- bind the Profile to exact implementation symbols, KFD alpha.35, merged Buildchain evidence, and immutable independent reviews\n- activate the qualified Kungfu Product Profile with product-scoped non-claims\n- regenerate KFD projections on the current dev baseline\n\n## Verification\n\n- `./shifu check:agent-work-state-contract`\n- `./shifu check:source`\n- `./shifu docs:check`\n- `./shifu kfd:buildchain`\n- KFD action-contract schema v2 validation under `@kungfu-tech/kfd@1.0.0-alpha.35`\n- Buildchain cross-repository KFD-7 release gate: `passed/pass`, 12/12 evidence categories, zero issues\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0109\"],\n  \"summary\": \"Activate the independently qualified KFD-7 Product Profile with retained runtime and session-refinement evidence\",\n  \"verification\": [\"./shifu check:agent-work-state-contract\", \"./shifu check:source\", \"Buildchain cross-repository KFD-7 release gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes retained release evidence and provenance declarations; it performs no publication or deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T15:23:38Z",
          "mergedAt": "2026-07-18T16:06:59Z",
          "additions": 2951,
          "deletions": 182,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 190,
          "url": "https://github.com/kungfu-systems/kfd/pull/190",
          "title": "feat(kfd-7): activate retained engineering contracts",
          "body": "## Qualification cut\n\n- retains exact Buildchain release-transaction and Kungfu agent-work Profile coordinates\n- exports a machine-readable KFD-7 activation evidence record and human audit page\n- registers both as cross-time surfaces and includes them in package/release-candidate artifacts\n- keeps KFD-7 draft with `qualified/pending` until an independent KFD-level review is retained\n\n## Product availability\n\n- Buildchain: `f5a591fc79b84ba1b5809f2523060bcc4fd4739e`\n- Kungfu: `218e253573bf38ffde745c5b192c1d18e319f43e`\n- KFD contract: `@kungfu-tech/kfd@1.0.0-alpha.35`\n\n## Validation\n\n- `npm run update:evidence`\n- `node scripts/check.mjs`\n- `npm run check`\n- native/WASM: 7 parity fixtures, 11 adversarial rejections\n\nThis PR intentionally requires an independent review of commit `bb6f651` before the separate organization-level `active/activate` verdict is committed.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T16:08:46Z",
          "mergedAt": "2026-07-18T16:21:44Z",
          "additions": 584,
          "deletions": 298,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 191,
          "url": "https://github.com/kungfu-systems/kfd/pull/191",
          "title": "chore(kfd): anchor alpha 36 release",
          "body": "Anchors the first immutable package coordinate carrying active KFD-7.\n\n- bumps `package.json` and `kfd.release.json` to `1.0.0-alpha.36`\n- refreshes KFD-1, KFD-2, and KFD-3 package-version/hash witnesses\n- preserves the already-reviewed KFD-7 activation evidence and action-contract v2 semantics\n\nValidation: `npm run update:evidence`, `npm run check`, 7 native/WASM parity fixtures, and 11 adversarial rejections.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T16:23:28Z",
          "mergedAt": "2026-07-18T16:26:41Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 192,
          "url": "https://github.com/kungfu-systems/kfd/pull/192",
          "title": "release(kfd): promote active KFD-7 to alpha 36",
          "body": "Promotes the reviewed active KFD-7 cut and release anchor from `dev/v1/v1.0` to `alpha/v1/v1.0`.\n\nIncluded delivery evidence:\n\n- KFD activation PR #190, dev merge `bca202feb823f9c3234753b05dfd4dff460e69f6`\n- release-anchor PR #191, dev merge `fd0fb4b55cc7c2dc4a87b35c6846d0f8c3683a1b`\n- package coordinate `@kungfu-tech/kfd@1.0.0-alpha.36`\n- retained Buildchain and Kungfu product availability cuts plus KFD-level qualification/final reviews\n\nNo stable/final release claim is made; this is the immutable alpha channel artifact.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T16:26:57Z",
          "mergedAt": "2026-07-18T16:30:06Z",
          "additions": 596,
          "deletions": 310,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1103,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1103",
          "title": "chore(xinfa): record KFD-7 successor activation cut",
          "body": "## Summary\n\n- record the exact successor Project Cut from the merged KFD-7 product tree\n- retain the verified Xinfa Atlas baseline and paired KFD-3 projections\n- declare an explicit empty Episode delta; no synthetic runtime evidence is introduced\n- supersede PRs #1101 and #1102 after their fail-closed source/ADR admission results\n\n## Evidence\n\n- product implementation: PR #1096, merge `218e253573bf38ffde745c5b192c1d18e319f43e`\n- Project Cut: `sha256:7aaa18c80470ec55959ab0fa4840e7711fa7526d9444831ef172bfbd4d5bad59`\n- source projection: `sha256:048f4546fb70d41e2c5843a36d641b114061fc2b22dfc13bb0732eb920179a92`\n- Xinfa Atlas: `sha256:34e1a8c4c4137581beffeaaf30fef3ea914b44c675185269754154e9208aa95b`\n- parent Project Cut: `sha256:4cc8108e52feb34db9214e200844e2a7906a58f9ee618d44997d6854a00eb0ba`\n\n## Validation\n\n- Project Cut dry-run and execute outputs matched\n- Project Cut exact-state verification passed\n- pre-commit staged gate passed\n- DCO sign-off present\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Record content-addressed completion evidence for an already merged ADR-0109 implementation without changing architecture contracts or ADR projections\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR records retained release evidence only; it performs no publication or deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation evidence is synchronized",
          "author": "dongkeren",
          "createdAt": "2026-07-18T17:33:07Z",
          "mergedAt": "2026-07-18T17:42:35Z",
          "additions": 11,
          "deletions": 0,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1105,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1105",
          "title": "chore(xinfa): record KFD-7 final closeout cut",
          "body": "## Summary\n\n- record the final closeout successor Project Cut after KFD-7 activation evidence merged\n- bind the merged dev source tree as the sealed kickoff/documentation baseline\n- preserve the prior activation Cut as the semantic parent\n- declare an explicit empty Episode delta; no synthetic runtime evidence is introduced\n\n## Evidence\n\n- prior activation Cut merge: PR #1103, merge `7c7703c51a9291b82d76e9d5d766faaf01212c08`\n- final Project Cut: `sha256:ed89ec9a58461c841ffd13d06c322997d42efa3bc814444567da3eafa3cbef96`\n- parent Project Cut: `sha256:7aaa18c80470ec55959ab0fa4840e7711fa7526d9444831ef172bfbd4d5bad59`\n- source projection: `sha256:048f4546fb70d41e2c5843a36d641b114061fc2b22dfc13bb0732eb920179a92`\n- Xinfa Atlas: `sha256:34e1a8c4c4137581beffeaaf30fef3ea914b44c675185269754154e9208aa95b`\n\n## Validation\n\n- successor Project Cut dry-run and execute outputs matched\n- Project Cut exact-state verification passed\n- pre-commit staged gate passed\n- DCO sign-off present\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Record a content-addressed closeout successor for already merged KFD-7 activation evidence without changing architecture contracts or ADR projections\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR records retained closeout evidence only; it performs no publication or deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation evidence is synchronized",
          "author": "dongkeren",
          "createdAt": "2026-07-18T18:07:07Z",
          "mergedAt": "2026-07-18T18:24:27Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1106,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1106",
          "title": "feat(ci): attribute dev native gate latency",
          "body": "## Summary\n\n- add source- and plan-bound Buildchain diagnostics to the required native Gate artifact\n- attribute native latency to install, configure, build, and test phases, plus compact process-concurrency and cache facts\n- measure only the first successful required-context admission no later than PR merge, retaining failed retries and excluding post-merge reruns\n- preserve old artifacts as unknown attribution and keep qualification fail-closed\n\nThe current 50-PR observation remains non-qualifying: overall P50 is 155 seconds and P95 is 879 seconds; native P50 is 172 seconds and P95 is 904 seconds. This PR adds the evidence needed to diagnose the remaining tail rather than claiming the SLO is complete.\n\n## Related issue\n\nDev required Gate latency SLO qualification.\n\n## Changes\n\n- stream affected-native subprocess output without the former fixed output buffer\n- retain Buildchain JSONL spans and a diagnostics artifact bound by digest, source, plan, and Gate consumer contract\n- summarize compile process-tree samples without retaining raw process snapshots or environment dumps\n- collect and validate the new diagnostics alongside portable-cache receipts\n- report phase P50/P95, warm/cold cohorts, and requested-versus-observed build concurrency\n- document admission timing and attribution semantics\n\n## Verification\n\n- `./shifu test:gate-latency` (16/16)\n- `./shifu core:affected -- --self-test` (21/21)\n- tier-none affected-native execute and receipt verification smoke (passed)\n- `./shifu check:source` (passed; 440 Node tests passed, 8 optional platform/build-dependent skips, plus Python, type, docs, Gate, Xinfa, and Project Cut checks)\n- live 50-PR read-only measurement: overall P50 155s / P95 879s; native P50 172s / P95 904s; non-native P50 111s / P95 379s; verdict remains non-qualifying\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Add phase-level Buildchain attribution to dev Gate latency qualification without weakening admission\",\n  \"verification\": [\"./shifu test:gate-latency\", \"./shifu core:affected -- --self-test\", \"./shifu check:source\", \"live 50-PR read-only measurement\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR consumes the public Buildchain diagnostics and logging toolkit and retains bounded CI evidence. It does not change credentials, branch protection, release authority, publication workflows, or hosted-service settings.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T18:09:50Z",
          "mergedAt": "2026-07-18T18:47:03Z",
          "additions": 649,
          "deletions": 76,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1098,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1098",
          "title": "feat(xinfa): add source-bound cargo run entry",
          "body": "## Summary\n\nMake the repository Xinfa entry source-bound so every invocation uses Cargo freshness against the current checkout instead of trusting a previously built physical binary.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add `./shifu xinfa <args>` and the Windows equivalent with a controlled per-checkout Cargo target directory\n- route documentation, quality, dogfood, qualification, and consumer adapters through the source-bound entry\n- add argv, stdio, exit-code, signal, source-entry, and Windows contract coverage\n- retain physical binaries only for explicit standalone and differential oracles\n- publish the content-addressed Project Cut for the qualified source state\n\n## Verification\n\n- `./shifu test:shifu-xinfa-source`\n- `./shifu xinfa:check`\n- `./shifu xinfa:quality --check`\n- `./shifu xinfa:dogfood`\n- `./shifu xinfa:standalone`\n- `./shifu check:source`\n- documentation final-ready review: fit\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0095\"],\n  \"summary\": \"Bind Xinfa source-development execution to the current checkout while preserving its standalone and Atlas boundaries.\",\n  \"verification\": [\"Shifu source-entry tests\", \"Xinfa checks and qualifications\", \"repository source gate\", \"Project Cut independent review\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR adds content-addressed Project Cut evidence only; it does not publish a package or change deployment authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T16:01:34Z",
          "mergedAt": "2026-07-18T19:28:23Z",
          "additions": 443,
          "deletions": 67,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1107,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1107",
          "title": "feat(action): add dual-host MJS action kernel",
          "body": "## Summary\n\nBootstrap the Action primitive as one host-neutral MJS kernel with source Node execution and embedded libnode execution, while preserving one canonical JSON contract and fail-closed host boundary.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add the framework/action contract, response schema, semantic kernel, manifest, migration map, and dual-host tests\n- expose source execution through Shifu and a Python Click adapter\n- extend embedded libnode execution to return the exact process exit code\n- stage and verify the Action package in CLI and Electron product layouts\n- preserve UTF-8 key ordering, safe-integer rules, stdout isolation, and installed-path canonicalization\n\n## Verification\n\n- `./shifu test:action-kernel` (Node 8/8; Python 4/4)\n- `./shifu check:source` (Node 449 total, 448 pass / 1 skip; Python and product adapter suites pass)\n- `./shifu dist --product cli` (installed-layout smoke passed on macOS arm64)\n- final Project Cut independent review will bind the exact PR head\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0117\"],\n  \"summary\": \"Bootstrap one host-neutral Action MJS kernel across source Node and embedded libnode hosts without changing Core authority.\",\n  \"verification\": [\"Action kernel dual-host tests\", \"Python CLI adapter tests\", \"repository source gate\", \"CLI installed-layout smoke\", \"Project Cut independent review\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes product staging and introduces content-addressed Project Cut evidence, but does not publish packages or alter deployment authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-18T19:32:17Z",
          "mergedAt": "2026-07-18T20:07:17Z",
          "additions": 1144,
          "deletions": 4,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1109,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1109",
          "title": "chore(action): record parent project cut",
          "body": "## Summary\n\nRecord the parent Project Cut that reconciles the already-delivered source-bound Xinfa Cargo Run and dual-host Action MJS bootstrap as one bounded Action Primitive Kernel settlement.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add the content-addressed parent Project Cut manifest and receipt\n- bind the exact merged child cuts from PR #1098 and PR #1107\n- preserve an explicit empty Episode delta because this commit adds settlement evidence only\n\n## Verification\n\n- parent Project Cut composition gate: passed with only the parent cut in the changed set\n- parent completion Go set: exact parent plus both bounded child Go contracts\n- independent completion review: fit, with no tracked-evidence diagnostics\n- Action kernel tests: Node 8/8 and Python 4/4\n- Xinfa Cargo source-entry tests: 19/19\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This chore adds only the parent content-addressed Project Cut settlement for implementation and ADR delivery already admitted by PR #1098 and PR #1107; it does not alter an architecture contract or implementation state.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR adds content-addressed Project Cut evidence only; it does not publish a package or change deployment authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-18T20:40:51Z",
          "mergedAt": "2026-07-18T20:51:02Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1111,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1111",
          "title": "chore(action): record successor parent project cut",
          "body": "## Summary\n\nRecord the successor parent Project Cut after the Atlas baseline refresh, preserving the previously merged parent Cut as an explicit predecessor.\n\n## Changes\n\n- add successor Project Cut manifest and receipt\n- bind exact commit 3450eb1c77913a6f06ad3689ef3cea955c33fc8a\n- preserve sha256:0a3d893071da286341c47f6efe115072ec7edf426e170f082b519ee621fe1c28 as parentCutRoot\n\n## Verification\n\n- ./shifu test:action-kernel: Node 8/8, Python 4/4\n- source-bound Xinfa tests: 6/6 in the final review checkout\n- native completion review review-9d4b6d961ab270686b08c5a5: fit, no diagnostics\n- Atlas Project Cut closeout gate: ok\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This chore adds only a successor content-addressed parent Project Cut after a control-plane baseline refresh; it preserves the already merged parent Cut as an explicit predecessor and does not alter architecture contracts, product behavior, or implementation state.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR adds content-addressed Project Cut evidence only; it does not publish a package or change deployment authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-18T21:23:01Z",
          "mergedAt": "2026-07-18T21:33:07Z",
          "additions": 4,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 93,
          "url": "https://github.com/kungfu-systems/libnode/pull/93",
          "title": "chore(release): prepare libnode alpha 19",
          "body": "## Summary\n\n- advance the anchored libnode package version to `22.22.3-kf.3-alpha.19`\n- refresh the stable and alpha Buildchain floating contract locks\n- regenerate KFD-1 and KFD-3 prebuild witnesses\n\n## Validation\n\n- `corepack pnpm verify-release`\n- `corepack pnpm verify-kfd-witnesses`\n- `corepack pnpm verify-package-source`\n- `buildchain validate --require-version-state --require-lifecycle-stages install,build,verify,publish`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-18T15:30:52Z",
          "mergedAt": "2026-07-18T22:14:05Z",
          "additions": 109,
          "deletions": 19,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 94,
          "url": "https://github.com/kungfu-systems/libnode/pull/94",
          "title": "chore(release): publish libnode alpha 19",
          "body": "## Release candidate\n\nPromote the anchored libnode version `22.22.3-kf.3-alpha.19` from the active development line into the alpha channel.\n\nThis PR is the Buildchain release candidate. Its Linux x64, macOS arm64, and Windows x64 artifacts must pass verification and will be reused by post-merge promotion without rebuilding.\n\n## Source\n\n- Node: `v22.22.3`\n- Node commit: `fdfa0ff0dbaf0fbf4d7d6d89a2ab807f3177fa5c`\n- npm version: `22.22.3-kf.3-alpha.19`",
          "author": "dongkeren",
          "createdAt": "2026-07-18T22:14:43Z",
          "mergedAt": "2026-07-18T22:25:04Z",
          "additions": 215,
          "deletions": 26,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1385,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1385",
          "title": "fix(promotion): honor consumer package manager version",
          "body": "## Summary\n\n- preserve the consumer-declared `packageManager` version in exact publication planning, promote-only dependency installation, and release reconciliation\n- validate the consumer package-manager contract in the PR-stage trust gate before native release-candidate jobs start\n- add a dogfood fixture for `pnpm@11.9.0` while Buildchain itself remains on pnpm 11.7.0\n\n## Validation\n\n- `pnpm run check`\n- the validator resolves the live libnode checkout as `pnpm@11.9.0`\n- Corepack resolves pnpm 11.9.0 from the live libnode checkout\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org/`\n\nAddresses #1384.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T22:43:08Z",
          "mergedAt": "2026-07-18T22:51:36Z",
          "additions": 174,
          "deletions": 31,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1386,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1386",
          "title": "release: publish promotion contract repairs alpha",
          "body": "## Summary\n\nPromote the current reviewed v2.14 development line to the protected alpha channel. This candidate includes the consumer package-manager version fix from #1385 together with the already-merged release passport and stable-deferral classification repairs.\n\n## Evidence\n\n- PR #1385 passed Verify and the libnode-shaped macOS, Windows, and Linux fixture matrix\n- merge-group Verify run 29664156451 succeeded\n- local `pnpm run check`: 690 tests\n- `alpha/v2/v2.14` is an ancestor of `dev/v2/v2.14` with no reverse divergence\n\nThe protected promotion workflow remains responsible for selecting the next immutable alpha version, trusted npm publication, GitHub prerelease evidence, release passport closure, and floating alpha refs.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T22:52:27Z",
          "mergedAt": "2026-07-18T22:54:45Z",
          "additions": 1802,
          "deletions": 162,
          "changedFiles": 56
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1112,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1112",
          "title": "feat(trunk): deliver native maintenance diagnostics",
          "body": "## Summary\n\nAdvance ADR-0071 with native Rust trunk diagnostics while correcting ADR-0046 and ADR-0071 lifecycle and command-placement boundaries.\n\nThis linear delivery supersedes #1097. It preserves the already-reviewed implementation tree while replacing the accumulated eight-Cut replay chain with one Project Cut rooted directly on the current `dev/v4/v4.0` baseline; #1097's merge-queue candidates timed out in the 900-second Source Acceptance composition step rather than failing a semantic check.\n\n## Changes\n\n- add native `kungfu verify`, `gc-plan`, and `repair-plan` routing and help discovery\n- extend the versioned embedding ABI with plan-only storage maintenance calls\n- qualify the real Windows `kungfu_embedding.dll` bootstrap and plan paths\n- keep ADR-0071 partial and state its remaining Bucket A and measurement-gated Bucket B work\n- publish a single linear Project Cut for the final business delta\n\n## Verification\n\n- `cargo test --manifest-path crates/Cargo.toml -p kungfu-embedding` (11 passed)\n- `cargo test --manifest-path crates/Cargo.toml -p kungfu-trunk` (34 passed)\n- `cargo fmt --manifest-path crates/Cargo.toml --all -- --check`\n- `cargo clippy --manifest-path crates/Cargo.toml --workspace --all-targets -- -D warnings`\n- local Project Cut composition gate on the one-Cut linear branch\n- qualification-only #1100 run 29656415133: exact implementation tree passed macOS, Linux, and Windows; Windows job 88111510606 loaded the real DLL through `LoadLibraryA` / `GetProcAddress`, exercised ABI v4, and produced both maintenance plans across five trials\n\nLocal native membrane configuration completed, but execution was correctly blocked because the available Ninja is 1.10.2 and the repository requires at least 1.11.1; no machine-level bypass was applied.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0046\", \"ADR-0071\"],\n  \"summary\": \"Deliver the second bounded ADR-0071 diagnostic stage and correct CLI lifecycle and placement boundaries without claiming final implementation.\",\n  \"verification\": [\"Rust embedding and trunk unit tests\", \"Rust fmt and clippy\", \"Project Cut composition\", \"CI embedding.membranes Linux and Windows qualification\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-18T23:06:56Z",
          "mergedAt": "2026-07-18T23:20:49Z",
          "additions": 996,
          "deletions": 54,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1388,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1388",
          "title": "feat(promotion): add dual-channel workflow shell router",
          "body": "## Summary\n\n- turn the public release-candidate promotion workflow into a generated channel router\n- select immutable alpha or stable workflow shells, runtimes, and consumer contract locks from promotion intent\n- bind router, shell, runtime, and lock identities into controller and release-passport evidence\n- keep the advanced implementation behind a hidden reusable workflow with generated interface parity\n\n## Validation\n\n- corepack pnpm run build\n- corepack pnpm run check (698 tests)\n- git diff --check\n- node scripts/generate-channel-promotion-workflow.mjs --check\n\nRefs #1387. The issue should remain open until the new libnode alpha PR proves the live alpha lane and the stable lane has its required evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T23:34:50Z",
          "mergedAt": "2026-07-18T23:39:32Z",
          "additions": 3437,
          "deletions": 1154,
          "changedFiles": 38
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1389,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1389",
          "title": "release: publish dual-channel promotion router alpha",
          "body": "## Summary\n\nPromote the reviewed v2.14 development line containing the generated dual-channel promotion workflow-shell router and immutable route evidence.\n\n## Evidence\n\n- PR #1388 passed Verify and the libnode-shaped macOS, Windows, and Linux fixture matrix\n- merge-group Verify run 29665562292 succeeded\n- post-merge Verify run 29665606579 succeeded\n- local Buildchain check passed 698 tests and all four action bundle integrity checks\n- alpha/v2/v2.14 is an ancestor of dev/v2/v2.14\n\nThe protected promotion workflow remains responsible for selecting the next immutable alpha version, trusted npm publication, GitHub prerelease evidence, release-passport closure, and floating alpha refs.\n\nRefs #1387.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T23:40:58Z",
          "mergedAt": "2026-07-18T23:43:25Z",
          "additions": 3437,
          "deletions": 1154,
          "changedFiles": 38
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1390,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1390",
          "title": "fix(promotion): audit the selected workflow shell",
          "body": "## Summary\n\n- bind publication-authority control-plane audit to the selected advanced workflow shell\n- preserve the public workflow as the backward-compatible default for non-routed callers\n- record the same selected authority workflow path in assembled admission evidence\n\n## Failure reproduced\n\nBuildchain alpha promotion run 29665753063 failed closed because the authority audited release-candidate-promote.yml#promote after that public workflow became a router with alpha/stable jobs. The actual promote job lives in the selected hidden advanced shell.\n\n## Validation\n\n- node --test tests/build-surface.test.mjs (82 tests)\n- bash scripts/check-workflows.sh\n- corepack pnpm run check (698 tests)\n- action bundle integrity check (4 bundles)\n- git diff --check\n\nRefs #1387.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T23:50:01Z",
          "mergedAt": "2026-07-18T23:54:21Z",
          "additions": 9,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1391,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1391",
          "title": "release: retry dual-channel promotion router alpha",
          "body": "## Summary\n\nPromote the selected-shell publication-authority audit fix together with the dual-channel workflow router. This replaces the failed alpha attempt from run 29665753063; that run failed closed before publish, so 2.14.3-alpha.1 remains unpublished.\n\n## Evidence\n\n- PR #1390 passed Verify and the libnode-shaped macOS, Windows, and Linux fixture matrix\n- merge-group Verify run 29665988500 succeeded\n- local Buildchain check passed 698 tests and all four action bundle integrity checks\n- the authority now audits .release-candidate-promote.yml#promote, the selected advanced shell containing the actual publish job\n\nRefs #1387.",
          "author": "dongkeren",
          "createdAt": "2026-07-18T23:54:59Z",
          "mergedAt": "2026-07-18T23:57:33Z",
          "additions": 9,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1113,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1113",
          "title": "feat(cli): expose Action primitives through kungfu",
          "body": "## Summary\n\nFreeze `kungfu` as the only public terminal entrypoint for Action Primitive workflows. Xinfa remains independently versioned and qualified, while users and Agents reach it through `kungfu xinfa`.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add `kungfu xinfa` workspace-to-Atlas compilation and private-engine delegation\n- add Atlas, Pursuit, Warrant, and Episode role command groups over the existing profile authority\n- make `kungfu agent brief` the complete one-shot onboarding surface\n- stage and smoke-test the private Xinfa engine in the CLI distribution without a public `xinfa` launcher\n- publish ADR-0118 and rooted CLI/Xinfa product contracts\n\n## Verification\n\n- `./shifu test:action-primitive-cli`\n- `./shifu test:action-kernel`\n- `./shifu check:agent-pack`\n- `./shifu xinfa:check`\n- `./shifu xinfa:standalone`\n- `./shifu dist --product cli`\n- `./shifu docs:check:readonly`\n- `./shifu check:source`\n- Project Cut `sha256:ac90ba61f4dc86b4b4214d8994e42c11131829605efd6100a09d55a8f1885101`, empty Episode delta, exact commit observation `920b81e0a2ec1478dc9a808b78d78c5855ea8cbc`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0118\"],\n  \"summary\": \"Stage the single-entry Action Primitive CLI topology and private Xinfa engine distribution boundary.\",\n  \"verification\": [\"Action Primitive CLI tests, Xinfa standalone qualification, installed-layout distribution smoke, source acceptance, and exact Project Cut observation\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects the public CLI topology and package layout. Contract checks, installed archive smoke tests, standalone Xinfa qualification, and source acceptance bind the boundary; it does not publish a release.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-18T23:56:19Z",
          "mergedAt": "2026-07-19T00:12:51Z",
          "additions": 1176,
          "deletions": 90,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 95,
          "url": "https://github.com/kungfu-systems/libnode/pull/95",
          "title": "fix(ci): adopt promotion channel router",
          "body": "## Summary\n\n- keep one declarative release-candidate promotion declaration\n- load the new public router from Buildchain v2-alpha\n- let the router select the alpha or stable workflow shell, runtime, and contract lock\n- accept the exact Buildchain 2.14.3-alpha.1 contract and refresh the KFD-1 workflow witness\n\n## Validation\n\n- corepack pnpm verify-release\n- corepack pnpm verify-kfd-witnesses\n- corepack pnpm verify-package-source\n- actionlint .github/workflows/release-new-version.yml\n- exact v2-alpha contract-lock evaluation: unchanged / compatible\n- promotion declaration count: 1\n- git diff --check\n\nRefs kungfu-systems/buildchain#1387.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T00:07:52Z",
          "mergedAt": "2026-07-19T00:23:41Z",
          "additions": 17,
          "deletions": 11,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 96,
          "url": "https://github.com/kungfu-systems/libnode/pull/96",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.19",
          "body": "## Summary\n\n- promote the single Buildchain channel-router declaration from dev to alpha\n- select the `v2-alpha` workflow shell and runtime through the exact alpha contract lock\n- build and seal a fresh three-platform candidate for `22.22.3-kf.3-alpha.19` before merge\n- publish the sealed candidate after merge without rebuilding native artifacts\n\n## Evidence target\n\n- declaration adoption: #95\n- version is currently unpublished on npm\n- Buildchain issue: kungfu-systems/buildchain#1387\n\n## Validation\n\nThe PR Build workflow must pass Linux x64, Windows x64, and macOS ARM64 builds, artifact relay, candidate aggregation, controller evidence, and the final `build` gate before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T00:24:09Z",
          "mergedAt": "2026-07-19T00:34:30Z",
          "additions": 17,
          "deletions": 11,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1392,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1392",
          "title": "fix(promotion): bootstrap stable workflow shell",
          "body": "## Summary\n\n- keep promotion workflow-shell layout as a provider-owned generated declaration\n- call the current stable public implementation at the immutable SHA behind `v2` until stable ships the hidden advanced workflow\n- verify logical shell ref, selected checkout SHA, configured call ref, and workflow path before candidate access\n- preserve the single consumer promotion declaration and the `v2-alpha` alpha shell/runtime lane\n\n## Regression\n\nGitHub rejected libnode promotion run 29667173855 before job startup because the generated router pre-parsed `.release-candidate-promote.yml@v2`, which does not exist in the current stable tag. The stable bootstrap call now resolves the existing public workflow at `c95f9fc36b0ac8fb4ff6400189850c4ae683f3ea`, preventing the missing-workflow parse failure without moving `v2`.\n\n## Validation\n\n- `pnpm run check`\n- `node --test tests/promotion-channel-router.test.mjs`\n- `node scripts/generate-channel-promotion-workflow.mjs --check`\n- `node scripts/generate-site-bundle.mjs --check`\n- `actionlint .github/workflows/release-candidate-promote.yml`\n- `git diff --check`\n\nRefs #1387",
          "author": "dongkeren",
          "createdAt": "2026-07-19T00:44:28Z",
          "mergedAt": "2026-07-19T00:51:15Z",
          "additions": 197,
          "deletions": 35,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1393,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1393",
          "title": "chore(release): prepare v2.14.3-alpha.2",
          "body": "## Summary\n\n- bump Buildchain to `2.14.3-alpha.2`\n- carry the promotion stable-shell bootstrap fix from #1392\n- refresh deterministic site and contract bundle metadata\n\n## Validation\n\n- `pnpm run check` (699 tests)\n- generated site bundle parity\n- action bundle parity\n\nRefs #1387",
          "author": "dongkeren",
          "createdAt": "2026-07-19T00:54:53Z",
          "mergedAt": "2026-07-19T00:59:09Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1394,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1394",
          "title": "release: publish buildchain v2.14.3-alpha.2",
          "body": "## Summary\n\n- publish `@kungfu-tech/buildchain@2.14.3-alpha.2`\n- move `v2-alpha` to the promotion-router stable-shell bootstrap fix\n- unblock libnode single-declaration alpha promotion after the startup parse failure\n\n## Evidence target\n\n- implementation: #1392\n- version preparation: #1393\n- consumer failure: kungfu-systems/libnode run 29667173855\n- issue: #1387\n\nThe release workflow must reuse this PR-stage candidate, pass sealed publication authority, publish npm/GitHub prerelease evidence, and move the alpha floating refs.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T00:59:38Z",
          "mergedAt": "2026-07-19T01:01:48Z",
          "additions": 213,
          "deletions": 51,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 97,
          "url": "https://github.com/kungfu-systems/libnode/pull/97",
          "title": "fix(ci): make release promotion retryable",
          "body": "## Summary\n- add an explicit workflow_dispatch entry to the single release promotion declaration\n- accept the published Buildchain v2.14.3-alpha.2 runtime contract\n- refresh the KFD-1 workflow byte witness\n\n## Why\nGitHub does not allow rerunning an invalid-workflow run with zero jobs. A first-class dispatch trigger lets maintainers retry promotion at the exact alpha/release ref without a dummy source change, while the normal branch push remains automatic.\n\n## Validation\n- libnode KFD witnesses\n- libnode release contract\n- package source verification\n- actionlint\n- Buildchain alpha contract lock: unchanged, compatible=true, drift=false\n- exactly one Buildchain promotion declaration\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T01:13:12Z",
          "mergedAt": "2026-07-19T01:26:31Z",
          "additions": 6,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 98,
          "url": "https://github.com/kungfu-systems/libnode/pull/98",
          "title": "chore(release): promote v22.22.3-kf.3-alpha.19 candidate",
          "body": "## Summary\n- promote the current dev/v22/v22.22 source into the alpha channel\n- build and qualify a fresh macOS ARM64, Linux x64, and Windows x64 release candidate\n- publish only after the protected alpha merge, reusing the qualified PR-stage candidate\n\n## Promotion contract\n- one declarative promotion workflow\n- alpha router, shell, and runtime: v2-alpha\n- selected contract lock: buildchain.alpha-contract-lock.json\n- target package version: 22.22.3-kf.3-alpha.19\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T01:26:57Z",
          "mergedAt": "2026-07-19T01:39:15Z",
          "additions": 6,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1395,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1395",
          "title": "fix(ci): gate promotion bootstrap inputs",
          "body": "## Summary\n- declare whether each routed promotion shell accepts Buildchain internal evidence inputs\n- keep all 11 internal routing identities on the alpha advanced shell\n- omit those inputs from the pinned legacy stable bootstrap wrapper\n- regenerate the public router and contract audit digest\n\n## Root cause\nGitHub pre-parses every reusable job even when its `if` condition is false. The v2-alpha router passed new promotion identity inputs to the pinned c95 stable wrapper, which predates those inputs, so alpha consumer runs failed before creating jobs.\n\n## Validation\n- full `pnpm run check` (700 tests)\n- actionlint and workflow parity\n- generated stable inputs are a subset of the exact c95 workflow_call input set\n- alpha route forwards all 11 internal evidence inputs\n- no native build job is added to promotion\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T01:44:27Z",
          "mergedAt": "2026-07-19T01:48:34Z",
          "additions": 59,
          "deletions": 41,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1396,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1396",
          "title": "chore(release): prepare v2.14.3-alpha.3",
          "body": "## Summary\n- prepare Buildchain 2.14.3-alpha.3\n- publish the promotion bootstrap input compatibility fix through v2-alpha\n- regenerate version-bound site and contract artifacts\n\n## Validation\n- full `pnpm run check` (700 tests)\n- generated site bundle parity\n- workflow and action bundle integrity\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T01:51:13Z",
          "mergedAt": "2026-07-19T01:55:05Z",
          "additions": 14,
          "deletions": 23,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1397,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1397",
          "title": "chore(release): promote v2.14.3-alpha.3",
          "body": "## Summary\n- promote Buildchain 2.14.3-alpha.3 to the v2.14 alpha line\n- publish the promotion bootstrap input compatibility fix\n- advance v2-alpha after sealed candidate reuse and publication\n\n## Validation\n- provider fix PR #1395 passed all checks and merge-group Verify\n- version prep PR #1396 passed all checks and merge-group Verify\n- full local `pnpm run check` passed with 700 tests\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T01:55:34Z",
          "mergedAt": "2026-07-19T01:57:57Z",
          "additions": 72,
          "deletions": 63,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1398,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1398",
          "title": "fix(promotion): decouple consumer target major",
          "body": "## Summary\n\n- stop deriving the Buildchain major from a consumer-owned promotion target ref\n- keep Buildchain major selection bound to the router/runtime contract\n- cover libnode-shaped `alpha/v22/v22.22` and stable consumer targets\n\n## Failure reproduced\n\nlibnode workflow run 29669611033 selected `v2-alpha` as the router, then failed because `alpha/v22/v22.22` was incorrectly interpreted as requiring Buildchain v22.\n\n## Validation\n\n- `node --test tests/promotion-channel-router.test.mjs`\n- exact failing CLI input now resolves `shellRef=v2-alpha` and `runtimeRef=v2-alpha`\n- `pnpm run check` (701 tests; site, workflows, actionlint, and action bundles pass)\n\nRefs #1387.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T02:08:29Z",
          "mergedAt": "2026-07-19T02:12:37Z",
          "additions": 10,
          "deletions": 14,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1399,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1399",
          "title": "chore(release): prepare v2.14.3-alpha.4",
          "body": "## Summary\n\n- advance Buildchain to `2.14.3-alpha.4`\n- regenerate deterministic site and contract version state\n- carry the consumer target-major routing fix from #1398 into the next alpha\n\n## Validation\n\n- `pnpm run check` (701 tests; inventory, site, workflows, actionlint, and action bundles pass)\n\nRefs #1387.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T02:14:47Z",
          "mergedAt": "2026-07-19T02:18:53Z",
          "additions": 14,
          "deletions": 23,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1400,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1400",
          "title": "chore(release): promote v2.14.3-alpha.4",
          "body": "## Release intent\n\nPromote `dev/v2/v2.14` to `alpha/v2/v2.14` and publish Buildchain `2.14.3-alpha.4`.\n\nThis alpha contains the promotion router fix that keeps consumer target versions independent from the Buildchain major, closing the libnode `alpha/v22/v22.22` routing failure observed in run 29669611033.\n\nRefs #1387 and #1398.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T02:19:20Z",
          "mergedAt": "2026-07-19T02:21:19Z",
          "additions": 24,
          "deletions": 37,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1114,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1114",
          "title": "feat(action): define recoverable loop coordination",
          "body": "## Summary\n\nDefine the internal Action Loop v0 coordination contract and deterministic recovery planner without freezing public naming or creating a new runtime authority.\n\n## Related issue\n\nAtlas goal 2026-07-19-kungfu-action-loop-contract-recovery\n\n## Changes\n\n- define the five-role Action Loop state and adapter-port contract\n- add typed recovery, idempotency, conflict, and uncertainty behavior\n- add deterministic fixtures and fault-matrix tests\n- record ADR-0119 and exact Project Cut evidence\n- supersede the stale rebased Cut with a verified single-parent cleanup successor\n\n## Verification\n\n- `./shifu test:action-kernel`\n- `./shifu docs:check`\n- `./shifu check:source`\n- independent exact-root Project Cut review: fit\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0119\"],\n  \"summary\": \"Recover the bounded Action Loop v0 coordination contract and deterministic recovery semantics\",\n  \"verification\": [\"./shifu test:action-kernel\", \"./shifu docs:check\", \"./shifu check:source\", \"independent exact-root Project Cut review: fit\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR records public-safe Project Cut and Xinfa provenance for the exact source tree. No credentials or private payloads are included.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T00:00:34Z",
          "mergedAt": "2026-07-19T02:25:49Z",
          "additions": 1109,
          "deletions": 4,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1401,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1401",
          "title": "fix(promotion): coerce routed boolean input",
          "body": "## Summary\n- coerce the promotion router job output into a boolean before forwarding it to the advanced reusable workflow\n- regenerate the public router and site contract digest\n- add a regression test for nested reusable-workflow input typing\n\n## Evidence\n- libnode promotion runs 29670239656 and 29670409699 resolved the alpha route, then GitHub did not instantiate the nested alpha job\n- reusable workflow job outputs are strings while promotion-override-used is declared as a boolean\n- pnpm run check (702 tests)\n\nFixes the updated cross-repository promotion acceptance target in #1387.\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T02:43:47Z",
          "mergedAt": "2026-07-19T02:48:11Z",
          "additions": 21,
          "deletions": 3,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1402,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1402",
          "title": "chore(release): prepare v2.14.3-alpha.5",
          "body": "## Summary\n\n- advance Buildchain to `2.14.3-alpha.5`\n- regenerate deterministic site and contract version state\n- carry the nested reusable-workflow boolean coercion from #1401 into the next alpha\n\n## Validation\n\n- `pnpm run check` (702 tests; inventory, site, workflows, actionlint, and action bundles pass)\n\nRefs #1387.\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T02:50:50Z",
          "mergedAt": "2026-07-19T02:55:11Z",
          "additions": 14,
          "deletions": 23,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 193,
          "url": "https://github.com/kungfu-systems/kfd/pull/193",
          "title": "fix(kfd): weld formal decision status to registry",
          "body": "## Summary\n\n- correct the KFD-7 formal reference decision status after activation\n- require every numbered formal reference to declare exactly one decision status matching `registry.json`\n- refresh standards digests, site projection, and KFD-1/2/3 witnesses\n\n## Verification\n\n- `npm run check`\n- controlled negative test: changing KFD-7 formal status back to `draft` is rejected with a registry mismatch\n\n## Governance\n\n- no credential, provider, hosted-service, brand, or release-identity changes\n- no semantic change to the formal models; this repairs and welds status projection",
          "author": "dongkeren",
          "createdAt": "2026-07-19T02:41:36Z",
          "mergedAt": "2026-07-19T02:57:07Z",
          "additions": 169,
          "deletions": 135,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1403,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1403",
          "title": "chore(release): promote v2.14.3-alpha.5",
          "body": "## Summary\n\nPromote the validated `dev/v2/v2.14` state to `alpha/v2/v2.14` for the sealed `2.14.3-alpha.5` publication.\n\nThis promotion includes:\n- nested reusable-workflow boolean input coercion from #1401\n- version-state preparation from #1402\n- cross-repository libnode promotion acceptance target from #1387\n\n## Validation\n\n- #1401 and #1402 passed repository checks, libnode-shaped three-platform dogfood, dual-identity review, and native merge queue verification\n- local `pnpm run check` passed with 702 tests\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T02:55:30Z",
          "mergedAt": "2026-07-19T02:57:26Z",
          "additions": 34,
          "deletions": 25,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 195,
          "url": "https://github.com/kungfu-systems/kfd/pull/195",
          "title": "feat(governance): open KFD as an evidence-governed standard",
          "body": "## Summary\n\n- position KFD as an open, evidence-governed engineering standard rather than an internal kungfu-systems rule registry\n- separate open participation from accountable canonical stewardship in a published governance model\n- make KFD-1 through KFD-7 applicability adopter-facing while preserving kungfu-systems as founding steward and mandatory adopter\n- add structured proposal, counterevidence, adopter Profile, and PR review entry points\n- publish and weld governance surfaces through KFD-1/KFD-2/KFD-3 evidence and package exports\n\n## Foundation Revision\n\nThis is a pre-stable Foundation Revision with major/breaking decision-surface impact. Published coordinates remain immutable; the revision expands portable applicability without weakening founding adoption commitments.\n\n## Verification\n\n- npm run check\n- npm pack --dry-run --json\n- 7 native/WASM parity fixtures\n- 11 adversarial verifier rejections\n- clean offline verifier extraction\n- JSON/YAML parse checks\n- git diff --check\n\n## Review\n\nAn independent reviewer should confirm the open participation / canonical stewardship boundary, adopter-facing applicability, and Foundation Revision classification before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T03:04:59Z",
          "mergedAt": "2026-07-19T03:08:04Z",
          "additions": 1553,
          "deletions": 336,
          "changedFiles": 36
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1404,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1404",
          "title": "fix(promotion): expose anchored public plan tag",
          "body": "## Summary\n\n- preserve the internal ABV transaction tag during dry-run publication planning\n- expose `v<publishedVersion>` as the exact public publication tag\n- cover anchored/manual libnode-style version/tag divergence\n\nFixes the promotion-plan mismatch discovered while validating #1387.\n\n## Validation\n\n- `node --test tests/promote-buildchain-ref.test.mjs` (115 passed)\n- `pnpm run check` (703 passed)\n- action bundle integrity check passed\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T03:12:31Z",
          "mergedAt": "2026-07-19T03:15:40Z",
          "additions": 63,
          "deletions": 43,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1405,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1405",
          "title": "chore(release): prepare v2.14.3-alpha.6",
          "body": "## Summary\n\nPrepare `@kungfu-tech/buildchain@2.14.3-alpha.6` with the anchored public publication-plan tag fix from #1404.\n\n## Validation\n\n- `pnpm run check` (703 passed)\n- action bundle integrity check passed\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T03:17:20Z",
          "mergedAt": "2026-07-19T03:20:32Z",
          "additions": 14,
          "deletions": 23,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 197,
          "url": "https://github.com/kungfu-systems/kfd/pull/197",
          "title": "chore(kfd): anchor alpha 37 release",
          "body": "## Release anchor\n\n- advances the explicit package coordinate to `@kungfu-tech/kfd@1.0.0-alpha.37`\n- keeps `package.json`, `package-lock.json`, and `kfd.release.json` aligned\n- refreshes KFD-1, KFD-2, and KFD-3 release evidence from the updated anchor\n- makes no additional decision, schema, or governance change\n\n## Validation\n\n- `npm ci --ignore-scripts --no-audit --no-fund`\n- `npm run check`\n- 7 native/WASM parity fixtures\n- 11 adversarial rejections\n- clean offline verifier extraction\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T03:19:26Z",
          "mergedAt": "2026-07-19T03:22:40Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1406,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1406",
          "title": "chore(release): promote v2.14.3-alpha.6",
          "body": "Promote the reviewed `v2.14.3-alpha.6` release material from dev to the protected alpha channel.\n\n- feature fix: #1404\n- version preparation: #1405\n- full local check: 703 passed\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T03:20:48Z",
          "mergedAt": "2026-07-19T03:22:44Z",
          "additions": 76,
          "deletions": 65,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 199,
          "url": "https://github.com/kungfu-systems/kfd/pull/199",
          "title": "release(kfd): promote v1.0.0-alpha.37",
          "body": "Promotes the verified `dev/v1/v1.0` cut to `alpha/v1/v1.0` for immutable publication as `@kungfu-tech/kfd@1.0.0-alpha.37`.\n\nIncluded delivery changes since alpha.36:\n\n- welds every formal reference decision status to the authoritative registry\n- publishes KFD as an open, evidence-governed engineering standard with explicit governance and public participation surfaces\n- commits npm package-manager lock facts required by the current Buildchain verification path\n- advances the explicit package and release anchors to `1.0.0-alpha.37`\n- refreshes KFD-1, KFD-2, KFD-3, site, standards, and release evidence\n\nValidation:\n\n- release-anchor PR #197 passed Verify and Buildchain Build\n- exact dev merge `7c8868b83df93b1cd3cf25378d7719502f0a7883` passed push Verify run 29671670336\n- supersedes closed PR #198, which had the same source and target but was opened under the review account\n- no stable/final release claim is made\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T03:28:06Z",
          "mergedAt": "2026-07-19T03:31:14Z",
          "additions": 1660,
          "deletions": 409,
          "changedFiles": 45
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 241,
          "url": "https://github.com/kungfu-systems/build-images/pull/241",
          "title": "feat(images): add Kungfu native source builder",
          "body": "## Summary\n\n- open the additive v1.3 image-family line with `kungfu-native-linux-x64`, rooted at `kungfu-verify`\n- pin and verify GCC 14, Node 22 bootstrap, Python/uv, Conan, and Rust/Cargo 1.96 tooling with a writable arbitrary-UID HOME/cache contract\n- add an exact-digest fresh-consumer smoke for Kungfu source `d6fb3879c8f495b6b4e4a1a619ce78358291a6e1`, frozen no-optional install, exact libnode seed, build receipt, host ELF/link verification, and an explicit no-performance boundary\n- route the v1.3 alpha channel through Buildchain v2 dual-channel promotion, contract locks, complete required OCI artifacts, Release Passport, and GitHub release evidence\n\n## Verification\n\n- `pnpm run check` (90 qualification tests, KFD123, unchanged alpha/stable contract locks)\n- image build and pinned tool smoke on agent-120, rooted at `kungfu-verify@sha256:bb659d824989f0a1e7e5ecd9f1644b3b71ddce43403a72182acae38fb889c84d`\n- fresh detached d6fb source checkout and empty HOME on agent-120: `./shifu build:core` exit 0\n- host fixture: Linux x86-64 ELF, all `ldd` dependencies resolved\n- source remained clean at d6fb; no timed workload was run\n- build log: `sha256:331aa789600f20b22df097414998f4a9dad3ba2481aaada36feaf7b3e29adb64`\n- build identity: `sha256:e1e60225789dcb27c6605712b07f11b5bcbe1d0d4070fff2229b1ca7c64a95d8`\n- fixture: `sha256:78e6296c69435b07f9a6f6c8828c5178088e332dbcffad300521c798adc33f7e`\n\nRelated to #239. The issue will close after the published exact-digest consumer smoke passes.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T03:31:50Z",
          "mergedAt": "2026-07-19T03:40:41Z",
          "additions": 909,
          "deletions": 172,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 242,
          "url": "https://github.com/kungfu-systems/build-images/pull/242",
          "title": "release: promote v1.3 native Kungfu builder alpha",
          "body": "## Summary\n\n- publish the new `kungfu-native-linux-x64` image contract\n- provide exact-digest Kungfu source-build tooling and evidence receipts\n- accept the reviewed Buildchain `v2.14.3-alpha.6` contract for alpha publication\n\n## Validation\n\n- `pnpm run check`\n- candidate image smoke on Linux amd64\n- fresh Kungfu `./shifu build:core` source build with clean checkout and ELF/ldd verification\n- PR #241 checks: 30 passed, 0 failed\n\nRelated to #239.\nResolves #240 after successful alpha publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T03:41:01Z",
          "mergedAt": "2026-07-19T03:43:37Z",
          "additions": 909,
          "deletions": 172,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 99,
          "url": "https://github.com/kungfu-systems/libnode/pull/99",
          "title": "fix(ci): declare sealed publication admission",
          "body": "## Summary\n\n- enable Buildchain-managed sealed publication admission for libnode\n- explicitly declare that libnode has no separate consumer Shifu Gate registry\n- bind publisher workflow, npm target, product, and package identity\n- refresh the KFD-1 byte-for-byte workflow witness\n\nThis advances the updated #1387 validation target after promotion run 29671823329 correctly denied missing sealed evidence before artifact download and OIDC.\n\n## Validation\n\n- `pnpm run verify-kfd-witnesses`\n- `pnpm run verify-release`\n- `pnpm exec prettier --check .github/workflows/release-new-version.yml`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T03:33:49Z",
          "mergedAt": "2026-07-19T03:43:39Z",
          "additions": 8,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 243,
          "url": "https://github.com/kungfu-systems/build-images/pull/243",
          "title": "fix(release): resolve artifacts for every release line",
          "body": "## Summary\n\n- make the default-branch `workflow_run` promotion entrypoint release-line agnostic\n- always compute and pass exact OCI artifact requirements\n- always bind the release impact file\n- move the manual dry-run default to `alpha/v1/v1.3`\n\n## Failure fixed\n\nThe v1.3 alpha promotion skipped `Resolve exact required image artifacts` because GitHub loaded the workflow from the default branch, where the step was limited to `/v1.2`. The publish lifecycle then rejected the empty `BUILDCHAIN_REQUIRED_ARTIFACTS` value before any image publication.\n\n## Validation\n\n- `actionlint -color=false .github/workflows/buildchain-ref-promotion.yml`\n- `bash scripts/check-workflows.sh`\n- exact workflow parity with `dev/v1/v1.3`\n\nRelated to #239.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T03:48:37Z",
          "mergedAt": "2026-07-19T03:49:45Z",
          "additions": 5,
          "deletions": 6,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 101,
          "url": "https://github.com/kungfu-systems/libnode/pull/101",
          "title": "chore(release): admit sealed libnode alpha publication",
          "body": "Promote the reviewed sealed-publication declaration to the protected alpha channel.\n\n- implementation: #99\n- new three-platform candidate will be built and qualified on this channel PR\n- post-merge publication must reuse that exact candidate with no native rebuild\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T03:43:57Z",
          "mergedAt": "2026-07-19T03:55:33Z",
          "additions": 8,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1118,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1118",
          "title": "feat(action): add recoverable loop begin",
          "body": "## Summary\n\nAdd the Action Loop v0 begin/checkpoint/resume binding over the recovered coordinator contract, using explicit compatibility adapters and public Core Episode, Work Profile, and Fact-ref authority.\n\n## Related issue\n\nAtlas goal 2026-07-19-kungfu-action-loop-begin-resume-binding\n\n## Changes\n\n- bind explicit Pursuit, Xinfa Atlas, Warrant, Episode, and Work Profile roles into one recoverable envelope\n- checkpoint the accepted bound prefix before Episode mutation and classify uncertain external effects deterministically\n- bridge Node coordination through public Python Core adapters for KFD-7 Work Profile, RuntimeEpisodeLifecycle, and Fact-ref CAS\n- recover a loop in a fresh process from only the durable loop ref\n- update ADR-0119, Action package hashes, and exact Project Cut evidence\n\n## Verification\n\n- `./shifu test:action-kernel` (25/25 Node, 4/4 Python, native cross-process test included)\n- `./shifu check`\n- `./shifu check:source` (449 contract tests; Python type baseline 164 files)\n- fresh independent review worktree: `./shifu build:core` and `./shifu test:action-kernel`, no skips\n- independent exact-root Project Cut review: fit\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0119\"],\n  \"summary\": \"Deliver recoverable Action Loop begin, checkpoint, and resume bindings over public Core authority\",\n  \"verification\": [\"./shifu test:action-kernel\", \"./shifu check\", \"./shifu check:source\", \"fresh independent Core build and native cross-process test\", \"independent exact-root Project Cut review: fit\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR records public-safe Project Cut and Xinfa provenance for the exact source tree. Runtime mutations use public Core adapters; no credentials or private payloads are included.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T03:49:13Z",
          "mergedAt": "2026-07-19T04:05:55Z",
          "additions": 1714,
          "deletions": 19,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1407,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1407",
          "title": "fix(publication): audit merged PR head checks",
          "body": "## Summary\n- audit required status checks on the exact merged PR head rather than the final merge commit\n- keep the final publication source bound to the protected branch head\n- record and verify the required-check SHA against the merged PR head SHA\n\n## Validation\n- live libnode reproduction: all six publication control-plane facts pass\n- pnpm run check (703/703 unit tests; action bundle integrity passed)\n\nRefs kungfu-systems/libnode#100",
          "author": "dongkeren",
          "createdAt": "2026-07-19T04:06:15Z",
          "mergedAt": "2026-07-19T04:10:29Z",
          "additions": 24,
          "deletions": 4,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 202,
          "url": "https://github.com/kungfu-systems/kfd/pull/202",
          "title": "docs(kfd): define continuity under uncertainty",
          "body": "## Summary\n- distinguish the KFD standard from its canonical repository and state its general continuity scope\n- connect ordinary action/feedback with hard-case Primitive discovery in the Foundation Model\n- align active KFD-7 status, live-case evidence boundaries, generated site bundle, and machine drift checks\n\n## Verification\n- `npm run update:evidence`\n- `npm run check`\n- `npm pack --dry-run`\n- Markdown local-link scan: 51 files\n- `git diff --check`\n\n## Review boundary\nKFD remains a small, falsifiable engineering foundation. The change does not add a numbered decision, claim a complete theory of continuity, or qualify Pursuit/Warrant as Primitives.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T04:09:57Z",
          "mergedAt": "2026-07-19T04:14:43Z",
          "additions": 502,
          "deletions": 271,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1408,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1408",
          "title": "chore(release): prepare v2.14.3-alpha.7",
          "body": "## Summary\n- prepare Buildchain 2.14.3-alpha.7\n- include the merged-PR-head publication audit fix from #1407\n\n## Validation\n- pnpm run check (703/703 unit tests; action bundle integrity passed)",
          "author": "dongkeren",
          "createdAt": "2026-07-19T04:12:09Z",
          "mergedAt": "2026-07-19T04:16:20Z",
          "additions": 14,
          "deletions": 23,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1409,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1409",
          "title": "chore(release): promote v2.14.3-alpha.7",
          "body": "## Summary\n- promote the qualified dev/v2/v2.14 state to alpha/v2/v2.14\n- publish @kungfu-tech/buildchain@2.14.3-alpha.7 after merge\n\n## Evidence\n- release preparation PR #1408\n- publication audit fix PR #1407\n- merge queue verification run 29673019583",
          "author": "dongkeren",
          "createdAt": "2026-07-19T04:17:24Z",
          "mergedAt": "2026-07-19T04:19:58Z",
          "additions": 37,
          "deletions": 26,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 125,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/125",
          "title": "feat(kfd): render continuity framing",
          "body": "## Summary\n- render KFD core question, engineering answer, and claim boundary in the hero\n- preserve compatibility with the existing `pastToFuture` and `kungfuPath` bundle fields\n- prevent duplicate `future-picture` rendering and add regression checks\n\n## Verification\n- `pnpm run build`\n- `pnpm run check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-19T04:09:56Z",
          "mergedAt": "2026-07-19T04:22:28Z",
          "additions": 76,
          "deletions": 8,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 244,
          "url": "https://github.com/kungfu-systems/build-images/pull/244",
          "title": "chore(images): accept v1.3.0 alpha.0 digests",
          "body": "## Summary\n\n- accept the complete `v1.3.0-alpha.0` Release Passport image family as the reviewed `images.lock.json` baseline\n- bind the updated lock into generated KFD-1/KFD-2 evidence\n- retire the `kungfu-native-linux-x64` first-publish marker after its immutable GHCR digest was published\n\n## Evidence\n\n- Release: https://github.com/kungfu-systems/build-images/releases/tag/v1.3.0-alpha.0\n- Publish run: https://github.com/kungfu-systems/build-images/actions/runs/29672438882\n- New image: `ghcr.io/kungfu-systems/build-images/kungfu-native-linux-x64@sha256:4bca43fda6c2e97a4766f45738b1034da48d02c5a82652b3c72364d7ac0b697b`\n- Parent: `sha256:dec36c59aa9a8131bf1b226f99cd8beb2117043643e025beba37fa567fc62786`\n\n## Validation\n\n- `corepack pnpm run check`\n- 90 comparator tests passed\n- KFD123 passed with unchanged alpha/stable contract locks\n- provenance planner recognizes commit `c68be6b` as a reviewed image-lock acceptance\n\nThe marker retirement remains a separate commit, matching the established first-publish lifecycle. It changes `image.toml`, so a future alpha promotion continues to fail closed under the documented manifest-global-invalidator policy.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T04:35:41Z",
          "mergedAt": "2026-07-19T04:38:28Z",
          "additions": 123,
          "deletions": 103,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 102,
          "url": "https://github.com/kungfu-systems/libnode/pull/102",
          "title": "chore(buildchain): accept alpha contract",
          "body": "## Summary\n- accept Buildchain v2-alpha at 180b64ae9a592ab35612e6847c3b7fb5c72f0042\n- update the reviewed runtime contract digest to sha256:bc4af5da2c40571f978cb16aa25370c0ffbbd08b3187c60844ebe58339f3ccae\n- preserve the major-compatible compatibility digest\n\n## Validation\n- exact contract lock check: unchanged, compatible\n- pnpm run verify-kfd-witnesses\n- pnpm run verify-release\n\nFixes #100",
          "author": "dongkeren",
          "createdAt": "2026-07-19T04:28:02Z",
          "mergedAt": "2026-07-19T04:42:52Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 246,
          "url": "https://github.com/kungfu-systems/build-images/pull/246",
          "title": "chore(buildchain): accept v2.14.3 alpha.7 contract",
          "body": "## Summary\n\n- upgrade the alpha Buildchain package from `2.14.3-alpha.6` to `2.14.3-alpha.7`\n- accept the current `v2-alpha` runtime SHA and contract digest reported by #245\n- regenerate KFD-2 aggregate/claims and the KFD123 summary from the installed package\n\n## Contract review\n\n- runtime SHA: `180b64ae9a592ab35612e6847c3b7fb5c72f0042`\n- contract: `sha256:bc4af5da2c40571f978cb16aa25370c0ffbbd08b3187c60844ebe58339f3ccae`\n- compatibility: `sha256:edc3653e5cb34efd97065a6941db16140bbf375a565bbcf329d9d795bb07676f`\n- compatibility status: compatible; the breaking digest is unchanged\n- upstream change: publication control-plane audit now checks merged PR head checks\n\nCloses #245.\n\n## Validation\n\n- `corepack pnpm run check`\n- 90 comparator tests passed\n- KFD123 passed\n- alpha and stable contract locks both report unchanged/no drift\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T04:47:28Z",
          "mergedAt": "2026-07-19T04:50:17Z",
          "additions": 19,
          "deletions": 19,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 103,
          "url": "https://github.com/kungfu-systems/libnode/pull/103",
          "title": "chore(release): promote Buildchain alpha contract",
          "body": "## Summary\n- promote the reviewed Buildchain v2-alpha contract lock into alpha/v22/v22.22\n- build and qualify a fresh three-platform release candidate for 22.22.3-kf.3-alpha.19\n- reuse that exact candidate in post-merge promotion without native rebuild\n\n## Evidence\n- contract acceptance PR #102\n- Buildchain publication audit fix kungfu-systems/buildchain#1407\n- Buildchain alpha.7 release kungfu-systems/buildchain#1409",
          "author": "dongkeren",
          "createdAt": "2026-07-19T04:43:11Z",
          "mergedAt": "2026-07-19T04:56:14Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 203,
          "url": "https://github.com/kungfu-systems/kfd/pull/203",
          "title": "chore(kfd): anchor alpha 38 release",
          "body": "## Summary\n\n- anchor `@kungfu-tech/kfd` at `1.0.0-alpha.38`\n- refresh KFD-1, KFD-2, and KFD-3 release evidence\n- prepare the continuity-under-uncertainty documentation update for Buildchain alpha promotion\n\n## Verification\n\n- `npm ci --ignore-scripts --no-audit --no-fund`\n- `npm run check`\n\n## Release boundary\n\nThis PR only establishes the explicit release fact on `dev/v1/v1.0`. Publication still requires the protected `dev/v1/v1.0 -> alpha/v1/v1.0` promotion PR, alpha Verify success, and Buildchain Ref Promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T04:58:07Z",
          "mergedAt": "2026-07-19T05:01:21Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 205,
          "url": "https://github.com/kungfu-systems/kfd/pull/205",
          "title": "release(kfd): promote v1.0.0-alpha.38",
          "body": "## Release anchor\n\n- Source release PR: #203\n- Verified dev SHA: `9cdc4c7c693a146554d7c199f07cee8d9c7af391`\n- Dev Verify: https://github.com/kungfu-systems/kfd/actions/runs/29674203352\n- Target package: `@kungfu-tech/kfd@1.0.0-alpha.38`\n\nBuildchain publication remains gated by the successful Verify run on the resulting `alpha/v1/v1.0` merge commit.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T05:04:12Z",
          "mergedAt": "2026-07-19T05:06:58Z",
          "additions": 516,
          "deletions": 285,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1411,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1411",
          "title": "fix(promotion): verify merged PR head checks",
          "body": "Fixes #1410. Verifies provider-enforced required checks on the merged pull request head SHA while retaining target-branch, same-repository PR, independent approval, exact check context, and configured app constraints. Fails closed when the PR head SHA is missing and rebuilds the action bundle. Validation: targeted tests 115/115; full check 703/703; 4 action bundles.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T05:05:30Z",
          "mergedAt": "2026-07-19T05:09:26Z",
          "additions": 56,
          "deletions": 44,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1412,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1412",
          "title": "chore(release): prepare v2.14.3-alpha.8",
          "body": "Prepare Buildchain 2.14.3-alpha.8 with provider-transaction PR-head check evidence from #1411. Compatibility digest remains unchanged. Validation: pnpm run check (703/703; 4 action bundles).",
          "author": "kungfu-origin",
          "createdAt": "2026-07-19T05:12:41Z",
          "mergedAt": "2026-07-19T05:16:41Z",
          "additions": 21,
          "deletions": 23,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1413,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1413",
          "title": "chore(release): promote v2.14.3-alpha.8",
          "body": "Promote the verified dev/v2/v2.14 state containing Buildchain 2.14.3-alpha.8 and the provider-transaction PR-head check fix. Dev push Verify: https://github.com/kungfu-systems/buildchain/actions/runs/29674600688",
          "author": "kungfu-origin",
          "createdAt": "2026-07-19T05:18:18Z",
          "mergedAt": "2026-07-19T05:20:35Z",
          "additions": 77,
          "deletions": 67,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1120,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1120",
          "title": "feat(action): add recoverable loop settlement",
          "body": "## Summary\n\nAdd the recoverable Action Loop v0 settlement bridge so a durable loop can seal its Episode, refresh successor Atlas/Fact authority, publish and independently review a completion claim, and finish KFD-7 transitions without treating process exit as completion.\n\n## Related issue\n\nAtlas goal 2026-07-19-kungfu-action-loop-settlement-bridge\n\n## Changes\n\n- add an idempotent settlement coordinator with durable prefix checkpoints and fresh-process recovery\n- seal the runtime Episode and bridge completion claim, independent review, and continuation decision through Mission Control\n- close Pursuit and Warrant through explicit final KFD-7 transitions with stale-ref CAS refusal\n- preserve completed prefixes across crashes and safely retry after partial external writes\n- update ADR-0119, Action contract/package hashes, docs, MAP, and exact Project Cut evidence\n\n## Verification\n\n- `node --test framework/action/action-loop-settle.test.mjs` (5/5)\n- `./shifu test:action-kernel` (30/30 Node, 4/4 Python)\n- `./shifu check:source` (449 Node contract tests; Ruff/Mypy baseline 164 files)\n- `./shifu check`\n- fresh `./shifu build:core` before native cross-process validation\n- independent exact-root Project Cut review: fit at `5dd342083c84c571bc12d2f525b2d648475552d2`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0119\"],\n  \"summary\": \"Deliver recoverable Action Loop settlement over Episode, Xinfa, Mission Control, and KFD-7 authority\",\n  \"verification\": [\"node --test framework/action/action-loop-settle.test.mjs\", \"./shifu test:action-kernel\", \"./shifu check:source\", \"./shifu check\", \"fresh ./shifu build:core\", \"independent exact-root Project Cut review: fit\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR records public-safe Project Cut/Xinfa provenance for the exact source tree. Runtime settlement uses public Core and Mission Control adapters; no credentials or private payloads are included.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T05:16:49Z",
          "mergedAt": "2026-07-19T05:31:33Z",
          "additions": 1668,
          "deletions": 16,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 247,
          "url": "https://github.com/kungfu-systems/build-images/pull/247",
          "title": "chore(buildchain): accept v2.14.3 alpha.8 contract",
          "body": "## Summary\n\n- update the alpha Buildchain package from `2.14.3-alpha.7` to `2.14.3-alpha.8`\n- accept the current `v2-alpha` runtime SHA and exact contract digest\n- refresh KFD-2 upstream evidence and the KFD123 summary\n\nThe compatibility digest remains unchanged, so this is compatible drift. No image source, manifest, or publish input changes.\n\n## Verification\n\n- `corepack pnpm run check`\n- 90 unit tests passed\n- KFD123 passed with `alphaContractDrift=false`\n- alpha contract digest: `sha256:81c7c3721fa796b8d4585b0d8495822e405dd1e68b3a31db55934d4bf5687997`\n- compatibility digest: `sha256:edc3653e5cb34efd97065a6941db16140bbf375a565bbcf329d9d795bb07676f`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T05:31:10Z",
          "mergedAt": "2026-07-19T05:34:17Z",
          "additions": 19,
          "deletions": 19,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 104,
          "url": "https://github.com/kungfu-systems/libnode/pull/104",
          "title": "chore(buildchain): accept alpha.8 contract",
          "body": "## Summary\n- accept the published Buildchain `v2-alpha` material at `v2.14.3-alpha.8`\n- preserve the existing `major-compatible` compatibility boundary\n- unblock a fresh libnode alpha candidate on the corrected publication runtime\n\n## Validation\n- exact Buildchain contract-lock check\n- `pnpm run verify-kfd-witnesses`\n- `pnpm run verify-release`",
          "author": "dongkeren",
          "createdAt": "2026-07-19T05:29:17Z",
          "mergedAt": "2026-07-19T05:39:10Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 105,
          "url": "https://github.com/kungfu-systems/libnode/pull/105",
          "title": "release: promote v22.22 dev to alpha",
          "body": "## Summary\n- promote the latest `dev/v22/v22.22` state to the alpha candidate lane\n- rebuild all platform artifacts against Buildchain `v2.14.3-alpha.8`\n- publish only after the sealed candidate and provider transaction gates pass\n\n## Validation\n- Buildchain channel candidate workflow\n- macOS ARM64, Linux x64, Windows x64 artifacts\n- release verification and sealed publication admission",
          "author": "dongkeren",
          "createdAt": "2026-07-19T05:39:32Z",
          "mergedAt": "2026-07-19T05:49:47Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 207,
          "url": "https://github.com/kungfu-systems/kfd/pull/207",
          "title": "fix(build): refresh Buildchain alpha contract",
          "body": "## Summary\n\n- accept the current `v2-alpha` runtime contract at `8270576a1a37d3d8464a10ddeff5c9da450cc22e`\n- preserve the existing `major-compatible` compatibility digest\n- regenerate the KFD-1, KFD-2, and KFD-3 evidence that binds the lock bytes\n\n## Verification\n\n- Buildchain contract evaluator: `unchanged`, compatible, no issue required\n- `npm run check`\n- `git diff --check`\n\nCloses #206.\nCloses #204.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T06:14:20Z",
          "mergedAt": "2026-07-19T06:17:53Z",
          "additions": 14,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1121,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1121",
          "title": "docs(core): freeze KFD-7 library boundary",
          "body": "## Summary\n\n- freeze the shipped KFD-7 library and consumer ABI boundary\n- define the planned successor-ABI contract without claiming it is shipped\n- keep legacy bootstrap exports and libyijinjing source/static-only\n- publish a clean Project Cut rebased onto the latest protected-channel head\n\nThis clean delivery supersedes #1119 after its merge-group qualification correctly detected Project Cut source drift behind #1120. PRs #1117 and #1119 remain the forward-only audit history; this branch contains only the product commits, sealed Episode, and a new single-root Cut for the latest base.\n\n## Validation\n\n- exact affected-native qualification on the product series: 111 build targets and 16/16 CTest passed\n- PR #1119 exact-head checks: 11/11 successful before merge queue\n- merge queue source-drift diagnosis: expected source projection changed to 2f8feee028d2d83fa6c33d78abee6718d6a9b06e857f4a7d4f594bfa34e74bee after #1120\n- clean v2 scoped composition gate: ok=true, Cut 637ce2c848e642501144b7dbcfaf1f15aa6c3d10be3d3f3a9ab7edac386062e9, diagnostics=[]\n- Episode dd831a8d fsck and git-workspace evidence verification: ok=true\n\n## Dependency boundary\n\nThe native foundation, canonical Root encoding, and kernel decomposition goals remain paused external dependencies. This PR defines their ABI boundary and does not implement or claim those provider roots.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0120\"],\n  \"summary\": \"Freeze the KFD-7 library ownership and successor ABI boundary without implementing or shipping the successor surface\",\n  \"verification\": [\"Shifu source acceptance\", \"agent-120 affected-native 16/16 CTest\", \"frozen old-consumer ABI v4 fixture\", \"Project Cut composition and exact-commit observation\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-19T06:03:29Z",
          "mergedAt": "2026-07-19T06:37:35Z",
          "additions": 715,
          "deletions": 5,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1124,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1124",
          "title": "feat(action): qualify source action loop dogfood",
          "body": "## Summary\n\nQualify the recoverable Action Loop against the real Kungfu source runtime, native Episode authority, successor Xinfa Atlas, exact-root Project Cut closure, and fresh-process/idempotent settlement recovery.\n\n## Related issue\n\nAtlas goal 2026-07-19-kungfu-action-loop-source-dogfood-qualification\n\n## Changes\n\n- add a qualification-only source Action Loop harness with human/JSON parity\n- exercise real begin, Episode seal, successor Atlas refresh, native completion review, final Fact settlement, fresh-process resume, and idempotent duplicate settle\n- preserve uint64 Episode identities losslessly across the Git Episode provider and Project Cut CLI\n- reject non-native completion executor profiles in the source harness\n- update ADR-0119 implementation evidence and commit exact Episode, Xinfa, and Project Cut artifacts\n\n## Verification\n\n- `node --test framework/action/action-loop-begin.test.mjs framework/action/action-loop-settle.test.mjs framework/action/action-loop-source-dogfood.test.mjs` (18/18)\n- `node --test scripts/check-project-cut-settlement.test.mjs scripts/check-git-episode-provider.test.mjs scripts/check-project-cut-composition.test.mjs`\n- `./shifu check:source` (451 tests: 450 pass, 1 skip, plus target source gates)\n- commit staged gates passed on every task/Project Cut commit\n- real Action Loop settled at Fact ref revision 10; fresh-process resume and duplicate settle returned `already-settled` with no write\n- independent exact-root Project Cut review: fit at `b1447e70633b28af427b955861773225c6bd9ad9`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0119\"],\n  \"summary\": \"Qualify the recoverable Action Loop end to end against native source authority and exact-root Project Cut closure\",\n  \"verification\": [\"18/18 Action Loop tests\", \"Project Cut and Git Episode provider tests\", \"./shifu check:source\", \"real fresh-process and idempotent source settlement\", \"independent exact-root Project Cut review: fit\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR adds public-safe qualification and exact-root provenance only. Runtime journals and private machine state are not committed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T07:32:48Z",
          "mergedAt": "2026-07-19T07:49:31Z",
          "additions": 10163,
          "deletions": 16,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1127,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1127",
          "title": "chore(project-cut): aggregate action loop closure",
          "body": "## Summary\n\nAggregate the four completed Action Loop source-dogfood child goals into one exact-root parent Project Cut and native Completion Claim.\n\n## Related issue\n\nAtlas goal 2026-07-19-kungfu-action-loop-source-dogfood-closure\n\n## Changes\n\n- add the aggregate parent Project Cut rooted at `sha256:ccbc1ab82e4b032177c81893c7c50849cd640adcbc454e4a8d272ae04f0343f6`\n- bind the exact merged Action Loop source projection and successor Xinfa Atlas\n- declare an explicit empty Episode delta because all implementation evidence is already sealed by the four child cuts\n\n## Verification\n\n- Project Cut prepare dry-run and execute produced the same exact root\n- commit observation bound the cut to `bbedb4165a8bc56d8dbede844d68a04f203d9272`\n- independent exact-root completion review returned `fit`\n- commit gates passed through source, architecture, KFD-7, documentation, and staged checks; the two generated JSON files passed direct Biome validation\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Aggregate already-delivered Action Loop evidence into a parent Project Cut without changing an architecture contract\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR adds only public-safe, content-addressed aggregate provenance. Runtime journals and private machine state are not committed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T08:13:22Z",
          "mergedAt": "2026-07-19T08:23:31Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 123,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/123",
          "title": "chore: consume KFD release",
          "body": "Buildchain release propagation from @kungfu-tech/kfd into the kfd.libkungfu.dev site surface.\n\nBuildchain release propagation plan:\n\n```json\n{\n  \"schemaVersion\": 1,\n  \"contract\": \"kungfu-buildchain-release-propagation-plan\",\n  \"source\": \"kfd\",\n  \"upstreamRelease\": {\n    \"repository\": \"kungfu-systems/kfd\",\n    \"channel\": \"alpha\",\n    \"tag\": \"v1.0.0-alpha.38\",\n    \"sourceSha\": \"b8502f8d14472762ebe3b42e571778adc4ab9c1e\",\n    \"package\": {\n      \"name\": \"@kungfu-tech/kfd\",\n      \"version\": \"1.0.0-alpha.38\",\n      \"integrity\": \"sha512-OBKBHZ5xJ0ogG5JfKRNKzfN2OWc5Fj7DFdTUD4B0OXBuHUXXIXCfo5Qc8f6VMk5/MVLeh12SvS8a7shFp6IEwg==\"\n    },\n    \"releasePassport\": {\n      \"url\": \"https://github.com/kungfu-systems/kfd/releases/download/v1.0.0-alpha.38/buildchain.release.json\",\n      \"sha256\": \"04a554991d7142916fc4400e6683cf8519591773744f83c9d90a43228679ee60\"\n    }\n  },\n  \"targets\": [\n    {\n      \"edge\": \"kfd-to-site-libkungfu-dev\",\n      \"source\": \"kfd\",\n      \"target\": \"site-libkungfu-dev\",\n      \"repository\": \"kungfu-systems/site-libkungfu-dev\",\n      \"channel\": \"alpha\",\n      \"baseRef\": \"main\",\n      \"lockPath\": \"buildchain.upstreams/kfd.release.json\",\n      \"lock\": {\n        \"schemaVersion\": 1,\n        \"contract\": \"kungfu-buildchain-release-propagation-lock\",\n        \"upstream\": {\n          \"node\": \"kfd\",\n          \"repository\": \"kungfu-systems/kfd\",\n          \"channel\": \"alpha\",\n          \"tag\": \"v1.0.0-alpha.38\",\n          \"sourceSha\": \"b8502f8d14472762ebe3b42e571778adc4ab9c1e\",\n          \"package\": {\n            \"name\": \"@kungfu-tech/kfd\",\n            \"version\": \"1.0.0-alpha.38\",\n            \"integrity\": \"sha512-OBKBHZ5xJ0ogG5JfKRNKzfN2OWc5Fj7DFdTUD4B0OXBuHUXXIXCfo5Qc8f6VMk5/MVLeh12SvS8a7shFp6IEwg==\"\n          },\n          \"releasePassport\": {\n            \"url\": \"https://github.com/kungfu-systems/kfd/releases/download/v1.0.0-alpha.38/buildchain.release.json\",\n            \"sha256\": \"04a554991d7142916fc4400e6683cf8519591773744f83c9d90a43228679ee60\"\n          }\n        },\n        \"downstream\": {\n          \"node\": \"site-libkungfu-dev\",\n          \"repository\": \"kungfu-systems/site-libkungfu-dev\",\n          \"channel\": \"alpha\",\n          \"baseRef\": \"main\",\n          \"lockPath\": \"buildchain.upstreams/kfd.release.json\"\n        },\n        \"propagation\": {\n          \"graphContract\": \"kungfu-buildchain-release-propagation-graph\",\n          \"edge\": \"kfd-to-site-libkungfu-dev\",\n          \"channelPolicy\": \"preserve\",\n          \"channelMap\": {\n            \"alpha\": \"alpha\",\n            \"release\": \"release\"\n          },\n          \"exact\": true,\n          \"floatingTags\": false\n        },\n        \"lockSha256\": \"3e25a8131685660ea3ae864fa94a0cafa2861581c6962fab37533375b83d08e7\"\n      }\n    }\n  ],\n  \"summary\": {\n    \"targetCount\": 1,\n    \"channels\": [\n      \"alpha\"\n    ],\n    \"repositories\": [\n      \"kungfu-systems/site-libkungfu-dev\"\n    ]\n  }\n}\n```\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-19T03:38:53Z",
          "mergedAt": "2026-07-19T08:43:10Z",
          "additions": 270,
          "deletions": 24,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1125,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1125",
          "title": "feat(cli): add native storage status",
          "body": "## Summary\n\nDeliver the next ADR-0071 Bucket A slice: native, read-only storage status through the Rust Trunk and embedding ABI v5, without CPython or target-runtime mutation.\n\n## Related issue\n\nADR-0071\n\n## Changes\n\n- add the bounded `storage-status` Trunk command and native embedding call\n- extend the prefix-compatible embedding table to ABI v5\n- preserve target-runtime contents by using a disposable embedding context root\n- qualify the real shared membrane and pin its managed Ninja environment\n- update ADR-0071 with the delivered stage and remaining Bucket A work\n\n## Verification\n\n- `./shifu fix`\n- `./shifu check`\n- `./shifu build`\n- `./shifu qualify:embedding-membranes`\n- assembled `kungfu-trunk storage-status --json` smoke with before/after target-directory comparison\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0071\"],\n  \"summary\": \"Deliver native read-only storage status through embedding ABI v5 and the Rust Trunk.\",\n  \"verification\": [\"./shifu check\", \"./shifu build\", \"./shifu qualify:embedding-membranes\", \"assembled kungfu-trunk storage-status smoke\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe Project Cut artifacts bind the implementation snapshot to its input Atlas and exact commit. The Project Cut qualification and commit-observation checks passed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T07:49:29Z",
          "mergedAt": "2026-07-19T09:01:26Z",
          "additions": 709,
          "deletions": 43,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 128,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/128",
          "title": "fix(site): preserve immutable paper pages",
          "body": "## Summary\n\n- scope KFD future-picture typography to the KFD homepage\n- keep shared page CSS byte-stable for published paper archive pages\n- reject KFD-only hero styles in immutable publication HTML\n\n## Verification\n\n- `pnpm run build`\n- `pnpm run check`\n- all three generated immutable paper version pages match staging byte-for-byte\n- KFD hero computed typography is unchanged\n- KFD foundation code line starts remain aligned\n\n## Failure repaired\n\nMain staging runs 29680298829 and 29680303136 correctly rejected an immutable digest mismatch. The generated `kfd-foundation-real-world-agent-work/v0.1.0-alpha.7/index.html` now restores the published SHA-256 `62400cb160e80ca7047ed2913e28d43c3d6995a34b4408a3e89e39d397b9166e`.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T08:53:09Z",
          "mergedAt": "2026-07-19T09:02:42Z",
          "additions": 11,
          "deletions": 15,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1130,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1130",
          "title": "docs: simplify the first-use README",
          "body": "## Summary\n\nMake the root README a concise CLI-first entry for new agent users while preserving the complete system model in a canonical second-level concept page.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- lead with context pressure, durable continuity, and the intended `kungfu run agent` first-release experience\n- state explicitly that the command is a qualification target, not an already published artifact\n- move the Episode, architecture, layer, and Xinfa overview to `docs/concepts/system-overview.md`\n- wire the new concept page into the documentation guide, map, concept index, and metadata registry\n- retain the repository and installed Agent discovery pointers required by the documentation contract\n\n## Verification\n\n- `./shifu docs:check`\n- `./shifu docs:prose:required`\n- `./shifu check:source`\n- `./shifu docs final-ready --since origin/dev/v4/v4.0 --budget 66560 --json` (`review-required`, no violations, parity matched)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Documentation-only restructuring preserves existing architecture contracts and release claims\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-19T09:09:53Z",
          "mergedAt": "2026-07-19T09:21:16Z",
          "additions": 236,
          "deletions": 150,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 129,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/129",
          "title": "Release production from 5943d52f1cb8",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `5943d52f1cb8286c8a41834afb762e87f02477a8`\n- Artifact hash: `65374ada065b05b10f93ce21cc087c2812b66a0e8717fb5bedd41eb6341d84c2`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29680881059)\n- Required label: `buildchain-release`\n- Release branch: `release/production-5943d52f1cb8`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-19T09:12:18Z",
          "mergedAt": "2026-07-19T09:46:05Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1132,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1132",
          "title": "feat(core): qualify generic fact kernel",
          "body": "## Summary\n\nDeliver the generic Fact identity, immutable version, typed relation, Fact Cut, named ref/CAS, recovery, Profile shadow, backend switch, and three-process dogfood qualification program on the exact current v4 base.\n\nThis linear replacement supersedes PR #1131 after its clean CI install exposed stale generated KFD dependency fingerprints. It carries the corrected KFD evidence and publishes one final root Cut against the exact queue base. The retained evidence supports `continue-shadow`; it does not authorize the P17 authority cutover.\n\n## Related issue\n\nAtlas Go `2026-07-18-kungfu-generic-fact-kernel`.\n\n## Changes\n\n- add the native generic Fact Cut/query/ref kernel and integrity/portability checks\n- add Profile shadow projection and atomic backend-switch qualification\n- add a filesystem-only three-process dogfood workload with explicit fault cases\n- batch Project Cut source/index projection reads and skip payload reads for excluded inputs\n- bind PR #1132 into ADR-0109 and refresh generated KFD evidence\n- publish one merge-queue-compatible root Project Cut\n\n## Verification\n\n- `./shifu test:fact-kernel-dogfood` — 1 passed\n- `./shifu test:fact-kernel-integrity` — 4 passed\n- `./shifu test:fact-profile-shadow` — 3 passed\n- `./shifu check:fact-cut-kernel-contract` — 7 passed\n- `./shifu check:agent-work-state-contract` — 5 Node + 33 Python passed\n- Project Cut settlement/composition tests — 20 passed\n- `./shifu kfd:buildchain:check`\n- `./shifu kfd2:claims:check`\n- `./shifu check:source` — passed; 452 source-acceptance tests (451 passed, 1 skipped)\n\n## Project Cut evidence\n\n- root Cut: `sha256:84bda1f8adfb9ea705f23e7f064fa8b9e312c95f44684131db3c4ed012987a3f`\n- Cut receipt: `sha256:e0994fda1c469f513d72feaf0c62725827e3ee7725e7086de7d3774c2a347e79`\n- source projection: `sha256:ffea3ea278853013047f2bc326f93e73bfd913b285ac90762d0d2e5f1a3dd261`\n- Cut publication commit: `5738fba4f17eac5d6a399e47a196915a82071bb8`\n- final HEAD: `1e800a4a22ab9009e4aae03130fec6bca4a90e90` (same tree as the Cut publication commit)\n- composition root: `sha256:6fc283fa9139ca5d924fffa5b5f4d719c6af77e1e4f12945adef29ae58b155d2`\n- Completion Claim: `completion-02b5fd413906bf663a19bba4`\n- independent review: `review-33bc13e9eb22d6a2ea198d9a` (`fit`, tracked diagnostics empty)\n- continuation decision: `decision-710709f1b3d6b3736407d0b9` (`close`)\n- parent and all seven direct child Go records included; Episode delta explicitly empty\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0109\"],\n  \"summary\": \"Stage the generic Fact kernel and bounded four-object Profile shadow qualification without authorizing P17 cutover\",\n  \"verification\": [\"Fact kernel dogfood, integrity, Profile shadow, KFD buildchain, source acceptance, and Project Cut closeout passed\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR adds content-addressed Project Cut/Xinfa qualification evidence only; it does not publish a package or perform a deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T10:21:20Z",
          "mergedAt": "2026-07-19T11:29:07Z",
          "additions": 2588,
          "deletions": 119,
          "changedFiles": 41
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 249,
          "url": "https://github.com/kungfu-systems/build-images/pull/249",
          "title": "feat(comparator): add formal performance runner",
          "body": "## Summary\n\n- publish a digest-bound `comparator-formal-runner` image with frozen 666-sample full-stack and Kungfu/Aeron schedules\n- add the fixed host provider, cgroup-v2 accounting, matched Aeron/Kungfu drivers, offline preparation, and fail-closed bundle verifier\n- preserve measurement-only authority, separate crash replay from whole-root restore, and keep `winner_authority=false`\n\n## Validation\n\n- `pnpm run check` (99 comparator tests plus Buildchain/KFD/contract-lock checks)\n- local linux/amd64 image build and `/opt/formal-performance/tests/smoke.sh`\n- agent-120 production-provider samples for PostgreSQL, ClickHouse, Aeron and Kungfu\n- agent-120 matched coverage for visible, durable-group, durable-sync, and recovery/whole-root paths\n\nPart of #248. The issue remains open until the published alpha digest completes the full 666-sample consumer run and offline verification.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T11:29:35Z",
          "mergedAt": "2026-07-19T11:36:46Z",
          "additions": 4689,
          "deletions": 127,
          "changedFiles": 38
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 250,
          "url": "https://github.com/kungfu-systems/build-images/pull/250",
          "title": "release: promote v1.3.0-alpha.1",
          "body": "## Release candidate\n\nPromote the reviewed #248 formal-performance runner from `dev/v1/v1.3` to the Buildchain alpha channel.\n\nBuildchain must publish:\n\n- exact repository tag `v1.3.0-alpha.1`\n- immutable `comparator-formal-runner` GHCR digest\n- Release Passport and publish evidence\n- GitHub Release with the governed evidence assets\n\nThe issue remains open until agent-120 prepares a fresh consumer from the published digest, completes all 666 preregistered samples without retry, and the offline verifier accepts the retained bundle.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T11:37:07Z",
          "mergedAt": "2026-07-19T11:40:42Z",
          "additions": 4818,
          "deletions": 236,
          "changedFiles": 45
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 252,
          "url": "https://github.com/kungfu-systems/build-images/pull/252",
          "title": "fix(comparator): normalize retained image digests",
          "body": "## Summary\n\n- normalize exact tagged image references to Docker canonical `repository@digest` form before checking `RepoDigests`\n- preserve fail-closed digest equality for all frozen inputs\n- cover tagged Docker Hub refs, registry ports, and already-canonical GHCR refs\n- advance the immutable prerelease version to `1.3.0-alpha.2`\n\n## Live failure reproduced\n\nFresh agent-120 preparation pulled `postgres:18.4-bookworm@sha256:d9c834...`; Docker retained the same digest as `postgres@sha256:d9c834...`. No scored sample ran.\n\n## Verification\n\n- targeted formal-performance tests: 10 passed\n- `pnpm run check`: 100 passed; KFD123 and both Buildchain contract locks pass",
          "author": "dongkeren",
          "createdAt": "2026-07-19T12:05:03Z",
          "mergedAt": "2026-07-19T12:08:01Z",
          "additions": 38,
          "deletions": 3,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1128,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1128",
          "title": "feat(ci): partition affected native gate",
          "body": "## Summary\n\nPartition the development affected-native required gate into two deterministic GitHub-hosted Linux workers behind one stable required-check aggregator, so a cold cohort can complete within the development latency budget without reserving self-hosted capacity.\n\n## Related issue\n\nAtlas goal `2026-07-18-kungfu-dev-cold-cohort-prewarm-closure`\n\nProvider follow-up: `2026-07-19-buildchain-portable-cache-promotion-primitive`\n\n## Changes\n\n- split the authoritative affected-native target and test plan into two deterministic, disjoint, complete partitions\n- bind compiler cache identity, execution receipts, diagnostics, coverage, and artifacts to the exact partition contract\n- retain the stable `affected-native / linux` required context through a fail-closed aggregator\n- aggregate all partition evidence in the latency collector and reject missing, overlapping, drifting, or source-mismatched cohorts\n- keep dependency cache writes single-owner and preserve the existing single-partition compatibility path\n- document the partitioned workflow authority and Gate binding\n\n## Verification\n\n- `./shifu test:gate-latency` (18/18)\n- `./shifu core:affected -- --self-test` (23 fixtures)\n- `./shifu check:gate-catalog` (38 gates, 6 profiles, 18 structured invocations, 17 closed-world workflows)\n- source, documentation, runtime, work-state, type, and formatting checks passed; one platform check is intentionally skipped on the local host\n- commit staged gates passed for implementation and Project Cut publication\n- Rebased root Project Cut `sha256:1d956ccf77c20f661a7ac3b90b4309cadb8bb706911ac9b28e808db93182251b` is the sole PR-local active Cut and was observed at final head `879874d843e7dd82e0c5e1032479e092f3783567` against dev baseline `43bc15ce10b2705501c1be50a55183bea3b456df`\n- Local scoped composition passed with root `sha256:34e227b008f7ecaf942dc9a1f66a4ddb7cb1cf471cbb05842f58639386937d64`, one changed Cut, and no diagnostics; Source Acceptance must repeat this on the exact merge group with no bypass\n- GitHub Actions run `29681765756` proved a compiler-cold two-shard required cohort in `480s` queue-inclusive; both compiler receipts recorded a qualified cold fallback and the stable aggregator passed\n\nThe trusted cross-run cache promotion path remains blocked by the current provider contract: GitHub pull-request cache scope cannot publish a default-branch scope, and no portable archive/promotion admission primitive exists yet. This delivery therefore proves the security-equivalent cold required path first; the provider primitive is tracked separately.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Partition the affected-native required gate into a fail-closed, source-bound cold cohort under one stable required context\",\n  \"verification\": [\"./shifu test:gate-latency\", \"./shifu core:affected -- --self-test\", \"./shifu check:gate-catalog\", \"./shifu check:source\", \"exact Project Cut observation\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe workflow remains on GitHub-hosted runners, does not add permissions, tokens, privileged untrusted execution, or self-hosted capacity, and keeps all required admission evidence source- and partition-bound.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-19T08:35:39Z",
          "mergedAt": "2026-07-19T12:16:22Z",
          "additions": 870,
          "deletions": 87,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1116,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1116",
          "title": "refactor(core): decompose Fact kernel internals",
          "body": "## Summary\n\nDecompose the Fact kernel implementation into explicit internal protocol, state, commit/action, query, and portability authority boundaries while preserving the public JSON edge and legacy semantics.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- keep `run_fact_kernel_operation()` as a thin stable facade\n- centralize Root/identity protocol, Fold/state reconstruction, commit coordination, and the static Action registry in single owners\n- remove Authority Import recursion through the public dispatcher and execute mutation batches under one writer fence\n- add behavior characterization, portable Fact Root fixtures, focused boundary tests, and architecture dependency ratchets\n- record the exact Xinfa Atlas and Project Cut for the published implementation head\n\n## Verification\n\n- `./shifu rebuild -j2`\n- `./shifu test:fact-kernel-native`\n- `./shifu check:fact-kernel-boundary`\n- `./shifu check:fact-root-canonical`\n- `./shifu check:fact-cut-kernel-contract`\n- `./shifu core:architecture`\n- `./shifu check:source`\n- staged pre-commit gates, DCO, exact-head Project Cut observation, and independent native completion reviews\n\n## Exact Project Cut evidence\n\n- source head: `02dae4e95f3c0f58d2484d52315959fbdab09608`\n- Xinfa Atlas: `sha256:abc91d603a2fe0ff3facf427adf478c74b5238f1b98a6a366d69dcff13ca9f3a`\n- Project Cut: `sha256:c497a41595103d5f470add27e48c37e994d93a6c43fa27d9c46e7bb06e5d45ee`\n- source projection: `sha256:64e46f9f7b4a042e1bc7e93bb733f7809a39a69ef13e223d18b3d6de6de4317d`\n- Cut receipt: `sha256:ef348847f2aeeeafb0147fc237f6f65cef18365c78fb0831ecf4dee92ecf3591`\n- commit-observation receipt: `sha256:72505db1004aa3821acc46f6bc5b52fa24b3105d9c1f391b1737dfe0960dfda6`\n- parent child-reconciliation: `sha256:609e38a9b0530d2cd21267d214c63d1686d7503d8f2a26c86c612522c8999f67`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0112\", \"ADR-0121\"],\n  \"summary\": \"Decompose Fact kernel internals behind one stable public semantic authority boundary\",\n  \"verification\": [\n    \"Fact kernel native characterization\",\n    \"portable Fact Root canonical fixtures\",\n    \"architecture boundary ratchets\",\n    \"exact-head Project Cut and independent native review\"\n  ]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T02:26:17Z",
          "mergedAt": "2026-07-19T12:50:41Z",
          "additions": 3626,
          "deletions": 1564,
          "changedFiles": 51
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 254,
          "url": "https://github.com/kungfu-systems/build-images/pull/254",
          "title": "fix(native): avoid self-replacing Cargo registry",
          "body": "## Summary\n\n- leave `KF_LIBWASM_CARGO_REGISTRY` empty by default so Cargo uses crates.io directly\n- preserve explicit distinct sparse mirror overrides\n- assert the image default in its smoke contract\n\n## Validation\n\n- `pnpm run check` (100 tests)\n- `bash -n` for the changed shell contracts\n- `git diff --check`\n\nThis fixes the fresh formal-performance preparation failure discovered while qualifying #248: Cargo rejected crates.io as its own `replace-with` source.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T12:46:19Z",
          "mergedAt": "2026-07-19T12:56:39Z",
          "additions": 6,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 253,
          "url": "https://github.com/kungfu-systems/build-images/pull/253",
          "title": "chore(release): promote v1.3.0-alpha.2",
          "body": "## Summary\n\nPromote the Docker RepoDigests normalization fix and `1.3.0-alpha.2` version state through the Buildchain v2 alpha channel.\n\n## Gate\n\n- PR #252 merged after independent review and all required checks\n- tagged image digest equality remains fail-closed\n- agent-120 fresh preparation prototype must complete before this PR is merged\n- Release Passport and GitHub release remain enabled by the standard dual-channel configuration",
          "author": "dongkeren",
          "createdAt": "2026-07-19T12:08:20Z",
          "mergedAt": "2026-07-19T12:59:48Z",
          "additions": 44,
          "deletions": 5,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 255,
          "url": "https://github.com/kungfu-systems/build-images/pull/255",
          "title": "chore(images): accept v1.3.0 alpha.2 lock",
          "body": "## Summary\n\n- accept the reviewed `v1.3.0-alpha.2` image family from Buildchain run 29688129149\n- bind all nine published image digests and provenance records in `images.lock.json`\n- remove the formal runner's first-publish marker after its public digest and smoke evidence were accepted\n- refresh KFD-1 and KFD-2 generated evidence for the accepted lock\n\n## Validation\n\n- `python3 scripts/verify-image-lock.py`\n- `pnpm run check`\n- `git diff --check`\n\n## Release evidence\n\n- https://github.com/kungfu-systems/build-images/actions/runs/29688129149\n- https://github.com/kungfu-systems/build-images/releases/tag/v1.3.0-alpha.2\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T13:17:56Z",
          "mergedAt": "2026-07-19T13:20:52Z",
          "additions": 126,
          "deletions": 106,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1135,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1135",
          "title": "feat(action): harden native authority loop",
          "body": "## Summary\n\nHarden the recoverable Action Loop so its source dogfood entry proves and preserves one exact native authority across begin, resume, Atlas refresh, independent review, and settlement.\n\nThis replaces #1134 after `dev/v4/v4.0` advanced; the implementation was rebased and its Project Cut was rebuilt against the current linear parent.\n\n## Related issue\n\nAtlas goal `2026-07-19-kungfu-action-loop-native-authority-hardening`.\n\n## Changes\n\n- bind the loaded source-build `pykungfu` artifact and active Mission Control Profile into one deterministic native authority root\n- fail closed before writes when the native binding or Profile root drifts\n- return rooted Mission Control write receipts with lossless Episode identities and payload hashes\n- make same-root first Atlas refresh valid while keeping exact replay idempotent and conflicting replay rejected\n- load the checked-out Python adapter before generated build copies while retaining the source-built native extension\n- add a dedicated Action Loop native-authority gate and one exact linear Project Cut successor\n\n## Verification\n\n- `./shifu check:source` — build-free source gate passed\n- `./shifu test:action-loop-native-authority` — 17/17 Node plus targeted Python passed\n- `./shifu test:action-kernel` — 37/37 Node and 4/4 Python passed\n- `./shifu test:agent-review-continuation` — 27/27 Node plus targeted Python passed\n- `./shifu check` — changed-scope gate passed\n- Project Cut composition gate — only changed Cut `sha256:aa1284759c68c14e554ddd231f737eac2519bf59e88ebe03873cbb11de276367`, diagnostics empty\n- real native Action Loop settled at Fact revision 10; exact duplicate settle returned `already-settled` with `writeOccurred=false`\n- Completion Claim binds exact observed commit `da1dc7fc198a80d3a9c2333f9dc9d858e575e18d`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0104\", \"ADR-0119\"],\n  \"summary\": \"Harden Action Loop source execution around exact native Mission Control authority and idempotent rooted settlement\",\n  \"verification\": [\"native-authority gate\", \"Action Kernel and continuation tests\", \"./shifu check:source\", \"./shifu check\", \"real settled and duplicate-no-write source dogfood\", \"exact-root Project Cut Completion Claim\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR records public-safe Xinfa and Project Cut provenance only. Runtime journals and private machine state remain untracked.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T13:32:12Z",
          "mergedAt": "2026-07-19T13:56:40Z",
          "additions": 886,
          "deletions": 40,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1414,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1414",
          "title": "fix(build): support legacy stable validator fallback",
          "body": "## Summary\n- prefer the selected Buildchain runtime package-manager validator when available\n- fall back to the selected workflow-shell validator when a stable runtime predates that script\n- preserve fail-closed behavior when neither validator exists\n\n## Evidence\n- reproduces the stable self-dogfood failure in run 29676190032\n- `node --test tests/build-surface.test.mjs` (82/82)\n- `pnpm run check` (703/703)\n- contract compatibility digest remains unchanged\n\nRefs #1384",
          "author": "dongkeren",
          "createdAt": "2026-07-19T14:02:10Z",
          "mergedAt": "2026-07-19T14:06:12Z",
          "additions": 19,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1115,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1115",
          "title": "feat(storage): define portable Fact Root encoding",
          "body": "## Summary\n\nDefine KFR2, an implementation-independent canonical encoding for portable Kungfu Fact roots, and qualify native C++ against an independent Python implementation.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- specify canonical scalar, collection, map, and schema-bound record encodings with stable rejection codes\n- add accepted and rejected cross-language vectors, including integer boundaries, signed zero, Unicode preservation, malformed UTF-8, duplicate keys, and schema drift\n- expose read-only native `canonical-root` computation and bind the contract into the Fact Cut capability surface\n- run the independent Python oracle directly through the platform interpreter, without requiring `uv` in source-only CI\n- allow the affected-native cold-cache closure up to 40 minutes after an observed 25-minute workflow cancellation during dependency setup and compilation\n- preserve historical Integration Cut validity when a later successor advances the source projection\n- publish ADR-0121, KFD witnesses, Xinfa Atlas material, and the exact Project Cut\n\n## Verification\n\n- `./shifu check:fact-root-canonical`\n- `./shifu check:fact-cut-kernel-contract`\n- `KUNGFU_REQUIRE_NATIVE=1 KUNGFU_DIR=framework/core/dist/kungfu ./shifu --filter @kungfu-tech/core test:storage-binding`\n- `./shifu core:affected`\n- `./shifu build:core`\n- `./shifu kfd:buildchain:check`\n- `./shifu check:source`\n- cold focused measurement run `29685836483`, job `88189806624`: `source.acceptance` passed in `1,639,045 ms` at immutable source `1edae0d8b1c0fbbabdd2df7f16093eb3de6259bf`\n- final scoped composition root: `sha256:31c28ea0647d4bc59144bac8f32f41367534880a0e392e976c78ceea5092b6ed`, one active leaf, no conflicts or diagnostics\n- final successor Project Cut `sha256:bad9f430e973a3dfd49ae3886debe66fce5f8070fc23c231f22753e5dbcbb220`, observed at merge-queue-compatible linear head `86e7ea222269d5974c2cf4b700a32ac4c4911e94`, with mainline Fact kernel Cut `sha256:c497a41595103d5f470add27e48c37e994d93a6c43fa27d9c46e7bb06e5d45ee` as its parent\n- Project Cut independent review `review-4ccd1a1c2eaa881294400bfd`: `fit`, trust root `sha256:ac5945236237f1104d522dd6007665c10ef6c75a110d84cac8d676a47b94873d`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0121\"],\n  \"summary\": \"Stage KFR2 canonical Fact Root encoding and cross-language conformance as a bounded development delivery\",\n  \"verification\": [\"check:fact-root-canonical\", \"native storage binding parity\", \"check:source\", \"Project Cut independent review fit\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR adds public KFD/Xinfa/Project Cut evidence only. It does not add credentials or perform a release or deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T01:08:13Z",
          "mergedAt": "2026-07-19T14:07:32Z",
          "additions": 310,
          "deletions": 25,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 256,
          "url": "https://github.com/kungfu-systems/build-images/pull/256",
          "title": "fix(comparator): harden formal sample cleanup",
          "body": "## Summary\n\n- tolerate the expected cgroup removal window while crash/restore tiers replace containers\n- terminate and reap the adapter process group when cgroup sampling fails\n- retain driver logs, raw cgroup samples, adapter failure artifacts, and a cleanup receipt\n- fall back to project-label cleanup and fail closed if any container, network, or volume remains\n- preserve the primary sample failure when cleanup also fails\n\n## Runtime finding\n\nThe first exact-image formal run for #248 failed closed at schedule index 7. The retained PostgreSQL crash-recovery adapter receipts show all ten fixed commands completed successfully; the failure occurred during post-process cgroup sampling and the old cleanup path masked that primary error.\n\nA non-scored agent-120 diagnostic replay of index 7 with this patch passed with 182 cgroup samples, positive CPU/RSS measurements, and zero retained containers, networks, or volumes.\n\n## Verification\n\n- `pnpm run check` (103 comparator tests)\n- targeted formal-performance suite (13 tests)\n- non-scored exact-input diagnostic replay of schedule index 7\n\nCloses no issue by itself; #248 still requires a new published exact runner and a complete 666-sample retained bundle.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T14:05:40Z",
          "mergedAt": "2026-07-19T14:08:34Z",
          "additions": 294,
          "deletions": 75,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1415,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1415",
          "title": "chore(release): prepare v2.14.3-alpha.9",
          "body": "## Summary\n- prepare Buildchain 2.14.3-alpha.9\n- declare the stable-runtime package-manager validator fallback as a patch workflow-contract impact\n- regenerate the deterministic site bundle\n\n## Validation\n- pnpm run check\n- git diff --check\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T14:08:24Z",
          "mergedAt": "2026-07-19T14:12:52Z",
          "additions": 21,
          "deletions": 23,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 257,
          "url": "https://github.com/kungfu-systems/build-images/pull/257",
          "title": "chore(release): prepare v1.3.0-alpha.3",
          "body": "## Summary\n\nPrepare `v1.3.0-alpha.3` after the formal-performance cleanup fix in #256.\n\nThis is a version-only release binding. The Buildchain selective planner remains authoritative for build/reuse decisions; the resulting exact runner digest will be used for the complete #248 formal schedule.\n\n## Verification\n\n- `pnpm run check`\n- 103 comparator tests\n- KFD-1/2/3 checks and alpha/stable contract locks unchanged\n- Release Passport smoke passed",
          "author": "dongkeren",
          "createdAt": "2026-07-19T14:10:14Z",
          "mergedAt": "2026-07-19T14:13:16Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1416,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1416",
          "title": "chore(release): promote v2.14.3-alpha.9",
          "body": "## Summary\n- promote the verified v2.14 dev head to the alpha channel\n- publish Buildchain 2.14.3-alpha.9 through the sealed Ref Promotion transaction\n- carry the legacy stable-runtime package-manager validator fallback into v2-alpha\n\n## Source evidence\n- release PR #1415 merged through the dev merge queue\n- merge-group Verify passed\n- PR Build Surface Fixture passed on macOS, Linux container, and Windows\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T14:13:18Z",
          "mergedAt": "2026-07-19T14:15:26Z",
          "additions": 39,
          "deletions": 27,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 258,
          "url": "https://github.com/kungfu-systems/build-images/pull/258",
          "title": "chore(release): promote v1.3.0-alpha.3",
          "body": "## Promotion\n\nPromote reviewed `dev/v1/v1.3` to the alpha channel for `v1.3.0-alpha.3`.\n\nIncluded since alpha.2:\n\n- accepted alpha.2 image lock and retired the formal-runner first-publish marker\n- formal-performance process/cgroup lifecycle and cleanup hardening from #256\n- version and release-impact binding for alpha.3\n\nA successful protected alpha Verify run will trigger the governed Buildchain `@v2-alpha` publish transaction with Release Passport and GitHub Release enabled. The resulting exact runner digest remains subject to the complete 666-sample #248 acceptance run.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T14:13:42Z",
          "mergedAt": "2026-07-19T14:16:42Z",
          "additions": 422,
          "deletions": 183,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1417,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1417",
          "title": "Release v2.14.3 from qualified v2.14.3-alpha.9",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.3-alpha.9`\n- Candidate SHA: `701cca28a5bf9fe6dcf49c26097572bbe5f39a8b`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T14:28:31Z",
          "mergedAt": "2026-07-19T14:33:01Z",
          "additions": 5437,
          "deletions": 1236,
          "changedFiles": 85
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1418,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1418",
          "title": "fix(patrol): reconcile stable source-lock ancestry",
          "body": "## Summary\n\n- reconcile a qualified alpha candidate with a divergent stable release branch before opening the source-lock PR\n- create a non-forced, exact-candidate-tree commit whose parents preserve both candidate and stable ancestry\n- reuse an already reconciled source-lock idempotently and fail closed if its tree or candidate lineage changes\n\n## Why\n\nThe v2.14.3 stable source-lock PR was conflict-free only after a manual exact-tree two-parent commit. Patrol should own that deterministic reconciliation instead of requiring an ad-hoc operator repair.\n\n## Validation\n\n- `node --test tests/stable-candidate-patrol.test.mjs` (9/9)\n- `pnpm run check` (705/705)\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T15:01:00Z",
          "mergedAt": "2026-07-19T15:04:02Z",
          "additions": 128,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1419,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1419",
          "title": "chore(release): prepare v2.14.3-alpha.10",
          "body": "## Summary\n\n- prepare Buildchain `v2.14.3-alpha.10`\n- publish the stable Patrol exact-tree ancestry reconciliation from #1418\n- regenerate the public site and contract evidence for the exact version\n\n## Validation\n\n- `pnpm run check` (705/705)\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T15:06:11Z",
          "mergedAt": "2026-07-19T15:09:24Z",
          "additions": 21,
          "deletions": 23,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 106,
          "url": "https://github.com/kungfu-systems/libnode/pull/106",
          "title": "chore(buildchain): accept v2.14.3 channel contracts",
          "body": "## Summary\n\n- accept the published Buildchain `v2.14.3` stable runtime at `565354f7b8abdbd68576468c04bfbcfc57d267e2`\n- accept `v2.14.3-alpha.9` on the alpha channel at `701cca28a5bf9fe6dcf49c26097572bbe5f39a8b`, resolving #107\n- record the new advanced release-candidate promotion surface and updated controller digests\n- preserve the existing `pnpm@11.9.0` consumer contract\n\n## Evidence\n\n- local stable contract check: compatible=true, drift=false\n- local alpha contract check: compatible=true, drift=false\n- stable and alpha promotion planner/validator blobs are byte-identical at the accepted revisions\n- Buildchain alpha self-dogfood, exact-candidate fixture, libnode canary, and stable sealed promotion all passed\n- local pnpm install used the package/noop path and did not rebuild native sources\n\nCloses #107\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T14:47:39Z",
          "mergedAt": "2026-07-19T15:10:17Z",
          "additions": 14,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1420,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1420",
          "title": "chore(release): promote v2.14.3-alpha.10",
          "body": "## Summary\n\nPromote the reviewed `v2.14.3-alpha.10` dev line to the protected alpha channel.\n\n- Patrol exact-tree source-lock ancestry reconciliation merged in #1418\n- release preparation merged in #1419 through the native merge queue\n- Verify and Build Surface Fixture passed\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T15:12:43Z",
          "mergedAt": "2026-07-19T15:13:53Z",
          "additions": 149,
          "deletions": 29,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1421,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1421",
          "title": "fix(dogfood): refresh stable and alpha contract locks",
          "body": "## Summary\n- accept the currently published stable v2 contract world\n- accept the alpha.10 v2-alpha contract world\n- keep the self-dogfood assertion aligned with the reviewed alpha lock\n\n## Validation\n- node --test --test-name-pattern=\"Buildchain self-dogfoods the current major alpha\" tests/build-surface.test.mjs\n- pnpm run check (705/705)\n- git diff --check\n\nSigned-off-by: Codex <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T15:27:05Z",
          "mergedAt": "2026-07-19T15:30:10Z",
          "additions": 59,
          "deletions": 9,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1422,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1422",
          "title": "chore(release): prepare v2.14.3-alpha.11",
          "body": "## Summary\n- prepare @kungfu-tech/buildchain 2.14.3-alpha.11\n- publish reviewed stable and alpha self-dogfood contract lock acceptance\n- regenerate the public site contract for the prerelease\n\n## Validation\n- pnpm run generate:site\n- pnpm run check (705/705)\n- git diff --check\n\nSigned-off-by: Codex <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T15:33:01Z",
          "mergedAt": "2026-07-19T15:36:20Z",
          "additions": 21,
          "deletions": 23,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1423,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1423",
          "title": "chore(release): promote v2.14.3-alpha.11",
          "body": "## Promotion\nPromote the reviewed `dev/v2/v2.14` release candidate to `alpha/v2/v2.14` for sealed publication of `@kungfu-tech/buildchain@2.14.3-alpha.11`.\n\n## Evidence\n- release preparation: #1422\n- local validation: 705/705\n- native merge queue verification passed\n\nSigned-off-by: Codex <[email-redacted]>",
          "author": "kungfu-origin",
          "createdAt": "2026-07-19T15:37:09Z",
          "mergedAt": "2026-07-19T15:38:17Z",
          "additions": 80,
          "deletions": 32,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1137,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1137",
          "title": "feat(cli): add versioned surface contract registry",
          "body": "## Summary\n\nAdd a versioned, machine-readable contract for the complete live Kungfu CLI surface and fold Core, System KFX, Profile KFX, and product-assembly metadata into one validated registry.\n\n## Related issue\n\nAtlas goal `2026-07-19-kungfu-cli-surface-contract-registry`.\n\n## Changes\n\n- inventory every live Click family and leaf with stable ids and canonical paths\n- freeze ownership, audience, maturity, visibility, section, aliases, KFD-3 API bindings, mutation/approval policy, schemas, and availability\n- fold explicit System/Profile KFX contribution rows without claiming that metadata activates runtime capabilities\n- expose the complete inventory through `kungfu contract surface --json`\n- reject orphan commands, duplicate ownership/path claims, alias cycles, dangling KFD-3/schema references, unknown mutation classes, and unqualified availability\n- verify Click topology, Action topology, Agent catalog parity, stable identity, and unavailable KFX projections\n- publish an explicit empty-Episode Project Cut successor for the exact implementation head\n\n## Verification\n\n- `KUNGFU_NATIVE_PATH='/Applications/Kungfu Episodes.app/Contents/Resources/kungfu' ./shifu test:cli-surface-contract` — 13 passed\n- `./shifu check:source` — build-free source gate passed; mypy passed for 168 source files\n- `./shifu check` — changed-scope gate passed\n- `./shifu docs:check` — deterministic documentation gate passed after the ADR-0091 projection update\n- commit hooks passed for implementation and settlement commits\n- Project Cut `sha256:5dacdcf95c9ff69d5e69b13b25723934ebbdc51da52d36c5bef171921ea4605e` has an explicit empty Episode delta and a published observation at `20b260726b83665018bd4f8992d145e84bf27ae5`\n- Completion Claim `completion-e75b3918c775f3e3270bef5c` binds the exact observed head with no known gaps; the ADR documentation obligation remains review-required until independent review\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0091\"],\n  \"summary\": \"Freeze the complete CLI surface and KFX contribution fold as one versioned, parity-checked contract\",\n  \"verification\": [\"CLI surface contract tests\", \"negative and live parity fixtures\", \"./shifu check:source\", \"./shifu check\", \"exact-root Project Cut Completion Claim\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR classifies CLI and KFD-3 linkage metadata and publishes public-safe Xinfa/Project Cut provenance. It does not activate KFX contributions, change provider execution authority, or track runtime journals/private machine state.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T15:15:32Z",
          "mergedAt": "2026-07-19T15:49:17Z",
          "additions": 1243,
          "deletions": 2,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1138,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1138",
          "title": "feat(core): close native Fact foundation (linear republish)",
          "body": "## Summary\n\nClose the remaining language-host dependency gap so Fact and Episode are peer native foundations. This is the linear, current-base republication of PR #1136: it preserves the reviewed implementation while replacing the unpublished historical Cut chain with one merge-queue-safe Episode and Project Cut.\n\n## Related issue\n\nAtlas Go `2026-07-18-kungfu-fact-native-foundation-closure`. Supersedes PR #1136 after GitHub's rebase merge queue rejected its merge commits before creating a merge group.\n\n## Changes\n\n- extend the native storage ABI for Fact and Episode control, recovery, writer liveness, fencing, import/export, rebuild, fsck, and fault-loop operations\n- move Episode retry/recovery state machines and Fact library lifecycle authority into C++\n- keep Python as a thin compatibility adapter and remove Python-owned runtime state machines\n- make Fact Library imports deterministic by sorting admitted Episodes\n- document the v1 JSON adapter boundary and refresh architecture projections\n- republish the reviewed source as three linear commits with no merge commits\n- bind the current `dev/v4/v4.0` parent Cuts through fresh native Episode `1136004` and one current-base Project Cut\n\n## Verification\n\n- `./shifu build:core` and `./shifu freeze` - passed\n- `./shifu test:episode-control` - 45 passed\n- `./shifu test:fact-kernel-native` - 7 passed\n- `./shifu check:fact-kernel-boundary` - 5 passed\n- `./shifu xinfa:quality --check` - 31 cases / 11 routes passed\n- `./shifu check:source` - passed, including 69 Node tests, TypeScript, Biome, Ruff, Mypy over 168 files, C/C++ format, documentation, architecture, and Project Cut gates\n- native Episode inspect/fsck/rebuild - manifest records, integrity, causal closure, replay, dependency, export-evidence, and projection checks passed\n- merge-safe composition against `45abd7640f7072f07e00cde24c5abb014a4b3265` - `qualified`, diagnostics empty\n- commit hooks and DCO checks passed for all three commits\n\n## Project Cut evidence\n\n- Cut: `sha256:fbd59b7a523de1f8cad12656d1a84d36585d84bbf013211a01713c6764c78a14`\n- Cut receipt: `sha256:84675bc1d5bd5e8e0d5741d2f197003e909d7eaf97fe04dd9a3aa34e6dff8e51`\n- source projection: `sha256:38d31b527f03545724a58346bb37722f03dedec6eb51d36f4e45fa54db737a1c`\n- composition: `sha256:d3509c86b455bf1d0c5257dee369ff0143041f0f39a0498feaed61d461bc7073` (`qualified`)\n- Episode semantic root: `sha256:cf41f87fc6194e3699419eb3640a5008fcbbbef0642eb34ff8a64437e529d21b`\n- Episode provider root: `sha256:2a63cd7b9bcfde886aec32699993d13b04dd9ed6e16f6b28ece27051c853d697`\n- Episode qualification root: `sha256:7be79fd8dbf8af68bae572620c3b177ca4b8c52792c4049b9e106090d7a592b6`\n- Episode seal receipt: `sha256:013b445951fef589deb0d8563d890c21ab3626a8e1d8c0e01d5eaf0417060608`\n- parent Cuts: `sha256:aa1284759c68c14e554ddd231f737eac2519bf59e88ebe03873cbb11de276367`, `sha256:bad9f430e973a3dfd49ae3886debe66fce5f8070fc23c231f22753e5dbcbb220`, `sha256:c497a41595103d5f470add27e48c37e994d93a6c43fa27d9c46e7bb06e5d45ee`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0112\", \"ADR-0113\"],\n  \"summary\": \"Close the native Fact and Episode peer-foundation runtime boundary through a linear current-base republication\",\n  \"verification\": [\"Core build, Episode and Fact native tests, source acceptance, Xinfa quality, fresh Episode fsck, and merge-safe Project Cut composition passed\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR adds content-addressed Project Cut/Xinfa qualification evidence only; it does not publish a package or perform a deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T17:08:20Z",
          "mergedAt": "2026-07-19T18:40:43Z",
          "additions": 1472,
          "deletions": 824,
          "changedFiles": 42
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1139,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1139",
          "title": "feat(fact): harden Fact kernel maintainability",
          "body": "## Summary\n\nComplete the staged Fact kernel maintainability program: typed action dispatch, stable diagnostics, schema parity, one advisory writer-lock implementation, CAS/import fault qualification, and KFR2 as the default writer authority while retaining the exact KFR1 reader and mapping receipts.\n\nThe final branch is linear from the current `dev/v4/v4.0` and carries one source-qualified Project Cut. The sealed integration Episode preserves exact references to all eight child Cuts, the native-foundation Cut, and the provisional integration Cut without importing their stale source projections.\n\n## Related goal\n\nAtlas Go `2026-07-19-kungfu-fact-kernel-maintainability-hardening`.\n\n## Authority evidence\n\n- Exact candidate head: `17a3b9418a152b4fd86b067ff73d3a145ed2055b`\n- Xinfa Atlas: `sha256:b34a08b538915f2cc9beed0e970643b6a25df674f385de1ef01cce5400750592`\n- Project Cut: `sha256:f80ef9547a0b9c416229d8a60bda9b7affc4e8838fb6a8ec751cea37fada6d45`\n- Integration Episode semantic root: `sha256:764eb757be51af3014e5999502d168d0b48c9e3a1ef73de5046e14e6a12b82e5`\n- Episode provider root: `sha256:c3c9abcce8367a4505009c3233e30b537fcdc79abc02dfe91374245a8511824d`\n- Scoped composition: `qualified`, no diagnostics, root `sha256:3a3f0a32c9035def3e1ac1f22807dd258c428a8466dc0183f9d53f5ad897988a`\n\n## Verification\n\n- `./shifu check:source` — passed (465 source-contract tests; 464 pass, 1 platform skip; Python typing/format/lint and C++ format passed)\n- `./shifu build:core` — passed after rebasing onto the current base\n- `./shifu test:fact-kernel-native` — 13 passed\n- `./shifu test:fact-kernel-integrity` — 5 passed\n- `./shifu test:advisory-file-lock` — passed\n- `./shifu check:fact-root-canonical` — 7 passed\n- `./shifu check:fact-cut-kernel-contract` — 8 passed\n- `./shifu check:fact-kernel-boundary` — 8 passed\n- documentation gate — 63 passed\n- KFD evidence — KFD-1, four KFD-2 claims, 134 KFD-3 surfaces current\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0112\", \"ADR-0121\"],\n  \"summary\": \"Harden the native Fact kernel and promote KFR2 as the explicit writer authority while retaining exact v1 readers\",\n  \"verification\": [\"Source acceptance, Core build, native characterization, integrity, canonical Root, Fact contract, boundary, documentation, KFD, and Project Cut composition passed\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR updates content-addressed qualification evidence only; it does not publish or deploy a release.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for behavior changes\n- [x] Project Cut source projection is qualified\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T17:46:37Z",
          "mergedAt": "2026-07-19T19:43:09Z",
          "additions": 3466,
          "deletions": 1033,
          "changedFiles": 71
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 260,
          "url": "https://github.com/kungfu-systems/build-images/pull/260",
          "title": "fix(comparator): account for cgroup restart lifecycles",
          "body": "## Summary\n\n- key cgroup counter baselines by container lifecycle so Compose restarts may reuse a cgroup path without producing negative deltas\n- retain lifecycle identity in raw cgroup samples and keep same-lifecycle monotonicity fail-closed\n- preserve the original sampling exception when the adapter process group exits between `poll()` and `killpg()`\n\n## Validation\n\n- `pnpm run check`\n- 105 comparator tests passed\n- deterministic unit coverage for cgroup-path reuse and process-group exit races\n- unscored replay of frozen schedule index 27 passed with attempt 1 and zero scoped residue\n\nContinues #248.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T22:09:37Z",
          "mergedAt": "2026-07-19T22:12:19Z",
          "additions": 163,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 108,
          "url": "https://github.com/kungfu-systems/libnode/pull/108",
          "title": "chore(release): publish libnode alpha 20",
          "body": "## Summary\n- advance the anchored package version to `22.22.3-kf.3-alpha.20`\n- carry the Buildchain v2.14.3 stable/alpha contract locks already reviewed on `dev/v22/v22.22`\n- refresh KFD-1 and KFD-3 witnesses from the version truth files\n\n## Verification\n- `corepack pnpm verify-release`\n- `corepack pnpm verify-kfd-witnesses`\n- `corepack pnpm verify-package-source`\n- `corepack pnpm pack --dry-run`\n- `corepack pnpm exec buildchain validate --require-version-state --require-lifecycle-stages install,build,verify,publish`\n- `actionlint .github/workflows/*.yml .github/workflows/*.yaml`\n- `git diff --check`\n\nThis is the strict Buildchain alpha publish-gate prerequisite for the next production release. The PR-stage build must qualify all three native platforms before merge; post-merge publication must reuse that candidate.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T22:04:38Z",
          "mergedAt": "2026-07-19T22:15:30Z",
          "additions": 25,
          "deletions": 20,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 263,
          "url": "https://github.com/kungfu-systems/build-images/pull/263",
          "title": "chore(release): prepare v1.3.0-alpha.4",
          "body": "## Summary\n\n- advance the v1.3 prerelease state to `1.3.0-alpha.4`\n- align the Buildchain release impact manifest with the package version\n\n## Validation\n\n- `pnpm run check`\n- Buildchain alpha/stable contract locks unchanged\n\nRelease follow-up for #248.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T22:14:24Z",
          "mergedAt": "2026-07-19T22:17:42Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 264,
          "url": "https://github.com/kungfu-systems/build-images/pull/264",
          "title": "chore(release): promote v1.3.0-alpha.4",
          "body": "## Summary\n\nPromote the reviewed cgroup lifecycle accounting fix and `1.3.0-alpha.4` version state from `dev/v1/v1.3` to `alpha/v1/v1.3`.\n\n## Evidence\n\n- fix PR #260 merged with all checks passing\n- version PR #263 merged with all checks passing\n- unscored frozen schedule index 27 replay passed at attempt 1 with zero scoped residue\n- Buildchain alpha and stable contract locks remain unchanged\n\nContinues #248.",
          "author": "dongkeren",
          "createdAt": "2026-07-19T22:18:02Z",
          "mergedAt": "2026-07-19T22:20:54Z",
          "additions": 165,
          "deletions": 8,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1140,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1140",
          "title": "test(fact): bind lifecycle gate to closure PR",
          "body": "## Summary\n\nBind the Fact lifecycle contract gate to ADR-0121 exact closure evidence so `closure_pr` cannot drift away from merged PR #1139 while implementation PRs, KFR2 writer authority, and qualification evidence remain aligned.\n\n## Related goal\n\nAtlas Go `2026-07-19-kungfu-fact-kernel-truth-reconciliation`.\n\n## Changes\n\n- assert ADR-0121 `closure_pr` is exactly `https://github.com/kungfu-systems/kungfu/pull/1139`\n- publish an explicit empty-Episode successor Project Cut rooted in the existing verified Xinfa Atlas\n\n## Verification\n\n- `./shifu check:fact-cut-kernel-contract` — 8 passed\n- `./shifu check:source` — 464 passed, 1 platform skip\n- `./shifu docs:check` — passed\n- pre-commit staged gate — passed\n- Project Cut closeout gate — passed with an independent `fit` review\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This test-only fix freezes already-merged ADR-0121 closure metadata and does not alter an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR adds a fail-closed assertion over existing merged closure evidence and publishes no release.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; no behavior change)",
          "author": "dongkeren",
          "createdAt": "2026-07-19T23:27:29Z",
          "mergedAt": "2026-07-19T23:34:59Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1425,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1425",
          "title": "feat(release): gate invariant passports",
          "body": "## Summary\n- add a generic product-owned invariant Passport gate to Release Passport collection and verification\n- expose file and command inputs through CLI, Action, and reusable promotion workflows\n- fail closed on tampered roots, falsified or incomplete coverage, dirty source, and stale release identity\n- document the responsibility boundary: products own invariant semantics; Buildchain owns release admission\n\n## Validation\n- `pnpm run build`\n- `pnpm run check` (709 tests passed; action bundle integrity passed)\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-19T23:32:36Z",
          "mergedAt": "2026-07-19T23:40:22Z",
          "additions": 505,
          "deletions": 124,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 265,
          "url": "https://github.com/kungfu-systems/build-images/pull/265",
          "title": "fix(comparator): tolerate cgroup ENODEV restarts",
          "body": "## Summary\n\n- treat Linux `ENODEV` while reading a running container cgroup as the same transient lifecycle disappearance as `ENOENT`\n- preserve fail-closed behavior for all other cgroup I/O errors\n- add positive and negative regression coverage\n\n## Formal-run evidence\n\nThe exact `v1.3.0-alpha.4` formal run stopped without retry at sample 69 (`postgresql`, scored round 1, J1 crash-recovery) with `[Errno 19] No such device`. The failed bundle is retained on agent-120; cleanup removed all scoped containers, networks, and volumes. This PR fixes the observed cgroup replacement race. The alpha4 run will not be resumed or reused as acceptance evidence.\n\n## Validation\n\n- `python3 -m unittest pilots.comparator.tests.test_formal_performance`\n- `pnpm run check` (107 comparator tests, KFD123 pass, alpha/stable contract locks unchanged)",
          "author": "dongkeren",
          "createdAt": "2026-07-20T00:14:00Z",
          "mergedAt": "2026-07-20T00:21:30Z",
          "additions": 63,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 266,
          "url": "https://github.com/kungfu-systems/build-images/pull/266",
          "title": "chore(release): prepare v1.3.0-alpha.5",
          "body": "## Summary\n\n- advance the v1.3 alpha release declaration to `1.3.0-alpha.5`\n- publish the reviewed cgroup `ENODEV` lifecycle fix from PR #265 through the standard Buildchain flow\n- leave alpha/stable contract locks and image acceptance locks unchanged\n\n## Validation\n\n- `pnpm run check`\n- 107 comparator tests passed\n- KFD123 passed\n- alpha/stable Buildchain contract locks unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-20T00:22:57Z",
          "mergedAt": "2026-07-20T00:28:05Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 267,
          "url": "https://github.com/kungfu-systems/build-images/pull/267",
          "title": "chore(release): promote v1.3.0-alpha.5",
          "body": "## Summary\n\nPromote the reviewed v1.3 development line to alpha after:\n\n- PR #265: tolerate transient cgroup `ENODEV` during crash-recovery lifecycle replacement\n- PR #266: declare `1.3.0-alpha.5`\n\nThe exact alpha4 formal run remains a retained failed attempt and is not reused. After this promotion publishes alpha5, alpha5 will receive a fresh preparation and exactly one new 666-sample formal run.\n\n## Release policy\n\n- Buildchain v2 alpha channel with contract lock\n- Release Passport enabled\n- GitHub release enabled\n- selective image publish enabled",
          "author": "dongkeren",
          "createdAt": "2026-07-20T00:28:34Z",
          "mergedAt": "2026-07-20T00:31:43Z",
          "additions": 65,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1142,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1142",
          "title": "feat(cli): add canonical compatibility aliases",
          "body": "## Summary\n\nIntroduce canonical developer and Mission Control CLI paths while preserving every public legacy path as a deprecated compatibility alias with deterministic diagnostics and removal gates.\n\n## Related issue\n\nAtlas goal `2026-07-19-kungfu-cli-canonical-alias-migration`.\n\n## Changes\n\n- add canonical `kungfu dev {engage,env,schema,sdk}` and `kungfu profile mission-control ...` paths\n- preserve old commands by sharing the exact Click command objects instead of duplicating implementations\n- emit one structured registry-backed deprecation warning on legacy alias invocation while canonical paths remain quiet\n- extend the CLI surface contract with 27 alias diagnostics, replacement paths, compatibility windows, and removal gates\n- keep `source`/`remote`, `profile`/`kfx profile`, and `work`/`agent work` distinct where they remain different concepts\n- verify stable Action/KFD-3 identities, JSON behavior, and ADR-0118 terminology\n- publish an explicit empty-Episode Project Cut successor for the exact implementation head\n\n## Verification\n\n- `./shifu build:core` — native Core and wasm adapters built\n- `./shifu test:cli-surface-contract` — 17 passed\n- `./shifu test:mission-authority-cutover` — 27 JavaScript and 7 Python tests passed\n- `./shifu test:agent-review-continuation` — 27 JavaScript and 2 Python tests passed\n- `./shifu check:source` — build-free source gate passed; 464 passed, 1 skipped\n- commit hooks passed all staged repository gates\n- Project Cut `sha256:e5dc93be0b28779de877acbde516a533c92ca90c7b3678b1a8dd9955f74a893d` has an explicit empty Episode delta and published observation at `3aadb4ae6f46aaea7d9691b14d3d6d3f23b717eb`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0118\"],\n  \"summary\": \"Migrate developer and Mission Control CLI families to canonical paths while retaining governed compatibility aliases\",\n  \"verification\": [\"CLI surface contract tests\", \"canonical and legacy Click identity tests\", \"alias diagnostic fixtures\", \"./shifu check:source\", \"exact-root Project Cut observation\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes CLI discovery and compatibility metadata only. It preserves command implementations and KFD-3 identities, does not remove public paths, and does not change provider execution authority or runtime journal semantics.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-20T00:25:58Z",
          "mergedAt": "2026-07-20T00:57:46Z",
          "additions": 307,
          "deletions": 14,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1143,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1143",
          "title": "feat(cli): add progressive root help",
          "body": "## Summary\n\nAdd contract-derived progressive root help that keeps the common task map small while preserving explicit full and machine-readable discovery across the Python source host and assembled Rust archive host.\n\n## Related issue\n\nAtlas goal `2026-07-19-kungfu-cli-progressive-help`.\n\n## Changes\n\n- govern seven ordered help sections and visibility defaults in the CLI surface registry\n- derive deterministic default, full, section, and JSON projections from the live contract with fail-closed schema and placement checks\n- expose `--help-all`, `--help-section`, and `--help-json` without initializing a workspace or runtime state\n- keep the archive root help native and offline while merging native dispatch metadata with the generated Python manifest\n- preserve advanced and compatibility commands behind explicit expansion instead of deleting or renaming them\n- enforce terminal width and no-color behavior, exact projection roots, source/archive parity, and unavailable/degraded diagnostics\n- publish an explicit empty-Episode Project Cut successor for the exact implementation head\n\n## Verification\n\n- `./shifu build:core` — native Core, trunk, Python, Node/Electron, and wasm adapters built\n- `./shifu test:cli-surface-contract` — 24 passed\n- `cargo test --manifest-path crates/trunk/Cargo.toml` — 39 passed\n- `./shifu freeze` — assembled runtime produced with generated help manifest and trunk aliases\n- source and archive smoke checks proved bare/`--help` equality, JSON root parity, 80-column wrapping, no ANSI, unknown-section exit 2, and no `KF_HOME` initialization\n- commit hooks passed the full staged repository gates, including Ruff, Biome, documentation contracts, Rust workspace clippy, and Rust workspace tests\n- Project Cut `sha256:804b9a3909bd3743d96f3e74efa301eb49d68df04a3493fa86a31cdbb94986ab` has an explicit empty Episode delta and published observation at `1b3fa81da33e66b71ef6052dad755320227d8d35`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0046\", \"ADR-0118\"],\n  \"summary\": \"Project contract-derived progressive CLI help through the native trunk and assembled runtime without changing canonical paths or authorization\",\n  \"verification\": [\"CLI surface contract tests\", \"Rust trunk help tests\", \"assembled source/archive root parity\", \"offline and no-init smoke checks\", \"exact-root Project Cut observation\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes CLI discovery and assembled help projection only. It does not change command handlers, canonical paths, authorization, provider execution, or runtime journal semantics. Full and machine-readable surfaces remain available through explicit stable flags.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T01:38:03Z",
          "mergedAt": "2026-07-20T02:06:55Z",
          "additions": 910,
          "deletions": 48,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1082,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1082",
          "title": "chore(project-cut): bind KFD-7 runtime cut",
          "body": "## Summary\n\n- bind the merged KFD-7 runtime slice to Project Cut `sha256:28d3b04890465d8873eff770546cf6e8f0c398aca447f265701d07f4f56a9b62`\n- record the exact source projection, protocol, schema, policy, and settlement roots\n- preserve an explicit empty Episode delta; this PR does not assert KFD-7 qualification or activation\n\n## Validation\n\n- Project Cut settlement dry-run and execute/stage passed\n- commit observation published for `8fafd434c2328c622ba36750662219a1c27b8870`\n- independent completion review verdict: `fit`\n- continuation decision: `close`\n- Atlas Project Cut closeout gate: `ok=true`\n- repository pre-commit suite passed, including route/gate/schema/runtime, 12 latency tests, markdownlint, 63 contract tests, ADR/release/toolchain checks, and Biome\n\n## Provenance\n\n- runtime delivery PR: #1081\n- source runtime merge: `f01c8111508349aa81a21d8386cd71261da10537`\n- this PR is bounded to Project Cut closeout evidence only\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Publish content-addressed Project Cut and successor Xinfa evidence for the already-merged provisional KFD-7 runtime delivery without changing architecture, qualification, or activation state\"\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis evidence-only PR grants no publishing or activation authority; the explicit empty Episode delta and non-qualification boundary are retained.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; evidence-only)",
          "author": "dongkeren",
          "createdAt": "2026-07-18T11:36:59Z",
          "mergedAt": "2026-07-20T02:15:00Z",
          "additions": 11,
          "deletions": 0,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1145,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1145",
          "title": "feat(cli): generate complete surface catalog",
          "body": "## Summary\n\nPublish the complete folded Click surface as one deterministic, checked-in Agent catalog and make source acceptance reject consumer drift.\n\n## Related issue\n\nAtlas goal `2026-07-19-kungfu-cli-catalog-parity-generation`.\n\n## Changes\n\n- generate a root-bound catalog with 373 surfaces and explicit KFD-3 linkage reasons\n- embed the complete graph in `kungfu agent capabilities --json` and the packaged Agent inventory\n- validate KFD-3, `commands.json`, docs/skills, GUI/Agent Console references, and packaging declarations\n- add offline root fencing plus stale, re-rooted, orphan, and omission negative tests\n\n## Verification\n\n- `KUNGFU_NATIVE_PATH=/Applications/Kungfu\\ Episodes.app/Contents/Resources/kungfu ./shifu test:cli-surface-contract`\n- `KUNGFU_NATIVE_PATH=/Applications/Kungfu\\ Episodes.app/Contents/Resources/kungfu ./shifu check:cli-catalog-parity`\n- `./shifu check:agent-pack`\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0118\"],\n  \"summary\": \"Deliver the deterministic Human-Agent CLI catalog parity stage\",\n  \"verification\": [\"CLI catalog parity gate\", \"complete source acceptance\", \"Project Cut a8d8213b5f22314be96ba5d843a73d48441aa3ac28a061dc2efb051ef5982d2e\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change adds CLI discovery data and packaging inventory declarations only; it does not publish a package or activate a runtime Profile. Source acceptance and the tracked Project Cut bind the evidence.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-20T03:25:48Z",
          "mergedAt": "2026-07-20T03:55:17Z",
          "additions": 31943,
          "deletions": 73,
          "changedFiles": 44
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1147,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1147",
          "title": "feat(invariant): publish unified verification source",
          "body": "## Summary\n\nPublish the final unified Fact/Episode invariant verification source on the current `dev/v4/v4.0` base, with one fresh root Project Cut that matches the publishable two-commit history.\n\nPR #1141 remains the full reviewed development and Project Cut audit trail. Its merge-heavy history cannot enter this repository's rebase-only mainline without invalidating historical Project Cut source projections. PR #1146 demonstrated that squashing those historical Cuts is also invalid: Source Acceptance correctly rejected the resulting `source-drift`. This PR therefore preserves the final source state and publishes a new root Cut without claiming ancestry over the old Cuts.\n\nFresh integration Project Cut: `sha256:9f62789adae889c5b7eef6909edfc541bc62d1ae5236941f960ecda0e5dbc678` at source commit `77fba1537e76204f4f5c20a2c906fb404e818bd6`, source projection `sha256:50bac870480026f783d4eb57d0bb8c5c8159c09f74b1f61457126b5d5e0c7cd7`, observed by receipt `sha256:e980ed605ea1f49decc7aec7877063aa41a0a33aba8b395c620d4d1329950603`.\n\n## Related issue\n\nAtlas goal `2026-07-20-kungfu-invariant-verification-system`; supersedes PRs #1141 and #1146 for mainline publication only.\n\n## Changes\n\n- preserve the final invariant registry, runner, evidence protocols, object receipts, successor gates, and release Passport boundary reviewed in #1141;\n- retain the Windows-safe native Fact checker correction from source commit `5a0fffb9a6a85861b9afef123e87906ea2cb904d`;\n- reconcile generated KFD projections with current mainline CLI catalog state;\n- publish one fresh root Project Cut for the exact current-base source tree;\n- retain #1141 and its final Cut `sha256:0b3422a965a1fab4548ec337c860cadd3fee8c204572a18446c242db23610491` as the historical audit trail, not as ancestry of the new publication Cut.\n\n## Verification\n\n- `./shifu check:source` (481 Node tests: 473 passed, 8 environment-gated skipped; all Python, runtime upgrade, desktop update, type, formatting, documentation, KFD, and Project Cut gates passed)\n- `node --test scripts/kungfu-invariant.test.mjs` (11/11)\n- `./shifu docs:check` (63/63)\n- `./shifu kfd:buildchain` (134 surfaces)\n- Project Cut generation and commit observation completed without diagnostics\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0122\"],\n  \"summary\": \"Publish the unified invariant registry, runner, evidence protocols, object receipt, evolution gate, cross-platform qualification, and Buildchain release Passport gate on a rebase-compatible mainline history.\",\n  \"verification\": [\"source acceptance\", \"adversarial invariant tests\", \"documentation gate\", \"KFD evidence gate\", \"fresh Project Cut observation\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release boundary is fail-closed and only consumes product-owned evidence. No package publishing, deployment, release promotion, or runtime activation is performed by this PR.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T04:01:24Z",
          "mergedAt": "2026-07-20T04:28:04Z",
          "additions": 4996,
          "deletions": 79,
          "changedFiles": 64
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1144,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1144",
          "title": "feat(fact): add end-to-end durable ref admission",
          "body": "## Summary\n\nAdd an explicit, default-off end-to-end durability frontier for Fact `ref-cas`.\nSuccess now requires the target Cut's transitive content closure, the adjacent\njournal transition and operation receipt, and the ref transition itself to be\ncovered by an admitted durable checkpoint. Unknown crash outcomes retain the\noriginal operation identity and reconcile after a fresh reopen.\n\nThe retained candidate is deliberately bounded to the named Linux/ext4/NVMe\nenvelope and the `yijinjing-file/v1` provider. It does not claim physical\npower-loss qualification, replication, high availability, consensus, or\nproduction eligibility. RocksDB `wal-os-buffered` remains rejected.\n\n## Related issue\n\nAtlas goal `2026-07-20-kungfu-fact-end-to-end-durable-admission`.\n\n## Changes\n\n- add the native durable Fact admission and `durability-reconcile` route\n- verify the complete transitive Cut closure and exact journal/receipt pair\n- inject deterministic faults at every admitted publication boundary\n- close the KFR2 `ref-cas` request projection with an optional durability field\n- register the `durability.contracts` release gate and Buildchain KFD evidence\n- retain an exact-source qualification report from agent-120 Linux/ext4/NVMe\n- document the bounded candidate, recovery semantics, and explicit non-claims\n\n## Verification\n\n- `./shifu rebuild:core` on agent-120\n- `./shifu test:fact-kernel-native` (28 passed)\n- `./shifu check:fact-cut-kernel-contract` (8 passed)\n- `./shifu test:durability-contract` (native, typed, and 13 composed tests passed)\n- `./shifu check:fact-durable-admission` (2 passed)\n- `node --test scripts/check-fact-root-canonical.test.mjs` (7 passed)\n- `./shifu docs:check`\n- `./shifu core:architecture`\n- retained qualification: 13 passed on Linux 6.8.0-134, ext4, `/dev/nvme0n1p1`\n- `./shifu check:source` (build-free source gate passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0112\"],\n  \"summary\": \"Close the bounded end-to-end durable Fact ref admission frontier and retain its current-hardware qualification evidence.\",\n  \"verification\": [\"Fact native and contract suites\", \"durability.contracts Gate\", \"agent-120 Linux/ext4/NVMe retained qualification\", \"source acceptance\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe retained report is digest-bound to the exact source set, native artifact,\nqualification envelope, underlying durable-ingest evidence, provider matrix,\nfault campaign, checker, and release Gate.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T02:20:34Z",
          "mergedAt": "2026-07-20T04:55:21Z",
          "additions": 1974,
          "deletions": 75,
          "changedFiles": 43
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1150,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1150",
          "title": "feat(exit): publish verifiable migration closure",
          "body": "## Summary\n\nPublish the reviewed Exit migration closure on\n`dev/v4/v4.0@cacdb81df0490d92a13482e2f0790b6b066875f1`, after the unified\ninvariant verification dependency landed through PR #1147 and durable Fact\nadmission advanced the mainline through PR #1144.\n\nPR branch `feature/exit-migration-closure` remains the complete development\nand six-child Project Cut audit trail. Its merge-heavy history cannot enter\nthis repository's rebase-only mainline without invalidating historical source\nprojections, so this PR republishes the final source state with one fresh,\nmainline-compatible root Project Cut.\n\nPR #1148 completed all PR checks and independent review on the prior mainline\ntip, but PR #1144 merged before it entered the queue and correctly made that\npublication dirty. This replacement preserves #1148 as an audit record\ninstead of rebasing or force-pushing its source-bound Cuts.\n\nFresh publication Cut:\n`sha256:baf4ed6ee9d1c24c3ad81dd6e399e7caf13feb70338aeaf3dc16d5d9779ad1b7`,\nsource projection\n`sha256:9dd9c350bf796b22cfdf2b0dafceb2e6f65036295c9f87d4a607924847013737`,\nobserved at commit\n`72bb7239b0f1a3a2cb63bdf74cbc01ade7c19130`\nby receipt\n`sha256:78b47ee9f8907442da8483c346c60fc910c772da560910ad47625920706a5fdc`.\n\n## Related issue\n\nAtlas goal `2026-07-20-kungfu-exit-migration-closure`.\n\n## Changes\n\n- publish the versioned Exit Bundle composition contract, closed inventory,\n  adversarial corpus, packaging registry, and fail-closed source drift gate;\n- expose registry-free installed verification through both\n  `kungfu-exit-verify` and `python -m kungfu.exit_verifier`;\n- retain clean-runtime import, projection rebuild, continuation, and exact\n  File-to-RocksDB migration/rollback evidence for the qualified Darwin arm64\n  CLI boundary;\n- bind release claims to the consumer-owned Invariant Passport and Buildchain\n  KFD evidence without promoting a release;\n- reconcile the Exit commands with the merged CLI Catalog authority and teach\n  its parity checker to honor declared standalone catalog routes;\n- retain the original branch final commit\n  `a2fcf90bc5ba1c5e7f13a07a189d17f37f189a12`, original parent Cut\n  `sha256:e9ae8dc0feaeb2bf5b045577bbec1a8eb4abea4ff17807d444ef265a097ad149`,\n  and six child Cuts as the historical audit trail, not as ancestry of the\n  fresh publication root.\n\n## Verification\n\n- `KUNGFU_NATIVE_PATH='/Applications/Kungfu Episodes.app/Contents/Resources/kungfu' ./shifu check:source`\n  (all Node contract, Core Python, runtime-upgrade, desktop-update, mypy over\n  174 source files, formatting, lint, documentation, KFD, and Project Cut\n  composition gates passed)\n- `node --test scripts/check-exit-bundle-contract.test.mjs scripts/check-cli-catalog-parity.test.mjs`\n  (covered by Source Acceptance)\n- `./shifu docs:check` (63/63 contract fixtures)\n- `./shifu kfd:buildchain` (136 KFD-3 surfaces)\n- fresh root Project Cut generated and commit-observed without diagnostics\n- `git diff --check`\n\n## Qualification boundary\n\nThe retained qualification covers the exact Darwin arm64 CLI and evidence\nnamed above. Linux and Windows product qualification, GUI/TUI workflows,\ncross-machine migration, destructive cleanup, distributed fencing,\nphysical-media durability, and real release/channel promotion remain\nunqualified and out of scope.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0122\"],\n  \"summary\": \"Publish the domain-neutral Exit Bundle, registry-free verifier, bounded clean-runtime and provider-migration evidence, and fail-closed release Passport boundary on a rebase-compatible mainline history.\",\n  \"verification\": [\"source acceptance\", \"Exit Bundle adversarial tests\", \"CLI Catalog parity tests\", \"documentation gate\", \"KFD evidence gate\", \"fresh Project Cut observation\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR verifies release evidence but performs no package publishing,\ndeployment, channel promotion, destructive cleanup, or real runtime mutation.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T05:06:11Z",
          "mergedAt": "2026-07-20T05:39:41Z",
          "additions": 10461,
          "deletions": 206,
          "changedFiles": 129
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 268,
          "url": "https://github.com/kungfu-systems/build-images/pull/268",
          "title": "fix(comparator): bound matched soak memory",
          "body": "## Summary\n\n- freeze a symmetric 10,000 messages/second ceiling for the 60-second Kungfu/Aeron soak\n- enforce the rate in the versioned plan, provider request, and both external drivers\n- keep latency and throughput workloads unthrottled\n\n## Context\n\nThe single exact `v1.3.0-alpha.5` formal attempt passed the prior cgroup lifecycle boundary and then failed at matched schedule index 382. The 60-second Kungfu soak produced an unbounded durable-record set, and the post-soak oracle materialization was killed by the frozen 2 GiB subject memcg.\n\nAt 10,000 messages/second, each 60-second soak retains exactly 600,000 replayable records. This preserves the frozen duration and symmetric semantics while bounding correctness verification under the common subject limit.\n\n## Verification\n\n- `pnpm run check` (108 qualification tests, KFD123, Release Passport smoke, alpha/stable contract locks unchanged)\n- focused formal-performance tests: 18 passed\n- Kungfu driver compiled against frozen source and completed a 60-second visible/64-byte diagnostic at 600,000 messages, 9,999.99 messages/second, zero anomalies, zero scoped residue, and no memcg OOM\n- Aeron driver compiled with the pinned Java 21 image and generated `formal-performance-aeron.jar`\n\nThe diagnostics are not formal acceptance evidence. After the next reviewed alpha is published, acceptance still requires fresh preparation and exactly one new 666-sample run from published exact digests on agent-120.\n\nCloses no issue yet; #248 remains open until stable publication and retained acceptance evidence are complete.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T06:05:21Z",
          "mergedAt": "2026-07-20T06:08:26Z",
          "additions": 98,
          "deletions": 11,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 269,
          "url": "https://github.com/kungfu-systems/build-images/pull/269",
          "title": "chore(release): prepare v1.3.0-alpha.6",
          "body": "## Summary\n\n- advance the v1.3 prerelease from `1.3.0-alpha.5` to `1.3.0-alpha.6`\n- keep the Buildchain v2 dual-channel contract locks unchanged\n- carry the reviewed bounded matched-soak fix from PR #268 into the next release candidate\n\n## Verification\n\n- `pnpm run check`\n- 108 qualification tests passed\n- KFD123 passed\n- Release Passport smoke passed\n- alpha `v2-alpha` and stable `v2` contract locks are unchanged\n\nThis PR only prepares version metadata. Publication remains owned by the standard `dev/v1/v1.3` -> `alpha/v1/v1.3` Buildchain promotion flow.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T06:10:25Z",
          "mergedAt": "2026-07-20T06:13:25Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 270,
          "url": "https://github.com/kungfu-systems/build-images/pull/270",
          "title": "chore(release): promote v1.3.0-alpha.6",
          "body": "## Promotion\n\nPromote `dev/v1/v1.3` at `133096c110c878feef5896cb9789b4d75dad314c` to `alpha/v1/v1.3`.\n\n## Included change\n\n- bound the symmetric 60-second Kungfu/Aeron matched soak to 10,000 messages/second\n- retain exactly 600,000 replayable records per soak under the frozen 2 GiB subject limit\n- advance release metadata to `1.3.0-alpha.6`\n\n## Reviewed source PRs\n\n- #268 comparator soak memory bound\n- #269 alpha.6 version preparation\n\n## Release contract\n\nPublication is owned by the standard Buildchain v2 alpha channel with the locked `v2-alpha` contract. Release Passport and GitHub release output remain enabled. Formal acceptance will use only the exact published image digests from this promotion, with fresh preparation and one unretried 666-sample run on agent-120.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T06:14:29Z",
          "mergedAt": "2026-07-20T06:17:31Z",
          "additions": 100,
          "deletions": 13,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1151,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1151",
          "title": "feat(product): qualify installed CLI surface",
          "body": "## Summary\n\nQualify the assembled Kungfu CLI from the extracted CLI archive and a clean registered Product app, proving the progressive-help, catalog, KFD-3, Profile/KFX, offline brief, and mutation receipt surfaces without relying on the source tree, PATH Node, or GUI-private state.\n\n## Related issue\n\nAtlas goal `2026-07-19-kungfu-cli-installed-product-qualification`.\n\n## Changes\n\n- add a standalone installed-layout CLI qualification harness with temporary HOME and workspace isolation\n- verify version/help/help JSON, Agent catalog roots, legacy alias warnings, KFD-3 linkage, Profile/KFX projections, offline briefs, and mutation plan/receipt behavior\n- invoke the qualification harness against every extracted CLI distribution and retain a deterministic qualification report\n- add positive and root-drift negative tests for the installed-product evidence contract\n- normalize `python -m kungfu` command paths so legacy SDK alias warnings remain visible on stderr in packaged layouts\n- expose dedicated qualification and test tasks\n- publish an explicit empty-Episode Project Cut successor for the exact implementation head\n\n## Verification\n\n- `./shifu test:cli-surface-qualification` — 19/19 passed\n- `./shifu test:cli-surface-contract` — 26 passed\n- `./shifu check:cli-catalog-parity` — JavaScript and Python folds passed\n- `./shifu dist:cli` — extracted archive installed-layout qualification passed\n- `./shifu dist:dir` — clean Product build `20260720T055819Z-c3a6b4713` passed\n- product-built app qualification — qualified with 373 surfaces, 27 aliases, 151 KFD-3 rows, and 18 Profile/KFX surfaces\n- commit hooks passed for implementation and settlement commits\n- Project Cut `sha256:ff7fdaa62711bbf567df283aca3f0f73880e8f0b3b690be82740caf0cc90067e` has an explicit empty Episode delta and a published observation at `44c0b5f04ef8a6bede3e29f518c6070cdfc076f5`\n- Completion Claim `completion-67221c5c8fa032cb2e831afd` binds the exact observed head with no known gaps\n- full `./shifu check` reached an unrelated pre-existing Xinfa documentation qualification hang and was interrupted without modifying the older stuck process; all changed-scope and commit-hook gates completed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0091\"],\n  \"summary\": \"Qualify the assembled CLI archive and clean Product app against the versioned CLI surface contract\",\n  \"verification\": [\"installed-layout qualification harness\", \"CLI surface contract tests\", \"catalog parity checks\", \"clean registered Product build\", \"exact-root Project Cut Completion Claim\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR qualifies public CLI/KFD-3/Profile-KFX metadata and product-assembly evidence. It does not activate unavailable KFX contributions, access GUI-private runtime state, or promote a build into `/Applications`; installed-app promotion remains an explicit human-confirmed operational step.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T06:13:50Z",
          "mergedAt": "2026-07-20T06:48:09Z",
          "additions": 668,
          "deletions": 5,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 208,
          "url": "https://github.com/kungfu-systems/kfd/pull/208",
          "title": "docs(kfd-7): distinguish Action Geometry from Domain Profiles",
          "body": "## Summary\n\n- name the cross-domain KFD-7 responsibility structure Action Geometry\n- reserve Domain Profile for adopter-specific fields, lifecycle, policy, and evidence\n- refresh KFD-1/2/3 witnesses and site metadata from the same sources\n\n## Verification\n\n- npm run check\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API or usage-attribution changes\n- [x] No hosted-service, branding, package identity, or deployment changes\n- [x] KFD release evidence and machine surfaces remain synchronized",
          "author": "dongkeren",
          "createdAt": "2026-07-20T07:00:14Z",
          "mergedAt": "2026-07-20T07:03:41Z",
          "additions": 227,
          "deletions": 166,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 210,
          "url": "https://github.com/kungfu-systems/kfd/pull/210",
          "title": "chore(kfd): anchor alpha 39 release",
          "body": "## Summary\n\n- anchor `@kungfu-tech/kfd` at `1.0.0-alpha.39`\n- refresh KFD-1, KFD-2, and KFD-3 release evidence\n- prepare the Buildchain lock refresh and KFD-7 Action Geometry clarification for alpha promotion\n\n## Verification\n\n- `npm ci --ignore-scripts --no-audit --no-fund`\n- `npm run check`\n- `npm pack --dry-run --json`\n- `npx --yes @kungfu-tech/buildchain@alpha release --dry-run --target-ref alpha/v1/v1.0 --json`\n- `npx --yes @kungfu-tech/buildchain@alpha npm dry-run --json`\n\n## Release boundary\n\nThis PR only establishes the explicit release fact on `dev/v1/v1.0`. Publication still requires the protected `dev/v1/v1.0 -> alpha/v1/v1.0` promotion PR, alpha Verify success, and Buildchain Ref Promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-20T07:28:33Z",
          "mergedAt": "2026-07-20T07:31:48Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 211,
          "url": "https://github.com/kungfu-systems/kfd/pull/211",
          "title": "release(kfd): promote v1.0.0-alpha.39",
          "body": "## Release anchor\n\n- Source release PR: #210\n- Verified dev SHA: `a0788b95c3b35c5ad83c083a9abf0826ea32e62f`\n- Dev Verify: https://github.com/kungfu-systems/kfd/actions/runs/29724898592\n- Target package: `@kungfu-tech/kfd@1.0.0-alpha.39`\n\nBuildchain publication remains gated by the successful Verify run on the resulting `alpha/v1/v1.0` merge commit.",
          "author": "dongkeren",
          "createdAt": "2026-07-20T07:33:21Z",
          "mergedAt": "2026-07-20T07:37:45Z",
          "additions": 261,
          "deletions": 200,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1155,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1155",
          "title": "docs(architecture): separate Action Geometry from Domain Profiles",
          "body": "## Summary\n\n- define Action Geometry as the cross-domain KFD-7 responsibility and invariant layer\n- define Domain Profiles as adopter-owned fields, lifecycle, validation, policy, and presentation\n- preserve existing combined-v1 roots and schema names as compatibility identities\n- refresh Buildchain KFD evidence for the changed ADR authority\n\n## Verification\n\n- `./shifu docs:check`\n- `node scripts/buildchain-kfd-evidence.mjs --check`\n- `./shifu docs final-ready --since c7c72a2429 --budget 66560 --json` (`review-required`, zero violations)\n- staged repository gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0123\"],\n  \"summary\": \"Separate cross-domain Action Geometry from adopter-owned Domain Profiles while preserving combined-v1 compatibility identities.\",\n  \"verification\": [\"Xinfa documentation Task Chart\", \"documentation gate\", \"staged repository gates\", \"independent maintainer review\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes architecture authority and generated KFD evidence only. It does not publish a release, mutate a runtime home, or reinterpret existing roots.\n\nSupersedes #1153 for publication because this branch contains only linear commits on the latest dev mainline.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-20T07:48:49Z",
          "mergedAt": "2026-07-20T08:04:05Z",
          "additions": 246,
          "deletions": 64,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 132,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/132",
          "title": "chore(kfd): consume alpha.39 release",
          "body": "Consumes the exact `@kungfu-tech/kfd@1.0.0-alpha.39` release envelope and preserves the managed KFD-5, KFD-6, and KFD-7 badge entries required after the consumer dynamically pins the new package.\n\nThe follow-up badge commit repairs the release-propagation ordering regression tracked in https://github.com/kungfu-systems/buildchain/issues/1380. The controller receipt mismatch is tracked separately in https://github.com/kungfu-systems/buildchain/issues/1426.\n\nBuildchain release propagation from @kungfu-tech/kfd into the kfd.libkungfu.dev site surface.\n\nBuildchain release propagation plan:\n\n```json\n{\n  \"schemaVersion\": 1,\n  \"contract\": \"kungfu-buildchain-release-propagation-plan\",\n  \"source\": \"kfd\",\n  \"upstreamRelease\": {\n    \"repository\": \"kungfu-systems/kfd\",\n    \"channel\": \"alpha\",\n    \"tag\": \"v1.0.0-alpha.39\",\n    \"sourceSha\": \"c30501679d0fe969c98b440a1fce70ab68fb2794\",\n    \"package\": {\n      \"name\": \"@kungfu-tech/kfd\",\n      \"version\": \"1.0.0-alpha.39\",\n      \"integrity\": \"sha512-WWxo9ZUL7IGdGg4iXUoa8rMpZrQ6mwZlIW91AeNwit56dSGJImJ5RB6jTUr9k2LaOBnIlj4ro1P6wnukXal1Jw==\"\n    },\n    \"releasePassport\": {\n      \"url\": \"https://github.com/kungfu-systems/kfd/releases/download/v1.0.0-alpha.39/buildchain.release.json\",\n      \"sha256\": \"2aa9e3b3979f116286d9e8885fab212a8397c81f5aa74b712757ec3369895ef8\"\n    }\n  },\n  \"targets\": [\n    {\n      \"edge\": \"kfd-to-site-libkungfu-dev\",\n      \"source\": \"kfd\",\n      \"target\": \"site-libkungfu-dev\",\n      \"repository\": \"kungfu-systems/site-libkungfu-dev\",\n      \"channel\": \"alpha\",\n      \"baseRef\": \"main\",\n      \"lockPath\": \"buildchain.upstreams/kfd.release.json\",\n      \"lock\": {\n        \"schemaVersion\": 1,\n        \"contract\": \"kungfu-buildchain-release-propagation-lock\",\n        \"upstream\": {\n          \"node\": \"kfd\",\n          \"repository\": \"kungfu-systems/kfd\",\n          \"channel\": \"alpha\",\n          \"tag\": \"v1.0.0-alpha.39\",\n          \"sourceSha\": \"c30501679d0fe969c98b440a1fce70ab68fb2794\",\n          \"package\": {\n            \"name\": \"@kungfu-tech/kfd\",\n            \"version\": \"1.0.0-alpha.39\",\n            \"integrity\": \"sha512-WWxo9ZUL7IGdGg4iXUoa8rMpZrQ6mwZlIW91AeNwit56dSGJImJ5RB6jTUr9k2LaOBnIlj4ro1P6wnukXal1Jw==\"\n          },\n          \"releasePassport\": {\n            \"url\": \"https://github.com/kungfu-systems/kfd/releases/download/v1.0.0-alpha.39/buildchain.release.json\",\n            \"sha256\": \"2aa9e3b3979f116286d9e8885fab212a8397c81f5aa74b712757ec3369895ef8\"\n          }\n        },\n        \"downstream\": {\n          \"node\": \"site-libkungfu-dev\",\n          \"repository\": \"kungfu-systems/site-libkungfu-dev\",\n          \"channel\": \"alpha\",\n          \"baseRef\": \"main\",\n          \"lockPath\": \"buildchain.upstreams/kfd.release.json\"\n        },\n        \"propagation\": {\n          \"graphContract\": \"kungfu-buildchain-release-propagation-graph\",\n          \"edge\": \"kfd-to-site-libkungfu-dev\",\n          \"channelPolicy\": \"preserve\",\n          \"channelMap\": {\n            \"alpha\": \"alpha\",\n            \"release\": \"release\"\n          },\n          \"exact\": true,\n          \"floatingTags\": false\n        },\n        \"lockSha256\": \"13dc200df62d9ff9cabbb8faae7d385c61a0556342cb1d4a2f25c50b4f024586\"\n      }\n    }\n  ],\n  \"summary\": {\n    \"targetCount\": 1,\n    \"channels\": [\n      \"alpha\"\n    ],\n    \"repositories\": [\n      \"kungfu-systems/site-libkungfu-dev\"\n    ]\n  }\n}\n```\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T08:02:11Z",
          "mergedAt": "2026-07-20T08:12:53Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 271,
          "url": "https://github.com/kungfu-systems/build-images/pull/271",
          "title": "fix(comparator): tolerate process exit during cgroup sampling",
          "body": "## Summary\n\n- treat Linux `ESRCH` as an expected cgroup lifecycle race when a measured container process exits after Docker inspection\n- keep unexpected cgroup I/O failures fail-closed\n- add a regression test for the exact `ProcessLookupError` path\n\n## Evidence\n\nThe single formal `v1.3.0-alpha.6` acceptance run stopped without retry at schedule index 112. PostgreSQL startup and initialization succeeded, cleanup left zero residue, and the provider failed with `formal-performance provider error: [Errno 3] No such process`. The preceding 112 completed samples used one attempt and passed correctness and cleanup.\n\n## Verification\n\n- `python3 -m unittest pilots.comparator.tests.test_formal_performance` (19 passed)\n- `pnpm run check` (109 qualification tests passed; KFD123 and Release Passport smoke passed; alpha/stable contract locks unchanged)",
          "author": "dongkeren",
          "createdAt": "2026-07-20T08:18:25Z",
          "mergedAt": "2026-07-20T08:21:02Z",
          "additions": 28,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 272,
          "url": "https://github.com/kungfu-systems/build-images/pull/272",
          "title": "chore(release): prepare v1.3.0-alpha.7",
          "body": "## Summary\n\nPrepare `v1.3.0-alpha.7` after merging the cgroup `ESRCH` lifecycle-race fix from PR #271.\n\n## Changes\n\n- update package version to `1.3.0-alpha.7`\n- update Buildchain release impact version to `1.3.0-alpha.7`\n- leave Buildchain v2 dual-channel configuration and both contract locks unchanged\n\n## Verification\n\n- `pnpm run check`\n- 109 qualification tests passed\n- KFD123 and Release Passport smoke passed\n- alpha/stable contract locks unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-20T08:21:59Z",
          "mergedAt": "2026-07-20T08:25:08Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 273,
          "url": "https://github.com/kungfu-systems/build-images/pull/273",
          "title": "chore(release): promote v1.3.0-alpha.7",
          "body": "## Promotion\n\nPromote `dev/v1/v1.3` at `bc4576c325c496ce0ba5b13863d35e24404f5d5d` to `alpha/v1/v1.3`.\n\n## Included change\n\n- tolerate Linux `ESRCH` when a measured container process exits between Docker inspection and cgroup counter reads\n- preserve fail-closed handling for unexpected cgroup I/O errors\n- advance release metadata to `1.3.0-alpha.7`\n\n## Reviewed source PRs\n\n- #271 cgroup process-exit lifecycle race\n- #272 alpha.7 version preparation\n\n## Release contract\n\nPublication is owned by the standard Buildchain v2 alpha channel with the locked `v2-alpha` contract. Release Passport and GitHub release output remain enabled. Formal acceptance will use only the exact published image digests from this promotion, with fresh preparation and one unretried 666-sample run on agent-120.",
          "author": "dongkeren",
          "createdAt": "2026-07-20T08:25:53Z",
          "mergedAt": "2026-07-20T08:28:38Z",
          "additions": 30,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 213,
          "url": "https://github.com/kungfu-systems/kfd/pull/213",
          "title": "docs(kfd-7): clarify action terminology and semantics",
          "body": "## What\n\nClarify KFD-7 so Action Geometry is immediately described as the cross-domain responsibility model, distinguish canonical terminology from retained compatibility identifiers, and define responsibility separation as semantic distinguishability rather than physical component count.\n\n## Contribution type\n\n- [ ] proposal or Candidate\n- [ ] evidence, counterexample, or independent review\n- [ ] adopter Profile or implementation\n- [x] decision, registry, schema, verifier, or release surface\n- [x] governance, documentation, or maintenance\n\n## Claim and evidence\n\nThe refinement keeps all published coordinates and version-2 compatibility identities immutable. It adds explicit terminology status, migration boundaries, and a formal semantic-independence obligation. Evidence is the regenerated KFD-1/2/3 material plus the native/WASM verifier parity and adversarial checks. It does not claim that conforming implementations require five stores, records, APIs, services, or UI components, and it does not activate a successor geometry contract.\n\n## Interests and review\n\nKungfu Origin Technology Limited maintains KFD and the first adopter implementations.\n\n- [x] A substantive change has a reviewer other than its author\n- [ ] Activation or Foundation Revision has an independent reviewer\n\n## Compatibility and registry agreement\n\n- [x] `node scripts/check.mjs` passes\n- [x] Applicability, compatibility, migration, and supersession impact are explicit\n- [x] Published coordinates remain immutable\n- [x] After Foundation Freeze, decision texts remain append-only (supersession over rewrite)\n\n## Version impact (per KFD-1)\n\n- [x] patch (content operation) / minor (registry schema additive) / major (machine surface breakage)\n\nPatch: semantic clarification and generated evidence refresh; no machine-surface breakage.",
          "author": "dongkeren",
          "createdAt": "2026-07-20T08:41:08Z",
          "mergedAt": "2026-07-20T08:44:41Z",
          "additions": 261,
          "deletions": 163,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1156,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1156",
          "title": "docs(architecture): clarify KFD-7 terminology boundaries",
          "body": "## Summary\n\nClarify the KFD-7 architecture language across the ADR, runtime model, Agent Work Domain Profile, and public vocabulary. Action Geometry now carries the plain-language subtitle “cross-domain responsibility model”; canonical terms are separated from combined-v1 compatibility identifiers; and semantic independence is explicitly distinguished from physical decomposition.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- define canonical Action Geometry, Domain Profile, Action Geometry Contract, and Domain Profile Declaration terminology\n- retain Action Profile and unqualified Action Contract only at existing compatibility identities, with explicit migration conditions\n- require traceability, counterfactual distinguishability, and fail-visible prohibited inference rather than five physical components\n- project the canonical model into the public vocabulary registry\n\n## Verification\n\n- `./shifu docs:check`\n- `./shifu docs:prose:required`\n- `./shifu adr:audit -- --json`\n- `node scripts/buildchain-kfd-evidence.mjs --check`\n- staged source gate executed by the commit hook\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0123\"],\n  \"summary\": \"Clarify canonical and compatibility terminology plus semantic-independence qualification for the staged KFD-7 architecture\",\n  \"verification\": [\"docs:check\", \"docs:prose:required\", \"adr:audit\", \"buildchain KFD evidence check\", \"staged source gate\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-20T08:41:08Z",
          "mergedAt": "2026-07-20T08:53:39Z",
          "additions": 122,
          "deletions": 12,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1159,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1159",
          "title": "docs(exit): publish compatibility support policy",
          "body": "## Summary\n\nPublish Kungfu's user-facing Exit, migration, and version compatibility commitment as a machine-readable product contract and prominent documentation surface.\n\nThe policy answers the upgrade question directly: qualified stable releases on the same `major.minor` line preserve registered authoritative semantics, while physical provider layout, caches, performance, and presentation are outside that promise. The current v4 alpha remains exact-evidence-only, and cross-minor support requires a declared historical reader or qualified migration.\n\nThis linear delivery supersedes #1154, #1157, and #1158 after the target branch advanced. It preserves every qualified Project Cut source snapshot while making the current `dev/v4/v4.0` head a direct ancestor.\n\n## Related issue\n\nFollow-up to #1150.\n\n## Changes\n\n- add `supportPolicy` to the canonical Exit Bundle contract, including stable same-minor, pre-release, cross-minor, cross-major, support-window, qualification, and non-claim boundaries\n- expose product identity, exact contract roots, policy, qualification, and protocol inventories through installed `kungfu exit verify --info --json`\n- publish a canonical user guide and link it from the repository README, docs index/map, upgrade guide, product chooser, qualification index, and agent brief\n- bind retained claims to the exact qualified `darwin-arm64` artifact evidence and leave Linux, Windows, stable v4, GUI/TUI parity, cross-machine migration, physical-media durability, and the prior-minor support window explicitly unqualified\n- refresh contract registry roots, KFD evidence, and the Project Cut chain, including explicit empty Episode deltas for target-branch synchronization\n\n## Verification\n\n- full `./shifu check:source` acceptance: 490 passed, 1 Windows-only skip, 0 failed; Phase B, Agent Work, runtime upgrade, desktop adapter, TypeScript, Biome, Ruff, and mypy passed\n- Exit Bundle contract tests: 8 passed\n- Python Exit verifier tests: 5 passed\n- documentation gate: 0 Markdown lint errors, links/contracts passed, 63 negative fixtures passed\n- CLI catalog parity, Agent Pack, KFD evidence, JSON parsing, Ruff, and `git diff --check` passed\n- pre-commit staged gate passed\n- merge-safe Project Cut composition passed from current base `755d197c25d5f3f4daa9c95af1ec4b4ba8d7b043`\n- final delivery-sync Cut `sha256:90ac6697fea968ad29e9f51544822472d16da0bbe503c9cc08d0f670c14f1c28` verified and observed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0122\"],\n  \"summary\": \"Publish the bounded public compatibility commitment and installed discovery surface for the qualified Exit and migration closure.\",\n  \"verification\": [\"source acceptance\", \"Exit Bundle contract tests\", \"installed verifier tests\", \"documentation gate\", \"KFD evidence gate\", \"Project Cut composition\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes a public product support statement and exposes retained release evidence. It does not qualify a release, publish an artifact, or widen any platform claim; exact artifact and platform matching remain mandatory.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T09:10:25Z",
          "mergedAt": "2026-07-20T09:35:38Z",
          "additions": 613,
          "deletions": 76,
          "changedFiles": 88
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 214,
          "url": "https://github.com/kungfu-systems/kfd/pull/214",
          "title": "docs(kfd-7): distinguish ontology from action geometry",
          "body": "## Summary\n\n- define Fact-Episode Ontology as admitted state plus realized causal occurrence\n- limit Action Geometry to Pursuit, Atlas, and Warrant\n- classify the retained v2 five-value interface as two ontology bindings plus three action-Primitive mappings\n- publish Foundation Revision 6 without rewriting prior roots, activation cuts, or compatibility coordinates\n\n## Verification\n\n- `npm run update:evidence`\n- `npm run check`\n- JSON parse checks\n- `git diff --check`\n\n## Compatibility\n\nExisting package, schema, contract, and field identities remain readable. The revision changes the pre-stable decision surface and explicitly preserves historical bytes and roots.",
          "author": "dongkeren",
          "createdAt": "2026-07-20T09:37:30Z",
          "mergedAt": "2026-07-20T09:43:24Z",
          "additions": 292,
          "deletions": 246,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1161,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1161",
          "title": "docs(architecture): distinguish ontology from action geometry",
          "body": "## Summary\n\n- add ADR-0125 for the Fact-Episode Ontology and three-coordinate Action Geometry\n- project the two-plus-three distinction into human and agent discovery surfaces\n- preserve the combined-v1 contract identity while publishing explicit semantic layers\n- regenerate KFD-1/2/3 evidence and canonical contract roots\n\n## Related issue\n\nNone. This is the bounded implementation projection of KFD-7 Foundation Revision 6.\n\n## Changes\n\nFact and Episode now form the ontology of admitted state and realized causal occurrence. Pursuit, Atlas, and Warrant remain the Action Geometry Primitives. Domain Profiles bind the former two and map the latter three.\n\n## Verification\n\n- `./shifu check:agent-work-state-contract`\n- `./shifu kfd:buildchain:check`\n- `./shifu docs:check`\n- `./shifu docs:prose:required`\n- staged source gate\n- JSON parse checks\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0125\"],\n  \"summary\": \"Stage the Fact-Episode Ontology and three-coordinate Action Geometry across human, agent, contract, and evidence surfaces\",\n  \"verification\": [\"Agent Work contract tests\", \"Buildchain KFD evidence check\", \"deterministic documentation gate\", \"required prose gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change updates generated KFD evidence only; it does not publish or promote a release.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-20T09:37:30Z",
          "mergedAt": "2026-07-20T10:15:49Z",
          "additions": 457,
          "deletions": 180,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1164,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1164",
          "title": "feat(agent): separate Action Geometry from Domain Profile",
          "body": "## Summary\n\nSeparate KFD-7's cross-domain Action Geometry from the first-party Agent Work Domain Profile while preserving every combined-v1 compatibility identity. This final queue-compatible branch is linear from the latest `dev/v4/v4.0` base and incorporates the updated KFD/ADR baseline, including ADR-0125's explicit distinction between Fact/Episode ontology bindings and Pursuit/Atlas/Warrant Action Geometry mappings.\n\nSupersedes #1160 (merge-queue topology rejection), #1162 (correctly rejected by Source Acceptance because squashing historical Project Cuts destroyed publication chronology), and #1163 (base advanced before qualification).\n\n## Related issue\n\nAtlas goal `2026-07-20-kungfu-action-geometry-domain-profile-separation`.\n\n## Changes\n\n- add a versioned Action Geometry contract and domain-neutral evaluator\n- add the Agent Work Domain Profile declaration with five exact `/v2` role schemas\n- bind successor bodies to exact geometry, domain-profile, and role-schema roots and fail closed on drift\n- preserve legacy request, receipt, role-body, object-type, CLI, replay, recovery, and persisted-root identities\n- expose the same roots through the central KFD-1 registry, generic contract discovery, Agent capabilities, Work capabilities, and primitive-role capabilities\n- preserve the latest ADR-0125/KFD model: Fact and Episode are ontology bindings; Pursuit, Atlas, and Warrant are Action Geometry mappings\n- refresh checked-in Buildchain KFD-1/2/3 evidence\n- bound Project Cut reconciliation blob reads to projection-included paths and protocol evidence\n- publish a latest-baseline empty-Episode Project Cut after the linear source commit\n\n## Verification\n\n- full local pre-commit gate passed on both the source and Project Cut commits\n- `./shifu check:source` — build-free Source Acceptance passed; 492 Node tests (484 passed, 8 environment skips), Agent Work Python 39/39, upgrade 76/76, desktop 69/69, TypeScript, Ruff, mypy 176 files\n- `./shifu check:agent-work-state-contract` — Node 6/6 and Python 39/39 passed\n- `./shifu kfd:buildchain:check` — KFD-1 witness, four KFD-2 claims, and 136 KFD-3 surfaces passed\n- `./shifu check:shifu-documentation-contract` — 368 surfaces\n- `./shifu adr:audit -- --json` — passed with 132 records and zero structural findings\n- latest-baseline Project Cut `sha256:80c9511299aac13ac833885a46314405da626ee95f7c9eba2f7a1fdc785cabdb` binds source projection `sha256:22774f375fabf483880f07381cb0adeb2d269c049b8a3a0b6a952e7ea381db4b`, Atlas `sha256:a1fe23bff802ac076a578361446d91fe67e5834b0a336f06574f170ab182bfc9`, and an explicit empty Episode delta\n- scoped composition root `sha256:055b2affd533d6ebad37a398e4b517394d699a561716e283692f964c0fb44fed`; zero diagnostics\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0123\"],\n  \"summary\": \"Implement separately rooted Action Geometry and Agent Work Domain Profile contracts with exact successor bindings and preserved combined-v1 compatibility identities on the current ADR-0125/KFD baseline.\",\n  \"verification\": [\"Agent Work contract suites\", \"central KFD registry and Buildchain evidence\", \"documentation and ADR gates\", \"latest-baseline exact-root Project Cut\", \"independent completion review\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR extends public capability metadata and checked-in KFD evidence. It does not publish a release, mutate a runtime home, rename legacy identities, or claim cross-platform release qualification; ADR-0123 remains `staged`.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T10:31:31Z",
          "mergedAt": "2026-07-20T10:57:48Z",
          "additions": 1699,
          "deletions": 174,
          "changedFiles": 53
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 215,
          "url": "https://github.com/kungfu-systems/kfd/pull/215",
          "title": "feat(protocol): add Agent Hub alpha profile",
          "body": "## What\n\nAdd the experimental kfd-agent-hub@0.1.0-alpha.1 protocol profile, schemas, conformance fixtures, a reference state machine, an implementer guide, package exports, registry metadata, and a dedicated checker.\n\n## Contribution type\n\n- [ ] proposal or Candidate\n- [ ] evidence, counterexample, or independent review\n- [x] adopter Profile or implementation\n- [x] decision, registry, schema, verifier, or release surface\n- [x] governance, documentation, or maintenance\n\n## Claim and evidence\n\nThis is a non-numbered experimental protocol profile applying KFD-1, KFD-2, KFD-3, and KFD-7 to topology-neutral Agent Hub exchange. It defines explicit authority, admission, delivery, receipt, idempotency, replay, conflict, redaction, partial-replication, and reconnect semantics. It does not claim certification, adoption, ecosystem consensus, or industry-standard status. Evidence includes eight manifest-rooted surfaces, two positive fixtures, four adversarial fixtures, a machine-readable state model, and native package checks.\n\n## Interests and review\n\nKungfu implementation interest disclosed; no additional material interests known.\n\n- [x] A substantive change has a reviewer other than its author\n- [ ] Activation or Foundation Revision has an independent reviewer\n\n## Compatibility and registry agreement\n\n- [x] node scripts/check.mjs passes\n- [x] Applicability, compatibility, migration, and supersession impact are explicit\n- [x] Published coordinates remain immutable\n- [x] After Foundation Freeze, decision texts remain append-only (supersession over rewrite)\n\n## Version impact (per KFD-1)\n\n- [x] minor: additive registry, schema, package, and protocol-profile surfaces\n\n## Validation\n\n- npm run check\n- npm pack --dry-run --json\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-20T11:16:12Z",
          "mergedAt": "2026-07-20T11:19:16Z",
          "additions": 2731,
          "deletions": 97,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 216,
          "url": "https://github.com/kungfu-systems/kfd/pull/216",
          "title": "fix(protocol): bind Agent Hub fixture to merged cut",
          "body": "## What\n\nBind the Agent Hub valid fixture to the channel-reachable protocol commit created by PR #215, and reject repeated-character placeholder commit coordinates in the profile checker.\n\n## Contribution type\n\n- [ ] proposal or Candidate\n- [ ] evidence, counterexample, or independent review\n- [x] adopter Profile or implementation\n- [x] decision, registry, schema, verifier, or release surface\n- [x] governance, documentation, or maintenance\n\n## Claim and evidence\n\nPR #215 used rebase merge, so its fixture retained a valid but non-channel source commit. This follow-up binds the fixture to commit 3bd810255410ff9eb13d925a2d2f4e4e99481cc0 on dev/v1/v1.0, whose Agent Hub manifest digest exactly matches the fixture. The checker now rejects repeated-character placeholder commits. No protocol semantics or manifest-rooted surfaces change.\n\n## Interests and review\n\nKungfu implementation interest disclosed; no additional material interests known.\n\n- [x] A substantive change has a reviewer other than its author\n- [ ] Activation or Foundation Revision has an independent reviewer\n\n## Compatibility and registry agreement\n\n- [x] node scripts/check.mjs passes\n- [x] Applicability, compatibility, migration, and supersession impact are explicit\n- [x] Published coordinates remain immutable\n- [x] After Foundation Freeze, decision texts remain append-only (supersession over rewrite)\n\n## Version impact (per KFD-1)\n\n- [x] patch: fixture-coordinate correction and checker hardening\n\n## Validation\n\n- npm run check\n- exact manifest digest comparison against commit 3bd810255410ff9eb13d925a2d2f4e4e99481cc0\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-20T11:23:21Z",
          "mergedAt": "2026-07-20T11:26:27Z",
          "additions": 8,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 217,
          "url": "https://github.com/kungfu-systems/kfd/pull/217",
          "title": "feat(conformance): add KFD Runtime 100 profile",
          "body": "Publishes the experimental kfd-agent-runtime alpha profile with a fixed rooted Runtime 100 suite, JSONL adapter contracts, two topology-distinct reference adapters, artifact-bound reports, and offline native/WASM verification. Core remains 35 KFD-7 responsibility-separation vectors; 65 provisional vectors remain explicitly Experimental. Passing reports are non-qualifying and non-self-certified.",
          "author": "dongkeren",
          "createdAt": "2026-07-20T12:03:12Z",
          "mergedAt": "2026-07-20T12:06:15Z",
          "additions": 9439,
          "deletions": 135,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1165,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1165",
          "title": "refactor(fact): type kernel state and query proof",
          "body": "## Summary\n\nReplace correctness-sensitive internal Fact fold/state and query-proof JSON bags with typed C++ domain projections while preserving the Hana POD journal as the durable authority.\n\nPublic JSON edges, failure taxonomy, result hashes, C ABI and Python/Node surfaces remain compatible. Legacy KFR1 and portable KFR2 Root/Receipt identities remain unchanged. A fail-closed authority validator now rejects any mismatch between repeated typed metadata and the authoritative Hana record before state admission.\n\nDuring exact-root dogfooding, the repository exceeded Project Cut reconcile fixed-buffer assumptions. This PR also makes Git blob reads deterministic and size-bounded by batch, restores publication discovery for Cuts introduced directly by merge commits, and traces synthetic merge previews back to an identical side-parent publication.\n\n## Related issue\n\nAtlas goal 2026-07-20-kungfu-fact-kernel-typed-state.\n\n## Changes\n\n- add typed Fact object, version, relation, revocation, Cut, ref, transition, receipt, issue and conflict projections\n- add typed query operators, lineage, proof, schema and recursive row values\n- keep JSON parsing and rendering at explicit boundary adapters\n- validate repeated metadata, aggregate roots, record roots and Receipt authority before fold admission\n- add authority parity characterization and architecture boundary enforcement\n- read aggregate Git blobs through size-aware bounded batches during Project Cut projection\n- discover merge-introduced Cut publications through deterministic first-parent fallback\n- trace synthetic merge previews to an identical side-parent publication\n- synchronize delivery and qualification references with ADR-0098, ADR-0112 and ADR-0116\n- publish one source-qualified final Project Cut on merge-queue-compatible linear history\n\n## Verification\n\n- `./shifu build:core`\n- `./shifu test:fact-kernel-native` (28 passed)\n- Fact authority contracts (2 passed)\n- query CLI tests (13 passed)\n- Fact boundary contracts (11 passed)\n- canonical Root contracts (7 passed)\n- storage CLI tests (4 passed)\n- Project Cut settlement tests (11 passed)\n- Project Cut composition tests (14 passed)\n- `./shifu check:source` (494 passed, 1 platform skip, 0 failed)\n- `./shifu core:architecture` (0 findings)\n- C++ clang-format, Python Ruff and Biome checks\n- final Project Cut verify and composition verify passed with 0 diagnostics\n\n## Exact-root evidence\n\n- HEAD: `1f01b556a83c37353b76fead2d46e3e5e4f08245`\n- Git tree: `c8c37da8793c380224e3a0e68718c091ff9354f2`\n- Source tree before Cut evidence: `bf02a2ae6fa1298250013d1fad0455761dfae59b`\n- Project Cut: `sha256:9298a9bf4b526bc62bead67cd3cf97171918c7e7fba0c10e873a22262980e9d2`\n- Cut receipt: `sha256:851ad2f5ed965889e4f30c32894a8da4cceeb8ef20a20af3b214bf61e765beb7`\n- Commit observation receipt: `sha256:9c79696b6938847ae988ea1a236bc2bb88d60787fb986ea484144be5033d4b63`\n- Composition root: `sha256:9c5f83ad3ccf17963f7e46ace194f7ff25e05a27d9dcbf0273d310537a13f79e`\n- Completion Claim: `completion-770518f4167c95dfef83c502`\n- Independent exact-root review: FIT; Blocker 0, Major 0, Minor 0\n- Native Project Cut closeout gate: passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0098\", \"ADR-0112\", \"ADR-0116\"],\n  \"summary\": \"Type the internal Fact state and query-proof projections while preserving Hana authority and Root/Receipt identity, and keep Project Cut exact-root verification bounded and merge-safe.\",\n  \"verification\": [\"Core build and native Fact characterization\", \"authority parity and fail-closed mismatch tests\", \"query, boundary, canonical Root and architecture gates\", \"Project Cut settlement, composition and source acceptance gates\", \"qualified successor Cut and independent exact-root review\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR retains content-addressed Project Cut, Completion Claim and independent review evidence only. It does not publish or deploy a release.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T10:32:55Z",
          "mergedAt": "2026-07-20T12:54:35Z",
          "additions": 2509,
          "deletions": 601,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 274,
          "url": "https://github.com/kungfu-systems/build-images/pull/274",
          "title": "fix(comparator): make matched timeout symmetric",
          "body": "## Summary\n\n- apply the 1800-second durable-sync throughput/recovery timeout to both matched candidates\n- preserve the 600-second timeout for all other matched variants\n- cover Kungfu and Aeron with one symmetric regression test\n\n## Evidence\n\nThe retained `v1.3.0-alpha.7` formal run completed 412 samples without invariant failures, then timed out at schedule 412: Aeron / durable_sync / 64-byte / throughput. The subject remained active for the full 600 seconds (~702 CPU-seconds, ~740 MB written, ~249 MB peak RSS), while the preceding 10k-record durable-sync latency sample required ~103 seconds. The symmetric 100k-record throughput sample needs the existing 1800-second budget already assigned to Kungfu.\n\n## Verification\n\n- `python3 -m unittest pilots.comparator.tests.test_formal_performance` (19 tests)\n- `pnpm run check` (109 qualification tests; KFD123 and Release Passport smoke pass)\n- alpha/stable Buildchain contract locks unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-20T13:15:51Z",
          "mergedAt": "2026-07-20T13:19:22Z",
          "additions": 27,
          "deletions": 24,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 218,
          "url": "https://github.com/kungfu-systems/kfd/pull/218",
          "title": "refactor(kfd): establish canonical terminology contracts",
          "body": "Merge refactor/kfd-nomenclature-contract into dev/v1/v1.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-20T13:19:10Z",
          "mergedAt": "2026-07-20T13:22:44Z",
          "additions": 2153,
          "deletions": 1372,
          "changedFiles": 52
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 275,
          "url": "https://github.com/kungfu-systems/build-images/pull/275",
          "title": "chore(release): prepare v1.3.0-alpha.8",
          "body": "## Summary\n\n- advance the v1.3 prerelease version to `1.3.0-alpha.8`\n- keep Buildchain alpha/stable contract locks unchanged\n- preserve Release Passport and GitHub Release publication\n\n## Included fix\n\n- symmetric 1800-second timeout for Kungfu and Aeron durable-sync throughput/recovery workloads (#274)\n\n## Verification\n\n- `pnpm run check` (109 qualification tests)\n- KFD123 passed\n- Release Passport smoke passed\n- alpha/stable Buildchain contract locks unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-20T13:20:48Z",
          "mergedAt": "2026-07-20T13:24:01Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 276,
          "url": "https://github.com/kungfu-systems/build-images/pull/276",
          "title": "chore(release): promote v1.3.0-alpha.8",
          "body": "## Promotion\n\nPromote `dev/v1/v1.3` to `alpha/v1/v1.3` for `v1.3.0-alpha.8`.\n\n## Included changes\n\n- symmetric durable-sync throughput/recovery timeout for Kungfu and Aeron matched candidates\n- alpha version metadata update\n\n## Release contract\n\n- Buildchain channel: `@v2-alpha`\n- contract lock: unchanged\n- release passport: enabled\n- GitHub release: enabled\n- selective publish should rebuild `comparator-formal-runner` and reuse unaffected images\n\n## Verification\n\n- PR #274 checks passed\n- PR #275 checks passed\n- 109 qualification tests passed\n- KFD123 and Release Passport smoke passed",
          "author": "dongkeren",
          "createdAt": "2026-07-20T13:24:19Z",
          "mergedAt": "2026-07-20T13:27:27Z",
          "additions": 29,
          "deletions": 26,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1427,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1427",
          "title": "feat(release): verify anchored derived material",
          "body": "## Summary\n\n- add a validated anchored/manual `version.derived_files` contract\n- fail before heavy builds on stale, hand-edited, or undeclared release material\n- repeat derivation and exact-tree checks during promotion and bind SHA-256 evidence into release passports\n- align optional release propagation controller stages with the workflow receipt\n- verify the existing managed badge refresh, consumer check, and DCO propagation flow\n\n## Validation\n\n- `pnpm run check` (717 tests)\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org/`\n- anchored KFD-1/KFD-3 fixture and protected promotion regression\n- action bundle integrity check (4 bundles)\n- train: `train/v2/v2.3/open-issues-alpha` at `453e987327e78ed35945f84aa7fae2edfcbbd01f`\n\nCloses #1380\nCloses #1424\nCloses #1426",
          "author": "dongkeren",
          "createdAt": "2026-07-20T13:37:25Z",
          "mergedAt": "2026-07-20T13:43:02Z",
          "additions": 1421,
          "deletions": 207,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1428,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1428",
          "title": "chore(release): promote v2.14.4-alpha.0",
          "body": "## Release intent\n\nPromote the reviewed `dev/v2/v2.14` mainline into the protected alpha channel.\n\n- source: `dev/v2/v2.14@22e64b5efd07ea3afdaa9e8c13e46705434ae8a6`\n- current alpha source: `alpha/v2/v2.14@8e9810cc5f8da5ba14699a114ce201e291356fc8`\n- selected immutable candidate: `v2.14.4-alpha.0`\n- npm dist-tag target: `alpha`\n- implementation PR: #1427\n- issues: #1380, #1424, #1426\n\nThe repository-owned promotion workflow must create and verify version state, publish evidence, GitHub prerelease assets, exact/floating refs, and self-dogfood evidence. No direct npm or protected-ref mutation is authorized.",
          "author": "dongkeren",
          "createdAt": "2026-07-20T13:44:55Z",
          "mergedAt": "2026-07-20T13:48:10Z",
          "additions": 1846,
          "deletions": 251,
          "changedFiles": 51
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 219,
          "url": "https://github.com/kungfu-systems/kfd/pull/219",
          "title": "docs(kfd): harden core object terminology",
          "body": "## Summary\\n\\n- define canonical explanatory subtitles for Fact, Episode, Atlas, Pursuit, and Warrant\\n- encode the Fact/Episode plus Atlas/Pursuit/Warrant structure in the terminology contract and site bundle\\n- add fail-closed anti-misreading checks and refresh KFD-1/2/3 witnesses and the offline verifier\\n\\n## Verification\\n\\n- npm run check\\n- node bin/kfd.mjs verify kfd-record terminology.json\\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-20T14:00:02Z",
          "mergedAt": "2026-07-20T14:13:11Z",
          "additions": 741,
          "deletions": 213,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1429,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1429",
          "title": "fix(build): preserve stable runtime compatibility",
          "body": "## Summary\n\n- keep the anchored-material preflight additive across mixed workflow-shell/runtime versions\n- prefer the selected runtime verifier and fall back to the trusted workflow-shell verifier only when the older stable runtime predates it\n- install workflow-shell dependencies only on fallback and retain fail-closed behavior if neither verifier exists\n- add regression coverage and regenerate the public contract digest\n\n## Evidence\n\n- Follow-up to #1427 after alpha self-dogfood exposed the compatibility gap\n- Failing evidence: https://github.com/kungfu-systems/buildchain/actions/runs/29748750689/job/88375851328\n- `pnpm run check`: 717/717 tests, workflow/site/action bundle checks passed\n- npm pack dry-run: 246 files\n\n## Version impact\n\nPatch repair inside the already-declared v2.14 minor surface.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T14:17:16Z",
          "mergedAt": "2026-07-20T14:22:10Z",
          "additions": 49,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1430,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1430",
          "title": "chore(release): promote v2.14.4-alpha.1",
          "body": "## Alpha promotion\n\n- source: `dev/v2/v2.14@3c1529cbfa2d5ebe46704ec2b027326afa91feb1`\n- current alpha: `alpha/v2/v2.14@496ea46c13504043755faf5e0ca720e76526af2b`\n- exact candidate selected from live tags and release-state refs: `v2.14.4-alpha.1`\n- includes follow-up compatibility fix from #1429 after the `v2.14.4-alpha.0` self-dogfood finding\n\nPublication must be performed only by the repository-owned protected promotion transaction after this PR passes required checks and merges. Do not publish or move tags directly.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T14:23:02Z",
          "mergedAt": "2026-07-20T14:26:49Z",
          "additions": 49,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1167,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1167",
          "title": "fix(fact): harden kernel qualification boundaries",
          "body": "## Summary\n\nHarden the Fact kernel review boundaries without changing canonical Root preimages, portable wire layouts, or retained semantic evidence.\n\n## Related issue\n\nAtlas goal: 2026-07-20-kungfu-fact-kernel-review-hardening\n\n## Changes\n\n- gate qualification fault injection behind an explicit process-level qualification switch\n- validate every root-list member and bound untrusted portable record counts before allocation\n- consolidate portable schema metadata and centralize failure taxonomy, including integrity failures\n- derive durable request IDs from the full operation identity while preserving legacy replay fallback\n- template repeated fold authority handling and split durable admission and import phases\n- add deterministic fold-scaling qualification and retain the measured defer-acceleration decision\n- bind the required Project Cut settlement with an explicitly empty Episode delta\n\n## Verification\n\n- ./shifu rebuild:core\n- ./shifu test:fact-kernel-native (39 passed)\n- ./shifu check:fact-kernel-boundary (13 passed)\n- ./shifu check:fact-root-canonical (7 passed)\n- ./shifu test:fact-kernel-integrity (5 passed)\n- ./shifu test:fact-kernel-dogfood (1 passed)\n- ./shifu test:fact-kernel-fold-performance (2 passed)\n- staged repository gate and git diff --check\n- full ./shifu check reaches three pre-existing ADR-0049 qualification assertions in files unchanged by this branch: two invariant-stage expectations and one frozen native-header digest\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0112\"],\n  \"summary\": \"Harden the delivered backend-neutral Fact kernel qualification and maintenance boundaries without changing canonical protocol bytes.\",\n  \"verification\": [\"Fact native characterization, boundary, canonical-root, integrity, dogfood, and fold-performance qualification suites\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release-evidence boundary is limited to the content-addressed Project Cut settlement. Its exact generated outputs passed the staged repository gate and the committed settlement was observed at 11bf8c6423d1c2b38ee4df2cc0db13d4a5c73c21.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated where behavior changed\n- [x] Focused qualification suites pass\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T13:49:02Z",
          "mergedAt": "2026-07-20T14:32:22Z",
          "additions": 1025,
          "deletions": 434,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 221,
          "url": "https://github.com/kungfu-systems/kfd/pull/221",
          "title": "chore(kfd): anchor alpha 40 release",
          "body": "## Summary\n\n- anchor `@kungfu-tech/kfd` at `1.0.0-alpha.40`\n- refresh generated KFD-1, KFD-2, and KFD-3 release witnesses\n- preserve the fixed `v1.0` outer line and Buildchain alpha promotion contract\n\n## Verification\n\n- `npm run update:evidence`\n- `npm run check`\n- `npm pack --dry-run --json`\n- `git diff --check`\n\n## Release path\n\nAfter this PR merges, promote `dev/v1/v1.0` to `alpha/v1/v1.0` through the protected same-repository PR path. Buildchain will publish npm and GitHub Release from the verified alpha branch.",
          "author": "dongkeren",
          "createdAt": "2026-07-20T14:57:49Z",
          "mergedAt": "2026-07-20T15:01:38Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 223,
          "url": "https://github.com/kungfu-systems/kfd/pull/223",
          "title": "release(kfd): promote v1.0.0-alpha.40",
          "body": "## Release\n\nPromote the verified KFD development line to `alpha/v1/v1.0` for `@kungfu-tech/kfd@1.0.0-alpha.40`.\n\n## Provenance\n\n- source branch: `dev/v1/v1.0`\n- target branch: `alpha/v1/v1.0`\n- anchored version: `1.0.0-alpha.40`\n- anchor PR: #221\n\nThe successful Verify push on the protected alpha branch will trigger Buildchain ref promotion, npm publication, GitHub Release creation, release passport generation, and downstream propagation.",
          "author": "dongkeren",
          "createdAt": "2026-07-20T15:02:14Z",
          "mergedAt": "2026-07-20T15:05:40Z",
          "additions": 14594,
          "deletions": 1196,
          "changedFiles": 92
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1432,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1432",
          "title": "fix(release): preserve pinned stable shell compatibility",
          "body": "## Summary\n\n- declare inputs unsupported by the immutable stable promotion shell in the routing authority\n- filter those inputs only from the stable generated call while preserving alpha forwarding\n- add regression coverage for the pinned-shell compatibility boundary\n- refresh the generated Buildchain contract projection\n\n## Verification\n\n- `corepack pnpm run check`\n- `actionlint .github/workflows/release-candidate-promote.yml`\n- `git diff --check`\n\nCloses #1431\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T15:24:22Z",
          "mergedAt": "2026-07-20T15:29:18Z",
          "additions": 30,
          "deletions": 7,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1433,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1433",
          "title": "chore(release): promote v2.14.4-alpha.2",
          "body": "## Release intent\n\nPromote the verified `dev/v2/v2.14` state to the alpha channel after fixing the public promotion router's pinned stable-shell compatibility boundary.\n\n- fixes #1431\n- unblocks KFD `1.0.0-alpha.40` publication\n- preserves the immutable stable shell while forwarding invariant-passport inputs on the alpha route\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T15:30:13Z",
          "mergedAt": "2026-07-20T15:32:52Z",
          "additions": 30,
          "deletions": 7,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1169,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1169",
          "title": "feat(core): add KFD Agent Runtime reference adapter",
          "body": "## Summary\n\nAdd Kungfu's product-owned KFD Agent Runtime reference adapter over the public\nlibkungfu C ABI, and bind its claim to the published KFD Runtime 100 profile\nand suite.\n\nThe current local qualification is intentionally limited to the exact\ndarwin/arm64 artifact. The promotion-only workflow can produce separately\nrooted Linux x64, macOS ARM64, and Windows x64 reports; this PR does not claim\nthose unobserved platform results or external adoption.\n\n## Related issue\n\nAtlas goal `2026-07-20-kungfu-kfd-conformance-reference-runtime`.\n\n## Changes\n\n- add the C++ JSONL adapter over public embedding ABI v5 and native-storage ABI v1\n- persist accepted transitions as Episodes while keeping rejected transitions write-free\n- add Runtime 100 qualification, independent offline verification, an always-accept negative control, SIGKILL/reopen recovery, and fsck evidence\n- stage the adapter and manifest into frozen and CLI distributions\n- expose installed/source discovery through `kungfu sdk kfd agent-runtime status --json`\n- qualify the same target in the promotion-only cross-platform membrane workflow\n- publish an explicit empty-Episode Project Cut for this source delivery\n\n## Verification\n\n- `./shifu check:source` — 493 tests, 492 passed, 1 skipped, 0 failed; Python, desktop, type, formatting, and documentation gates passed\n- `./shifu build:core`\n- `./shifu freeze`\n- `./shifu kfd:agent-runtime:qualify -- --kfd-root /Users/dkr/Code/kungfu-systems/kfd` — Core 35/35 and Experimental 65/65 on darwin/arm64, with independent verifier pass\n- `./shifu dist:cli`\n- `./shifu gate run embedding.membranes --capability native-toolchain --capability rust`\n- `./shifu docs:check:readonly`\n- `actionlint .github/workflows/embedding-membrane-spike.yml`\n\nProject Cut: `sha256:9474a59ca464011afc2f41478965f2db9ae34813c962ca302ccc6e174b394259`.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0120\"],\n  \"summary\": \"Deliver the public-ABI KFD Agent Runtime reference adapter and exact artifact qualification surface\",\n  \"verification\": [\"Source Acceptance\", \"KFD Runtime 100\", \"core build and freeze\", \"CLI distribution smoke\", \"embedding membrane gate\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change adds exact artifact qualification and promotion-only evidence\ncollection. It does not publish a package or deploy a service. Evidence is\nbounded by source commit, artifact digest, profile, suite root, platform, and\nindependent verifier output.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-20T15:35:39Z",
          "mergedAt": "2026-07-20T16:18:56Z",
          "additions": 1860,
          "deletions": 39,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1435,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1435",
          "title": "feat(passport): add KFD agent runtime conformance evidence",
          "body": "## Summary\n\nAdd a first-class KFD Agent Runtime conformance Passport gate that binds exact Profile and suite roots, product source commits, platform reports, adapter release artifacts, and an explicit non-inferred claim level. Buildchain remains the release-binding authority while the packaged @kungfu-tech/kfd offline WASM verifier remains the conformance authority.\n\n## Related issue\n\nAtlas goal: `2026-07-20-buildchain-kfd-conformance-passport`\n\n## Changes\n\n- add the `kfd-agent-runtime` witness and Passport contracts plus public Node API\n- independently rerun retained reports with KFD alpha.40 packaged WASM and bind exact artifacts/platforms/Core closure\n- distinguish `tested`, `independently-verified`, `reference-adopter`, and `externally-adopted` without inference\n- fail closed on stale roots, partial platforms, producer-only verification, tampering, and missing adoption evidence\n- wire the witness through the CLI, promotion action, reusable workflow, site registries, docs, and managed action/SEA bundles\n- retain a real Kungfu PR #1169 consumer canary and deliberate negative fixtures\n\n## Verification\n\n- `pnpm run check` (654 tests passed; inventory, site, workflows, and all action bundles passed)\n- `pnpm run pack:check`\n- standalone SEA public CLI test passed with the embedded exact KFD verifier bytes\n- KFD Agent Runtime focused suite: 12/12 passed\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change extends release evidence and promotion inputs. It does not publish a release or move stable refs. Exact-root negative fixtures, full workflow checks, action builds, SEA verification, and package dry-run provide the boundary evidence.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-20T16:56:53Z",
          "mergedAt": "2026-07-20T16:59:53Z",
          "additions": 1979,
          "deletions": 167,
          "changedFiles": 38
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1170,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1170",
          "title": "feat(xinfa): link compiler into trunk",
          "body": "## Summary\n\nLink Xinfa into the native Rust trunk and expose it as `kungfu xinfa`, replacing the product-owned standalone engine while preserving the existing compiler roots and boundary allowlist.\n\nThis delivery deliberately rejects an MJS rewrite. The component remains Rust-native and one-way linked from `kungfu-trunk`; a future Wasm surface, if any, is a separate decision.\n\n## Related issue\n\nAtlas goal `2026-07-20-kungfu-xinfa-trunk-component`.\n\n## Changes\n\n- split the Xinfa CLI dispatcher into a reusable Rust library plus a thin standalone compatibility binary\n- link the library into `kungfu-trunk` and add the native `kungfu xinfa` subcommand\n- route Python and Shifu source entrypoints through the assembled trunk without arbitrary PATH engine discovery\n- remove the private `xinfa-engine` product artifact and stage the public Xinfa contract beside `kungfu-trunk`\n- preserve exact project, authority, context-pack, and Atlas roots across direct, extracted, and Shifu paths\n- update ADR-0126, boundary contracts, extraction manifests, product smoke tests, and empty-delta Project Cut evidence\n\n## Verification\n\n- `./shifu check:source` — 497 contract tests, 496 passed and 1 Windows-only skip; Python, mypy, Biome, docs, Project Cut, and KFD gates passed\n- `cargo test --locked --manifest-path crates/Cargo.toml -p kungfu-trunk` — 44 passed\n- `./shifu xinfa:check` — 43 Xinfa library tests passed\n- `./shifu xinfa:standalone` — byte-identical project, authority, pack, and Atlas roots preserved\n- `./shifu xinfa:quality --check` — 31 cases and 11 routes passed\n- `./shifu xinfa:dogfood` — direct, extracted, and Shifu roots are equal\n- `./shifu dist:cli` — cold native/Electron/Wasm/Python build and installed-layout smoke passed\n- product distribution contract tests — 18 passed; archive contains `runtime/kungfu-trunk` and no `xinfa-engine`\n\nProject Cut: `sha256:b62fd9f944efb60bac75a596beae8d40eabdb812f25dbc37325771045fad07de`.\nIndependent completion review: `fit` (`sha256:ab5d50886821b80da37b4998f494121be571bada89579fdce3ecf9f92134098c`).\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0126\"],\n  \"summary\": \"Link Xinfa into kungfu-trunk as the native kungfu xinfa component and retire the standalone product engine\",\n  \"verification\": [\"Source Acceptance\", \"Xinfa exact-root qualification\", \"CLI distribution smoke\", \"Project Cut independent review\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change alters the CLI distribution layout but does not publish a package or deploy a service. Product smoke and archive contract tests prove the linked trunk is staged and the retired private engine is absent.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-20T16:17:34Z",
          "mergedAt": "2026-07-20T17:30:11Z",
          "additions": 1599,
          "deletions": 947,
          "changedFiles": 46
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 277,
          "url": "https://github.com/kungfu-systems/build-images/pull/277",
          "title": "fix(comparator): budget durable-sync throughput runs",
          "body": "## Summary\n\n- allow 3600 seconds for the frozen 100,000-message durable-sync throughput workload\n- retain 1800 seconds for the 10,000-message durable-sync recovery workload\n- apply both workload-derived budgets symmetrically to Kungfu and Aeron\n- preserve the 600-second limit for latency, soak, and non-durable-sync variants\n\n## Evidence\n\nThe single `v1.3.0-alpha.8` formal run passed the previous Aeron timeout boundary: schedule 412 completed in 981 seconds. It then stopped without retry at schedule 413 because the Kungfu 100,000-message durable-sync throughput sample exceeded 1800 seconds. The preceding 10,000-message Kungfu durable-sync latency sample required 241 seconds, so the frozen throughput workload requires a bounded 3600-second budget.\n\nRetained evidence: https://github.com/kungfu-systems/build-images/issues/248#issuecomment-5025895687\n\n## Verification\n\n- `python3 -m py_compile images/comparator-formal-runner/opt/formal-performance/bin/formal-performance-provider`\n- `python3 -m unittest pilots.comparator.tests.test_formal_performance` (19 tests)\n- `pnpm run check` (109 qualification tests; KFD123 and Release Passport smoke pass)\n- alpha/stable Buildchain contract locks unchanged\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T18:45:12Z",
          "mergedAt": "2026-07-20T18:47:56Z",
          "additions": 12,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 279,
          "url": "https://github.com/kungfu-systems/build-images/pull/279",
          "title": "chore(release): prepare v1.3.0-alpha.9",
          "body": "## Summary\n\n- advance the v1.3 prerelease state to `1.3.0-alpha.9`\n- publish the reviewed durable-sync throughput timeout budget from PR #277\n\n## Verification\n\n- `pnpm run check` (109 qualification tests; KFD123 and Release Passport smoke pass)\n- alpha/stable Buildchain contract locks unchanged\n\nRelated to #248.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T18:49:13Z",
          "mergedAt": "2026-07-20T18:51:56Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1149,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1149",
          "title": "fix(invariant): qualify Fact native harness cross-platform",
          "body": "## Summary\n\nMake the Fact native invariant route genuinely cross-platform and keep its durability claims honest. The invariant runner remains generic and delegates every checker through Shifu; the Fact-owned harness supplies the source-tree Python boundary, native build paths, bounded process-tree timeout, and explicit foreign-runtime admission on macOS, Linux, and Windows.\n\nThis follow-up to #1147 is integrated with current `dev/v4/v4.0` and carries one replay-safe queue Cut. The rebase-only merge queue head `79f69faa0d22eca1dd4ed2e1205acad0958fc30d` / tree `07dfd49c072ff346374b7eaa4c9262093d4ea735` contains two linear commits: the exact implementation delta replayed onto base `258828447c4c5b408fe9e5d41e0d39c0dea4e210`, followed by its independently replayable Project Cut publication. Superseded non-mainline Cut attempts remain only in Git/Mission Control audit history.\n\nProject Cut: `sha256:9c8cbb3b7089b068b05d8e488152f8dc8daac0b7487c9d55bb718bca3444df65` at commit `79f69faa0d22eca1dd4ed2e1205acad0958fc30d`, source projection `sha256:4cdbbb178086d0328e19ddb4cdc4a10f652a872e70471d8d458a676ae71e946e`, Xinfa Atlas `sha256:b089c99b4aaf47530009d23466fb2c82a9dbce9a46994b25bc344edceef7ec5c`. This is a fresh mainline publication root because prior invariant-project Cuts never entered the queue base; Project Cut composition admits it with root `sha256:8bfbd437c7505e57af52fc5b17c7586e8e1aa7caae5a94b40934be7098de1d83` and zero diagnostics.\n\n## Changes\n\n- add `scripts/run-fact-kernel-native-tests.mjs` as the owned cross-platform Fact native harness;\n- preserve `KUNGFU_ALLOW_FOREIGN_RUNTIME=1` for the intentional source-Python plus built-native qualification boundary;\n- include single-config and multi-config native build locations in `PATH` and `PYTHONPATH`;\n- expose bounded checker diagnostics and terminate the complete Windows process tree on timeout;\n- decode Fact fixtures explicitly as UTF-8;\n- drain multiprocessing queues before joining producers, avoiding Windows feeder-thread deadlock;\n- await actual peer-process termination before asserting terminal lifecycle state;\n- stop calling unsupported `FlushFileBuffers` on Win32 directory handles;\n- open the Win32 Fact journal with a writable `CreateFileW` handle before `FlushFileBuffers`, fixing the five exact Windows durable-admission/fault-frontier failures;\n- report Windows Fact journal durability as `file-sync-without-directory-flush` with `directory_synced=false`, while retaining POSIX file-plus-directory-sync evidence;\n- bind retained Fact qualification to every `fact_*.cpp`/`fact_*.h` storage module plus the public Fact Kernel interface, so future internal decomposition fails closed instead of drifting outside the evidence set;\n- reconcile ADR-0124 implementation and closure metadata from closed PR #1141 to the actually merged PR #1147.\n\n## Verification\n\n- staged repository gate — passed, including invariant 15/15, docs 63/63, ADR audit, C++ format, and Biome;\n- `./shifu check:fact-durable-admission` — 2/2;\n- exact fresh agent-120 build `./shifu test:fact-kernel-native` — 39/39;\n- exact fresh agent-120 build `./shifu test:invariant-system` — 15/15;\n- retained current-hardware candidate — 13/13 durable admission/fault-frontier cases on Linux x64, ext4, NVMe; this does not claim physical power-loss or production qualification;\n- prior diagnostic matrix: https://github.com/kungfu-systems/kungfu/actions/runs/29748241425 — macOS/Linux passed and Windows isolated the writable-file-flush defect;\n- final exact-task-head macOS/Linux/Windows matrix: https://github.com/kungfu-systems/kungfu/actions/runs/29762568598 — six jobs passed; all three full-profile artifacts bind `d984d3614db7a18e9f03f337d53239b2f293b2b7` / tree `2475d14564f4d9b974bc8272c5a00df049adb86d`, with 51/51 invariant coordinates verified;\n- queue linearization proof — the implementation delta `057d4579cd843b2a2413ad26f4957926d45bf3f1..d984d3614db7a18e9f03f337d53239b2f293b2b7` applied cleanly to latest base, then Project Cut `sha256:9c8cbb3b7089b068b05d8e488152f8dc8daac0b7487c9d55bb718bca3444df65` was generated from the exact staged tree; local scoped composition passed with zero diagnostics, and fresh PR/merge-group gates qualify the queue head;\n- the collected Passport `sha256:7fbde723e3e6338c4ba2092e946e5044002ee18caa034ba81df8d9bbfca38d43` remains intentionally `unqualified`: invariant coverage is complete, while candidate artifacts and exact installed-product qualification for all three release platforms were not supplied by this PR qualification run. Buildchain rejects that Passport instead of promoting invariant coverage into a release claim.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0124\"],\n  \"summary\": \"Reconcile ADR-0124 to the merged implementation PR while repairing its cross-platform qualification evidence without changing the accepted invariant semantics.\",\n  \"verification\": [\"source acceptance\", \"adversarial invariant tests\", \"fresh Fact native qualification\", \"fresh Project Cut observation\", \"three-platform invariant matrix\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis repairs qualification evidence collection and narrows an unsupported Windows durability claim. It performs no publishing, deployment, release promotion, or runtime activation.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation remains accurate; no user-facing behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T04:57:28Z",
          "mergedAt": "2026-07-20T18:53:03Z",
          "additions": 338,
          "deletions": 127,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 280,
          "url": "https://github.com/kungfu-systems/build-images/pull/280",
          "title": "chore(release): promote v1.3.0-alpha.9",
          "body": "## Summary\n\nPromote the reviewed durable-sync throughput timeout budget and `1.3.0-alpha.9` version state from `dev/v1/v1.3` to the protected alpha channel.\n\n## Evidence\n\n- fix: PR #277\n- version state: PR #279\n- retained alpha.8 failure evidence: https://github.com/kungfu-systems/build-images/issues/248#issuecomment-5025895687\n\n## Release contract\n\nAfter merge, a successful `Verify` run on `alpha/v1/v1.3` must trigger Buildchain `v2-alpha` publication with `release-passport=true` and `github-release=true`. No manual tag or release creation is permitted.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T18:52:10Z",
          "mergedAt": "2026-07-20T18:55:16Z",
          "additions": 14,
          "deletions": 8,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1171,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1171",
          "title": "feat(agent): add OpenCode libkungfu embedding reference",
          "body": "## Summary\n\nAdd a concrete OpenCode reference integration that preserves the vendor-owned TUI, model/provider routing, accounts, permissions, cloud connection, and customer relationship while embedding libkungfu only for native Episode facts, recovery, portable evidence, and the KFD Runtime 100 report.\n\nThis is a private reference package and qualification candidate. It does not claim OpenCode endorsement, universal compatibility, external adoption, or a published package.\n\n## Related issue\n\nFollow-up to #1155.\n\n## Changes\n\n- add `examples/opencode-kungfu` as an exact public-plugin-seam reference with lifecycle hooks and a bounded tool\n- retain no prompts, tool arguments/results/errors, provider/model/token/account data, or credential material, and leave hook output unchanged\n- recover unsealed Episodes on startup while assigning a new Episode to the resumed vendor session\n- add C, Node, and Python quickstarts over the same native authority\n- add a disposable clean-install qualification with OpenCode discovery, SIGKILL/restart recovery, 100 paired hooks, native export/import/fsck, and exact KFD Runtime 100 evidence\n- preserve unsigned 64-bit Episode IDs across the Node service edge and restrict generic transfer operations to export/import\n- let an exact active successor anchor superseded same-PR Cut replay mismatches after merge-queue linearization while retaining explicit omissions and failing closed on active or unanchored drift\n- retain a thin public Episode bundle for Project Cut while keeping native journals and private runtime bytes out of Git\n- document the boundary, verification command, and explicit residual risks\n\n## Verification\n\n- vendor qualification passed on `darwin/arm64`, Node `v22.22.3`, OpenCode `1.18.3`, and pnpm `10.9.8`\n- 100 paired public-hook samples passed; p50 `1.183 ms`, p95 `2.400 ms`, p99 `3.450 ms`, max `3.788 ms`\n- forced `SIGKILL` recovered 1 unsealed Episode; native export/import/fsck passed for Episode `9568181418175688493`\n- exact KFD Runtime 100 report passed all 100 vectors (`35` Core, `65` Experimental), with offline verifier valid\n- plugin tests, Node storage-transfer regression, C/Node/Python quickstarts, exact packed clean install, docs final-ready, and `git diff --check` passed\n- merge-queue replay regression passed red-to-green; full Project Cut composition suite passed 15/15 and local Source Acceptance passed 501 Node tests plus 39 and 76 Python tests\n- exact-root successor Project Cut `sha256:2c555ff848de196df32dd5ae416d2055d7a470dbc98706b3d9bbb2f8e4bc29c5` observed at final head `7eeb5bd1b45492f4da27eaacbe63eddfd6245176`; Completion Claim `completion-1cd3d5e9a820c4691f82ba60` admitted with an empty Episode delta after merge-queue replay repair\n- local full `./shifu check` reached documentation-consumer tests, where a spawned Xinfa verifier remained macOS `launched-suspended`; the same command run directly verified the exact Atlas successfully, and an unrelated pre-existing worktree is stalled in the same launcher state. GitHub required checks remain the independent full-suite authority.\n\nResidual qualification limits: only `darwin/arm64` was observed, the public hook shape was tested without invoking a model provider, `SIGKILL` is not physical power loss, and no vendor endorsement or adoption is asserted.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0116\", \"ADR-0120\", \"ADR-0124\"],\n  \"summary\": \"Deliver a bounded OpenCode reference integration that preserves vendor ownership while using the accepted libkungfu authority, exact invariant evidence boundaries, and merge-queue-safe successor Cut composition.\",\n  \"verification\": [\"vendor embedding qualification\", \"KFD Runtime 100\", \"native Episode export/import/fsck\", \"plugin and binding regressions\", \"Project Cut observation\", \"merge-queue replay composition\", \"Completion Claim\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe integration observes only OpenCode's public npm plugin shape and deliberately avoids model/provider calls, account access, payload retention, hosted-service replacement, usage attribution, and publication. The reference package is private; public qualification evidence is exact-root-bound and excludes native journal bytes.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T18:27:24Z",
          "mergedAt": "2026-07-20T20:06:52Z",
          "additions": 1670,
          "deletions": 23,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1436,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1436",
          "title": "Release v2.14.4 from qualified v2.14.4-alpha.2",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.4-alpha.2`\n- Candidate SHA: `ca8823dee47b809ac1509387a1db26e0f488c73a`\n- Selection: `latest-qualified`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-20T20:17:56Z",
          "mergedAt": "2026-07-20T20:19:05Z",
          "additions": 2134,
          "deletions": 285,
          "changedFiles": 60
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 136,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/136",
          "title": "feat(site): add embeddable runtime developer entry",
          "body": "## Outcome\n\nMake `libkungfu.dev` the concrete embeddable runtime entry: vendor-owned product → libkungfu → KFD → vendor-owned Hub.\n\n## Changes\n\n- project the exact reviewed Kungfu PR #1171 source, mainline, Project Cut, KFD Runtime 100 suite root, qualification, and claim boundary into `/runtime.json`\n- lead the human homepage with architecture, C/Node/Python quickstarts, package availability, privacy boundary, measured evidence, and known limits\n- keep KFD/Buildchain/Core as release-trust evidence rather than the product definition\n- align `@kungfu-tech/kfd` with the already-propagated alpha.39 lock so the current baseline builds\n- fail closed if source/Cut/suite roots drift or a public install is invented\n\n## Validation\n\n- `npm run build`\n- `npm run check`\n- `git diff --check`\n- JSON and shell syntax checks\n- Chrome desktop 1440px and mobile 390px: no console errors or horizontal page overflow\n- local route audit: `/`, `/core/`, `/buildchain/`, `/kfd/`, `/papers/`, `/runtime.json` all 200; no heading skips, duplicate IDs, unnamed links, or missing image alt text\n\n## Claim boundary\n\nThis is first-party `reference-adopter` evidence only. No public registry artifact, external vendor adoption, certification, OpenCode endorsement, physical-loss qualification, or unobserved platform claim is made.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-20T20:24:32Z",
          "mergedAt": "2026-07-20T20:33:33Z",
          "additions": 512,
          "deletions": 30,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 137,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/137",
          "title": "fix(site): keep runtime styles out of paper archives",
          "body": "## Fix\n\nPR #136 added runtime-specific CSS to the shared page template. Buildchain staging correctly rejected the deploy because that changed an already-published immutable paper path.\n\nThis follow-up scopes the CSS to the hub homepage and adds a regression assertion that runtime selectors never enter the retained paper HTML. It does not overwrite or delete the existing S3 object.\n\n## Evidence\n\n- failing staging expected `9cf5968e…`, existing immutable object was `62400cb1…`\n- fixed staging build produces exactly `62400cb160e80ca7047ed2913e28d43c3d6995a34b4408a3e89e39d397b9166e`\n- changing the CI timestamp does not change that digest\n- `npm run build` and `npm run check` pass\n- `git diff --check` passes\n\nProduction remains gated and was skipped in the failed main run.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-20T20:39:12Z",
          "mergedAt": "2026-07-20T20:48:47Z",
          "additions": 159,
          "deletions": 147,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 38,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/38",
          "title": "feat(site): add Agent Builder adoption path",
          "body": "## Summary\n\nAdd a secondary Agent Builder path without changing the Cost / State / Proof consumer first screen.\n\n## Changes\n\n- add a For Agent Builders navigation item and below-first-screen homepage callout\n- add /agent-builders/ with the vendor-owned product -> libkungfu -> KFD -> vendor-owned Hub architecture\n- bind runtime facts to exact reviewed source and keep the future Kungfu Cloud boundary explicit\n- extend shared-layout, build, and fail-closed site checks for the new route\n\n## Verification\n\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- bash -n scripts/build-site.sh scripts/check-site.sh\n- jq empty site/shared-layout.json\n- git diff --check\n- Chrome 1440x900 and 390x844: no overflow, console errors, duplicate IDs, or unnamed links\n- all local routes and exact external evidence links returned HTTP 200\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe page uses existing Kungfu/libkungfu/KFD/Buildchain names and exact public evidence links. It does not claim a current Kungfu Cloud product, external vendor adoption, certification, or an unapproved libkungfu.dev production machine route. Production remains governed by the existing Buildchain release PR flow.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-20T21:10:31Z",
          "mergedAt": "2026-07-20T21:20:37Z",
          "additions": 570,
          "deletions": 7,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1438,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1438",
          "title": "fix(web): grant release intent pull request read access",
          "body": "## Summary\n\n- grant the reusable Web Surface `release-intent` job the minimal `pull-requests: read` permission it requires\n- add a regression assertion for the exact job-level permission\n- regenerate the public contract world (audit digest only; breaking and compatibility digests remain unchanged)\n\n## Why\n\nA `main` push in `kungfu-systems/site-kungfu-tech` failed before staging with `403 Resource not accessible by integration` while calling `repos.listPullRequestsAssociatedWithCommit`. The reusable workflow globally narrows permissions to `actions: read` and `contents: read`, and the `release-intent` job did not restore the documented API requirement (`pull_requests=read`). Pull-request preview runs did not exercise this main-only path.\n\nFailing run: https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29779809115\n\n## Validation\n\n- `pnpm run check:workflows`\n- `node --test tests/build-surface.test.mjs` (82 passed)\n- `pnpm run check` (717 passed; action bundles current)\n- `git diff --check`\n\n## Contract impact\n\n- breaking digest: unchanged\n- compatibility digest: unchanged\n- audit digest: updated\n\nSupersedes #1437, which was closed only to restore the intended author/reviewer identity separation.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T21:25:50Z",
          "mergedAt": "2026-07-20T21:29:01Z",
          "additions": 9,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1439,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1439",
          "title": "chore(release): promote v2.14.4-alpha.2",
          "body": "## Release intent\n\nPromote the current `dev/v2/v2.14` line to `alpha/v2/v2.14` through the protected Buildchain release path.\n\n## Included fix\n\n- #1438 grants the reusable Web Surface `release-intent` job the minimal `pull-requests: read` permission required by `listPullRequestsAssociatedWithCommit`\n- regression coverage and the generated public contract audit digest are current\n- breaking and compatibility digests are unchanged\n\n## Validation\n\n- PR #1438: independent exact-head approval, full Verify, Build Surface Fixture, and merge-group Verify passed\n- local `pnpm run check`: 717 passed\n- downstream failure being repaired: https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29779809115\n",
          "author": "dongkeren",
          "createdAt": "2026-07-20T21:30:07Z",
          "mergedAt": "2026-07-20T21:31:29Z",
          "additions": 9,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1441,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1441",
          "title": "Release v2.14.5 from qualified v2.14.5-alpha.0",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.5-alpha.0`\n- Candidate SHA: `9324835dcdd6e7611fe268c6551ffd4ef8284161`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-20T21:48:58Z",
          "mergedAt": "2026-07-20T21:51:47Z",
          "additions": 25,
          "deletions": 19,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1175,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1175",
          "title": "chore(project-cut): publish Agent Hub trunk successor",
          "body": "## Summary\n\nPublish the reviewed Project Cut history for goal `2026-07-20-kungfu-kfd-agent-hub-standardization` and a merge-safe successor rooted in current `dev/v4/v4.0`.\n\n- completion Cut: `sha256:f4f8b476b57b38419cda4dc14045a87655b7d0c9e2e35a3865fe8538cc379542`\n- current-trunk successor: `sha256:3543abb73fc500c6e86df705f1b3798d5e58fd50cbeac6fe1740905ccd53e27d`\n- current source projection: `sha256:c9a90c256549466bad4e3aa15a1c83c7a84c54a64cff783019062d28fb097ec2`\n\n## Verification\n\n- `GITHUB_BASE_REF=dev/v4/v4.0 node scripts/check-project-cut-composition-gate.mjs` -> qualified, no diagnostics\n- `node scripts/check-project-cut-contract.mjs`\n- JSON parse and diff checks\n- pinned Biome check for all eight JSON objects\n- historical objects byte-compared to reviewed source commit `e20015bca84dbcede967681e2988f9296b68b075`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Publish immutable Project Cut history and a current-trunk successor without altering architecture contracts or runtime behavior\"\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes only content-addressed Project Cut evidence; scoped composition and Source Acceptance are the admission authority.",
          "author": "dongkeren",
          "createdAt": "2026-07-20T22:36:06Z",
          "mergedAt": "2026-07-20T22:42:24Z",
          "additions": 8,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1152,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1152",
          "title": "feat(core): qualify KFD-7 library boundary",
          "body": "## Summary\n\nDeliver the KFD-7 end-state native library boundary: a narrow three-symbol\n`libkungfu` facade with one successor C bootstrap, provider-neutral Fact\nauthority in source/static `libyijinjing`, installed C/C++ consumer\ncoordinates, and fail-closed conformance evidence while retaining both legacy\nbootstraps unchanged.\n\n## Related issue\n\nAtlas goal `2026-07-19-kungfu-kfd7-library-boundary-abi`.\n\n## Changes\n\n- add `kungfu_get_api` v1 with independently versioned discovery, stream,\n  ledger-action, and maintenance tables;\n- freeze opaque-handle, caller-sized-struct, explicit-release, numeric-status,\n  thread-affinity, cancellation, protocol/schema/encoding, and ActionBinding\n  root semantics;\n- export exactly three public bootstrap symbols from the installed facade and\n  move the implementation surface behind private `libkungfu_runtime`;\n- move generic Fact record/receipt pairing, replay verification, recovery\n  classification, and exact snapshot export into source/static\n  `libyijinjing`;\n- retain fail-closed truncated/unknown-schema replay hardening and qualify\n  Windows checkpoint evidence without claiming POSIX directory-fsync semantics;\n- install public C/C++ headers, `KungfuConfig.cmake`, machine contracts,\n  examples, and a consumer guide;\n- add clean external C, C++, and source-static consumers plus\n  Darwin/Linux/Windows full-profile qualification and retained reports;\n- keep `kungfu_embedding_get_api` v1-v5 and\n  `kungfu_native_storage_get_api` v1 as compatibility-only surfaces.\n\n## Verification\n\nFinal delivery head: `dacd9d6d68b0e523fda1d74934d299f85428a75f` against\n`dev/v4/v4.0` at `462a6c16e0608e0cbf71d8d304ddd3192e79ffc3`.\n\n- `./shifu check:source` — exact-head source, docs, architecture, type, format,\n  lint, runtime-upgrade, desktop-update, native Fact, and KFD-7 contract gates\n  passed; 1 Windows-only test was skipped on macOS\n- full local Core build and 25/25 native CTests passed during qualification\n- Fact native characterization and integrity — 39/39 focused tests passed\n- public facade symbol audit — exactly `kungfu_get_api`,\n  `kungfu_embedding_get_api`, and `kungfu_native_storage_get_api`\n- [exact-head Core build profiles run 29781276961](https://github.com/kungfu-systems/kungfu/actions/runs/29781276961)\n  — full and embedded-minimal profiles passed on Darwin arm64, Linux x64, and\n  Windows x64 at `dacd9d6d68b0e523fda1d74934d299f85428a75f`\n- retained installed-consumer reports prove clean external C/C++ consumers,\n  source-static `language_hosts=0`, and exact ActionBinding root\n  `sha256:c156cb56fc16603689f6b875985ed7b7d92bec5d5d5b76adc2f75c67fabb3739`\n- retained current-hardware durable-admission report root\n  `sha256:816935b96145c6e0cb301cbf0023e78fb40e3c8e26d81479d7efee455a7bcf70`\n  passed on the agent-120 Linux x64 ext4/NVMe envelope\n- final reviewed Project Cut\n  `sha256:2f52bb214d64b69685c439b286eeca54742fe7cd420b1d17e714709e84ad2e8d`\n  records an explicit empty Episode delta and a close continuation decision\n\n## Qualification boundary\n\nThis PR claims a consumer-ready, pre-release v1 C ABI and source/static\ncoordinate on the supported three-platform matrix. Protocol, schema, encoding,\nwrong-thread, busy, stale-handle, and cancel-before-admission paths fail closed.\nCancellation and timeout do not preempt an already admitted native call;\nRust/Python/Node successor wrappers remain experimental, and external adoption,\nlong-term binary stability, or battle-tested maturity is not claimed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0120\"],\n  \"summary\": \"Implement and qualify the KFD-7 successor C ABI, source-static reality kernel boundary, installed consumer kit, compatibility membrane, and exact supported-platform evidence.\",\n  \"verification\": [\"source acceptance\", \"full Core build\", \"25 native CTests\", \"Fact characterization and integrity\", \"installed C and C++ consumers\", \"source-static language-host-free consumer\", \"exact public symbol policy\", \"Darwin arm64, Linux x64, and Windows x64 full/minimal matrix\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis adds the pre-release `Kungfu::kungfu` native package coordinate and\nqualification evidence. It performs no package publication, deployment,\nchannel promotion, credential access, or real-system mutation.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-20T07:07:27Z",
          "mergedAt": "2026-07-20T23:05:38Z",
          "additions": 3869,
          "deletions": 514,
          "changedFiles": 75
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 111,
          "url": "https://github.com/kungfu-systems/libnode/pull/111",
          "title": "chore(release): prepare libnode alpha 21",
          "body": "## Summary\n- declare anchored derived version material and lifecycle.version-state\n- accept Buildchain v2.14.5 stable/alpha contract locks\n- prepare 22.22.3-kf.3-alpha.21 for one-pass three-platform validation\n\n## Local verification\n- buildchain validate --require-version-state --require-lifecycle-stages install,build,version-state,verify,publish\n- pnpm sync-kfd-witnesses (idempotent)\n- pnpm verify-release\n- pnpm verify-kfd-witnesses\n- pnpm verify-package-source\n- pnpm pack --dry-run\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-20T23:39:37Z",
          "mergedAt": "2026-07-20T23:50:26Z",
          "additions": 27,
          "deletions": 19,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 225,
          "url": "https://github.com/kungfu-systems/kfd/pull/225",
          "title": "docs(kfd): add action and software-domain layers",
          "body": "## Summary\n\n- promote Atlas, Pursuit, and Warrant into numbered draft KFD-8, KFD-9, and KFD-10\n- add draft KFD-11 for the software work responsibility lifecycle\n- add draft KFD-12 for Project Cut settlement without authority fusion\n- state explicitly that KFD-11 and KFD-12 are software-domain applications, not universal workflows for other domains\n- update candidate lineage, terminology, formal/usage pages, site projection, and KFD-1/2/3 witnesses\n\n## Verification\n\n- `npm run check`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T00:25:15Z",
          "mergedAt": "2026-07-21T00:28:43Z",
          "additions": 1975,
          "deletions": 348,
          "changedFiles": 42
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 281,
          "url": "https://github.com/kungfu-systems/build-images/pull/281",
          "title": "fix(comparator): add durable-sync timeout headroom",
          "body": "## Summary\n\n- raise only the matched `durable_sync` throughput timeout from 3600 to 5400 seconds\n- keep `durable_sync` recovery at 1800 seconds and all other matched workloads at 600 seconds\n- preserve candidate symmetry and cover the new bound in the provider unit test\n\n## Evidence\n\nThe retained `v1.3.0-alpha.9` formal run passed full-stack 378/378 and schedule 412 at attempt 1, then schedule 413 wrote 234,743,205,888 bytes over 3,597.7 seconds before the 3600-second provider timeout. Cleanup removed all residue and no retry was attempted. The 5400-second bound supplies 50% headroom over the observed near-complete run while remaining workload-specific and bounded.\n\nIssue evidence: https://github.com/kungfu-systems/build-images/issues/248#issuecomment-5028799863\n\n## Verification\n\n- `python3 -m unittest pilots.comparator.tests.test_formal_performance` (19 tests)\n- `pnpm run check` (109 qualification tests, KFD123, Passport smoke)\n- alpha/stable Buildchain contract locks unchanged\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T00:33:28Z",
          "mergedAt": "2026-07-21T00:36:17Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 283,
          "url": "https://github.com/kungfu-systems/build-images/pull/283",
          "title": "chore(release): prepare v1.3.0-alpha.10",
          "body": "## Summary\n\n- bump the package version to `1.3.0-alpha.10`\n- align the Buildchain release-impact declaration\n\n## Verification\n\n- `pnpm run check`\n- 109 comparator tests passed\n- KFD123 and Release Passport smoke passed\n- alpha and stable contract locks unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-21T00:37:20Z",
          "mergedAt": "2026-07-21T00:40:15Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 284,
          "url": "https://github.com/kungfu-systems/build-images/pull/284",
          "title": "chore(release): promote v1.3.0-alpha.10",
          "body": "## Summary\n\nPromote the validated `dev/v1/v1.3` state to the alpha release channel for `v1.3.0-alpha.10`.\n\n## Release controls\n\n- Buildchain alpha contract lock: `v2-alpha`\n- Release Passport: enabled\n- GitHub release: enabled\n- no manual tag or release creation",
          "author": "dongkeren",
          "createdAt": "2026-07-21T00:40:27Z",
          "mergedAt": "2026-07-21T00:43:07Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1443,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1443",
          "title": "fix(release): reconcile routed build checks",
          "body": "## Summary\n\n- add a stable top-level aggregate to the public build channel router\n- derive and idempotently reconcile stale protected-branch aggregate contexts from an already-tested pull request SHA\n- enforce release-propagation workflow and controller stage vocabulary equality in source checks\n- add a libnode-shaped `build.yml@v2` consumer fixture and reconciliation documentation\n\n## Verification\n\n- `pnpm run check`\n- `pnpm run pack:check`\n- live dry-run against libnode PR #112 candidate `4fa074877b7263c1a32727eac4fb993c47776147`\n\nCloses #1434.\nCloses #1442.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T00:46:08Z",
          "mergedAt": "2026-07-21T00:54:53Z",
          "additions": 889,
          "deletions": 33,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 227,
          "url": "https://github.com/kungfu-systems/kfd/pull/227",
          "title": "docs(kfd): name initiative and assignment",
          "body": "## Summary\n\n- define `Initiative` as KFD-11's continuing coordinated software-work context\n- define `Assignment` as its independently addressable bounded responsibility\n- remove `Mission` and `Go` from current normative KFD surfaces while preserving historical live-case evidence\n- update the formal model, terminology contract, standards metadata, site bundle, and KFD-1/2/3 witnesses\n\n## Verification\n\n- `npm run update:evidence`\n- `npm run check`\n- `git diff --check`\n- decision and formal hashes match `standards.json`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T00:56:01Z",
          "mergedAt": "2026-07-21T00:59:22Z",
          "additions": 276,
          "deletions": 208,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1445,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1445",
          "title": "chore(release): promote v2.14.5-alpha.1",
          "body": "## Release intent\n\nPromote the current `dev/v2/v2.14` line to `alpha/v2/v2.14` through the protected Buildchain release path.\n\n## Included fixes\n\n- #1434 adds a static release-propagation controller/descriptor stage-alignment gate so stable `v2` cannot drift from the declared public stage contract\n- #1442 adds a stable caller-level build aggregate plus idempotent required-check reconciliation for already-tested candidate SHAs\n- the libnode-shaped fixture now dogfoods the public build router and proves both the nested and caller-level aggregate checks\n\n## Validation\n\n- PR #1443: independent exact-head approval, full Verify, Build Surface Fixture, and merge-group Verify passed\n- post-merge Verify on `dev/v2/v2.14` passed: https://github.com/kungfu-systems/buildchain/actions/runs/29791668222\n- local `pnpm run check`: 722 passed\n- local `pnpm run pack:check`: passed\n- live libnode candidate dry-run preserves unrelated branch policy and proposes only the stale Buildchain aggregate replacement\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T00:56:50Z",
          "mergedAt": "2026-07-21T01:00:05Z",
          "additions": 889,
          "deletions": 33,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1447,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1447",
          "title": "Release v2.14.6 from qualified v2.14.6-alpha.0",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.6-alpha.0`\n- Candidate SHA: `4414293013b252120828a331519132baaa0e2520`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T01:13:05Z",
          "mergedAt": "2026-07-21T01:14:27Z",
          "additions": 905,
          "deletions": 49,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 112,
          "url": "https://github.com/kungfu-systems/libnode/pull/112",
          "title": "release: publish libnode 22.22.3-kf.4",
          "body": "## Summary\n- promote the tested v22.22.3-kf.3-alpha.21 tree to stable 22.22.3-kf.4\n- carry Buildchain v2.14.5 anchored derived-material declarations and accepted stable/alpha locks\n- limit alpha-to-release changes to package.json, libnode.release.json, and the two declared KFD witnesses\n\n## Buildchain preflight\n- latest alpha: v22.22.3-kf.3-alpha.21 @ 858bce0c45b15c2a0886f046ec3e0b427b4ff5b0\n- anchored derived material: verified\n- allowed paths == changed paths (4 files)\n- clean-checkout verify-release / verify-kfd-witnesses / verify-package-source / pack --dry-run passed\n- Buildchain v2.14.5 config validation passed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T00:00:15Z",
          "mergedAt": "2026-07-21T01:20:47Z",
          "additions": 1572,
          "deletions": 159,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 138,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/138",
          "title": "Release production from a99441327038",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `a99441327038864bb0b05170a11277b81aabf722`\n- Artifact hash: `c215ca6d9c62d009bb9d71019785a27c309b516eec8a31a2200bc81d69b39d47`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29777669535)\n- Required label: `buildchain-release`\n- Release branch: `release/production-a99441327038`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-20T20:59:04Z",
          "mergedAt": "2026-07-21T01:28:37Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 228,
          "url": "https://github.com/kungfu-systems/kfd/pull/228",
          "title": "docs(kfd): settle software work primitives",
          "body": "## Summary\n\n- preserve the two KFD-4 perspective transformations that exposed Initiative, Assignment, and Project Cut\n- add independent KFD-5 version 3 qualification cuts accepting each object within its bounded software-domain layer\n- project the live case through KFD-11/12, usage docs, MAP, foundation, site bundle, and KFD-1/2/3 evidence\n- keep KFD-11/12 activation, cross-domain universality, historical novelty, and private Agent-origin authorship outside the accepted claims\n\n## Review focus\n\n- Initiative and Assignment remain software-work organization Primitives, not aliases for lower action coordinates\n- Project Cut remains a higher-layer settlement Primitive, not a fourth fact engine or peer action coordinate\n- maintainer testimony about Agent-origin genesis stays separate from public repository evidence\n- accepted candidate cuts do not activate the draft KFD-11 or KFD-12 decisions\n\n## Verification\n\n- `npm run update:evidence`\n- `npm run check`\n- `npm pack --dry-run --json` (all 10 live-case files included)\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-21T01:32:35Z",
          "mergedAt": "2026-07-21T01:36:05Z",
          "additions": 2838,
          "deletions": 100,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1177,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1177",
          "title": "docs(product): center work on Project Cut",
          "body": "## Summary\n\nDefine the Project Cut-centered product loop for Kungfu v4.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- make Project Cut the ordinary project settlement interface\n- define Initiative and Assignment as the Agent Work organization layer\n- specify the first kungfu cut command design and v4 qualification gate\n- register the public terminology and documentation routes\n\n## Verification\n\n- ./shifu docs:check\n- ./shifu docs:prose:required\n- ./shifu adr:audit -- --json\n- ./shifu check:source\n- ./shifu docs final-ready --since origin/dev/v4/v4.0 --budget 66560 --json (review-required, zero violations, parity matched)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0127\"],\n  \"summary\": \"Complete the bounded product-model and initial architecture design stage\",\n  \"verification\": [\"docs gate, prose gate, ADR audit, source gate, and documentation final-ready receipt\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T02:01:26Z",
          "mergedAt": "2026-07-21T02:09:50Z",
          "additions": 741,
          "deletions": 14,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 43,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/43",
          "title": "feat(site): explain the Hub architecture visually",
          "body": "## Summary\n\n- replace the linear builder stack with an intuitive libkungfu action-world loop\n- show two independently owned Hubs exchanging responsibility through KFD without a central KFD authority\n- expose the Delivery versus Admission, Occurrence versus Completion, and Authentication versus Authority invariants\n- link exact semantic source commits and the live libkungfu runtime facts endpoint\n\n## Validation\n\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- git diff --check\n- desktop visual inspection\n- 390px mobile visual inspection with no horizontal overflow\n\nGoal: 2026-07-21-kungfu-kfd-hub-architecture-visualization",
          "author": "dongkeren",
          "createdAt": "2026-07-21T03:00:36Z",
          "mergedAt": "2026-07-21T03:04:33Z",
          "additions": 288,
          "deletions": 65,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 230,
          "url": "https://github.com/kungfu-systems/kfd/pull/230",
          "title": "docs(kfd): add consequential settlement layer",
          "body": "## Claim and evidence\n\n- Allocates KFD-11 to the cross-domain Claim -> Assessment -> Decision -> Admission procedure.\n- Renumbers the prerelease software work and Project Cut drafts to KFD-12 and KFD-13 under an explicit Foundation Revision.\n- Publishes a Field Responsibility Matrix separating kernel, cross-domain, Domain Profile, and participant-projection fields.\n- Adds a versioned KFD-11 schema plus KFD-1, KFD-2, KFD-3, site, registry, standards, and witness projections.\n\n## Interests and review\n\nThe maintainer authorized this pre-stable correction. Independent review by kungfu-origin is required before merge because the latest numbered routes change. Immutable historical commits, package coordinates, digests, rendered artifacts, and KFD-5 cuts are preserved.\n\n## Compatibility and registry agreement\n\n- Impact: major / breaking.\n- Package line remains v1.0 under pre-stable Foundation Revision policy.\n- Migration: old KFD-11 -> current KFD-12; old KFD-12 -> current KFD-13.\n- The next commit will bind this PR URL into the machine revision record, closing the only intentionally pending gate.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T03:00:16Z",
          "mergedAt": "2026-07-21T03:05:46Z",
          "additions": 2760,
          "deletions": 774,
          "changedFiles": 48
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 141,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/141",
          "title": "feat(site): visualize action world and Hub network",
          "body": "## Summary\n\n- replace the misleading linear runtime stack with a complete Fact Cut to Action Geometry to ActionBinding to Episode to local admission loop\n- add a two-participant KFD network that keeps each Hub control plane local and makes the responsibility boundary explicit\n- pin exact Kungfu and KFD source commits, document hashes, profile coordinates, and public claim boundaries\n- retain source data as a machine-readable fixture while keeping the visual responsive and semantic\n\n## Validation\n\n- npm run build\n- npm run check\n- git diff --check\n- desktop visual inspection\n- 390px mobile visual inspection with no horizontal overflow\n- manual SHA256 verification of the four pinned source documents\n\nGoal: 2026-07-21-kungfu-kfd-hub-architecture-visualization",
          "author": "dongkeren",
          "createdAt": "2026-07-21T03:00:33Z",
          "mergedAt": "2026-07-21T03:06:39Z",
          "additions": 610,
          "deletions": 40,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 44,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/44",
          "title": "Release production from 93897f317457",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `93897f317457e7e51705c657251da6a5155538e8`\n- Artifact hash: `55c9d4db5600987f976b138d5fce28250d05e40488299708ec9931bf61c150bb`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29797536236)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-93897f317457`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-21T03:06:43Z",
          "mergedAt": "2026-07-21T03:07:40Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 231,
          "url": "https://github.com/kungfu-systems/kfd/pull/231",
          "title": "docs(kfd): close foundation revision evidence",
          "body": "## Claim and evidence\n\nThis is the post-merge evidence closure for substantive PR #230. It records the actual kungfu-origin approval, reviewed head, merge commit, and merge time in the Foundation Revision machine map and refreshes all dependent KFD witnesses.\n\n## Interests and review\n\nNo KFD semantics, numbering, field ownership, or compatibility classification changes. The source facts are the immutable review and merge records of #230.\n\n## Compatibility and registry agreement\n\nPatch-level evidence closure only. The underlying Foundation Revision remains major/breaking as already declared. The package gate now rejects a revision record that stops at a merely declared review coordinate.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T03:10:38Z",
          "mergedAt": "2026-07-21T03:14:08Z",
          "additions": 74,
          "deletions": 61,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 46,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/46",
          "title": "chore(ci): accept Buildchain v2.14.6 contract",
          "body": "## Summary\n\n- regenerate the stable production contract lock from exact Buildchain v2.14.6 commit 8e19b5ad70ffda5540df967bd009bd4ffef0af5a\n- accept the new release-candidate-promote and controller surfaces required by the current stable runtime\n- preserve the alpha lock and every production approval gate\n\n## Cause\n\nProduction release run 29797686849 failed closed because the prior stable lock did not recognize the v2.14.6 release-candidate-promote breaking digest.\n\n## Validation\n\n- exact-runtime contract lock check: unchanged and compatible\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- git diff --check\n\nGoal: 2026-07-21-kungfu-kfd-hub-architecture-visualization",
          "author": "dongkeren",
          "createdAt": "2026-07-21T03:13:19Z",
          "mergedAt": "2026-07-21T03:16:59Z",
          "additions": 55,
          "deletions": 5,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 47,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/47",
          "title": "Release production from 5aa6b92c29aa",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `5aa6b92c29aa9c7bcbdc07484822e1054aa00858`\n- Artifact hash: `55c9d4db5600987f976b138d5fce28250d05e40488299708ec9931bf61c150bb`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29798121481)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-5aa6b92c29aa`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-21T03:19:00Z",
          "mergedAt": "2026-07-21T03:21:46Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 143,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/143",
          "title": "chore(buildchain): refresh stable v2 contract lock",
          "body": "## Summary\n- refresh the stable v2 contract lock to Buildchain v2.14.6 (8e19b5a)\n- accept the current release-candidate promotion surface and advanced promotion workflow\n- restore fail-closed staging and production promotion checks\n\n## Validation\n- exact-runtime contract lock check: unchanged / compatible\n- corepack pnpm@11.9.0 install --frozen-lockfile\n- npm run build\n- npm run check\n- stable canary workflow: run 29798149914 (success)\n- git diff --check\n\nGoal: 2026-07-21-kungfu-kfd-hub-architecture-visualization",
          "author": "dongkeren",
          "createdAt": "2026-07-21T03:20:29Z",
          "mergedAt": "2026-07-21T03:32:06Z",
          "additions": 11,
          "deletions": 6,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 232,
          "url": "https://github.com/kungfu-systems/kfd/pull/232",
          "title": "docs(kfd): trace decision admission genesis",
          "body": "## Claim and evidence\n\n- Records the KFD-4 transformation from numbered-noun allocation to the state-admission authority perspective.\n- Preserves maintainer testimony that the Agent introduced Admission and compressed the four roles into one procedure; human authorization remains a later governance fact.\n- Adds a provisional KFD-5 Consequential Settlement cut with deletion, fuse, alternatives, falsifiers, and first-party evidence limits.\n- Projects the live case through KFD-11, its source candidate, Foundation Revision, MAP, site bundle, and KFD-1/2/3 witnesses.\n\n## Authorship boundary\n\nThe private genesis transcript is not retained. Maintainer testimony supports Agent-origin candidate generation. Public Git proves the later formalization, schema, review, and merge, while commit `ebb29ef` declares `Agent: Codex`; it does not independently prove the private utterance.\n\n## Review focus\n\n- Do not rewrite human authorization as human candidate generation.\n- Confirm that the procedure is provisional rather than cross-domain accepted.\n- Confirm that Claim/Assessment remain KFD-2 responsibilities, Decision remains Warrant-bound, and Admission remains independently owned by the target Fact authority.\n- Confirm that four responsibilities do not imply four physical objects or user steps.\n\n## Verification\n\n- `npm run update:evidence`\n- `npm run check`\n- `npm pack --dry-run --json`\n- `git diff --cached --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-21T03:38:04Z",
          "mergedAt": "2026-07-21T03:42:24Z",
          "additions": 1308,
          "deletions": 93,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1182,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1182",
          "title": "chore(project-cut): bind Hub architecture visualization delivery",
          "body": "## Summary\n\nBind the Hub architecture visualization delivery to the exact Kungfu source projection and Xinfa Atlas. The Cut intentionally declares an empty runtime Episode delta because the delivered changes are evidence-bound site visualizations, not a Kungfu runtime behavior change.\n\n## Related issue\n\nAtlas goal: 2026-07-21-kungfu-kfd-hub-architecture-visualization\n\n## Changes\n\n- add content-addressed Project Cut f58f9be5bb76\n- promote the exact input Atlas 8c8ea84f6809\n- preserve empty Episode delta and bridge authority semantics\n\n## Verification\n\n- project-cut prepare dry-run and execute passed\n- project-cut verify passed\n- project-cut commit-observe published exact commit 32730287f8b063fde2b8463bde1079cf23b92006\n- full pre-commit staged gate passed\n- documentation final-ready verdict passed\n- independent review on superseded declaration PR #1180 was fit and approved by kungfu-origin\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This chore records content-addressed delivery evidence for external documentation sites and does not alter a Kungfu architecture or runtime behavior contract\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe Project Cut is public, content-addressed provenance only; no private runtime journals or credentials are included.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed; no runtime behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T03:37:48Z",
          "mergedAt": "2026-07-21T03:46:51Z",
          "additions": 11,
          "deletions": 0,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 144,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/144",
          "title": "Release production from 92630f4a0f23",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `92630f4a0f23ba5a460748d2ce2320f7e45e7d10`\n- Artifact hash: `27801871147cc9bc0aa61a4b85fe01c57114266bb9622699369a04617faa963f`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29798780103)\n- Required label: `buildchain-release`\n- Release branch: `release/production-92630f4a0f23`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-21T03:40:34Z",
          "mergedAt": "2026-07-21T03:49:49Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 233,
          "url": "https://github.com/kungfu-systems/kfd/pull/233",
          "title": "docs(kfd): preserve settlement development lineage",
          "body": "## Summary\n- trace Claim and Assessment to agent-generated KFD-2 execution design on 2026-07-11\n- trace Decision to the agent-generated Mission/Go lifecycle and later independent review dogfood\n- preserve Fact Admission as an earlier independent line and record the later cross-domain compression\n- publish the corrected lineage through the live-case registry, site bundle, and KFD-3 witness\n\n## Validation\n- npm run update:evidence\n- npm run check\n- git diff --check\n- npm pack --dry-run --json\n\n## Evidence boundary\nPublic Git proves chronology and implementation. Retained maintainer-held transcripts plus maintainer testimony support conversational attribution but are not included in the public package.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T04:14:08Z",
          "mergedAt": "2026-07-21T04:18:11Z",
          "additions": 975,
          "deletions": 282,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1184,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1184",
          "title": "feat(agent-work): bind continuity release evidence",
          "body": "## Summary\n\nBind the continuity-first launch promise to an explicit, fail-closed qualification contract: one-minute smoke evidence, matched long-task comparison evidence, and public animation evidence are separate profiles with exact boundaries.\n\n## Changes\n\n- extend the Agent Work State contract from FO1-FO8 to FO1-FO10\n- define the public continuity outcome as \"Keep the work when the chat ends.\"\n- add machine-readable positive and negative continuity evidence fixtures\n- keep Cost / State / Proof and the four-role model out of first-contact copy\n- make Buildchain Release Passport binding conditional on the exact Kungfu claim and evidence set\n- regenerate canonical policy and KFD projections\n\n## Verification\n\n- `./shifu check:agent-work-state-contract`\n- `./shifu kfd:buildchain:check`\n- `./shifu docs:check:readonly`\n- `./shifu check:source`\n- pre-commit staged gate\n\nNo full long-task comparison was run in this PR; the comparison profile is a release-evidence contract, not a fabricated result.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0109\"],\n  \"summary\": \"Bind continuity-first release evidence profiles and fail-closed qualification boundaries\",\n  \"verification\": [\"agent-work-state contract tests\", \"KFD Buildchain evidence check\", \"documentation gates\", \"full source gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes release-evidence semantics only. It does not publish, deploy, or bind a comparative result.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T04:11:49Z",
          "mergedAt": "2026-07-21T04:42:52Z",
          "additions": 1055,
          "deletions": 124,
          "changedFiles": 45
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 234,
          "url": "https://github.com/kungfu-systems/kfd/pull/234",
          "title": "docs(kfd): link early autonomous discovery evidence",
          "body": "## Summary\n- identify the Consequential Settlement lineage as an early retained KFD-6 natural pre-enactment\n- map the observed development loop onto KFD-6 formal objects without claiming conformance or activation\n- preserve missing gates: autonomous trigger, predeclared cut, method comparison, baselines, held-out evaluation, and false-candidate rejection\n- expose the relationship through KFD-6 decision, formal/usage docs, MAP, live case, site bundle, and KFD witnesses\n\n## Validation\n- npm run update:evidence\n- npm run check\n- git diff --check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-21T04:46:02Z",
          "mergedAt": "2026-07-21T04:50:02Z",
          "additions": 214,
          "deletions": 99,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 235,
          "url": "https://github.com/kungfu-systems/kfd/pull/235",
          "title": "docs(kfd): preserve Episodes as historical assets",
          "body": "## Summary\n- establish well-formed Episodes as durable historical assets on the README first screen\n- define KFD-6 stewardship, replay value, and retention/privacy/migration boundaries\n- preserve the distinction between Episode accumulation and qualified Primitive discovery\n\n## Verification\n- npm run check\n- git diff --check\n- npm pack --dry-run --json\n- site bundle first-screen and KFD-6 usage assertions",
          "author": "dongkeren",
          "createdAt": "2026-07-21T05:02:03Z",
          "mergedAt": "2026-07-21T05:07:51Z",
          "additions": 142,
          "deletions": 92,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 145,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/145",
          "title": "feat(site): publish public dogfood evidence",
          "body": "## Summary\n\n- publish a full public dogfood evidence page and machine-readable JSON snapshot\n- add a compact proof rail to the libkungfu.dev home page\n- make the 30-day GitHub metrics reproducible and bind them to retained Project Cut evidence\n- document strict counting and attribution boundaries\n\n## Evidence contract\n\n- observation: `2026-06-21T04:45:00Z..2026-07-21T04:45:00Z` (`P30D`)\n- merged public PRs: `2,740` across `10` public repositories\n- retained public Project Cuts: `148` at `kungfu@dad7c45`\n- cases: three-actor continuation qualification and Hub architecture cross-repository production delivery\n\n## Validation\n\n- `pnpm run build`\n- `pnpm run check`\n- `node scripts/check-dogfood-evidence.mjs --verify-live`\n- desktop and mobile browser visual checks\n\n## Governance\n\n- [x] Public content is English\n- [x] DCO sign-off is present\n- [x] No credentials, private paths, or private control-plane records are included\n- [x] PR count is not presented as feature count\n- [x] GitHub author identity is not presented as Agent actor identity\n- [x] `reviewed-by` search is not presented as approval or exact-root review\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T04:56:32Z",
          "mergedAt": "2026-07-21T05:07:51Z",
          "additions": 786,
          "deletions": 1,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 49,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/49",
          "title": "feat(site): show public dogfood proof",
          "body": "## Summary\n\nAdd a compact, public dogfood proof rail to the Agent Builders page so builders can see that Kungfu is built through the same evidence loop it exposes.\n\n## Changes\n\n- show the fixed P30D snapshot: 2,740 merged public PRs, 10 repositories, and 148 retained public Project Cuts\n- link the human-readable evidence page and machine-readable JSON snapshot\n- pin the projection to `site-libkungfu-dev@5a15649` and evidence SHA-256 `3fa6bacc...`\n- keep PR, actor, and review attribution boundaries visible beside the metrics\n- add an offline contract checker for the proof rail\n\n## Verification\n\n- `pnpm run build`\n- `pnpm run check`\n- exact upstream blob SHA-256 rechecked through the GitHub API\n- desktop and 390px-equivalent mobile browser visual checks\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: this changes only the public `kungfu.tech/agent-builders/` content projection and links to the independently versioned libkungfu.dev evidence snapshot. It does not change infrastructure, credentials, DNS, or release policy.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T05:02:25Z",
          "mergedAt": "2026-07-21T05:08:32Z",
          "additions": 170,
          "deletions": 2,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 51,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/51",
          "title": "fix(site): distinguish dogfood evidence hashes",
          "body": "## Summary\n\nMake the dogfood proof pin unambiguous by recording both the source fixture bytes and the pretty-printed public JSON bytes.\n\n## Changes\n\n- rename the existing `3fa6...` digest to `sourceFixtureSha256` and record its exact path\n- add the staging-verified public `/dogfood-evidence.json` digest `5893...` as `publishedEvidenceSha256`\n- require both byte identities to remain explicit and distinct\n\n## Verification\n\n- `pnpm run build`\n- `pnpm run check`\n- source blob SHA-256: `3fa6bacc...`\n- staging public JSON SHA-256: `5893623e...`\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: this is a machine-audit metadata correction. It does not alter rendered site bytes or release policy.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T05:14:37Z",
          "mergedAt": "2026-07-21T05:19:18Z",
          "additions": 11,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 48,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/48",
          "title": "feat(homepage): lead with agent continuity",
          "body": "## Summary\n\nMake cross-session continuation the first-contact outcome on kungfu.tech, with an evidence-bounded before/after handoff visual and a dedicated method page.\n\n## Changes\n\n- replace the control-pane-first hero with “Your agent shouldn't start over when the chat ends.”\n- show a static-complete, progressively animated baseline/Kungfu handoff using only the preparatory pilot's public-safe facts\n- add `/how-tested/continuity/` with method, exact evidence links, versions, and limitations\n- move Cost / State / Proof below the continuation story and remove fabricated preview numbers\n- preserve a truthful static fallback and disable motion under `prefers-reduced-motion`\n- fix the shared mobile header so 390px layouts do not overflow\n\n## Verification\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- Chrome desktop screenshot at 1440×1100\n- Chrome mobile emulation at 390×844: `scrollWidth=390`\n- reduced-motion emulation: continuity transfer `animation-name=none`\n\nThe evidence is explicitly labeled preparatory. The page does not claim model-provider superiority, multi-hour durability, retention, or FO10 results. Production remains behind the existing Buildchain release approval path.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes official public copy and links only to retained public evidence. Preview/staging/production behavior is unchanged; production requires the existing Buildchain approval flow.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T04:55:00Z",
          "mergedAt": "2026-07-21T05:21:02Z",
          "additions": 326,
          "deletions": 18,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1176,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1176",
          "title": "feat(core): native Action Geometry, Domain Profile, and apply_action authority",
          "body": "## Summary\n\n- Port Action Geometry evaluator, Domain Profile engine, and `apply_action` orchestration into `libkungfu` C++ under `runtime/action/`, with byte-identical characterization fixtures.\n- Expose the authority via the existing storage JSON edge (`action_runtime`); Python `work_profile` / `action_geometry` / `domain_profile` become thin shims (native when bindings expose `run_storage_service_operation`, Python fallback for stub `pykungfu`).\n- Shadow dual-run suite (`test:action-runtime-shadow`) is clean; public authority prefers native. Project Cut empty-delta settlement, Completion Claim, independent exact-root review (`fit`), and continuation decision (`close`) are bound to the delivery head on this branch.\n\n## Test plan\n\n- [x] `./shifu build:core`\n- [x] native: geometry / domain_profile / profile_action / action_runtime tests\n- [x] `./shifu test:action-runtime-shadow`\n- [x] `test:fact-kernel-native` + `test_agent_work_state_contract`\n- [x] `node framework/core/architecture/check-layers.mjs`\n- [ ] Required CI on this PR\n- [ ] Independent `kungfu-origin` approval + merge queue into `dev/v4/v4.0`\n\n## Notes\n\n- Out of phase-1 scope: `export_authority` / `import_authority` (still fact_kernel), `action_loop` coordination (phase 2).\n- Atlas goal: `2026-07-20-kungfu-action-geometry-native-authority`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0123\"],\n  \"summary\": \"Sink Action Geometry, Domain Profile, and apply_action orchestration into libkungfu as the single semantic authority with byte-identical fixtures, storage JSON edge exposure, and Python thin shims.\",\n  \"verification\": [\"native geometry/domain/profile_action/action_runtime tests\", \"action-runtime shadow suite\", \"architecture check-layers\", \"empty-delta Project Cut exact-root claim and independent review\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR lands native Action Geometry authority and checked-in architecture projections. It does not publish a release or claim cross-platform release qualification; ADR-0123 remains the governing ADR for this delivery.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T01:40:57Z",
          "mergedAt": "2026-07-21T05:21:54Z",
          "additions": 4741,
          "deletions": 285,
          "changedFiles": 74
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 146,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/146",
          "title": "Release production from f6542d4af525",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `f6542d4af525c10c63aca6ab8cdd5b5da25914f8`\n- Artifact hash: `20a00f808f7797a2a72ab08240b930ba82d5182cefc7b59a9adf5bc5db59b896`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29803122081)\n- Required label: `buildchain-release`\n- Release branch: `release/production-f6542d4af525`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-21T05:16:28Z",
          "mergedAt": "2026-07-21T05:25:11Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 53,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/53",
          "title": "Release production from 87f86c98ef0a",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `87f86c98ef0ad9e5a3364b30c6c1ef238767a272`\n- Artifact hash: `31b508ed029da029b2416c1d604d12cb22aa2487a027d507eff975594dc58009`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29803742763)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-87f86c98ef0a`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-21T05:23:12Z",
          "mergedAt": "2026-07-21T05:26:00Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1178,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1178",
          "title": "refactor(core): retire libkungfu compatibility bootstraps",
          "body": "## Summary\n\n- migrate embedding and storage consumers to the standard `kungfu_get_api` ABI\n- remove the legacy embedding/native-storage bootstraps, headers, implementations, slices, and compatibility tests\n- align SDK packaging, symbol policy, architecture contracts, qualification gates, and consumer examples\n- publish exact-root Project Cut evidence for both migrations and final retirement\n\n## Verification\n\n- `./shifu check`\n- `./shifu build`\n- native runtime/API/state CTests\n- `./shifu pack:sdk`\n- `./shifu layers:qualify:sdk`\n- `./shifu qualify:embedding-membranes`\n- `./shifu kfd7:qualify:installed-consumer`\n- release qualification tests and Project Cut closeout gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0120\"],\n  \"summary\": \"Retire the pre-release compatibility bootstraps after migrating all supported consumers to the standard successor ABI\",\n  \"verification\": [\"source check, native runtime and ABI tests, SDK packaging, membrane qualification, installed-consumer qualification, and Project Cut closeout gates\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe standard native package identity, exported ABI surface, and release qualification evidence are updated together and verified by the listed gates.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for the changed ABI and packaging behavior",
          "author": "dongkeren",
          "createdAt": "2026-07-21T02:44:16Z",
          "mergedAt": "2026-07-21T06:20:38Z",
          "additions": 12047,
          "deletions": 5509,
          "changedFiles": 114
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1189,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1189",
          "title": "docs(project-cut): publish public dogfood evidence cut",
          "body": "## Summary\n\n- retain the Xinfa Atlas used to settle the public dogfood evidence delivery\n- publish current successor Project Cut `sha256:89a68d7de98184ac3a302c0e0d3c8189c8248edc078c1324b2fcca7047503286`\n- compose parent Cut `sha256:b20d4d707fa572785fcaee44901e6052f17c89eebc0b95c2ca773e57801d4b40`, which transitively names original task Cut `sha256:24647b7adabcd60b408b2a1b45cab207fd12b6274522ce5e932cc1ff5112899d`\n- bind valid receipt `sha256:04c8e55d3972c434d40d6480e8adba586db6784a6a95a159ae133adc331145ec`\n- record an explicit empty Episode delta because this delivery changes public documentation surfaces, not Kungfu runtime behavior\n\n## Production evidence\n\n- https://libkungfu.dev/dogfood/\n- https://libkungfu.dev/dogfood-evidence.json\n- https://kungfu.tech/agent-builders/\n- libkungfu.dev Buildchain production run: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29803939386\n- kungfu.tech Buildchain production run: https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29803978492\n\n## Verification\n\n- Project Cut settlement and commit observation passed for exact commit `fa82f57bbc2e9191c87ee5b21a7f806442cd7f23`\n- successor source projection matches the latest mainline merge composition: `sha256:ffca74a16bb13d9bb92a462f98cca748465791cb7aa7aa4e5e640eace17d9dad`\n- repository pre-commit gate passed, including 18 latency/cache tests, 17 invariant tests, 63 documentation negative fixtures, schema gates, Markdown/link checks, and staged formatting\n- live machine evidence bytes match SHA-256 `5893623ebd225d3d90691241014270c2c4c9ffb5f347ae43d402d39c84d0ed2f`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This PR retains the already-completed public evidence delivery as an immutable Project Cut; it does not change an architecture contract or advance an ADR implementation projection.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release-evidence boundary is limited to public GitHub metadata, public production URLs, and retained public Project Cut roots. No credentials or private runtime payloads are included.\n\n## Counting boundary\n\nPR count is not feature count. GitHub author attribution is not Agent actor identity. `reviewed-by` search is not approval or exact-root independent review.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T05:41:27Z",
          "mergedAt": "2026-07-21T06:36:38Z",
          "additions": 15,
          "deletions": 0,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 285,
          "url": "https://github.com/kungfu-systems/build-images/pull/285",
          "title": "fix(comparator): budget projected durable-sync tail",
          "body": "## Summary\n\n- raise only the durable-sync throughput timeout from 5,400 to 9,000 seconds\n- retain the 1,800-second recovery and 600-second default budgets\n- align the focused timeout test\n\n## Evidence\n\nThe retained alpha.10 formal run completed 413 samples without retry, including full-stack 378/378, schedule 382, and schedule 412. Schedule 413 remained active until the 5,400-second bound and wrote 363,860,234,240 bytes with low memory use before fail-closed cleanup.\n\nThe same-lane 10k sample wrote 5,917,691,904 bytes. A quadratic write-amplification projection places the 100k completion near 6,888 seconds; 9,000 seconds provides about 30% bounded headroom over that inference.\n\n## Verification\n\n- `python3 -m unittest pilots.comparator.tests.test_formal_performance`\n- `pnpm run check`\n- 109 comparator tests passed\n- KFD123 and Release Passport smoke passed\n- alpha and stable contract locks unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-21T06:50:49Z",
          "mergedAt": "2026-07-21T06:54:29Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 287,
          "url": "https://github.com/kungfu-systems/build-images/pull/287",
          "title": "chore(release): prepare v1.3.0-alpha.11",
          "body": "## Summary\n- advance the v1.3 alpha version to `1.3.0-alpha.11`\n- align the Buildchain release-impact declaration\n- preserve both alpha and stable contract locks unchanged\n\n## Verification\n- `pnpm run check`\n- 109 comparator qualification tests passed\n- KFD123 and Release Passport smoke passed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T06:55:35Z",
          "mergedAt": "2026-07-21T06:58:46Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 288,
          "url": "https://github.com/kungfu-systems/build-images/pull/288",
          "title": "chore(release): promote v1.3.0-alpha.11",
          "body": "## Promotion\nPromote the reviewed `dev/v1/v1.3` state as `v1.3.0-alpha.11`.\n\n## Release contract\n- alpha channel remains anchored to the unchanged `v2-alpha` contract lock\n- Release Passport generation remains enabled\n- GitHub release publication remains enabled\n- stable `v2` contract lock remains unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-21T06:59:01Z",
          "mergedAt": "2026-07-21T07:01:56Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1185,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1185",
          "title": "feat(xinfa): add hash-pinned wasm engine",
          "body": "## Summary\n\n- add a `wasm32-unknown-unknown` Xinfa engine compiled from the same Rust core and checked in with a pinned SHA-256 manifest\n- make Shifu prefer the zero-dependency Node wasm host for source-tree development, with an explicit source-fresh native fallback\n- stage the wasm and its qualification manifest in release artifacts while keeping production receipt minting native-only\n- make wasm builds reproducible and path-neutral, and document the authority boundary in ADR-0128\n\n## Verification\n\n- `./shifu xinfa:check`\n- `./shifu check:source`\n- `node scripts/check-project-cut-composition-gate.mjs`\n- wasm SHA-256: `ef4acec22e292d583ce9a9b80d8b954f796ee35b82a0e56f238bd86561339a94`\n- Project Cut: `sha256:04df8a7a6d438084eaf14906e24f8523477d8243ebfbc6b9618f3ad6d70e2a93`\n\nSupersedes #1183; this branch is rebased onto the current `dev/v4/v4.0` tip and carries one exact-head Cut publication.\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"ADR-0128\"],\"summary\":\"Deliver the hash-pinned Xinfa wasm engine, zero-compile Shifu development host, release verification artifact, and native-only production minting boundary.\",\"verification\":[\"./shifu xinfa:check\",\"./shifu check:source\",\"node scripts/check-project-cut-composition-gate.mjs\"]}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T04:27:58Z",
          "mergedAt": "2026-07-21T07:11:47Z",
          "additions": 3049,
          "deletions": 675,
          "changedFiles": 55
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1448,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1448",
          "title": "feat(patrol): publish observed evidence directly",
          "body": "## Summary\n\nAdd a generic observed-evidence Patrol contract that publishes immutable snapshots before atomically advancing a last-known-good latest alias. Extend web-surface deploys to preserve Patrol-owned objects.\n\n## Related issue\n\nAtlas goal 2026-07-21-kungfu-dogfood-evidence-patrol\n\n## Changes\n\n- add the reusable Patrol observed-evidence workflow and publisher\n- enforce default-branch schedule/manual trust, exact digests, conditional immutable writes, read-after-write, and targeted invalidation\n- preserve externally owned evidence paths during ordinary full-site sync\n- publish workflow/manual/authority registry projections\n\n## Verification\n\n- pnpm run check (726 tests, workflow checks, generated surface audit, and 4 action bundles)\n- dedicated immutable collision, publication order, and ordinary-deploy preservation tests\n- train ref: train/v2/v2.3/observed-evidence-patrol at b0b7e6576c357f8b8c94d32c24d46473e3a73144\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe reusable workflow obtains caller-scoped OIDC only after validating the trusted default-branch bundle. It has no embedded credentials; the consumer role remains provider-enforced and path-scoped.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T07:54:37Z",
          "mergedAt": "2026-07-21T08:01:11Z",
          "additions": 810,
          "deletions": 32,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1187,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1187",
          "title": "feat(agent-work): add bounded continuity pilot",
          "body": "## Summary\n\nAdd a bounded, repeatable continuity pilot that contrasts a chat-only baseline with one durable-fact continuation path, then retains the public-safe projection and animation production pack under one exact run identity.\n\n## Changes\n\n- add a versioned continuity pilot contract, fixture, runner, and negative tests\n- keep smoke, provider comparison, durability, retention, and FO10 claims explicitly separate\n- retain baseline and Kungfu reports, raw-event index, public projection, and a 32-second animation pack\n- document the exact method, redaction boundary, static fallback, and limitations\n- add `qualify:continuity-pilot` and source-acceptance coverage\n- seal the exact result with Project Cut `sha256:2b3097ff74e459a9e9de690c2a06bb1486767d9fe33104453e2b3dc1f487529a`\n\n## Verification\n\n- `./shifu test:continuity-pilot` (6/6, including negative cases)\n- `./shifu check:agent-work-state-contract` (Node 7/7; Python 39/39)\n- `./shifu qualify:continuity-pilot -- --output docs/qualification/evidence/continuity-pilot/2026-07-21-preparatory-v1 --source-head 70467db1ad6ba2f61248369523ca91670228e1e8 --run-id 2026-07-21-preparatory-v1`\n- `./shifu check:source` (509 Node tests: 508 pass, 1 skip, 0 fail; all downstream gates pass)\n- desktop/mobile evidence-consumer validation is owned by the dependent public-surfaces goal\n\nThe result is preparatory fixture evidence. It is not a native or hosted model-agent comparison, a multi-hour durability result, a user-retention study, or proof of FO10/provider superiority.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0109\"],\n  \"summary\": \"Add a bounded continuity pilot and retain its public-safe preparatory evidence\",\n  \"verification\": [\"continuity pilot negative tests\", \"agent-work state contract tests\", \"full source gate\", \"Project Cut exact-root observation\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR publishes preparatory evidence only; it does not deploy production or assert comparative performance.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T04:54:19Z",
          "mergedAt": "2026-07-21T08:04:11Z",
          "additions": 1150,
          "deletions": 74,
          "changedFiles": 41
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1449,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1449",
          "title": "chore(release): promote observed-evidence patrol",
          "body": "## Release intent\n\nPromote the current `dev/v2/v2.14` line to `alpha/v2/v2.14` through the protected Buildchain release path.\n\n## Included capability\n\n- #1448 adds immutable-first observed-evidence publication, last-known-good latest advancement, path-scoped authority, targeted invalidation, and full-site ownership preservation\n\n## Validation\n\n- PR #1448: independent approval and all required checks passed\n- post-merge Verify on `dev/v2/v2.14` passed: https://github.com/kungfu-systems/buildchain/actions/runs/29812641598\n- local `pnpm run check`: 726 tests and generated/public workflow audits passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T08:07:44Z",
          "mergedAt": "2026-07-21T08:12:55Z",
          "additions": 810,
          "deletions": 32,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 54,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/54",
          "title": "feat(dogfood): project upstream latest evidence",
          "body": "## Summary\n\nRemove the fixed dogfood snapshot/hash coupling and project the current libkungfu.dev evidence channel with an explicit retained fallback.\n\n## Verification\n\n- pnpm install --frozen-lockfile --ignore-scripts\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n\nThe downstream page does not collect facts independently and no longer pins source commits, fixture hashes, published hashes, windows, or metrics.\n\nAll commits are signed off.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T07:54:36Z",
          "mergedAt": "2026-07-21T08:21:40Z",
          "additions": 35,
          "deletions": 43,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 147,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/147",
          "title": "feat(dogfood): automate public evidence refresh",
          "body": "## Summary\n\nTurn the fixed public dogfood snapshot into a weekly rolling P30D observation published directly by Buildchain Patrol without a per-refresh PR or human review.\n\n## Changes\n\n- generate GitHub and retained Project Cut evidence from public sources\n- add the weekly/manual caller for immutable/latest publication\n- declare Patrol-owned S3 paths so full-site releases preserve them\n- project latest evidence on the dogfood page with a labelled retained fallback\n\n## Verification\n\n- pnpm install --frozen-lockfile --ignore-scripts\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- offline deterministic GitHub fixture plus real current Kungfu Project Cut scan: 154 retained and valid pairs\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe caller reads only public GitHub/Kungfu evidence. Its future production role is a dedicated OIDC role limited to two evidence object paths and one CloudFront distribution.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T07:54:36Z",
          "mergedAt": "2026-07-21T08:26:33Z",
          "additions": 305,
          "deletions": 12,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 57,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/57",
          "title": "Release production from f9c6ded1ca98",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `f9c6ded1ca98e9ca914657a5d0cf749d5256f625`\n- Artifact hash: `8866ace220226ecd0e8933f569d1a4282efb396cedff3d84a3be2f249166e5e7`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29813985391)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-f9c6ded1ca98`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-21T08:23:42Z",
          "mergedAt": "2026-07-21T08:27:57Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1451,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1451",
          "title": "Release v2.14.7 from qualified v2.14.7-alpha.0",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.7-alpha.0`\n- Candidate SHA: `4cbf31492a9baa940887eeb100f3d348eb376e2b`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T08:27:05Z",
          "mergedAt": "2026-07-21T08:28:18Z",
          "additions": 826,
          "deletions": 48,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 150,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/150",
          "title": "Release production from 5e4ea4e80cac",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `5e4ea4e80cac43ba496068a8fc9249e6769003c0`\n- Artifact hash: `3875adcbcdc18f6c242b9d3ec5d2dab45ceef9a240836d1d6db86d104aed8748`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29814300977)\n- Required label: `buildchain-release`\n- Release branch: `release/production-5e4ea4e80cac`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-21T08:34:07Z",
          "mergedAt": "2026-07-21T08:43:29Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 53,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/53",
          "title": "docs: center white paper on verified continuity",
          "body": "## Summary\n\n- make Project Cut the first user object and define the complete cross-session continuation loop\n- tell Agent builders to embed `libkungfu` now while building their own KFD-compatible Hub in parallel\n- distinguish Project Cut, `libkungfu`, KFD, Buildchain, and vendor Hub authority\n- publish exact KFD maturity, first-party evidence, adoption gates, risks, and non-claims\n- regenerate the complete brand/evidence site bundles without changing historical artifact routes\n\n## Claim boundary\n\nThis is an alpha product and architecture paper. It does not claim external vendor adoption, certification, stable Hub interoperability, or broad production readiness. Embedding `libkungfu` provides the reference runtime implementation; it does not automatically establish KFD conformance.\n\n## Validation\n\n- `npm run check`\n- `make pdf` (15 pages; no overflow or clipping; bibliography-only underfull-box warnings)\n- complete PDF visual review\n- `npx --no-install buildchain validate --json`\n- `npm pack --dry-run --json`\n- independent semantic review against the cited KFD, Kungfu, Agent Builder, and dogfood evidence coordinates",
          "author": "dongkeren",
          "createdAt": "2026-07-21T08:47:39Z",
          "mergedAt": "2026-07-21T08:52:49Z",
          "additions": 993,
          "deletions": 531,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 55,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/55",
          "title": "release: publish verified continuity alpha.6",
          "body": "## Summary\n- publish Kungfu product white paper `0.1.0-alpha.6`\n- release the Project Cut continuity rewrite under the title `Kungfu: Verified Continuity for Agent Work`\n- preserve the Buildchain contract lock updated against the current `v2-alpha` contract\n- regenerate all site bundle version surfaces for downstream publication\n\n## Checks\n- [x] `npm run update:site-bundles`\n- [x] `npm run check`\n- [x] `make pdf`\n- [x] `npx --no-install buildchain validate --json`\n- [x] `npm pack --dry-run --json`\n- [x] `git diff --check`\n\n## Governance\n- [x] No credentials, tokens, secrets, or private logs.\n- [x] No unpublished reviewer correspondence or private operational data.\n- [x] Provider/API/data claims are sourced or clearly marked as future work.\n- [x] Public branding and trademark language stays factual.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-21T08:55:27Z",
          "mergedAt": "2026-07-21T08:57:49Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 56,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/56",
          "title": "chore(release): promote verified continuity alpha",
          "body": "Promote the verified continuity white paper to the alpha channel as `0.1.0-alpha.6`.\n\nThis promotion publishes the rewritten paper **Kungfu: Verified Continuity for Agent Work**, its named PDF, npm package, site bundles, archival evidence, and release Passport through the repository Buildchain paper workflow.\n\nThe content was independently reviewed in #53; release preparation was independently approved and validated in #55.\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T08:58:22Z",
          "mergedAt": "2026-07-21T09:01:12Z",
          "additions": 1000,
          "deletions": 538,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1191,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1191",
          "title": "docs(product): lead with continuity outcome",
          "body": "## Summary\n\nMake cross-session work continuity the first thing a new reader understands, then connect that promise to the public handoff, method, and retained source evidence.\n\n## Changes\n\n- lead with the outcome: a fresh agent should not start over when the chat ends\n- link the kungfu.tech continuity handoff and how-tested surface\n- link the retained continuity pilot protocol and evidence\n- state that the current result is preparatory fixture evidence, not provider comparison, multi-day durability or retention, or FO10 qualification\n- preserve the existing kungfu run agent first-release CLI shape and deeper mechanism sections\n- seal the exact result with Project Cut sha256:ba0ec4cb276ac59d979331451721a541e8df8b469392bbe1f9babeaa464de14f\n\n## Verification\n\n- ./shifu docs:check\n- ./shifu check:source (510 Node tests: 509 pass, 1 skip, 0 fail; Python and downstream source gates pass)\n- staged commit gate, including documentation, Project Cut, route topology, schema authority, and KFD boundary checks\n- Project Cut exact-head observation and documentation final-ready review-required receipt\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0109\"],\n  \"summary\": \"Project the bounded continuity pilot into the first-contact README without widening its claims\",\n  \"verification\": [\"documentation gate\", \"full source gate\", \"Project Cut exact-root observation\", \"documentation final-ready review\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe README changes product positioning and evidence links only. It does not deploy production, change package identity, or widen the pilot's evidence claims.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T08:27:02Z",
          "mergedAt": "2026-07-21T09:04:43Z",
          "additions": 39,
          "deletions": 13,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1193,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1193",
          "title": "docs(project-cut): settle dogfood evidence patrol",
          "body": "## Summary\n\n- publish the successor Project Cut for the production dogfood evidence Patrol\n- bind Cut `sha256:1d46b95fac7c61cd957a20c9273df0eb83415ec7754dcbc94020a85fd53f6496` and Atlas `sha256:b8621a17f248650bf167f67d2ac5b3f80406ccbf9978d4dbea0459e9e324c9e4`\n- compose prior public evidence Cut `sha256:89a68d7de98184ac3a302c0e0d3c8189c8248edc078c1324b2fcca7047503286`\n- declare an explicit empty Episode delta because product implementation lives in Buildchain, site, and infrastructure repositories\n\n## Production evidence\n\n- Patrol canary: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29814798750\n- full-site preservation deploy: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29815398893\n- live latest: https://libkungfu.dev/dogfood-evidence.json\n- live experience: https://libkungfu.dev/dogfood/\n- downstream projection: https://kungfu.tech/agent-builders/\n\n## Verification\n\n- exact settlement commit `1801cb6d043530c583c464ae7ecf600f0150ea85` is observed as published\n- source projection root `sha256:6c44ce4d517d4e79eefa6ca9c7ab1e0222322e891f40672a0147ba09abdb0b62`\n- latest and immutable public bytes remain identical after the full-site production deploy\n- exact SHA-256 `db60fce21c0b1e6e262ec21b54309bbb137fb9c18e7d3fdf8214595cc4405ca6`\n- pre-commit gates passed, including schemas, route topology, invariants, documentation and staged formatting\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This PR retains the completed observed-evidence Patrol delivery as an immutable Project Cut; it does not change a Kungfu architecture contract or ADR implementation projection.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release-evidence boundary is limited to public production URLs, public workflow receipts, and retained public Project Cut roots. No credentials or private runtime payloads are included.\n\n## Counting boundary\n\nPR count is not feature count. GitHub author attribution is not Agent actor identity. `reviewed-by` search is not approval or exact-root independent review.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T08:59:48Z",
          "mergedAt": "2026-07-21T09:17:21Z",
          "additions": 11,
          "deletions": 0,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 57,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/57",
          "title": "fix(release): package white paper site bundles",
          "body": "## Summary\n- publish `0.1.0-alpha.7` as the corrected downstream-consumable alpha\n- declare each site bundle as an explicit publication metadata file\n- ensure Buildchain's deterministic npm paper package contains `site/brand-site.json`, `site/evidence-site.json`, and `site/site-bundles.json`\n\n`0.1.0-alpha.6` successfully published the rewritten paper, PDF, and Passport, but exposed a packaging gap: directory-valued metadata is recorded in the manifest yet the deterministic npm package copier admits files only. This release keeps the paper content unchanged and makes the site-consumption files explicit.\n\n## Checks\n- [x] `npm run update:site-bundles`\n- [x] `npm run check`\n- [x] `make pdf`\n- [x] `buildchain@2.14.7-alpha.0 publication-artifact manifest`\n- [x] `buildchain@2.14.7-alpha.0 publication-artifact npm-package`\n- [x] npm pack dry-run includes all three `site/*.json` files\n- [x] `npx --no-install buildchain validate --json`\n- [x] `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T09:16:26Z",
          "mergedAt": "2026-07-21T09:19:11Z",
          "additions": 11,
          "deletions": 9,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 58,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/58",
          "title": "chore(release): promote consumable white paper alpha",
          "body": "Promote the corrected downstream-consumable white paper package to the alpha channel as `0.1.0-alpha.7`.\n\nThe white-paper content is unchanged from the approved verified-continuity rewrite. This promotion makes the three declared `site/*.json` bundles concrete npm package files so `kungfu.tech` can consume the release without extracting the source archive.\n\nThe packaging correction was independently reviewed and fully validated in #57.\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T09:19:19Z",
          "mergedAt": "2026-07-21T09:21:42Z",
          "additions": 11,
          "deletions": 9,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1190,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1190",
          "title": "fix(core): clean retired ABI evidence",
          "body": "## Summary\n\nAlign the current KFD-7 ABI contracts, Release Passport, public header, version registry, and historical documents with the retired compatibility bootstraps. The current tree now describes exactly one public `libkungfu` bootstrap and keeps the original embedding/native-storage material only as explicitly historical evidence.\n\nThe exact functional candidate `b2994d0d8016e152710124172147c84ffb536fa7` passed the full/minimal installed-consumer matrix on Darwin arm64, Linux x64, and Windows x64 in [Core build profiles run 29809371727](https://github.com/kungfu-systems/kungfu/actions/runs/29809371727). The single replayable Project Cut successor on current `dev/v4/v4.0` is bound to `25b9ff7cad708bdc2aafea20eadd6950cf784733`.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- remove stale compatibility claims and deleted evidence paths from current contracts and the Release Passport\n- classify Rust/Python successor wrappers and the remaining Node ABI-wrapper risk accurately\n- mark the original embedding spike as historical without rewriting its evidence\n- strengthen the KFD-7 boundary gate to reject retired artifacts, stale classification, missing evidence paths, and unbound reports\n- record source revision in installed-consumer reports\n- retain a queue-linear Project Cut successor after integrating the current target branch\n\n## Verification\n\n- `./shifu check:kfd7-library-boundary`\n- `./shifu docs:check`\n- staged pre-commit gate on the target-integrated tree\n- exact three-platform `Core build profiles` run 29809371727: six full/minimal jobs passed\n- Project Cut composition gate: passed with exactly one changed Cut\n- Project Cut closeout gate: passed for Cut `sha256:e1f815cec57e239206f1e6ecfe4caad619f50e8cb57332f30f55a5f104225e77`\n- independent Project Cut review: `fit`\n\nThe post-merge `./shifu check:source` run completed all ABI, architecture, Project Cut, documentation, and most repository contract assertions without failure, then was interrupted because three existing concurrent test workers stopped making progress; the staged pre-commit gate completed successfully on the same tree.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0120\"],\n  \"summary\": \"Close post-retirement ABI evidence drift and bind the sole-bootstrap tree to a fresh supported-platform qualification.\",\n  \"verification\": [\"KFD-7 boundary gate\", \"documentation gate\", \"source acceptance\", \"three-platform installed-consumer qualification\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe qualification is exact-revision and pre-release. It does not claim external adoption, battle-tested maturity, or a stable ABI line.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T07:08:34Z",
          "mergedAt": "2026-07-21T09:46:06Z",
          "additions": 244,
          "deletions": 88,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 58,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/58",
          "title": "feat(whitepaper): publish verified continuity alpha",
          "body": "## Summary\n- pin `@kungfu-tech/paper-kungfu-product-white-paper@0.1.0-alpha.7`\n- consume the Buildchain-generated package layout through the exported package manifest and declared primary artifact path\n- render the new responsibility matrices and complete KFD status as semantic HTML tables without dropping KFD-4 through KFD-13\n- update machine entry, manifest, PDF, and reader pages from the exact upstream package\n\n## Verification\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- rendered PDF SHA-256: `59c639d8386c79c12e4f749d58b8b414b9a1b82c0071743d19d9cb65ceeb37bc`\n- rendered manifest source: `c3703c7f376bbe96183d215e0dc7d31c57539c62`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T09:27:11Z",
          "mergedAt": "2026-07-21T09:54:43Z",
          "additions": 73,
          "deletions": 37,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1195,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1195",
          "title": "chore(project-cut): close continuity-first launch",
          "body": "## Summary\n\nPublish the aggregate Project Cut that closes the continuity-first launch after all three direct child goals reached exact-root independent review and terminal close decisions.\n\n## Changes\n\n- bind release-gate alignment Cut `sha256:8470f3c5...`\n- bind the bounded continuity pilot and animation Cut `sha256:59e9daab...`\n- bind the public-surface Cut `sha256:8662cf6b...`\n- preserve the exact current source projection and declare an empty Episode delta\n- add no product behavior, public claim, deployment, or release configuration\n\n## Verification\n\n- Project Cut prepare, native bind, commit observation, and Completion Claim on exact commit `83b2d8eb2be5876f0655085a93c3e8e96ad0a075`\n- parent child reconciliation root `sha256:5fca4ed680acf39286665f66d399ebe7c3950f8123fa6e8c76eb6885bec5f7d1`\n- pre-commit contract, invariant, documentation, ADR, and staged-format checks passed; Biome checked both staged JSON files directly\n- GitHub required checks remain authoritative for merge\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This PR only publishes the aggregate Project Cut for already-merged, already-declared ADR-0109 delivery; it changes no architecture contract or product behavior\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe only release-evidence change is a content-addressed aggregate Project Cut. It does not publish packages or deploy production.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable: no behavior change)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T09:16:43Z",
          "mergedAt": "2026-07-21T09:57:54Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 59,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/59",
          "title": "Release production from f8d2e986cac1",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `f8d2e986cac17c28aa6fe306e746d562a5e01b22`\n- Artifact hash: `c6475f032be9e26eca9d1a9cd8c1947d345cd9430b8d519dde840824499d6236`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29820147546)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-f8d2e986cac1`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-21T09:57:06Z",
          "mergedAt": "2026-07-21T10:00:20Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/paper-episodes-to-primitives",
          "number": 3,
          "url": "https://github.com/kungfu-systems/paper-episodes-to-primitives/pull/3",
          "title": "docs(paper): introduce episodes-to-primitives alpha",
          "body": "## Summary\n\n- establish the public paper repository baseline and Buildchain publication contract\n- define causal Episode historical assets and the KFD-4/5/6 ontology-revision mechanism\n- freeze the current KFD live-case evidence cut with explicit evidence grades and non-claims\n- add falsifiable representation, shadow-loop, transfer, and governance evaluations\n\n## Checks\n\n- make check\n- make pdf (15 pages; rendered pages visually inspected)\n- npx -y @kungfu-tech/buildchain@2.14.7 validate --cwd . --json\n- Buildchain publication manifest and passport status: passed\n- clean-clone make check, make pdf, and Buildchain validation\n- PR #1 CI passed; this successor preserves the same commits and restores dev/review account separation\n\n## Governance\n\n- no private Episode bodies, credentials, tokens, private logs, or provider state\n- KFD-6 remains draft and is not presented as demonstrated capability\n- accepted candidate claims remain limited to their current software-domain profiles\n- retention, deletion, consent, portability, and independent promotion boundaries are explicit\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-21T10:21:27Z",
          "mergedAt": "2026-07-21T10:22:29Z",
          "additions": 1777,
          "deletions": 0,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 61,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/61",
          "title": "feat(site): focus homepage on agent builders",
          "body": "## Summary\n\nFocus the Kungfu homepage on the continuity-first message and give agent builders a direct path to the dedicated adoption page.\n\n## Changes\n\n- remove the Cost / State / Proof control pane and repeated strategic triangle from the homepage\n- promote Agent Builders to a direct shared-header link and the primary hero action\n- reduce the hero to two actions and update the repository policy text\n- add a regression check that rejects the retired first-screen treatment\n\n## Verification\n\n- corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- bash -n scripts/check-site.sh\n- shellcheck scripts/check-site.sh\n- desktop headless-browser render inspected\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T10:21:50Z",
          "mergedAt": "2026-07-21T10:24:42Z",
          "additions": 24,
          "deletions": 337,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/paper-episodes-to-primitives",
          "number": 4,
          "url": "https://github.com/kungfu-systems/paper-episodes-to-primitives/pull/4",
          "title": "release(paper): promote 0.1.0-alpha.1",
          "body": "## Summary\n\nPromote the reviewed Episodes-to-Primitives paper and its Buildchain publication contract from dev/v0/v0.1 to alpha/v0/v0.1.\n\n## Release target\n\n- publication version: 0.1.0-alpha.1\n- npm package: @kungfu-tech/paper-episodes-to-primitives\n- PDF: episodes-to-primitives.pdf\n- source PR: #3\n- source merge: 49ff493a420af928608811ccc93a69aa49a00c4d\n\n## Gate\n\nDo not merge until the one-time npm package bootstrap and GitHub Trusted Publishing relationship are verified.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-21T10:24:47Z",
          "mergedAt": "2026-07-21T10:29:55Z",
          "additions": 1777,
          "deletions": 0,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 63,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/63",
          "title": "feat(site): state the Hub noncompetition promise",
          "body": "## Summary\n\n- make the explicit adoption promise that Kungfu does not compete for the Builder-owned Hub\n- state that users, accounts, billing, models, UI, Agent, cloud, and customer relationships remain with the Builder\n- bound KFD to an open interoperability protocol with no required central Kungfu cloud\n- bound libkungfu to a public local runtime rather than a route into the host product\n- reinforce the promise on the continuity-first homepage and add regression checks\n\n## Validation\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `bash -n scripts/check-site.sh scripts/build-site.sh`\n- `shellcheck scripts/check-site.sh scripts/build-site.sh`\n- Chrome desktop and responsive visual review",
          "author": "dongkeren",
          "createdAt": "2026-07-21T10:39:12Z",
          "mergedAt": "2026-07-21T10:42:46Z",
          "additions": 146,
          "deletions": 13,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-episodes-to-primitives",
          "number": 5,
          "url": "https://github.com/kungfu-systems/paper-episodes-to-primitives/pull/5",
          "title": "fix(build): make PDF output reproducible",
          "body": "## Summary\n\n- derive SOURCE_DATE_EPOCH from the exact source commit for both local Tectonic and pinned Buildchain LaTeX Docker builds\n- document the byte-stability contract\n- preserve paper content and evidence boundaries unchanged\n\n## Evidence\n\n- local Tectonic: two clean builds produced identical SHA-256 63919a9ef0bbeee2102caa98553003c034849f92f51248601d61bf42f372e833\n- pinned Docker: two independent clones produced identical SHA-256 b176c04dd6c8183619aee8a30f63846c8203929c9b8f85e9bd9feb05b0e6b3d1\n- both outputs remain 15 pages\n- make check passed\n- Buildchain 2.14.7 validate passed\n\n## Release recovery\n\nThe first alpha.1 npm package was published through Trusted Publishing, but the transaction stopped before GitHub Release finalization. A later rerun correctly rejected different PDF bytes caused only by build timestamps. This patch makes future candidates byte-stable so the next alpha can complete as a fully sealed release.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T10:46:40Z",
          "mergedAt": "2026-07-21T10:47:45Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-episodes-to-primitives",
          "number": 6,
          "url": "https://github.com/kungfu-systems/paper-episodes-to-primitives/pull/6",
          "title": "release(paper): promote reproducible alpha",
          "body": "## Promotion\n\nPromote the reviewed reproducible-PDF fix from dev/v0/v0.1 to alpha/v0/v0.1.\n\nThe npm package 0.1.0-alpha.1 exists with valid Trusted Publishing provenance but its Buildchain transaction stopped before GitHub Release finalization. This promotion advances the source and lets Buildchain select the next immutable alpha for a complete sealed transaction.\n\nRequired evidence:\n- PR #5 independently approved and merged\n- dev push Build and Verify workflows passed at c2ee82bcd16374f2631381a25fb1fa46be014de2\n- local Tectonic duplicate builds matched\n- pinned Docker duplicate builds matched\n- BUILDCHAIN_PROMOTION_TOKEN is configured\n- npm Trusted Publishing remains bound to paper-release.yml",
          "author": "dongkeren",
          "createdAt": "2026-07-21T10:48:53Z",
          "mergedAt": "2026-07-21T10:50:05Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-episodes-to-primitives",
          "number": 7,
          "url": "https://github.com/kungfu-systems/paper-episodes-to-primitives/pull/7",
          "title": "chore(release): advance paper alpha",
          "body": "## Summary\n\nAdvance the declared immutable paper version from 0.1.0-alpha.1 to 0.1.0-alpha.2.\n\nThe alpha.1 npm package remains a valid OIDC-published artifact, but its Buildchain transaction is permanently bound to source 844483e91351e119f421aae2f1d95dcd47a544d0 and cannot be finalized with the corrected reproducible source. Buildchain correctly rejects identity drift, so the repaired source requires a new version.\n\n## Validation\n\n- only .buildchain/buildchain.toml publication.version changes\n- make check passed\n- Buildchain 2.14.7 validate reports alpha.2, trusted-publishing, and pinned-docker-toolchain\n- reproducible build fix is already merged through PR #5",
          "author": "dongkeren",
          "createdAt": "2026-07-21T10:52:46Z",
          "mergedAt": "2026-07-21T10:54:10Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-episodes-to-primitives",
          "number": 8,
          "url": "https://github.com/kungfu-systems/paper-episodes-to-primitives/pull/8",
          "title": "release(paper): publish 0.1.0-alpha.2",
          "body": "Promote the reproducible paper source with the explicitly advanced immutable version 0.1.0-alpha.2.\n\nEvidence:\n- reproducible build fix merged via PR #5\n- explicit alpha.2 version advance merged via PR #7\n- dev Build and Verify passed at 0cd592ecfd3803a78d262bc37de597376d2b8502\n- npm Trusted Publishing and BUILDCHAIN_PROMOTION_TOKEN are configured\n- the prior alpha.1 release-state remains immutable and bound to its original source",
          "author": "dongkeren",
          "createdAt": "2026-07-21T10:55:19Z",
          "mergedAt": "2026-07-21T10:56:28Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1196,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1196",
          "title": "refactor(rust): unify Xinfa under crates workspace",
          "body": "## Summary\n\nMove the Xinfa Rust product source from the repository root into the canonical `crates/` workspace while preserving its standalone extraction and installed product identity.\n\n## Related issue\n\nAtlas go `2026-07-21-kungfu-rust-workspace-unification`.\n\n## Changes\n\n- move all Xinfa Rust source and qualification assets to `crates/xinfa/`\n- add Xinfa to `crates/Cargo.toml` and use the canonical production lock/profile\n- retain the extraction-only lock and prove clean standalone build/test\n- retarget Shifu, CI, documentation, product assembly, and KFD contracts\n- preserve installed `xinfa/...`, command, schema, state, and historical baseline coordinates\n- regenerate the deterministic WASM artifact under the canonical workspace lock\n\n## Verification\n\n- `cargo metadata --locked --no-deps --format-version 1 --manifest-path crates/Cargo.toml`\n- `node scripts/check-shifu-workspace.mjs`\n- `./shifu xinfa:check`\n- `./shifu xinfa:standalone`\n- `node crates/xinfa/tooling/qualify-wasm.mjs`\n- `node crates/xinfa/tooling/dogfood.mjs`\n- documentation consumer/control-plane tests: 25/25\n- product distribution tests: 18/18\n- `./shifu check:source`\n- pre-commit staged source, documentation, Rust workspace, KFD, and Xinfa gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0129\"],\n  \"summary\": \"Xinfa is physically unified under the canonical Rust workspace while extraction and product identity remain qualified\",\n  \"verification\": [\"workspace metadata and all-target checks\", \"Xinfa standalone extraction\", \"deterministic WASM qualification\", \"product distribution and source acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe source coordinate changes are explicitly separated from unchanged installed product coordinates and verified by product distribution tests plus Xinfa qualification evidence.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T09:28:57Z",
          "mergedAt": "2026-07-21T11:03:04Z",
          "additions": 477,
          "deletions": 289,
          "changedFiles": 188
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 65,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/65",
          "title": "feat(site): draw the KFD Hub network topology",
          "body": "## Summary\n\n- place the concrete KFD-libkungfu topology before the noncompetition promise\n- show libkungfu inside the adopting Hub and KFD only at independently owned Hub edges\n- separate transport delivery from receiver-owned semantic admission\n- preserve responsive topology behavior and add reading-order regressions\n\n## Validation\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `bash -n scripts/check-site.sh scripts/build-site.sh`\n- `shellcheck scripts/check-site.sh scripts/build-site.sh`\n- Chrome headless visual QA at 1440px and 820px\n\n## Risk\n\n- Content-only site change; production remains approval-gated through a generated Buildchain release PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T12:02:25Z",
          "mergedAt": "2026-07-21T12:05:33Z",
          "additions": 292,
          "deletions": 81,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 67,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/67",
          "title": "feat(site): clarify the KFD adoption value",
          "body": "## Summary\n\n- state the adoption tradeoff immediately after the KFD Hub topology\n- make clear that a local Hub still works without KFD but each external connection needs a custom bridge\n- contrast proprietary handoff semantics with one portable KFD responsibility boundary\n- label the Hub-to-libkungfu seam as the Host Runtime API and the KFD edge as optional for local-only use\n- replace six technical rationale cards with a shorter Builder decision\n\n## Validation\n\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `bash -n scripts/check-site.sh scripts/build-site.sh`\n- `shellcheck scripts/check-site.sh scripts/build-site.sh`\n- Chrome headless visual QA at 1440px and 820px\n\n## Risk\n\n- Content-only site change; production remains approval-gated through a generated Buildchain release PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T12:30:14Z",
          "mergedAt": "2026-07-21T12:33:18Z",
          "additions": 101,
          "deletions": 25,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1198,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1198",
          "title": "feat(core): gate libkungfu bootstrap admission",
          "body": "## Summary\n\nMake the libkungfu bootstrap inventory fail closed. `kungfu_get_api` remains the sole qualified link-visible entry, while source definitions, the public header, symbol policy, layer registry, boundary contract, Release Passport, and installed binary exports must resolve to one exact admitted set.\n\nNew bootstraps now require two separate changes: an independently approved authorization-only PR must already be present on the target branch, then a later implementation PR must preserve that authorization and pass complete Darwin arm64, Linux x64, and Windows x64 installed-artifact requalification before the symbol may become qualified.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- introduce the v2 closed-world bootstrap admission policy with default deny\n- prevent an implementation PR from authorizing its own bootstrap\n- require target-branch preauthorization and independently reviewed evidence\n- weld qualified admissions to source exports, the public header, symbol policy, layer registry, and boundary contract\n- compare actual installed-library exports with the qualified admission set\n- add negative coverage for unauthorized, same-change, tampered, and stale-evidence paths\n- refresh architecture and SDK hash projections\n\n## Verification\n\n- `./shifu check:kfd7-library-boundary`\n- `./shifu check`\n- `./shifu check:source`\n- staged pre-commit gate\n- three-platform installed-consumer requalification: [run 29825943409](https://github.com/kungfu-systems/kungfu/actions/runs/29825943409) passed on all six jobs for functional candidate `5901fd0255e2c259454e4208736bd90c07f8ba49`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0120\"],\n  \"summary\": \"Require independent target-branch admission and complete requalification before any new libkungfu bootstrap can ship.\",\n  \"verification\": [\"KFD-7 boundary gate\", \"source acceptance\", \"closed-world negative fixtures\", \"three-platform installed-consumer qualification\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change does not add an ABI symbol. It tightens admission and requalification of the existing pre-release ABI.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T10:57:54Z",
          "mergedAt": "2026-07-21T13:03:17Z",
          "additions": 634,
          "deletions": 38,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1199,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1199",
          "title": "refactor(xinfa): modularize compiler internals",
          "body": "## Summary\n\nMake the Xinfa Rust compiler substantially easier for a new Agent to understand and change without altering its public CLI, JSON/schema contracts, deterministic roots, standalone product, or WASM behavior.\n\n## Related issue\n\nAtlas go `2026-07-21-xinfa-internal-modularity`.\n\n## Changes\n\n- add a source architecture map, ownership table, invariants, and task-oriented change recipes\n- decompose project validation into ordered responsibility-focused validators\n- introduce one typed command/operation authority shared by Native CLI and WASM engine adapters\n- split Pack source/verification/impact and Episode admission into explicit internal modules\n- add native output-path traversal, symlink, overwrite, and parent-boundary tests\n- retain standalone extraction coverage and refresh deterministic WASM plus exact documentation bindings\n- publish successor Xinfa Atlas `sha256:7ddaa22a...` and Project Cut `sha256:13fa9fd7...`\n\n## Verification\n\n- `./shifu xinfa:check` (48 Rust tests, clippy, schema, boundary, quality, Native/WASM equivalence)\n- `./shifu xinfa:standalone`\n- `./shifu xinfa:wasm:build`\n- `./shifu xinfa:wasm:check`\n- `./shifu xinfa:dogfood`\n- `./shifu check:source` (509 passed, 1 skipped, plus Python/runtime/desktop/tooling checks)\n- pre/post standalone project, authority, repository-pack, and Xinfa Atlas roots are identical\n- pre-commit staged source, documentation, Rust workspace, KFD, Xinfa, and Project Cut gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This PR is a behavior-preserving internal Xinfa modularity refactor and source-navigation improvement; it changes no accepted architecture contract, public protocol, CLI, schema, root algorithm, or product coordinate.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release-evidence impact is limited to refreshed deterministic WASM metadata, Xinfa Atlas material, and a content-addressed Project Cut. No package is published or deployed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for the new internal architecture and handoff path\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T12:44:47Z",
          "mergedAt": "2026-07-21T13:06:05Z",
          "additions": 2457,
          "deletions": 2137,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 69,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/69",
          "title": "feat(site): show dogfood proof before adoption",
          "body": "## Summary\n- move the concise public dogfood proof directly after the local action model\n- place the bounded starting path after evidence so Builders can audit before integrating\n- tighten the evidence-to-adoption boundary and lock the reading order with regression checks\n\n## Validation\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `bash -n scripts/check-site.sh scripts/build-site.sh`\n- `shellcheck scripts/check-site.sh scripts/build-site.sh`\n- headless Chrome desktop and narrow full-page visual QA",
          "author": "dongkeren",
          "createdAt": "2026-07-21T13:31:15Z",
          "mergedAt": "2026-07-21T13:34:34Z",
          "additions": 33,
          "deletions": 29,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 71,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/71",
          "title": "feat(site): unify builder chapter hierarchy",
          "body": "## Summary\n- make the four Builder chapters explicit with consistent numbered labels and section shells\n- preserve the noncompetition promise as a cross-cutting Builder contract\n- nest the current claim boundary inside chapter 04 and add regression coverage for chapter count and order\n\n## Validation\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `bash -n scripts/check-site.sh scripts/build-site.sh`\n- `shellcheck scripts/check-site.sh scripts/build-site.sh`\n- headless Chrome desktop and narrow full-page visual QA",
          "author": "dongkeren",
          "createdAt": "2026-07-21T13:50:29Z",
          "mergedAt": "2026-07-21T13:53:41Z",
          "additions": 99,
          "deletions": 28,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 73,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/73",
          "title": "feat(site): align About with continuity positioning",
          "body": "## Summary\n\n- replace the shared Agent Work Ledger tagline with Continuity for Agent Work\n- rewrite About around continuity, KFD, libkungfu, and the Hub noncompetition boundary\n- preserve public evidence and commercial stewardship language\n\n## Validation\n\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- git diff --check\n- visual QA at 1440px and 500px widths\n\n## Release boundary\n\nThis normal feature PR may publish staging after merge. Production remains gated by the separate Buildchain release PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T14:09:10Z",
          "mergedAt": "2026-07-21T14:15:48Z",
          "additions": 41,
          "deletions": 25,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 74,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/74",
          "title": "Release production from bb7c22d405eb",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `bb7c22d405eb4c0d758e88cc62681784f11a567d`\n- Artifact hash: `7370858fdfa343fbf6190b9b25bf569c615fd6d9069b4d1c7cddd8cffdf34d34`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29838273494)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-bb7c22d405eb`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-21T14:18:03Z",
          "mergedAt": "2026-07-21T14:24:05Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1454,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1454",
          "title": "fix(promotion): pin resolved workflow identities",
          "body": "## Summary\n- bind the public promotion router to GitHub's selected reusable-workflow SHA\n- resolve floating shell and runtime refs exactly once, then use immutable SHAs for every checkout and delegated promotion\n- preserve logical refs in routing evidence and document idempotent promote-only recovery\n\n## Validation\n- `pnpm run check` (727 tests, 4 action bundles)\n- deterministic moving-`v2` resolver fixture\n\nFixes #1452",
          "author": "dongkeren",
          "createdAt": "2026-07-21T14:29:32Z",
          "mergedAt": "2026-07-21T14:35:13Z",
          "additions": 335,
          "deletions": 92,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1455,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1455",
          "title": "chore(release): promote v2.14.8-alpha.0",
          "body": "## Release intent\n\nPromote the current `dev/v2/v2.14` line to `alpha/v2/v2.14` through the protected Buildchain release path.\n\n## Included fix\n\n- #1452 binds the promotion router to GitHub's selected workflow SHA, resolves floating shell/runtime refs exactly once, and delegates only immutable SHAs\n- logical refs remain available as routing audit metadata\n- complete-rerun recovery reuses the existing promote-only candidate without a native rebuild\n\n## Validation\n\n- PR #1454: independent exact-head approval, full Verify, Build Surface Fixture, and merge-group Verify passed\n- post-merge Verify on `dev/v2/v2.14` passed: https://github.com/kungfu-systems/buildchain/actions/runs/29839805797\n- local `pnpm run check`: 727 passed, 4 action bundles\n- deterministic moving-`v2` fixture resolves the ref once\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T14:36:51Z",
          "mergedAt": "2026-07-21T14:39:59Z",
          "additions": 335,
          "deletions": 92,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 59,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/59",
          "title": "docs(paper): lead with the session continuity failure",
          "body": "## Summary\n- retitle the paper as **Kungfu: The Session Is Not the Work**\n- open with the session-model failure and the Project Cut → libkungfu → KFD continuity chain\n- establish `kungfu-white-paper.pdf` and `/whitepaper/kungfu-white-paper` as the sole greenfield publication coordinates\n- align npm exports, site bundles, Buildchain artifact declarations, and release workflows\n\nNo compatibility alias or redirect is included because these coordinates have no external consumers yet.\n\n## Validation\n- [x] `npm run check`\n- [x] pinned Docker LaTeX build produced a 15-page PDF\n- [x] all 15 rendered pages visually inspected\n- [x] PDF title, author, and subject metadata verified with `pdfinfo`\n- [x] `npm pack --dry-run --json` contains `_build/kungfu-white-paper.pdf`\n- [x] `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-21T14:53:37Z",
          "mergedAt": "2026-07-21T14:56:13Z",
          "additions": 92,
          "deletions": 72,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1457,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1457",
          "title": "Release v2.14.8 from qualified v2.14.8-alpha.0",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.8-alpha.0`\n- Candidate SHA: `8c5617ab6017a41915a4617b87c64e75f678758d`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T14:56:42Z",
          "mergedAt": "2026-07-21T14:57:56Z",
          "additions": 351,
          "deletions": 108,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 61,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/61",
          "title": "release: prepare session continuity alpha.8",
          "body": "## Summary\n- advance the publication from `0.1.0-alpha.7` to `0.1.0-alpha.8`\n- publish **Kungfu: The Session Is Not the Work** as `_build/kungfu-white-paper.pdf`\n- keep package and generated site-bundle versions aligned\n\nThis is the release preparation for the content and greenfield coordinate change approved in #59.\n\n## Validation\n- [x] `npm run check`\n- [x] pinned Docker publication build\n- [x] Buildchain manifest reports `0.1.0-alpha.8` and `_build/kungfu-white-paper.pdf`\n- [x] `npm pack --dry-run --json` includes the named PDF\n- [x] PDF metadata and 15-page render verified\n- [x] `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-21T14:58:08Z",
          "mergedAt": "2026-07-21T15:00:52Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 62,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/62",
          "title": "chore(release): promote session continuity alpha",
          "body": "Promote **Kungfu: The Session Is Not the Work** to the alpha channel as `0.1.0-alpha.8`.\n\nThis promotion publishes the 15-page PDF as `kungfu-white-paper.pdf`, the npm package, greenfield brand-site coordinates, source archive, Buildchain publication evidence, and GitHub Release assets. No compatibility aliases are included because the publication coordinates have no external consumers yet.\n\nThe content and release contract were independently reviewed and fully validated in #59 and #61.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-21T15:01:09Z",
          "mergedAt": "2026-07-21T15:03:49Z",
          "additions": 99,
          "deletions": 79,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 75,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/75",
          "title": "feat(whitepaper): consume session continuity alpha",
          "body": "## Summary\n\n- consume `@kungfu-tech/paper-kungfu-product-white-paper@0.1.0-alpha.8`\n- move the canonical reader and PDF to the greenfield `/whitepaper/kungfu-white-paper` paths\n- render the new `Kungfu: The Session Is Not the Work` title and publication manifest\n\n## Validation\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `git diff --check`\n\n## Delivery boundary\n\nDevelopment mainline only. Do not add `buildchain-release`, create a release PR, or publish production as part of this change.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T15:18:33Z",
          "mergedAt": "2026-07-21T15:21:34Z",
          "additions": 19,
          "deletions": 19,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1458,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1458",
          "title": "fix(promotion): advance stable shell routing",
          "body": "## Summary\n- pin the stable promotion lane to the hidden advanced workflow shipped by Buildchain v2.14.8\n- forward the complete immutable router/shell/runtime/lock identity surface\n- remove the legacy public-wrapper compatibility boundary and refresh generated docs/site contracts\n\n## Evidence\n- Buildchain issue #1452 resolver fix succeeds in libnode run 29792871772 attempt 3 through immutable checkout verification\n- the remaining failure uses legacy shell c95f9fc with pnpm 11.7.0 while libnode declares 11.9.0\n- Buildchain v2.14.8 hidden advanced shell uses the consumer package-manager contract and is pinned here at 6fb6f1c\n\n## Validation\n- `node --test tests/promotion-channel-router.test.mjs` (12 passed)\n- `pnpm run check:workflows`\n- `pnpm run check` (727 passed; action bundle integrity passed)\n- `git diff --check`\n\nFollow-up to #1452.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T15:17:53Z",
          "mergedAt": "2026-07-21T15:22:59Z",
          "additions": 63,
          "deletions": 61,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1459,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1459",
          "title": "chore(release): promote v2.14.9-alpha.0",
          "body": "## Release intent\n\nPromote the current `dev/v2/v2.14` line to `alpha/v2/v2.14` through the protected Buildchain release path.\n\n## Included fix\n\n- route the stable promotion shell to the hidden advanced workflow at immutable Buildchain `v2.14.8` SHA `6fb6f1c3b806309ca02baa2a9d31068bc037899d`\n- forward exact router, shell, runtime, lock and invariant identity into the stable shell\n- allow consumer promotion to install the package manager declared by the consumer instead of the legacy shell pin\n\n## Validation\n\n- PR #1458: exact-head approval, full Verify, Build Surface Fixture and merge-group Verify passed\n- post-merge Verify on `dev/v2/v2.14` passed: https://github.com/kungfu-systems/buildchain/actions/runs/29843708002\n- local `pnpm run check`: 727 passed, 4 action bundles\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T15:24:52Z",
          "mergedAt": "2026-07-21T15:28:26Z",
          "additions": 63,
          "deletions": 61,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 152,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/152",
          "title": "feat: present the libkungfu runtime substrate on Core",
          "body": "## Summary\n\n- reframe core.libkungfu.dev around the mmap journal as retained evidence and the local observation bus\n- move the placeholder spec manifest into a secondary source contract\n- add Core-owned manifest and llms entrypoints with immutable Kungfu evidence links\n- distinguish visible, candidate-qualified durable, and future replication frontiers\n\n## Claim boundary\n\nThe shared-memory publish protocol and multi-process reader path are implemented. Hub payload capture, broad end-to-end qualification, production durable ingest, replication, and HA remain separately qualified capabilities.\n\n## Validation\n\n- pnpm run build\n- pnpm run check\n- node --check scripts/render-site.mjs\n- bash -n scripts/build-site.sh scripts/check-site.sh\n- desktop and narrow-viewport browser inspection",
          "author": "dongkeren",
          "createdAt": "2026-07-21T15:23:06Z",
          "mergedAt": "2026-07-21T15:35:30Z",
          "additions": 982,
          "deletions": 103,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 78,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/78",
          "title": "feat(site): publish package-backed paper catalog",
          "body": "## Summary\n\n- add the Episodes to Primitives paper to the public Papers catalog\n- consume exact current KFD, Buildchain, and paper package releases as source contracts\n- generate and validate a deterministic paper catalog plus KFD/Buildchain source facts\n- refresh Buildchain stable and alpha contract locks\n\n## Version impact\n\n- Minor: adds public content and dependency-backed generation without changing existing canonical product-white-paper routes.\n\n## Validation\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `bash -n scripts/build-site.sh`\n- `shellcheck scripts/build-site.sh`\n- `node --check scripts/whitepaper-source.mjs`\n- `node --check scripts/render-whitepaper.mjs`\n- `node --check scripts/check-whitepaper.mjs`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-21T15:40:55Z",
          "mergedAt": "2026-07-21T15:43:46Z",
          "additions": 446,
          "deletions": 60,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1461,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1461",
          "title": "fix(promotion): bind delegated shell call ref",
          "body": "## Problem\n\nThe v2.14.9 alpha router correctly delegates the stable shell at immutable SHA `6fb6f1c3b806309ca02baa2a9d31068bc037899d`, but forwarded the logical audit ref `v2` as the advanced shell identity. The advanced shell therefore rejected its actual GitHub called-workflow ref.\n\nObserved in libnode promotion attempt 4: https://github.com/kungfu-systems/libnode/actions/runs/29792871772/attempts/4\n\n```text\nCalled promotion shell ref 6fb6f1c3b806309ca02baa2a9d31068bc037899d does not match v2\n```\n\n## Fix\n\n- preserve `shell-ref=v2` as the public logical audit identity\n- emit a separate internal `shell-call-ref` from the exact-once resolver\n- forward `shell-call-ref` to the advanced workflow `promotion-shell-ref` input\n- keep immutable SHA checkout and comparison gates unchanged\n\n## Validation\n\n- targeted promotion router tests: 12 passed\n- `pnpm run check`: 727 passed\n- workflow, inventory, generated site and 4 action bundles passed\n- `git diff --check` passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T15:40:22Z",
          "mergedAt": "2026-07-21T15:45:51Z",
          "additions": 32,
          "deletions": 19,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 79,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/79",
          "title": "Release production from 4d53e1e61b57",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `4d53e1e61b5726650242044166c3f7e01b2936d2`\n- Artifact hash: `08d50ff906f617b3bf091ccda5d9d09b87d6a17dd86e43498f8cfd887d0f39d2`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29845335135)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-4d53e1e61b57`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-21T15:45:49Z",
          "mergedAt": "2026-07-21T15:48:29Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1462,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1462",
          "title": "chore(release): promote v2.14.9-alpha.1",
          "body": "## Release intent\n\nPromote the current `dev/v2/v2.14` line to `alpha/v2/v2.14` through the protected Buildchain release path.\n\n## Included fix\n\n- preserve the stable shell logical ref as public audit metadata\n- forward the exact immutable shell call ref into the advanced workflow identity check\n- keep router, shell, runtime, lock and target SHA verification unchanged\n\n## Validation\n\n- PR #1461: exact-head approval, full Verify, Build Surface Fixture and merge-group Verify passed\n- post-merge Verify passed: https://github.com/kungfu-systems/buildchain/actions/runs/29845499712\n- local `pnpm run check`: 727 passed, 4 action bundles\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T15:47:33Z",
          "mergedAt": "2026-07-21T15:49:46Z",
          "additions": 32,
          "deletions": 19,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 156,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/156",
          "title": "fix: isolate Core styles from immutable archives",
          "body": "## Summary\n- emit Core-only visual CSS only for the Core surface\n- preserve byte-for-byte rendering of immutable publication archive pages\n- add a regression check that rejects Core CSS in immutable publication HTML\n\n## Verification\n- `node --check scripts/render-site.mjs`\n- `bash -n scripts/build-site.sh scripts/check-site.sh`\n- `SITE_SURFACE_CHANNEL=staging SITE_PREVIEW_ALIAS='' pnpm run build`\n- `SITE_SURFACE_CHANNEL=staging SITE_PREVIEW_ALIAS='' pnpm run check`\n- staging-channel immutable index SHA-256 restored to `62400cb160e80ca7047ed2913e28d43c3d6995a34b4408a3e89e39d397b9166e`\n- desktop Core screenshot visually checked after style isolation\n\n## Context\nFollow-up to #152 after the staging immutable-object guard correctly detected shared-template CSS drift.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T15:44:20Z",
          "mergedAt": "2026-07-21T15:49:49Z",
          "additions": 17,
          "deletions": 7,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1201,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1201",
          "title": "feat(core): define KFD-7 embedder runtime semantics",
          "body": "## Summary\n\nDefine a machine-readable KFD-7 embedder operational contract and align the C ABI implementation with honest timeout, cancellation, recovery, and HA process-isolation semantics.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- declare exact operational semantics for all 24 C ABI operations\n- reserve timeout behavior until an operation implements a real deadline\n- add cooperative batch cancellation checkpoints and conformance fixtures\n- publish recovery tiers and a discardable-worker HA reference state machine\n- stage ADR-0130 and install the contract for SDK consumers\n\n## Verification\n\n- ./shifu check\n- ./shifu check:kfd7-library-boundary\n- ./shifu docs:check:readonly\n- ./shifu adr:audit -- --json\n- ./shifu layers:qualify:sdk -- --validate-only\n- public-header-aware affected native qualification: 21/21 passed\n- Project Cut commit observation and independent completion review: passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0130\"],\n  \"summary\": \"Stage the KFD-7 embedder operational semantics contract and deterministic conformance coverage\",\n  \"verification\": [\"Full Shifu check\", \"KFD-7 boundary gate\", \"21 affected native targets\", \"Project Cut independent review\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR adds tracked Project Cut provenance artifacts and verifies their exact commit binding.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated because behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T15:12:46Z",
          "mergedAt": "2026-07-21T16:05:12Z",
          "additions": 489,
          "deletions": 25,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1464,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1464",
          "title": "fix(publish): resolve protected check context",
          "body": "## Problem\n\nA stable libnode recovery reached publication admission but the protected-branch fallback compared legacy `required-status-check: build` literally with GitHub's protected exact context `build / Build with resolved channel / Summarize build contract`. The transaction was otherwise exact, protected, independently approved, and green.\n\nObserved run: https://github.com/kungfu-systems/libnode/actions/runs/29792871772/attempts/5\n\n## Fix\n\n- retain exact required context declarations unchanged\n- resolve a legacy reusable job id only when the protected branch exposes exactly one matching `job / ...` context\n- verify the resolved exact context on the merged PR head with the configured GitHub App id\n- fail closed when the prefix is ambiguous\n\n## Validation\n\n- live read-only audit against libnode PR #112: all 6 control-plane facts passed\n- targeted publication authority tests: 20 passed, including ambiguous-prefix denial\n- `pnpm run check`: 727 passed\n- workflow/site/inventory and 4 action bundles passed\n- `git diff --check` passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T16:06:41Z",
          "mergedAt": "2026-07-21T16:11:51Z",
          "additions": 83,
          "deletions": 21,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1465,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1465",
          "title": "chore(release): promote v2.14.9-alpha.2",
          "body": "## Release intent\n\nPromote the protected-check context resolution to the v2.14 alpha line.\n\n## Validation\n\n- PR #1464 exact-head approval, full checks and merge-group Verify passed\n- post-merge Verify: https://github.com/kungfu-systems/buildchain/actions/runs/29847503442\n- live read-only libnode control-plane audit: all six facts passed\n- local `pnpm run check`: 727 passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T16:13:13Z",
          "mergedAt": "2026-07-21T16:16:22Z",
          "additions": 83,
          "deletions": 21,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1467,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1467",
          "title": "Release v2.14.9 from qualified v2.14.9-alpha.2",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.9-alpha.2`\n- Candidate SHA: `ad39d99ab79f9aa29ed38564e704fc18a854c027`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T16:24:47Z",
          "mergedAt": "2026-07-21T16:25:58Z",
          "additions": 172,
          "deletions": 95,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 289,
          "url": "https://github.com/kungfu-systems/build-images/pull/289",
          "title": "fix(comparator): keep Aeron archive control session live",
          "body": "## Summary\n\n- poll Aeron's control-response channel during long matched samples so archive liveness pings cannot fill the response stream\n- retain bounded Compose status and service logs before failed Aeron samples are cleaned up\n- add regression coverage for both behaviors\n\n## Root cause\n\nAeron 1.52.2 sends one control-response liveness ping per second. The formal driver previously read only the recording-position counter between `startRecording` and `stopRecording`, so multi-thousand-second samples never drained the control-response stream. Once the stream filled, the archive closed the control session and `stopRecording` failed.\n\n## Verification\n\n- `python3 pilots/comparator/tests/test_formal_performance.py` (21 tests)\n- `pnpm run check` (111 tests plus workflow, KFD123, lock, and Release Passport checks)\n- `git diff --check`\n\nRefs #248",
          "author": "dongkeren",
          "createdAt": "2026-07-21T16:25:02Z",
          "mergedAt": "2026-07-21T16:38:03Z",
          "additions": 153,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 291,
          "url": "https://github.com/kungfu-systems/build-images/pull/291",
          "title": "chore(release): prepare v1.3.0-alpha.12",
          "body": "## Summary\n\n- prepare build-images v1.3.0-alpha.12\n- preserve the Buildchain v2 dual-channel contract locks\n- publish the Aeron archive control-session liveness fix from #248\n\n## Verification\n\n- `pnpm run check`\n- 111 tests passed\n- KFD123 passed\n- alpha/stable contract locks unchanged\n- Release Passport smoke passed\n\nCloses no issue: formal 666-sample qualification remains required before #248 can close.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T16:41:31Z",
          "mergedAt": "2026-07-21T16:45:35Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1468,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1468",
          "title": "fix(promotion): pin stable shell to v2.14.9",
          "body": "## Summary\n- pin the stable promotion shell call to the immutable v2.14.9 release SHA\n- retain the public logical `v2` identity while forwarding the exact call ref\n- refresh router assertions, documentation, and generated site contracts\n\n## Verification\n- `pnpm run check` (727 tests passed; 4 action bundles verified)\n- stable release/tag/npm latest all resolve to v2.14.9 / 1ea9324f79d16548d85cf4f5175cc379c9eb5dac",
          "author": "dongkeren",
          "createdAt": "2026-07-21T16:39:53Z",
          "mergedAt": "2026-07-21T16:46:08Z",
          "additions": 30,
          "deletions": 30,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 292,
          "url": "https://github.com/kungfu-systems/build-images/pull/292",
          "title": "chore(release): promote v1.3.0-alpha.12",
          "body": "## Release promotion\n\nPromote `dev/v1/v1.3` to `alpha/v1/v1.3` for Buildchain v2 alpha publication.\n\n- version: `1.3.0-alpha.12`\n- release passport: enabled\n- GitHub release: enabled\n- alpha contract lock: `@v2-alpha`\n- stable contract lock remains `@v2`\n\nThe published exact image digest will be used for a fresh, no-retry 666-sample qualification before any stable promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T16:45:57Z",
          "mergedAt": "2026-07-21T16:49:25Z",
          "additions": 155,
          "deletions": 2,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1469,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1469",
          "title": "chore(release): promote v2.14.10-alpha.0",
          "body": "## Summary\n- promote the v2.14.9 stable-shell routing pin to the v2 alpha channel\n- expose the publication-audit fix through the public v2-alpha router\n\n## Verification\n- PR #1468 merged through the dev merge queue\n- post-merge Verify run 29850065456 passed\n- local `pnpm run check`: 727 tests and 4 action bundles passed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T16:47:47Z",
          "mergedAt": "2026-07-21T16:51:06Z",
          "additions": 30,
          "deletions": 30,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1472,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1472",
          "title": "fix(release): accept exact RC source trees",
          "body": "Closes #1471.\n\nPromote-only stable publication may accept a broad reviewed release PR only when the downloaded PR-stage RC passport proves exact target SHA/tree equivalence. The target must still be a merged same-repository PR, and generated, stale, mismatched, or unreviewed sources retain the existing alpha-tree/version-state gates.\n\nValidation:\n- pnpm run check\n- action bundle integrity check (4 bundles)\n- focused stable promote-only acceptance/rejection test",
          "author": "dongkeren",
          "createdAt": "2026-07-21T17:18:45Z",
          "mergedAt": "2026-07-21T17:25:42Z",
          "additions": 305,
          "deletions": 62,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1202,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1202",
          "title": "feat(tui): add Mission Control full-window profile",
          "body": "## Summary\n\nDeliver the Mission Control full-window TUI v0 through the public KFX Profile boundary. The first screen projects the canonical five Mission Control questions from the public read-only Mission Home query, with responsive one-, two-, and three-column layouts and a fail-safe alternate-screen lifecycle.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add the public read-only `mission-home` Profile member and Work Dashboard client projection\n- add a generic full-window Profile shell with qualified 80x24, 120x36, and 160x48 layouts\n- add keyboard navigation, refresh generation fencing, non-TTY diagnostics, and deterministic terminal cleanup\n- add snapshot, resize, startup-failure, real Ink, POSIX PTY, and Episode immutability tests\n- publish and observe the exact-root Project Cut for the delivery\n\n## Verification\n\n- `./shifu fix`\n- `./shifu check`\n- `./shifu build`\n- `./shifu test:agent-profile-sdk`\n- TUI tests: 17 passed\n- Work Dashboard tests: 27 passed\n- Mission Control read-only Python proof: 1 passed\n- independent closeout review: no blocker, high, or medium findings\n- Project Cut closeout gate: passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0069\", \"ADR-0083\", \"ADR-0091\"],\n  \"summary\": \"Deliver a public read-only Mission Control Profile projection and qualified full-window TUI shell without widening the runtime authority boundary.\",\n  \"verification\": [\"full source gate\", \"TUI snapshot and POSIX PTY qualification\", \"Mission Control Episode immutability proof\", \"Project Cut exact-root observation\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe public Profile/CLI boundary is read-only and is covered by an Episode before/after immutability proof. The release-evidence change consists only of the observed Project Cut and exact-root Xinfa projection.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T15:30:22Z",
          "mergedAt": "2026-07-21T17:28:03Z",
          "additions": 1643,
          "deletions": 193,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1473,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1473",
          "title": "chore(release): promote v2.14.10-alpha.1",
          "body": "## Summary\n- promote the exact RC release-source admission fix to the v2 alpha channel\n- close Buildchain #1471 without weakening ordinary stable alpha-tree gates\n\n## Verification\n- PR #1472 merged through the dev merge queue\n- post-merge Verify run 29852893069 passed\n- local focused test passed both unreviewed rejection and exact reviewed RC acceptance\n- local `pnpm run check` and 4 action bundle integrity check passed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T17:27:36Z",
          "mergedAt": "2026-07-21T17:28:54Z",
          "additions": 305,
          "deletions": 62,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1474,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1474",
          "title": "Release v2.14.10 from qualified v2.14.10-alpha.1",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.10-alpha.1`\n- Candidate SHA: `1d010b8e88fa2b72940fd1116279518dc2e79ddf`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T17:36:37Z",
          "mergedAt": "2026-07-21T17:37:47Z",
          "additions": 346,
          "deletions": 103,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1476,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1476",
          "title": "fix(router): pin stable shell v2.14.10",
          "body": "## Summary\n- pin the public alpha router stable lane to the immutable v2.14.10 stable shell\n- expose exact RC release-source admission to consumers using `v2-alpha`\n- refresh generated workflow and site metadata\n\n## Verification\n- `pnpm run check`\n- promotion router tests\n- generated workflow and site bundle checks",
          "author": "dongkeren",
          "createdAt": "2026-07-21T17:47:18Z",
          "mergedAt": "2026-07-21T17:50:23Z",
          "additions": 30,
          "deletions": 30,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1477,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1477",
          "title": "chore(release): promote v2.14.11-alpha.0",
          "body": "## Summary\n- promote the v2.14.10 stable-shell pin to the public v2 alpha channel\n- make exact RC release-source admission available through `v2-alpha`\n\n## Verification\n- PR #1476 merged through the dev merge queue\n- post-merge Verify run 29854641785 passed\n- local `pnpm run check` and promotion-router tests passed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T17:52:03Z",
          "mergedAt": "2026-07-21T17:53:23Z",
          "additions": 30,
          "deletions": 30,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1480,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1480",
          "title": "fix(release): bind transaction recovery to planned version",
          "body": "## Summary\n- bind durable alpha/release transaction recovery to the exact planned publication version\n- prevent failed ancestor transactions from reclaiming old exact tags for newer releases\n- preserve same-version finalization recovery and document the invariant\n\n## Validation\n- pnpm run check\n- 729 tests passed\n- action bundle integrity passed\n\nCloses #1478",
          "author": "dongkeren",
          "createdAt": "2026-07-21T18:14:31Z",
          "mergedAt": "2026-07-21T18:19:38Z",
          "additions": 140,
          "deletions": 27,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1481,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1481",
          "title": "chore(release): promote v2.14 transaction recovery fix to alpha",
          "body": "## Summary\n- promote planned-version-bound transaction recovery to the v2.14 alpha lane\n- publish the regression fix needed to complete the libnode 22.22.3-kf.4 release\n\n## Evidence\n- PR #1480 approved and merged through the dev merge queue\n- local pnpm run check passed with 729 tests\n- merge-group Verify passed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T18:20:29Z",
          "mergedAt": "2026-07-21T18:23:42Z",
          "additions": 140,
          "deletions": 27,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1482,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1482",
          "title": "Release v2.14.11 from qualified v2.14.11-alpha.1",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.11-alpha.1`\n- Candidate SHA: `bfd3fb1638afbd61fac96c9baece289dd3fdb2ce`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T18:31:40Z",
          "mergedAt": "2026-07-21T18:32:54Z",
          "additions": 181,
          "deletions": 68,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1484,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1484",
          "title": "fix(release): rebind stale internal transaction tags",
          "body": "## Summary\n\n- bind the internal exact tag into durable publication transaction identity\n- safely rebind only unfinished published/finalizing anchored transactions whose version, material, complete artifact set, and evidence still match\n- preserve the stale tag and fail closed if either the old or requested tag represents conflicting release material\n- add a libnode-shaped regression proving registry publication is not repeated\n\n## Validation\n\n- `pnpm run check` (730 tests, 0 failures)\n- generated site and action bundle integrity checks pass\n\nFollow-up to #1478.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T18:49:35Z",
          "mergedAt": "2026-07-21T18:53:16Z",
          "additions": 355,
          "deletions": 74,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1485,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1485",
          "title": "chore(release): promote exact-tag transaction recovery to alpha",
          "body": "## Summary\n\n- promote the safe exact-tag transaction rebind fix to the v2.14 alpha lane\n- unblock completion of the already-published libnode 22.22.3-kf.4 package set without republishing\n\n## Evidence\n\n- PR #1484 approved and merged through the dev merge queue\n- local `pnpm run check` passed with 730 tests\n- merge-group Verify passed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T18:53:53Z",
          "mergedAt": "2026-07-21T18:55:06Z",
          "additions": 355,
          "deletions": 74,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1486,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1486",
          "title": "Release v2.14.12 from qualified v2.14.12-alpha.0",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.12-alpha.0`\n- Candidate SHA: `0d5ea3d3df5a45afaf4655711ecc75d052823c1b`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T19:03:39Z",
          "mergedAt": "2026-07-21T19:04:57Z",
          "additions": 371,
          "deletions": 90,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1488,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1488",
          "title": "fix(workflow): pin stable promotion shell to v2.14.12",
          "body": "## Summary\n\n- pin the public stable promotion router to the immutable v2.14.12 implementation SHA\n- carry planned-version recovery and guarded stale exact-tag rebinding into consumer stable promotions\n- refresh generated workflow, site contracts, tests, and documentation\n\n## Verification\n\n- pnpm run check\n- 730 tests passed\n- workflow, site, and four action bundle integrity checks passed\n\n## Release impact\n\nPatch. This updates provider-owned routing only; consumer declarations remain unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T19:15:50Z",
          "mergedAt": "2026-07-21T19:21:26Z",
          "additions": 30,
          "deletions": 30,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1489,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1489",
          "title": "chore(release): promote dev/v2/v2.14 to alpha",
          "body": "## Summary\n\nPromote the validated dev/v2/v2.14 head to alpha so the public v2-alpha router pins stable promotions to the immutable v2.14.12 workflow implementation.\n\nIncluded fix:\n- #1488 stable promotion shell routing update\n\nExpected prerelease: v2.14.13-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T19:22:59Z",
          "mergedAt": "2026-07-21T19:26:19Z",
          "additions": 30,
          "deletions": 30,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1207,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1207",
          "title": "feat(storage): freeze workspace home layout v1",
          "body": "## Summary\n- freeze the workspace `.kungfu` home layout as an additive v1 persistence contract\n- pin the journal wire epoch and retain historical header bytes\n- add a schema identity and compatibility reader for `first-party.json`\n- document the `.kungfu` runtime-fact and `.xinfa` semantic-authority boundary\n\n## Verification\n- `./shifu check:source`\n- `./shifu build`\n- focused Python layout and manifest tests\n- yijinjing retained-wire tests\n- Node/Python storage parity and TUI KFX parity\n- full macOS, Ubuntu, Windows, and affected-native CI passed on predecessor PR #1205\n\n## Governance\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, billing, quota, or usage-attribution change\n- [x] No hosted-service or deployment change\n- [x] No package publication or release action\n- [x] Contract and generated evidence projections are current\n\n<!-- kungfu-adr-release:v1 {\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"ADR-0131\"],\"summary\":\"Freeze workspace .kungfu home layout v1\",\"verification\":[\"Dev delivery qualification checks\"]} -->",
          "author": "dongkeren",
          "createdAt": "2026-07-21T18:57:46Z",
          "mergedAt": "2026-07-21T19:33:04Z",
          "additions": 2340,
          "deletions": 151,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1492,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1492",
          "title": "fix(release): infer impact for tree-equivalent promotion",
          "body": "Closes #1491.\n\nStable promote-only publication can now derive the required patch-level release impact when the PR-stage release-candidate passport proves exact tree equivalence. Explicit impact input still wins; missing, stale, non-equivalent, or non-release evidence remains fail-closed.\n\nThis fixes the libnode v22.22.3-kf.4 finalization failure from run 29861917542 without rebuilding or republishing the already validated package set.\n\nValidation:\n- pnpm run check (732 tests, 0 failures)\n- generated workflow/site/action bundle integrity checks passed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T19:49:22Z",
          "mergedAt": "2026-07-21T19:52:32Z",
          "additions": 202,
          "deletions": 64,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1493,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1493",
          "title": "release: promote v2.14 tree-equivalent impact fix",
          "body": "Promotes the verified tree-equivalent release impact fix from dev/v2/v2.14 to alpha/v2/v2.14.\n\nIncludes #1492 / #1491. Post-merge dev Verify run 29863358381 passed.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T19:54:00Z",
          "mergedAt": "2026-07-21T19:55:21Z",
          "additions": 202,
          "deletions": 64,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1206,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1206",
          "title": "feat(xinfa): add generic repository onboarding",
          "body": "## Summary\n\nAdd a safe, explainable, declaration-driven onboarding loop for previously unknown Git repositories: discover, candidate, explain, accept, and compile.\n\n## Related issue\n\nAtlas go 2026-07-21-xinfa-generic-repository-onboarding\n\n## Changes\n\n- Add shared native/WASM onboarding core and native/Node Git hosts.\n- Add six versioned onboarding schemas and four CLI subcommands.\n- Enforce dry-run-first, stale-root checks, sensitive-path exclusion, atomic publication, hard discovery caps, and untracked-name privacy.\n- Qualify seven ecosystem shapes, eight adversarial categories, and two real non-Kungfu consumer repositories.\n- Isolate explicit repository discovery and test fixtures from inherited Git index/worktree environment variables.\n- Add ADR-0132, architecture documentation, and content-addressed Project Cut evidence.\n\n## Verification\n\n- ./shifu xinfa:check\n- ./shifu check:source\n- ./shifu xinfa:standalone\n- ./shifu xinfa:dogfood\n- cargo test --manifest-path crates/xinfa/Cargo.toml native_io::tests::onboarding_transaction_is_dry_run_first_stale_safe_and_atomic with inherited GIT_INDEX_FILE\n- node --test scripts/release-promotion-rehearsal.test.mjs\n- ./shifu docs final-ready --since 89e7f0d88374370ebd14669d7db11f1f16d2ebab --xinfa crates/target/debug/xinfa --json\n- Project Cut completion claim, independent review, and continuation decision\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0132\"],\n  \"summary\": \"Deliver the complete generic repository onboarding authority transition.\",\n  \"verification\": [\"Xinfa native/WASM qualification\", \"two real non-Kungfu consumers\", \"Project Cut independent review\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR adds content-addressed Project Cut and onboarding qualification evidence; no release or deployment action is performed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T18:17:19Z",
          "mergedAt": "2026-07-21T20:03:21Z",
          "additions": 3364,
          "deletions": 31,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1494,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1494",
          "title": "Release v2.14.13 from qualified v2.14.13-alpha.1",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.13-alpha.1`\n- Candidate SHA: `cb7059e27fae3f174d30d03091ddbe386537f563`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T20:02:22Z",
          "mergedAt": "2026-07-21T20:03:38Z",
          "additions": 243,
          "deletions": 105,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1496,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1496",
          "title": "fix(workflow): pin stable promotion shell to v2.14.13",
          "body": "Pins the generated public promotion router stable lane to the immutable v2.14.13 release SHA so downstream stable publication uses the tree-equivalent impact fix.\n\nValidation:\n- node --test tests/promotion-channel-router.test.mjs (12/12)\n- pnpm run check (732/732)\n- generated workflow/site/action bundle checks passed\n\nFollow-up to #1492 and stable release v2.14.13.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-21T20:12:20Z",
          "mergedAt": "2026-07-21T20:15:36Z",
          "additions": 30,
          "deletions": 30,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1497,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1497",
          "title": "chore(release): promote v2.14.13 stable shell routing",
          "body": "Promotes the verified stable-shell routing update to alpha/v2/v2.14.\n\nThe public router will call the hidden stable workflow at immutable v2.14.13 SHA 725592ae. Post-merge dev Verify 29864997005 passed.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T20:16:54Z",
          "mergedAt": "2026-07-21T20:18:15Z",
          "additions": 30,
          "deletions": 30,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1209,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1209",
          "title": "fix(storage): close workspace layout coverage gaps",
          "body": "## Summary\n- classify admitted `runtime/full-evidence/` receipts in the frozen workspace layout\n- verify explicit runtime, storage, and coordinator roots without scanning unrelated home parents\n- retain distinct values for every journal v1 frame-header field and assert each decoded value\n\n## Verification\n- `./shifu check:source`\n- `./shifu build:core`\n- `framework/core/build/Release/yijinjing_mmap_tests`\n- focused `test_atlas_storage.py -k workspace_layout` (3 passed)\n- independent read-only review completed; both evidence gaps were addressed\n\n## ADR delivery / release declaration\n<!-- kungfu-adr-release:v1 {\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"ADR-0131\"],\"summary\":\"Close the remaining workspace layout v1 coverage and retained-wire evidence gaps\",\"verification\":[\"Source acceptance, Core build, focused layout tests, and retained wire tests\"]} -->\n\n## Governance risk check\n- [x] none of the listed governance boundaries\n\n## Checklist\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated with behavior\n\nMade with [Cursor](https://cursor.com)",
          "author": "dongkeren",
          "createdAt": "2026-07-21T20:11:42Z",
          "mergedAt": "2026-07-21T20:37:22Z",
          "additions": 62,
          "deletions": 15,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1499,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1499",
          "title": "chore(contract): accept v2.14.14 alpha runtime",
          "body": "## Summary\n- accept the reviewed `v2.14.14-alpha.0` runtime contract in Buildchain self-dogfood\n- preserve the unchanged major-compatible digest and breaking surface digests\n- align the self-dogfood fixture and release-impact evidence with the accepted alpha\n\nCloses #1495\n\n## Verification\n- `node --test tests/buildchain-contract.test.mjs` (12/12)\n- `node --test --test-name-pattern='Buildchain self-dogfoods the current major alpha' tests/build-surface.test.mjs` (1/1)\n- `pnpm run check` (732/732; inventory, site, workflows, and action bundles passed)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T20:34:25Z",
          "mergedAt": "2026-07-21T20:37:43Z",
          "additions": 6,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 157,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/157",
          "title": "Release production from ec3c1d46bf90",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `ec3c1d46bf908b02feed3b33d99ff87eac4df65f`\n- Artifact hash: `c3f469f696fe81a994e2dc27a97e37ee812572edf864629d035582a226e3103a`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29845808332)\n- Required label: `buildchain-release`\n- Release branch: `release/production-ec3c1d46bf90`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-21T15:58:33Z",
          "mergedAt": "2026-07-21T21:11:21Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 77,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/77",
          "title": "Release production from 98e16a1f32de",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `98e16a1f32de164e3b7f5a2edd644b29e64e9da0`\n- Artifact hash: `e4a6c2f8cfbad89e35135cf5024823949af7450f8ee7ee08f396e425f3fc6de5`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29843597714)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-98e16a1f32de`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-21T15:23:46Z",
          "mergedAt": "2026-07-21T21:11:58Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1501,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1501",
          "title": "fix(web-surface): retry stale CloudFront ETags",
          "body": "## Summary\n\n- retry CloudFront UpdateDistribution after bounded PreconditionFailed stale-ETag races\n- re-read distribution state before each compare-and-swap attempt and accept concurrent convergence\n- preserve fail-closed behavior for conflicting viewer-request functions and non-ETag AWS errors\n- add black-box fake-AWS regression coverage and update generated site contracts\n\n## Verification\n\n- pnpm run check\n- node --test tests/web-surface-cloudfront-rewrite.test.mjs tests/web-surface.test.mjs (52 tests passed)\n\nNo live AWS operations were executed during verification.\n\nCloses #1453",
          "author": "dongkeren",
          "createdAt": "2026-07-21T22:36:33Z",
          "mergedAt": "2026-07-21T22:39:52Z",
          "additions": 311,
          "deletions": 66,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1502,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1502",
          "title": "chore(release): promote CloudFront stale-ETag retry",
          "body": "Promotes the verified CloudFront stale-ETag retry and the current v2.14.14 alpha contract lock from dev/v2/v2.14 to alpha/v2/v2.14.\n\nIncluded delivery:\n- #1501 / f99ab9d3: bounded CloudFront UpdateDistribution retry after PreconditionFailed\n- #1499 / 0aad15b2: accept the current v2.14.14 alpha runtime contract\n\nVerification:\n- PR #1501 Verify and Build Surface Fixture passed\n- merge-group Verify 29874438888 passed\n- post-merge dev Verify 29874544490 passed\n\nNo live AWS operations were executed during this fix validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-21T22:41:39Z",
          "mergedAt": "2026-07-21T22:42:51Z",
          "additions": 317,
          "deletions": 72,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1210,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1210",
          "title": "feat(xinfa): converge baseline storage to tracked witnesses with local material",
          "body": "## Problem\n\n`.xinfa/baselines` grew linearly in Git: every Project Cut settlement tracked ~7 MB of Atlas bodies (`atlas.json`, views, context packs), adding ~120–180 MB/day of checkout size.\n\n## Change\n\n- Settlement publication outputs are now witness-only: `manifest.json` + `receipt.json` per baseline layer (~4 small files per settlement). Atlas bodies stay on disk as an ignored immutable content-addressed store.\n- Verification binds the full tracked witness chain from the exact Git index (`verifySettlement`) or observed commit (`observeSettlementCommit`): source projection → promotion bytes → manifest/receipt semantic roots → artifact content roots, with unsafe-path rejection. Missing/drifted local material fails visibly (`atlas-material-missing` / `atlas-material-drift`); corrupted witnesses fail with `atlas-witness-*`.\n- `reconcileCommit` validates the same chain body-independently, so a clean clone reconciles every published cut without bodies.\n- New promotions seal Atlas semantic roots (`atlasRoots`) so witness-only checkouts recover authenticity without bodies; all 98 legacy promotions are authenticated through a digest-pinned closed-set backfill (`.xinfa/manifests/legacy-atlas-roots.json`, digest fixed in the KFD-1 builder) that fails closed on missing entries, deleted promotions, or tampered backfill bytes.\n- Re-promoting an Atlas already covered by a tracked legacy promotion reuses the tracked bytes only under exact working-tree/index byte equality and exact root binding; any mismatch fails closed on immutable collision instead of silently rewriting a sealed promotion.\n- 96 legacy baselines (384 body files) untracked via `git rm --cached` — no history rewrite, working trees keep the bytes.\n- `buildchain-documentation-witness` verifies consumed bodies against the tracked witness before attesting.\n- Merge-queue compatibility fix (`412f358fa9`): the Project Cut composition observer now replays drifted Cuts squash-published together with their parent order-independently — the delta base prefers the parent publication when it sits at or after the merge base (moving-main base fallback preserved), and replay deltas stream through a disk-backed patch file so huge binary untracking deltas no longer abort with ENOBUFS.\n- ADR-0133 documents the split (renumbered from 0130→0131→0133 as the base branch delivered its own ADR-0130, ADR-0131 workspace layout, and ADR-0132 onboarding); mission-control-workspaces guide corrected for witness-only clean clones.\n\n## Verification\n\n- 13/13 unit tests (`check-project-cut-settlement.test.mjs`), incl. negative tests: staged witness forgery, working-tree concealment, path traversal, committed receipt corruption\n- 2/2 integration tests (incl. legacy re-promotion reuse and working-tree mismatch rejection)\n- 5/5 `backfill-legacy-atlas-roots.test.mjs`, 10/10 `buildchain-documentation-witness.test.mjs`, 6/6 materialized documentation tests\n- `shifu lint` clean, `shifu check:project-cut-settlement` pass, `check-shifu-documentation-contract` pass\n- Witness-only fresh checkout: KFD-1 witness check passes, material lane defers explicitly; tampered backfill and deleted promotions fail closed\n- `reconcileCommit` at HEAD: byte-identical diagnostic profile before/after (no new diagnostics)\n- 16/16 composition tests (`check-project-cut-composition.test.mjs`), incl. new squash-published sibling-order regression that fails closed on the previous observer; composition gate `ok:true` with zero diagnostics on this branch; `source-acceptance` pass\n- Project Cut successor cycle closed at head: publication commit `4653e98b86`, cut `551ba04b83…` (parent `96a491ce9c…`), atlas `c6454d05…`, fit independent review, continuation close, closeout gate pass\n- Linear delivery: this PR supersedes #1203 (same reviewed tree). The dev/v4/v4.0 merge queue uses REBASE and cannot linearize the original merge-commit history (`rebaseable: false`); squash commit `ce1c796816` is tree-identical to the fit-reviewed head `76d03dcad0` (tree `5b10d0594b`), followed only by witness publications (`60e8ef6966` cut 96a491ce, `4653e98b86` cut 551ba04b) and the composition replay fix `412f358fa9`. Original branch preserved, no force push, no history rewrite.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0133\"],\n  \"summary\": \"Xinfa baseline storage convergence: settlements publish witness manifests/receipts only, Atlas bodies stay local-immutable, legacy promotions authenticated via digest-pinned backfill, no history rewrite\",\n  \"verification\": [\"check-project-cut-settlement unit+integration tests\", \"backfill-legacy-atlas-roots tests\", \"buildchain-documentation-witness tests and --check\", \"witness-only fresh checkout KFD-1 verification\", \"shifu lint\", \"Project Cut settlement cycle with fit independent review\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n\n\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-21T21:31:58Z",
          "mergedAt": "2026-07-21T22:48:18Z",
          "additions": 2460,
          "deletions": 447,
          "changedFiles": 433
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 161,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/161",
          "title": "Refresh governed publication surfaces",
          "body": "## Summary\n\n- update Buildchain, KFD, and all paper package pins to their current governed releases\n- add the Episodes to Primitives paper to the publication catalog\n- render KFD formal-model and terminology pages plus the terminology contract/schema\n- keep Buildchain badges intact across the 2.14.13 bundle field boundary\n- equalize homepage action-loop card heights across responsive layouts\n\n## Verification\n\n- `corepack pnpm@11.9.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `corepack pnpm@11.9.0 run build`\n- `corepack pnpm@11.9.0 run check`\n- `node --check scripts/render-site.mjs`\n- `bash -n scripts/build-site.sh scripts/check-site.sh`\n- headless Chrome card-height measurements at 1440px, 820px, and 390px: one uniform height at each viewport\n- Episodes PDF SHA-256: `6d330c243facd537c7ab0a94436889133b0f88f091ad309e8801e69c2987ea65`\n\nRelated upstream defect: kungfu-systems/buildchain#1503",
          "author": "dongkeren",
          "createdAt": "2026-07-21T22:48:04Z",
          "mergedAt": "2026-07-21T23:00:11Z",
          "additions": 319,
          "deletions": 73,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 163,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/163",
          "title": "Release production from 5235669dac90",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `5235669dac9006d9624beea433a6154078d931a4`\n- Artifact hash: `22c76ed270698ccaba71621566aef687ad4e3c91a13dbaf2ccdabb76bb7c6ee6`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29875678919)\n- Required label: `buildchain-release`\n- Release branch: `release/production-5235669dac90`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-21T23:11:50Z",
          "mergedAt": "2026-07-21T23:20:33Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1200,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1200",
          "title": "feat(mission-control): add Initiative and Assignment L3 world",
          "body": "## Summary\n\n- add the versioned kungfu.initiative-assignment contract world and canonical Initiative/Assignment fact surfaces\n- retain kungfu.mission-control v1-v3 evidence as a read-only projection with sealed identity coordinates unchanged\n- expose successor Python, Profile action, collaboration, and Work Dashboard intent APIs while keeping Mission/Go compatibility commands\n- register ADR-0130 and successor ADR-0134 plus the KFD-1 welded surface; leave KFD-7 Pursuit unchanged\n- bind the refreshed moving-main settlement at Project Cut sha256:23bb25624ac392e5e9e09449ae80d68163b4832729ed63e3c228d12ee47f50d0 and commit a96cb2cc8423ac2b416bcaf6c2981a699b1e93aa\n\n## Verification\n\n- full native Core build on Linux x64\n- Mission Control Profile activation/catalog focused test\n- focused Atlas import plus Initiative/Assignment coexistence and sealed-identity tests\n- Work Dashboard: 27/27\n- ADR audit and structural pass\n- ruff format/check, py_compile, JSON/hash checks, git diff --check\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0130\", \"ADR-0134\"],\n  \"summary\": \"Deliver the additive Initiative and Assignment L3 contract world with exact read-only legacy evidence projection\",\n  \"verification\": [\"Linux native Core build\", \"Mission Control Profile and Atlas storage focused tests\", \"Work Dashboard 27 of 27\", \"ADR structural audit\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T14:42:52Z",
          "mergedAt": "2026-07-22T00:15:16Z",
          "additions": 1059,
          "deletions": 199,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1505,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1505",
          "title": "fix(release): close current publication issue gaps",
          "body": "## Summary\n\n- make the declared promotion channel authoritative for GitHub Release prerelease/latest metadata\n- keep managed README badge blocks intact in the generated homepage lead\n- deduplicate contract-drift reports across compatible runtime digest changes and suppress the local Build Surface Fixture self-report\n- refresh the reviewed v2-alpha contract lock and release-impact evidence\n\n## Validation\n\n- `pnpm run check` (743 tests passed; generated surfaces and 4 Action bundles verified)\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org/`\n- site badge boundary assertion\n- zone identity guard and public-context leak scan\n\nCloses #1500\nCloses #1503\nCloses #1504",
          "author": "dongkeren",
          "createdAt": "2026-07-22T00:25:34Z",
          "mergedAt": "2026-07-22T00:39:44Z",
          "additions": 427,
          "deletions": 121,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 164,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/164",
          "title": "Align action cards and paper ordering",
          "body": "## Summary\n\n- reset action-loop list-item margins so every homepage card shares the same top edge\n- fix the canonical papers order to White Paper, Foundation, Observer, Episodes\n- enforce package-set, registry, manifest, and homepage card ordering in checks\n- guard the action-card margin reset as part of the visual contract\n\n## Verification\n\n- `corepack pnpm@11.9.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `corepack pnpm@11.9.0 run build`\n- `corepack pnpm@11.9.0 run check`\n- `node --check scripts/render-site.mjs`\n- `bash -n scripts/build-site.sh scripts/check-site.sh`\n- headless Chrome at 1440px: seven cards share one top coordinate, one height, and `margin-top: 0px`\n- responsive browser checks at 820px and 390px: all cards retain `margin-top: 0px`",
          "author": "dongkeren",
          "createdAt": "2026-07-22T00:30:29Z",
          "mergedAt": "2026-07-22T00:40:16Z",
          "additions": 27,
          "deletions": 7,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 165,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/165",
          "title": "Release production from dd55f32b01dd",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `dd55f32b01dde0a77f01f5864d5b11f8fd2d78be`\n- Artifact hash: `71ebff68d8791160e0a6a3984240ed1f39b078073d1e8eec78c49f708cebedcc`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29880901541)\n- Required label: `buildchain-release`\n- Release branch: `release/production-dd55f32b01dd`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T00:51:58Z",
          "mergedAt": "2026-07-22T01:02:28Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1506,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1506",
          "title": "fix(release): seal standalone binary publication",
          "body": "## Summary\n\n- dispatch Binary Distribution after managed promotion and seal its controller evidence\n- auto-admit exact three-platform archives into the protected GitHub Release publisher\n- add fail-closed publication authority checks, generated contracts, docs, and tests\n\n## Validation\n\n- `pnpm run check` (745 tests passed)\n- `git diff --check`\n\n## Control plane\n\n- provisioned protected environment `buildchain-release-assets` with a `v*` tag deployment policy",
          "author": "dongkeren",
          "createdAt": "2026-07-22T01:27:02Z",
          "mergedAt": "2026-07-22T01:32:26Z",
          "additions": 851,
          "deletions": 81,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1507,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1507",
          "title": "chore(release): promote sealed binary publication to alpha",
          "body": "## Summary\n\nPromote the reviewed Buildchain standalone binary publication fix from `dev/v2/v2.14` to the alpha channel.\n\nThe promotion will publish the next exact alpha, then run Binary Distribution and the sealed `buildchain-release-assets` publisher for the same tag.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T01:33:40Z",
          "mergedAt": "2026-07-22T01:36:41Z",
          "additions": 1267,
          "deletions": 191,
          "changedFiles": 49
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1508,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1508",
          "title": "fix(release): grant bootstrap binary dispatch",
          "body": "## Summary\n\nGrant the Buildchain self-promotion caller the `actions: write` permission required by the newly sealed promotion shell to dispatch Binary Distribution.\n\nThis fixes the workflow validation `startup_failure` observed in run 29883618497 before any job was created.\n\n## Validation\n\n- `pnpm run check:workflows`\n- `node --test tests/build-surface.test.mjs` (83 tests passed)\n- `git diff --check`",
          "author": "kungfu-origin",
          "createdAt": "2026-07-22T01:40:41Z",
          "mergedAt": "2026-07-22T01:47:36Z",
          "additions": 6,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1212,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1212",
          "title": "feat(mission-control): add build-free assignment capture",
          "body": "## Summary\n\nAdd a build-free, capture-only Assignment request ingress before runtime admission. Requests and capture receipts are canonical and content-addressed, workspace target resolution matches the existing capture-only policy, and expiry is dry-run/exact-plan with retained evidence.\n\n## Related issue\n\nAtlas goal `2026-07-21-kungfu-hub-capture-surface`.\n\n## Changes\n\n- add `./shifu assignment capture|cleanup` on POSIX and Windows source launchers\n- preserve opaque Atlas work definitions through canonical JSON round trips\n- keep capture separate from Initiative association, Assignment admission/claim, runtime, journal, and Git effects\n- add content-addressed receipts, idempotence, stale-plan fencing, retained-byte expiry, and incomplete-capture failure tests\n- register ADR-0135 and the integration/cross-time contract surface\n\n## Verification\n\n- `./shifu test:assignment-capture`\n- `./shifu fix`\n- `./shifu check`\n- `./shifu check:source`\n- `./shifu docs:check`\n- `./shifu adr:audit -- --json`\n- `bash -n shifu`\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0135\"],\n  \"summary\": \"Stage a build-free Assignment request capture boundary with canonical retained evidence and no semantic admission authority\",\n  \"verification\": [\"Assignment capture tests\", \"changed-scope gate\", \"source acceptance\", \"documentation contracts\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-22T01:02:25Z",
          "mergedAt": "2026-07-22T01:49:51Z",
          "additions": 1332,
          "deletions": 0,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1509,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1509",
          "title": "chore(release): promote binary dispatch permission to alpha",
          "body": "## Summary\n\nPromote the reviewed self-publication permission fix from `dev/v2/v2.14` to the alpha channel.\n\nThis closes the startup failure from run 29883618497 and allows the promotion shell to dispatch Binary Distribution.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T01:48:26Z",
          "mergedAt": "2026-07-22T01:51:25Z",
          "additions": 6,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1511,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1511",
          "title": "fix(release): grant binary dispatch to promotion job",
          "body": "## Summary\n- keep preflight on read-only Actions access\n- grant Actions write to the promote job that dispatches exact-tag Binary Distribution\n- lock the permission boundary with exact workflow tests and regenerated contract evidence\n\n## Validation\n- `pnpm run check` (745/745 tests)\n- `git diff --check`\n\nFixes the alpha promotion HTTP 403 observed in run 29884290299.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T02:04:28Z",
          "mergedAt": "2026-07-22T02:07:34Z",
          "additions": 13,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1512,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1512",
          "title": "fix(release): propagate binary evidence access",
          "body": "## Summary\n- propagate `actions: read` through the sealed binary publication authority job\n- preserve `contents: read` and the protected publication environment\n- add an exact nested reusable-workflow permission regression test\n\n## Evidence\n- Binary Distribution run 29884875919 built all three platforms successfully\n- Binary Release Assets run 29884957715 failed at workflow startup because the nested authority requested Actions evidence access that its caller did not grant\n\n## Validation\n- `node scripts/check-inventory.mjs`\n- `pnpm run check:workflows`\n- `node --test tests/build-surface.test.mjs` (83/83)",
          "author": "dongkeren",
          "createdAt": "2026-07-22T02:10:52Z",
          "mergedAt": "2026-07-22T02:14:07Z",
          "additions": 5,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1513,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1513",
          "title": "fix(release): publish binary checksums",
          "body": "## Summary\n- generate checksum evidence without hashing the output file itself\n- deterministically rebuild `checksums.txt` from the exact downloaded binary artifacts inside the sealed publisher\n- publish the checksum file with the three platform archives\n\n## Evidence\n- Binary Release Assets run 29885402849 successfully published all three archives but the release lacked `checksums.txt` because the publisher downloaded only the original per-platform artifacts\n\n## Validation\n- `node scripts/check-inventory.mjs`\n- `pnpm run check:workflows`\n- `node --test tests/build-surface.test.mjs` (83/83)\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-22T02:22:06Z",
          "mergedAt": "2026-07-22T02:25:10Z",
          "additions": 29,
          "deletions": 10,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 166,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/166",
          "title": "fix(site): align dogfood flow cards",
          "body": "## Summary\n\n- reset inherited list margins on the dogfood flow cards\n- add a regression check for the alignment contract\n\n## Verification\n\n- `corepack pnpm@11.9.0 run build`\n- `corepack pnpm@11.9.0 run check`\n- `node --check scripts/render-site.mjs`\n- `bash -n scripts/build-site.sh scripts/check-site.sh`\n- browser geometry checks at 1440px, 820px, and 390px\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, CLI, billing, quota, or usage-attribution changes\n- [x] No hosted-service identity or branding changes\n- [x] Changes the public web surface and therefore requires the normal preview, staging, and production release gates",
          "author": "dongkeren",
          "createdAt": "2026-07-22T02:27:38Z",
          "mergedAt": "2026-07-22T02:43:40Z",
          "additions": 14,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1211,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1211",
          "title": "feat(docs): distribute ADR identity allocation",
          "body": "## Summary\n\nFreeze the legacy sequential ADR namespace at the exact pre-cutover tree and move all new Core/Shifu ADRs to offline UUIDv7 identities.\n\n## Related issue\n\nAtlas goal: 2026-07-22-kungfu-adr-identity-concurrency-gate\n\n## Changes\n\n- add `./shifu adr:new` with local UUIDv7 generation and exclusive one-file writes\n- grandfather exactly 140 legacy id/path pairs at commit `8857b44ff5ced6328524508639f30353238f63ed`\n- make UUID ADRs publication-reachable without a shared README/index mutation\n- fail closed on identity, routing, extension, profile, inventory, duplicate, and release-gate drift\n- prove two independently authored ADR branches merge in either order without identity or index conflicts\n- absorb the merged Assignment capture work and migrate its post-cutover `ADR-0135` to `KF-ADR-019f878c-5480-7890-bc64-9b2aab7e9aa5` without widening the grandfather set\n\n## Verification\n\n- `./shifu adr:identity:test` (39/39)\n- `./shifu docs:check` (85/85 fixture tests plus audit/toolchain/examples)\n- `./shifu check:source`\n- independent read-only review: fit, no blocking correctness findings\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-019f86ff-a8d6-7431-ae05-0ec95fdb7ace\", \"KF-ADR-019f878c-5480-7890-bc64-9b2aab7e9aa5\"],\n  \"summary\": \"Freeze legacy ADR identity authority and enable conflict-free offline UUIDv7 authoring.\",\n  \"verification\": [\"./shifu adr:identity:test\", \"./shifu docs:check\", \"./shifu check:source\", \"independent read-only review\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes ADR release admission evidence only; no package publication or deployment action is performed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T00:31:53Z",
          "mergedAt": "2026-07-22T02:58:40Z",
          "additions": 2084,
          "deletions": 57,
          "changedFiles": 48
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 168,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/168",
          "title": "Release production from dfd2ae51365f",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `dfd2ae51365f5f7eb5e6ae1a308ab29ec056d5f8`\n- Artifact hash: `f410e2b8cda914cdd7ec601464446df63e443aab1b9ece79fa4f8def1476d82b`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29886578424)\n- Required label: `buildchain-release`\n- Release branch: `release/production-dfd2ae51365f`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T02:55:10Z",
          "mergedAt": "2026-07-22T03:07:00Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1514,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1514",
          "title": "chore(release): promote sealed binary fixes to alpha",
          "body": "## Summary\n\nPromote the sealed binary publication fixes from `dev/v2/v2.14` to the protected alpha channel.\n\nThis is the required channel-workflow rerun for #1510. It carries the promotion job dispatch permission, nested publisher evidence access, and deterministic `checksums.txt` publication.\n\n## Related issue\n\nCloses #1510.\n\n## Changes\n\n- grant the protected promotion job the scoped Actions dispatch permission\n- propagate read access into the sealed binary publisher\n- publish deterministic release checksums beside all three platform archives\n\n## Verification\n\n- PR #1511 merged with Buildchain check 745/745\n- PR #1512 merged and sealed Binary Release Assets run 29885402849 completed\n- PR #1513 targeted publisher checks passed 83/83\n- sealed publisher run 29886171118 uploaded Darwin arm64, Linux x64, Windows x64 archives and `checksums.txt`\n- this PR must pass the protected Buildchain Ref Promotion workflow before merge\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change is limited to scoped GitHub Actions permissions and sealed release-asset publication. It introduces no token-bearing fallback or hosted-registry environment route.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T03:07:29Z",
          "mergedAt": "2026-07-22T03:10:33Z",
          "additions": 46,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1214,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1214",
          "title": "fix(shifu): pin sealed Buildchain alpha binary",
          "body": "## Summary\n\nPin Shifu's standalone Buildchain tool to the sealed `2.14.14-alpha.2` binary release while keeping the npm verifier package on stable `2.14.1`.\n\nThe pin is backed by the refreshed alpha contract lock and release-admission runtime evidence. A clean XDG cache/config probe fetched the macOS arm64 archive from the GitHub release and executed KFD claims without a source build or hosted-registry fallback.\n\n## Related issue\n\nRelated to kungfu-systems/buildchain#1510 and Atlas goal `2026-07-11-buildchain-kfd-artifact-onboarding`.\n\n## Changes\n\n- move the standalone Shifu Buildchain pin and fallback to `2.14.14-alpha.2`\n- refresh the `v2-alpha` contract lock to source `3743410384e2f163c04561a4a87270afe9f2574a`\n- retain the stable npm verifier boundary and document the separate tool pin\n- update release-admission fixtures for the current alpha runtime\n\n## Verification\n\n- `./shifu check`\n- `./shifu kfd:buildchain:check`\n- `./shifu test:release-admission`\n- `cargo test --manifest-path crates/Cargo.toml -p shifu-core buildchain_is_pin_first_and_uses_release_archives`\n- isolated `XDG_CONFIG_HOME` and `XDG_CACHE_HOME` fresh-cache probe: fetched `2.14.14-alpha.2`, printed `v2.14.14-alpha.2`, and passed `./shifu kfd2:claims:check`\n- Buildchain release `v2.14.14-alpha.2`: Darwin arm64, Linux x64, Windows x64 archives and `checksums.txt` present\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix updates the already-defined standalone Buildchain tool pin and its sealed release evidence; it does not change a Kungfu architecture contract.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change consumes an already-published sealed Buildchain alpha. The three-platform release assets, checksum manifest, refreshed contract lock, fresh-cache acquisition, release-admission tests, and full Shifu check provide the evidence.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T02:43:13Z",
          "mergedAt": "2026-07-22T03:14:59Z",
          "additions": 27,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1217,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1217",
          "title": "chore(project-cut): close KFD artifact onboarding",
          "body": "## Summary\n\nPublish the exact Project Cut closure for the completed KFD artifact onboarding and preserve the successor relationship after the merge-queue baseline advanced.\n\n## Related issue\n\n- kungfu-systems/buildchain#1510\n- Follow-up to #1214\n\n## Changes\n\n- Record the original explicit empty-Episode Project Cut.\n- Record the successor Cut against the exact post-merge baseline.\n- Retain the Xinfa baseline witnesses and promotion manifest for the successor Atlas.\n\n## Verification\n\n- `./shifu project-cut verify --execute --json`\n- Full staged pre-commit gate, including docs, invariant, KFD boundary, schema authority, and formatting checks\n- Native Completion Claim and independent Completion Review: fit, zero Episode evidence, explicit empty Episode delta\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This PR only publishes content-addressed Project Cut and Xinfa closure evidence for behavior already merged in #1214; it does not change an architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe tracked artifacts are content-addressed closure evidence; Project Cut verification, the full staged gate, and independent exact-root review all passed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (no behavior change in this follow-up)",
          "author": "dongkeren",
          "createdAt": "2026-07-22T03:38:28Z",
          "mergedAt": "2026-07-22T03:45:01Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 169,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/169",
          "title": "feat(site): add reader contract and guided synthesis",
          "body": "## Summary\n\n- make `site-libkungfu-dev` the explicit owner of first-screen framing, reading order, cross-surface synthesis, progressive disclosure, navigation, and visual composition\n- preserve Kungfu, KFD, and Buildchain as the sole authorities for runtime semantics, protocol decisions, commands, schemas, release facts, qualification, and provenance\n- add a four-layer reader contract and source-bound continuity/supply-chain synthesis to the root human and agent surfaces\n- give Core, KFD, and Buildchain concise reader-first entry screens before their complete upstream-owned content\n- add failure-oriented checks for source binding, claim classes, ownership drift, human/agent parity, down-level content, and stable routes\n\n## Claim boundary\n\nThe KFD Agent Hub profile remains alpha. This change does not claim external vendor adoption, plural-Hub deployment, stable certification, an industry standard, or a published libkungfu registry package.\n\n## KFD-1 version impact\n\n`minor` — this is an additive public reader and machine contract (`libkungfu-dev-reader-contract/v1` and `site-manifest/v1`). Existing human routes, machine routes, upstream content, and claim boundaries remain compatible.\n\n## Validation\n\n- `jq empty src/fixtures/site-manifest.json src/fixtures/libkungfu-runtime-surface.json`\n- `node --check scripts/render-site.mjs`\n- `bash -n scripts/check-site.sh`\n- `shellcheck scripts/check-site.sh`\n- `pnpm build`\n- `pnpm check`\n- browser screenshots at 1440x1000 and 390x844 for the root, Core, KFD, and Buildchain surfaces\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T04:02:23Z",
          "mergedAt": "2026-07-22T04:20:08Z",
          "additions": 950,
          "deletions": 53,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1515,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1515",
          "title": "docs: expose Buildchain supply chain role",
          "body": "## Summary\n\nExpose Buildchain as the exact declaration-to-artifact evidence layer between KFD-3 product discovery and KFD-2 purpose-bound assessment. The package-owned product-mechanism site fact carries the same bounded claim.\n\n## Changes\n\n- add the README layer explanation and vendor evaluation route\n- add agentSupplyChain metadata to product-mechanism.json\n- regenerate package-owned site facts and page digests\n\n## Verification\n\n- corepack pnpm@11.7.0 run check\n- 745 unit tests passed\n- generated site bundle check passed\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n\nThe change describes existing release-passport authority and explicitly keeps product facts, KFD-2 trust decisions, certification, and adoption outside Buildchain.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-22T03:49:50Z",
          "mergedAt": "2026-07-22T04:20:33Z",
          "additions": 76,
          "deletions": 7,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1516,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1516",
          "title": "fix(release): explicitly dispatch sealed binary publication",
          "body": "## Summary\n\n- dispatch Binary Release Assets explicitly after the binary evidence passport succeeds\n- remove the `workflow_run` hop that GitHub suppresses for `GITHUB_TOKEN`-dispatched evidence runs\n- keep product publication isolated behind the existing sealed capability and environment\n- update generated publication authority and contract evidence\n\n## Regression\n\nProtected alpha promotion run 29887811187 dispatched Binary Distribution run 29888008577, but no Binary Release Assets run followed and `v2.14.14-alpha.3` had no platform archives.\n\n## Validation\n\n- `pnpm run check`\n- 745 unit tests passed\n- action bundle integrity passed\n\nCloses #1510",
          "author": "dongkeren",
          "createdAt": "2026-07-22T03:52:27Z",
          "mergedAt": "2026-07-22T04:23:08Z",
          "additions": 38,
          "deletions": 23,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 236,
          "url": "https://github.com/kungfu-systems/kfd/pull/236",
          "title": "docs: define KFD supply chain role",
          "body": "## What\n\nDefine where KFD-3, KFD-2, and the Agent Hub alpha profile sit in the open Agent Supply Chain while preserving KFD neutrality and receiver-owned admission.\n\n## Contribution type\n\n- [x] decision, registry, schema, verifier, or release surface\n- [x] governance, documentation, or maintenance\n\n## Claim and evidence\n\nThe change updates rooted public profile documentation and therefore regenerates the Agent Hub manifest, dependent Agent Runtime root, WASM verifier, fixtures, and KFD-1/2/3 evidence. It explicitly does not claim two independent production Hubs, external adoption, stable certification, or industry-standard status.\n\n## Interests and review\n\nFounding implementation interest: kungfu-systems. No external adoption claim.\n\n## Compatibility and registry agreement\n\n- [x] node scripts/check.mjs passes as part of npm run check\n- [x] Applicability, compatibility, migration, and supersession impact are explicit\n- [x] Published coordinates remain immutable\n- [x] No frozen decision text is rewritten\n\n## Version impact (per KFD-1)\n\n- [x] patch: documentation and rooted evidence refresh\n\nVerification: npm run build:verifier; npm run update:evidence; npm run check.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T03:49:46Z",
          "mergedAt": "2026-07-22T04:26:21Z",
          "additions": 87,
          "deletions": 38,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 64,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/64",
          "title": "docs: add Agent Supply Chain narrative",
          "body": "## Summary\n\nAdd Agent Supply Chain as the white paper second strategic axis and publish one package-owned machine narrative for kungfu.tech and papers.libkungfu.dev.\n\nThe narrative preserves five-layer ownership, proved-now versus protocol-enabled maturity, and explicit non-claims for multi-Hub adoption, endorsement, standards status, and blanket compatibility.\n\n## Checks\n\n- [x] npm run check\n- [ ] npm run build if a TeX toolchain is available\n- [x] Buildchain release surface remains generated from the existing publication contract\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs.\n- [x] No unpublished reviewer correspondence or private operational data.\n- [x] Provider/API/data claims are sourced or clearly marked as future work.\n- [x] Public branding and trademark language stays factual.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T03:49:56Z",
          "mergedAt": "2026-07-22T04:27:53Z",
          "additions": 235,
          "deletions": 9,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1517,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1517",
          "title": "chore(release): promote explicit binary publication to alpha",
          "body": "## Summary\n\nPromote the explicit sealed binary publication dispatch fix from `dev/v2/v2.14` to the protected alpha channel.\n\nThis closes the remaining #1510 gap: `GITHUB_TOKEN`-dispatched Binary Distribution runs no longer depend on a suppressed downstream `workflow_run` event.\n\n## Verification\n\n- PR #1516 merged through native merge queue\n- local `pnpm run check`: 745/745 tests and action bundles green\n- PR head hosted Build Surface passed Linux, Windows, and macOS\n- merge-group Verify passed on top of predecessor PR #1515\n- recovery Binary Release Assets run 29889658427 completed and restored all `v2.14.14-alpha.3` platform assets\n\n## Governance risk check\n\n- [x] provider APIs, CLIs, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n\nNo token-bearing fallback, hosted registry environment, or ad hoc publication route is introduced.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and generated contract evidence are aligned\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T04:26:24Z",
          "mergedAt": "2026-07-22T04:30:23Z",
          "additions": 114,
          "deletions": 30,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 66,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/66",
          "title": "release: prepare Agent Supply Chain alpha.9",
          "body": "## Summary\n\nPrepare @kungfu-tech/paper-kungfu-product-white-paper@0.1.0-alpha.9 on the development line with the Agent Supply Chain strategic axis, package-owned site bundles, and current Buildchain alpha contract.\n\n## Verification\n\n- npm run update:site-bundles\n- npm run check\n- git diff --check\n- feature PR #64 full Buildchain publication workflow passed, including the Linux PDF build\n\n## Release boundary\n\nThis PR only prepares the development-line version and site-bundle coordinates. The separate dev/v0/v0.1 to alpha/v0/v0.1 promotion is the publication gate.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T04:31:27Z",
          "mergedAt": "2026-07-22T04:34:07Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 238,
          "url": "https://github.com/kungfu-systems/kfd/pull/238",
          "title": "chore(kfd): anchor Agent Supply Chain alpha 41",
          "body": "## Summary\n\nPrepare @kungfu-tech/kfd@1.0.0-alpha.41 on the development line so the Agent Supply Chain narrative and current Buildchain alpha contract can be published through the protected alpha promotion path.\n\n## Verification\n\n- npm run update:evidence\n- npm run check\n- Rust verifier workspace: 8 tests passed\n- Agent Hub and Agent Runtime profile checks passed\n- generated KFD-1, KFD-2, and KFD-3 evidence matches the alpha.41 anchor\n\n## Release boundary\n\nThis PR only prepares the development-line version and evidence. The separate dev/v1/v1.0 to alpha/v1/v1.0 promotion is the publication gate.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T04:31:27Z",
          "mergedAt": "2026-07-22T04:34:31Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 239,
          "url": "https://github.com/kungfu-systems/kfd/pull/239",
          "title": "release(kfd): promote Agent Supply Chain alpha.41",
          "body": "Promote the verified KFD development line to alpha/v1/v1.0 for @kungfu-tech/kfd@1.0.0-alpha.41.\n\nThe development line now contains:\n\n- the bounded Agent Supply Chain role for KFD-3 discovery and KFD-2 purpose-bound trust;\n- current Buildchain v2-alpha contract acceptance;\n- regenerated KFD-1, KFD-2, and KFD-3 source-bound evidence;\n- green Agent Hub, Agent Runtime, Rust, native, and WASM checks on PRs #236 and #238.\n\nMerging this PR triggers real npm and GitHub alpha publication. It therefore remains pending explicit human release authority.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T04:34:42Z",
          "mergedAt": "2026-07-22T04:39:58Z",
          "additions": 9316,
          "deletions": 762,
          "changedFiles": 91
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 67,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/67",
          "title": "chore(release): promote Agent Supply Chain paper alpha.9",
          "body": "Promote the Agent Supply Chain white paper update to the protected alpha channel as 0.1.0-alpha.9.\n\nThe development line now contains:\n\n- the second strategic axis across executive summary, architecture, ecosystem, and conclusion;\n- package-owned brand and evidence site bundles with bounded vendor evaluation guidance;\n- the exact current Buildchain alpha contract lock;\n- a successful Linux PDF publication build and all repository checks on PRs #64 and #66.\n\nMerging this PR triggers real npm and GitHub alpha publication. It therefore remains pending explicit human release authority.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T04:34:19Z",
          "mergedAt": "2026-07-22T04:40:18Z",
          "additions": 242,
          "deletions": 16,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1197,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1197",
          "title": "feat(api): add layered runtime action SDK boundary",
          "body": "## Summary\n\nAdd the first contract-generated four-language L1 SDK slice over the sole `kungfu_get_api` C ABI waist, while defining protocol-owned identity and carrier encoding boundaries.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add KF-ADR-019f87cb-b4e7-7cda-80ec-be5aceb7b500 and its machine-readable layered API/encoding contract\n- add additive runtime-action interface v1 and safe C++/Node/Python/Rust wire wrappers\n- generate typed geometry-root projections from one language-keyed contract\n- freeze exact receipt/root bytes and shared negative vectors across four installed SDK artifacts\n- measure semantic versus operational filesystem writes and add required affected-native CI qualification\n- preserve Xinfa's direct and transitive FlatBuffers-free boundary after its move to `crates/xinfa`\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu build:core`\n- `./shifu pack:sdk`\n- `./shifu layers:qualify:sdk -- --report product/qualification/layered-sdk-report.json`\n- `kungfu_api_contract_tests`\n- `cargo test -p kungfu-sdk --features link-native` with the staged native runtime\n- exact-head independent review: no blockers\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f87cb-b4e7-7cda-80ec-be5aceb7b500\"],\n  \"summary\": \"Stage the additive runtime-action ABI and generated four-language SDK pilot with frozen wire vectors\",\n  \"verification\": [\"source acceptance\", \"full Core build\", \"four-language installed-artifact qualification\", \"ABI contract tests\", \"independent review\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR extends source/qualification evidence and SDK package contents; frozen artifact qualification and workflow-authority gates cover the change.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-21T09:39:17Z",
          "mergedAt": "2026-07-22T04:40:25Z",
          "additions": 3665,
          "deletions": 109,
          "changedFiles": 165
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1219,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1219",
          "title": "docs: add Agent Supply Chain evaluation route",
          "body": "## Summary\n\nAdd one public architecture and vendor-evaluation route that places the Kungfu runtime in the five-layer Agent Supply Chain while preserving exact pre-release and first-party evidence boundaries.\n\n## Changes\n\n- add a concise README stack and non-claim block\n- add docs/architecture/agent-supply-chain.md\n- route the page from the documentation guide, map, and architecture index\n- register public document metadata in the repository authority\n\n## Verification\n\n- ./shifu docs:check\n- deterministic documentation gate: 85 tests passed\n- staged repository gate passed during commit\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"This documentation-only branch composes existing KFD, Buildchain, runtime, Exit, and qualification contracts without changing an architecture contract.\"}\n-->\n\n## Governance risk check\n\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n\nNo release is published and no adoption, provider endorsement, second production Hub, stable compatibility, or power-loss qualification is claimed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-22T03:49:53Z",
          "mergedAt": "2026-07-22T04:43:23Z",
          "additions": 109,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 171,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/171",
          "title": "fix(site): preserve immutable paper chrome",
          "body": "## Summary\n\n- scope reader-contract CSS away from the Papers surface\n- preserve all four published immutable paper version pages byte-for-byte\n- reject future reader-contract style leakage in the site checker\n\n## Failure reproduced\n\nMerged-main run 29890787016 correctly rejected staging because `episodes-to-primitives/v0.1.0-alpha.2/index.html` changed from the deployed immutable digest `20057177...` to a new digest.\n\n## Validation\n\n- restored the staging digest to `20057177f2072c2ad1f394225a8b782dfe69d58d82df1f0e6f3b01fc7fcb1a23`\n- byte-compared all four immutable version pages against pre-reader-contract main (`0a06dce`)\n- byte-compared root/Core/KFD/Buildchain against merged reader-contract main (`c8898bb`)\n- `pnpm build`\n- `pnpm check`\n- `bash -n scripts/check-site.sh`\n- `shellcheck scripts/check-site.sh`\n- `node --check scripts/render-site.mjs`\n- `git diff --check`\n\nKFD-1 impact remains minor and additive. No production apply is requested.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T04:37:03Z",
          "mergedAt": "2026-07-22T04:46:44Z",
          "additions": 7,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 240,
          "url": "https://github.com/kungfu-systems/kfd/pull/240",
          "title": "feat(conformance): add Agent Hub adopter profile",
          "body": "## What\n\nPublish an adopter-facing experimental Agent Hub conformance profile from the KFD npm package:\n\n- fixed, rooted Agent Hub 20 cross-Hub vector suite\n- dual-Hub JSONL adapter request/response contracts\n- package-, capability-, adapter-, suite-, result-, and transcript-bound report\n- independent offline JavaScript report verifier\n- two structurally different reference adapters\n- clean npm-pack and consumer-working-directory tests\n\n## Contribution type\n\n- [ ] proposal or Candidate\n- [ ] evidence, counterexample, or independent review\n- [x] adopter Profile or implementation\n- [x] decision, registry, schema, verifier, or release surface\n- [x] governance, documentation, or maintenance\n\n## Claim and evidence\n\nA passing `kfd.agent-hub-report/v1` is exact-scope evidence for the named adapter bytes, two or more declared Hub capability documents, fixed Agent Hub 20 suite, installed KFD package cut, platform, and retained residual risks. It is not KFD certification, a security assessment, production fitness, independent vendor adoption, or evidence that provisional semantics became normative.\n\nEvidence:\n\n- both reference adapters pass 20/20\n- the offline verifier rejects ten adversarial report mutations\n- clean npm-pack extraction runs and verifies without a repository checkout\n- a consumer-local adapter configuration test proves the runner preserves the caller working directory\n- the existing Runtime 100 native/WASM parity and adversarial checks remain green after the CLI addition\n\nFalsifiers include root drift, missing or duplicate vectors, mutated expectations or responses, capability-root mismatch, adapter-byte mismatch, result/transcript drift, and claim-scope widening.\n\n## Interests and review\n\nKungfu is the founding steward and mandatory adopter of KFD. This change implements a public package surface maintained by kungfu-systems; no independent vendor adoption is claimed.\n\n- [x] A substantive change has a reviewer other than its author\n- [ ] Activation or Foundation Revision has an independent reviewer\n\n## Compatibility and registry agreement\n\n- [x] `node scripts/check.mjs` passes\n- [x] Applicability, compatibility, migration, and supersession impact are explicit\n- [x] Published coordinates remain immutable\n- [x] After Foundation Freeze, decision texts remain append-only (supersession over rewrite)\n\n## Version impact (per KFD-1)\n\n- [x] minor (additive adopter-facing profile, schemas, runner, and verifier)\n\n## Verification\n\n- `npm run check`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T04:44:51Z",
          "mergedAt": "2026-07-22T04:51:16Z",
          "additions": 2147,
          "deletions": 98,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 241,
          "url": "https://github.com/kungfu-systems/kfd/pull/241",
          "title": "fix(release): grant promotion actions permission",
          "body": "## Summary\n\nGrant the KFD Buildchain promotion caller the job-level permissions required by the current nested alpha publication workflow, then regenerate all release evidence that binds the workflow source.\n\nThe approved alpha.41 promotion reached a fail-closed GitHub startup error because the caller allowed actions read while the nested alpha job requires actions write.\n\n## Verification\n\n- actionlint .github/workflows/buildchain-ref-promotion.yml\n- npm run update:evidence\n- npm run check\n- npm run check:verifier\n- GitHub failure evidence: https://github.com/kungfu-systems/kfd/actions/runs/29891722789\n\n## Release recovery\n\nAfter this PR merges into dev/v1/v1.0, promote dev to alpha again. The package version remains 1.0.0-alpha.41 because the failed startup published no npm package or GitHub Release.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T04:47:39Z",
          "mergedAt": "2026-07-22T04:58:50Z",
          "additions": 17,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 70,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/70",
          "title": "feat(narrative): index immutable supply-chain evidence",
          "body": "## Summary\n- add immutable evidence coordinates to every Agent Supply Chain layer\n- publish explicit known limits alongside maturity status\n- enforce the five-layer evidence/limit contract in package checks\n\n## Verification\n- npm run update:site-bundles\n- npm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-22T04:55:56Z",
          "mergedAt": "2026-07-22T05:00:56Z",
          "additions": 220,
          "deletions": 5,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 244,
          "url": "https://github.com/kungfu-systems/kfd/pull/244",
          "title": "chore(release): promote dev/v1/v1.0 to alpha",
          "body": "Promote the current reviewed KFD development cut to alpha after restoring reusable promotion workflow permissions. Includes the Agent Supply Chain narrative and Agent Hub conformance profile.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T04:59:05Z",
          "mergedAt": "2026-07-22T05:03:52Z",
          "additions": 2157,
          "deletions": 102,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 71,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/71",
          "title": "release: prepare Agent Supply Chain alpha.10",
          "body": "Prepare the immutable evidence-index revision of the Kungfu white paper package for alpha.10.\n\nVerification:\n- npm run update:site-bundles\n- npm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-22T05:01:42Z",
          "mergedAt": "2026-07-22T05:05:13Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 72,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/72",
          "title": "chore(release): promote white paper alpha.10",
          "body": "Promote the immutable Agent Supply Chain evidence-index package to alpha.10 after source and publication checks passed.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T05:05:23Z",
          "mergedAt": "2026-07-22T05:08:01Z",
          "additions": 227,
          "deletions": 12,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1519,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1519",
          "title": "feat(kfd): add declarative Agent Hub builder flow",
          "body": "## Summary\n\n- add one-declaration Agent Hub adoption with init, inspect, test, and explain APIs and CLI commands\n- lock the exact KFD profile, protocol, vectors, verifier, adapter, and invocation boundary into portable evidence\n- attach verified Agent Hub evidence to Release Passport and expose reusable workflow support\n- pin @kungfu-tech/kfd 1.0.0-alpha.41 and regenerate its authoritative KFD site facts\n- make standalone binary distribution an explicit opt-in capability so npm-only consumers do not require binary-distribution.yml\n\n## Verification\n\n- pnpm run check: 753/753 tests passed\n- generated site, workflow contracts, and four action bundles are current\n- demo clean-clone canary passed against the frozen Agent Hub runtime and the public KFD alpha.41 cut\n- train/v2/v2.3/agent-hub-builder-flow points to b867b6ae6f20ec485aae63e28941026541effca7\n\n## Recovery evidence\n\nKFD alpha.41 published npm, its exact tag, and its GitHub Release before the old promotion shell failed on an unconditional binary-distribution.yml dispatch. The new standalone-binary-distribution input defaults to false; Buildchain self-promotion opts in explicitly. A complete rerun after this change reaches v2-alpha can reuse the durable transaction without republishing existing artifacts.\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [x] official hosted or managed services\n- [x] no credentials, private logs, or provider bypasses introduced\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and generated contract evidence are aligned",
          "author": "dongkeren",
          "createdAt": "2026-07-22T05:21:05Z",
          "mergedAt": "2026-07-22T05:26:46Z",
          "additions": 3634,
          "deletions": 175,
          "changedFiles": 95
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1521,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1521",
          "title": "chore(release): promote Agent Hub builder flow to alpha",
          "body": "## Summary\n\nPromote the declarative Agent Hub builder flow and the standalone binary-distribution capability gate from dev/v2/v2.14 to the protected alpha channel.\n\n## Verification\n\n- feature PR #1519 merged through the native merge queue as cc5e9285890e0734131bbd9660f2451c16141f85\n- local pnpm run check passed 753/753 tests with generated site, workflows, and four action bundles current\n- hosted PR checks passed across Linux, Windows, and macOS\n- downstream clean-clone canary passed against train/v2/v2.3/agent-hub-builder-flow and public @kungfu-tech/kfd@1.0.0-alpha.41\n- npm-only promotion regression proves binary-distribution.yml is not required unless standalone-binary-distribution is explicitly enabled\n\n## Recovery intent\n\nAfter the alpha channel publishes this fix, KFD promotion run 29892784105 will be rerun completely. Its durable alpha.41 npm package, exact tag, and GitHub Release already exist and must be reused idempotently; the rerun only completes the aggregate/controller receipt.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and generated contract evidence are aligned",
          "author": "dongkeren",
          "createdAt": "2026-07-22T05:28:45Z",
          "mergedAt": "2026-07-22T05:31:27Z",
          "additions": 3634,
          "deletions": 175,
          "changedFiles": 95
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1520,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1520",
          "title": "fix(release): skip absent binary distribution workflow",
          "body": "## Summary\n- probe for a consumer-owned binary distribution workflow before dispatch\n- skip the standalone binary stage when the consumer has no such surface\n- keep authentication and non-404 workflow lookup failures closed\n\n## Verification\n- actionlint reusable promotion workflows\n- pnpm run check\n- git diff --check\n\nObserved from KFD alpha.41 promotion: npm and GitHub Release succeeded, but the generic aggregate failed on a non-applicable 404 dispatch.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T05:21:18Z",
          "mergedAt": "2026-07-22T05:32:46Z",
          "additions": 15,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 173,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/173",
          "title": "feat(site): explain Buildchain value to Hub builders",
          "body": "## Summary\n\n- reframe the Buildchain first screen around Builder Hub admission value\n- show the KFD-3 offer -> KFD-2 assessment -> Buildchain release -> local Hub verdict loop\n- separate current shipped evidence from the future ecosystem effect and preserve the no-Hub-competition boundary\n- keep the same source-bound synthesis in the generated agent index and add contract checks for ordering and parity\n\n## Validation\n\n- `node --check scripts/render-site.mjs`\n- `bash -n scripts/check-site.sh`\n- `git diff --check`\n- `npm run build`\n- `npm run check`\n- headless Chrome desktop and 390px mobile visual inspection\n\nNo production release is included in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T05:27:54Z",
          "mergedAt": "2026-07-22T05:36:04Z",
          "additions": 438,
          "deletions": 19,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1218,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1218",
          "title": "feat(work): add Project Cut product loop facade",
          "body": "## Summary\n\nDeliver the first independently usable Project Cut-centered Work loop slice. The change freezes the machine Work API, adds one read-only Cut/Work model, binds managed runs to exact WorkRefs, and exposes completion and settlement plans without creating a second authority state machine.\n\nFull executable `begin` and settlement remain intentionally gated on native Initiative/Assignment orchestration reaching the shared `dev/v4/v4.0` baseline.\n\n## Related issue\n\nAtlas goal `2026-07-22-kungfu-project-cut-product-loop`.\n\n## Changes\n\n- add the versioned machine-readable Work API contract\n- add side-effect-free `kungfu cut` inspection with explicit missing, conflicted, stale, thin, and degraded states\n- extend `kungfu work` with unified `inspect`, `recover`, `complete`, and `settle` planning surfaces\n- make managed runs validate and idempotently bind an existing WorkRef before Episode execution\n- preserve Project Cut, Work journal, authority receipts, independent review, and continuation decisions as the canonical owners\n- stage a UUIDv7 ADR for the public Project Cut Work facade\n\n## Verification\n\n- `./shifu test:work-facade` — 3 Node tests and 14 Python tests passed\n- `./shifu adr:identity:test` — 39/39 passed\n- `./shifu docs:check:readonly` — 85/85 passed\n- `node --test --test-concurrency=1 scripts/release-promotion-rehearsal.test.mjs` — 9/9 passed\n- targeted Ruff formatting and checks passed\n- CLI catalog parity could not be regenerated locally because this worktree does not contain a built `pykungfu` native binding; hosted qualification remains required\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f87e8-6b8b-735c-b036-fa42d7cee8cf\"],\n  \"summary\": \"Stage the Project Cut-centered public Work facade with read-only inspection, typed recovery, exact WorkRef binding, and non-settling completion plans.\",\n  \"verification\": [\"Work facade contract tests\", \"ADR identity suite\", \"read-only documentation gate\", \"serialized release-promotion rehearsal\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe provider-facing change is limited to new local CLI/read-model surfaces. The release-evidence change is the staged ADR; no package is published or deployed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated because behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-22T03:45:05Z",
          "mergedAt": "2026-07-22T05:38:32Z",
          "additions": 1002,
          "deletions": 2,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1522,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1522",
          "title": "chore(release): prepare v2.14.14-alpha.5",
          "body": "## Summary\n\n- advance the v2.14 alpha release to `2.14.14-alpha.5`\n- publish the optional `binary-distribution.yml` dispatch fix from #1520 through the official alpha channel\n- regenerate the public Buildchain site and contract manifests for the exact version\n\n## Validation\n\n- `pnpm run check`\n- generated site bundle drift check\n- workflow and action bundle integrity checks",
          "author": "dongkeren",
          "createdAt": "2026-07-22T05:36:03Z",
          "mergedAt": "2026-07-22T05:41:56Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1525,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1525",
          "title": "fix(release): preserve stable shell input compatibility",
          "body": "## Summary\n\n- declare the new standalone binary input unsupported by the immutable stable promotion shell\n- keep forwarding it to the current alpha shell while omitting it from the pinned stable call\n- add a regression that inspects the generated stable reusable-workflow call\n\n## Why\n\nGitHub validates every reusable-workflow call at workflow compilation time, including jobs skipped by `if`. A consumer alpha rerun therefore failed before jobs because the generated stable call forwarded a new input to the older pinned stable shell.\n\n## Validation\n\n- `pnpm run check` (753 tests; site/workflow generation and four action bundles green)\n- `node --test tests/promotion-channel-router.test.mjs tests/build-surface.test.mjs` (96 tests)\n- `node scripts/generate-channel-promotion-workflow.mjs --check`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T05:43:01Z",
          "mergedAt": "2026-07-22T05:50:22Z",
          "additions": 10,
          "deletions": 6,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1526,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1526",
          "title": "chore(release): synchronize published alpha.5 history",
          "body": "## Summary\n\n- merge the already-published `alpha/v2/v2.14` alpha.5 history back into dev\n- preserve the #1520 optional binary-distribution fix on dev\n- resolve only generated timestamp/source metadata from the exact published alpha.5 anchor\n- remove the same-version/different-content conflict before preparing alpha.6\n\n## Validation\n\n- `pnpm run check`\n- generated site bundle drift check\n- workflow and action bundle integrity checks",
          "author": "kungfu-origin",
          "createdAt": "2026-07-22T05:46:44Z",
          "mergedAt": "2026-07-22T05:52:29Z",
          "additions": 9,
          "deletions": 9,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 82,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/82",
          "title": "feat(site): publish Capital & Stewardship principles",
          "body": "## Summary\n\n- publish a stable `/capital/` page for future capital-compatibility principles\n- keep the homepage product-first and expose the page only through About and the shared footer\n- distinguish KFD public-protocol stewardship from Kungfu Origin commercial durability without asserting legal ownership or governance effects\n- add route, copy-boundary, shared-layout, and build assertions\n\n## Public claim boundary\n\n- this is not a financing announcement, securities offer, subscription invitation, or transaction channel\n- no amount, valuation, security type, price, allocation, timetable, subscription mechanics, or transaction terms\n- KFD global credibility is stated as a goal, not as current standard status, independent adoption, or foundation status\n- the page does not establish or alter entity structure, IP ownership, trademark rights, protocol governance, or investor rights\n- any future transaction or operative rights require separate private diligence, approvals, professional review, and definitive documents\n\n## Review checklist\n\n- [x] Product priority: hero and primary header remain unchanged\n- [x] Technical claims: KFD is described only as the public protocol layer; future credibility is explicitly bounded\n- [x] Commercial claims: Kungfu Origin durability and ecosystem-expansion economics are principles, not financing commitments\n- [x] Securities/entity/IP/trademark/governance language: marked as non-operative and routed to professional review if a future transaction or legal arrangement is pursued\n- [x] Contact policy: public repository and issue tracker only; no email, direct mail, form, or financing-proposal channel\n\n## KFD impact\n\n- KFD-1: `minor` — new public reader route and stable second-level discoverability; no KFD, libkungfu, or Buildchain contract change\n- KFD-2: exact local build/check evidence plus 1440px desktop and 390px mobile full-page browser rendering; no horizontal overflow\n\n## Validation\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `bash -n scripts/build-site.sh scripts/check-site.sh`\n- `shellcheck scripts/build-site.sh scripts/check-site.sh`\n- `git diff --check`\n- Chrome full-page desktop: 1440px viewport, `scrollWidth=clientWidth=1425`\n- Chrome full-page mobile: 390px viewport, `scrollWidth=clientWidth=390`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T05:42:36Z",
          "mergedAt": "2026-07-22T05:53:10Z",
          "additions": 348,
          "deletions": 7,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 174,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/174",
          "title": "fix(site): keep Buildchain styles out of paper archives",
          "body": "## Summary\n\n- scope Buildchain/mobile overflow styles to non-Papers surfaces\n- preserve the byte-stable chrome of immutable paper version pages\n- add a regression check for reader-contract style leakage\n\n## Evidence\n\n- `npm run build`\n- `npm run check`\n- `node --check scripts/render-site.mjs`\n- `bash -n scripts/check-site.sh`\n- `git diff --check`\n- local immutable Episodes index matches the current production SHA-256: `989251febddc66d51d9a9785a93ddbc9a259bf5f1ac251f834e298af07cbf4bb`\n\n## Incident\n\nMain run 29894245862 rejected staging because the Buildchain homepage overflow rule leaked into `papers/archive/episodes-to-primitives/v0.1.0-alpha.2/index.html`, changing an immutable object digest. Production was not applied.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T05:43:11Z",
          "mergedAt": "2026-07-22T05:54:11Z",
          "additions": 14,
          "deletions": 7,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1528,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1528",
          "title": "chore(release): prepare v2.14.14-alpha.6",
          "body": "## Summary\n\n- advance the synchronized v2.14 alpha line to `2.14.14-alpha.6`\n- include the optional `binary-distribution.yml` dispatch fix from #1520 in the published package\n- regenerate the public Buildchain site and contract manifests for the exact version\n\n## Validation\n\n- Buildchain full check passed on the synchronized alpha.5 history in #1526\n- inventory, generated site drift, workflows, and action bundle integrity rechecked for alpha.6",
          "author": "kungfu-origin",
          "createdAt": "2026-07-22T05:54:11Z",
          "mergedAt": "2026-07-22T05:57:59Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 85,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/85",
          "title": "Release production from f2c1391ed8c7",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `f2c1391ed8c7d184c860c97526c52ad41ec2025e`\n- Artifact hash: `2b3653df85b3df26191bf013b78512b29418494eda065ec9406322439d777747`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29895051654)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-f2c1391ed8c7`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T05:55:21Z",
          "mergedAt": "2026-07-22T05:59:42Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1529,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1529",
          "title": "chore(release): promote v2.14.14-alpha.6",
          "body": "## Summary\n\n- promote reviewed dev release anchor #1528 to protected alpha\n- publish `@kungfu-tech/buildchain@2.14.14-alpha.6` with the optional binary-distribution dispatch fix from #1520\n- move `v2-alpha` to the exact fixed runtime\n\n## Evidence\n\n- alpha.5 history synchronization #1526\n- alpha.6 release anchor #1528\n- merge-group Verify 29895199507",
          "author": "dongkeren",
          "createdAt": "2026-07-22T05:58:25Z",
          "mergedAt": "2026-07-22T06:00:43Z",
          "additions": 40,
          "deletions": 24,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 86,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/86",
          "title": "feat: publish Agent Supply Chain narrative",
          "body": "## Summary\n\n- publish the five-layer Agent Supply Chain human route and machine contract\n- give each layer an owner, input, output, exact evidence coordinate, status, and known limit\n- add explicit multi-Hub non-claims, vendor 30-day next action, nav, canonical/OG/JSON/llms discovery, and mobile layout\n- consume the released KFD alpha.41 and product white-paper alpha.10 source contracts\n\n## Validation\n\n- `SITE_GENERATED_AT=2026-07-22T00:00:00Z SITE_PUBLISHED_AT=2026-07-22T00:00:00Z SITE_TIMESTAMP_POLICY=ci-injected SITE_SOURCE_REVISION=$(git rev-parse HEAD) pnpm run build`\n- `pnpm run check`\n- `git diff --check`\n- static accessibility, internal-link, metadata, machine-contract, and mobile breakpoint audit",
          "author": "dongkeren",
          "createdAt": "2026-07-22T06:24:58Z",
          "mergedAt": "2026-07-22T06:41:49Z",
          "additions": 247,
          "deletions": 33,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 176,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/176",
          "title": "feat: project Agent Supply Chain contract",
          "body": "## Summary\n\n- project the shared five-layer Agent Supply Chain on the developer homepage and `/agent-supply-chain.json`\n- preserve upstream ownership for KFD, Buildchain, product paper, and exact Kungfu runtime evidence\n- expose owner/input/output/evidence/status/known-limit fields plus explicit non-claims to humans and agents\n- update the pinned KFD alpha.41 and product white-paper alpha.10 release contracts\n\n## Validation\n\n- `SITE_GENERATED_AT=2026-07-22T00:00:00Z SITE_PUBLISHED_AT=2026-07-22T00:00:00Z SITE_TIMESTAMP_POLICY=ci-injected SITE_SOURCE_REVISION=$(git rev-parse HEAD) pnpm run build`\n- `pnpm run check`\n- `git diff --check`\n- static human/agent parity, accessibility, link, and Hub non-claim audit",
          "author": "dongkeren",
          "createdAt": "2026-07-22T06:24:57Z",
          "mergedAt": "2026-07-22T06:50:22Z",
          "additions": 141,
          "deletions": 45,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 87,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/87",
          "title": "Release production from b5889f3c9547",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `b5889f3c9547f8241ba43b60c5460118c30f3988`\n- Artifact hash: `39a6430811fe6f1aba7d18d9b3a4b98b31e184064bc1a27a40e5c9fb178db046`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29897587815)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-b5889f3c9547`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T06:45:30Z",
          "mergedAt": "2026-07-22T06:51:44Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1530,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1530",
          "title": "chore(release): prepare v2.14.14-alpha.7",
          "body": "## Summary\n- advance the unreleased Buildchain candidate from alpha.6 to alpha.7\n- regenerate the exact package-owned site and contract metadata\n- preserve the optional standalone binary-distribution compatibility fix in the candidate lineage\n\n## Why alpha.7\nThe alpha.6 promotion never published: its PR-stage evidence run was cancelled and cannot be rerun after GitHub removed the merged PR ref. A new candidate keeps the release evidence gate intact instead of bypassing or fabricating artifacts.\n\n## Verification\n- `pnpm run check`\n- timestamp-bound `pnpm run generate:site && pnpm run check:site`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "kungfu-origin",
          "createdAt": "2026-07-22T06:49:05Z",
          "mergedAt": "2026-07-22T06:54:13Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1531,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1531",
          "title": "chore(release): promote v2.14.14-alpha.7",
          "body": "## Summary\n- promote the fully qualified alpha.7 candidate from `dev/v2/v2.14`\n- preserve the optional standalone binary-distribution compatibility fix\n- publish through the normal Buildchain Ref Promotion evidence chain\n\n## Required evidence\n- candidate PR #1530 checks and three-platform release-candidate artifacts are green\n- dev merge-queue Verify is green at `b551826abbeb20648a7e9c75460b416bb33098e7`\n- alpha.6 was not published; alpha.7 is the unique recoverable publication candidate\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T06:54:46Z",
          "mergedAt": "2026-07-22T06:58:03Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1532,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1532",
          "title": "fix(build): bind channel router to workflow SHA",
          "body": "## Summary\n- bind the public channel router checkout to immutable `job.workflow_sha`\n- preserve the logical `job.workflow_ref` only for channel-routing evidence\n- bind the controller shell checkout to the same exact router SHA\n- cover merged-PR reruns where `refs/pull/N/merge` has expired\n\n## Validation\n- `pnpm run check` (753 tests; workflow/site/inventory; 4 action bundles)\n- contract digest: `sha256:c66c11937984ff26af869b1328d7a37d6b9273860ed8d1360cf4fc7c08166ffd`\n\n## Incident proof\nBuild Surface run `29895305561` attempt 2 failed after PR #1529 merged because `refs/pull/1529/merge` no longer existed. This patch uses the immutable called-workflow SHA that GitHub preserves for reruns.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T06:56:09Z",
          "mergedAt": "2026-07-22T07:01:09Z",
          "additions": 84,
          "deletions": 12,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 88,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/88",
          "title": "feat(site): clarify capital and publication hierarchy",
          "body": "## Summary\n\n- make Capital & Stewardship the prominent primary action in the homepage commercial-stewardship section\n- present the White Paper as the product thesis with a distinct card, label, and action\n- order the remaining research publications as Foundation Model, Observer, then Episodes\n- lock the reader hierarchy and card semantics in the site checks\n\n## Verification\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `bash -n scripts/build-site.sh scripts/check-site.sh`\n- `shellcheck scripts/build-site.sh scripts/check-site.sh`\n- desktop and 390px browser review for `/` and `/whitepaper/`\n- 390px device metrics: `scrollWidth == clientWidth` on both routes\n\n## Release impact\n\nKFD-1: patch. This changes reader hierarchy and presentation without adding a route, protocol claim, machine contract, or release-system behavior.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T07:04:28Z",
          "mergedAt": "2026-07-22T07:09:07Z",
          "additions": 124,
          "deletions": 21,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1534,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1534",
          "title": "chore(release): prepare v2.14.14-alpha.8",
          "body": "## Summary\n- advance the Buildchain candidate from alpha.7 to alpha.8\n- include the exact workflow SHA router binding merged by #1532\n- regenerate package-owned site and contract metadata\n\n## Why alpha.8\nAlpha.7 unblocked the KFD reconciliation path. Alpha.8 carries the durable router fix so a merged channel PR can retain exact reusable workflow checkout identity after GitHub removes its pull-request merge ref.\n\n## Verification\n- `pnpm run check` (753 tests, 4 action bundles)\n- `pnpm run check:site`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T07:06:20Z",
          "mergedAt": "2026-07-22T07:11:45Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 245,
          "url": "https://github.com/kungfu-systems/kfd/pull/245",
          "title": "chore(buildchain): accept v2 alpha runtime contract",
          "body": "## Summary\n- lock KFD alpha consumers to Buildchain `v2-alpha` at `ff0d7b4d5899edea44cfded755df83c2939f1899`\n- accept contract digest `sha256:092252416420b9539577d23a314916faf1a18f412e66444ef330cffabac8cc71`\n- refresh KFD-1/KFD-2/KFD-3 generated witness hashes\n\n## Compatibility\nThe compatibility digest and all 26 breaking surface digests are unchanged. This accepts a compatible runtime release that makes standalone binary distribution optional for npm-only consumers.\n\n## Verification\n- `npm run update:evidence`\n- `npm run check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T07:08:19Z",
          "mergedAt": "2026-07-22T07:12:20Z",
          "additions": 14,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 177,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/177",
          "title": "Release production from 48ab36ca8d7e",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `48ab36ca8d7ea65a2bcd7a1f015474513fc10b55`\n- Artifact hash: `6849d56b78424e40c4c7d9f223e2836285d344b978ee495f221cce84864375cd`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29898064755)\n- Required label: `buildchain-release`\n- Release branch: `release/production-48ab36ca8d7e`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T07:01:35Z",
          "mergedAt": "2026-07-22T07:14:40Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 89,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/89",
          "title": "Release production from d2ec0c88ae04",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `d2ec0c88ae04551acba4b6fdc187002202cc77b9`\n- Artifact hash: `934593af2d5fdfa5fd3cd4a1ac72ee0ce6e95fd1df8166eb5ea97e5423bfa9b4`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29899166476)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-d2ec0c88ae04`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T07:11:44Z",
          "mergedAt": "2026-07-22T07:15:00Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 246,
          "url": "https://github.com/kungfu-systems/kfd/pull/246",
          "title": "chore(release): reconcile alpha.41 Buildchain runtime",
          "body": "## Summary\n- promote the accepted Buildchain `v2-alpha` runtime lock into the KFD alpha line\n- preserve the already-published KFD `1.0.0-alpha.41` package and GitHub Release\n- rerun the idempotent release transaction so the final controller receipt proves npm-only promotion skips the absent standalone binary workflow\n\n## Evidence\n- Buildchain `2.14.14-alpha.7` release: https://github.com/kungfu-systems/buildchain/releases/tag/v2.14.14-alpha.7\n- KFD runtime-lock PR #245 is merged and green\n- KFD alpha.41 registry package and GitHub Release already exist; this reconciliation must not republish conflicting bytes\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T07:12:46Z",
          "mergedAt": "2026-07-22T07:16:00Z",
          "additions": 14,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 178,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/178",
          "title": "feat(site): add progressive disclosure routes",
          "body": "## Summary\n\n- bound the Hub, Core, Buildchain, KFD, and Papers homepages to reader-first overview content\n- move complete architecture, runtime, release-trust, decision, and publication evidence into stable depth routes\n- preserve human/agent parity and add homepage word budgets plus detail-route regression checks\n\n## Validation\n\n- `npm run build`\n- `npm run check`\n- `bash -n scripts/build-site.sh`\n- `bash -n scripts/check-site.sh`\n- `node --check scripts/render-site.mjs`\n- desktop and 390px browser rendering for all five overview and five depth routes; no horizontal overflow\n\n## Release boundary\n\nThis PR is intended for ordinary main/staging delivery only. It does not request a production release.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T07:02:09Z",
          "mergedAt": "2026-07-22T07:19:54Z",
          "additions": 612,
          "deletions": 185,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1535,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1535",
          "title": "fix(release): reconcile settled alpha transactions",
          "body": "## Summary\n- preserve exact version and tag outputs when an alpha target is already settled at the requested SHA\n- restore and finalize the durable complete transaction on an explicit promotion rerun\n- reuse existing publication evidence and never invoke the publish lifecycle again\n- keep legacy settled no-op calls mutation-free when no publish reconciliation was requested\n\n## Regression\n- anchored/manual KFD-shaped same-SHA dry-run emits `1.0.0-alpha.41` and `v1.0.0-alpha.41`\n- real rerun restores the complete transaction and asserts the publish script does not execute\n- prior generated-version settled no-op remains unchanged\n\n## Verification\n- targeted regression: 3/3 passed\n- `pnpm run check`: 755/755 tests; 4 action bundles current\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T07:17:45Z",
          "mergedAt": "2026-07-22T07:22:38Z",
          "additions": 261,
          "deletions": 46,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1538,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1538",
          "title": "chore(release): sync alpha.7 promotion history",
          "body": "## Summary\n- record the alpha.7 promotion merge as a second parent of the current alpha.8 dev lineage\n- preserve the current dev tree exactly\n- unblock the dev-to-alpha alpha.8 channel PR without discarding release history\n\n## Proof\n- merge commit first parent: `d04f3be785d1c681559d2f7a835078e125a9055a`\n- merge commit second parent: `ff0d7b4d5899edea44cfded755df83c2939f1899`\n- merge tree equals first-parent dev tree: `6884b7638ad8ef8e339bd3d0be39354ab8f6db4d`\n- content delta against dev: empty\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T07:25:16Z",
          "mergedAt": "2026-07-22T07:31:02Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 247,
          "url": "https://github.com/kungfu-systems/kfd/pull/247",
          "title": "chore(kfd): anchor Agent Supply Chain alpha 42",
          "body": "## Summary\n\nPrepare @kungfu-tech/kfd@1.0.0-alpha.42 on the development line after the Buildchain runtime-lock reconciliation advanced the alpha source.\n\n## Verification\n\n- npm run update:evidence\n- npm run check\n- Rust verifier workspace: 8 tests passed\n- Agent Hub, Agent Hub conformance, and Agent Runtime profile checks passed\n- generated KFD-1, KFD-2, and KFD-3 evidence matches the alpha.42 anchor\n\n## Release boundary\n\nThis PR only prepares the development-line version and evidence. The separate dev/v1/v1.0 to alpha/v1/v1.0 promotion remains the publication gate. No external adoption, stable status, or second production Hub is claimed.\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T07:27:56Z",
          "mergedAt": "2026-07-22T07:32:34Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1537,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1537",
          "title": "release: promote v2.14.14-alpha.8",
          "body": "## Summary\n- promote the complete v2.14.14-alpha.8 candidate from dev to alpha\n- include exact workflow SHA router binding from #1532\n- include settled same-SHA publication reconciliation from #1535\n\n## Admission policy\nThis pull request intentionally has auto-merge disabled. It must remain open until its own PR-stage Build Surface artifacts and Verify checks complete successfully; only then may it be merged and used by Buildchain Ref Promotion.\n\n## Verification\n- dev merge-group Verify for #1535: run 29899869643 passed\n- local `pnpm run check`: 755/755 tests and 4 action bundles passed\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T07:23:05Z",
          "mergedAt": "2026-07-22T07:34:25Z",
          "additions": 361,
          "deletions": 74,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1221,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1221",
          "title": "chore(core): upgrade libnode to 22.22.3-kf.4",
          "body": "## Summary\n\nUpgrade Kungfu's embedded Node runtime dependency to @kungfu-tech/libnode 22.22.3-kf.4.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Pin @kungfu-tech/libnode to 22.22.3-kf.4.\n- Refresh the wrapper and platform package lock entries.\n- Regenerate KFD upstream projections for libnode revision 4.\n\n## Verification\n\n- ./shifu kfd:buildchain:check\n- ./shifu check\n- Runtime resolution probe confirmed the Darwin library path exists.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Dependency maintenance updates an existing embedded runtime pin and generated evidence without changing architecture contracts\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe KFD release evidence was regenerated from the published package anchor and verified with the repository KFD and full check gates.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (no user-facing behavior change)",
          "author": "dongkeren",
          "createdAt": "2026-07-22T04:12:06Z",
          "mergedAt": "2026-07-22T07:34:27Z",
          "additions": 42,
          "deletions": 43,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 248,
          "url": "https://github.com/kungfu-systems/kfd/pull/248",
          "title": "chore(release): promote KFD alpha 42",
          "body": "## Summary\n\nPromote the development line containing the explicit @kungfu-tech/kfd@1.0.0-alpha.42 anchor to the protected alpha channel.\n\n## Evidence\n\n- release anchor PR: #247\n- dev merge commit: 2b248a36e2e1934573fc4587ad1db36293527270\n- local npm run update:evidence and npm run check passed\n- exact seven-file version/evidence transition independently reviewed\n\n## Boundary\n\nThis publishes an alpha package and release. It does not claim stable status, industry-standard adoption, external vendor endorsement, or a second independent production Hub.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T07:33:33Z",
          "mergedAt": "2026-07-22T07:37:19Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1539,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1539",
          "title": "Release v2.14.14 from qualified v2.14.14-alpha.8",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.14-alpha.8`\n- Candidate SHA: `0f220a75b0a930670dd662067be82b431467d2b7`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T07:47:32Z",
          "mergedAt": "2026-07-22T07:48:43Z",
          "additions": 5636,
          "deletions": 434,
          "changedFiles": 141
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 91,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/91",
          "title": "feat(capital): add investor perspective",
          "body": "## Summary\n\nAdd a dedicated investor-side framework beneath Capital & Stewardship. It explains how an open protocol can support company value, makes the evidence burden explicit, and discloses the cross-border facts and risk capacity relevant to investor fit.\n\n## Changes\n\n- add `/capital/investor-perspective/` with a conditional protocol-to-company value chain\n- distinguish acceptable value capture from protocol control and customer lock-in\n- disclose the founder citizenship and Hong Kong incorporation facts, potential cross-border friction, and the need for transaction-specific professional review\n- link primary U.S. Treasury and BIS diligence context without classifying any future transaction\n- add a prominent Investor Perspective entry to `/capital/`\n- register the route in shared layout, build assertions, site checks, and README policy\n\n## Verification\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash -n scripts/build-site.sh scripts/check-site.sh`\n- `shellcheck scripts/build-site.sh scripts/check-site.sh`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- desktop and 390px mobile render review; no horizontal overflow\n- Buildchain preview for the same commit passed on superseded PR #90\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: this changes public positioning and adds a route on the production domain. It does not change corporate structure, protocol governance, infrastructure, deployment workflows, or transaction terms. Content checks preserve the non-offer and transaction-specific review boundaries.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-22T07:58:18Z",
          "mergedAt": "2026-07-22T08:08:48Z",
          "additions": 508,
          "deletions": 4,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 180,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/180",
          "title": "feat(site): add main-site return link",
          "body": "Merge feature/header-main-site-link into main (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-22T08:10:04Z",
          "mergedAt": "2026-07-22T08:10:18Z",
          "additions": 56,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 92,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/92",
          "title": "Release production from 7b0e063f37fa",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `7b0e063f37faa1b1767f9633add291ef87be8391`\n- Artifact hash: `68a8442e55d7d40a7d2f88b93c1fb220acbff8dfc02aa64b4cbf3389d82af0d7`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29902858886)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-7b0e063f37fa`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T08:14:26Z",
          "mergedAt": "2026-07-22T08:17:12Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 134,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/134",
          "title": "chore: consume KFD release",
          "body": "Buildchain release propagation from @kungfu-tech/kfd into the kfd.libkungfu.dev site surface.\n\nBuildchain release propagation plan:\n\n```json\n{\n  \"schemaVersion\": 1,\n  \"contract\": \"kungfu-buildchain-release-propagation-plan\",\n  \"source\": \"kfd\",\n  \"upstreamRelease\": {\n    \"repository\": \"kungfu-systems/kfd\",\n    \"channel\": \"alpha\",\n    \"tag\": \"v1.0.0-alpha.42\",\n    \"sourceSha\": \"03deef6bbc6e2ac8aecfedc76f17f6c74a72b878\",\n    \"package\": {\n      \"name\": \"@kungfu-tech/kfd\",\n      \"version\": \"1.0.0-alpha.42\",\n      \"integrity\": \"sha512-bl3xQwdhpBZPplemrFnBIq7O/xRu+HurQhNOhOlx/+8blFVQF3m9UFNXri04i+pxbQNXMtZbNtqMyegZeIcEMw==\"\n    },\n    \"releasePassport\": {\n      \"url\": \"https://github.com/kungfu-systems/kfd/releases/download/v1.0.0-alpha.42/buildchain.release.json\",\n      \"sha256\": \"18f0d2321b88b37ceeb8822a6949e351b8d28f3c2f1f23a9081742de18a81199\"\n    }\n  },\n  \"targets\": [\n    {\n      \"edge\": \"kfd-to-site-libkungfu-dev\",\n      \"source\": \"kfd\",\n      \"target\": \"site-libkungfu-dev\",\n      \"repository\": \"kungfu-systems/site-libkungfu-dev\",\n      \"channel\": \"alpha\",\n      \"baseRef\": \"main\",\n      \"lockPath\": \"buildchain.upstreams/kfd.release.json\",\n      \"lock\": {\n        \"schemaVersion\": 1,\n        \"contract\": \"kungfu-buildchain-release-propagation-lock\",\n        \"upstream\": {\n          \"node\": \"kfd\",\n          \"repository\": \"kungfu-systems/kfd\",\n          \"channel\": \"alpha\",\n          \"tag\": \"v1.0.0-alpha.42\",\n          \"sourceSha\": \"03deef6bbc6e2ac8aecfedc76f17f6c74a72b878\",\n          \"package\": {\n            \"name\": \"@kungfu-tech/kfd\",\n            \"version\": \"1.0.0-alpha.42\",\n            \"integrity\": \"sha512-bl3xQwdhpBZPplemrFnBIq7O/xRu+HurQhNOhOlx/+8blFVQF3m9UFNXri04i+pxbQNXMtZbNtqMyegZeIcEMw==\"\n          },\n          \"releasePassport\": {\n            \"url\": \"https://github.com/kungfu-systems/kfd/releases/download/v1.0.0-alpha.42/buildchain.release.json\",\n            \"sha256\": \"18f0d2321b88b37ceeb8822a6949e351b8d28f3c2f1f23a9081742de18a81199\"\n          }\n        },\n        \"downstream\": {\n          \"node\": \"site-libkungfu-dev\",\n          \"repository\": \"kungfu-systems/site-libkungfu-dev\",\n          \"channel\": \"alpha\",\n          \"baseRef\": \"main\",\n          \"lockPath\": \"buildchain.upstreams/kfd.release.json\"\n        },\n        \"propagation\": {\n          \"graphContract\": \"kungfu-buildchain-release-propagation-graph\",\n          \"edge\": \"kfd-to-site-libkungfu-dev\",\n          \"channelPolicy\": \"preserve\",\n          \"channelMap\": {\n            \"alpha\": \"alpha\",\n            \"release\": \"release\"\n          },\n          \"exact\": true,\n          \"floatingTags\": false\n        },\n        \"lockSha256\": \"5070b1eef1b3583060fd2b2ae70e6279c18bc5f9752338ef30aa991be9e702eb\"\n      }\n    }\n  ],\n  \"summary\": {\n    \"targetCount\": 1,\n    \"channels\": [\n      \"alpha\"\n    ],\n    \"repositories\": [\n      \"kungfu-systems/site-libkungfu-dev\"\n    ]\n  }\n}\n```\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-20T15:56:18Z",
          "mergedAt": "2026-07-22T08:18:32Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 181,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/181",
          "title": "fix(site): preserve immutable paper pages",
          "body": "Merge fix/immutable-header-preservation into main (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-22T08:20:20Z",
          "mergedAt": "2026-07-22T08:20:28Z",
          "additions": 53,
          "deletions": 44,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1226,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1226",
          "title": "chore(project-cut): seal Agent Supply Chain narrative",
          "body": "## Summary\n\nSeal the already-merged Agent Supply Chain narrative delivery with its required Project Cut and exact admitted Xinfa Atlas.\n\n## Related issue\n\nParent delivery: #1219\n\n## Changes\n\n- record an explicit empty Episode delta for the documentation-only delivery\n- publish Project Cut `sha256:48f4331d848427820aad787eed44c6dd2707caa8025bc86558e8ad37f927041c`\n- promote the exact admitted Atlas `sha256:6e41409116fa74f2417b96edddf05d766bbcda8adb18201eb3ea49eefcfb9c3f`\n\n## Verification\n\n- `project-cut prepare` dry-run and execute produced the same cut root\n- `project-cut commit-observe` published commit `6a105769753d99742aa117f29281a9d177311794`\n- staged gate passed, including documentation, invariant, Project Cut, and format checks\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This PR records content-addressed settlement evidence for an already-reviewed documentation narrative and does not alter an architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe new files are generated, content-addressed Project Cut and Atlas receipts; the release mechanism and product behavior are unchanged.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T07:23:37Z",
          "mergedAt": "2026-07-22T08:22:05Z",
          "additions": 4,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 182,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/182",
          "title": "fix(site): retain immutable archive index",
          "body": "Merge fix/immutable-archive-index into main (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-22T08:26:46Z",
          "mergedAt": "2026-07-22T08:26:52Z",
          "additions": 4,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1540,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1540",
          "title": "fix(kfd): resolve Windows package manager shims",
          "body": "## Summary\n\n- share the standalone Windows command shim with the Agent Hub adapter runner\n- resolve npm, npx, pnpm, yarn, and corepack through their .cmd shims on Windows\n- preserve direct process spawning on macOS and Linux\n- refresh generated Node API contract digests\n\n## Regression\n\nThe Windows regression injects a win32 spawn boundary and verifies an Agent Hub adapter build invokes npm.cmd with shell execution.\n\n## Validation\n\n- node --test tests/kfd-agent-hub.test.mjs tests/cli.test.mjs\n- pnpm run check (756 tests passed; 4 action bundles passed)\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n\nFixes the official v2 Agent Hub conformance failure: spawnSync npm ENOENT on Windows.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T08:26:10Z",
          "mergedAt": "2026-07-22T08:31:28Z",
          "additions": 55,
          "deletions": 21,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1541,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1541",
          "title": "release: promote Windows package-manager shim patch",
          "body": "## Summary\n- promote the merged Windows package-manager shim fix from dev to alpha\n- make the official Agent Hub adapter build resolve `npm.cmd` on Windows\n- reuse the standalone-binary shim implementation rather than adding a demo workaround\n\n## Admission policy\nThis pull request intentionally has auto-merge disabled. It must remain open until its own PR-stage Build Surface artifacts and Verify checks complete successfully; only then may it be merged and used by Buildchain Ref Promotion.\n\n## Verification\n- source PR #1540 Verify passed: run 29903985537\n- source PR #1540 Build Surface passed on Linux, macOS, and Windows: run 29903986108\n- merge-group Verify passed: run 29904214515\n- local `pnpm run check`: 756/756 tests and 4 action bundles passed\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T08:32:24Z",
          "mergedAt": "2026-07-22T08:41:27Z",
          "additions": 55,
          "deletions": 21,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1227,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1227",
          "title": "docs(adr): resolve alpha settlement evidence debt",
          "body": "## Summary\n\nResolve legacy ADR metadata debt so the complete v4 development delta can pass the alpha settlement gate without weakening stable admission.\n\n## Changes\n\n- classify 27 legacy unknown records as partial with explicit evidence exemptions\n- move 9 implemented-but-unqualified records back to staged\n- preserve all stable blockers until qualification evidence exists\n\n## Verification\n\n- `./shifu check`\n- `./shifu docs:check`\n- `./shifu adr:audit` (structural findings: 0)\n- `./shifu release:promotion:rehearse`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"ADR-0008\",\n    \"ADR-0009\",\n    \"ADR-0010\",\n    \"ADR-0011\",\n    \"ADR-0014\",\n    \"ADR-0015\",\n    \"ADR-0016\",\n    \"ADR-0019\",\n    \"ADR-0020\",\n    \"ADR-0021\",\n    \"ADR-0022\",\n    \"ADR-0023\",\n    \"ADR-0024\",\n    \"ADR-0025\",\n    \"ADR-0026\",\n    \"ADR-0027\",\n    \"ADR-0028\",\n    \"ADR-0029\",\n    \"ADR-0030\",\n    \"ADR-0031\",\n    \"ADR-0032\",\n    \"ADR-0033\",\n    \"ADR-0034\",\n    \"ADR-0035\",\n    \"ADR-0038\",\n    \"ADR-0039\",\n    \"ADR-0044\",\n    \"ADR-0047\",\n    \"ADR-0050\",\n    \"ADR-0052\",\n    \"ADR-0054\",\n    \"ADR-0055\",\n    \"ADR-0056\",\n    \"ADR-0057\",\n    \"ADR-0059\",\n    \"ADR-0062\"\n  ],\n  \"summary\": \"Make legacy ADR implementation and qualification debt explicit before the first v4 alpha settlement\",\n  \"verification\": [\n    \"./shifu check\",\n    \"./shifu docs:check\",\n    \"./shifu adr:audit\",\n    \"./shifu release:promotion:rehearse\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR only makes existing evidence debt explicit; it does not waive stable qualification.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T08:37:51Z",
          "mergedAt": "2026-07-22T08:50:07Z",
          "additions": 64,
          "deletions": 37,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 183,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/183",
          "title": "Release production from c34559deb203",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `c34559deb203f60c592e040bf8ec2b537ed3496b`\n- Artifact hash: `a38df2d60ffb798762c8d2a0ef9fbc5dcf8c8f3ba0f08ad50b0aa5c431a0b26a`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29904028885)\n- Required label: `buildchain-release`\n- Release branch: `release/production-c34559deb203`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T08:37:43Z",
          "mergedAt": "2026-07-22T08:53:36Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 185,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/185",
          "title": "chore(buildchain): accept v2.14.14 contract",
          "body": "## Summary\n\n- review and accept Buildchain stable v2.14.14 contract world\n- bind the stable lock to exact runtime SHA `8e7955851381b50f0081008bc0655c4cf8aa92aa`\n- admit the publication-channel GitHub Release metadata guarantee and binary-distribution controller\n\n## Verification\n\n- Buildchain contract lock check: unchanged, compatible=true\n- `pnpm run build`\n- `pnpm run check`\n\n## Release context\n\nProduction run 29905769351 failed closed before build or deploy because the floating `v2` tag advanced after release PR #183 was staged. This lock refresh is required before retrying the stable publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T09:00:15Z",
          "mergedAt": "2026-07-22T09:01:59Z",
          "additions": 10,
          "deletions": 5,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1224,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1224",
          "title": "fix(ci): admit Project Cut before merge queue",
          "body": "## Summary\n\nReject deterministic Project Cut source drift and replay conflicts before a PR is approved or added to the merge queue.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Reconstruct the GitHub rebase-style merge candidate with temporary Git objects only.\n- Run Project Cut composition admission against that exact candidate.\n- Classify deterministic drift and conflicts as repair-required and non-retryable.\n- Add the admission to Source Acceptance and the Atlas Kungfu PR merge helper.\n\n## Verification\n\n- ./shifu test:project-cut-queue-admission\n- ./shifu check:source\n- Historical PR #1202 replay produced the exact GitHub merge-group tree and the two expected source-drift diagnostics.\n- Current branch admission against origin/dev/v4/v4.0 returned qualified.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix enforces the existing ADR-0116 Project Cut composition contract earlier in the delivery path without changing architecture authority\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change validates existing Project Cut evidence before approval and enqueue; the full Source Acceptance and Project Cut contract suites passed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-22T04:59:05Z",
          "mergedAt": "2026-07-22T09:02:53Z",
          "additions": 439,
          "deletions": 0,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1542,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1542",
          "title": "fix(release): keep passing controller receipts coherent",
          "body": "## Summary\n\n- omit stale failure reasons when a controller receipt resolves to `passed`\n- reject externally supplied passing receipts that still declare a failure reason\n- refresh the repository stable contract lock to the current `v2.14.14` release used by self-dogfood\n\n## Validation\n\n- `pnpm run check` (756 tests, 4 action bundles)\n- exact `v2.14.14` contract-lock check: unchanged, compatible, no drift\n\nThis repairs the contradictory `passed`/`qualifying=true` promotion receipt emitted for `2.14.15-alpha.0` and clears the unrelated stale stable lock that blocked the stable self-dogfood consumer.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T09:04:05Z",
          "mergedAt": "2026-07-22T09:13:09Z",
          "additions": 25,
          "deletions": 10,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1543,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1543",
          "title": "chore(release): promote v2.14.15 alpha receipt fix",
          "body": "## Summary\n\nPromote the merged v2.14 receipt-coherence and stable self-dogfood lock fix from `dev/v2/v2.14` to `alpha/v2/v2.14`.\n\n## Source evidence\n\n- source PR: #1542\n- merged source: `0eaccfa536ee83ed02dbc1af97ccbc50124d4400`\n- PR Verify: `29906484780`\n- PR Build Surface: `29906485301` (Linux, macOS, and Windows passed)\n- merge-group Verify: `29906788753`\n\nAfter merge, the promotion receipt will be checked for `passed`, `qualifying=true`, and absence of a stale failure reason before stable qualification proceeds.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T09:14:16Z",
          "mergedAt": "2026-07-22T09:21:14Z",
          "additions": 25,
          "deletions": 10,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1544,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1544",
          "title": "Release v2.14.15 from qualified v2.14.15-alpha.1",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.15-alpha.1`\n- Candidate SHA: `bf157446ad634849fa7f7dce438067dbf58e8ead`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T09:38:39Z",
          "mergedAt": "2026-07-22T09:39:58Z",
          "additions": 94,
          "deletions": 45,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1545,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1545",
          "title": "feat(web-surface): record cache-control classes",
          "body": "Summary:\n- add optional default, mutable, and immutable cache-control classes to the S3/CloudFront adapter\n- record effective cache policy in deploy plans, bindings, operations, and manifests\n- preserve existing consumer behavior when cache classes are not configured\n\nVerification:\n- corepack pnpm@11.7.0 run check: 757 tests passed; workflow, site bundle, and action bundle checks passed\n\nRelease readiness:\nThis enables site-kungfu-tech and site-libkungfu-dev to distinguish bounded-TTL HTML/JSON/XML from append-only publication archives while retaining exact CloudFront invalidation evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T09:40:48Z",
          "mergedAt": "2026-07-22T09:53:57Z",
          "additions": 324,
          "deletions": 106,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 1,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/1",
          "title": "feat: add clean-room Agent Hub demo",
          "body": "## Summary\n\n- add two independent file-CAS Agent Hubs with Ed25519 identities and explicit authority, admission, conflict, disclosure, completion, export, and recovery semantics\n- add the public KFD JSONL adapter and frozen Buildchain Agent Hub adoption declaration\n- add product tests, Runtime 100 soak, public governance documents, and an exact first-class Buildchain quickstart\n\n## Public contract cut\n\n- demo head: `70e32b47f2390dcb291b92409f3ba7f8e16bd2c9`\n- Buildchain: `@kungfu-tech/buildchain@2.14.14`, official `v2` `8e7955851381b50f0081008bc0655c4cf8aa92aa`\n- KFD: `@kungfu-tech/kfd@1.0.0-alpha.41`\n- adoption lock root: `sha256:ded43e95f877d817de234474b8d8a0c07b96d2ea89ab4856a3ce80f9541ed376`\n- verified report digest: `sha256:1d3a86b618fd579e36be3c6ae5c5c2f5a791ab553e217cc303baea2a4615b5a0`\n\n## Validation\n\n- clean clone from GitHub at the exact demo head\n- `npm ci --registry=https://registry.npmjs.org/`\n- `npm audit --omit=dev`: 0 vulnerabilities\n- `npm test`: 6/6 passed\n- `npm run build`: passed\n- `npm run runtime100`: 100/100 admitted\n- `npx --yes --package @kungfu-tech/buildchain@2.14.14 buildchain kfd hub test --for agent`: valid\n- publishable artifact scan: no private keys, local paths, or private material\n\n## Claim boundary\n\nThis is a first-party clean-room consumer and structural-independence witness. It is not KFD certification, a production security assessment, independent vendor adoption, or plural-vendor interoperability proof.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T07:59:50Z",
          "mergedAt": "2026-07-22T09:58:41Z",
          "additions": 1479,
          "deletions": 2,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1546,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1546",
          "title": "chore(release): promote web cache classes to v2.14 alpha",
          "body": "Promote the current v2.14 development line after Buildchain PR 1545.\n\nRelease intent:\n- publish explicit web-surface cache-control class support\n- retain immutable archive exclusions and exact invalidation evidence\n- unblock staging qualification for the Kungfu release-readiness run\n\nSource verification:\n- Buildchain PR 1545 merged at 2b95b9b4034f7183a5da7584605c47fbdfe8da1d\n- Verify workflow 29909800126 passed on the merged dev head",
          "author": "dongkeren",
          "createdAt": "2026-07-22T09:57:58Z",
          "mergedAt": "2026-07-22T10:01:09Z",
          "additions": 324,
          "deletions": 106,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 94,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/94",
          "title": "feat(deploy): classify web cache metadata",
          "body": "Summary:\n- declare bounded cache classes for preview, staging, and production\n- keep mutable HTML/JSON/XML at five minutes in staging and production\n- retain exact Buildchain invalidation evidence\n\nVerification:\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n\nDependency:\n- requires Buildchain PR 1545 for cache metadata application and evidence",
          "author": "dongkeren",
          "createdAt": "2026-07-22T09:45:37Z",
          "mergedAt": "2026-07-22T10:08:25Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 187,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/187",
          "title": "feat(deploy): classify web cache metadata",
          "body": "Summary:\n- assign a one-year immutable cache class to declared publication archives\n- bound mutable HTML/JSON/XML to five minutes in staging and production\n- retain exact Buildchain invalidation evidence\n\nVerification:\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n\nDependency:\n- requires Buildchain PR 1545 for cache metadata application and evidence",
          "author": "dongkeren",
          "createdAt": "2026-07-22T09:45:37Z",
          "mergedAt": "2026-07-22T10:08:25Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1225,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1225",
          "title": "feat(work): expose Work loop capability parity",
          "body": "## Summary\n\nExpose one shared, machine-readable Work loop capability manifest through both CLI and Agent surfaces. The manifest covers the complete nine-operation loop and reports each operation as available, degraded, plan-only, or unavailable without upgrading convenience projections into authority.\n\nGUI/TUI adapters, executable `begin`, portable import/export, and Domain Profile projection remain explicitly unavailable until their contracts are admitted.\n\n## Related issue\n\nAtlas goal `2026-07-22-kungfu-project-cut-product-loop`.\n\n## Changes\n\n- add side-effect-free `kungfu work capabilities --json`\n- project the exact same manifest from `kungfu agent capabilities --json` as `workLoop`\n- register the current Cut/Work public surfaces in KFD-3 and regenerate all governed projections\n- document the current multisurface boundary and incomplete release obligations\n- prove CLI/Agent equality and prove capability discovery does not initialize runtime state\n\n## Verification\n\n- `./shifu test:work-facade` — 3 Node tests and 15 Python tests passed\n- `./shifu check:agent-work-state-contract` — 7 Node tests and 40 Python tests passed\n- `./shifu check:agent-pack` — 15 files and 164 commands passed\n- `./shifu check:cli-catalog-parity` — generated catalog and declared consumers current\n- `./shifu check:source` — build-free source gate passed\n- `./shifu check` — changed-scope gate passed\n- commit staged gate — passed, including KFD evidence and documentation gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f87e8-6b8b-735c-b036-fa42d7cee8cf\"],\n  \"summary\": \"Stage the shared CLI and Agent Work loop capability manifest with complete operation coverage and fail-visible multisurface limits.\",\n  \"verification\": [\"Work facade contract tests\", \"Agent Work state contract\", \"CLI catalog parity\", \"source acceptance\", \"changed-scope gate\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe provider-facing change is limited to local CLI and Agent capability discovery. KFD evidence is regenerated; no package is published or deployed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated because behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T06:19:57Z",
          "mergedAt": "2026-07-22T10:18:27Z",
          "additions": 1624,
          "deletions": 83,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 2,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/2",
          "title": "feat(release): add Agent Hub qualification evidence",
          "body": "## Summary\n\n- add tracked KFD-2 public claim and KFD-3 collaboration-surface registries\n- add a public clean-clone release qualification workflow with KFD-1/2/3 and Agent Hub evidence\n- add twelve fail-closed report/declaration/artifact/policy/export-import mutations plus an offline Release Passport mutation\n- publish checksummed prerelease assets for exact tags while preserving the limited first-party clean-room structural-independence claim\n\n## Verification\n\n- `npm run check`\n- public Buildchain Agent Hub gate: valid report and verification\n- mutation oracle: 12/12 rejected as expected\n- KFD-1 gate and verifier: passed\n- KFD-2 generated claim: current\n- KFD-3 audit: 4/4 passed\n- Release Passport collect and independent verify: passed\n- Release Passport mutation: `kfdAgentHub.reportDigest` rejected\n- `actionlint .github/workflows/release-qualification.yml`\n\n## Claim boundary\n\nThis is first-party clean-room structural-independence evidence within the exact tested scope. It is not KFD certification, general third-party interoperability, a security or performance assessment, hosted-service evidence, or production-fitness certification.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T10:36:33Z",
          "mergedAt": "2026-07-22T10:42:06Z",
          "additions": 872,
          "deletions": 0,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 3,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/3",
          "title": "fix(release): include Passport sibling evidence",
          "body": "## Summary\n\n- include every Release Passport sibling evidence document in the checksummed public bundle\n- make a downloaded bundle independently verifiable without the source checkout\n- refresh the KFD-3 documentation surface digest after the release manual update\n\n## Verification\n\n- reproduced the previous downloaded-bundle failure (`impact.*`, `agentIndex.*`, and `productMechanism.*`)\n- assembled the complete sibling set in a clean temporary directory\n- `buildchain verify release-passport <downloaded-dir>/buildchain.release.json --json` returns `ok: true` with only the declared KFD-2 residual-risk warnings\n- KFD-3 audit remains 4/4 passed\n- `actionlint .github/workflows/release-qualification.yml`",
          "author": "dongkeren",
          "createdAt": "2026-07-22T10:44:43Z",
          "mergedAt": "2026-07-22T10:49:06Z",
          "additions": 8,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 95,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/95",
          "title": "Release production from 3cc2b787b1ba",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `3cc2b787b1baecd2b0828f8f90aa9d092a782042`\n- Artifact hash: `68a8442e55d7d40a7d2f88b93c1fb220acbff8dfc02aa64b4cbf3389d82af0d7`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29910769164)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-3cc2b787b1ba`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T10:10:42Z",
          "mergedAt": "2026-07-22T10:59:54Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 188,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/188",
          "title": "Release production from ea8c7facd858",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `ea8c7facd85858a08361209c364a0692fcbe7c1c`\n- Artifact hash: `d0de12189097f914698f26b375d51a800ca8b5dc8b4352f9d23df2b89d6fae49`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29910768465)\n- Required label: `buildchain-release`\n- Release branch: `release/production-ea8c7facd858`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T10:22:51Z",
          "mergedAt": "2026-07-22T10:59:54Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1231,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1231",
          "title": "ci(dco): admit trusted GitHub merge envelopes",
          "body": "## Summary\n\nAdmit only trusted GitHub-generated two-parent merge envelopes without weakening DCO for authored content commits.\n\n## Changes\n\n- keep `Signed-off-by` mandatory for every ordinary commit\n- admit an unsigned merge only when it has exactly two parents, the exact GitHub committer identity, and the canonical same-repository PR merge subject\n- continue inspecting every parent/content commit independently\n- refresh the closed-world workflow authority digests\n\n## Verification\n\n- full alpha-to-dev replay: 1494 signed commits, 4 trusted GitHub merge envelopes, 0 missing\n- `./shifu check:gate-catalog`\n- `./shifu check:source`\n- full pre-commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Tighten DCO handling for platform-authored merge envelopes without changing architecture contracts\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change narrows the merge-envelope admission shape and does not grant publication authority or bypass content-commit DCO.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation authority projection refreshed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T09:17:00Z",
          "mergedAt": "2026-07-22T11:09:10Z",
          "additions": 22,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 96,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/96",
          "title": "feat(site): add stable not-found page",
          "body": "Add a deploy-owned `/404.html` so CloudFront can safely translate private-S3 AccessDenied responses into stable HTTP 404 responses.\n\nValidation:\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`",
          "author": "dongkeren",
          "createdAt": "2026-07-22T11:16:30Z",
          "mergedAt": "2026-07-22T11:16:44Z",
          "additions": 23,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 190,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/190",
          "title": "feat(site): add stable not-found page",
          "body": "Add a deploy-owned `/404.html` so CloudFront can safely translate private-S3 AccessDenied responses into stable HTTP 404 responses.\n\nValidation:\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`",
          "author": "dongkeren",
          "createdAt": "2026-07-22T11:16:30Z",
          "mergedAt": "2026-07-22T11:16:44Z",
          "additions": 31,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 191,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/191",
          "title": "Release production from f85654bbab92",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `f85654bbab923bce2549210e898f14b711f8ad69`\n- Artifact hash: `a7a2663816edb17c9b82d3e6cd0412dedae253b7d0e16a6b094ef3ba579966a5`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29915098690)\n- Required label: `buildchain-release`\n- Release branch: `release/production-f85654bbab92`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T11:39:34Z",
          "mergedAt": "2026-07-22T11:40:03Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1232,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1232",
          "title": "feat(ci): reuse exact affected-native proof in merge queue",
          "body": "## Summary\n\nReuse a recent successful `affected-native / linux` pull-request proof when the merge queue sees the exact same source tree, base revision, semantic affected-native plan, and partition contract.\n\nThe required merge-group context still runs and verifies the proof itself. Missing, duplicate, expired, cross-fork, failed, tampered, or drifted evidence falls back to the full two-partition native build.\n\nThis is a linear replacement for #1216; it is based directly on the current `dev/v4/v4.0` head so the rebase merge queue does not replay obsolete commits.\n\n## Related issue\n\nAtlas goal `2026-07-17-kungfu-dev-gate-latency-slo`.\n\n## Changes\n\n- add a source-bound proof descriptor, artifact lookup, sealing, and verification CLI\n- publish short-lived immutable PR proof artifacts only after both native partitions pass\n- probe and re-verify the exact proof in merge-group runs before skipping heavy shards\n- preserve the stable required `affected-native / linux` aggregate and fail-closed full-run fallback\n- add proof, artifact-authority, and workflow-wiring tests\n- refresh closed-world workflow authority and extend SHIFU-ADR-0004 operational documentation\n\n## Verification\n\n- `./shifu test:gate-latency` (25 passed)\n- `./shifu check:source` (passed)\n- staged repository gates on both DCO commits (passed)\n- Project Cut merge-queue admission against current `dev/v4/v4.0` (qualified, two commits replayed, no diagnostics)\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Implement exact affected-native proof reuse for merge-group validation while preserving the required context, trust boundary, and fail-closed full-run fallback.\",\n  \"verification\": [\"./shifu test:gate-latency\", \"./shifu check:source\", \"Project Cut merge-queue admission\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change consumes only GitHub-hosted same-repository workflow metadata and immutable artifacts through read-only `actions` permission. It does not add secrets, write permissions, or a branch-protection bypass.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T09:48:22Z",
          "mergedAt": "2026-07-22T12:07:48Z",
          "additions": 1288,
          "deletions": 13,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1234,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1234",
          "title": "feat(work): freeze Project Cut release evidence contract",
          "body": "## Summary\n\nFreeze the complete Project Cut product-loop release evidence boundary without claiming qualification. The contract names the six required scenarios, ten fail-closed negative cases, CLI/Agent/GUI/TUI parity, Darwin/Linux/Windows artifacts, built-in and third-party Domain Profiles, exact source/passport bindings, independent review, and zero residual unknowns.\n\nThe target Shifu Gate remains explicitly pending and the product loop remains `not-qualified` until a retained evidence runner and real cross-platform campaign exist.\n\n## Related issue\n\nAtlas goal `2026-07-22-kungfu-project-cut-product-loop`.\n\n## Changes\n\n- add the fail-closed Project Cut product-loop release contract and verifier\n- require exact source SHA, release-passport digest, platform artifacts, root/evidence bindings, independent review, and zero residual risks\n- reject incomplete scenario sets, missing GUI/TUI parity, self-review, third-party Core changes, and stale/mismatched evidence\n- register the release contract in the public Work API contract\n- document the pending Gate and remaining qualification blockers\n- keep synthetic verifier fixtures explicitly separate from release evidence\n\n## Verification\n\n- `node --test scripts/project-cut-product-loop-release.test.mjs` — 10/10 passed\n- `./shifu test:work-facade` — 13 Node tests and 15 Python tests passed\n- `./shifu check:source` — build-free source gate passed; 521 source-contract tests (520 passed, 1 platform skip), Agent Work 7 Node + 40 Python, upgrade 76, desktop 69\n- `./shifu check` — changed-scope gate passed on clean rerun\n- release-promotion rehearsal standalone rerun — 1/1 passed after one shared-ref concurrency flake\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f87e8-6b8b-735c-b036-fa42d7cee8cf\"],\n  \"summary\": \"Freeze the fail-closed Project Cut product-loop release evidence contract while retaining an explicit not-qualified and pending-Gate boundary.\",\n  \"verification\": [\"Project Cut release contract tests\", \"Work facade contract tests\", \"source acceptance\", \"changed-scope gate\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR defines an admission contract only. It does not publish artifacts, register the pending Gate, or claim retained product-loop qualification.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated because the release boundary changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T10:32:31Z",
          "mergedAt": "2026-07-22T12:52:35Z",
          "additions": 687,
          "deletions": 8,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1238,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1238",
          "title": "fix(core): preserve standard KFD request boundary",
          "body": "## Summary\n\nRestore exact KFD Runtime 100 compatibility and reliable promotion lifecycle execution while preserving the standard libkungfu ActionBinding authority.\n\n## Changes\n\n- stage the actual libkungfu_runtime shared library beside the KFD adapter on macOS and Linux\n- treat ActionBinding as an explicit Kungfu storage extension instead of a required KFD v1 field\n- retain and validate Episodes only for explicitly bound probes; never invent roots for standard KFD requests\n- align the frozen-artifact qualification harness and static boundary gate\n- make Shifu cold source bootstrap build and copy from one isolated Cargo target on POSIX and Windows\n\n## Verification\n\n- ./shifu check:kfd-agent-runtime-boundary\n- ./shifu check:gate-catalog\n- ./shifu check:entry-contract\n- Shifu entry contract tests: 14/14\n- full pre-commit source, documentation, KFD boundary, invariant, and formatting gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fix packaging, protocol compatibility, and cold-bootstrap execution regressions without changing the KFD or libkungfu architecture contracts\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change repairs the exact qualification artifact and lifecycle execution, while keeping storage retention fail-closed when the optional binding is explicitly requested.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation authority projection refreshed",
          "author": "dongkeren",
          "createdAt": "2026-07-22T12:02:35Z",
          "mergedAt": "2026-07-22T13:53:27Z",
          "additions": 116,
          "deletions": 27,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 5,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/5",
          "title": "chore(release): adopt Buildchain channel governance",
          "body": "## Summary\n\n- make Buildchain semver/auto the explicit version authority\n- replace the tag-driven custom release workflow with Buildchain Verify, release-candidate, promotion, publish-gate, Release Passport, and GitHub Release surfaces\n- retain product-owned Agent Hub and KFD qualification without consumer-owned version or tag decisions\n- document the protected dev/alpha/release branch model and v0.1 decision\n\n## Validation\n\n- `npm run check`\n- public Buildchain 2.14.15 Agent Hub/KFD-1/2/3 qualification\n- 12/12 fail-closed release mutations\n- `actionlint .github/workflows/*.yml`\n- publish-evidence synthetic release-candidate test\n\n## Version impact\n\nPatch. This changes release governance and CI ownership without widening the public Agent Hub runtime contract. The existing `v0.1.0-alpha.0` tag remains immutable.\n\n## Governance checklist\n\n- [x] No credentials, tokens, private logs, or private paths\n- [x] No provider API or billing behavior changes\n- [x] Release identity and evidence changes are Buildchain-managed\n- [x] Public claim boundary remains first-party clean-room structural independence only\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T13:53:53Z",
          "mergedAt": "2026-07-22T13:57:36Z",
          "additions": 347,
          "deletions": 207,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 6,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/6",
          "title": "chore(release): promote v0.1 alpha",
          "body": "## Promotion\n\nPromote the verified v0.1 development line to the protected alpha channel.\n\n- source: `dev/v0/v0.1`\n- target: `alpha/v0/v0.1`\n- version: `0.1.0-alpha.1`\n- release authority: Buildchain semver/auto\n- immutable predecessor: `v0.1.0-alpha.0`\n\nA successful merge lets the Buildchain promotion workflow create the exact/floating alpha refs, publish-gate state, Release Passport, and GitHub Release from the verified release-candidate artifacts.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T13:58:27Z",
          "mergedAt": "2026-07-22T14:02:26Z",
          "additions": 348,
          "deletions": 208,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 7,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/7",
          "title": "fix(release): grant promotion artifact access",
          "body": "## Summary\n\nGrant the Buildchain promotion caller `actions: write`, matching the reusable workflow contract used to read and reconcile release-candidate artifacts.\n\n## Evidence\n\nThe first automatic alpha promotion was rejected by GitHub at workflow startup before any job or publication action ran. The caller exposed only `actions: read`; Buildchain's reusable promotion workflow requires `actions: write`.\n\n## Validation\n\n- `actionlint .github/workflows/*.yml`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:05:15Z",
          "mergedAt": "2026-07-22T14:06:45Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1547,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1547",
          "title": "Release v2.14.16 from qualified v2.14.16-alpha.0",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.16-alpha.0`\n- Candidate SHA: `7458ddfc0f3651dffa8a947fdf4d139b761903e5`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:08:08Z",
          "mergedAt": "2026-07-22T14:09:28Z",
          "additions": 340,
          "deletions": 122,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 8,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/8",
          "title": "chore(release): retry v0.1 alpha promotion",
          "body": "## Promotion retry\n\nPromote the verified v0.1 development line after aligning the caller's Actions permission with the Buildchain reusable promotion contract.\n\n- source: `dev/v0/v0.1`\n- target: `alpha/v0/v0.1`\n- intended version: `0.1.0-alpha.1`\n- prior attempt: startup failure before jobs or publication\n- release authority: Buildchain semver/auto\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:07:13Z",
          "mergedAt": "2026-07-22T14:12:08Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 9,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/9",
          "title": "chore(release): accept Buildchain channel contracts",
          "body": "## Summary\n\nAdd the authoritative Buildchain v2 alpha and stable runtime contract locks required by channel builds and promotion.\n\n## Provenance\n\nBoth files are byte-identical to the locks published by `kungfu-systems/buildchain@v2`:\n\n- `.buildchain/alpha-contract-lock.json` git blob `21be5b554031610d20a84d1ecb57e53a8a680c53`\n- `.buildchain/contract-lock.json` git blob `12940968f81ac7a6ecd6f64ce446babbcf2bb03d`\n\n## Validation\n\n- JSON contract/ref/compatibility assertions\n- exact Git blob parity with Buildchain v2\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:20:18Z",
          "mergedAt": "2026-07-22T14:21:19Z",
          "additions": 287,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 11,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/11",
          "title": "chore(release): complete v0.1 alpha promotion",
          "body": "## Promotion\n\nPromote the v0.1 line with the required Buildchain v2 alpha/stable contract locks now committed.\n\n- source: `dev/v0/v0.1`\n- target: `alpha/v0/v0.1`\n- intended version: `0.1.0-alpha.1`\n- release authority: Buildchain semver/auto\n- previous promotion runs failed before publication and created no release refs\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:22:07Z",
          "mergedAt": "2026-07-22T14:25:57Z",
          "additions": 287,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 12,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/12",
          "title": "fix(release): use custom publication contract",
          "body": "## Summary\n\nKeep Agent Hub Demo on Buildchain's custom lifecycle publication path for GitHub Release output, and remove npm-only automatic admission inputs.\n\n## Evidence\n\nBuildchain correctly rejected the previous mixed declaration before publication because `publication-auto-admission` requires `publication-target: npm:<package>` to exactly match `publication-package-name`. This repository does not publish to npm; `.buildchain/buildchain.toml` supplies custom GitHub Release evidence instead.\n\n## Validation\n\n- `actionlint .github/workflows/*.yml`\n- `git diff --check`\n- no release refs or tags were created by the rejected run\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:30:16Z",
          "mergedAt": "2026-07-22T14:31:20Z",
          "additions": 0,
          "deletions": 6,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 13,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/13",
          "title": "chore(release): publish v0.1 alpha",
          "body": "## Promotion\n\nPromote the v0.1 line using the Buildchain custom lifecycle publication contract.\n\n- source: `dev/v0/v0.1`\n- target: `alpha/v0/v0.1`\n- intended version: `0.1.0-alpha.1`\n- publication: Buildchain custom evidence plus GitHub Release\n- npm publication: none\n- prior runs failed before any tag or release mutation\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:31:46Z",
          "mergedAt": "2026-07-22T14:35:32Z",
          "additions": 0,
          "deletions": 6,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1548,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1548",
          "title": "fix(release): admit sealed stable reconciliation lineage",
          "body": "## Summary\n\n- admit a stable release reconciliation commit only when its single parent is an independently approved protected-channel PR merge\n- constrain reconciliation to the canonical Buildchain repository, exact stable version metadata, and the release-only generated path allowlist\n- bind repair dispatches to the exact workflow source SHA while keeping the release tag source independently sealed\n\n## Validation\n\n- `node --test tests/publication-authority.test.mjs tests/build-surface.test.mjs` (106 passed)\n- `node scripts/check-inventory.mjs`\n- `pnpm run check:workflows`\n- `pnpm run test:unit` (757 passed)\n- `node scripts/check-action-bundles.mjs` (4 bundles)\n- live control-plane audit for `v2.14.16`: all facts pass with reconciliation enabled; the same audit remains non-qualifying without it\n\n## Release impact\n\nPatch. This repairs sealed binary asset publication without changing public package APIs.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:32:27Z",
          "mergedAt": "2026-07-22T14:40:49Z",
          "additions": 186,
          "deletions": 11,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 62,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/62",
          "title": "docs(paper): recast foundation as recursive triad",
          "body": "## Summary\n\n- recast KFD-1/2/3 as the minimal recursive structure for persistent cooperative work\n- replace the boundary-primitive case survey with removal, order-inversion, and cross-session continuation arguments\n- keep KFD-4/5/6 as a narrow derived frontier into the Observer and Episodes companion papers\n- align publication metadata with the new title\n\n## Checks\n\n- [x] `make check`\n- [x] `make pdf`\n- [x] rendered and visually inspected all 13 PDF pages\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs.\n- [x] No unpublished reviewer correspondence or private operational data.\n- [x] Provider/API/data claims are sourced or clearly bounded.\n- [x] Public branding and trademark language stays factual.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:36:04Z",
          "mergedAt": "2026-07-22T14:41:54Z",
          "additions": 713,
          "deletions": 817,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 97,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/97",
          "title": "Release production from be63c56d4dcf",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `be63c56d4dcf9eb07d3fe73282252ccf34159984`\n- Artifact hash: `1430fba099a71c3185cf9a98b77560784baf44ff7ecf41bbbc9a84d4c9c54f00`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29915098745)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-be63c56d4dcf`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T14:39:41Z",
          "mergedAt": "2026-07-22T14:42:36Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 64,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/64",
          "title": "release: prepare foundation triad alpha.8",
          "body": "## Summary\n\n- advance the publication version to `0.1.0-alpha.8`\n- publish the narrowed paper under the title *Facts, Trust, and Cooperation: The KFD Foundation Triad*\n\n## Checks\n\n- [x] `make check`\n- [x] `make pdf`\n- [x] 13-page PDF render verified on the content commit\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs.\n- [x] Publication metadata matches the reviewed paper source.\n- [x] Buildchain v2-alpha contract lock is reviewed and current.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:43:15Z",
          "mergedAt": "2026-07-22T14:44:35Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1241,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1241",
          "title": "feat(work): project Cut loop into GUI and TUI",
          "body": "## Summary\n\nProject the public Project Cut to Work to next Cut read model into the Work Dashboard and Mission Control TUI through one shared, read-only TypeScript adapter.\n\nGUI and TUI now show the current Cut, Work, confidence, gaps, next actions, and recovery plan without owning Work or settlement authority. The release contract remains not-qualified: retained three-platform parity evidence, the Gate runner, and the real campaign are still pending.\n\n## Related issue\n\nAtlas goal 2026-07-22-kungfu-project-cut-product-loop.\n\n## Changes\n\n- add @kungfu-tech/api.openWorkLoop for exact public capabilities, inspect, and recover JSON\n- expose the same projection in Work Dashboard and Mission Control TUI\n- restrict Electron IPC to the exact three read-only commands and reject mutation\n- fail visibly when no project workspace exists; clear stale GUI summaries after read failure\n- keep fresh-runtime reads parseable by avoiding native journal assembly when no journal exists\n- update the Work API and ADR; replace the obsolete GUI/TUI not implemented blocker with the remaining retained parity evidence gap\n\n## Verification\n\n- ./shifu check — changed-scope gate passed on db0e16e3fbac\n- Work Dashboard tests — 28/28 passed\n- fresh KF_HOME inspect probe — one parseable JSON document, no native no-page prefix\n- Python empty-runtime guard — 2 targeted tests passed\n- pre-commit staged gates — passed for all three commits\n- release-promotion rehearsal — standalone 9/9 and final staged rerun 85/85 passed after one non-reproducible side-effect fixture failure\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f87e8-6b8b-735c-b036-fa42d7cee8cf\"],\n  \"summary\": \"Project the shared read-only Project Cut Work loop into GUI and TUI while retaining explicit pending qualification boundaries.\",\n  \"verification\": [\"Work loop API and IPC tests\", \"Work Dashboard and Mission Control TUI tests\", \"fresh-runtime JSON probe\", \"changed-scope gate\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR adds read-only product projections and narrows one release blocker. It does not register the pending Gate, publish artifacts, mutate Work through GUI/TUI, or claim retained product-loop qualification.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated because the public surfaces and release boundary changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T12:58:13Z",
          "mergedAt": "2026-07-22T14:45:37Z",
          "additions": 824,
          "deletions": 23,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 65,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/65",
          "title": "release: promote foundation triad alpha.8",
          "body": "## Summary\n\nPromote the reviewed Foundation Triad rewrite and `0.1.0-alpha.8` publication state from `dev/v0/v0.1` to the alpha channel.\n\n## Included\n\n- *Facts, Trust, and Cooperation: The KFD Foundation Triad*\n- removal and order-inversion tests for KFD-1/2/3\n- recursive `Facts -> Trust -> Cooperation -> New Facts` kernel\n- narrow KFD-4/5/6 bridge into companion papers\n- reviewed Buildchain v2-alpha contract lock\n\n## Checks\n\n- [x] Content PR #62 passed Verify and Build\n- [x] Release PR #64 passed Verify and Build\n- [x] Local 13-page PDF render inspected",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:44:52Z",
          "mergedAt": "2026-07-22T14:45:55Z",
          "additions": 714,
          "deletions": 818,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1549,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1549",
          "title": "fix(release): bind binary admission to sealed controller runtime",
          "body": "## Summary\n\n- validate the sealed binary distribution controller plan together with its receipt\n- bind publication admission to the controller runtime recorded by the evidence\n- keep the newer independent authority verifier separate for stable release repair\n\n## Validation\n\n- `pnpm run check`\n- `node --test tests/publication-authority.test.mjs tests/build-surface.test.mjs`\n- `git diff --check`\n\n## Release evidence\n\nThis repairs the second fail-closed false negative observed while publishing the already-promoted `v2.14.16` binary assets. The stable source and evidence remain `4612956c052aed8bb8f1d1b2edfd80c79326f654` / run `29927665947`; only the independent verifier runtime is newer.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:46:22Z",
          "mergedAt": "2026-07-22T14:51:50Z",
          "additions": 19,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 98,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/98",
          "title": "fix(site): keep not-found smoke route indexable",
          "body": "## Summary\n- keep the dedicated not-found document compatible with Buildchain production nested-route health checks\n- retain the eventual HTTP 404 edge response as the search-engine exclusion signal\n- guard against reintroducing a noindex meta tag\n\n## Verification\n- `bash -n scripts/check-site.sh`\n- `pnpm run build`\n- `pnpm run check`\n- `git diff --check`\n\nGoal: 2026-07-22-kungfu-site-launch-traffic-readiness",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:48:40Z",
          "mergedAt": "2026-07-22T14:51:50Z",
          "additions": 4,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 14,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/14",
          "title": "ci(release): keep GitHub-only publication fail closed",
          "body": "## Summary\n\n- keep the canonical Buildchain promotion planner dry-run-only for the current GitHub-Release-only publication target\n- document the exact Buildchain v2 admission boundary\n- forbid consumer-owned tag/release fallbacks and false npm identity\n\n## Why\n\nBuildchain v2 auto-seals release-candidate admission only when publication-target exactly matches npm:<package>. Agent Hub Demo publishes through GitHub Releases. The prior automatic apply therefore failed correctly before mutation. This patch preserves Buildchain authority and removes the misleading expectation that the unsupported provider lane is live.\n\n## Validation\n\n- actionlint .github/workflows/*.yml\n- git diff --check\n- npm run check (7 tests, 100/100 soak, build)\n- no tag, GitHub Release, or publish-gate ref mutation\n\nGoal: 2026-07-22-agent-hub-demo-buildchain-release-governance",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:52:02Z",
          "mergedAt": "2026-07-22T15:01:48Z",
          "additions": 26,
          "deletions": 6,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1550,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1550",
          "title": "fix(release): separate verifier and evidence runtimes",
          "body": "## Summary\n\n- bind the checked-out authority runtime directly to the requested immutable verifier SHA\n- preserve the sealed binary controller runtime on the publication capability\n- retain the existing same-runtime invariant for non-binary admission kinds\n\n## Validation\n\n- `pnpm run check`\n- `node --test tests/publication-authority.test.mjs tests/build-surface.test.mjs`\n- `git diff --check`\n\n## Release evidence\n\nThis fixes the final runtime-role conflation observed in binary asset repair run `29930647126` for `v2.14.16`.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T15:00:37Z",
          "mergedAt": "2026-07-22T15:03:57Z",
          "additions": 15,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 99,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/99",
          "title": "Release production from ca14d3882442",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `ca14d3882442299ada47822bd96edbfaea51b3c3`\n- Artifact hash: `9e7c4addf8798c628037afd6c7ce51c72053678ac37608e0ce2c5f54af2eba1a`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29930634809)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-ca14d3882442`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T15:01:25Z",
          "mergedAt": "2026-07-22T15:03:59Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 100,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/100",
          "title": "feat(site): clarify agent-mediated supply chain",
          "body": "## Summary\n\nReframe the Agent Supply Chain page so readers first understand delegated Agent tool selection, then the Agent-first distribution advantage and conditional Kungfu/Buildchain flywheel, before seeing the complete five-layer mechanism.\n\n## Changes\n\n- establish the human/Hub authority boundary before Agent-mediated selection\n- compare human-led and Agent-mediated software use\n- explain the conditional distribution flywheel without claiming current adoption\n- move the five-layer evidence mechanism to the final explanatory chapter\n- add an additive machine-readable reader progression contract\n- render human-facing KFD-2 and KFD-3 names in uppercase and enforce that convention\n- document the site/upstream narrative ownership boundary\n\n## Verification\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `bash -n scripts/build-site.sh scripts/check-site.sh`\n- `shellcheck scripts/build-site.sh scripts/check-site.sh`\n- desktop Chrome render at 1440px\n- mobile Chrome render at 390px\n- local route, link, and machine-contract checks\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change updates public KFD naming and the site presentation of upstream-owned release evidence. Existing evidence coordinates, maturity classes, claims, URLs, and Buildchain deployment semantics remain unchanged; the machine contract extension is additive.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-22T15:01:34Z",
          "mergedAt": "2026-07-22T15:05:04Z",
          "additions": 168,
          "deletions": 20,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 16,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/16",
          "title": "chore(release): advance fail-closed v0.1 alpha governance",
          "body": "## Summary\n\nAdvance the reviewed Buildchain governance tree from dev/v0/v0.1 to alpha/v0/v0.1.\n\nThe promotion entrypoint is now intentionally dry-run-only for this GitHub-Release-only consumer. A successful post-merge workflow must plan through Buildchain without creating or moving tags, releases, or publish-gate refs.\n\n## Evidence\n\n- source PR #14 approved and merged by kungfu-origin\n- Build run 29930651621 passed Linux, macOS, Windows, trust gate, and controller evidence\n- Verify run 29930651134 passed\n\nGoal: 2026-07-22-agent-hub-demo-buildchain-release-governance",
          "author": "dongkeren",
          "createdAt": "2026-07-22T15:02:05Z",
          "mergedAt": "2026-07-22T15:06:07Z",
          "additions": 26,
          "deletions": 6,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 192,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/192",
          "title": "chore(papers): publish foundation triad alpha.8",
          "body": "## Summary\n\n- advance the pinned KFD foundation paper package to `0.1.0-alpha.8`\n- publish the new *Facts, Trust, and Cooperation: The KFD Foundation Triad* title and archive routes\n- update the exact immutable-route assertion and package integrity lock\n\n## Checks\n\n- [x] `pnpm install --lockfile-only --ignore-scripts --registry=https://registry.npmjs.org/ --config.minimumReleaseAge=0`\n- [x] `pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/ --config.minimumReleaseAge=0`\n- [x] `pnpm run build`\n- [x] `pnpm run check`\n\n## Governance\n\n- [x] Exact published npm package and SHA-512 integrity are pinned.\n- [x] Existing paper versions and unrelated upstream coordinates are unchanged.\n- [x] No private data or Atlas control-plane content is introduced.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:53:09Z",
          "mergedAt": "2026-07-22T15:08:57Z",
          "additions": 9,
          "deletions": 9,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 101,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/101",
          "title": "Release production from a7ff629255d6",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `a7ff629255d656933e749c29425236d9438737cf`\n- Artifact hash: `3dde7233ab982b95a4af71610dbc1cc3864d84ed506cb06609cc6e1d8776a371`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29931688427)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-a7ff629255d6`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T15:07:25Z",
          "mergedAt": "2026-07-22T15:10:22Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 17,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/17",
          "title": "chore(buildchain): accept current v2-alpha contract",
          "body": "## Summary\n\nAccept the current Buildchain v2-alpha contract after reviewing the compatible drift reported by issue #15.\n\nThe lock is generated by Buildchain commit 7458ddfc0f3651dffa8a947fdf4d139b761903e5 using scripts/buildchain-contract-lock.mjs write-lock. It adds the binary-distribution controller surface and updates the exact runtime, contract, and compatibility digests.\n\n## Validation\n\n- generated lock byte-for-byte matches the Buildchain authority output\n- compatibility policy remains major-compatible\n- actionlint .github/workflows/*.yml\n- git diff --check\n\nGoal: 2026-07-22-agent-hub-demo-buildchain-release-governance",
          "author": "dongkeren",
          "createdAt": "2026-07-22T15:11:24Z",
          "mergedAt": "2026-07-22T15:14:52Z",
          "additions": 9,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 18,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/18",
          "title": "chore(buildchain): advance accepted v2-alpha contract",
          "body": "## Summary\n\nAdvance the reviewed current Buildchain v2-alpha contract lock from dev/v0/v0.1 to alpha/v0/v0.1.\n\n## Evidence\n\n- source PR #17 approved and merged by kungfu-origin\n- Build run 29932180306 passed trust gate, Linux, macOS, Windows, and controller evidence\n- lock byte-for-byte matches Buildchain 7458ddfc0f3651dffa8a947fdf4d139b761903e5 write-lock output\n\nThe post-merge Buildchain promotion remains non-authorizing dry-run-only.\n\nGoal: 2026-07-22-agent-hub-demo-buildchain-release-governance",
          "author": "dongkeren",
          "createdAt": "2026-07-22T15:15:06Z",
          "mergedAt": "2026-07-22T15:18:18Z",
          "additions": 9,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1551,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1551",
          "title": "fix(web-surface): preserve exact publication prefixes",
          "body": "## Summary\n- protect only manifest-declared immutable version prefixes during web-surface publication\n- keep mutable archive indexes eligible for normal sync and cache metadata updates\n- add a regression fixture that changes `archive/index.html` while preserving `archive/<paper>/<version>/`\n\n## Verification\n- `node --test --test-name-pattern=\"preserves version prefixes\" tests/web-surface.test.mjs`\n- `corepack pnpm run check` (758 tests passed)\n\n## Downstream evidence\nThis fixes the staging failure in `site-libkungfu-dev` run 29931994645, where the mutable papers archive index was incorrectly verified as immutable before upload.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T15:16:48Z",
          "mergedAt": "2026-07-22T15:22:27Z",
          "additions": 23,
          "deletions": 22,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1552,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1552",
          "title": "chore(release): promote exact publication prefixes to v2.14 alpha",
          "body": "## Release intent\nPromote the current protected `dev/v2/v2.14` line to alpha.\n\nThe train contains the reviewed sealed binary admission/runtime separation fixes plus the exact publication-prefix preservation fix required by `site-libkungfu-dev` staging.\n\n## Evidence\n- constituent PRs #1548, #1549, #1550, and #1551 are merged\n- #1551 passed Verify, the full Build Surface Fixture matrix, and merge-queue Verify\n- local Buildchain done-check passed with 758 tests\n- downstream failure is reproducible at `site-libkungfu-dev` run 29931994645 and is addressed without overwriting immutable version objects",
          "author": "dongkeren",
          "createdAt": "2026-07-22T15:23:33Z",
          "mergedAt": "2026-07-22T15:26:44Z",
          "additions": 243,
          "deletions": 37,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1240,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1240",
          "title": "ci: scope installed SDK qualification by source impact",
          "body": "## Summary\n\nScope the installed four-language SDK qualification to changes that can affect its ABI, generated inputs, build/package policy, or qualification harness.\n\nThis deliberately does not relax affected-native proof identity. Reuse still requires one unique successful proof with the exact base revision, candidate source tree, plan projection, partition contract, platform tier, and toolchain authority. A base or candidate-tree move remains `reuse:false` with a full fail-closed run.\n\n## Related issue\n\nAtlas goal `2026-07-17-kungfu-dev-gate-latency-slo`.\n\n## Changes\n\n- add a conservative SDK-impact decision and reasons to the source-bound affected-native plan\n- keep public ABI, schemas/bindings, SDK generation/package inputs, lock/workspace/build authority, SDK harness, and unknown root-package impact fail-closed\n- compare an exact base/head projection before treating an unrelated root `package.json` task change as SDK-neutral\n- separate `native-required` from `sdk-required` in the workflow, while keeping SDK-only qualification on partition zero\n- retain affected native closure coverage for internal native implementation changes without always rebuilding and packaging four SDK languages\n- add planner fixtures and workflow source-contract assertions, refresh workflow authority, and document the contract in SHIFU-ADR-0004\n\n## Verification\n\n- `node scripts/run-core-affected-native.mjs --self-test` (27 passed)\n- `./shifu test:gate-latency` (25 passed)\n- `./shifu check:source` (passed)\n- staged repository gates on both DCO commits (passed)\n- Project Cut `sha256:7d26ffa037703c6f7368a7973910e5dae1f50951f37905132ccf43416ce9e953` published at `c89cf458cc35bfedbd5a35151d2ba792b23c2a5a`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Scope installed SDK qualification by exact source impact while preserving exact affected-native proof identity and fail-closed full-run fallback.\",\n  \"verification\": [\"./shifu test:gate-latency\", \"./shifu check:source\", \"Project Cut published observation\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change modifies CI qualification scheduling but does not add secrets, write permissions, hosted dependencies, or a branch-protection bypass. Unknown impact remains a full SDK qualification.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-22T12:35:49Z",
          "mergedAt": "2026-07-22T15:33:04Z",
          "additions": 265,
          "deletions": 21,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1244,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1244",
          "title": "fix(shifu): forward cold Windows launcher arguments",
          "body": "## Summary\n\nPreserve the original Windows lifecycle argument vector after a freshly built or acquired Shifu launcher is resolved, and make the cold dispatch path a required Windows CI proof.\n\n## Diagnosis\n\nAlpha Build run 29926184191 built the Windows launcher successfully, then every lifecycle task returned 0 without executing; release qualification retained only its summary and failed the eight-artifact minimum. The prior live test covered the direct `cache` bypass, while `shifu CI` did not activate for `shifu.cmd` or execute lifecycle tests on Windows.\n\n## Changes\n\n- dispatch freshly resolved Windows launchers from a top-level batch label instead of inside parsed build/acquire blocks\n- add a static contract for both source-build and acquisition routes\n- add a Windows-only live cold-cache test that builds the launcher and proves `--version` survives the handoff\n- activate `shifu CI` for Shifu entry/lifecycle changes and run the lifecycle/entry suite on Windows\n- refresh the checked-in workflow authority projection\n\n## Verification\n\n- `./shifu check:entry-contract`\n- `./shifu --filter @kungfu-tech/workspaces exec node --test scripts/run-shifu-lifecycle.test.mjs`\n- `node --test scripts/check-shifu-entry-contract.test.mjs scripts/run-shifu-lifecycle.test.mjs` (25 pass, 2 Windows-only skip on macOS)\n- workflow authority refresh and staged repository gates (pass)\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair a Windows batch argument-forwarding defect and its CI coverage gap without changing any ADR projection.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:19:02Z",
          "mergedAt": "2026-07-22T15:47:06Z",
          "additions": 87,
          "deletions": 13,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 193,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/193",
          "title": "chore(buildchain): accept 2.14.17 alpha contract",
          "body": "## Summary\n\n- accept Buildchain `v2-alpha` at `e7ad500238f5bbfc301b3388e01621383c0bd6fb` (`2.14.17-alpha.0`)\n- preserve the existing major-compatible compatibility digest\n- unblock the Foundation Triad alpha.8 archive-index deployment after exact-prefix immutability fix\n\n## Verification\n\n- `corepack pnpm install --frozen-lockfile`\n- `corepack pnpm run build`\n- `corepack pnpm run check`\n- exact Buildchain contract-lock check against `v2.14.17-alpha.0`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-22T15:36:24Z",
          "mergedAt": "2026-07-22T15:49:10Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 102,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/102",
          "title": "feat(agent-builders): smooth the reader progression",
          "body": "## Summary\n\n- establish the adoption decision and Builder ownership before the network topology\n- bridge KFD responsibility interoperability into one concrete release action and a five-stage runtime model\n- show one auditable proof unit before aggregate dogfood metrics and end with one bounded reference action\n- lock the reader progression into the site checks and repository contract\n\n## Validation\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `bash -n scripts/check-site.sh`\n- `shellcheck scripts/check-site.sh`\n- desktop and 390px mobile browser checks, with no page-level horizontal overflow\n\n## Version impact\n\nPatch-level public content and presentation change. No machine contract, API, package, adoption, or qualification claim changes.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T15:48:25Z",
          "mergedAt": "2026-07-22T15:51:46Z",
          "additions": 284,
          "deletions": 108,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1245,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1245",
          "title": "feat(work): make Project Cut-bound Work portable",
          "body": "## Summary\n\nMake one Work item portable across a clean runtime or Agent context while binding it to the exact tracked current Project Cut.\n\nExport emits a byte-stable semantic envelope without machine-local timestamps. Import is verify-first and dry-run by default; only an explicit --execute appends a verified missing prefix. Divergent Work, a wrong Cut, modified roots, path escape, oversized input, signed URLs, and high-confidence credential material fail before any append.\n\n## Related issue\n\nAtlas goal 2026-07-22-kungfu-project-cut-product-loop.\n\n## Changes\n\n- add kungfu work export/import and expose both through the shared Work capability manifest\n- bind portable Work to exact Project Cut roots, receipt paths, and publication commit\n- preserve Work semantics while explicitly excluding timestamps and cross-type event ordering\n- support idempotent exact replay and interrupted-prefix recovery through the existing Work journal\n- reject divergent state, tamper, path escape, oversized rows/text/envelopes, signed URLs, labeled secrets, private keys, AWS keys, GitHub/GitLab/Slack/OpenAI-style credentials, and Bearer credentials\n- update KFD/Agent/SDK projections and the Work API/ADR contracts\n- remove the stale release blocker that claimed export/import were still incomplete while retaining begin/completion/settlement blockers\n\n## Verification\n\n- source/final-base range-diff: exact; patch-id 0bea6ee941b87cb418172fa3c26c30de7b78c7f6\n- ./shifu test:work-facade — 15 Node tests and 20 Python tests passed\n- ./shifu check — exit 0; changed-scope gate passed on 716d0db01784\n- fresh-home dogfood — plan made no target directory; execute restored create/checkpoint/status; exact replay reused without writes\n- staged pre-commit gates — passed, including ADR/docs, invariants, schema authority, carrier/action-envelope, and Gate contracts\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f87e8-6b8b-735c-b036-fa42d7cee8cf\"],\n  \"summary\": \"Deliver Project Cut-bound portable Work export/import with verify-first explicit admission and fail-closed recovery.\",\n  \"verification\": [\"Work facade contract tests\", \"fresh-home portability dogfood\", \"changed-scope gate\", \"source/final-base range-diff and patch-id\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [x] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR transports semantic Work evidence but does not transport source bytes, mint Project Cut authority, authenticate origin, register the pending release Gate, or claim retained product-loop qualification.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated because the public Work surface and release boundary changed",
          "author": "dongkeren",
          "createdAt": "2026-07-22T14:51:25Z",
          "mergedAt": "2026-07-22T16:00:53Z",
          "additions": 1517,
          "deletions": 78,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 103,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/103",
          "title": "Release production from e38e993834db",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `e38e993834db9fbc0268a2d9a97b94657691f3b5`\n- Artifact hash: `39303757d196887d56f1bdd3ac1175d24263d72e9af7a1ed9fca9d6c3e012def`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29935368830)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-e38e993834db`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T15:56:14Z",
          "mergedAt": "2026-07-22T16:04:03Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 194,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/194",
          "title": "Release production from 297ac9117d54",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `297ac9117d5431353048e5fec0270f3f24aedbce`\n- Artifact hash: `7b5edaeacd3c8124793feea974a3e5c26d40f8ac1c92e93340716c7f834d544e`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29935165440)\n- Required label: `buildchain-release`\n- Release branch: `release/production-297ac9117d54`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-22T16:01:32Z",
          "mergedAt": "2026-07-22T16:18:16Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1250,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1250",
          "title": "ci: measure merge queue delivery waste",
          "body": "## Summary\n\nExtend the read-only dev Gate latency collector with merge-queue delivery and wasted-runner evidence. The report now separates completed delivery latency from queue attempts that were dequeued before eventual merge, so failed or still-open attempts remain visible instead of becoming zero or disappearing.\n\nThis deliberately does not relax affected-native proof identity. Reuse still requires the exact base, candidate source tree, plan projection, partitions, tier, receipt, and toolchain evidence. A changed merge-group base remains `reuse:false` with a full fail-closed run.\n\n## Related issue\n\nAtlas goal `2026-07-17-kungfu-dev-gate-latency-slo`.\n\n## Changes\n\n- pair authoritative GitHub GraphQL merge-queue add/remove events into queue rounds and retain official dequeue reasons\n- bind Core `merge_group` Actions runs back to their PR and queue round without using the evidence to authorize proof reuse\n- report first-entry-to-merge P50/P90, dequeue rate/reasons, repeated Core validation, non-merged-round runner time, and the portion that continued after dequeue\n- include still-open dequeued PRs in waste totals while excluding incomplete delivery from latency percentiles\n- fail closed on unpaired events, unmatched runs, missing jobs, non-terminal jobs, or collection failures\n- document the measurement cohort, SLO, runner-minute semantics, and exact proof-identity boundary\n\n## Verification\n\n- `./shifu test:gate-latency` (30 passed)\n- `./shifu check:source` (passed)\n- live `./shifu gate:latency:measure --branch dev/v4/v4.0 --limit 30`\n- staged repository gates on both DCO commits (passed)\n- Project Cut `sha256:51f0cea15736e4c894d1f0fb14222495c57e3cbaaa050f89308f0ded20d45c40` published at `32125210a60b7ace3fec4efd9618a3d6a1135fb2`\n\nThe live cohort contained 31 completed delivery samples with P50/P90 of 2798/7924 seconds. Sixteen of 34 queue-observed PRs had a non-merged exit; failed rounds consumed 14062 runner-seconds, including 12304 seconds after dequeue. PR #1239 alone retained the authoritative `failed_checks` reason and 3087 post-dequeue runner-seconds.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Measure merge-queue delivery, dequeue, repeated validation, and wasted runner time without weakening exact affected-native proof identity.\",\n  \"verification\": [\"./shifu test:gate-latency\", \"./shifu check:source\", \"live 30-PR merge-queue measurement\", \"Project Cut published observation\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe collector reads GitHub branch protection, pull-request timelines, Actions runs, jobs, checks, and artifacts with the existing read-only token. It adds no permissions, mutations, hosted dependency, or proof-reuse authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T16:09:21Z",
          "mergedAt": "2026-07-22T16:38:54Z",
          "additions": 750,
          "deletions": 7,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1249,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1249",
          "title": "fix(shifu): forward cached Windows launcher arguments",
          "body": "## Summary\n\nRoute every resolved Windows Shifu launcher through the top-level batch dispatcher, including explicit `SHIFU_BIN`, warm source-cache, and release-pin hits.\n\n## Diagnosis\n\nAlpha promotion Build run 29935225064 proved the cold source build completed, but cache-applied lifecycle re-entry inherited `SHIFU_BIN` and hit a remaining direct invocation inside a parsed batch block. The nested task again returned 0 without executing, leaving only one artifact instead of the required eight.\n\n## Changes\n\n- route explicit `SHIFU_BIN`, warm source-cache, and release-pin hits through `:runresolved`\n- statically reject direct native launcher calls inside parsed batch blocks\n- extend the Windows live test across cold, warm, explicit override, and cache-apply re-entry paths\n\n## Verification\n\n- combined entry/lifecycle tests: 25 pass, 2 Windows-only skip on macOS\n- `./shifu check:entry-contract`\n- full staged repository gate, docs gate, Biome formatting, and DCO: pass\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair the remaining Windows cached-launcher argument-forwarding defect without changing any ADR projection.\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T16:05:13Z",
          "mergedAt": "2026-07-22T16:46:54Z",
          "additions": 74,
          "deletions": 19,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1254,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1254",
          "title": "ci: stage dev qualification in merge queue",
          "body": "## Summary\n\nMake the development merge queue the single authoritative producer for expensive candidate qualification while keeping pull-request admission fast and fail-closed.\n\nGitHub merge-group formation remains the conflict authority. Pull requests run DCO, source acceptance, Buildchain configuration, ADR/promotion governance, and exact source-impact planning; compiler, installed-artifact, packaging, and three-platform work starts only for the synthetic merge-group candidate after both preflight lanes pass.\n\n## Related issue\n\nFollow-up to the dev required-gate latency and affected-native qualification work.\n\n## Changes\n\n- keep one stable required context, `affected-native / linux`, with distinct PR-admission and merge-group qualification semantics\n- make source acceptance and governance preflight explicit dependencies of every expensive queue job\n- run affected-native/SDK, impact-selected three-platform Shifu, and impact-selected KFD qualification in parallel after preflight\n- run the installed four-language SDK wire contract only when the exact source-bound plan selects it\n- retire PR proof reuse because expensive evidence is no longer produced before the queue\n- remove candidate-equivalent affected-native, Buildchain-validation, Shifu, and KFD work from dev pushes or dev PR-specific standalone workflows\n- preserve alpha and release workflow behavior and retain the old required contexts during the bounded branch-protection transition\n- refresh the closed-world workflow authority, bindings, ADR, gate docs, and contract fixtures\n\n## Verification\n\n- `./shifu check:gate-catalog` (38 gates, 6 profiles, 25 structured invocations, 17 workflows)\n- `./shifu test:gate-latency` (28 passed)\n- focused workflow/catalog contracts (30 passed)\n- `./shifu check:source` (passed; documentation 85/85 and source contracts with zero failures)\n- staged pre-commit repository gate (passed)\n- Project Cut successor kickoff/run gate bound to `39ca45f4495ff3792ff132519fb285f9348e0ec6`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Move expensive dev candidate qualification behind ordered merge-group preflight while preserving one fail-closed required aggregate.\",\n  \"verification\": [\"./shifu test:gate-latency\", \"./shifu check:source\", \"real pull_request and merge_group workflow observation\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change alters qualification scheduling and required-context aggregation. It adds no secrets, write permissions, mutable third-party authority, protected-branch bypass, or release-policy weakening. The old required contexts remain in force until the replacement aggregate is observed on both PR and merge-group events.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\nReplacement for #1252: identical tree, replayed as one linear commit because the dev merge queue is configured with REBASE and rejected the prior two-parent synchronization commit as merge_conflict.\n\nReplacement for #1253 after dev advanced through e874346ec2. This is again one linear commit on the current dev head; the only replay conflict was resolved by preserving both complementary SHIFU-ADR-0004 decision paragraphs.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T16:45:59Z",
          "mergedAt": "2026-07-22T17:39:14Z",
          "additions": 817,
          "deletions": 189,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1257,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1257",
          "title": "feat(docs): shorten ADR identity filenames",
          "body": "## Summary\n\nShorten modern ADR filenames to their full canonical UUIDv7 identity while keeping link labels readable, and add an exact-tree migration planner/codemod for the remaining legacy corpus.\n\n## Related issue\n\nAtlas goal: `2026-07-22-kungfu-adr-identity-migration-tooling`\n\n## Changes\n\n- require modern paths to be exactly `docs/adr/<full-canonical-id>.md`\n- rename the existing UUIDv7 ADR files without truncating their identity\n- keep the deprecated `--slug` generator input as an ignored compatibility surface while removing slugs from canonical paths\n- centralize canonical reference extraction and unique prefix resolution\n- add deterministic `adr:migrate` planning from an exact Git tree, with expected-root apply, idempotence, collision checks, and symbol/reference conservation\n- classify authored, fixture, generated, and historical append-only migration surfaces without applying the 140-record legacy corpus rewrite in this PR\n- recognize Git renames as review-required historical moves while continuing to reject deletion or reclassification of historical documents\n\n## Verification\n\n- `./shifu adr:identity:test` (44/44)\n- `./shifu adr:migrate:test` (3/3)\n- `node --test scripts/shifu-documentation-surfaces.test.mjs` (9/9)\n- documentation gate (90/90)\n- `./shifu adr:audit -- --json` (145 records: 136 Kungfu, 9 Shifu; 0 structural findings)\n- staged repository gate passed\n- Project Cut `sha256:c102d018ed4cbeb28f07c8c078fa7b1de1fea0ddf3b922623476282813750b44`\n- source projection `sha256:8719982ea78b6e3528337dedae035ab127136233c0b617e701975fdc81692c9e`\n- merge-queue admission against staged qualification base `0bee589703aa1c6edd3de2d133b090067b6f880a`: qualified, 21 commits, 0 diagnostics, composition `sha256:5cf4c0d8bacaab7078e1e9827d7662278717f8e2d9c0ef15206035d2c6993a4f`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-019f86ff-a8d6-7431-ae05-0ec95fdb7ace\", \"KF-ADR-019f8759-ab29-7627-bc04-6aba547ea45f\", \"KF-ADR-019f878c-5480-7890-bc64-9b2aab7e9aa5\"],\n  \"summary\": \"Adopt ID-only UUIDv7 ADR paths and deliver exact-tree migration tooling without rewriting the legacy corpus.\",\n  \"verification\": [\"./shifu adr:identity:test\", \"./shifu adr:migrate:test\", \"documentation surface tests\", \"Project Cut merge-queue admission\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes ADR release/documentation admission evidence and Project Cut records only; it performs no package publication or deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\nSupersedes #1220, #1233, #1235, #1239, #1243, #1246, #1248, and #1256. This candidate is built directly on the queued #1254 merge-group head so its exact-tree admission remains valid behind the staged qualification rollout.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T17:07:52Z",
          "mergedAt": "2026-07-22T18:42:45Z",
          "additions": 1790,
          "deletions": 249,
          "changedFiles": 78
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1215,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1215",
          "title": "feat(mission-control): add native Assignment orchestration",
          "body": "## Summary\n\nMove Assignment admission and the Atlas-compatible go state machine into Kungfu Mission Control. The new source-first CLI performs strict current-checkout admission, explicit claim and lease management, fail-closed run/closeout gates, structured next actions, and content-addressed settlement seals that survive worktree deletion.\n\n## Related issue\n\nAtlas goal `2026-07-21-kungfu-native-admit-go-orchestration`.\n\n## Changes\n\n- admit captured requests into native Initiative/Assignment L3 facts with strict compiled-current-checkout provenance\n- add claim, kickoff, stage, status, gate, Completion Claim, independent review, continuation decision, seal, and verify-seal commands\n- project the exact Atlas coordinator gate field set without retaining Atlas as authority\n- distinguish Owner, Agent, Slot, authorization scope, and bounded Lease\n- persist portable sealed orchestration snapshots under the shared Git common directory\n- register `KF-ADR-019f87cc-bd1f-786d-896d-07ea9245861e` and `KF-ADR-019f87cc-bd45-7a5c-9b37-1d6b5917928a` plus KFD/collaboration surface evidence\n- adopt the concurrent distributed UUIDv7 ADR baseline without shared sequence or index writes\n\n## Verification\n\n- `./shifu build:core`\n- focused Assignment orchestration and Mission Control tests: 9 passed\n- `./shifu test:assignment-capture`: 5 passed\n- `./shifu test:cli-surface-contract`: 27 passed\n- `./shifu docs:check:readonly`\n- `./shifu check:cli-catalog-parity`\n- `./shifu kfd:buildchain`\n- `./shifu check`\n- clean merged-base `./shifu check:source`: 511 passed, 1 skipped, 0 failed in the contract suite; complete build-free gate passed\n- end-to-end strict dogfood: capture -> admit -> claim -> kickoff -> stage -> Completion Claim -> independent review -> continuation decision -> closeout gate -> durable seal -> verify after worktree deletion\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f87cc-bd1f-786d-896d-07ea9245861e\", \"KF-ADR-019f87cc-bd45-7a5c-9b37-1d6b5917928a\"],\n  \"summary\": \"Stage native Assignment admission and a portable fact-backed go orchestration state machine with bounded claim identity and lease authority\",\n  \"verification\": [\"strict current-checkout dogfood\", \"Assignment orchestration tests\", \"changed-scope gate\", \"source acceptance\", \"documentation contracts\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-22T03:06:52Z",
          "mergedAt": "2026-07-22T19:11:31Z",
          "additions": 3069,
          "deletions": 160,
          "changedFiles": 59
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1261,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1261",
          "title": "ci: retire duplicate dev qualification entrypoints",
          "body": "## Summary\n\nFinish the staged dev CI transition proven by #1254: the single `affected-native / linux` aggregate now owns dev pull-request admission and merge-group qualification, while duplicate standalone dev entrypoints are retired.\n\n## Changes\n\n- make Source Acceptance, ADR Release Gate, and Docs Check manual diagnostics\n- make DCO and Buildchain Validate ignore `dev/v*/v*` while preserving non-dev and alpha/release responsibilities\n- retain the exact PR evidence-base SHA inside aggregate source acceptance\n- refresh workflow authority, Gate bindings, ADR/docs, and contract tests\n- keep branch protection on the already-proven single required aggregate\n\n## Verification\n\n- `./shifu check:source` (passed; source contract suite 529 passed, 2 platform skips, zero failures)\n- `./shifu check:gate-catalog` (38 gates, 6 profiles, 25 structured invocations, 17 workflows)\n- focused source/document/catalog contracts (72 passed)\n- staged pre-commit repository gate (passed)\n- affected-native plan: authoritative native qualification required; four-language SDK wire-contract not required\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Retire duplicate dev qualification entrypoints after the staged aggregate was proven on pull_request and merge_group.\",\n  \"verification\": [\"./shifu check:source\", \"./shifu check:gate-catalog\", \"pull_request and merge_group workflow observation\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis only changes scheduling authority and removes redundant dev triggers. It does not weaken source, governance, native, SDK, Shifu, KFD, alpha, or release qualification.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T17:59:07Z",
          "mergedAt": "2026-07-22T19:25:55Z",
          "additions": 72,
          "deletions": 101,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1553,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1553",
          "title": "Release v2.14.17 from qualified v2.14.17-alpha.0",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.17-alpha.0`\n- Candidate SHA: `e7ad500238f5bbfc301b3388e01621383c0bd6fb`\n- Selection: `latest-qualified`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T20:10:34Z",
          "mergedAt": "2026-07-22T20:11:43Z",
          "additions": 259,
          "deletions": 53,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1262,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1262",
          "title": "fix(core): restore witnessed documentation material",
          "body": "Restore the product Documentation Atlas from an immutable selector-pinned Git material commit when Buildchain uses a witness-only or shallow checkout. Verify every restored artifact against its tracked size and SHA-256 witness, add shallow-clone and tamper coverage, and refresh affected KFD evidence.\n\n<!-- kungfu-adr-release:v1 {\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"Repairs release packaging after the accepted witness-only baseline split without changing its architecture contract\"} -->",
          "author": "dongkeren",
          "createdAt": "2026-07-22T19:36:02Z",
          "mergedAt": "2026-07-22T20:24:36Z",
          "additions": 199,
          "deletions": 8,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1265,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1265",
          "title": "chore(project-cut): bind Initiative Assignment parent closure",
          "body": "## Summary\n\nBind the completed Initiative Assignment control-plane program into a parent Project Cut after all four child goals reached continuation-decided. This PR publishes the parent Cut and Xinfa Atlas compatibility artifacts at the exact reviewed feature head.\n\n## Related issue\n\nAtlas goal `2026-07-21-kungfu-initiative-assignment-control-plane`.\n\n## Evidence bound\n\n- hub capture surface: PR #1200\n- L3 Initiative/Assignment schema: PR #1212\n- native admit/go orchestration: PR #1215\n- Atlas Assignment client cutover: sealed Atlas integration state\n- parent Project Cut: `sha256:635b84628b768f3166647c2c1e1b4c382bd0a9400b53e612c06d302266703e65`\n- parent observed commit: `a3c0fda890600de50fb4259d94dce6f210920285`\n\n## Verification\n\n- Project Cut prepare, execute, stage, bind, and commit-observe\n- parent child reconciliation against sealed child Project Cut states\n- native Completion Claim and independent review (`fit`)\n- continuation decision (`close`) and closeout gate\n- Kungfu pre-commit suite, including source/documentation gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This PR publishes parent Project Cut and Xinfa compatibility evidence for behavior already delivered by the referenced child PRs; it does not alter an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence or provenance artifacts only\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T19:45:01Z",
          "mergedAt": "2026-07-22T20:29:28Z",
          "additions": 7,
          "deletions": 0,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1267,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1267",
          "title": "chore(project-cut): publish rebased staged CI settlement",
          "body": "## Summary\n\nPublish the final Project Cut for the completed dev merge-queue staged-CI delivery. This is an empty-Episode settlement: it adds no product or CI behavior and only binds the already-merged delivery to the current dev source and Xinfa Atlas.\n\nThe predecessor PR #1263 was correctly rejected by Queue preflight after another queued change advanced dev. No heavy lane started. This successor is regenerated from exact dev commit `867598c5d8a357b4d014933b8e03c75d4e04d8e5`.\n\n## Related issue\n\nAtlas goal `2026-07-22-kungfu-dev-merge-queue-staged-ci`.\n\n## Changes\n\n- publish Project Cut `sha256:7cf3c0a19dac2f92e9861e1d29da1f3ee90400e07b692d4714b620ef7305d7d2`\n- reconcile the two current `kungfu` Project Cut leaves into one successor\n- bind source projection `sha256:fa90b13cee0e1c56aeb482e8f8c3c86f89a58db522301e82cc547b76aab00e87`\n- record an empty native Episode delta and the exact final dev Atlas root\n\n## Verification\n\n- `./shifu project-cut prepare --execute --stage --json`\n- `./shifu project-cut verify --state ... --json`\n- `./shifu project-cut commit-observe --commit 2cc887214291dc8498b4ac736281e31dfc3d034c --execute --json`\n- local pre-commit reached and passed 23 staged-CI contract tests, then stopped because this fresh worktree has no local `yaml` dependency; no dependency install was performed\n- GitHub Candidate source acceptance and governance preflight are the authoritative full-source recheck\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This PR publishes machine-generated settlement evidence for already-merged CI behavior and changes no architecture contract.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe only affected boundary is Project Cut provenance. The native settlement, verify, and exact-commit observation passed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T20:36:46Z",
          "mergedAt": "2026-07-22T20:43:52Z",
          "additions": 7,
          "deletions": 0,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1268,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1268",
          "title": "fix(core): make documentation material shallow-safe",
          "body": "## Summary\n\nMake the public Documentation Atlas material reproducible inside credential-free shallow Buildchain checkouts.\n\n- replace private history fetches with a content-addressed tracked gzip bundle\n- validate every restored byte against the existing witness manifest\n- materialize before body-dependent documentation qualification\n- retain the original material commit as provenance\n\n## Verification\n\n- full staged pre-commit gate\n- node --test scripts/documentation-product-pack.test.mjs\n- node scripts/run-documentation-material-tests.mjs\n- git-archive checkout with no .git restores and passes all 7 documentation material tests\n- ./shifu kfd:buildchain:check\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"Repair credential-free shallow release checkout materialization without changing an ADR projection.\"}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-22T20:49:27Z",
          "mergedAt": "2026-07-22T21:28:03Z",
          "additions": 119,
          "deletions": 106,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1258,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1258",
          "title": "fix(ci): retain closed merge queue attempts",
          "body": "## Summary\n\nRetain merge-queue delivery attempts for recently updated, non-merged pull requests even when GitHub never created a `merge_group` workflow run.\n\nThis is an observability-only correction. It does not change the affected-native planner, workflow, proof format, or reuse lookup. Proof reuse remains fail-closed and bound to one unambiguous candidate with the exact base revision, candidate source tree, plan projection, partition/tier, receipt, and toolchain evidence. A moved base still requires `reuse: false` and the complete native run.\n\n## Related issue\n\nAtlas goal `2026-07-17-kungfu-dev-gate-latency-slo`.\n\n## Changes\n\n- Probe non-merged PRs updated during the selected delivery window, then retain only PRs with authoritative queue events or incomplete collection.\n- Preserve paired enqueue/dequeue attempts that produced no merge-group run.\n- Keep ordinary recent PRs that never entered the queue outside the cohort.\n- Add deterministic coverage for candidate selection and paired closed attempts without runs.\n- Document the fail-closed evidence and exact affected-native proof identity boundary.\n\n## Verification\n\n- `./shifu test:gate-latency` (32/32)\n- `./shifu check:source` after Project Cut publication (Node 529 passed, 2 platform skips; Python 41/41; runtime upgrade 76/76; composition diagnostics empty)\n- Live `./shifu gate:latency:measure --branch dev/v4/v4.0 --limit 30`: PR #1252 is retained with two `merge_conflict` exits, zero merge-group runs, and zero observed runner work from completely paired events. The queue-observed cohort increased from 36 to 43 PRs and exit count from 45 to 68.\n- Project Cut `sha256:fd99fb1fee91f09fa17873f17bba2397b7eb4f518442125df6339280f4e65072`, empty Episode delta, published by `95de211fd2a57b8426f4c62be9142a4b70be502f`.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Close the merge-queue delivery discovery gap for closed attempts without workflow runs while preserving exact affected-native proof identity\",\n  \"verification\": [\"Gate latency tests\", \"full source acceptance\", \"live GitHub queue-event measurement\", \"Project Cut publication\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR updates read-only gate delivery evidence and publishes its Project Cut. It does not alter release admission, proof reuse authority, credentials, or deployment behavior.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T17:07:56Z",
          "mergedAt": "2026-07-22T21:55:19Z",
          "additions": 156,
          "deletions": 19,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1270,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1270",
          "title": "fix(shifu): dispatch Windows lifecycle after resolution",
          "body": "## Summary\n\nRestore direct dispatch at every resolved Windows launcher path so ordinary lifecycle tasks reach pnpm after a cold, warm, explicit, or release-pinned resolution.\n\n## Diagnosis\n\nAlpha promotion Build run 29959438156 compiled the launcher and returned 0 without entering `dist`; the following `verify` found only the qualification summary instead of the required product artifacts. The `:runresolved` repair added after the last successful three-platform Build was the behavioral delta. Its tests exercised `--version` and the build-free `cache` shortcut, not an ordinary command.\n\n## Changes\n\n- dispatch the resolved executable directly with the original `%*` vector\n- use delayed expansion only for binary paths first assigned inside parsed blocks\n- add a Windows live probe that requires `doctor` output across cold, warm, explicit, and cache-applied paths\n- update the static contract to reject reintroduction of the no-op `:runresolved` path\n\n## Verification\n\n- targeted entry tests: 3 passed\n- lifecycle tests: 10 passed, 2 Windows-only skipped on macOS\n- full staged repository gate, docs gate, Biome formatting, and DCO: passed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair a Windows launcher argument-dispatch regression without changing any ADR projection.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-22T21:51:37Z",
          "mergedAt": "2026-07-22T21:58:51Z",
          "additions": 28,
          "deletions": 48,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1272,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1272",
          "title": "fix(shifu): dispatch after Windows source build",
          "body": "## Summary\n\nSeparate Windows source-launcher resolution from task dispatch so a successful cold build cannot return 0 before executing the original lifecycle command.\n\n## Diagnosis\n\nAlpha Product Build runs 29959438156 and 29961313640 both showed the same runtime signature: the launcher compiled successfully, no `doctor`/install/dist output followed, every later stage rebuilt the launcher, and `verify` found only one of eight required artifacts. The cache publication and task invocation were nested inside the post-build command block, so that block remained an execution authority and could silently skip the task.\n\n## Changes\n\n- record the fresh target executable inside the build block and dispatch only after the block closes\n- treat publishing the warm cache slot as an optimization, not a prerequisite for running the task\n- fall back to the just-built target executable when cache publication is unavailable\n- ratchet the static contract around top-level post-build dispatch; retain the Windows live `doctor` probe\n\n## Verification\n\n- targeted source-launcher contract tests: 4 passed\n- lifecycle tests: 10 passed, 2 Windows-only skipped on macOS\n- full staged repository gate, docs gate, Biome formatting, and DCO: passed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair a Windows post-build dispatch defect without changing any ADR projection.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-22T22:13:57Z",
          "mergedAt": "2026-07-22T22:20:24Z",
          "additions": 27,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1277,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1277",
          "title": "fix(shifu): inline Windows environment loading",
          "body": "## Summary\n\nInline the two Windows build-local.env reads and remove the trailing `:loadenv` batch subroutine. Recursive Node shell entry could make `cmd.exe` lose that label and leak `cannot find the batch label specified - loadenv` into strict child protocols.\n\n## Verification\n\n- entry-contract and lifecycle tests: 26 passed, 2 Windows-only skipped locally\n- full staged gate passed\n- regression contract requires inline parsing and forbids `call :loadenv` / `:loadenv`\n- failure reproduced in alpha promotion PR #1274, Windows shifu CI job 89066975673\n\nADR-neutral bugfix; no ADR status transition.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair Windows launcher environment parsing without changing any ADR projection.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-22T22:32:55Z",
          "mergedAt": "2026-07-22T22:48:47Z",
          "additions": 24,
          "deletions": 18,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1279,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1279",
          "title": "fix(profile): bind Assignment orchestration in GUI",
          "body": "## Summary\n\n- bind the declared `claim-assignment` intent to a real Work Dashboard GUI action\n- bind the declared `advance-assignment` intent to a real Work Dashboard GUI action\n- cover both Profile authorization paths and keep release KFD-3 client probes aligned\n\n## Diagnosis\n\nAlpha promotion Product Build run 29962626774 reached KFD-3 release parity on Linux and macOS, then failed because the GUI did not expose `.claimAssignment(` or `.advanceAssignment(` calls for the two declared intents. This patch adds real operator-facing Assignment orchestration controls instead of weakening the release contract.\n\n## Verification\n\n- `node --test --experimental-strip-types extensions/work-dashboard/tests/mission-control-profile.test.ts` — passed\n- `corepack pnpm --filter @kungfu-tech/kfx-view-work-dashboard test` — 28/28 passed\n- full staged repository gate — passed\n- Biome, Ruff format and Ruff lint — passed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair declared Assignment GUI API parity without changing any ADR projection.\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T22:54:50Z",
          "mergedAt": "2026-07-22T23:14:33Z",
          "additions": 262,
          "deletions": 19,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1556,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1556",
          "title": "fix(runtime): preserve compatible contracts and release PR routing",
          "body": "## Summary\n\n- accept explicitly compatible historical surface digests so additive action inputs do not block floating alpha consumers\n- recognize merged same-repository release PR closed events as production authority\n- bind production planning, controller evidence, and capability verification to the release merge commit while preserving ordinary preview cleanup\n\n## Verification\n\n- `pnpm run check`\n- exact regression replay of the accepted `v2-alpha` contract digest reports `compatible-drift` with no breaking reasons\n- action bundle integrity, generated site bundle, and workflow lint checks pass\n\n## Version impact\n\nPatch: this corrects contract classification and event routing without removing or changing required inputs or outputs.\n\nCloses #1554\nCloses #1533",
          "author": "dongkeren",
          "createdAt": "2026-07-22T23:21:02Z",
          "mergedAt": "2026-07-22T23:24:00Z",
          "additions": 144,
          "deletions": 42,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1557,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1557",
          "title": "chore(release): promote contract and web routing fixes to v2.14 alpha",
          "body": "## Summary\n\n- preserve compatible Buildchain action contracts across newly optional inputs\n- route qualified merged release PRs into production publication with the exact merge SHA\n- publish the verified fixes through the protected v2.14 alpha channel\n\n## Verification\n\n- `pnpm run check`\n- action bundle verification\n- exact historical contract-drift regression replay\n\nThis PR only advances the protected alpha channel; Buildchain computes and publishes the exact prerelease after merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T23:26:28Z",
          "mergedAt": "2026-07-22T23:27:33Z",
          "additions": 144,
          "deletions": 42,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 68,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/68",
          "title": "docs(paper): derive observer model from foundation triad",
          "body": "## Summary\n\n- derive KFD-4 directly from the Foundation Triad and the shared cross-session case\n- define the generic observer contract before introducing Episode as the Kungfu implementation substrate\n- treat observer incarnation as a second-order refinement and center the evaluation plan on observer-level reproduction and action\n- preserve current Episode, runtime-readiness, and continuity evidence with explicit non-claims\n\n## Checks\n\n- [x] `make check`\n- [x] local `make pdf` completes without warnings\n- [ ] Buildchain `Build` workflow passes\n- [ ] Buildchain `Verify` workflow passes\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs.\n- [x] No unpublished reviewer correspondence or private operational data.\n- [x] Provider/API/data claims are sourced or clearly marked as future work.\n- [x] Public branding and trademark language stays factual.\n\n## Version impact\n\nPatch-level paper revision. No package coordinate, schema, or release contract change.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T23:29:28Z",
          "mergedAt": "2026-07-22T23:35:43Z",
          "additions": 486,
          "deletions": 370,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1282,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1282",
          "title": "feat(profile): define domain profile authoring contract",
          "body": "## Summary\n\nDefine a public, versioned Domain Profile authoring contract and an auditable Work lifecycle operation matrix. The delivery proves a declarative non-software Course Production profile package without adding Core-specific code or claiming four-language runtime parity before later qualification stages.\n\nThis PR is the exact-base clean-history successor of #1222, #1273, #1276, #1278, and #1280. It preserves the reviewed Domain business tree, starts at live `dev/v4/v4.0@31302cabc323a2b5072deb8db06cf0085d2e599d`, and publishes one fresh canonical Project Cut. The predecessors remain available as audit trails.\n\n## Related issue\n\nAtlas parent goal `2026-07-22-kungfu-work-profile-lifecycle-four-language` and child goals `2026-07-22-kungfu-work-lifecycle-operation-matrix` / `2026-07-22-kungfu-domain-profile-authoring-contract`.\n\n## Changes\n\n- define Profile identity, schema/package/dependency/capability/compatibility, responsibility mappings, workflows, policy, settlement, Cut projection, migration, and lifecycle receipts\n- fail closed on role fusion, undeclared authority, dependency cycles, schema/root drift, incompatible migration, and unsigned or unqualified activation\n- add a hash-closed Course Production reference package that exercises a non-software domain without Core-specific symbols\n- publish the 41-operation Work lifecycle matrix, including 11 Domain Profile authoring/distribution operations and explicit C++/Python/Node/Rust parity gaps\n- generate architecture documentation and byte-identical installed contract projections from auditable sources\n\n## Verification\n\n- `./shifu check:domain-profile-authoring` (8/8)\n- `./shifu check:work-lifecycle-operation-matrix` (6/6)\n- `./shifu kfd:buildchain:check` (144 KFD-3 surfaces)\n- `./shifu test:work-facade` (15 Node tests, 20 Python tests)\n- full staged Shifu gate for both clean5 commits\n- `./shifu project-cut composition-verify --receipt .kungfu/runtime/project-cut-go/2026-07-22-kungfu-domain-profile-authoring-contract/composition-receipt-e362.json --json` (`ok: true`, zero diagnostics)\n- final Project Cut: `sha256:6eacb100913619dd7a30a5aec860f004364b351f9792a976c952f97ddee7b189`\n- parent Project Cut: `sha256:57cdfd1baf870cca6263044d0dd518e75f690933e05073abb7a74cc37bf020f4`\n- source projection: `sha256:7f93ecf0ec4ee7c8a3aa4164e3cf80b047eff53f1028fe5963f27c24c6b3f76e`\n- composition receipt: `sha256:a9ede77dd837c1a72aa0a972f1362fdc564aed89168170c9ce3825bce9cd8088`\n- observed commit: `e36266a1d810e709301fb5f3d175ed2891765370`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f8822-1d7a-7594-adea-65ad12c47733\"],\n  \"summary\": \"Stage a declarative third-party Domain Profile authoring contract and complete Work lifecycle inventory without widening Core authority.\",\n  \"verification\": [\"Domain Profile authoring contract tests\", \"Work lifecycle operation matrix tests\", \"full staged Shifu gate\", \"Project Cut exact-root composition qualification\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release-evidence change is limited to content-addressed Project Cut witnesses; no package publication or deployment is performed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T23:17:37Z",
          "mergedAt": "2026-07-22T23:36:28Z",
          "additions": 8516,
          "deletions": 48,
          "changedFiles": 53
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 71,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/71",
          "title": "release(paper): prepare foundation triad alpha.9",
          "body": "## Summary\\n\\n- carry the Foundation Triad-derived Observer rewrite onto the v0.1 development line\\n- advance the paper package from 0.1.0-alpha.8 to 0.1.0-alpha.9\\n- refresh the publication abstract and accept the reviewed v2-alpha contract world at e7ad5002\\n- preserve the alpha.8 PDF naming, sealed publication entrypoint, toolchain digest, and trusted publishing contract\\n\\n## Checks\\n\\n- [x] make check\\n- [x] make pdf\\n- [x] generated observer-declared-timelines.pdf is 17 pages\\n- [x] Buildchain lock exactly matches the accepted remote contract world\\n\\n## Governance\\n\\n- [x] No credentials, tokens, private logs, or unpublished reviewer correspondence\\n- [x] Paper evidence boundaries and future-work non-claims remain explicit\\n- [x] Version impact is patch-level prerelease advancement",
          "author": "dongkeren",
          "createdAt": "2026-07-22T23:38:47Z",
          "mergedAt": "2026-07-22T23:39:49Z",
          "additions": 444,
          "deletions": 373,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 72,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/72",
          "title": "chore(release): promote foundation triad Observer alpha.9",
          "body": "Promote the verified Foundation Triad-derived Observer paper from dev/v0/v0.1 to the alpha channel.\n\nRelease intent:\n\n- publish @kungfu-tech/paper-observer-declared-timelines version 0.1.0-alpha.9\n- publish the 17-page observer-declared-timelines.pdf GitHub Release asset\n- preserve the sealed OIDC and trusted-publishing entrypoint and alpha.8 toolchain identity\n- carry the reviewed v2-alpha at e7ad5002 contract lock\n\nQualification:\n\n- candidate PR Build and Verify passed\n- dev merge SHA caee88138c7f8b1db6d37066c355e91897227ebd Build and Verify passed\n- local PDF build is warning-free with no unresolved citations",
          "author": "dongkeren",
          "createdAt": "2026-07-22T23:40:49Z",
          "mergedAt": "2026-07-22T23:42:00Z",
          "additions": 444,
          "deletions": 373,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1283,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1283",
          "title": "fix(runtime): bind installed contract search root",
          "body": "## Summary\n\n- pass the assembled product root into the native Action Runtime as its default `search_base`\n- preserve caller-supplied search roots\n- cover both installed-product injection and explicit override behavior\n\n## Diagnosis\n\nAlpha Product Build run 29965568435 successfully assembled and packaged Linux, including the contract registry under `runtime/config`, then failed the installed CLI capability smoke. `work_profile.capabilities()` crosses into the C++ Action Runtime with an empty runtime directory and no `search_base`; native registry discovery therefore searched only the qualification temp cwd. The Python host seam already knows the installed product root, so this patch carries that fact across the Python/native boundary without relying on CI-only environment variables.\n\n## Verification\n\n- `PYTHONPATH=src/python uv run --frozen pytest tests/python/test_contract.py -q` — 3 passed\n- Ruff format and lint — passed\n- full staged repository gate — passed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair installed-product native contract discovery without changing any ADR projection.\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T23:33:24Z",
          "mergedAt": "2026-07-22T23:51:50Z",
          "additions": 55,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 195,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/195",
          "title": "chore(papers): publish observer alpha.9",
          "body": "## Summary\n\n- advance the pinned Observer paper package to 0.1.0-alpha.9\n- expose the Foundation Triad-derived abstract and alpha.9 immutable archive routes\n- update the exact npm integrity lock while leaving the other paper coordinates unchanged\n\n## Checks\n\n- pnpm install lockfile-only with the public npm registry\n- pnpm install frozen lockfile with the public npm registry\n- pnpm run build\n- pnpm run check\n- generated archive PDF SHA-256 matches the GitHub Release asset digest\n\n## Governance\n\n- Exact published npm package and SHA-512 integrity are pinned.\n- Existing paper versions and unrelated upstream coordinates are unchanged.\n- No private data or Atlas control-plane content is introduced.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T23:47:52Z",
          "mergedAt": "2026-07-23T00:00:32Z",
          "additions": 8,
          "deletions": 8,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1284,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1284",
          "title": "fix(adr): make corpus migration classification explicit",
          "body": "## Summary\n\nMake the one-time ADR corpus migration plan complete and fail closed before the corpus rewrite.\n\n## Related issue\n\nAtlas goal 2026-07-22-kungfu-adr-corpus-identity-rewrite.\n\n## Changes\n\n- Scan every tracked Git blob and classify authored, current test, semantic fixture, historical, and generated references explicitly.\n- Rewrite ADR index and current test references in path-only mode while preserving legacy semantic fixtures and immutable history.\n- Declare the complete KFD and Xinfa regeneration output closure.\n- Add a completion receipt that binds after-roots, preserved bytes, regeneration checks, and generated output roots.\n\n## Verification\n\n- ./shifu lint\n- ./shifu adr:identity:test (45/45)\n- ./shifu check:source\n- deterministic 4,984-blob plan, 140-to-140 identity conservation, zero problems\n- independent review PASS\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-019f86ff-a8d6-7431-ae05-0ec95fdb7ace\"],\n  \"summary\": \"Make the reviewed full-corpus identity rewrite plan complete and fail closed before execution\",\n  \"verification\": [\"./shifu check:source\", \"./shifu adr:identity:test\", \"independent migration-plan review PASS\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change only declares and validates local derived-evidence regeneration outputs; it performs no publishing or deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-22T23:48:05Z",
          "mergedAt": "2026-07-23T00:12:19Z",
          "additions": 453,
          "deletions": 38,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1286,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1286",
          "title": "fix(shifu): reuse pinned Windows lifecycle binary",
          "body": "## Summary\n\nRepair nested Windows Shifu lifecycle dispatch after Product Build run 29967583701 (Windows job 89082416060) showed that build and verify re-entered `cmd.exe -> shifu.cmd` even though the cache-active environment had already selected a native launcher in `SHIFU_BIN`.\n\nThe lifecycle runner now directly spawns that pinned native binary on Windows when it exists, preserving the selected launcher and avoiding a second batch-parser boundary. The existing `cmd.exe /d /s /c shifu.cmd` path remains the fallback when no pinned binary is available.\n\n## Verification\n\n- `node --test scripts/run-shifu-lifecycle.test.mjs` — 13 tests, 11 passed, 2 platform skips\n- `node --test scripts/check-shifu-entry-contract.test.mjs` — 16/16 passed\n- `corepack pnpm exec biome check scripts/run-shifu-lifecycle.mjs scripts/run-shifu-lifecycle.test.mjs`\n- repository staged validation / commit hooks passed\n- new regression test emulates Windows with `SHIFU_BIN` pointing to the current native Node executable and an invalid `ComSpec`, proving the direct path bypasses cmd\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair nested Windows lifecycle dispatch without changing any ADR projection.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T00:13:25Z",
          "mergedAt": "2026-07-23T00:19:31Z",
          "additions": 28,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 196,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/196",
          "title": "Release production from a15621681e67",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `a15621681e67e1c51ef0b933705ccc8ba33d7724`\n- Artifact hash: `f6c855d8646e9695aae688878fbb9a7bfcf4f4df527afba9e732e8e920d9eaeb`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29967830256)\n- Required label: `buildchain-release`\n- Release branch: `release/production-a15621681e67`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-23T00:10:45Z",
          "mergedAt": "2026-07-23T00:25:51Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 295,
          "url": "https://github.com/kungfu-systems/build-images/pull/295",
          "title": "fix(comparator): synchronize cgroup sampling baseline",
          "body": "## Summary\n\n- gate every full-stack workload on two retained raw cgroup-v2 samples\n- keep the existing fail-closed two-sample and exact subject-limit requirements\n- refresh adapter registry and production-plan identity locks\n- cover the provider/adapter handshake and one-sample rejection\n\n## Formal evidence boundary\n\nThe single exact `v1.3.0-alpha.12` formal attempt is retained and rejected without retry. It passed the previous Aeron liveness boundary at schedule index 420, completed 577 samples on attempt 1, then the fast Kungfu visible/64-byte recovery sample finished before the sampler retained a second raw observation. The provider therefore failed closed with `cgroup-v2 sampler retained fewer than two samples`.\n\nThis patch does not synthesize samples or relax verification. The provider emits a one-shot marker only after retaining two raw samples and proving the exact subject limits; the adapter consumes that marker before starting the measured workload.\n\n## Verification\n\n- `pnpm run check`\n- 114 comparator unit tests\n- production plan validation for PostgreSQL, ClickHouse, and Aeron\n- KFD123 check with unchanged Buildchain v2 alpha/stable contract locks\n\nCloses no issue by itself. #248 remains open until a new published alpha passes one fresh, complete, no-retry 666-sample run.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T22:04:47Z",
          "mergedAt": "2026-07-23T00:35:06Z",
          "additions": 202,
          "deletions": 8,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 298,
          "url": "https://github.com/kungfu-systems/build-images/pull/298",
          "title": "chore(release): prepare v1.3.0-alpha.13",
          "body": "## Summary\n\n- prepare `v1.3.0-alpha.13` after the reviewed cgroup sampler baseline fix\n- adopt Buildchain `2.14.17-alpha.1` and stable `2.14.16`\n- refresh the independent `v2-alpha` and `v2` contract locks from exact published runtimes\n- regenerate KFD123 evidence, including the new binary-distribution controller surface\n- keep pnpm minimum-release-age enforcement while expressing the two approved KFD prereleases as one exact version union\n\n## Contract identities\n\n- Alpha: `v2-alpha@fa773a92941632d8cfb1244ba90b350a70be6d8c`\n  - contract: `sha256:9d5bef7245674767352cc2746d507d556a11d685502120c00176f1a15bade2ba`\n- Stable: `v2@4612956c052aed8bb8f1d1b2edfd80c79326f654`\n  - contract: `sha256:81c0ed79269d4b0c2f94c11cc316069db7b4264814f3170b3877a9f960ac0320`\n\n## Verification\n\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- 114 comparator tests\n- KFD123 alpha/stable lock status: unchanged, drift false\n- Release Passport smoke: passed\n\nCloses #296.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T00:40:48Z",
          "mergedAt": "2026-07-23T00:44:17Z",
          "additions": 502,
          "deletions": 63,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 299,
          "url": "https://github.com/kungfu-systems/build-images/pull/299",
          "title": "chore(release): promote v1.3.0-alpha.13",
          "body": "## Release promotion\n\nPromote `dev/v1/v1.3` to `alpha/v1/v1.3` for Buildchain v2 alpha publication.\n\n- version: `1.3.0-alpha.13`\n- release passport: enabled\n- GitHub release: enabled\n- alpha contract lock: `@v2-alpha` at `fa773a92941632d8cfb1244ba90b350a70be6d8c`\n- stable contract lock remains `@v2`\n- includes the cgroup sampler readiness handshake required by #248\n\nThe published exact image digest will be used for one fresh, no-retry 666-sample qualification before stable promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T00:44:32Z",
          "mergedAt": "2026-07-23T00:47:21Z",
          "additions": 704,
          "deletions": 71,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1275,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1275",
          "title": "docs(ci): refresh dev gate latency baseline",
          "body": "## Summary\n\nRefresh the retained dev gate latency baseline after the staged-CI rollout changed the protected branch contract to one stable required context: `affected-native / linux`.\n\nThe previous retained baseline correctly failed closed because its expected required-context set no longer matched live branch protection. This PR updates that authority in the same measurement contract and records a fresh 30-sample snapshot. It does not change the affected-native planner, workflow, proof format, lookup, or reuse semantics. Proof reuse remains bound to the exact base revision, candidate/source tree, plan projection, partition/tier, receipt, and toolchain evidence; a moved base still requires `reuse: false` and a complete native run.\n\n## Related issue\n\nAtlas goal `2026-07-17-kungfu-dev-gate-latency-slo`.\n\n## Changes\n\n- Align the retained baseline required-context set with current live protection: `affected-native / linux` only.\n- Refresh the 30-sample aggregate and native/non-native slices.\n- Document that any future protected-branch context transition must update the retained measurement baseline in the same delivery.\n- Publish the exact Project Cut for this baseline refresh.\n\n## Current evidence\n\n- Required-check aggregate: P50 509s, P95 3204s, max 4947s.\n- Native slice: 19 samples, P50 2360s, P95/max 4947s.\n- Non-native slice: 11 samples, P50 157s, P95/max 550s.\n- Merge queue: 52 observed PRs, 43 completed deliveries, P50 2532s, P90 10727s, 24/52 dequeued.\n- Queue exits: 50 merge conflicts, 15 failed checks, 11 manual exits, 3 invalid merge commits.\n- Repeated validations: 13, with 16216s observed runner time and 13386s post-dequeue time.\n\nThe first merge-group preview correctly failed closed with `source-drift` when the queue base differed from the prior Project Cut source/base identity. After #1279, #1282, #1283, #1284, and #1286 serialized through the queue (while #1133 failed its own source check and exited), this branch was regenerated on the exact current base `96e743c69e2e69640b6ae5cd93d6deeb3ffa4d99` with source projection `sha256:61a4d32e4c479a96e8072a789bdebff82284a237b214e22731d1413cc2fb5f26`; no base-forward proof reuse was introduced.\n\nThe snapshot is intentionally unqualified. It shows the current dev path still misses the P95 latency SLO and preserves that evidence instead of normalizing it away.\n\n## Verification\n\n- `node --test scripts/measure-dev-required-latency.test.mjs` (22/22)\n- `./shifu test:gate-latency` (35/35)\n- `./shifu check:source` on the prior exact candidate passed (Node 530 passed, 2 Windows-only skips; Python 41/41; runtime upgrade 76/76); final r8 staged pre-commit and composition gates passed before push\n- Project Cut composition gate: `ok: true`, changed Cut root `sha256:9df442484f4dccfe1b63a8dea6ff40c6cda43210313494e6a583a3fceb80e87d`\n- Project Cut observation: published by `e62d530839544e303141116fdc3244d4cf9501cd`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This PR refreshes retained measurement evidence and its Project Cut after a protected-branch context transition; it changes no architecture or proof-reuse contract.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe affected boundary is retained latency evidence and Project Cut provenance. No workflow, affected-native proof authority, reuse lookup, or deployment behavior changes.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n\n\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-22T22:22:38Z",
          "mergedAt": "2026-07-23T00:47:29Z",
          "additions": 53,
          "deletions": 34,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1558,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1558",
          "title": "feat(observability): add candidate timeline contract",
          "body": "## Summary\n\n- add a source-bound `buildchain.candidate-timeline/v1` contract and public Node API\n- isolate Merge Queue retries into independent attempts and calculate interval unions instead of summing nested or parallel spans\n- expose `buildchain candidate timeline` for machine artifacts and compact reports\n- publish the CLI and API through Buildchain public-surface registries and observability docs\n\n## Verification\n\n- `pnpm run check` (766 tests passed; workflow and action bundle checks passed)\n- `node scripts/check-inventory.mjs`\n- `bash scripts/check-workflows.sh`\n- `node --test tests/candidate-timeline.test.mjs`\n- `pnpm run check:site`\n- `git diff --check`\n\n## Safety\n\nThe contract records bounded correlation and timing facts only. It explicitly separates attempts, preserves dependency-blocked/not-required states without invented durations, and labels provider timestamp precision.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T00:40:45Z",
          "mergedAt": "2026-07-23T00:47:35Z",
          "additions": 711,
          "deletions": 26,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1288,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1288",
          "title": "fix(shifu): preserve Windows pnpm task dispatch",
          "body": "## Summary\n\nProduct Build run 29968856850 proved the Windows launcher could build successfully while ordinary lifecycle arguments never reached pnpm: install/build/verify emitted only launcher-build messages, and verify produced one artifact instead of the required eight.\n\nEnter the repository batch shim through an explicit `call` command boundary under `cmd.exe /d /s /c`. This preserves the full ordinary-task argument vector after the batch file returns through nested cache-applied lifecycle execution.\n\nThe regression suite now executes a real Windows `pnpm exec node` command and requires a filesystem side effect. Previous coverage only exercised launcher-owned `--version` and `doctor` paths and therefore could not detect a dropped pnpm task.\n\n## Verification\n\n- `node --test scripts/run-shifu-lifecycle.test.mjs` — 11 pass, 3 Windows-only skips locally\n- `node --test scripts/check-shifu-entry-contract.test.mjs` — 16/16 pass\n- `corepack pnpm exec biome check scripts/run-shifu-lifecycle.mjs scripts/run-shifu-lifecycle.test.mjs`\n- full staged repository gate passed during signed commit\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair Windows ordinary pnpm task dispatch without changing any ADR projection.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T00:37:34Z",
          "mergedAt": "2026-07-23T00:53:40Z",
          "additions": 30,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1559,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1559",
          "title": "chore(release): promote v2.14 alpha",
          "body": "## Summary\n\nPromote the reviewed v2.14 development channel, including the candidate timeline observability contract, through the normal alpha release path.\n\n## Source\n\n- dev source: `f4d441228f37e83e27f0ba29ee92ee76d30f6908`\n- originating PR: #1558\n- downstream validation train: `train/v2/v2.14/candidate-timeline-telemetry`\n\n## Expected result\n\nPublish the next immutable v2.14 alpha and update the normal alpha channel refs without bypassing release governance.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T00:50:39Z",
          "mergedAt": "2026-07-23T00:55:29Z",
          "additions": 711,
          "deletions": 26,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1291,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1291",
          "title": "fix(adr): close migrated revision bindings",
          "body": "## Summary\n\nClose the ADR corpus migration revision-binding gap discovered during the reviewed full-corpus rehearsal. The migration plan now binds every legacy ADR byte root to its post-ID/path rewrite root and fails closed if revision rewriting is non-terminal.\n\n## Related issue\n\nAtlas goal: 2026-07-22-kungfu-adr-corpus-identity-rewrite\n\n## Changes\n\n- Add deterministic revisionMappings to the reviewed migration plan.\n- Rewrite expectedRevision references only in full live transformations.\n- Reject non-terminal ADR root rewrites before apply.\n- Cover multiple live revision bindings and fail-closed root dependencies.\n\n## Verification\n\n- ./shifu adr:migrate:test (5/5)\n- ./shifu check:source\n- ./shifu check\n- git diff --check\n- Independent read-only review: PASS\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Bugfix closes migration revision bindings without changing the distributed UUIDv7 ADR identity contract\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe migration manifest remains exact-tree, deterministic, independently reviewed, and fail-closed on source or algorithm drift.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (no contract change; regression tests cover the fix)",
          "author": "dongkeren",
          "createdAt": "2026-07-23T00:57:47Z",
          "mergedAt": "2026-07-23T01:03:42Z",
          "additions": 126,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1133,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1133",
          "title": "feat(cli): expose native compact plan",
          "body": "## Summary\n\nDeliver ADR-0071 Bucket A stage four: expose native read-only `compact-plan` through the Rust Trunk and the ADR-0120 successor `kungfu_get_api` / `maintenance v1` interface.\n\nThe original branch proposed a prefix-compatible embedding ABI v6. Before merge, ADR-0120 retired that pre-standard bootstrap after first-party convergence. This revision preserves the product behavior without restoring a retired export.\n\n## Related issue\n\nADR-0071; supersession alignment with ADR-0120.\n\n## Changes\n\n- add `compact-plan` to the single Rust Trunk routing/help table\n- add a typed Rust maintenance request that always emits `dry_run=true` and exposes no mutating controls\n- call existing `KF_MAINTENANCE_COMPACT_PLAN` operation 6 through the sole `kungfu_get_api` ABI v1 bootstrap and `maintenance v1`\n- isolate the API context log in an ephemeral directory so inspection does not initialize files inside the selected runtime\n- extend the real shared-library API contract test with report and sentinel/tree non-mutation assertions; on Windows this links the actual `kungfu_abi` DLL facade\n- make fixture cleanup non-throwing so a Windows-held log handle cannot turn a passed ABI contract into `std::terminate`\n- declare the API contract test's direct `nlohmann_json` dependency so the hosted affected-native closure is complete\n- retain focused Gate history/cache fixes needed for exact-revision qualification\n- revise ADR-0071 to record the fourth stage and the pre-merge supersession of the literal ABI v6 draft\n\n## Verification\n\n- final exact head `c8f0281cff0a26f71fd319cf5084b10105dd4a84` on base `b50203b5bb1916af9c5190ff7090fca5e3cdf6d6`\n- exact local pre-push gates, staged/ADR/docs checks: passed\n- exact PR required checks: passed (`Core affected native` run `29971169425`)\n- Rust workspace tests, focused Gate helper tests, and clean CMake `kungfu_api_contract_tests`: passed\n- final successor Project Cut `sha256:80bee5075ac8b6ddaceee36c68aee2fd426c8a634f3aeaab1267e72105ef2c0d`\n- parent Cut `sha256:42f6a7d36f53b16b52722b11a89f14fa926cf90bb975319cf4c27734f85d7391`\n- source projection `sha256:05664fd8026f749c7bfe33920ecf44b3e957042c7fda91c7a8b7727ffb4d1174`\n- immediately preceding source-bound composition `sha256:106de9dd3d21768fcf682c9a0dd1fc2dff554f913187d0552c05cdf8c0dd16a3`: qualified; the exact `b50203b` source acceptance is running\n- three-platform `embedding.membranes` Gate `29964588050`: Linux `89073169537`, Windows `89073169557`, macOS `89073169595`, all passed on source-equivalent head `11c7b74a0b7ef710b41cdcd18ede44231e3eb443`\n- final source-only rebase preserves stable task-delta patch-id `eb1b46081bdfc4ef49ec5cb840c84ea21244cbdc`\n- independent exact-head review: https://github.com/kungfu-systems/kungfu/pull/1133#pullrequestreview-4760028369\n- exact-head Project Cut closeout gate: passed; claim `completion-0ff38cf7edc8e2462fed2491`, review `review-96a75bbced26857623ae8c10`, decision `decision-70d8e13269aea296bc061564`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0071\"],\n  \"summary\": \"Deliver native read-only compact planning through the ADR-0120 standard maintenance interface and the Rust Trunk.\",\n  \"verification\": [\"exact-head ./shifu check:source\", \"Rust workspace tests\", \"three-platform source-equivalent embedding.membranes Gate Measurement with stable patch-id proof\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe final successor Project Cut is bound to the exact source. Runtime journals and machine-local state remain untracked. The native compact operation is fail-closed to dry-run mode.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-19T10:23:17Z",
          "mergedAt": "2026-07-23T01:33:57Z",
          "additions": 515,
          "deletions": 46,
          "changedFiles": 90
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1292,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1292",
          "title": "fix(shifu): preserve fallback lifecycle argv",
          "body": "## Summary\n\nProduct Build run 29970417379 proved the previous Windows regression test was a false positive: the test process inherited `SHIFU_BIN` from its parent Shifu invocation and bypassed the cmd fallback, while the real cache-active Product Build still ran no ordinary pnpm tasks and produced one artifact.\n\nThis patch:\n\n- passes `cmd.exe /d /s /c call`, the batch shim, and every task argument as discrete spawn arguments so Node owns Windows quoting;\n- removes `windowsVerbatimArguments`, eliminating the hand-built single command payload that dropped the ordinary task vector;\n- makes the Windows regression strip `SHIFU_BIN`, force `SHIFU_CACHE_ACTIVE=1`, use an isolated launcher cache, and require a real `pnpm exec node` filesystem side effect.\n\n## Verification\n\n- `node --test scripts/run-shifu-lifecycle.test.mjs scripts/check-shifu-entry-contract.test.mjs` — 27 pass, 3 Windows-only skips locally\n- `corepack pnpm exec biome check scripts/run-shifu-lifecycle.mjs scripts/run-shifu-lifecycle.test.mjs`\n- full staged repository gate passed during signed commit\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair Windows fallback lifecycle argv without changing any ADR projection.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T01:21:29Z",
          "mergedAt": "2026-07-23T01:36:34Z",
          "additions": 26,
          "deletions": 16,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1295,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1295",
          "title": "fix(shifu): quote Windows lifecycle payload once",
          "body": "## Summary\n\nThe corrected cache-active fallback regression in alpha PR #1294 proved that passing discrete arguments after `cmd.exe /c` exits 255. The earlier single-payload form failed because it combined hand-written outer quotes with `windowsVerbatimArguments`.\n\nThis patch uses the Windows-safe middle ground:\n\n- construct one `call \"shifu.cmd\" \"task\" ...` payload for `/c`;\n- pass that payload as one normal spawn argument with no hand-written outer quote pair;\n- let Node escape the single CreateProcess argument;\n- retain the corrected regression that removes inherited `SHIFU_BIN`, forces `SHIFU_CACHE_ACTIVE=1`, isolates the cache, and requires a real pnpm filesystem side effect;\n- expose child output during the regression so a future failure is diagnostic.\n\n## Verification\n\n- `node --test scripts/run-shifu-lifecycle.test.mjs scripts/check-shifu-entry-contract.test.mjs` — 27 pass, 3 Windows-only skips locally\n- `corepack pnpm exec biome check scripts/run-shifu-lifecycle.mjs scripts/run-shifu-lifecycle.test.mjs`\n- full staged repository gate passed during signed commit\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair Windows lifecycle payload quoting without changing any ADR projection.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T01:48:10Z",
          "mergedAt": "2026-07-23T01:54:48Z",
          "additions": 10,
          "deletions": 12,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1560,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1560",
          "title": "feat(observability): add candidate optimization analysis",
          "body": "## Summary\n- add measured execution-lane summaries and lane skew to candidate timelines\n- expose cache outcomes, dominant actionable spans, and a falsifiable next optimization target\n- keep the analysis observational and source-bound; do not claim causality or sum nested spans\n\n## Verification\n- `pnpm check`\n- candidate timeline tests include lane skew, cache state, target selection, and compact report output\n\n## Channel boundary\nThis is alpha observation capability. Stable release authority and stable contract lock remain unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T01:59:12Z",
          "mergedAt": "2026-07-23T02:04:08Z",
          "additions": 211,
          "deletions": 14,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1298,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1298",
          "title": "fix(adr): close post-apply migration gates",
          "body": "## Summary\n\nClose the two post-apply gaps found by the full ADR corpus migration rehearsal.\n\n## Changes\n\n- retire the frozen legacy ADR index rows instead of projecting UUID rows into the shared index\n- close the rewritten legacy Atlas manifest byte root into its pinned live consumer\n- keep planning and application on one rewrite algorithm with fail-closed closure checks\n- add fixture coverage for both boundaries\n\n## Verification\n\n- ./shifu adr:migrate:test\n- ./shifu check:source\n- ./shifu check\n- independent read-only review: PASS\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fixes deterministic migration mechanics and preserves the accepted ADR architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above",
          "author": "dongkeren",
          "createdAt": "2026-07-23T01:59:57Z",
          "mergedAt": "2026-07-23T02:06:40Z",
          "additions": 110,
          "deletions": 20,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1561,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1561",
          "title": "chore(release): promote v2.14 alpha telemetry analysis",
          "body": "## Summary\n\nPromote the reviewed v2.14 development channel, including candidate lane skew, cache state, dominant spans, and falsifiable optimization targets, through the normal alpha release path.\n\n## Source\n\n- dev source: `27ee767c9753d39f6cbf8a1664bd5634a1863501`\n- originating PR: #1560\n- downstream validation train: `train/v2/v2.14/candidate-timeline-analysis`\n\n## Channel boundary\n\nThis publishes the next immutable v2.14 alpha only. Stable release authority, stable package version, and stable contract lock remain unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T02:04:41Z",
          "mergedAt": "2026-07-23T02:07:38Z",
          "additions": 211,
          "deletions": 14,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 197,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/197",
          "title": "feat(dogfood): retain append-only evidence history",
          "body": "## Summary\n\n- evolve new Dogfood Evidence observations to a v2 append-only history contract while retaining v1 compatibility\n- reconstruct the 2026-07-06, 2026-07-13, and 2026-07-20 observation points from exact GitHub queries and exact Kungfu commits\n- preserve the 2026-07-21 immutable baseline as an off-cadence legacy node\n- add stable snapshot URLs, archive navigation, adjacent observation deltas, integrity validation, and accessible fallback behavior\n- add a manual-only, default-branch-only migration workflow that publishes immutable objects with `If-None-Match: *`, verifies remote bytes, and advances latest only after all immutable checks pass\n\n## Validation\n\n- `npm run build`\n- `npm run check`\n- generated and validated all three backfill snapshots against the exact historical Git trees\n- generated a migration current snapshot and a subsequent weekly snapshot to prove append-only continuation\n- negative checker test rejects a broken previous-snapshot link\n- Playwright verified latest, stable 2026-07-13 archive URL, Previous navigation, legacy/off-cadence display, unknown-id fallback, corrupt-snapshot fallback, adjacent deltas, and updated hero accessibility text\n\n## Production follow-up\n\nAfter merge and production site deployment, dispatch `Dogfood Evidence History Backfill` once from `main`. The workflow reuses the existing production-evidence role and keys; it does not list or delete objects and does not change IAM.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T02:03:06Z",
          "mergedAt": "2026-07-23T02:14:38Z",
          "additions": 1057,
          "deletions": 82,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1299,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1299",
          "title": "fix(shifu): preserve raw Windows lifecycle payload",
          "body": "## Summary\n\n- pass the single `call ...` payload to `cmd.exe` with `windowsVerbatimArguments: true` so Node does not turn token quotes into literal backslash-quote bytes\n- align Product Qualification coverage with the same raw payload contract\n- retain the corrected Windows fallback regression that executes a real pnpm command and requires a filesystem side effect\n\n## Verification\n\n- `node --test scripts/run-shifu-lifecycle.test.mjs scripts/run-zero-burden-product-qualification.test.mjs` — 21 pass, 3 Windows-only skips locally\n- Biome passed for both changed files\n- full signed commit gate passed, including 92 documentation/promotion tests\n- failing exact Windows evidence: run 29973082365, job 89099070087 (`\\\"...shifu.cmd\\\" is not recognized`)\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"Repair Node-to-cmd raw argument transport without changing runtime architecture or release claims.\"}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis repair changes qualification invocation only; it does not publish artifacts.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T02:09:48Z",
          "mergedAt": "2026-07-23T02:15:47Z",
          "additions": 5,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 249,
          "url": "https://github.com/kungfu-systems/kfd/pull/249",
          "title": "feat: add KFD-11-13 activation contracts",
          "body": "## Summary\n\n- add machine-readable adopter witness schemas for KFD-11, KFD-12, and KFD-13\n- add a shared qualification report and fail-closed activation record contract\n- expose stable registry, package, site, Agent Hub, and verifier paths\n- preserve KFD-11 through KFD-13 as numbered drafts\n\n## Verification\n\n- `npm run check`\n- `cargo fmt --all --manifest-path verifier/Cargo.toml -- --check`\n- `git diff --check`\n- `npm pack --dry-run --json --ignore-scripts` with required-file assertions\n\n## Non-claims\n\nThis PR does not claim cross-domain adoption, does not claim Kungfu conformance, and does not activate KFD-11 through KFD-13.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T02:20:52Z",
          "mergedAt": "2026-07-23T02:24:26Z",
          "additions": 1486,
          "deletions": 173,
          "changedFiles": 45
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 104,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/104",
          "title": "feat: add Kungfu UNGFU trademark surfaces",
          "body": "## Summary\n\nAdd Kungfu UNGFU™ as a secondary source-identifying signature while preserving the continuity proposition and Kungfu product name.\n\n## Changes\n\n- pair the exact mark with Never Guess. Facts Unfold. on the homepage\n- explain the source signature and non-product boundary on Why Kungfu\n- add a shared site-wide owner notice and legal-page registration disclaimer\n- add focused negative checks for registered-symbol use, registration claims, product renaming, and missing surfaces\n\n## Verification\n\n- corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- git diff --check\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change uses ™ only, makes no registration-complete claim, keeps Coming Soon non-downloadable, and requires independent preview/staging review before any production action.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-23T02:23:46Z",
          "mergedAt": "2026-07-23T02:31:36Z",
          "additions": 129,
          "deletions": 6,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 198,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/198",
          "title": "Release production from e24d1537762a",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `e24d1537762a4fe96bc0bedb8b05981c29bb0864`\n- Artifact hash: `7744d1083a6c46ad6134b50629c2e6fe42230d62d1d2ab9fe6af068766871545`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29973898443)\n- Required label: `buildchain-release`\n- Release branch: `release/production-e24d1537762a`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-23T02:27:02Z",
          "mergedAt": "2026-07-23T02:38:57Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1293,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1293",
          "title": "feat(buildchain): record candidate timeline telemetry",
          "body": "## Summary\n\nAdopt Buildchain's `buildchain.candidate-timeline/v1` contract for Kungfu dev candidate telemetry. The change preserves the Buildchain dual-channel boundary: the alpha runtime supplies the observation API, while the stable release runtime and contract lock remain untouched release authority.\n\n## Changes\n\n- emit bounded, source-bound internal stage events from Core configure/build, SDK pack/setup/wire qualification, and affected-native install/configure/build/test\n- retain the event JSONL in the authoritative affected-native merge-queue artifact\n- split the formerly monolithic four-language SDK workflow step into toolchain, Core build, pack, and wire-contract provider intervals\n- collect GitHub queue, workflow, job, and step timing plus internal events into one per-candidate timeline without mixing PR and merge-queue attempts\n- compute critical-path duration from interval unions so nested and parallel spans are not double-counted\n- preserve missing runner queue time and older internal phase detail as explicit unknowns\n- expose focused historical collection through repeated `--pull` and one-pull `--timeline-output`\n- consume `@kungfu-tech/buildchain@2.14.17-alpha.2` through an alpha-only package alias while retaining stable `@kungfu-tech/buildchain@2.14.1`\n\n## Verification\n\n- `./shifu check:source`\n- staged source/ADR/docs gate during both signed-off commits\n- 26 dev required Gate latency/cache contract tests\n- candidate event success/failure/source-binding tests\n- `./shifu check:gate-catalog`\n- `./shifu test:release-admission`\n- `./shifu release:promotion:rehearse`\n- `./shifu layers:qualify:sdk -- --validate-only`\n- historical PR 1254 reconstructed into a valid two-attempt candidate timeline; queue residence 3,013 s, SDK wire provider interval 2,113 s, native closure interval union 1,149 s, with unavailable old internal phases remaining unknown\n\nFresh source-bound internal stage evidence will be collected from this PR's authoritative merge-queue run after admission.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Stage source-bound Buildchain candidate timelines for authoritative dev merge-queue builds while preserving separate alpha observation and stable release authority.\",\n  \"verification\": [\"full ./shifu check:source\", \"candidate timeline and dev latency contract tests\", \"release admission and promotion rehearsal\", \"fresh merge-queue proof required before closeout\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release boundary change is limited to consuming the already-published Buildchain alpha observation API. Stable release admission remains pinned to its existing package and contract lock; this PR publishes no package and performs no deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T01:35:04Z",
          "mergedAt": "2026-07-23T03:37:03Z",
          "additions": 1317,
          "deletions": 124,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1304,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1304",
          "title": "feat: add trademark public-use gate",
          "body": "## Summary\n\nStage the Kungfu UNGFU™ source signature and a fail-closed first-real-release evidence boundary without renaming Kungfu or any technical identifier.\n\n## Related issue\n\nAssignment: 2026-07-23-kungfu-ungfu-trademark-public-use\n\n## Changes\n\n- place the exact mark and principle on the README first screen and canonical Why Kungfu explanation\n- attribute the mark in TRADEMARK.md while separating trademark identity from Apache-2.0 permissions\n- add a machine-readable release contract, public-safe evidence procedure, and negative fixtures\n- record the accepted brand and release-evidence decision in KF-ADR-019f8cc4-e796-7b0e-9a16-50c08614e848\n\n## Verification\n\n- node scripts/check-trademark-public-use.mjs\n- node --test scripts/check-trademark-public-use.test.mjs\n- node scripts/run-docs-source-check.mjs with the promotion rehearsal serialized after a shared-ref concurrency retry\n- source-acceptance pre-document checks and complete post-document plan\n- pre-commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f8cc4-e796-7b0e-9a16-50c08614e848\"],\n  \"summary\": \"Stage the secondary Kungfu UNGFU source signature and the fail-closed first-real-release evidence gate while released-software use remains false.\",\n  \"verification\": [\"trademark public-use contract and four negative fixtures\", \"documentation contracts and ADR audit\", \"source-acceptance contract, upgrade, desktop, type, and format checks\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR uses ™ only, records no first-use date, publishes no private filing material, and does not claim registration or released downloadable software.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-23T02:23:49Z",
          "mergedAt": "2026-07-23T03:47:09Z",
          "additions": 595,
          "deletions": 6,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 106,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/106",
          "title": "Explain how Agents bootstrap into the supply chain",
          "body": "## Summary\n- add the missing bootstrap chapter between selection advantage and the conditional flywheel\n- explain how a compact Skill envelope points a Kungfu-managed Agent to exact installed KFD-3, KFD-2, and Buildchain evidence\n- preserve the cold-start boundary and project the same causal bridge into JSON and llms.txt\n\n## Verification\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `bash -n scripts/check-site.sh`\n- `shellcheck scripts/check-site.sh`\n- desktop and 390px browser checks",
          "author": "dongkeren",
          "createdAt": "2026-07-23T04:21:02Z",
          "mergedAt": "2026-07-23T04:23:34Z",
          "additions": 80,
          "deletions": 14,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 107,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/107",
          "title": "Release production from 42fbfb2bc0b6",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `42fbfb2bc0b6e3341124433dd277510bbc1e021c`\n- Artifact hash: `b84db645b49daf73ec92ea4e5b68fe6a61ef7cc4c6e5a6753d17dc31fa0e5fda`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29979433851)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-42fbfb2bc0b6`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-23T04:25:41Z",
          "mergedAt": "2026-07-23T04:28:18Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1307,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1307",
          "title": "fix(verify): isolate mypy from project sync",
          "body": "## Summary\n\n- reuse the existing exact `sourceMypyCommand` selector in release verification\n- run pinned mypy 1.20.2 as an isolated tool instead of `uv run --frozen mypy`, which unnecessarily synchronized and built the full local Kungfu project\n- add a regression that rejects restoring the project-sync invocation\n\n## Evidence\n\n- Product Build Linux run 29973981366 job 89101856248: 66/67 checks passed; installed registry smoke verified 16 contracts; the only failure was mypy exiting after project build/install with no mypy diagnostic\n- same failure previously reproduced in run 29970417379\n- `uvx --from mypy==1.20.2 mypy` — `Success: no issues found in 181 source files`\n- `node --test scripts/source-acceptance.test.mjs` — 20/20 pass\n- full signed commit gate passed, including 92 documentation/promotion tests\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"Repair release verification tool isolation without changing runtime architecture or release claims.\"}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis repair changes verification execution only; it does not publish artifacts.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T02:45:06Z",
          "mergedAt": "2026-07-23T04:42:08Z",
          "additions": 13,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1308,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1308",
          "title": "fix(adr): close migrated publication reachability",
          "body": "## Summary\n\nClose the publication reachability gap found by the full ID-only ADR corpus migration rehearsal.\n\n## Changes\n\n- migrate the ADR implicit-collection contract from UUID-plus-slug paths to canonical ID-only paths\n- require the exact legacy publication pattern to occur once before planning\n- include the documentation contract as an explicit reviewed transformation\n- cover successful rewrite plus missing and duplicate fail-closed paths\n\n## Verification\n\n- ./shifu adr:migrate:test (6/6)\n- ./shifu check:source\n- ./shifu check\n- independent read-only review: PASS\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This repairs deterministic migration closure for the already accepted ID-only ADR identity contract.\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above",
          "author": "dongkeren",
          "createdAt": "2026-07-23T02:45:38Z",
          "mergedAt": "2026-07-23T04:44:56Z",
          "additions": 96,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1309,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1309",
          "title": "feat(cut): add Project Cut loop evidence runner",
          "body": "## Summary\n\nAdd the executable, fail-closed evidence runner for the Project Cut product loop without claiming release qualification or prematurely registering the target Gate.\n\nThe runner binds retained evidence to the exact committed source checkout, the exact Buildchain release-passport bytes, the passport source SHA, and the three platform artifact digests. It emits digest-bound Shifu evidence when invoked by a Gate executor, but does not create or repair campaign evidence.\n\n## Related issue\n\nAtlas goal `2026-07-22-kungfu-project-cut-product-loop`.\n\n## Changes\n\n- add `project-cut-loop:qualify` and its executable runner\n- require a clean tracked checkout and derive the exact Git source commit\n- open and hash the supplied Buildchain release passport\n- require the passport source SHA and Darwin/Linux/Windows artifact digests to match the evidence report\n- emit repository-relative, digest-bound Shifu evidence pointers\n- retain `product.project-cut-loop` as pending until real three-platform measurement and registration evidence exists\n- document the runner and the remaining qualification boundary\n\n## Verification\n\n- `node --test scripts/project-cut-product-loop-release.test.mjs` — 14/14 passed, including an executable temporary-Git runner fixture\n- `./shifu test:work-facade` — 19 Node tests and 20 Python tests passed\n- `./shifu check:source` — build-free source gate passed; 534 source-contract tests (531 passed, 3 platform skips), Agent Work 7 Node + 41 Python, upgrade 76, desktop 69\n- pre-commit staged gate passed after rebasing onto current `dev/v4/v4.0`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f87e8-6b8b-735c-b036-fa42d7cee8cf\"],\n  \"summary\": \"Stage the fail-closed Project Cut product-loop evidence runner while retaining pending Gate registration and an explicit not-qualified boundary.\",\n  \"verification\": [\"Project Cut release runner tests\", \"Work facade contract tests\", \"source acceptance\", \"staged repository gate\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis change verifies retained evidence only. It does not publish artifacts, register the pending Gate, dispatch a campaign, or claim product-loop qualification.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated because the release evidence surface changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T03:56:49Z",
          "mergedAt": "2026-07-23T05:01:45Z",
          "additions": 515,
          "deletions": 15,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1310,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1310",
          "title": "fix: harden UNGFU release evidence admission",
          "body": "## Summary\n\nHarden the pending Kungfu UNGFU™ public-use contract so UNGFU cannot become a technical rename and a future released-software claim cannot pass without source-bound, public evidence for one exact release.\n\n## Related issue\n\nAssignment: 2026-07-23-kungfu-ungfu-trademark-public-use\nFollow-up completion audit for #1304.\n\n## Changes\n\n- freeze the existing repository, CLI, npm/Python package, domain, KFD, Buildchain, and libkungfu identifiers\n- require stable acquisition/product surface ids and one shared release coordinate\n- bind public evidence to the canonical repository and a full source commit\n- reject private/local URLs, future dates, preview/staging hosts, and mismatched surfaces even when mislabeled as release evidence\n- document the exact reviewer and future-release boundary\n\n## Verification\n\n- `./shifu check`\n- `./shifu fix`\n- `node --test scripts/check-trademark-public-use.test.mjs` (6/6)\n- `./shifu check:source` (540 contract tests: 530 passed, 10 platform skips; source gate passed)\n- `./shifu docs final-ready --since origin/dev/v4/v4.0 --budget 66560 --json` (no violations; human review required for three changed docs)\n- pre-commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f8cc4-e796-7b0e-9a16-50c08614e848\"],\n  \"summary\": \"Harden the staged Kungfu UNGFU source-signature contract with protected technical identifiers and source-bound evidence for one exact future release.\",\n  \"verification\": [\"trademark public-use positive and negative fixtures\", \"full build-free source acceptance\", \"documentation final-ready parity and human-review obligations\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR publishes no site, creates no downloadable release, records no first-use date, and makes no registration or legal conclusion.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T04:25:23Z",
          "mergedAt": "2026-07-23T05:13:13Z",
          "additions": 422,
          "deletions": 38,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1311,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1311",
          "title": "perf(ci): narrow SDK core build graph",
          "body": "## Summary\n\nReduce the authoritative merge-queue SDK Core build from the generic full Core graph to an explicit SDK artifact closure. The new path builds only the Node runtime `kungfu_node` target, stages an exact fail-closed native artifact allowlist, and keeps the installed four-language SDK wire qualification unchanged.\n\nBaseline evidence attributed 1,916,403 ms of the 3,304,000 ms partition-0 tail to the generic Core native build, including unrelated Electron, Python, Wasm, native-test, and public-header targets. Candidate timeline events now identify the selected build scope and target so fresh queue evidence can separate graph reduction from cache effects.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- Add a machine-readable SDK Core build plan with exact target, CMake definitions, required artifacts, and excluded work.\n- Add `build:core:sdk` and route merge-queue partition 0 through it.\n- Reuse the pinned Shifu Python and current Ninja executable when reconfiguring persistent CMake trees.\n- Add fail-closed plan, workflow, platform, and artifact-closure regression tests.\n- Refresh the governed workflow authority digest.\n\n## Verification\n\n- `./shifu build:core:sdk`\n- `./shifu pack:sdk`\n- `./shifu layers:qualify:sdk -- --report /tmp/kungfu-sdk-p0-local-qualification.json` (C++, Python, Node, and Rust wire artifacts passing)\n- `./shifu check:gate-catalog`\n- `./shifu check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This CI-only optimization narrows the existing SDK qualification build graph without changing an architecture or public product contract.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-23T04:40:36Z",
          "mergedAt": "2026-07-23T05:50:46Z",
          "additions": 340,
          "deletions": 48,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1562,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1562",
          "title": "feat(release): admit GitHub-only release candidates",
          "body": "## Summary\n\n- allow managed release-candidate admission for an exact caller-bound GitHub Release target\n- audit the Buildchain authority workflow job-scoped GitHub token\n- document the GitHub-Release-only consumer contract\n\n## Validation\n\n- `corepack pnpm run check` (767 tests passed before minimizing formatter-only drift)\n- `node --test tests/publication-authority.test.mjs tests/build-surface.test.mjs` (106 passed)\n- `corepack pnpm run generate:site`\n- `git diff --check`\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T05:24:47Z",
          "mergedAt": "2026-07-23T05:59:58Z",
          "additions": 61,
          "deletions": 20,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1563,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1563",
          "title": "chore(release): promote GitHub-only admission to v2.14 alpha",
          "body": "## Summary\n\nPromote the reviewed GitHub-Release-only publication admission capability through the normal Buildchain v2.14 alpha channel.\n\n## Source\n\n- dev source: `5c341b29814e7721e5516345257d06c85e8e8600`\n- originating PR: #1562\n- downstream consumer: `kungfu-systems/agent-hub-demo` v0.2 binary KFD-1/2/3 Release Passport reference\n\n## Channel boundary\n\nThis publishes the next immutable v2.14 alpha and advances `v2-alpha`. Stable release authority and stable package coordinates remain unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T06:01:00Z",
          "mergedAt": "2026-07-23T06:05:08Z",
          "additions": 61,
          "deletions": 20,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1312,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1312",
          "title": "feat(release): add signed channel index authority",
          "body": "## Summary\n\nAdd a signed, deterministic alpha/stable release-channel authority for standalone Kungfu CLI discovery. The installed client verifies exact source, Buildchain passport, manifest, artifact, platform, architecture, install-source, rollout, and freshness identities without trusting transport or a generic latest-release lookup.\n\n## Related goal\n\nAtlas/Kungfu Assignment `2026-07-23-kungfu-cli-release-channel-index`, child of `2026-07-23-kungfu-standalone-cli-distribution-and-one-command-update`.\n\n## Changes\n\n- add the versioned `kungfu.release-channel-index/v1` schema\n- generate canonical signed indexes deterministically with release-passport and admitted-manifest coordinates\n- verify Ed25519 signatures in the installed Python CLI without an ambient crypto package or executable\n- resolve only bounded HTTPS, explicit local fixtures, or verified still-fresh offline cache entries\n- reject unsigned, noncanonical, stale, cross-channel, unsupported, paused, downgrade, rollback-only, and tampered inputs with stable codes\n- expose exact admitted manifest paths from upgrade publication admission for release assembly\n- register the additive KFD-1 impact and extend ADR-0087\n\n## Verification\n\n- `./shifu test:release-channel`: 9 Node tests and 89 Python runtime-upgrade tests passed\n- `./shifu test:upgrade-qualification`: 19 passed\n- `./shifu docs:check:readonly`: passed\n- `./shifu check:source`: full build-free Source Acceptance passed; 538 contract tests passed with 10 declared skips, 182-file mypy baseline passed, 89 runtime-upgrade tests passed, and 69 desktop adapter tests passed\n- pre-commit staged gate passed\n\nNo production signing key, private endpoint, signed URL, hosted channel, artifact publication, or real release action is included.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0087\"],\n  \"summary\": \"Stage deterministic signed alpha and stable release-channel discovery bound to Buildchain passport, source, manifest, and artifact roots\",\n  \"verification\": [\"release-channel cross-language tests\", \"upgrade publication admission tests\", \"runtime-upgrade tests\", \"source acceptance\", \"documentation contracts\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T04:41:12Z",
          "mergedAt": "2026-07-23T06:13:39Z",
          "additions": 1865,
          "deletions": 5,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1314,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1314",
          "title": "fix(adr): close workflow authority regeneration",
          "body": "## Summary\n\nClose the ADR corpus migration regeneration set over workflow authority digests.\n\n## Changes\n\n- declare workflow authority refresh and gate-catalog verification in migration plans\n- include the generated authority manifest in completion output roots\n- cover the exact command, check, and output contract in migration tests\n\n## Verification\n\n- ./shifu adr:migrate:test\n- ./shifu check:source\n- ./shifu check\n- independent review: PASS\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fail-closed migration tooling closure; no architecture decision or implementation status changes\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-23T05:13:49Z",
          "mergedAt": "2026-07-23T06:16:32Z",
          "additions": 15,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1315,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1315",
          "title": "fix(core): stage Windows ABI import library",
          "body": "## Summary\n\nPlace the Windows `kungfu_abi.lib` import library in `KUNGFU_BUILD_DIR`, which is the native search directory consumed by the Rust trunk embedding build.\n\nThe Product Build evidence on alpha PR #1313 showed `kungfu.dll` linking successfully, followed by `LNK1181` because Cargo searched `framework/core/build` while CMake left the import library in its target-local directory.\n\n## Verification\n\n- layered API encoding boundary tests: 5/5 passed\n- Biome check passed\n- full staged commit hook passed, including 93 documentation/promotion tests\n- final proof is the fresh three-platform Product Build after this repair enters dev\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"intent\":\"bugfix\",\"reason\":\"Windows ABI import-library placement repair only\"}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T05:14:39Z",
          "mergedAt": "2026-07-23T06:19:17Z",
          "additions": 13,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 19,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/19",
          "title": "feat(release): ship standalone KFD reference binaries",
          "body": "## Summary\n\n- publish Node SEA standalone binaries for Linux x64, macOS arm64, and Windows x64\n- expose one machine-readable CLI for version, capabilities, demo, adapter, and self-verification\n- bind product, platform binaries, KFD-1/2/3 evidence, checksums, manifests, and negative qualification into one Buildchain Release Passport flow\n- open the additive `v0.2.0-alpha.0` line while preserving `v0.1.0-alpha.0`\n\n## Buildchain boundary\n\nProduct compilation stays product-owned. Generic release-candidate resolution, publication authority, KFD gates, Passport generation, and GitHub Release publication remain Buildchain-owned through `v2-alpha`. The repository is private to npm and publishes only the exact caller-bound GitHub Release target.\n\n## Validation\n\n- `npm run check`: 9 tests, runtime-100 100/100, standalone macOS binary smoke passed\n- KFD Agent Hub 20-vector report: valid\n- KFD-1 release gate and independent verify: passed\n- KFD-2: bounded first-party claim with explicit residual risk\n- KFD-3: declared CLI plus three-platform distribution; local audit reports only the expected unregistered generated macOS binary warning\n- release qualification: 12/12 deliberate mutations rejected as expected\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`\nMission: `kungfu-technical-stewardship`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T06:02:15Z",
          "mergedAt": "2026-07-23T06:20:00Z",
          "additions": 2216,
          "deletions": 333,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 21,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/21",
          "title": "release: promote v0.2.0-alpha.0 KFD reference binaries",
          "body": "## Summary\n\nPromote the Buildchain-managed `v0.2` development line to alpha with standalone Linux x64, macOS arm64, and Windows x64 binaries.\n\n## Release qualification\n\n- KFD-1 per-platform binary witnesses and mutation checks\n- KFD-2 bounded trust claim and residual-risk passport section\n- KFD-3 one CLI distributed across all three supported platforms\n- Buildchain GitHub-only publication authority and consumer predicate\n- exact `v2-alpha` contract lock at `8d7ead86465c1dae2f6c4fd53ca1453ea979851f`\n\nExpected public tag: `v0.2.0-alpha.0`\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`\nMission: `kungfu-technical-stewardship`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T06:20:38Z",
          "mergedAt": "2026-07-23T06:24:49Z",
          "additions": 2217,
          "deletions": 334,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 23,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/23",
          "title": "fix(release): map Buildchain artifact platform IDs",
          "body": "## Summary\n\n- separate Buildchain transport artifact IDs from product target IDs\n- map the macOS RC artifact `macos` to the product target `macos-arm64`\n- cover the actual RC payload path shape with a regression test\n\n## Verification\n\n- `npm run check`\n- `git diff --check`\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T06:35:12Z",
          "mergedAt": "2026-07-23T06:39:27Z",
          "additions": 50,
          "deletions": 20,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 24,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/24",
          "title": "chore(release): promote v0.2 alpha",
          "body": "Promote the Buildchain-managed v0.2 release candidate after correcting the macOS release-candidate artifact mapping.\n\nThe protected channel workflow remains the sole release authority.\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T06:39:53Z",
          "mergedAt": "2026-07-23T06:43:46Z",
          "additions": 50,
          "deletions": 20,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1317,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1317",
          "title": "fix(core): restore full build test scope",
          "body": "## Summary\n\nMake the generic full Core build explicitly restore `KUNGFU_WITH_CORE_TESTS=ON` for both Node and Electron configurations. This prevents an SDK-scoped CMake cache (`OFF`) from leaking into a later full build in a reused worktree or long-lived runner.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- Pass the full-build test definition explicitly to Node and Electron Core configurations.\n- Add a regression assertion that both full-build configurations restore the test scope.\n\n## Verification\n\n- `./shifu exec node --test framework/core/tests/sdk-core-build.test.js`\n- `./shifu check:types`\n- `./shifu check`\n- staged commit gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix restores the generic full Core build test scope after SDK-specific configuration; it does not change architecture or a public contract.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-23T06:00:35Z",
          "mergedAt": "2026-07-23T06:56:58Z",
          "additions": 11,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1564,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1564",
          "title": "fix(kfd): bind distributed binaries in KFD-3 audits",
          "body": "## Summary\n\n- bind detected binaries to their owning KFD-3 surface through declared `distribution.artifacts`\n- preserve one participant-facing CLI while proving its platform-specific binary distributions\n- expose distribution bindings in audit evidence and document the behavior\n\n## Verification\n\n- `pnpm run check` (768 tests passed)\n- targeted KFD-3 regression proves a detected Windows binary is not reported as an unrelated surface\n\nThis closes the promotion failure observed in `kungfu-systems/agent-hub-demo` run `29985990093` without weakening taxonomy or Passport verification.\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T06:52:11Z",
          "mergedAt": "2026-07-23T06:57:29Z",
          "additions": 126,
          "deletions": 15,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1319,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1319",
          "title": "fix(assignment): keep native admission source coherent",
          "body": "## Summary\n\n- bind CLI-admitted Assignments to the same Kungfu-native source authority as the Initiative created during admission\n- preserve Atlas provenance through the existing content-addressed request and capture receipt roots\n- unblock fresh-workspace Assignment admission and avoid conflicts after Atlas imports\n\n## Validation\n\n- `test_assignment_orchestration.py`: 4 passed\n- `test_initiative_assignment_reads_legacy_sealed_identity_without_rewrite`: passed\n- fresh runtime: real Atlas-captured request admitted, claimed, and kicked off successfully\n- repository staged gate passed\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`\nMission: `kungfu-technical-stewardship`\n\nSupersedes #1316 after correcting the work branch classification from `feature/*` to `fix/*`.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair native Assignment admission source selection without changing the accepted Initiative and Assignment architecture contract.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T06:22:59Z",
          "mergedAt": "2026-07-23T06:59:57Z",
          "additions": 4,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1565,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1565",
          "title": "chore(release): promote KFD-3 distribution binding",
          "body": "Promote the KFD-3 distribution artifact binding needed by the agent-hub-demo Release Passport reference project.\n\nThe protected Buildchain alpha flow remains the sole release authority.\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T06:58:12Z",
          "mergedAt": "2026-07-23T07:01:21Z",
          "additions": 126,
          "deletions": 15,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1320,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1320",
          "title": "feat(release): gate Class 9 filing evidence",
          "body": "## Summary\n\nAdd a fail-closed US Class 9 filing-readiness gate for the future public Kungfu UNGFU alpha. The gate freezes six core identifications, two conditional identifications, and the exact released-product evidence required for each selected item.\n\nThis is an engineering evidence boundary, not a first-use, registrability, ownership, or legal-sufficiency conclusion. Counsel review remains required before filing.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- require released capability evidence for all six core Class 9 identifications\n- admit the interactive and first-party KFX plug-in items only when those downloadable capabilities actually ship\n- reject roadmap, source-only, fixture, preview, staging, and Coming Soon evidence\n- bind each item to the same public acquisition and product release coordinate\n- document the future-alpha filing workflow and specimen boundary\n\n## Verification\n\n- `node scripts/check-trademark-public-use.mjs`\n- `node --test scripts/check-trademark-public-use.test.mjs` (8/8)\n- `./shifu check:source`\n- `./shifu docs:check` (93/93)\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f8cc4-e796-7b0e-9a16-50c08614e848\"],\n  \"summary\": \"Freeze the future public-alpha Class 9 capability evidence contract without claiming legal sufficiency\",\n  \"verification\": [\"trademark public-use contract tests\", \"source gate\", \"documentation gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe exact mark and release evidence are governed by the existing trademark public-use ADR. The new negative fixtures fail closed on speculative or altered claims.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T06:36:44Z",
          "mergedAt": "2026-07-23T07:12:34Z",
          "additions": 533,
          "deletions": 11,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 199,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/199",
          "title": "feat(dogfood): expose verified history projection",
          "body": "## Summary\n- expose the append-only dogfood timeline to trusted kungfu.tech parent surfaces\n- serve archived snapshots on demand after existing SHA-256 and schema verification\n- bind messages to the expected parent window and approved production, staging, or preview origins\n\n## Validation\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- Playwright cross-origin bridge exercise with the downstream agent-builders page\n\n## Boundary\nThis adds a read-only projection bridge. libkungfu.dev remains the sole collector and authority for dogfood observations.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:03:15Z",
          "mergedAt": "2026-07-23T07:13:48Z",
          "additions": 65,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 25,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/25",
          "title": "fix(kfd3): bind declared binary distributions",
          "body": "## Summary\n\n- bind generated standalone binaries to the owning KFD-3 CLI distribution surface\n- qualify exact dist-relative artifact paths\n- accept Buildchain v2.14.17-alpha.5 and its KFD-3 distribution-binding semantics\n\n## Verification\n\n- npm run check\n- exact released Buildchain v2.14.17-alpha.5: kfd 3 audit --cwd . --artifact dist --json (passed)\n\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:10:56Z",
          "mergedAt": "2026-07-23T07:14:51Z",
          "additions": 14,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 26,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/26",
          "title": "chore(release): promote v0.2 development to alpha",
          "body": "Promote the KFD-3 distribution-artifact binding fix and Buildchain v2.14.17-alpha.5 contract lock from the protected development line to alpha.\n\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:15:16Z",
          "mergedAt": "2026-07-23T07:15:44Z",
          "additions": 64,
          "deletions": 26,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 200,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/200",
          "title": "Release production from 1ea62a758efe",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `1ea62a758efeb49831ac31e97cf5ee7d712e2be3`\n- Artifact hash: `09368e1413b789b7e1e23da1323cd7184f0937f7bc9ea7c9221e8a2801c7d6d2`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29987601631)\n- Required label: `buildchain-release`\n- Release branch: `release/production-1ea62a758efe`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-23T07:24:14Z",
          "mergedAt": "2026-07-23T07:26:34Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1323,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1323",
          "title": "fix(release): hydrate ADR promotion boundaries",
          "body": "## Summary\n\nHydrate the exact alpha base and promotion head commits when ADR settlement runs inside Buildchain’s immutable depth-1 PR merge checkout, then retry the fail-closed changed-file computation.\n\nThe fetch accepts only two full 40-character commit OIDs from the trusted pull-request event and keeps the checkout shallow at depth 2.\n\n## Verification\n\n- shallow promotion fixture proves both boundaries are initially absent and exact hydration restores the ADR diff\n- focused ADR release tests: 15/15 passed\n- Biome check passed\n- full staged commit hook passed, including documentation and invariant gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"intent\":\"bugfix\",\"reason\":\"Preserve ADR settlement evidence in immutable shallow Buildchain checkouts\"}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:01:12Z",
          "mergedAt": "2026-07-23T07:26:55Z",
          "additions": 116,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 28,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/28",
          "title": "fix(release): regenerate embedded facts after versioning",
          "body": "## Summary\n\n- regenerate embedded product facts in the npm precheck lifecycle\n- retain the strict pretest stale-cache assertion\n- prove the release transaction version 0.2.0-alpha.1 is embedded before tests and binary build\n\n## Verification\n\n- npm run check\n- isolated simulated Buildchain version bump to 0.2.0-alpha.1 followed by npm run check\n\nFixes the concrete failure in promotion run 29987756350.\n\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:27:07Z",
          "mergedAt": "2026-07-23T07:31:07Z",
          "additions": 11,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 109,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/109",
          "title": "Add clear KFD reader entrypoints for Agent Builders",
          "body": "## Summary\n\nMake KFD understandable and discoverable before Agent Builder readers reach the adoption decision, while preserving `kfd.libkungfu.dev` as the canonical protocol authority.\n\n## Changes\n\n- add a compact “KFD in one sentence” primer before the adoption tradeoff\n- link the primer to the KFD overview and KFD-3 implementation guide\n- make the Builder contract KFD layer clickable\n- separate Chapter 01 reading paths into overview, implementation guidance, and the exact pinned Agent Hub alpha profile\n- add KFD protocol to the shared Developers menu\n- document and test the intended reader progression\n\n## Verification\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `bash -n scripts/check-site.sh`\n- `shellcheck scripts/check-site.sh`\n- `git diff --check`\n- browser validation at 1440px and 390px: expected content order, visible links, and no horizontal overflow\n- confirmed the KFD overview, KFD-3, and KFD-3 usage URLs return HTTP 200\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: this changes public site copy and navigation to the official KFD domain. It does not change KFD protocol content, release facts, infrastructure, DNS, credentials, or production approval semantics. The shared-layout renderer and full site checks pass.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:25:37Z",
          "mergedAt": "2026-07-23T07:34:11Z",
          "additions": 133,
          "deletions": 14,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 29,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/29",
          "title": "chore(release): promote v0.2 release-check fix to alpha",
          "body": "Promote the release-version-aware embedded-facts lifecycle to alpha so Buildchain can resume the 0.2.0-alpha.1 transaction.\n\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:31:42Z",
          "mergedAt": "2026-07-23T07:36:23Z",
          "additions": 11,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1322,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1322",
          "title": "fix(core): resolve canonical ADR records",
          "body": "## Summary\n\nAllow the Core architecture health authority to resolve both canonical UUIDv7 ADR records and grandfathered legacy slug records without accepting nested or prefix-collision paths.\n\n## Changes\n\n- load tracked ADR Markdown paths once and require direct children of docs/adr\n- match canonical identities only by exact filename\n- retain bounded legacy slug resolution for ADR-#### and SHIFU-ADR-####\n- add positive and adversarial self-test cases\n\n## Verification\n\n- ./shifu core:architecture --self-test\n- ./shifu check:source\n- staged commit gate\n- independent review: PASS\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"intent\":\"bugfix\",\"reason\":\"Identity-aware architecture health path resolution; no architecture decision or implementation status change\"}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-23T06:52:28Z",
          "mergedAt": "2026-07-23T07:43:42Z",
          "additions": 34,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 110,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/110",
          "title": "Release production from 47772e1760e8",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `47772e1760e8b259e7d7be4fc38c1d403f19adc2`\n- Artifact hash: `28c4956fb88edd0ebd7e66cad9899b67e7c5ee00e4bd9e005530c3771c15cdaf`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29988776544)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-47772e1760e8`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-23T07:39:20Z",
          "mergedAt": "2026-07-23T07:47:36Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 30,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/30",
          "title": "docs(release): pin public Buildchain verifier",
          "body": "## Summary\n\n- pin the documented public Agent Hub gate to Buildchain 2.14.17-alpha.5\n- pin independent Release Passport verification to the same public contract\n- explain why the prerelease is intentionally exact for KFD-3 binary binding\n\n## Verification\n\n- `git diff --check`\n- `npm run check` (11 tests, runtime-100 100/100, macOS SEA build)\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:41:59Z",
          "mergedAt": "2026-07-23T07:50:04Z",
          "additions": 6,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 111,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/111",
          "title": "chore(buildchain): accept v2.14.16 contract",
          "body": "## Summary\n\n- accept Buildchain stable `v2.14.16` at immutable SHA `4612956c052aed8bb8f1d1b2edfd80c79326f654`\n- record the updated runtime contract and compatibility digests\n- unblock the gated production release for #110 without bypassing contract review\n\nThe breaking digest change is limited to `promote-buildchain-ref-action` release metadata semantics; this site consumes the `web-surface` workflow, whose breaking surface is unchanged. The new binary-distribution controller is additive.\n\n## Verification\n\n- exact `v2` contract lock check: `unchanged`, compatible `true`\n- `pnpm run build`\n- `pnpm run check`\n- `git diff --check`\n\nCloses #93",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:42:46Z",
          "mergedAt": "2026-07-23T07:51:06Z",
          "additions": 10,
          "deletions": 5,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 31,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/31",
          "title": "chore(release): promote v0.2 dev to alpha",
          "body": "Promote the fully verified v0.2 release line to alpha. Includes the exact public Buildchain 2.14.17-alpha.5 reference used for KFD-3 binary distribution binding and independent Release Passport verification.\n\nSource PR: #30\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:50:26Z",
          "mergedAt": "2026-07-23T07:51:37Z",
          "additions": 6,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 32,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/32",
          "title": "fix(release): keep embedded facts stable across versioning",
          "body": "## Summary\n\n- source product version directly from package state so Node source and SEA binaries follow the Buildchain transaction version\n- keep generated KFD and adapter facts independent from mutable version state\n- scope the adapter artifact root to implementation sources instead of `package.json`\n- add a regression test for the version-state boundary\n\n## Verification\n\n- `npm run check` (11 tests, runtime-100 100/100, macOS SEA build)\n- isolated `npm version --no-git-tag-version 0.2.0-alpha.1 && npm run check`\n- after the simulated transaction, only `package.json` and `package-lock.json` changed\n- simulated SEA `version --json` reported `0.2.0-alpha.1`\n\nFixes the exact Promotion diagnosis: `Version verification changed files outside version state: M src/generated-facts.js`.\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:55:30Z",
          "mergedAt": "2026-07-23T07:57:10Z",
          "additions": 26,
          "deletions": 17,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 33,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/33",
          "title": "chore(release): promote version-stable v0.2 to alpha",
          "body": "Promote the version-stable release transaction fix to alpha.\n\nThe source now reads product version directly from package state while generated KFD/adapter facts remain stable. An isolated simulated `0.2.0-alpha.1` transaction passed `npm run check`, changed only `package.json` and `package-lock.json`, and produced a SEA binary reporting `0.2.0-alpha.1`.\n\nSource PR: #32\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:57:32Z",
          "mergedAt": "2026-07-23T07:58:45Z",
          "additions": 26,
          "deletions": 17,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 113,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/113",
          "title": "feat(agent-builders): add dogfood period selector",
          "body": "## Summary\n\n- add an observation-period selector to the Agent Builders dogfood evidence card\n- load verified append-only history through the libkungfu.dev projection bridge\n- provide stable snapshot URLs, previous/next navigation, and adjacent observation comparison\n- preserve the existing latest-evidence fallback when the upstream bridge is unavailable\n\n## Evidence semantics\n\nAdjacent values compare overlapping rolling P30D observation windows. The UI explicitly avoids presenting the delta as new work completed in one week.\n\n## Validation\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `git diff --check`\n- Playwright desktop and mobile checks with the production `libkungfu.dev` bridge\n\nSupersedes #108 and #112, which encountered stale GitHub PR head/mergeability state while current `main` and its production release were being integrated.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:49:34Z",
          "mergedAt": "2026-07-23T08:01:05Z",
          "additions": 281,
          "deletions": 19,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 116,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/116",
          "title": "Release production from a7f647063253",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `a7f647063253ac3af73fbd3ed57c159da321b2ff`\n- Artifact hash: `a7ee760579611f15c9bf1272be9a875f82f988f1a765b267d6787c1094ff2cb4`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29989942683)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-a7f647063253`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-23T08:03:00Z",
          "mergedAt": "2026-07-23T08:08:47Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1321,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1321",
          "title": "feat(product): expose UNGFU identity surfaces",
          "body": "## Summary\n\nProject the exact secondary signature `Kungfu UNGFU™ · Never Guess. Facts Unfold.` from stable CLI and GUI product-controlled surfaces without changing Kungfu's primary identity or making a released-software-use claim.\n\n## Changes\n\n- preserve the existing version as the first line of both native and Python `kungfu --version`, with the secondary signature on the following line\n- add the same exact signature to the packaged Kungfu Episodes About panel while keeping the real application version and primary product name\n- extend product qualification and the trademark public-use contract to reject drift, primary-brand substitution, renamed executables, or premature release evidence\n- serialize Git-sensitive documentation fixtures so source and full documentation gates remain deterministic\n\n## Verification\n\n- `./shifu check:source` (543 contract tests: 533 passed, 10 platform skips; source gate passed)\n- `cargo test --manifest-path crates/Cargo.toml -p kungfu-trunk` (46/46)\n- `pnpm --filter @kungfu-tech/gui run build`\n- `node --test scripts/check-trademark-public-use.test.mjs product/scripts/cli-surface-qualification.test.mjs` (14/14)\n- native and Python `kungfu --version` smoke checks\n- pre-commit staged gates for both commits\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f8cc4-e796-7b0e-9a16-50c08614e848\"],\n  \"summary\": \"Project the staged Kungfu UNGFU secondary source signature from stable CLI and GUI surfaces while preserving primary identity and release-evidence boundaries.\",\n  \"verification\": [\"native and Python version-surface tests\", \"packaged GUI build\", \"trademark product-surface contract fixtures\", \"full build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR publishes no site, creates no downloadable release, records no first-use date, and makes no registration or legal conclusion.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T06:41:08Z",
          "mergedAt": "2026-07-23T08:31:03Z",
          "additions": 377,
          "deletions": 17,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1567,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1567",
          "title": "fix(release): rematerialize Passport inputs on resume",
          "body": "## Summary\n\n- add an explicit `publish-rematerialize-on-resume` workflow/action input\n- replay only the consumer-owned lifecycle or publish command after valid durable evidence is restored\n- reject provider-side `promote-existing-version` replay and revalidate evidence\n- cover fresh-runner Passport input recovery and regenerate public contract assets\n\n## Verification\n\n- `pnpm run check` (769 tests passed)\n\nAgent: Codex\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference\nMission: kungfu-technical-stewardship",
          "author": "dongkeren",
          "createdAt": "2026-07-23T08:24:01Z",
          "mergedAt": "2026-07-23T08:32:11Z",
          "additions": 273,
          "deletions": 118,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1570,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1570",
          "title": "feat(ci): add macOS credential island",
          "body": "## Summary\n\nAdd a sealed macOS credential island to the reusable Buildchain workflow. The ordinary matrix emits a source/tree-bound unsigned app archive; a separate GitHub-hosted job, protected by a caller-owned environment, imports an exact Developer ID identity into a temporary keychain, signs, notarizes, staples, Gatekeeper-assesses, and emits byte-bound evidence.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add the reusable credential-island action and bundled runtime\n- seal the exact macOS app after the credential-free build lifecycle\n- disable signing identity auto-discovery in the ordinary matrix\n- upload signed DMG/ZIP evidence as an additional release-candidate platform\n- extend generated workflow and public contract projections\n\n## Verification\n\n- `pnpm check`\n- 777 unit tests passed\n- 5 action bundles passed integrity verification\n- credential-island contract tests passed\n\n## Governance risk check\n\n- [x] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nCredentials are available only to the protected credential-island job. The ordinary build and promotion verifiers remain credential-free; private command output is redacted and temporary keychain material is removed in main and post cleanup paths.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-23T08:37:11Z",
          "mergedAt": "2026-07-23T08:44:19Z",
          "additions": 2824,
          "deletions": 96,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 250,
          "url": "https://github.com/kungfu-systems/kfd/pull/250",
          "title": "feat(agent-hub): add executable onboarding",
          "body": "## What\n\nTurn the existing Agent Hub schema and Hub 20 machinery into an executable, release-ready onboarding path under the single `kfd` CLI.\n\n- add zero-configuration `kfd demo agent-hub` with rooted report output and bound offline verification\n- add deterministic C++ / Node / Python / Rust starter scaffolds through `kfd scaffold agent-hub`\n- add machine-readable `kfd capabilities agent-hub --json`\n- preserve the existing adapter conformance and offline report verification commands\n- publish KFD-1 capability evidence, profile manifest roots, quickstart, implementer guidance, and package exports\n- prepare `1.0.0-alpha.43` for protected dev-to-alpha promotion\n\n## Claim and evidence\n\nApplicability: executable onboarding for the fixed Agent Hub 20 profile and packaged local reference adapters. The CLI remains transport-neutral and invokes adapters as subprocesses.\n\nEvidence: `npm run check` passes the Agent Hub protocol and conformance profiles, all four scaffold smoke tests, 11 adversarial mutations, path-safety checks, clean npm-pack validation, Agent Runtime 100, Rust verifier tests, and native/WASM parity fixtures.\n\nNon-claims: scaffolds are teaching starters, not production interoperability, qualification, certification, or proof of Hub 20 support. Their default behavior fails closed for unimplemented scenarios. C++ and Rust JSON handling is fixture-scoped and explicitly requires replacement by adopters. Agent Hub verification remains host-only because it requires process execution; no Agent Hub rule is claimed in the Rust/WASM verifier. A future verifier move requires a versioned bundle kind and full byte-for-byte native/WASM parity.\n\nCounterevidence/falsifiers: any scaffold that reports Hub 20 without implementing all scenarios, any package containing generated build/cache directories, any verifier acceptance of tampered or mismatched rooted reports, any undocumented verifier-backend claim, or any drift between the capability surface and executable CLI invalidates this claim.\n\nInterests: implementation authored for kungfu-systems KFD; no additional material interests known.\n\n## Compatibility and registry agreement\n\n- [x] `node scripts/check.mjs` / `npm run check` passes\n- [x] applicability, compatibility, migration, supersession impact, and recovery are explicit\n- [x] published coordinates remain immutable\n- [x] no Foundation decision text is rewritten\n- [x] substantive review must be performed by someone other than the author\n\n## Version impact (per KFD-1)\n\n- [x] patch/content-operation release on the v1.0 alpha line (`1.0.0-alpha.43`)\n\n## Out of scope\n\nThis change does not modify `kungfu-systems/agent-hub-demo` or Buildchain. Release promotion continues through the protected `dev/v1/v1.0 -> alpha/v1/v1.0` path.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T08:41:29Z",
          "mergedAt": "2026-07-23T08:48:17Z",
          "additions": 1108,
          "deletions": 125,
          "changedFiles": 58
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1571,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1571",
          "title": "chore(release): reconcile v2.14 alpha version state",
          "body": "Supersedes #1569 after GitHub failed to attach the native PR check to its refreshed head.\n\n## Summary\n\nMerge the current `v2.14.17-alpha.5` generated version state back into dev while preserving the new Passport-input rematerialization contract from #1567. This makes the protected dev-to-alpha promotion conflict-free.\n\n## Verification\n\n- regenerated managed site/contract assets\n- `pnpm run check` (769 tests passed)\n- exact head `d4ef9bf935ba6d94ee0e543078ea5de972c1a3fa` passed Verify run 29991761018\n\nAgent: Codex\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference\nMission: kungfu-technical-stewardship",
          "author": "dongkeren",
          "createdAt": "2026-07-23T08:40:41Z",
          "mergedAt": "2026-07-23T08:52:11Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 251,
          "url": "https://github.com/kungfu-systems/kfd/pull/251",
          "title": "release: promote KFD 1.0.0-alpha.43",
          "body": "## What\n\nPromote the protected KFD development channel to alpha through the required same-repository provenance path:\n\n`dev/v1/v1.0 -> alpha/v1/v1.0`\n\nThe promoted development head is `3f82e768403e6429b4b6961611cf8b8176cf44ec`, containing Agent Hub executable onboarding PR #250 at reviewed source head `bbf80ea6b23af354d0206a279a0a8aaf45331ff9`.\n\n## Release material\n\n- package: `@kungfu-tech/kfd@1.0.0-alpha.43`\n- zero-configuration Agent Hub demo\n- C++ / Node / Python / Rust fail-closed starter scaffolds\n- machine-readable capability boundary\n- host-only bound report verification and public quickstart\n\n## Evidence and boundaries\n\nPR #250 received independent approval and passed Verify plus Build. The onboarding remains non-qualifying and non-certifying; starter smoke tests do not claim Hub 20 semantics or production interoperability. No Agent Hub rule is claimed in the Rust/WASM verifier.\n\n## Release contract\n\n- [x] exact protected channel head/base pair\n- [x] immutable package coordinate prepared\n- [x] alpha tag only; `latest` remains bootstrap\n- [x] same-repository PR lineage for Buildchain\n- [x] substantive review separated from author",
          "author": "dongkeren",
          "createdAt": "2026-07-23T08:49:04Z",
          "mergedAt": "2026-07-23T08:53:40Z",
          "additions": 2520,
          "deletions": 224,
          "changedFiles": 92
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1568,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1568",
          "title": "release: promote Buildchain v2.14 alpha",
          "body": "Promote the durable Passport-input rematerialization recovery fix to the Buildchain v2.14 alpha channel.\n\n- source: dev/v2/v2.14 at a73bb67d454882b7c3fba8ce03751d370d1c1ab6\n- validation: PR #1567 check and merge-queue check passed\n- expected release: v2.14.17-alpha.6\n\nAgent: Codex\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference\nMission: kungfu-technical-stewardship",
          "author": "dongkeren",
          "createdAt": "2026-07-23T08:33:01Z",
          "mergedAt": "2026-07-23T08:55:12Z",
          "additions": 3068,
          "deletions": 185,
          "changedFiles": 41
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1324,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1324",
          "title": "feat(cli): orchestrate one-command updates",
          "body": "## Summary\n\nMake bare `kungfu update` the complete service-free update workflow. It discovers the selected signed channel, explains current and target versions plus activation impact, asks at most once, executes only the install source's bounded adapter, verifies the installed result, and writes a durable receipt.\n\n## Related goal\n\nAtlas/Kungfu Assignment `2026-07-23-kungfu-cli-one-command-update-orchestrator`, child of `2026-07-23-kungfu-standalone-cli-distribution-and-one-command-update`.\n\n## Changes\n\n- add the no-argument update orchestrator with `--check`, `--yes`, `--channel`, `--offline`, and stable JSON behavior\n- bind update plans to the full signed selection, manifest, release passport, artifact, source, current/target version, and exact adapter identity\n- execute package-manager adapters as exact argv with `shell=False`, an allowlisted environment, bounded timeouts, and target-version verification\n- retain archive side-by-side apply and expose explicit manager-required, desktop-required, unsupported-source, downgrade-refused, cancellation, failure, and recovery states\n- persist append-only success, cancellation, and failure receipts without retaining manager output or ambient secrets\n- preserve all lower-level update commands and regenerate the CLI surface catalog and Buildchain KFD projections\n\n## Verification\n\n- `UV_OFFLINE=1 ./shifu check:source`: full latest-state Source Acceptance passed after merging current `dev/v4/v4.0`\n- source contracts: 543 total, 533 passed, 10 declared skips, 0 failed\n- runtime-upgrade: 99 passed\n- desktop update adapters: 69 passed\n- agent-work state: 41 passed\n- Python type baseline: 182 source files, 0 issues\n- `./shifu kfd:buildchain:check`: passed\n- `./shifu check:cli-catalog-parity`: passed with the qualified native binding\n- pre-commit staged gate: passed\n\nNo production publication, manager-owned package-file overwrite, live-service dependency, background updater, implicit process kill, or runtime migration is included.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0087\"],\n  \"summary\": \"Stage the service-free one-command update orchestration surface over ADR-0087 signed release and runtime-upgrade authorities\",\n  \"verification\": [\"runtime-upgrade tests\", \"desktop update adapter tests\", \"CLI catalog parity\", \"Buildchain KFD evidence\", \"source acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:16:41Z",
          "mergedAt": "2026-07-23T08:55:51Z",
          "additions": 1148,
          "deletions": 32,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 34,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/34",
          "title": "docs(release): record version transaction boundary",
          "body": "## Summary\n\n- document `package.json`/lockfile as the only product version state\n- explain why generated KFD/adapter facts exclude mutable version state\n- record the fail-closed recovery path for version verification drift\n\n## Verification\n\n- `git diff --check`\n- `npm run check:embedded`\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T08:05:25Z",
          "mergedAt": "2026-07-23T09:03:54Z",
          "additions": 16,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1572,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1572",
          "title": "feat(build): expose matrix fail-fast policy",
          "body": "## Summary\n\n- expose a backward-compatible `fail-fast` boolean on the advanced build workflow\n- apply the policy consistently to native, container, and artifact relay matrices\n- preserve all-platform diagnostics by default and document promotion usage\n- regenerate the public channel workflow and contract/site registries\n\n## Verification\n\n- `pnpm run check` (769 tests passed; workflow, site, and action bundle checks passed)\n\n## Safety\n\nThis changes scheduling only. It does not remove any declared platform, convert cancellation into success, or alter credentials, artifacts, release admission, or publication policy.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T08:40:46Z",
          "mergedAt": "2026-07-23T09:08:23Z",
          "additions": 141,
          "deletions": 44,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1328,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1328",
          "title": "fix(core): preserve legacy ADR resolver fixture",
          "body": "## Summary\n\nKeep the Core architecture legacy ADR resolver fixture outside corpus migration references while preserving its runtime coverage.\n\n## Verification\n\n- ./shifu core:architecture --self-test\n- ./shifu adr:migrate:test\n- staged commit gate\n- independent review: PASS\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"intent\":\"bugfix\",\"reason\":\"Test-fixture isolation for the ADR identity migration; no architecture decision change\"}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:59:27Z",
          "mergedAt": "2026-07-23T09:09:12Z",
          "additions": 5,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1573,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1573",
          "title": "test(release): lock rematerialization workflow surface",
          "body": "## Summary\n\nAdd end-to-end public-surface assertions for `publish-rematerialize-on-resume` across the reusable promotion workflow, action metadata, implementation, and operator docs.\n\nThis also provides a fresh governed dev→alpha promotion source after GitHub run 29993083121 completed its job but remained stuck in `in_progress` and could not be canceled through either standard or force-cancel APIs.\n\n## Verification\n\n- targeted Build Surface tests: 2/2 passed\n- previous merged composition: `pnpm run check` (778/778 passed)\n\nAgent: Codex\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference\nMission: kungfu-technical-stewardship",
          "author": "dongkeren",
          "createdAt": "2026-07-23T09:05:55Z",
          "mergedAt": "2026-07-23T09:10:38Z",
          "additions": 8,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1574,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1574",
          "title": "release: promote rematerialization surface test",
          "body": "Promote the public-surface recovery assertion and produce a fresh governed alpha push after GitHub run 29993083121 completed its only job but remained stuck in `in_progress` and returned HTTP 500 from both cancel endpoints.\n\n- dev source: `442c8f148375eeccb1307a6e1be3b22f91041ca4`\n- current alpha: `17063f104ec6ef8e900f667d4a2641ad0ed4f218`\n- expected next alpha: `v2.14.17-alpha.6` unless the stuck run recovers first, in which case semver sequencing will select the next immutable prerelease\n\nAgent: Codex\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference\nMission: kungfu-technical-stewardship",
          "author": "dongkeren",
          "createdAt": "2026-07-23T09:12:02Z",
          "mergedAt": "2026-07-23T09:13:30Z",
          "additions": 149,
          "deletions": 44,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1327,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1327",
          "title": "fix(release): close alpha qualification gaps",
          "body": "## Summary\n\nClose the deterministic alpha qualification gaps proven by PR #1325:\n\n- invoke installed Windows `.cmd` launchers through explicit `ComSpec` / `cmd.exe /d /s /c call`\n- hydrate the exact pinned ADR legacy cutover commit when a locked Buildchain checkout is depth-1\n- force electron-builder macOS signing only for same-repository alpha/release pull requests, after validating the event payload head and base repositories\n- pin external KFD Runtime 100 conformance to published `v1.0.0-alpha.42` (`03deef6bbc6e2ac8aecfedc76f17f6c74a72b878`), aligned with vector root `sha256:1e996b8c43b0b3e38630ccd58acf8a714cbc24b339d3794318347faab9057e5f`\n\n## Verification\n\n- focused product, GUI launcher, metadata, and CLI qualification tests: 55/55 passed\n- synthetic depth-1 remote fixture proves exact legacy cutover hydration\n- same-repository/fork/dev macOS signing admission fixtures\n- KFD Agent Runtime boundary and exact workflow pin passed\n- workflow authority manifest refreshed and gate catalog passed\n- Biome check passed\n- full staged commit hook passed for all three commits\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"intent\":\"bugfix\",\"reason\":\"Restore deterministic Windows CLI, shallow ADR, signed macOS, and KFD Runtime 100 alpha qualification\"}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T07:57:44Z",
          "mergedAt": "2026-07-23T09:26:00Z",
          "additions": 268,
          "deletions": 23,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 35,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/35",
          "title": "fix(release): rematerialize Passport inputs on resume",
          "body": "## Summary\n- accept Buildchain v2.14.17-alpha.6 contract lock\n- rematerialize ephemeral KFD/Passport inputs when resuming durable publication evidence\n- cover the caller-level recovery contract\n\n## Verification\n- npm run check\n- exact v2-alpha contract-lock check: unchanged, compatible=true\n\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference",
          "author": "dongkeren",
          "createdAt": "2026-07-23T09:23:51Z",
          "mergedAt": "2026-07-23T09:34:40Z",
          "additions": 19,
          "deletions": 19,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 36,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/36",
          "title": "release: promote v0.2 development to alpha",
          "body": "Promote the reviewed Passport recovery and exact Buildchain v2.14.17-alpha.6 contract lock into the v0.2 alpha channel.\n\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference",
          "author": "dongkeren",
          "createdAt": "2026-07-23T09:34:53Z",
          "mergedAt": "2026-07-23T09:38:55Z",
          "additions": 35,
          "deletions": 19,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 37,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/37",
          "title": "fix(release): pin promotion workflow to released runtime",
          "body": "## Summary\n- invoke the immutable Buildchain v2.14.17-alpha.6 promotion workflow\n- align the accepted alpha contract-lock ref and offline verification commands\n- preserve rematerialization-on-resume behavior\n\n## Why\nGitHub reusable-workflow validation cached the moving v2-alpha signature and rejected the newly added input at startup. The immutable released workflow exposes the input and binds the same accepted SHA/digests.\n\n## Verification\n- actionlint\n- npm run check\n\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference",
          "author": "dongkeren",
          "createdAt": "2026-07-23T09:42:43Z",
          "mergedAt": "2026-07-23T09:44:03Z",
          "additions": 5,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 38,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/38",
          "title": "release: bind v0.2 alpha to Buildchain v2.14.17-alpha.6",
          "body": "Promote the immutable Buildchain release binding required for Passport transaction recovery.\n\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference",
          "author": "dongkeren",
          "createdAt": "2026-07-23T09:44:19Z",
          "mergedAt": "2026-07-23T09:45:28Z",
          "additions": 5,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1575,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1575",
          "title": "fix(release): isolate alpha resume input from stable shell",
          "body": "## Summary\n- mark publish-rematerialize-on-resume unsupported by the immutable stable promotion shell\n- keep forwarding it through the alpha shell\n- regenerate the public channel promotion workflow and contract world\n\n## Why\nGitHub validates both nested reusable-workflow calls before selecting the channel. Forwarding the new alpha-only input to the older stable shell caused external callers to fail at workflow startup.\n\n## Verification\n- node --test tests/promotion-channel-router.test.mjs tests/build-surface.test.mjs (96/96)\n- pnpm run check (778/778; action bundles intact)\n\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference",
          "author": "dongkeren",
          "createdAt": "2026-07-23T09:50:14Z",
          "mergedAt": "2026-07-23T09:55:13Z",
          "additions": 9,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1576,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1576",
          "title": "release: promote alpha rematerialization wrapper fix",
          "body": "## Summary\n- promote the stable-routing compatibility fix for the alpha rematerialization input\n- keep `publish-rematerialize-on-resume` on the alpha shell while excluding it from the immutable stable shell\n- release the corrected reusable workflow surface for consumer recovery\n\n## Validation\n- `pnpm run check` (778/778)\n- promotion channel router targeted tests (96/96)\n\nAgent: Codex\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference\nMission: kungfu-technical-stewardship",
          "author": "dongkeren",
          "createdAt": "2026-07-23T09:55:43Z",
          "mergedAt": "2026-07-23T09:59:01Z",
          "additions": 9,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1329,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1329",
          "title": "feat(ci): require notarized macOS alpha artifacts",
          "body": "## Summary\n\nWire Kungfu alpha/release candidates to the immutable Buildchain macOS credential island. Functional builds remain credential-free; the exact unsigned macOS app is sealed, signed and notarized in a separate protected GitHub-hosted job, then admitted as a fourth release-candidate payload.\n\n## Related issue\n\nBuildchain PR kungfu-systems/buildchain#1570\n\n## Changes\n\n- pin the credential-island Buildchain train runtime\n- seal `product/dist/desktop/mac-arm64/Kungfu Episodes.app` after the functional matrix\n- replace the credential-bearing native campaign with credential-free functional qualification\n- require the signed DMG/ZIP/evidence payload during promotion\n- verify exact source, byte inventory, bundle/team/certificate identity, notarization, staple, and Gatekeeper evidence\n- refresh closed-world workflow authority and Gate bindings\n\n## Verification\n\n- `./shifu check`\n- `./shifu release:promotion:rehearse`\n- 10 credential-island publication admission tests\n- Gate catalog and closed-world workflow authority checks\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This implements the existing Buildchain credential-isolation boundary and does not alter a Kungfu product architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [x] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe workflow receives no credential values in the functional matrix. The protected `alpha-macos-signing` environment is consumed only by the isolated signing job; promotion reads byte-bound public evidence and no signing secret.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-23T08:44:01Z",
          "mergedAt": "2026-07-23T10:01:36Z",
          "additions": 593,
          "deletions": 26,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 39,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/39",
          "title": "fix(release): pin recovered promotion to alpha.7",
          "body": "## Summary\n- pin the consumer promotion wrapper to Buildchain `v2.14.17-alpha.7`\n- accept the exact released runtime SHA and contract digest\n- keep recovery rematerialization enabled for the existing `v0.2.0-alpha.1` transaction\n\n## Validation\n- `npm run check`\n- `actionlint .github/workflows/*.yml`\n- `npx --yes --package @kungfu-tech/buildchain@2.14.17-alpha.7 buildchain kfd hub test --for agent`\n\nAgent: Codex\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference\nMission: kungfu-technical-stewardship",
          "author": "dongkeren",
          "createdAt": "2026-07-23T10:08:48Z",
          "mergedAt": "2026-07-23T10:12:57Z",
          "additions": 8,
          "deletions": 8,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 40,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/40",
          "title": "release: resume Buildchain-managed v0.2 alpha",
          "body": "## Summary\n- promote the Buildchain alpha.7 recovery wrapper to the v0.2 alpha channel\n- resume the immutable `v0.2.0-alpha.1` transaction with rematerialized binary and Passport inputs\n- publish the cross-platform KFD-1/2/3 reference release through Buildchain\n\n## Validation\n- PR #39 checks passed on Linux x64, macOS arm64, Windows x64, and the consumer check lifecycle\n\nAgent: Codex\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference\nMission: kungfu-technical-stewardship",
          "author": "dongkeren",
          "createdAt": "2026-07-23T10:13:15Z",
          "mergedAt": "2026-07-23T10:17:02Z",
          "additions": 8,
          "deletions": 8,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1332,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1332",
          "title": "feat(cli): harden archive self-update recovery",
          "body": "## Summary\n\nHarden standalone archive self-update with immutable side-by-side frontend images, rooted receipts, retry-safe staging, generation-fenced atomic selection, rollback coordinates, and read-only inventory fsck.\n\n## Verification\n\n- check:source\n- test:runtime-upgrade (105 passed)\n- test:cli-surface-qualification (24 passed)\n- mypy (183 source files)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0087\"],\n  \"summary\": \"Complete the bounded standalone archive self-update and recovery stage\",\n  \"verification\": [\"source acceptance\", \"runtime upgrade tests\", \"packaged archive and launcher qualification\"]\n}\n-->\n\n## Governance risk check\n\nRelease evidence and product upgrade surfaces are changed; qualification is named above.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T09:45:02Z",
          "mergedAt": "2026-07-23T10:25:48Z",
          "additions": 503,
          "deletions": 18,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 41,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/41",
          "title": "fix(release): version KFD adapter declaration atomically",
          "body": "## Summary\n- declare `.buildchain/kfd/agent-hub.json#adapter.version` as Buildchain-owned version state\n- advance the package version and KFD adapter declaration in the same generated version commit\n- preserve the exact adapter/package binding during the existing alpha.2 transaction recovery\n\n## Validation\n- `buildchain validate --require-version-state --require-lifecycle-stages install,build,verify,publish`\n- `npm run check`\n- simulated Buildchain version-state update proves both keys become `0.2.0-alpha.2`\n\nAgent: Codex\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference\nMission: kungfu-technical-stewardship",
          "author": "dongkeren",
          "createdAt": "2026-07-23T10:22:45Z",
          "mergedAt": "2026-07-23T10:26:30Z",
          "additions": 13,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1333,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1333",
          "title": "fix(adr): close architecture projection regeneration",
          "body": "## Summary\nDeclare Core architecture projections as a closed ADR migration regeneration and require source acceptance before completion.\n\n## Verification\n- ./shifu adr:migrate:test\n- ./shifu core:architecture:write\n- ./shifu check:source\n- git diff --check\n- independent review: PASS\n\n## ADR delivery / release declaration\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"intent\":\"bugfix\",\"reason\":\"Migration completion closure for generated Core architecture projections; no architecture decision change\"}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T09:49:26Z",
          "mergedAt": "2026-07-23T10:29:04Z",
          "additions": 23,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 42,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/42",
          "title": "release: recover atomic KFD adapter version state",
          "body": "## Summary\n- promote atomic package/KFD adapter version state to the v0.2 alpha channel\n- recover the existing Buildchain-managed `v0.2.0-alpha.2` publication transaction\n- retain the exact alpha.7 Buildchain authority and Release Passport inputs\n\n## Validation\n- PR #41 checks passed on Linux x64, macOS arm64, Windows x64, and consumer check lifecycle\n- exact Buildchain config validation recognizes both version-state keys\n\nAgent: Codex\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference\nMission: kungfu-technical-stewardship",
          "author": "dongkeren",
          "createdAt": "2026-07-23T10:26:48Z",
          "mergedAt": "2026-07-23T10:30:31Z",
          "additions": 13,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1334,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1334",
          "title": "fix(release): qualify installed CLI and Git history",
          "body": "## Summary\n- invoke installed `kungfu.cmd` through the canonical explicit `cmd.exe /d /s /c call` adapter during CLI surface qualification\n- hydrate the complete exact source history on the Linux release-qualification leg before ADR reachability auditing\n\n## Evidence\n- `node --test product/scripts/dist.test.mjs product/scripts/cli-surface-qualification.test.mjs scripts/run-release-qualification.test.mjs scripts/prepare-gate-measurement-history.test.mjs` (45 passed)\n- full managed pre-commit hook passed\n\n## Failure provenance\nRepairs deterministic Windows CLI spawn and Linux shallow-history failures observed in alpha promotion PR #1330.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"intent\":\"bugfix\",\"reason\":\"Restore deterministic Windows installed CLI and complete-history ADR alpha qualification\"}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T10:19:12Z",
          "mergedAt": "2026-07-23T10:31:53Z",
          "additions": 97,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 43,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/43",
          "title": "fix(release): pair platform Passport witnesses",
          "body": "## Summary\n- bind KFD-1 witnesses to the exact files copied into the public release asset set\n- pair each platform KFD-3 prebuild witness with its corresponding artifact witness\n- add a hermetic publication-evidence regression test\n\n## Validation\n- `npm run check`\n- `actionlint .github/workflows/buildchain-ref-promotion.yml`\n- `git diff --check`\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "kungfu-origin",
          "createdAt": "2026-07-23T10:43:12Z",
          "mergedAt": "2026-07-23T10:52:57Z",
          "additions": 198,
          "deletions": 17,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 44,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/44",
          "title": "Promote Passport witness pairing to alpha/v0/v0.2",
          "body": "Promote the verified platform KFD witness pairing fix so Buildchain can resume and finalize the existing immutable `v0.2.0-alpha.2` release transaction.\n\nSource PR: #43\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T10:53:08Z",
          "mergedAt": "2026-07-23T10:54:21Z",
          "additions": 198,
          "deletions": 17,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 45,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/45",
          "title": "fix(release): scope public manifest witness to Linux",
          "body": "## Summary\n- prove the single public product manifest once in the Linux KFD-1 contract world\n- keep macOS and Windows KFD-1 worlds scoped to their exact shipped binaries\n- preserve independent platform witness pairing from #43\n\n## Evidence\nPromotion run `30001115717` proved all KFD-3 comparisons and all binary surfaces; only the duplicated platform manifest surfaces failed.\n\n## Validation\n- `npm test` (13/13)\n- `git diff --check`\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "kungfu-origin",
          "createdAt": "2026-07-23T11:01:25Z",
          "mergedAt": "2026-07-23T11:02:57Z",
          "additions": 16,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 46,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/46",
          "title": "Promote narrowed manifest world to alpha/v0/v0.2",
          "body": "Promote the KFD-1 manifest boundary correction so Buildchain can create the next immutable alpha transaction after `v0.2.0-alpha.3` failed closed.\n\nSource PR: #45\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T11:03:22Z",
          "mergedAt": "2026-07-23T11:04:57Z",
          "additions": 16,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1335,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1335",
          "title": "ci: fail fast alpha promotion preflight",
          "body": "## Summary\n\n- add an exact-source three-platform Alpha preflight and fail-closed reusable receipt\n- move Windows cmd, ADR history, macOS codesign, and locked Cargo fetch failures ahead of expensive product matrices\n- cancel stale promotion runs and enable fail-fast required lanes while retaining explicit diagnostic mode\n- pin Buildchain PR #1572 for reusable workflow fail-fast propagation\n- replace #1331 with linear topic history required by the protected rebase merge queue\n\n## Qualification\n\n- ./shifu check:source\n- ./shifu gate run governance.promotion-rehearsal\n- ./shifu test:alpha-promotion-preflight\n- staged commit gate\n\n## Safety boundary\n\nThe reusable receipt binds the exact source commit/tree plus workflow, gate, toolchain, and policy roots. Signing, notarization, credentials, and publication evidence remain fresh and are explicitly excluded from reuse.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0073\"],\n  \"summary\": \"Add an exact-source fail-fast preflight stage to the Buildchain promotion settlement boundary\",\n  \"verification\": [\"source acceptance\", \"promotion rehearsal\", \"exact-tree receipt drift tests\"]\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T10:51:26Z",
          "mergedAt": "2026-07-23T11:11:26Z",
          "additions": 1399,
          "deletions": 45,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 47,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/47",
          "title": "fix: scope promotion KFD-1 to immutable artifacts",
          "body": "## Summary\n- clear release-candidate workspace source coordinates when rematerializing publish-time KFD-1 witnesses\n- retain exact public artifact byte surfaces as the promotion proof boundary\n- regress the transformed witness contract for all three platforms\n\n## Verification\n- `npm test`\n- `npm run check`\n- `git diff --check`\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T11:13:49Z",
          "mergedAt": "2026-07-23T11:17:35Z",
          "additions": 4,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 48,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/48",
          "title": "promote: dev/v0/v0.2 to alpha",
          "body": "Promote the KFD-1 publish-boundary correction through the protected alpha line.\n\nSource fix: #47\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T11:17:45Z",
          "mergedAt": "2026-07-23T11:22:00Z",
          "additions": 4,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 9,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/9",
          "title": "feat(tap): prepare Kungfu CLI Formula",
          "body": "## Summary\n\n- prepare a release-passport-gated standalone Kungfu CLI Formula without creating an installable Formula before official CLI artifacts exist\n- enforce exact Homebrew update and verification argv, deterministic KFD/checksum projection, and Formula/Cask type disambiguation\n- refresh the existing Buildchain Formula to v2.14.16 and accept the reviewed current v2/v2-alpha consumer contract locks\n\n## Checks\n\n- [x] node scripts/update-managed-products.mjs --check --update-lock\n- [x] node --test scripts/update-managed-products.test.mjs\n- [x] node scripts/check-tap.mjs\n- [x] buildchain validate --require-lifecycle-stages verify\n- [x] buildchain lifecycle run verify --required\n- [x] git diff --check\n\n## Governance\n\n- [x] This change does not include credentials, tokens, secrets, or private logs.\n- [x] This change does not misrepresent provider APIs, billing, quota, or usage attribution.\n- [x] This change does not create or change an official hosted service.\n- [x] Package names, release identity, and domains are intentional.\n- [x] Release evidence, provenance, package publishing, or deployment surfaces are documented when touched.\n\nKungfu remains under plannedEntries: no Formula/kungfu.rb, tag, release, signing, notarization, or installability claim is created. Buildchain v2.14.16 uses its exact upstream buildchain.release.json and published archive checksums.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T11:11:17Z",
          "mergedAt": "2026-07-23T11:26:55Z",
          "additions": 795,
          "deletions": 90,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1577,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1577",
          "title": "fix(release-passport): persist text evidence only",
          "body": "## Summary\n- persist only text-based Release Passport evidence to the durable release-state branch\n- keep standalone binaries in the local Passport directory for byte-identical GitHub Release upload\n- cover extensionless and `.exe` binary exclusion while retaining checksums and JSON\n- regenerate the promote action bundle\n\n## Verification\n- `node --test tests/promote-buildchain-ref.test.mjs` (125/125)\n- `pnpm run check` (779/779; action bundle integrity passed)\n- `git diff --check`\n\nConsumer failure: agent-hub-demo promotion run 30002889938 returned GitHub blob input-too-large while persisting binary assets.\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T11:28:34Z",
          "mergedAt": "2026-07-23T11:33:35Z",
          "additions": 37,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1578,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1578",
          "title": "promote: dev/v2/v2.14 to alpha",
          "body": "Promote the Release Passport durable text-evidence correction through the v2.14 alpha channel.\n\nSource fix: #1577\nConsumer validation target: `kungfu-systems/agent-hub-demo`\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T11:34:01Z",
          "mergedAt": "2026-07-23T11:37:12Z",
          "additions": 37,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1338,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1338",
          "title": "feat(cli): add trusted Homebrew update adapter",
          "body": "## Summary\n\nAdd the trusted Homebrew package-manager adapter for the standalone CLI, keep install-source ownership in the colocated product manifest, and retain stable receipts for failed or cancelled upgrades.\n\n## Verification\n\n- check:source (549 contract tests: 539 passed, 10 skipped, 0 failed)\n- test:runtime-upgrade (114 passed)\n- test:cli-surface-qualification (25 passed)\n- mypy (183 source files)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0087\"],\n  \"summary\": \"Complete the bounded Homebrew-owned standalone CLI update adapter stage\",\n  \"verification\": [\"source acceptance\", \"runtime upgrade tests\", \"packaged launcher qualification\", \"exact package-manager argv and stable failure receipts\"]\n}\n-->\n\n## Governance risk check\n\nNo Formula, release, signing, notarization, or Cellar-write claim is opened. The adapter accepts only one local exact argv contract and verifies the selected target version.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T11:10:19Z",
          "mergedAt": "2026-07-23T11:40:06Z",
          "additions": 379,
          "deletions": 34,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1339,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1339",
          "title": "fix(adr): close CLI catalog regeneration",
          "body": "## Summary\nDeclare the generated CLI surface catalog as a closed ADR migration regeneration before final source acceptance.\n\n## Verification\n- ./shifu adr:migrate:test\n- ./shifu fix:cli-catalog-parity\n- ./shifu check:cli-catalog-parity\n- ./shifu check:source\n- git diff --check\n- independent review: PASS\n\n## ADR delivery / release declaration\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"intent\":\"bugfix\",\"reason\":\"Migration completion closure for the generated CLI surface catalog; no architecture decision change\"}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T11:18:47Z",
          "mergedAt": "2026-07-23T11:42:57Z",
          "additions": 13,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 49,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/49",
          "title": "fix(release): pin Passport promotion to alpha.8",
          "body": "## Summary\n\n- pin the managed promotion workflow to Buildchain v2.14.17-alpha.8\n- accept the exact alpha.8 runtime contract while preserving the compatible v2 surface digest\n- update public verification examples and the recovery regression\n\n## Why\n\nBuildchain alpha.8 keeps binary Passport assets in the public Release payload while persisting only reviewable text evidence in Git-backed release state. This removes the Git blob-size failure observed after KFD-1/2/3 passed for v0.2.0-alpha.5.\n\n## Verification\n\n- `npm test` (13/13)\n- `npm run check` (tests, Runtime 100, macOS arm64 binary build)\n- `git diff --check`\n\nAgent: Codex\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference\nMission: kungfu-technical-stewardship",
          "author": "dongkeren",
          "createdAt": "2026-07-23T11:47:15Z",
          "mergedAt": "2026-07-23T11:51:14Z",
          "additions": 8,
          "deletions": 8,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 50,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/50",
          "title": "chore(release): promote v0.2 development to alpha",
          "body": "## Summary\n\nPromote the v0.2 development branch to alpha with the Buildchain v2.14.17-alpha.8 Passport artifact policy.\n\nThe prior v0.2.0-alpha.5 transaction proved KFD-1, KFD-2, and KFD-3 before failing only on oversized Git-backed binary state. Alpha.8 persists text evidence while retaining binaries for the public GitHub Release.\n\nAgent: Codex\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference\nMission: kungfu-technical-stewardship",
          "author": "dongkeren",
          "createdAt": "2026-07-23T11:51:32Z",
          "mergedAt": "2026-07-23T11:55:33Z",
          "additions": 8,
          "deletions": 8,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1340,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1340",
          "title": "fix(ci): run alpha preflight contracts directly on Windows",
          "body": "The live exact-source Alpha preflight run 30002186983 proved the new fail-fast boundary but exposed a Windows bootstrap defect: the early source-only contract step entered through `./shifu`, so Git Bash tar interpreted the Windows drive prefix as a remote host.\n\nThis follow-up runs the two dependency-free source contract suites through the workflow-pinned `actions/setup-node` runtime, keeps the Shifu entry exception explicit and machine-audited, refreshes workflow authority, and adds a regression assertion that prevents the Windows-specific bootstrap path from returning.\n\nVerification:\n- staged repository gate passed\n- Alpha/CLI contract tests: 8/8\n- Gate catalog contract tests: 23/23\n- documentation/rehearsal tests: 96/96\n- actionlint passed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0073\"],\n  \"summary\": \"Route the exact-source Alpha preflight test through setup-node on Windows\",\n  \"verification\": [\"source acceptance\", \"workflow authority\", \"live Windows fail-fast evidence\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T11:21:55Z",
          "mergedAt": "2026-07-23T11:59:03Z",
          "additions": 24,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1579,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1579",
          "title": "feat(control-plane): publish Buildchain project cut",
          "body": "Publishes the Buildchain Project Cut used by the organization-wide installed Kungfu Assignment dogfood campaign and refreshes generated bundle digests. Full Buildchain checks passed.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T12:11:47Z",
          "mergedAt": "2026-07-23T12:17:40Z",
          "additions": 30,
          "deletions": 0,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 51,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/51",
          "title": "fix(release): bind candidate binary version",
          "body": "## Summary\n\n- predeclare the exact governed alpha.7 transaction version before cross-platform binary builds\n- deny publication capabilities whose version differs from the candidate source\n- document the division of authority: candidate declaration plus independent Buildchain recomputation/tag ownership\n\n## Validation\n\n- `npm test` (14/14)\n- `npm run runtime100` (100/100)\n- `npm run check`\n- macOS SEA binary reports `0.2.0-alpha.7` and passes `self-verify`\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T12:16:05Z",
          "mergedAt": "2026-07-23T12:20:20Z",
          "additions": 124,
          "deletions": 50,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 52,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/52",
          "title": "release: promote v0.2 dev to alpha",
          "body": "Promote the reviewed v0.2 development line to alpha after PR #51 bound cross-platform binaries to the exact governed candidate version.\n\nValidation: PR #51 CI run 30006314066 passed all Linux, macOS, Windows, trust, and controller checks.\n\nGoal: `2026-07-23-agent-hub-binary-kfd123-passport-reference`",
          "author": "dongkeren",
          "createdAt": "2026-07-23T12:20:35Z",
          "mergedAt": "2026-07-23T12:24:27Z",
          "additions": 124,
          "deletions": 50,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1342,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1342",
          "title": "fix(ci): keep hosted Cargo preflight on public registry",
          "body": "Live Alpha preflight run 30005181986 proved the Windows early-source repair, then failed at 2m05s because the GitHub-hosted runner inherited an office-only Cargo mirror at `192.168.100.222:8082`.\n\nThis follow-up makes automatic hosted preflight use the public Cargo registry. A mirror remains available only as an explicit `workflow_dispatch` input for a diagnostic run, so private infrastructure cannot leak into automatic public-runner qualification.\n\nVerification:\n- staged repository gate passed\n- Alpha/CLI contract tests: 9/9\n- Gate catalog contract tests: 23/23\n- documentation/rehearsal tests: 96/96\n- actionlint passed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0073\"],\n  \"summary\": \"Keep automatic hosted Alpha preflight on a publicly reachable Cargo registry\",\n  \"verification\": [\"source acceptance\", \"workflow authority\", \"live private-mirror fail-fast evidence\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T12:04:38Z",
          "mergedAt": "2026-07-23T12:27:03Z",
          "additions": 21,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1345,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1345",
          "title": "fix(adr): preserve declared regeneration outputs",
          "body": "## Summary\nTreat every declared ADR migration regeneration output as generated from the same manifest authority, so completion validates the real regenerated artifact instead of a naive text-rewrite root.\n\nReturn isolated regeneration declarations for each plan so consumer mutation cannot weaken later manifests.\n\n## Verification\n- ./shifu adr:migrate:test (7/7)\n- ./shifu check:source (549 tests: 539 pass, 10 skip; 41 Python; 114 runtime-upgrade; 69 desktop-update)\n- pnpm exec biome check scripts/adr-migration.mjs scripts/adr-migration.test.mjs\n- git diff --check\n- independent review: PASS\n\n## ADR delivery / release declaration\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"intent\":\"bugfix\",\"reason\":\"Fail-closed lifecycle correction for already-declared ADR migration regeneration outputs; no architecture decision change\"}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T12:19:49Z",
          "mergedAt": "2026-07-23T12:33:19Z",
          "additions": 145,
          "deletions": 56,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1344,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1344",
          "title": "feat(assignment): qualify organization-wide installed dogfood",
          "body": "## Summary\n\nQualifies the installed Kungfu Assignment control plane across KFD and Buildchain, fixes installed packaging, capture, portable-seal, and root-preservation gaps, and records bounded organization-wide dogfood evidence.\n\n## Changes\n\n- make installed Profile dependency resolution and Assignment ingress work outside the source checkout\n- preserve and verify portable Assignment settlement roots across workspace boundaries\n- record the KFD, Home, and Buildchain dogfood matrix and its fail-closed cases\n- keep stable release and untested platforms as explicit non-claims\n\n## Verification\n\n- `./shifu check:source`\n- staged repository gate and affected Assignment tests\n- installed `/Applications/Kungfu Episodes.app` and `/usr/local/bin/kungfu` parity checks\n- KFD, Home, and Buildchain Assignment completion, review, decision, closeout, seal, and offline verification\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f87cc-bd1f-786d-896d-07ea9245861e\"],\n  \"summary\": \"Qualify the installed portable Assignment control plane for organization-wide dogfood across KFD, Home, and Buildchain.\",\n  \"verification\": [\"./shifu check:source\", \"installed organization-wide Assignment dogfood matrix\"]\n}\n-->\n\n## Governance risk check\n\n- No stable or general-release claim is made.\n- No untested platform is qualified.\n- The delivery remains bounded to the accepted portable Assignment orchestration ADR and retained qualification evidence.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T12:15:34Z",
          "mergedAt": "2026-07-23T13:08:44Z",
          "additions": 1986,
          "deletions": 71,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1346,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1346",
          "title": "feat(upgrade): require one-command release qualification",
          "body": "## Summary\n\nBind every future advertised standalone update tuple to a fresh clean previous-public-to-exact-candidate `kungfu update` campaign, and carry its roots through Kungfu publication admission into Buildchain release-passport evidence. Keep all current platform and Homebrew public claims closed until real native artifacts and campaigns exist.\n\n## Related issue\n\nAtlas goal `2026-07-23-kungfu-cli-update-qualification-and-docs`.\n\n## Changes\n\n- require exact source, platform, channel, install-owner, manifest, artifact, channel-index, release-passport, receipt, smoke, activation, fault-recovery, and documentation evidence\n- reject missing, stale, simulated, mismatched, incomplete, duplicate, or overclaimed campaign evidence\n- require native qualification to retain the matching campaign set and bind admitted roots into Buildchain custom publish evidence\n- align CLI help, upgrade documentation, release gate documentation, and release notes with the current no-public-channel truth\n\n## Verification\n\n- `./shifu test:upgrade-qualification` (42 passed)\n- `./shifu test:release-channel` (14 JavaScript + 114 Python passed)\n- focused release/manifest qualification tests (34 passed)\n- `./shifu docs:check` (96 passed; 357 Markdown files linted, 356 link/contract files checked)\n- `./shifu check:source` (568 tests: 558 passed, 10 declared skipped; Agent Work 41, runtime upgrade 114, desktop update 69; mypy 183 files)\n- staged pre-commit gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0087\"],\n  \"summary\": \"Complete the bounded one-command update qualification and Buildchain evidence-binding stage\",\n  \"verification\": [\"source acceptance\", \"upgrade qualification fixtures\", \"release-channel tests\", \"Buildchain publication admission\", \"documentation gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes only fail-closed evidence admission and documentation. It does not publish, sign, notarize, install, or advertise any release artifact or package-manager channel.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-23T12:23:16Z",
          "mergedAt": "2026-07-23T13:25:43Z",
          "additions": 1040,
          "deletions": 30,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1347,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1347",
          "title": "fix(ci): forward alpha preflight command arguments",
          "body": "Live Alpha preflight run 30007028822 proved public Cargo fetch on Linux and macOS, then failed at 1m14s while writing the first platform receipt. The workflow passed an extra `--` through the Shifu task, so the receipt script parsed the wrong command.\n\nThis follow-up removes the redundant separator from `write-platform`, `aggregate`, and `verify`, adds a source regression contract for all three calls, and locally executes the exact Shifu `write-platform` route to a qualifying receipt.\n\nVerification:\n- exact Shifu write-platform route produced a passed linux-x64 receipt\n- staged repository gate passed\n- Alpha/CLI contract tests: 10/10\n- Gate catalog contract tests: 23/23\n- documentation/rehearsal tests: 96/96\n- actionlint passed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0073\"],\n  \"summary\": \"Forward exact Alpha preflight receipt commands through Shifu\",\n  \"verification\": [\"source acceptance\", \"workflow authority\", \"live receipt-write fail-fast evidence\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T12:32:39Z",
          "mergedAt": "2026-07-23T13:42:22Z",
          "additions": 25,
          "deletions": 8,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 252,
          "url": "https://github.com/kungfu-systems/kfd/pull/252",
          "title": "feat(site): publish Agent Hub onboarding page",
          "body": "## Summary\n\n- generate a first-class `/agent-hub` route and renderer-ready `agentHubPage` from the packaged Agent Hub profile, implementer guide, capabilities, and manifest\n- expose demo, adopter testing, offline verification, four scaffold languages, JSONL binding, exit codes, rooted evidence, recovery, and claim boundaries\n- add deterministic drift gates, discovery mapping, release-impact evidence, and anchor `1.0.0-alpha.44`\n\n## Validation\n\n- `npm run check`\n- deterministic site-bundle regeneration\n- `npm pack` into a clean consumer\n- installed bundle route/page assertions\n- packaged reference demo: Hub 20 passed 20/20\n- offline report verification passed\n\n## Compatibility and claims\n\nThis is an additive schemaVersion 2 site-bundle surface. Existing routes and page fields remain unchanged. Agent Hub remains experimental, non-qualifying, and non-certifying. Scaffold availability does not claim four-language runtime parity, and Agent Hub report verification/process spawning remain host-only.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T13:47:50Z",
          "mergedAt": "2026-07-23T13:49:41Z",
          "additions": 480,
          "deletions": 93,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 253,
          "url": "https://github.com/kungfu-systems/kfd/pull/253",
          "title": "chore(kfd): promote alpha 44",
          "body": "## Release\n\nPromote `dev/v1/v1.0` to `alpha/v1/v1.0` for immutable `@kungfu-tech/kfd@1.0.0-alpha.44` publication.\n\n## Included surface\n\n- first-class `/agent-hub` site-bundle route\n- renderer-ready Agent Hub onboarding page generated from packaged sources\n- deterministic drift and claim-boundary gates\n- additive site-bundle release-impact record\n\n## Evidence\n\n- feature PR #252 approved and merged\n- repository check passed locally and in protected CI\n- deterministic site generation passed\n- clean npm tarball consumer read the new route/page\n- packaged reference demo passed Hub 20 (20/20)\n- offline report verification passed\n\nThe profile remains experimental, non-qualifying, and non-certifying. Four scaffold languages do not imply runtime parity; Agent Hub report verification and process spawning remain host-only. npm `latest` remains the bootstrap package; `alpha` advances.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T13:49:57Z",
          "mergedAt": "2026-07-23T13:51:37Z",
          "additions": 480,
          "deletions": 93,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1349,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1349",
          "title": "fix(cli): refresh catalog surface root authority",
          "body": "## Summary\n- refresh the CLI registry expected surface root before catalog projection\n- keep regeneration build-free and fail closed on ambiguous registry literals\n- declare both CLI registry and catalog as generated ADR migration outputs\n\n## Validation\n- env -u KUNGFU_NATIVE_PATH ./shifu test:cli-surface-contract (19 passed, 10 skipped)\n- KUNGFU_NATIVE_PATH=... ./shifu test:cli-surface-contract (29 passed)\n- ./shifu adr:migrate:test (7 passed)\n- ./shifu check:source (passed)\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"Repair generated CLI catalog authority without changing an ADR record\"}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T13:14:42Z",
          "mergedAt": "2026-07-23T14:06:52Z",
          "additions": 89,
          "deletions": 2,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 254,
          "url": "https://github.com/kungfu-systems/kfd/pull/254",
          "title": "fix(ci): allow reusable build artifact reads",
          "body": "## Fix\n\nGrant the KFD reusable Build caller `actions: read`, matching the permission now required by the current Buildchain `v2-alpha` workflow.\n\n## Evidence\n\n- PR #252 Build run: startup failure before any job was created\n- promotion PR #253 Build run: startup failure before any job was created\n- both runs resolved Buildchain `v2-alpha` to `2bbe3023638eb6d8e12c2037fe3babefa80c0a6f`\n- that reusable workflow declares `actions: read`; KFD uses an explicit permissions map, so the omitted permission was `none`\n- KFD Verify remained green, isolating the failure to reusable Build workflow admission\n\nThis one-line caller fix does not grant write access, change package bytes, modify Buildchain, or widen the Agent Hub claim boundary.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T14:02:46Z",
          "mergedAt": "2026-07-23T14:12:25Z",
          "additions": 12,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 256,
          "url": "https://github.com/kungfu-systems/kfd/pull/256",
          "title": "chore(release): reconcile alpha promotion ancestry",
          "body": "## Summary\n\n- bind both the current protected `dev/v1/v1.0` merge ancestry and the prior `alpha/v1/v1.0` promotion ancestry\n- preserve the exact reviewed alpha.44 product tree while making the governed dev-to-alpha release source satisfy strict freshness\n- keep the release source itself as `dev/v1/v1.0`, as required by KFD release governance\n\n## Invariant\n\nHead `83dffef3cad2d3a482d5a0c805e45fa60ba0efb3` and protected dev resolve to the same tree `48e8b2a0ccda6da2faf267a33c85d78155c7e260`; this PR changes ancestry only.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T14:16:20Z",
          "mergedAt": "2026-07-23T14:22:10Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 255,
          "url": "https://github.com/kungfu-systems/kfd/pull/255",
          "title": "chore(kfd): complete alpha 44 promotion",
          "body": "## Summary\n\n- promote the first-class Agent Hub site-bundle page and `/agent-hub` route\n- include the minimum reusable-build `actions: read` permission required by Buildchain v2-alpha\n- carry refreshed rooted KFD-1/KFD-2/KFD-3 evidence into the immutable alpha.44 candidate\n\n## Validation\n\n- `npm run update:evidence && npm run check`\n- protected PR #254 Verify and Buildchain Build passed on exact head `e7bb50df61a33fe21233a4ffd323369898a0dcfb`\n\n## Boundary\n\nThis promotion remains alpha/non-certifying and keeps verifier execution host-only.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T14:13:35Z",
          "mergedAt": "2026-07-23T14:28:44Z",
          "additions": 12,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1351,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1351",
          "title": "fix(ci): write alpha preflight receipts with setup-node",
          "body": "## Summary\n\n- write dependency-free Alpha platform receipts with the workflow-pinned Node runtime\n- avoid entering the Windows Shifu/fnm bootstrap after Cargo preflight succeeds\n- preserve Shifu authority for aggregate and verify while testing the explicit exception\n\n## Live evidence\n\nRun https://github.com/kungfu-systems/kungfu/actions/runs/30012390934 reached public Cargo fetch on all three platforms and produced the Linux receipt, then Windows failed in Shifu's fnm bootstrap because Git Bash tar interpreted the `C:` path as a remote. This patch moves only the dependency-free receipt writer before that bootstrap boundary.\n\n## Verification\n\n- `node scripts/check-shifu-entry-contract.mjs`\n- `node scripts/check-kungfu-gate-catalog.test.mjs`\n- `node --test scripts/alpha-promotion-preflight.test.mjs product/scripts/cli-surface-qualification.test.mjs`\n- `actionlint .github/workflows/alpha-promotion-preflight.yml`\n- direct `write-platform` receipt generation\n- full staged commit gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0073\"],\n  \"summary\": \"Write Alpha platform receipts with workflow-pinned Node before Windows Shifu bootstrap\",\n  \"verification\": [\"source acceptance\", \"workflow authority\", \"live Windows receipt fail-fast evidence\"]\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T13:48:56Z",
          "mergedAt": "2026-07-23T14:32:06Z",
          "additions": 15,
          "deletions": 6,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 257,
          "url": "https://github.com/kungfu-systems/kfd/pull/257",
          "title": "docs(kfd): incubate federated work continuity",
          "body": "## Summary\n\n- preserve Work as an unnumbered, incubating KFD Candidate\n- add an experimental formal comparison of entity, derived-view, Initiative, and no-new-Primitive outcomes\n- add a provisional KFD-5 live case, immutable cut, site projection, and regenerated KFD witnesses\n\n## Claim boundary\n\nThis PR does not allocate a KFD number, qualify Work, claim completed federation dogfood, or prefer an independent entity over Initiative or a derived view.\n\n## Verification\n\n- `npm run update:evidence`\n- `npm run check`\n- `npm pack --dry-run --json`\n- JSON parse and immutable cut SHA-256 check\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-23T14:30:57Z",
          "mergedAt": "2026-07-23T14:35:18Z",
          "additions": 1561,
          "deletions": 86,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 258,
          "url": "https://github.com/kungfu-systems/kfd/pull/258",
          "title": "chore(release): reconcile alpha 44 publication ancestry",
          "body": "## Summary\n\n- merge published alpha.44 ancestry back into the current protected dev history\n- preserve all concurrently merged PR #257 work\n- make Buildchain post-publish reconciliation idempotent without moving dev backward or changing the dev product tree\n\n## Invariant\n\nHead `16d246f0dac9e244a17eac60bebda0100372bdb7` and current dev resolve to the identical tree `fe1512c3fc1876c04d217058187cb0cdf2432021`; this PR changes ancestry only.\n\n## Publication state\n\n`@kungfu-tech/kfd@1.0.0-alpha.44` is already immutable on npm with integrity `sha512-CXoN4ui3tvjRSyDwwwa96swJiiJ1B4eXZ2/R2AzJmin6hAJt8Qa/5R1lWKnSPk3YVnMhU9W8Fc1Fr+Ql7Nlvpw==`. This PR enables an idempotent workflow rerun to finish tag and GitHub prerelease creation.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T14:39:58Z",
          "mergedAt": "2026-07-23T14:43:55Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 259,
          "url": "https://github.com/kungfu-systems/kfd/pull/259",
          "title": "chore(kfd): anchor federated work alpha 46",
          "body": "## Summary\n\n- advance the immutable KFD prerelease coordinate to `1.0.0-alpha.46`\n- skip alpha.45 because recovery of alpha.44 minted that exact Git tag without an npm package or GitHub Release\n- regenerate KFD-1/2/3 witnesses against the alpha.46 package coordinate\n- retain the incubating Federated Work Continuity candidate and provisional KFD-5 live case merged in #257\n\n## Verification\n\n- `npm run update:evidence`\n- `npm run check`\n- `npm pack --dry-run --json`\n- required candidate/formal/live-case/cut/site files present in the alpha.46 tarball\n- `git diff --check`\n\n## Boundary\n\nThis release does not allocate a KFD number or qualify Work. The alpha.45 tag anomaly is preserved and reported at kungfu-systems/buildchain#1580 rather than deleted or retargeted.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-23T14:48:33Z",
          "mergedAt": "2026-07-23T14:53:40Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 260,
          "url": "https://github.com/kungfu-systems/kfd/pull/260",
          "title": "release(kfd): promote federated work alpha 46",
          "body": "## Release\n\nPromote reviewed `dev/v1/v1.0` to `alpha/v1/v1.0` for immutable `@kungfu-tech/kfd@1.0.0-alpha.46` publication.\n\n## Included surface\n\n- unnumbered incubating Federated Work Continuity KFD Candidate\n- experimental entity/derived-view/Initiative/no-new-Primitive formal comparison\n- provisional KFD-5 live case and immutable Work cut\n- candidate, formal, live-case, cut, and route projection in the npm/site bundle\n- protected alpha.44 ancestry reconciliation and version-derived KFD witnesses\n\n## Evidence\n\n- candidate PR #257 approved and merged\n- alpha.44 recovery and ancestry PR #258 completed without product-tree drift\n- alpha.46 anchor PR #259 approved and merged\n- local full KFD checks and clean npm pack passed\n\n## Boundary\n\nWork remains incubating and provisional. This release allocates no KFD number, claims no completed federation dogfood, and preserves Initiative, derived-view, Portfolio/query, and no-new-Primitive alternatives. Alpha.45 is intentionally skipped because its exact Git tag was minted during alpha.44 recovery without a corresponding npm package or GitHub Release; the defect is tracked at kungfu-systems/buildchain#1580.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T14:54:12Z",
          "mergedAt": "2026-07-23T14:58:00Z",
          "additions": 1588,
          "deletions": 113,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1355,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1355",
          "title": "feat(cut): generalize work lifecycle authority",
          "body": "## Summary\n\nGeneralize Project Cut into a domain-neutral Core Cut authority and publish one Work lifecycle contract through the existing native action waist for C++, Python, Node.js, and Rust. This successor also proves the generated bindings through exact installed wheel, npm, crate, and C++ artifacts, and makes native receipt admission preserve the boundary between routing and domain authority execution.\n\nThis PR supersedes #1354. It is rebuilt from the exact current shared dev base after the earlier merge-group source replay conflicted with changes landed ahead of it; no previous branch history was rewritten.\n\n## Changes\n\n- define domain-neutral Core Cut build, verify, import, export, settlement, recovery, and archive semantics\n- retain software Project Cut as an explicit profile and one-way migration adapter\n- publish one generated Work lifecycle operation set across C++, Python, Node.js, and Rust\n- require delegated mutation receipts to bind the requested operation and declared authority\n- return structured missing-authority and authority-mismatch denials without claiming domain execution\n- prove seven lifecycle cases byte-for-byte through exact installed artifacts in all four languages\n- retain a non-software Course Production profile fixture without Core changes\n\n## Exact roots\n\n- shared base: `1e5f0c34fc01002fbdeaeebe6cbe9831b0861eee`\n- observed head: `b7ee1bdf69670fb8a57647697b65bed3d379ee2b`\n- Project Cut: `sha256:fb24bd879e11a5fd01ed4827324b246b58e620c04de57a5b6d29b8a9ba6866ee`\n- Project Cut receipt: `sha256:323d5f0ab1ece38a3ac67e6e5a063e683a4556ed5d41fb64153c41577994eaa4`\n- source projection: `sha256:f2207ad954d9717a8dbf530becf2bdf08ab57eb59e1dc072a94e2c74a4da9276`\n- Xinfa Atlas: `sha256:aa199e7179b28695107c1fc7626e4d0d6517a67542376757a6ed3d5bec3e64ec`\n- Episode delta: explicit empty (`nativeRoots: []`)\n\n## Verification\n\n- `./shifu check:source` (569 tests; 566 passed, 3 platform-specific skipped, 0 failed)\n- Project Cut scoped composition gate: passing, no diagnostics\n- `./shifu sdk:work-lifecycle:check` (8/8)\n- `./shifu check:work-lifecycle-operation-matrix` (6/6)\n- `./shifu build:core:sdk`\n- `./shifu pack:sdk`\n- `./shifu layers:qualify:sdk -- --report /tmp/kungfu-work-lifecycle-sdk-clean14.json` (C++/Python/Node/Rust exact artifacts passing)\n- commit hooks: DCO, docs/contracts, Biome, ruff/mypy, clang-format, cargo fmt/clippy/tests\n- local affected-native execute could not enter compilation because the Mac system Ninja is 1.10.2 while the gate requires 1.11.1; the protected Linux affected-native jobs remain the authority for that lane\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f8c53-6105-71e5-8f34-53f2a81ee61c\"],\n  \"summary\": \"Stage a domain-neutral Core Cut authority and exact four-language Work lifecycle projections without widening business authority.\",\n  \"verification\": [\"full Shifu source gate\", \"Core SDK exact-artifact qualification\", \"four-language Work lifecycle byte parity\", \"Project Cut exact-root closeout\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release-evidence change is limited to content-addressed Project Cut witnesses and ADR staging; no package publication or deployment is performed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T14:44:16Z",
          "mergedAt": "2026-07-23T15:27:53Z",
          "additions": 3446,
          "deletions": 440,
          "changedFiles": 59
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1358,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1358",
          "title": "fix(cli): infer installed Action layout",
          "body": "## Summary\n\n- infer installed Action layout from the packaged binding/action directory relationship\n- preserve the explicit KUNGFU_INSTALL_SOURCE compatibility path\n- cover packaged archives without relying on ambient install metadata\n\n## Failure evidence\n\nThe macOS Alpha build smoke in run 30016491923 packaged a valid embedded Action entry, but `kungfu action contract --json` reported `layout: source`. Product archive validation therefore failed before entering the credential island.\n\n## Verification\n\n- `./shifu test:action-kernel`\n- `./shifu check:source`\n- staged pre-commit gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This restores installed Action host provenance for packaged CLI archives without changing product or architecture contracts.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T15:02:06Z",
          "mergedAt": "2026-07-23T15:49:54Z",
          "additions": 26,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1359,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1359",
          "title": "fix(adr): close invariant migration regeneration",
          "body": "<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"Close generated invariant-root regeneration and preserve KFD decision identity across the corpus rename\"}\n-->\n\n## Summary\n- declare invariant registry root synchronization in ADR migration plans\n- verify the generated invariant registry before source completion\n- bind KFD-7 preauthorization to the exact deterministic legacy-to-UUID migration mapping\n- reject arbitrary ADR renames and decision path/identity drift\n\n## Verification\n- ./shifu adr:migrate:test\n- ./shifu node --test scripts/check-kfd7-library-boundary.test.mjs\n- ./shifu node --test scripts/kungfu-invariant.test.mjs\n- ./shifu invariant:verify -- --sync-roots --json\n- ./shifu check:source",
          "author": "dongkeren",
          "createdAt": "2026-07-23T15:16:56Z",
          "mergedAt": "2026-07-23T15:52:49Z",
          "additions": 203,
          "deletions": 17,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1364,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1364",
          "title": "feat(workspace): federate Assignment graphs",
          "body": "## Summary\n\n- add portable workspace identity, machine-local locator Catalog, and path-free WorkRefs\n- add zero-write federated Assignment graph queries and relation handshakes across Home and project workspaces\n- expose CLI, GUI, Profile, and generated agent/buildchain surfaces with a public ADR and real-repository qualification\n- require independent Decision plus Project Cut and settlement receipt before global completion\n\n## Validation\n\n- 72 targeted Python tests passed\n- Dashboard workspace test suite: 28 passed\n- generated Agent command catalog: 173 commands\n- generated KFD surface catalog: 148 surfaces\n- Ruff, Biome, docs evidence, generated-artifact, and affected checks passed\n- real clean-snapshot qualification against kungfu-trader/action-approve and kungfu-trader/qlib passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f8e99-9354-7ab6-a9ba-b166f83f25a3\"],\n  \"summary\": \"Complete the bounded workspace federation and Assignment graph delivery stage\",\n  \"verification\": [\"targeted Python, Dashboard, generated surface, source acceptance, and real-repository qualification checks\"]\n}\n-->\n\n## Known baseline\n\nThe broader Atlas storage suite has two pre-existing contract-drift assertions unrelated to this change; the touched source and tests do not introduce them.\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T16:02:01Z",
          "mergedAt": "2026-07-23T16:31:59Z",
          "additions": 4935,
          "deletions": 386,
          "changedFiles": 55
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1363,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1363",
          "title": "feat(governance): add incubation passports",
          "body": "## Summary\n\nAdd a versioned incubation passport contract that decides runtime versus Git anchors, destined authority, schema ownership, persistent-byte authority, Root conformance, and runtime deadlines at object birth.\n\nThe exact baseline keeps seven pre-existing issues visible without allowing new debt. This change registers current Work, Atlas, Rewind, and Mission Control incubation objects without moving schemas, rewriting journals, recalculating Roots, or changing sealed evidence.\n\n## Related issue\n\nKungfu Assignment `2026-07-23-kungfu-incubation-passport-governance`.\n\n## Changes\n\n- add accepted ADR `KF-ADR-019f8fb8-579b-78d5-9ebb-da03bb9aa40c`\n- add the v1 contract, JSON schemas, registry, and exact expiring baseline\n- add a baseline-aware checker plus positive and negative fixtures\n- scan all tracked FlatBuffers declarations and derivatives for owner registration\n- require two independent implementation languages plus golden vectors for Root protocols\n- fail overdue runtime incubation and wire the checker into source acceptance\n- document the future byte-preserving `work_events.fbs` owner move\n\n## Verification\n\n- `node scripts/check-incubation-passport.mjs --today 2026-07-23 --json`\n- `node --test scripts/check-incubation-passport.test.mjs`\n- `node scripts/source-acceptance.mjs`\n- `node scripts/adr-audit.mjs`\n- `node scripts/run-docs-source-check.mjs`\n- `./shifu build:core`\n- pre-commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f8fb8-579b-78d5-9ebb-da03bb9aa40c\"],\n  \"summary\": \"Stage birth-time incubation governance with exact owner, persistence, Root conformance, deadline, and no-rewrite boundaries.\",\n  \"verification\": [\"source acceptance\", \"incubation passport golden and negative fixtures\", \"ADR audit\", \"Core build\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-23T16:01:51Z",
          "mergedAt": "2026-07-23T16:48:38Z",
          "additions": 1365,
          "deletions": 0,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1366,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1366",
          "title": "fix(adr): close contract policy migration regeneration",
          "body": "<!-- kungfu-adr-release:v1\\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"Close canonical contract-policy regeneration and preserve KFD decision-status fixture semantics across ADR identity cutover\"}\\n-->\\n\\n## Summary\\n\\n- regenerate the canonical KFD contract policy before KFD evidence and close both source/artifact bytes\\n- allowlist the exact policy verification command in ADR migration completion\\n- keep the KFD decision-status negative fixture valid before and after identity cutover\\n\\n## Verification\\n\\n- [source-acceptance] revision=fdf23fb8126817761dcd6e96cdad4ee94fc0b93c base=origin/dev/v4/v4.0@e4e9b2a70b54bda7973abfa16132b03a00d4fc7e\n[source-acceptance] changed files: 4\n\n[source-acceptance] diff hygiene\n[source-acceptance] $ git diff --check\n\n[source-acceptance] no Bash scripts\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/no-bash-guard.mjs\n\n[source-acceptance] Shifu entry contract\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-shifu-entry-contract.mjs\n[shifu-entry] participant-facing commands use Shifu\n\n[source-acceptance] Shifu cache contract\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-shifu-cache-contract.mjs\n[shifu-cache] contract=docs/shifu/cache-contract.json valid=3 rejected=2\n\n[source-acceptance] Shifu Documentation Protocol\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-shifu-documentation-contract.mjs\n[shifu-docs] contract=docs/shifu/documentation-contract.json providers=7 routes=2 surfaces=401 rejected=6 schema=passed\n\n[source-acceptance] documentation material lane\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/run-documentation-material-tests.mjs\ndocumentation KFD-1 witness current\n[freeze] restored witnessed Documentation Atlas material from tracked gzip: atlas.json\n✔ installed reader verifies and reads the exact offline Xinfa pack (1066.705333ms)\n✔ tampered product bytes fail closed before any read (210.009ms)\n✔ freeze assembly stages the selected verified Atlas into the product (0.397375ms)\n✔ freeze materializes Mission Control dependency links (5.386459ms)\n✔ freeze restores an ignored product Atlas body from a tracked gzip bundle without Git (15.316875ms)\n✔ final documentation matrix binds product and multi-consumer roots (1866.836667ms)\n✔ a second compiler or selector authority fails qualification (0.143834ms)\n✔ an unbounded compatibility alias fails qualification (0.078458ms)\nℹ tests 8\nℹ suites 0\nℹ pass 8\nℹ fail 0\nℹ cancelled 0\nℹ skipped 0\nℹ todo 0\nℹ duration_ms 1922.751875\n\n[source-acceptance] Shifu Gate contract\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-shifu-gate-contract.mjs\n[shifu-gate] contract=docs/shifu/gate-contract.json valid=1 rejected=5 schema=passed\n\n[source-acceptance] Kungfu Gate catalog\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-kungfu-gate-catalog.mjs\n[kungfu-gates] 38 gates, 6 profiles, 25 structured invocations and 18 closed-world workflows aligned\n\n[source-acceptance] Xinfa standalone boundary\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node crates/xinfa/tooling/check-boundary.mjs\n[xinfa-boundary] linked component boundary passed\n\n[source-acceptance] carrier/action envelope\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-carrier-action-envelope.mjs\n[carrier-action] envelope gate passed\n\n[source-acceptance] runtime greenfield\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-runtime-greenfield.mjs\n[runtime-greenfield] gate passed\n\n[source-acceptance] trademark public-use gate\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-trademark-public-use.mjs\n[trademark-public-use] contract=framework/release/kungfu-trademark-public-use.contract.json state=pre-release class9-core=6 valid=true\n\n[source-acceptance] schema authority\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-schema-authority.mjs\n[schema-authority] single-owner, JSON-edge, and projection-route gates passed\n\n[source-acceptance] core architecture contract\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node framework/core/architecture/check-layers.mjs\nOK: 316 first-party C/C++ files have one component owner; public contracts, the layer map and internal target graph are current.\n\n[source-acceptance] core architecture negative fixtures\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node framework/core/architecture/check-layers.mjs --self-test\n  ok: clean contract passes\n  ok: target without CMake evidence fails\n  ok: unclassified source fails\n  ok: multiple ownership fails\n  ok: component budget overflow fails\n  ok: forbidden reverse include fails\n  ok: resolved internal reverse include fails\n  ok: undeclared resolved dependency fails\n  ok: declared reverse dependency fails\n  ok: reverse target dependency fails\n  ok: component dependency cycle fails\n  ok: internal target dependency cycle fails\n  ok: target edge outside component graph fails\n  ok: contract test without CMake evidence fails\n  ok: source without internal target fails\n  ok: source with multiple internal targets fails\n  ok: missing responsibility token fails\n  ok: forbidden responsibility token fails\n  ok: source responsibility budget fails\n  ok: clean public contract inventory passes\n  ok: unclassified public header fails\n  ok: multiply classified public header fails\n  ok: stable symbol drift fails\n  ok: binding parity drift fails\n  ok: missing retained layout fixture fails\n  ok: incomplete deprecation ledger fails\nOK: core architecture negative fixtures fail for the intended reasons.\n\n[source-acceptance] core architecture query and health contract\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node framework/core/architecture/query-health.mjs\n[core-architecture] components=12 authority=sha256:101dfc1c09e69455d7fbfce001fdeac0bd5180e968bb6f259c1694d8575d258f findings=0\n\n[source-acceptance] core architecture query negative and navigation fixtures\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node framework/core/architecture/query-health.mjs --self-test\n  ok: legacy and canonical ADR record paths resolve exactly\n  ok: path:framework/core/src/libkungfu/src/runtime/storage/query_render.cpp -> runtime-storage-services\n  ok: symbol:kungfu_get_api -> core-composition-bindings\n  ok: error:unsupported api version -> core-composition-bindings\n  ok: capability:live -> runtime-live-services\n  ok: profile:journal -> yijinjing-schema\n  ok: unknown capability fails closed\n  ok: missing owner fails closed\n  ok: component cycle is visible\n  ok: health regression fails closed\n  ok: advisory regression stays visible without blocking\n\n[source-acceptance] core build capability contract\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node framework/core/architecture/check-build-capabilities.mjs\n[core-build-capabilities] 5 profiles; default=full; supported=journal,embedded-minimal,embedded-sqlite,full\n\n[source-acceptance] core build capability negative fixtures\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node framework/core/architecture/check-build-capabilities.mjs --self-test\n  ok: unknown profile component fails\n  ok: incomplete component closure fails\n  ok: planned default fails closed\n  ok: unknown target dependency fails\n  ok: unmapped architecture component fails\n[core-build-capabilities] negative fixtures passed\n[core-build-capabilities] 5 profiles; default=full; supported=journal,embedded-minimal,embedded-sqlite,full\n\n[source-acceptance] core affected-native negative fixtures\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/run-core-affected-native.mjs --self-test\n  ok: deterministic implementation plan\n  ok: unrelated root package task does not schedule SDK qualification\n  ok: SDK root package task change schedules qualification\n  ok: unknown root package impact fails closed\n  ok: public ABI and gate authority schedule SDK qualification\n  ok: partition set is deterministic, disjoint, and complete\n  ok: native contract JSON fixture selects qualification tests\n  ok: cross-language Core qualification expands globally\n  ok: outside-Core change emits a required-check-safe tier-none plan\n  ok: Python source changes do not invent native work\n  ok: runtime packaging changes do not invent native work\n  ok: generated native binding stubs force full native coverage\n  ok: unclassified source fails closed\n  ok: native source outside tracked_roots is outside the authority\n  ok: Core test fixtures and qualification harness expand globally\n  ok: Core slice qualification harness remains non-native\n  ok: unknown qualification source expands globally\n  ok: authority dependency change expands globally\n  ok: Core native build support changes expand globally\n  ok: core build definition change expands globally\n  ok: public header propagates to consumers\n  ok: target deletion fails closed\n  ok: test mapping loss fails closed\n  ok: receipt drift fails closed\n  ok: receipt partition drift fails closed\n  ok: source-bound plan verifies before execution\n  ok: source-bound plan digest drift fails closed\n[core-affected] 27 negative/determinism fixtures passed\n\n[source-acceptance] journal authority boundary\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-journal-authority-boundary.mjs\n[journal-authority] Session/legacy CLI retired; Storage/Episode authority boundary clean\n\n[source-acceptance] live runtime terminology\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-live-runtime-terminology.mjs\n[live-runtime-terminology] live/reactor/peer/coordinator vocabulary clean; wire-v1 adapter isolated\n\n[source-acceptance] runtime activation contract\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-runtime-contract.mjs\n[runtime-contract] contract=framework/runtime/kungfu-runtime.contract.json valid=5 rejected=7 schema=passed\n\n[source-acceptance] runtime upgrade contract\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-upgrade-contract.mjs\n[upgrade-contract] contract=framework/upgrade/kungfu-upgrade.contract.json states=12 reasons=14 fixtures=6\n\n[source-acceptance] product upgrade qualification\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-upgrade-qualification.mjs\n[upgrade-qualification] contract=framework/upgrade/kungfu-upgrade-qualification.contract.json fixtures=29 messages=19 platforms=3\n\n[source-acceptance] agent session contract\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-agent-session-contract.mjs\n[agent-session-contract] contract=framework/agent-session/kungfu-agent-session.contract.json valid=7 rejected=8 schema=passed\n\n[source-acceptance] CLI catalog parity\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-cli-catalog-parity.mjs\nok (generated CLI catalog and all declared consumers are current)\n\n[source-acceptance] Project Cut contract\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-project-cut-contract.mjs\n[project-cut-contract] schema=sha256:3c4193cab90f3b1b48f504033b4d842b721d48c10259bd4ece8ea62a2fd9a055 protocol=sha256:d47894a6d80d6f406488bc0731440773cb902385e5711546ff9855aec27482b9 cut=sha256:11c1806ceab489c78cb3ccb8865497c52cd3f7eec8e059165bb1d87b068e4561 receipt=sha256:13c6a9c870ead0d73bb1ccdcaccc0875f6aa50bd6a95108a56596b07b75c0b7a schemas=4 schema-validation=passed schema-fixtures=5 negative=12\n\n[source-acceptance] Project Cut settlement contract\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-project-cut-settlement.mjs\n[project-cut-settlement] schema=sha256:2f87355a9fb4ef44221f21806e87422ea914d6d3bcafa780627f63aaf3269041 contract=sha256:5bfc42e0a4955d2f75b94278b2308f556baad4fe2c730168b39074f1ea880f57 schemas=4 schema-validation=compiled\n\n[source-acceptance] Project Cut history contract\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-project-cut-history.mjs\n[project-cut-history] schema=sha256:5fcd30c3fcbe4720d1ce10ea3c9ebbbd46dba497e6276b5489d94deb8455dd96 contract=sha256:01ff866029f7b19e2a18ba97a96cf1cc75844d145103abdda9a4c6c7420c8720 schemas=2 schema-validation=compiled\n\n[source-acceptance] Project Cut composition contract\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-project-cut-composition.mjs\n[project-cut-composition] schema=sha256:e89bee1dccfc5599b1684818ca5173b22843d5bc3d6773b1c818cbb601edd6be contract=sha256:1f72d31af0b5addcad97f9da90ab5068c4b1301a6791d417b52561bcba19ddaa schemas=1\n\n[source-acceptance] Project Cut scoped composition admission\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-project-cut-composition-gate.mjs\n[project-cut-composition] no changed Cut manifests; scoped gate skipped\n\n[source-acceptance] workspace continuation contract\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-workspace-continuation.mjs\n[workspace-continuation] contract=sha256:f2977d2b85cd368da3fc66f4768d982851629f1a4da5a588c3b868014e6720ca states=4 actions=5\n\n[source-acceptance] Episode Admission contract\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-episode-admission-contract.mjs\n[episode-admission] contract=sha256:e91ea5549a2d4be1b4ed3d53ee96abb69d5ff927279ed4cc3004dfc1234923cb actions=7 transports=3 states=9\n\n[source-acceptance] durability production-candidate admission\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/check-durability-production-candidate.mjs\n[durability-admission] passed-current-hardware-production-candidate; inputs=6; production_eligible=false\n\n[source-acceptance] Buildchain KFD release evidence\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/buildchain-kfd-evidence.mjs --check\n[kfd] ok: KFD-1 witness, 4 KFD-2 claim(s), 144 KFD-3 surface(s)\n\n[source-acceptance] Shifu version sync\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/sync-shifu-version.mjs --check\n\n[source-acceptance] layered SDK projections\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/generate-layered-sdk.mjs --check\n[layered-sdk] generated projections are current\n\n[source-acceptance] documentation contracts\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/run-docs-source-check.mjs\n[docs:source] Markdown structure\nmarkdownlint-cli2 v0.22.1 (markdownlint v0.40.0)\nFinding: **/*.md !.buildchain/runtime/** !.buildchain/tmp/** !framework/core/.deps/** !**/node_modules/** !**/.venv*/** !**/build/** !**/dist/** !**/out/**\nLinting: 360 file(s)\nSummary: 0 error(s)\n[docs:source] local links, anchors, and contracts\n[docs] checked 359 Markdown files; local links, anchors, and documentation contracts passed\n[docs:source] documentation contract fixtures\n✔ admits fully qualified Core and Shifu records under one policy (7.975416ms)\n✔ reports status debt by default and fails strict or stable qualification (0.192833ms)\n✔ fails on structural findings even when release obligations are admitted (0.094125ms)\n✔ excludes terminal decisions from stable obligations (0.088083ms)\n✔ creates canonical UUIDv7 identities without shared sequence state (0.578833ms)\n✔ resolves unique human prefixes without creating a second identity (0.316792ms)\n✔ creates 100 unique identities at one fixed timestamp (0.42675ms)\n✔ classifies only canonical new and grandfatherable legacy identities (0.488875ms)\n✔ extracts the complete identity from UUIDv7 filenames (0.204958ms)\n✔ classifies only direct lowercase Markdown ADR record paths as canonical (1.036542ms)\n✔ plans deterministic ID-only renames from an exact Git tree (513.349375ms)\n✔ keeps regeneration declarations immutable across plans (480.104042ms)\n✔ applies a reviewed manifest idempotently and preserves historical bytes (446.409292ms)\n✔ completes only after declared regeneration checks and output closure (459.637458ms)\n✔ fails closed on expected-root or working-file drift (353.2905ms)\n✔ fails closed unless the legacy publication pattern occurs exactly once (896.623583ms)\n✔ fails closed when revision rewriting changes a target ADR root again (446.188875ms)\n✔ plans an ADR without allocating a number or updating a shared index (0.783708ms)\n✔ keeps the deprecated slug input out of the canonical path (0.189667ms)\n✔ independent writers create distinct files and leave README untouched (1.519541ms)\n✔ refuses to overwrite an existing ADR (1.866625ms)\n✔ two ADR branches merge in either order without identity or index conflict (689.983334ms)\n✔ fails closed when ADR identity authority reports a structural finding (3.254625ms)\n✔ validates the repository ADR authority without injected findings (6249.002458ms)\n✔ release loading fails closed on identity-looking noncanonical paths (4.187084ms)\n✔ parses exactly one JSON manifest from the PR body (0.385875ms)\n✔ hydrates exact promotion boundaries in a shallow build checkout (788.891167ms)\n✔ feature dev PR requires a stage-ready or implemented delivery (1.882875ms)\n✔ implemented dev intent needs a staged/implemented qualified ADR (1.356ms)\n✔ ADR-neutral bugfix remains available outside feature branches (1.760791ms)\n✔ alpha settlement must match a changed ADR projection (1.581583ms)\n✔ alpha allows an explicit no-ADR-progress settlement (1.547542ms)\n✔ alpha rejects changed accepted ADRs omitted from settlement (1.694875ms)\n✔ stable blocks every unaccounted accepted ADR (10.083667ms)\n✔ stable admits an exact-release, exact-condition admin waiver (1.556542ms)\n✔ stable rejects stale, unauthorized, and broader waivers (1.387875ms)\n✔ implemented ADR without qualification evidence still blocks stable (1.3005ms)\n✔ rejects mutable documentation Action refs (3.158209ms)\n✔ accepts local files, cross-file anchors, images, and external links (7.192333ms)\n✔ rejects missing local targets with source coordinates (9.134958ms)\n✔ rejects missing cross-file anchors (1.57ms)\n✔ rejects local-link case mismatches on case-insensitive filesystems (1.27925ms)\n✔ tracks GitHub duplicate-heading suffixes (1.4275ms)\n✔ rejects missing canonical entry pointers (1.369333ms)\n✔ rejects repository-escaping local links (1.601042ms)\n✔ rejects unreachable public documents (1.456375ms)\n✔ admits declared implicit collection members without per-file index edits (1.894542ms)\n✔ enforces a canonical docs hierarchy with entry-only root Markdown (2.032792ms)\n✔ rejects every undeclared root Markdown document (3.203292ms)\n✔ rejects Markdown under every retired documentation root (2.699167ms)\n✔ rejects undeclared executable examples (1.331208ms)\n✔ rejects declared executable examples outside the safe argv allowlist (1.098625ms)\nTo /var/folders/lh/63dh4_t12tl7smhvvcr9wwlr0000gn/T/kungfu-cutover-Hvu06C/remote.git\n * [new branch]      main -> main\nCloning into '/var/folders/lh/63dh4_t12tl7smhvvcr9wwlr0000gn/T/kungfu-cutover-Hvu06C/checkout'...\nAutomatic merge went well; stopped before committing as requested\n✔ hydrates the exact ADR cutover commit in a shallow checkout (695.001625ms)\n✔ accepts typed public metadata and aligned ADR projections (4.725542ms)\n✔ rejects deleting or weakening the repository ADR identity policy (4.699542ms)\n✔ cannot bypass ADR routing with external schemas or profile order (10.299ms)\n✔ rejects a new sequential ADR outside the exact legacy inventory (2.261166ms)\n✔ rejects a legacy inventory that differs from its fixed cutover tree (211.633167ms)\n✔ hydrates the exact legacy cutover commit in a shallow checkout (779.861167ms)\n✔ accepts an ID-only UUIDv7 ADR without a shared index row (3.585916ms)\n✔ rejects duplicate UUIDs and heading or owner-prefix drift (2.31025ms)\n✔ routes every non-index ADR Markdown file through identity validation (7.055333ms)\n✔ rejects copying a grandfathered identity to a different path (2.129416ms)\n✔ accepts reciprocal acyclic ADR supersession metadata (1.649958ms)\n✔ rejects one-sided and cyclic ADR supersession graphs (2.073458ms)\n✔ rejects missing required public registry metadata (0.986084ms)\n✔ rejects the ambiguous legacy status field (1.140625ms)\n✔ rejects visible frontmatter when the registry is authoritative (1.259292ms)\n✔ rejects undeclared maintenance attribution in registry metadata (1.433417ms)\n✔ rejects orphaned registry entries (0.882167ms)\n✔ rejects ADR body status drift (1.813375ms)\n✔ rejects ADR index status drift (1.635417ms)\n✔ rejects implementation detail in the ADR index status column (1.44125ms)\n✔ preserves independently consumed frontmatter schemas (1.474959ms)\n✔ accepts reachable full-SHA implementation and closure evidence (368.437334ms)\n✔ pins PR evidence reachability to the source-acceptance base SHA (0.749209ms)\n✔ runs Git-sensitive documentation fixtures serially in both gates (0.566291ms)\n✔ accepts a merge preview by default but rejects PR-only evidence against its base (674.572917ms)\n✔ accepts stable PR implementation and closure evidence (363.948292ms)\n✔ rejects closure PR evidence outside the canonical repository (224.834625ms)\n✔ rejects malformed implementation commit evidence (224.232458ms)\n✔ rejects implementation evidence on a not-started ADR (287.9425ms)\n✔ rejects pull-request evidence outside the canonical repository (281.396375ms)\n✔ rejects a legacy exemption after evidence becomes complete (272.813917ms)\n✔ the committed Buildchain promotion consumer contract is coherent (2.898958ms)\n✔ alpha and stable promotion fixtures cover admission and fail-closed paths (16.49525ms)\n✔ promotion workflow drift is rejected before Buildchain promotion (0.857458ms)\n✔ release qualification rejects ADR admission before Episode evidence (0.470792ms)\n✔ promotion preflight owns no release credentials or side-effect commands (0.200917ms)\n✔ the full rehearsal preserves tracked files, branches, and tags (6222.336708ms)\n✔ a non-promotion GitHub event does not become ADR admission (6586.903833ms)\n✔ an actual GitHub promotion event traverses the ADR gate CLI (12724.955208ms)\n✔ an actual stable event fails closed on the current ADR balance sheet (12611.345916ms)\n✔ accepts a registry aligned with the public vocabulary reference (3.219208ms)\n✔ rejects canonical heading drift (1.975291ms)\n✔ rejects duplicate canonical terms and missing governed roots (9.753625ms)\n✔ projects canonical terms and prose rules into disposable Vale styles (5.838084ms)\nℹ tests 97\nℹ suites 0\nℹ pass 97\nℹ fail 0\nℹ cancelled 0\nℹ skipped 0\nℹ todo 0\nℹ duration_ms 54587.187084\n[docs:source] ADR release contract\n[adr-release] contract and waiver ledger are valid\n[docs:source] ADR authority audit\n[adr-audit] canonical authority: docs/adr\n[adr-audit] records=150 kungfu=141 shifu=9\n[adr-audit] structural=0 debt=88 stable-admitted=40 stable-blocked=97\n[adr-audit] result=pass\n[docs:source] immutable documentation toolchain\n[docs:toolchain] immutable action, container, and archive pins passed\n[docs:source] build-free documentation gate passed\n\n[source-acceptance] source-acceptance contract tests\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node --test scripts/buildchain-install.test.mjs scripts/run-shifu-lifecycle.test.mjs scripts/check-typescript-files.test.mjs scripts/source-acceptance.test.mjs scripts/check-shifu-entry-contract.test.mjs scripts/check-shifu-cache-contract.test.mjs scripts/check-health-diagnostics-contract.test.mjs scripts/shifu-cache-runtime.test.mjs scripts/shifu-conan-publish.test.mjs scripts/shifu-uv-cache-adapter.test.mjs scripts/shifu-gate-runtime.test.mjs scripts/shifu-gate-executor.test.mjs scripts/shifu-documentation-runtime.test.mjs scripts/shifu-documentation-surfaces.test.mjs scripts/shifu-documentation-consumers.test.mjs scripts/kungfu-xinfa-consumer.test.mjs scripts/check-kungfu-gate-catalog.test.mjs scripts/affected-native-proof.test.mjs scripts/verify-kungfu-release-admission.test.mjs crates/xinfa/tooling/check-boundary.test.mjs scripts/check-schema-authority.test.mjs scripts/check-runtime-contract.test.mjs scripts/check-trademark-public-use.test.mjs scripts/check-upgrade-contract.test.mjs scripts/probe-cpp-cmake-contract.test.mjs scripts/check-upgrade-qualification.test.mjs scripts/upgrade-publication-admission.test.mjs scripts/check-agent-session-contract.test.mjs scripts/check-cli-catalog-parity.test.mjs scripts/check-fact-cut-kernel-contract.test.mjs scripts/check-exit-bundle-contract.test.mjs scripts/check-fact-root-canonical.test.mjs scripts/kungfu-invariant.test.mjs scripts/check-kfd7-library-boundary.test.mjs scripts/check-layered-api-encoding-boundary.test.mjs scripts/check-kfd-agent-runtime-boundary.mjs scripts/check-fact-root-canonical.test.mjs scripts/check-project-cut-contract.test.mjs scripts/check-git-episode-provider.test.mjs scripts/check-project-cut-settlement.test.mjs scripts/check-project-cut-history.test.mjs scripts/check-project-cut-composition.test.mjs scripts/project-cut-merge-queue-admission.test.mjs scripts/check-workspace-continuation.test.mjs framework/assignment-capture/assignment-capture.test.mjs scripts/run-continuity-pilot.test.mjs scripts/check-episode-admission-contract.test.mjs framework/agent-session/tests/capsule-host.test.mjs framework/agent-session/tests/peer-transport.test.mjs framework/agent-session/tests/runtime-port.test.mjs framework/agent-session/tests/provider-adapters.test.mjs framework/agent-session/tests/interaction-port.test.mjs framework/agent-session/tests/codex-app-server-contract.test.mjs framework/agent-session/tests/codex-app-server-interaction.test.mjs framework/agent-session/tests/codex-app-server-recovery.test.mjs framework/agent-session/tests/codex-app-server-runtime.test.mjs framework/agent-session/tests/codex-app-server-product.test.mjs framework/agent-session/tests/product-surface.test.mjs framework/agent-session/tests/product-detached-host.test.mjs extensions/terminal/tests/agent-session-snapshot.test.ts framework/core/tests/qualification/runtime-activation/run.test.mjs framework/core/tests/qualification/durability/run.test.mjs framework/core/tests/qualification/durability/powercut_plan.test.mjs framework/core/tests/qualification/durability/fault_campaign.test.mjs framework/core/tests/qualification/durability/candidate_evidence.test.mjs framework/core/tests/qualification/durability/retained_evidence.test.mjs framework/core/tests/qualification/durability/institutional_evidence.test.mjs framework/core/tests/qualification/durability/product_contract.test.mjs framework/core/tests/qualification/durability/slo_evidence.test.mjs framework/core/tests/qualification/durability/offhost_evidence.test.mjs framework/core/tests/qualification/durability/clean_restart_evidence.test.mjs framework/core/tests/qualification/durability/production_candidate_admission.test.mjs scripts/run-durability-powercut-qemu.test.mjs scripts/prepare-durability-powercut-qemu.test.mjs scripts/run-durability-fault-campaign.test.mjs scripts/run-durability-institutional-qemu.test.mjs scripts/run-durability-slo.test.mjs scripts/run-durability-offhost-restore.test.mjs scripts/run-durability-clean-host-restart.test.mjs\n✔ current Xinfa source satisfies the linked component boundary (22.088167ms)\n✔ pure core rejects filesystem access while test-only access is ignored (2.25975ms)\n✔ trunk dependency direction is exact and one-way (0.3985ms)\n✔ non-registry and non-allowlisted dependencies are rejected (0.240666ms)\n✔ private host-product imports are rejected (0.695459ms)\n(node:80695) [MODULE_TYPELESS_PACKAGE_JSON] Warning: Module type of file:///Users/dkr/Worktrees/kungfu/fix/adr-migration-contract-policy-regeneration/extensions/terminal/tests/agent-session-snapshot.test.ts is not specified and it doesn't parse as CommonJS.\nReparsing as ES module because module syntax was detected. This incurs a performance overhead.\nTo eliminate this warning, add \"type\": \"module\" to /Users/dkr/Worktrees/kungfu/fix/adr-migration-contract-policy-regeneration/extensions/terminal/package.json.\n(Use `node --trace-warnings ...` to show where the warning was created)\n✔ renders retained PTY transcript lines (0.493833ms)\n✔ renders structured-session status without requiring a terminal snapshot (0.07ms)\n✔ renders the waiting state before a snapshot arrives (0.064083ms)\n✔ VT snapshot preserves the active text grid without presenting escape bytes (0.937833ms)\n✔ VT snapshot reconstructs absolute columns, whole-line erase, and saved cursor (0.138958ms)\n✔ bounded output emits an explicit gap while the VT snapshot remains current (3.847125ms)\n✔ input is idempotent and fenced by attempt, generation, epoch and process identity (1.193292ms)\n✔ provider exit closes input before any later write can reach a shell (0.541167ms)\n✔ resize and signal target only the current process identity (6.988959ms)\n✔ PTY readiness failure is exposed before provider spawn (0.1635ms)\n✔ pinned stable schema manifest has a self-recomputing deterministic bundle digest (10.712ms)\n✔ contract gate pins CLI, stable schema and non-experimental capability shape (2.947667ms)\n✔ positive fixtures map only typed provider events without retaining raw payloads (3.020583ms)\n✔ negative fixtures fail closed on method, direction, envelope and identity drift (2.55975ms)\n✔ contract preserves provider-specific authority and recovery limits (0.264958ms)\n✔ turn identity comes from turn/started and has one terminal boundary (13.654542ms)\n✔ approval control is exact-targeted and defaults to deny (1.682ms)\n✔ non-approval controls deny by default and require explicit allow results (0.937708ms)\n✔ steer and interrupt plans require the exact active provider turn (2.732417ms)\n✔ usage, error and unknown item types stay typed without raw retention (3.16275ms)\n✔ event gaps, stale processes and plan mutation fail closed (0.9355ms)\n✔ CLI and Agent consumers produce the same deterministic plan root (1.192375ms)\n✔ production route freezes the exact Codex app-server stdio launch (1.006083ms)\n✔ product policy defaults Codex to structured with an explicit PTY rollback (0.113084ms)\n✔ feature flag off and non-Codex providers retain the PTY plan (12.177625ms)\n✔ GUI CLI and Agent share one frozen structured route and exact controls (141.749542ms)\n✔ durable admission precedes provider write and exact duplicates reuse one receipt (20.750833ms)\n✔ a crash window rehydrates as duplicate unknown and never writes twice (4.705459ms)\n✔ runtime exit and request rejection converge on one unknown receipt (5.260083ms)\n✔ approval controls retain exact request identity, default deny and deduplicate (1.865917ms)\n✔ runtime loss marks unresolved input and controls unknown before closing attempt (1.3165ms)\n✔ resume and read bind an exact old boundary without replaying old input (3.176291ms)\n✔ backpressure, fence drift and ledger corruption fail before provider write (6.6165ms)\n✔ PTY fallback preserves the old structured receipts and requires a new attempt (2.078708ms)\n✔ continuous reader exposes turn identity before a late turn/start response (88.851834ms)\n✔ malformed and unknown frames fail closed and freeze admission (154.7425ms)\n✔ bounded queue freezes before the hard bound and reports overflow without growth (72.789791ms)\n✔ thread and turn identities remain isolated across concurrent notifications (83.471375ms)\n✔ server requests correlate exactly and stale writers are rejected (65.564375ms)\n✔ slow or failing consumers cannot block stdout draining (63.652958ms)\n✔ stderr content is never retained or surfaced (71.550541ms)\n✔ stdout pipe loss terminates the provider with an unknown attempt boundary (8.4095ms)\n✔ unexpected provider exit is visible and never claims a terminal outcome (70.743917ms)\n✔ version drift fails before spawn (0.940917ms)\n✔ ready instruction is one idempotent atomic paste and proves no outcome (4.699042ms)\n✔ Claude instruction submits paste and Enter as separately idempotent writes (1.290292ms)\n✔ busy queue flushes only after a supported ready signature (0.634625ms)\n✔ approval and unknown modal states never auto-deliver or auto-queue (0.616916ms)\n✔ interrupt mode sends one fenced signal then waits for ready before text (0.518708ms)\n✔ sendKey is manual-only, deduplicated, and never implies approval outcome (0.369625ms)\n✔ provider exit and opaque shell fallback fail closed (0.416209ms)\n✔ adapter version drift is visible and cannot write through a ready-looking screen (0.258625ms)\n✔ bounded queue rejects overflow without dropping or writing hidden input (0.359584ms)\n✔ multiple readers recover by journal cursor even when notices are lost (9.464125ms)\n✔ AgentSession declares process loss as lost-control instead of fake PTY recovery (0.834584ms)\n✔ one controller wins, duplicate input is idempotent, and stale authority fails closed (0.727333ms)\n✔ interrupt signal is idempotent and uses the same controller and foreground fencing (0.358542ms)\n✔ explicit takeover and resize coalescing retain one auditable winner (0.628083ms)\n✔ Coordinator re-registration preserves stream epoch and controller lease (0.283167ms)\n✔ Capsule continuity consumes the Core runtime authority schema and fences regressions (0.102ms)\n✔ Supervisor adoption requires exact runtime, generation and process identity (0.245792ms)\n✔ slow reader gets an explicit gap and VT snapshot without blocking output (1.060333ms)\n✔ bounded journal transport has no per-reader output fanout in the writer path (30.788959ms)\n✔ detached endpoint is stable per runtime root and contains no main pid (1.3135ms)\n✔ a new main client reconnects to one worker and worker loss never fakes continuity (183.766833ms)\n✔ independent clients serialize first worker startup (129.836875ms)\n✔ product state hides process topology and reserves action-required for unsafe recovery (1.031417ms)\n✔ Core resolves one primary WorkConsole for a generic WorkRef (0.591834ms)\n✔ GUI, CLI, and KFD-3 produce the exact same reviewed start plan (9.431708ms)\n✔ one Go action starts once, auto-attaches, and later views reuse the Capsule (16.17725ms)\n✔ all clients see one Hub projection and presentation detach never ends the provider (10.922583ms)\n✔ a provider restart creates a new attempt under the same primary WorkConsole (1.315334ms)\n✔ the durable Core registry migrates view-owned v1 data without presentation authority (82.086625ms)\n✔ Terminal persistence contains presentation references but no Console authority (12.023417ms)\n✔ Terminal WorkRef launch remains Profile-neutral and rejects partial identity (18.625209ms)\n✔ the published v2 schema admits the Core registry and excludes presentation (65.35525ms)\n✔ provider exit metadata remains visible without retaining terminal output (0.791583ms)\n✔ controller lease has one winner and transfers only after exact release (3.495125ms)\n✔ Agent instruction uses the shared plan and receipt without claiming work outcome (0.869709ms)\n✔ approval state holds shared automatic instruction and stale plans fail closed (0.783125ms)\n✔ the product runtime executes a reviewed plan through the real Capsule host (0.700084ms)\n✔ the local product RPC preserves the same action and error envelopes (22.236042ms)\n✔ codex adapter classifies only versioned redacted fixtures (4.938458ms)\n✔ claude adapter classifies only versioned redacted fixtures (4.444125ms)\n✔ version drift and foreground mismatch fail visibly to raw human fallback (0.122125ms)\n✔ Claude volatile state uses the latest bounded signature and fails closed on a later modal (1.43175ms)\n✔ Claude current VT grid supersedes erased volatile states (0.184417ms)\n✔ instruction encoding uses each provider bounded paste submit sequence (0.399ms)\n✔ version probe returns metadata only and never claims private-state inspection (0.240084ms)\n✔ native port uses action envelopes on one public journal writer (1.063041ms)\n✔ reader follows a Peer public journal and reconstructs cursor frames (0.329042ms)\n✔ native queue overflow becomes an explicit gap (0.110042ms)\n✔ capture round-trips the complete historical Atlas card field set (18.092875ms)\n✔ capture target order matches workspace.py capture-only resolution (198.575833ms)\n✔ expiry cleanup is dry-run-first and retains captured bytes (14.54725ms)\n✔ cleanup fails closed for request material without a valid receipt (5.725334ms)\n✔ Shifu source entry captures without compiled Kungfu artifacts (147.739375ms)\n✔ retained v2 campaign is complete, immutable, and hardware-bounded (121.64325ms)\n✔ retained canary cannot be promoted into qualification evidence (112.905917ms)\n✔ current Linux process evidence retains every raw suite log (459.342459ms)\n✔ institutional drill proves same-host recovery without widening claims (76.455917ms)\n✔ retained clean-restart reports are exact machine artifacts (6.178916ms)\n✔ clean host restart preserves authority and cannot widen its claim (4.112291ms)\n✔ fault campaign freezes three complete seeded device-model cycles (13.879375ms)\n✔ fault campaign order is deterministic and claims stay bounded (2.225833ms)\n✔ fault campaign rejects profile cardinality drift (1.305125ms)\n✔ institutional evidence binds every correctness tier (0.85975ms)\n✔ institutional evidence cannot imply physical or production qualification (0.089291ms)\n✔ retained off-host reports are exact machine artifacts (5.145833ms)\n✔ off-host restore preserves authoritative facts and stays bounded (4.189125ms)\n✔ power-cut plan is dry-run-only and names every fault boundary (2.371584ms)\n✔ plan limits writes and termination to disposable run identities (0.421958ms)\n✔ unsafe workspace or command inputs fail closed (0.249125ms)\n✔ checkpoint publication before directory sync remains an allowed range (0.141ms)\n✔ product capability authority is bound to retained evidence (5.643458ms)\n✔ product capability fails closed outside its named envelope (0.178458ms)\n✔ production-candidate admission is digest-bound and fail-closed (371.725333ms)\n✔ retained three-platform process evidence is complete and immutable (1121.280584ms)\n✔ all platform profiles are schema-valid and cover both receipt profiles (80.105ms)\n✔ the dry run plans only local Shifu commands and makes no claim (26.766084ms)\n✔ Windows qualification commands enter Shifu through cmd.exe (0.254125ms)\n✔ Windows Episode workers preserve Path and declare the source runtime boundary (0.121708ms)\n✔ passing suites qualify only the declared process-crash envelope (22.243583ms)\n✔ dirty source or platform facts fail closed without rewriting suite evidence (26.221834ms)\n✔ a failed or marker-incomplete suite fails the report and its fault coverage (56.150875ms)\n✔ retained agent-120 SLO index is immutable and profile-bound (2.51125ms)\n✔ candidate SLO evidence cannot widen hardware or production claims (0.305542ms)\n✔ failed suites print only a bounded normalized log tail (0.600375ms)\n✔ default evidence survives Core build-directory cleanup (0.290792ms)\n✔ dry-run plans every Shifu-owned qualification step without claims (40.682083ms)\n✔ product verification checks the distribution outputs without rebuilding them (0.533291ms)\n✔ only source-tree Python suites allow the hosted qualification interpreter (0.16375ms)\n✔ Windows suites invoke the repository Shifu shim through ComSpec (0.241875ms)\n✔ Windows suite invocation rejects cmd expansion syntax (0.225ms)\n✔ clean passing source qualifies exact product artifacts with bounded claims (48.015542ms)\n✔ omitted products and dirty source fail closed as unqualified (28.080167ms)\n✔ one failed suite fails its coverage and every supported claim (26.007625ms)\n✔ raw logs are retained as a checksummed gzip bundle beside the report (4.645083ms)\n✔ commit rewrites reuse only when the exact tree, base, and plan projection match (4.277875ms)\n✔ complete partition evidence seals and verifies against the exact producer (5.327167ms)\n✔ missing, tampered, or stale proof evidence fails closed (7.306541ms)\n✔ tree, producer, and unsuccessful receipt drift cannot reuse proof (6.016625ms)\n✔ lookup admits one current same-repository successful PR artifact (0.612208ms)\n✔ lookup degrades duplicate, fork, failed, and expired artifacts to full run (0.191834ms)\n✔ workflow keeps one required context while staging authoritative queue builds (2.662042ms)\n✔ source install provisions only build-free tools from wheels (0.6405ms)\n✔ source install fails closed off GitHub-hosted Linux in CI (0.251458ms)\n✔ verify install preserves the existing Shifu lifecycle (0.834541ms)\n✔ agent-session contract accepts positive fixtures and rejects all named safety failures (110.223459ms)\n✔ contract keeps PTY delivery separate from semantic work authority (0.104875ms)\n✔ coordinator and session stream epochs remain independent (0.417958ms)\n✔ unknown modal state cannot admit an automatic semantic instruction (0.0855ms)\n✔ repository CLI catalog parity is current (32.481541ms)\n✔ catalog root drift fails closed (25.94825ms)\n✔ a hand-edited and re-rooted catalog still fails the registry fence (58.430667ms)\n✔ orphan and mismatched consumer entries fail closed (26.080375ms)\n✔ standalone command routes require an explicit live Click target (22.591625ms)\n✔ orphan runtime API and packaged omission fail closed (24.542709ms)\n✔ Episode Admission contract and public projections stay aligned (3.381459ms)\n✔ removing destination authority fails closed (12.980834ms)\n✔ widening the simulated remote adapter fails closed (18.21075ms)\n✔ registers one packaged KFD-1 Exit Bundle contract (2.4065ms)\n✔ embedded schemas validate the exact contract and full fixture (111.488583ms)\n✔ public compatibility policy is bounded by exact retained evidence (0.171417ms)\n✔ machine inventory stays bound to current domain authorities (1.239459ms)\n✔ full and thin semantics remain mutually exclusive (0.097916ms)\n✔ positive and negative corpus pins fail-closed diagnostics (154.41825ms)\n✔ ADR maturity and public Mission schema references cannot drift (1.346792ms)\n✔ composition authority never absorbs member domain semantics (0.145834ms)\n✔ registers one accepted contract with the native writer stage implemented (1.116791ms)\n✔ keeps Fact lifecycle claims aligned with current implementation evidence (3.203042ms)\n✔ the embedded Draft 2020-12 schema validates the exact contract (63.11975ms)\n✔ separates every authoritative role and freezes the Cut root inputs (0.160417ms)\n✔ declares one owner for closed metadata, typed bodies, bytes, and projections (0.075333ms)\n✔ accepts the positive fixtures (0.271917ms)\n✔ every declared falsifier fails for the declared reason (0.171375ms)\n✔ the machine contract contains no product workflow vocabulary (0.656167ms)\n✔ KFR2 freezes a library-independent closed typed protocol (1.062292ms)\n✔ the independent Python implementation reproduces every byte and rejection (104.954459ms)\n✔ the machine registry welds ordered C++ and Python schema projections (87.145208ms)\n✔ Fact mutation requests have an exact closed-field projection (0.594208ms)\n✔ the C++ authority exposes KFR2 as writer and retains the exact legacy reader (0.500083ms)\n✔ the writer authority passport welds migration, rollback and exact candidate gates (0.123208ms)\n✔ the corpus carries the adversarial cross-language boundary cases (0.140292ms)\n✔ public schemas close producer bytes without claiming the native root (88.837833ms)\n✔ seals one immutable JSONL segment and re-import is idempotent (119.605375ms)\n✔ projects valid int63 Episode identities to lossless decimal strings (2.134333ms)\n✔ provider export/import preserves both roots across workspaces (168.648291ms)\n✔ different Episodes have independent leases; the same Episode rejects a second writer (113.125875ms)\n✔ crash before rename is bounded and leaves no published segment (140.831917ms)\n✔ torn tail, duplicate, out-of-order, hash drift, and unknown schema fail visibly (404.094542ms)\n✔ raw runtime material and unqualified roots are rejected (0.261ms)\n✔ qualification preimage drift fails visibly (95.9675ms)\n✔ an existing workspace ignore must retain every private/runtime exclusion (6.059084ms)\n✔ capability matrix keeps native authority separate from Git shadow storage (0.110083ms)\n✔ diagnostics contract is registered with stable statuses and exits (0.848916ms)\n✔ every problem template is actionable and never embeds execute (0.156125ms)\n✔ command preflight profiles are fresh, bounded, and explicit (0.127209ms)\n✔ recovery classifications bind only fenced authority operations (0.079542ms)\n✔ unified recovery defaults to plan-only and requires exact execution identity (0.22275ms)\n✔ high-value command paths declare the registered preflight profiles (0.321584ms)\n✔ fast mode contract excludes fsck and health source has no mutation calls (0.212875ms)\n✔ full-profile CI requires native health and preflight performance qualification (0.552125ms)\n{\"schema\":\"kungfu.kfd-agent-runtime.boundary-check/v1\",\"ok\":true,\"publicHeaders\":[\"kungfu/api.h\"],\"linkedTarget\":\"${LIBKUNGFU_NAME}\",\"suiteRoot\":\"sha256:1e996b8c43b0b3e38630ccd58acf8a714cbc24b339d3794318347faab9057e5f\"}\n✔ scripts/check-kfd-agent-runtime-boundary.mjs (63.269875ms)\nKFD-7 library boundary contract: ok\n✔ scripts/check-kfd7-library-boundary.test.mjs (397.703334ms)\n✔ the single required dev workflow is merge-queue compatible (1.115084ms)\n✔ dev candidate heavy work is queue-only and depends on both preflights (0.450708ms)\n✔ focused measurement bootstrap is exact and fail-closed (0.53075ms)\n✔ current Kungfu catalog, docs, matrix, actions, and workflows align (346.996125ms)\n✔ an omitted workflow dependency stays required and distinctly bound (434.7415ms)\n✔ workflow authority rejects unknown workflows, jobs, steps, and activation drift (390.082083ms)\n✔ refreshing digests cannot authorize a mutable action in an authority-bearing workflow (137.319292ms)\n✔ refreshing digests cannot give qualification jobs inherited secrets or an Environment (243.954916ms)\n✔ matrix rendering is deterministic and includes every profile (0.811959ms)\n✔ a new Gate requires complete source-bound measurement coverage (229.819541ms)\n✔ the frozen unmeasured baseline cannot absorb a new Gate (74.091208ms)\n✔ missing platforms and stale Gate definitions fail measurement coverage (143.738167ms)\n✔ dirty, unsuccessful, and duration-drifted receipts fail measurement coverage (79.883833ms)\n✔ handler Gate measurements require an intact controller binding receipt (106.497417ms)\n✔ matrix, gate document, and workflow drift each fail closed (501.932792ms)\n✔ execution parameter and reuse tuple drift fail closed (133.955875ms)\n✔ document facts and workflow entrypoints fail closed (294.166792ms)\n✔ every controller class has a structured adapter and input drift fails closed (897.006792ms)\n✔ rogue, duplicate, missing, and invalid controller adapters fail closed (636.255958ms)\n✔ direct Gate invocations are discovered from YAML and must have one binding (241.651ms)\n✔ direct Gate arguments and profile inputs fail closed on drift (356.584292ms)\n✔ schema v2 rejects missing invocation contracts and legacy snippets (100.639417ms)\n✔ Gate and profile mismatch or dynamic ids fail closed (580.393292ms)\n✔ the layered API contract projects one public ABI waist (1.882542ms)\n✔ identity protocols retain their existing canonical preimages (1.190959ms)\n✔ FlatBuffers carrier identity is not confused with logical identity (0.206958ms)\n✔ the L1 SDK pilot is generated for all four language consumers (3.515959ms)\n✔ Xinfa keeps JSON evidence dependencies and no FlatBuffers authority (31.792792ms)\n✔ Work lifecycle publishes one generated operation set through the same waist (2.200458ms)\nSwitched to a new branch 'candidate'\nAutomatic merge went well; stopped before committing as requested\nAutomatic merge went well; stopped before committing as requested\nSwitched to a new branch 'preview'\nSwitched to a new branch 'moving-main'\nSwitched to branch 'feature-a'\nRebasing (1/2)\nRebasing (2/2)\nSuccessfully rebased and updated refs/heads/feature-a.\nSwitched to branch 'feature-b'\nRebasing (1/2)\nRebasing (2/2)\nSuccessfully rebased and updated refs/heads/feature-b.\nSwitched to branch 'feature-c'\nRebasing (1/2)\nRebasing (2/2)\nSuccessfully rebased and updated refs/heads/feature-c.\nSwitched to a new branch 'moving-main'\nSwitched to branch 'iterative-feature'\nRebasing (1/4)\nRebasing (2/4)\nRebasing (3/4)\nRebasing (4/4)\nSuccessfully rebased and updated refs/heads/iterative-feature.\nSwitched to a new branch 'candidate'\nSwitched to a new branch 'candidate'\nSwitched to a new branch 'candidate'\nSwitched to a new branch 'candidate'\nSwitched to a new branch 'candidate'\n✔ composition contract is rooted without changing Project Cut v1 (70.987667ms)\n✔ two concurrent disjoint Cuts compose into one qualified N:M receipt (6684.454917ms)\n✔ a Cut first published by a merge commit has a deterministic publication (2946.265083ms)\n✔ a merge preview reuses the publication from its identical side parent (3742.244667ms)\n✔ three concurrent Cuts survive a moving-main merge and clean-clone rebuild (9678.357333ms)\n✔ an exact successor anchors superseded Cut publications after queue rebase (6606.433958ms)\n✔ a squash-published Cut chain replays independent of sibling order (6136.787667ms)\n✔ a self-consistent Cut with the wrong source root still fails closed (1683.594166ms)\n✔ resolved overlap stays incomplete until integration evidence is admitted (2698.631625ms)\n✔ resolved overlap qualifies with a tracked admitted Integration Episode (3871.697166ms)\n✔ a qualified Integration Cut remains valid after forward evolution (7779.651584ms)\n✔ self-consistent forged Episode evidence cannot admit an overlap (3791.716042ms)\n✔ receipt-only and Episode-only evidence deletion enter the scoped gate (3052.053833ms)\n✔ multiple project identities receive separate candidate projections (2894.737083ms)\n✔ missing parent manifest and missing receipt fail closed (1495.732875ms)\n✔ tampering is rejected and empty scopes remain distinct from global audit (790.093083ms)\n✔ Project Cut contract, schema bundle, golden roots, and negative fixtures are welded (113.78525ms)\n✔ object field order cannot change semantic or serialization roots (1.179292ms)\n✔ cut root, serialization root, artifact digest, and receipt root are separate identities (0.945584ms)\n✔ publication coordinates are not admitted into a Project Cut root preimage (0.7685ms)\n✔ canonical JSON rejects ambiguous text and number encodings (0.904125ms)\n✔ lossless Episode-edge parsing preserves uint64 tokens without widening Project Cut roots (0.2135ms)\n✔ semantic parent availability is independent of Git ancestry (1.258334ms)\n✔ receipt verification detects artifact-byte drift without changing semantic identity (2.071916ms)\nAutomatic merge went well; stopped before committing as requested\n✔ history schemas and operation matrix are rooted (111.904542ms)\n✔ history inventory retains legacy cut.json compatibility (772.77275ms)\n✔ history CLI emits stable JSON envelopes for observe and reconcile (952.227458ms)\n✔ rewrite operations preserve sealed roots and unqualified rewrites fail visibly (2325.7025ms)\n✔ merge, revert, recovery, empty, and ref contention have explicit semantics (2912.666792ms)\n✔ orphan and archive reconciliation are visible and concurrent worktrees need no global lock (1854.839541ms)\n✔ reconcile skips excluded baseline bytes while retaining protocol evidence (0.569041ms)\n✔ prepare is deterministic, dry-run does not mutate, and explicit staging is exact (2610.559917ms)\n✔ explicit empty Episode delta prepares, publishes, and reconciles without an Episode (1683.944875ms)\n✔ commit projection chunks aggregate blob reads beyond one bounded batch (1994.534625ms)\n✔ commit observe preserves sealed-unpublished state, then proves publication (4595.858958ms)\n✔ source drift, private input, and a commit without a cut fail visibly (1713.045875ms)\n✔ partial staging remains explicit and abandonment requires execute (1217.097125ms)\n✔ baseline material stays out of Git and missing material fails visibly (2136.939334ms)\n✔ tracked witnesses are validated from the exact index and commit (2940.103458ms)\n✔ thin hooks verify and observe through the public settlement core (1205.950291ms)\n✔ CLI emits one stable JSON envelope and requires the agent-first flag (766.951ms)\n✔ public CLI seals a qualified Episode only on execute and stages exact outputs (429.612167ms)\n✔ public CLI matches a lossless int63 bundle to decimal-string fsck evidence (172.420709ms)\n✔ runtime contract accepts positive fixtures and rejects all safety failures (136.6815ms)\n✔ process diagnostics do not upgrade a handle without a durable cut (0.142666ms)\n✔ process placement is explicit while semantic host and embedded remain non-claims (0.447583ms)\n✔ operation registry classifies daemonless and live-required work from one authority (0.10875ms)\n✔ the existing Profile action registry references the runtime operation authority (6.628166ms)\n✔ standalone readiness and lease targets enforce their local invariants (4.823458ms)\n✔ valid typed view, opaque body, and foreign JSON edge are not authorities (3.182875ms)\n✔ one semantic identity cannot have Hana and FlatBuffers owners (1.243541ms)\n✔ JSON cannot become a core semantic service surface (0.514958ms)\n✔ projection route is exclusive to its schema owner (0.812ms)\n✔ repository inventory matches production sources (45.443167ms)\n✔ cache contract schemas accept valid fixtures and reject unsafe policy (188.620834ms)\n✔ shifu exposes the exact checked-in contract (59.807875ms)\n✔ shifu exposes the exact checked-in profile schema (65.961083ms)\n✔ shifu exposes the exact checked-in resolution schema (81.059083ms)\n✔ shifu exposes the exact checked-in diagnostic schema (77.186791ms)\n✔ shifu exposes the exact checked-in config plan schema (67.453667ms)\n✔ unknown cache schema fails with usage (73.065041ms)\n✔ shifu validates a profile through its runtime authority (75.12075ms)\n✔ cache apply is transparent when no profile projection is configured (117.006625ms)\n✔ cache status is local-only and distinguishes absent from partial configuration (6.866ms)\n✔ cache use is dry-run by default and manages only its delimited block (22.862958ms)\n✔ cache use refuses to overwrite an Atlas controller projection (6.21375ms)\n✔ cache doctor resolves configured profiles while leaving hit evidence unproven (11.224791ms)\n✔ cache doctor probes selected HTTP endpoints only when requested (63.449959ms)\n✔ cache doctor uses the lightweight devpi API for legacy Python profiles (13.174708ms)\n✔ HTTP probe retries a transient timeout and succeeds (0.166084ms)\n✔ HTTP probe keeps persistent timeouts failed at the attempt bound (0.122917ms)\n✔ HTTP probe retries 5xx but accepts a reachable 4xx without retry (0.093459ms)\n✔ cache profile runtime rejects probe attempts above the schema bound (6.281042ms)\n✔ cache status CLI emits the diagnostic receipt as JSON (68.9525ms)\n✔ shell shim keeps cache on L2 when native task execution is forced (116.079958ms)\n✔ ordinary shell task auto-applies a projected profile exactly once (1298.643667ms)\n✔ explicit runner projection overrides user-global development config (912.476875ms)\n✔ shell gate run applies a projected profile once at the outer boundary (1305.91075ms)\n✔ active child and absent projection bypass automatic cache application (1681.192875ms)\n✔ active child does not reload developer bindings omitted by its cache profile (709.070333ms)\n✔ partial projection reaches the resolver and fails closed (766.007041ms)\n✔ accepts Shifu commands in participant documentation (1.709833ms)\n✔ rejects direct package-manager commands in participant documentation (0.197208ms)\n✔ rejects direct node in a workflow run block (0.142417ms)\n✔ allows one explicitly justified implementation command (0.087333ms)\n✔ current participant surfaces satisfy the contract (7.035083ms)\n✔ cache execution boundaries distinguish gate run and source acceptance (0.486208ms)\n✔ Xinfa product tasks bypass unrelated Kungfu dependency caches (0.321041ms)\n✔ Xinfa source entry prefers hash-pinned wasm and preserves native fallback (0.357ms)\n✔ Xinfa quality uses the source resolver and forwards one Windows mode (0.818208ms)\n✔ Windows source-fresh launcher retries one transient build failure (0.267125ms)\n✔ Windows local environment parsing is inline and label-free (0.186125ms)\n✔ source-fresh launchers pin nested Shifu entry to the resolved binary (0.215667ms)\n✔ cold source acquisition copies the binary from its isolated Cargo target (0.564958ms)\n✔ Windows launchers dispatch after resolution blocks and preserve arguments (0.358375ms)\n✔ runtime guard rejects a direct task and accepts Shifu provenance (136.019583ms)\n✔ package manager cannot run a guarded root task without Shifu (712.196125ms)\n(node:81107) [MODULE_TYPELESS_PACKAGE_JSON] Warning: Module type of file:///Users/dkr/Worktrees/kungfu/fix/adr-migration-contract-policy-regeneration/framework/gui/src/main/product-identity.ts is not specified and it doesn't parse as CommonJS.\nReparsing as ES module because module syntax was detected. This incurs a performance overhead.\nTo eliminate this warning, add \"type\": \"module\" to /Users/dkr/Worktrees/kungfu/fix/adr-migration-contract-policy-regeneration/framework/gui/package.json.\n(Use `node --trace-warnings ...` to show where the warning was created)\n✔ the current pre-release state is truthful and complete (23.481083ms)\n✔ the GUI About projection preserves product and version identity (0.216667ms)\n✔ registered symbols and unsupported registration claims are rejected (14.525458ms)\n✔ removing a source product surface or its runtime wiring is rejected (13.990083ms)\n✔ renaming the product or removing an exact-mark surface is rejected (5.026791ms)\n✔ renaming protected technical identifiers or packages is rejected (25.645667ms)\n✔ preview or staging cannot satisfy the first real release gate (2.588416ms)\n✔ released use requires source-bound public evidence for one exact release (7.326292ms)\n✔ released use requires evidence for every core Class 9 identification (3.322584ms)\n✔ conditional Class 9 items require released evidence when selected (1.6725ms)\n✔ file-scoped type check reports only diagnostics owned by requested files (1321.592334ms)\n✔ upgrade contract weld and state fixtures stay complete (1.333583ms)\n✔ every reason keeps one complete user message (17.360708ms)\n✔ activation authority drift fails closed (6.063125ms)\n✔ runtime upgrade tests enter pinned uv through Shifu (0.623ms)\n✔ runtime upgrade tests use the welded Windows Shifu entry (0.108541ms)\n✔ upgrade qualification contract keeps messages, docs, and platform claims welded (2.109958ms)\n✔ native campaign evidence signs every retained artifact without persisting a private key (21.0285ms)\n✔ upgrade qualification fixture: qualified-native-evidence (1.144292ms)\n✔ upgrade qualification fixture: missing-evidence (1.009708ms)\n✔ upgrade qualification fixture: source-only-tier (0.470375ms)\n✔ upgrade qualification fixture: source-mismatch (0.421ms)\n✔ upgrade qualification fixture: surface-missing (0.377416ms)\n✔ upgrade qualification fixture: runtime-churn-insufficient (0.414958ms)\n✔ upgrade qualification fixture: messages-unqualified (0.422084ms)\n✔ upgrade qualification fixture: docs-unqualified (0.450834ms)\n✔ upgrade qualification fixture: signature-missing (2.152ms)\n✔ upgrade qualification fixture: signature-invalid (0.53875ms)\n✔ upgrade qualification fixture: artifact-digest-mismatch (0.457791ms)\n✔ upgrade qualification fixture: campaign-missing (0.318125ms)\n✔ upgrade qualification fixture: campaign-source-mismatch (0.372834ms)\n✔ upgrade qualification fixture: campaign-channel-root-missing (1.048708ms)\n✔ upgrade qualification fixture: campaign-artifact-root-mismatch (0.574917ms)\n✔ upgrade qualification fixture: campaign-passport-mismatch (0.37225ms)\n✔ upgrade qualification fixture: campaign-previous-public-invalid (0.352542ms)\n✔ upgrade qualification fixture: campaign-platform-mismatch (0.330042ms)\n✔ upgrade qualification fixture: campaign-owner-mismatch (0.49825ms)\n✔ upgrade qualification fixture: campaign-command-mismatch (0.347708ms)\n✔ upgrade qualification fixture: campaign-confirmation-unbounded (0.357875ms)\n✔ upgrade qualification fixture: campaign-result-mismatch (0.342959ms)\n✔ upgrade qualification fixture: campaign-smoke-missing (0.350375ms)\n✔ upgrade qualification fixture: campaign-activation-mismatch (0.489375ms)\n✔ upgrade qualification fixture: campaign-fault-missing (0.354917ms)\n✔ upgrade qualification fixture: campaign-nonclaim-mismatch (0.335583ms)\n✔ upgrade qualification fixture: campaign-docs-missing (0.40325ms)\n✔ upgrade qualification fixture: campaign-simulated (0.31225ms)\n✔ upgrade qualification fixture: campaign-stale (0.30525ms)\n✔ workspace continuation contract and public projections stay aligned (4.242792ms)\n✔ missing explicit continuation action fails closed (32.032333ms)\n✔ checker command resolution uses the native Windows shifu launcher (0.614667ms)\n✔ checker diagnostics prefer stderr, remove control codes, and redact the repository root (0.1735ms)\n✔ checker timeout terminates the complete Windows process tree (0.497792ms)\n✔ checker failures expose bounded stdout and stderr diagnostics (0.196083ms)\n✔ Fact native harness preserves its source qualification boundary on Windows (0.233833ms)\n✔ Windows invariant checker delegates Fact native execution to the shared harness (0.173375ms)\n✔ Fact characterization fixtures use an explicit cross-platform encoding (0.599917ms)\n✔ meta-contract freezes orthogonal stability, maturity, verdict, and layer vocabularies (0.175334ms)\n✔ registry validates, has no root drift, and binds strong invariants to models and refinements (74.124166ms)\n✔ the public source runner discovers and verifies both domains without native prerequisites (338.202917ms)\n✔ source drift, unknown checker, and missing strong-model bindings fail closed (30.453125ms)\n✔ implementation passport verifies a complete three-platform matrix and rejects omission, falsification, staleness, and tamper (4816.235791ms)\n✔ release evidence aggregation preserves the built source identity and rejects mixed sources (378.228333ms)\n✔ Exit migration release claims bind exact installed witnesses and fail closed on every declared downgrade (9.623583ms)\n✔ Episode object receipt is stable, separate from admission, and honest for sealed, open, damaged, and changed objects (84.382208ms)\n✔ successor gate rejects silent semantic change and requires model/refinement impact for strong invariants (20.901917ms)\n✔ schemas reject unknown verdicts and tampered receipt roots (106.996167ms)\n✔ Kungfu materializes Human, Agent, and GUI views without owning compiler semantics (1023.740583ms)\n✔ preparation remains dry-run and run-scoped by default (1.014666ms)\n✔ preparation implementation has no workflow or host-service authority (1.088459ms)\n✔ the C++ probe searches the Windows libkungfu archive output directory (1.864625ms)\n✔ the C++ probe compiles public Core headers as UTF-8 on MSVC (0.19925ms)\n✔ the C++ probe links the separate Windows yijinjing archive (1.102458ms)\n✔ the C++ probe links the Windows yijinjing xxHash dependency (0.397292ms)\n✔ the SDK resolves the real uv base interpreter for Windows CMake builds (0.465792ms)\n✔ the SDK pins multi-config C++ probe artifacts to the declared dist directory (0.341208ms)\n✔ synthetic replay matches the tree produced by a real rebase (1924.309583ms)\n✔ merge conflicts are deterministic repair-required admissions (939.941625ms)\n✔ source drift is rejected before merge queue entry (4083.196917ms)\n✔ a source-only candidate with no Cut delta is qualified (791.959875ms)\n✔ runs one bounded preparatory pilot and generates animation inputs (52.526625ms)\n✔ rejects hidden transcript injection (46.438875ms)\n✔ rejects different task trees (26.714916ms)\n✔ rejects missing baseline identity and missing oracle (19.895083ms)\n✔ rejects fabricated public metrics (26.750542ms)\n✔ rejects smoke evidence presented as FO10 (23.489833ms)\n✔ clean-restart plan is frozen, sentinel-protected, and two-phase (3.925625ms)\n✔ unsafe run identities and phases fail before any host operation (0.41475ms)\n✔ Node architecture names normalize to the frozen Linux vocabulary (0.093292ms)\n✔ runner contains no CI, deletion, or host-control authority (0.362209ms)\n✔ campaign dry run names the full bounded mutation surface (10.891625ms)\n✔ canary is one named trial and cannot claim qualification (1.519542ms)\n✔ QEMU device envelopes are explicit and do not widen hardware claims (0.113791ms)\n✔ campaign source records every failure and preserves the workspace (0.284042ms)\n✔ institutional QEMU qualification remains local and disposable (0.628292ms)\n✔ institutional evidence includes ENOSPC, restart, fsck, and restore (0.10825ms)\n✔ off-host plan is frozen, build-local, sentinel-protected, and delete-free (1.257333ms)\n✔ unsafe run identities fail before any host operation (0.498792ms)\n✔ Node architecture names normalize to the frozen Linux hardware vocabulary (0.094042ms)\n✔ runner contains no self-hosted CI, deletion, or host-service authority (0.468458ms)\n✔ QEMU execution arguments isolate root and raw durability devices (1.450666ms)\n✔ execution remains explicit (0.7025ms)\n✔ profile freezes both profiles, rollover, throughput, and two 15-minute soaks (1.811125ms)\n✔ dry-run plan is project-local and cannot dispatch GitHub CI (0.28975ms)\n✔ correctness is a knockout and absolute ceilings do not move (0.287291ms)\n✔ aggregate report passes only the exact named host and NVMe/ext4 envelope (1.704417ms)\n✔ implementation contains no GitHub or host-control authority (0.33225ms)\n✔ wraps an arbitrary child command in one cache projection (0.966125ms)\n✔ an active cache projection is reused without acquiring a second partition (0.101833ms)\n✔ an inactive lifecycle enters the cache projection exactly once (0.089292ms)\n✔ copies the lifecycle environment without mutating the caller (0.130208ms)\n✔ adds retained upgrade evidence only to dist (0.176875ms)\n✔ preserves release evidence supplied by the build environment (0.073833ms)\n✔ wraps a lifecycle task in cache apply without a shell command (0.074208ms)\n✔ runs the Unix shim without a shell (171.057667ms)\n✔ Windows reuses a selected native launcher without a nested cmd shim (25.391666ms)\n✔ quotes a Windows shim payload and rejects expansion syntax (3.323666ms)\n✔ enters a Windows batch shim with one Node-quoted cmd payload (0.206375ms)\n﹣ Windows preserves a multi-argument Shifu batch invocation (0.073958ms) # SKIP\n﹣ Windows cold, warm, explicit, and cache-applied launchers dispatch ordinary commands (0.0685ms) # SKIP\n﹣ Windows lifecycle dispatch reaches an ordinary pnpm command (0.036666ms) # SKIP\n✔ Windows cache re-entry leaves the welded shim token unquoted (0.669625ms)\n✔ Conan storage partitions are stable per execution principal and isolated across principals (0.433541ms)\n✔ validates exact bytes and applies only environment bindings (1.051542ms)\n✔ origin-only registry endpoints do not gain a trailing slash (0.246792ms)\n✔ fails closed on digest mismatch and secret-like environment keys (0.425292ms)\n✔ rejects endpoint credentials, query strings, and unknown fields (0.549042ms)\nshifu cache: Python effective lock unavailable; using declared public fallback\nshifu cache: managed Conan storage is already in use; timed out waiting for the same partition\nshifu cache: reclaimed a managed Conan lock whose owner is no longer running\n✔ resolves an HTTP reference and emits a redacted schema receipt (102.814917ms)\n✔ cache apply injects bindings and writes a receipt (70.349917ms)\n✔ cache apply strips inherited uv transport when the profile has no Python index (75.906334ms)\n✔ strict Python cache uses a disposable effective lock and redacted receipt (2363.999875ms)\n✔ strict Python cache fails before starting the child when effective lock rebinding fails (584.304042ms)\n✔ development Python cache records declared fallback when effective lock is unavailable (1006.065417ms)\n✔ cache apply overrides Cargo and isolates Conan without mutating persistent config (2998.542833ms)\n✔ cache apply cleans config overlays after a failing child (82.262583ms)\n✔ nested cache apply preserves the original tool PATH instead of wrapping a wrapper (148.665084ms)\n✔ nested Gate task re-entry does not acquire Conan storage when Conan is unused (755.07875ms)\n✔ a non-Conan child does not contend with an occupied Conan partition (66.2915ms)\n✔ a Conan child waits boundedly and preserves a live same-partition lock (587.991042ms)\n✔ a Conan child reclaims a lock whose recorded process is dead (894.387625ms)\n✔ cache apply is a transparent pass-through when no profile is configured (46.605583ms)\n✔ matrix contract covers the required three platforms (1.06675ms)\n✔ dry-run plan keeps publisher credentials out of Buildchain (3.449375ms)\n✔ package revision read-back requires exact recipe and package revisions (0.26025ms)\n✔ execute fails closed outside Shifu before invoking Conan (76.62175ms)\n✔ two non-Kungfu consumer shapes compile through one Xinfa authority (2580.131583ms)\n✔ documentation contract accepts Kungfu inputs and rejects every negative fixture (235.009916ms)\n✔ shifu exposes the exact checked-in documentation contract (75.736375ms)\n✔ shifu exposes the exact checked-in documentation submission schema (68.133458ms)\n✔ shifu exposes the exact checked-in documentation receipt schema (83.603959ms)\n✔ validate emits a non-qualifying, non-self-certified receipt (101.388667ms)\n✔ show emits deterministic roots independent of collection order (77.3015ms)\n✔ unknown fields and public routing of private providers fail visibly (0.818ms)\n✔ CLI JSON diagnostics are stable for the same invalid fixture (201.514667ms)\n✔ stdin validation rejects malformed JSON without executing anything (67.002167ms)\n✔ Shifu delegates Atlas compilation and verification to the public Xinfa CLI (1362.085125ms)\n✔ surface inventory closes tracked prose (115.616791ms)\n﹣ surface inventory emits an exact Xinfa project (0.093541ms) # requires a built Xinfa binary\n﹣ human surface inventory and Xinfa submission are deterministic (0.445541ms) # requires a built Xinfa binary\n﹣ Xinfa derives semantic nodes and rejects an unverified inventory root (0.0635ms) # requires a built Xinfa binary\n✔ Xinfa Agent discovery closes repository, installed-pack, and dual-first routes (2.865333ms)\n﹣ a one-sided dual-first parity group fails closed (0.06425ms) # requires a built Xinfa binary\n﹣ documentation context stays a thin Xinfa delegation with the declared parity group (0.059042ms) # requires a built Xinfa binary\n﹣ documentation final-ready binds KFD-1 impact and dual-first projections (0.0455ms) # requires a built Xinfa binary\n﹣ implementation revision drift is preserved as a Xinfa document dependency mismatch (0.048209ms) # requires a built Xinfa binary\n✔ authoring impact classifies review obligations and blocks historical deletion (639.035542ms)\n✔ an eligible surface without a classification fails closed (3.582041ms)\n✔ explicit multi-gate runs close and deduplicate shared dependencies (203.196292ms)\n✔ explicit diagnostic runs can omit one declared dependency without becoming qualifying (52.067ms)\n✔ dependency omission rejects qualifying, explicit, and unrelated Gates (1.391208ms)\n✔ a clean complete profile produces a current qualifying receipt (325.064083ms)\n✔ receipt integrity binds the effective execution parameters (313.161708ms)\n✔ advisory failures remain visible without blocking required qualification (137.517125ms)\n✔ required failures keep a copyable single-gate reproduction argv (104.745958ms)\n✔ task failure reasons retain a bounded diagnostic output tail (92.016958ms)\n✔ task output above the legacy 16 MiB buffer remains executable (106.440292ms)\n✔ required gate-specific evidence is enforced without embedding its content (87.963042ms)\n✔ unsafe evidence refs and inherited environment values cannot enter receipts (3.332916ms)\n✔ a required handler skip is non-successful and non-qualifying (1.602875ms)\n✔ handler reasons are bounded and redact paths, URLs and secret-like assignments (1.316875ms)\n✔ timeouts are bounded and recorded as errors (1006.31675ms)\n✔ task actions re-enter an existing lightweight Shifu task beside an active qualification (9693.289333ms)\n✔ stale source, changed definitions and incomplete coverage fail receipt reuse (168.864083ms)\n✔ task invocation uses the native Shifu entrypoint on POSIX and cmd.exe on Windows (0.248584ms)\n✔ gate contract accepts the valid fixture and rejects every semantic failure class (136.622584ms)\n✔ shifu exposes the exact checked-in Gate contract (64.702417ms)\n✔ shifu exposes the exact checked-in Gate registry schema (86.904083ms)\n✔ shifu exposes the exact checked-in Gate plan schema (85.879875ms)\n✔ shifu exposes the exact checked-in Gate receipt schema (56.704375ms)\n✔ validate remains available when the selected registry is invalid (79.392708ms)\n✔ list, show, explain and matrix have versioned deterministic JSON (426.265916ms)\n✔ plan closes dependencies into deterministic parallel groups (100.869708ms)\n✔ explicit diagnostic selection is non-qualifying and still closes dependencies (72.946ms)\n✔ required unsupported gates fail the plan without pretending to skip (65.734709ms)\n✔ explicit gate execution emits a non-qualifying unified receipt (860.837125ms)\n✔ the legacy rich-command error still rejects unrelated unknown commands (48.134167ms)\n✔ official PyPI lock policy rejects private and alternate hosts (1.397083ms)\n✔ transport URL rebinding preserves the uv lock semantic digest (0.621834ms)\n✔ effective lock and environment stay outside the canonical checkout (950.63075ms)\n✔ type baseline covers every Python surface declared by [tool.mypy] (2148.335084ms)\n✔ release verification reuses the exact mypy tool lane without project sync (0.667416ms)\n✔ Python source checks use uvx when a bare ruff is unavailable (0.48425ms)\n✔ Python source checks use uv tool run when the uvx shim is absent (0.080292ms)\n✔ C++ source checks use the exact ambient formatter when it matches the repository pin (0.156459ms)\n✔ C++ source checks isolate an incompatible ambient formatter behind pinned uvx (0.130042ms)\n✔ Python type checks use the pinned CI mypy when it is healthy (0.079666ms)\n✔ Python type checks isolate a broken ambient mypy behind pinned uvx (0.071625ms)\n✔ Python type checks use pinned uv tool run without a uvx shim (0.076917ms)\n✔ source plan covers representative source-only checks (721.769792ms)\n✔ clang-format falls back to pinned uv tool run without a uvx shim (0.165417ms)\n✔ generated Xinfa and Project Cut evidence is not treated as web source (0.140625ms)\n✔ Conan recipe Python is linted without widening into the product type baseline (14.60575ms)\n✔ changed GUI TypeScript receives a file-scoped semantic check (0.202209ms)\n✔ RocksDB source archive keeps an explicit tar filename (0.214791ms)\n✔ source plan cannot enter build, compiler, artifact, or release lifecycles (0.580416ms)\n✔ reusable workflow is bound to source mode and the pinned stable runtime (0.226833ms)\n✔ manual package build is welded to the reviewed Phase B consumer (0.500208ms)\n✔ the native membrane matrix is a promotion gate, not a dev PR gate (0.140375ms)\n✔ documentation lint excludes the checked-out Buildchain runtime (0.903917ms)\n✔ publication admission verifies three native payloads plus authoritative signed macOS bytes (67.734875ms)\n✔ publication admission rejects a missing credential-island payload (43.82125ms)\n✔ publication admission rejects signed DMG byte drift (45.313583ms)\n✔ publication admission rejects a non-authoritative signing identity (61.003459ms)\n✔ publication admission rejects unaccepted notarization evidence (40.335083ms)\n✔ publication admission rejects missing retained qualification evidence (20.622375ms)\n✔ publication admission rejects payload byte drift after manifest creation (34.693167ms)\n✔ publication admission rejects source identity outside the RC passport (33.864208ms)\n✔ publication admission rejects campaign evidence bound to a different RC passport (35.1165ms)\n✔ publication admission rejects an incomplete platform matrix (43.362084ms)\n✔ publication admission rejects divergent duplicate release manifests (42.6765ms)\n✔ Kungfu independently accepts only a current sealed qualifying capability (243.730791ms)\n✔ Kungfu rejects missing platform evidence and replayed or stale admission (128.069208ms)\n✔ Kungfu rejects policy, runner, control-plane, and artifact substitution (97.932875ms)\n✔ Kungfu consumer qualification seals only an exact current handoff (25.745625ms)\nℹ tests 569\nℹ suites 0\nℹ pass 559\nℹ fail 0\nℹ cancelled 0\nℹ skipped 10\nℹ todo 0\nℹ duration_ms 64351.906542\n\n[source-acceptance] Phase B package identity contract tests\n[source-acceptance] $ python3 -m unittest scripts.test_prepare_kungfu_phase_b_package\n{\"consumer\": {\"commit\": \"bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb\", \"ref\": \"v1.2.4-alpha.28\", \"repository\": \"kungfu-systems/build-images\"}, \"package\": {\"filename\": \"kungfu-episodes-cli-linux-x64.tar.gz\", \"platform\": \"linux-x64\", \"sha256\": \"4c0e52e82dbdd31e64e70bf61554556ac5145347f2e21434592a31265b2aa4b5\", \"sizeBytes\": 422, \"sourceCommit\": \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\", \"version\": \"4.0.0-alpha.1\"}, \"schema\": \"kungfu.phase-b-package-identity/v1\"}\n\n[source-acceptance] agent work state contract and CLI parity\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/run-agent-work-state-tests.mjs\n✔ registers one layered Agent Work contract with bounded claims (1.499417ms)\n✔ validates Profile shape and cross-object semantics from one contract (169.742833ms)\n✔ separates Action Geometry from the Agent Work Domain Profile by exact roots (1.509375ms)\n✔ proves context payload alone cannot determine action validity (27.805208ms)\n✔ publishes every invalid inference and P17 check (0.360041ms)\n✔ separates continuity smoke, comparison, and public projection evidence (13.269792ms)\n✔ human and agent routes point to the same contract authority (0.493708ms)\nℹ tests 7\nℹ suites 0\nℹ pass 7\nℹ fail 0\nℹ cancelled 0\nℹ skipped 0\nℹ todo 0\nℹ duration_ms 297.546834\n.........................................                                [100%]\n41 passed in 5.47s\n\n[source-acceptance] runtime upgrade control-plane tests\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/run-runtime-upgrade-tests.mjs\n........................................................................ [ 63%]\n..........................................                               [100%]\n114 passed in 6.56s\n\n[source-acceptance] desktop update adapter tests\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node scripts/run-desktop-update-tests.mjs\n✔ passes Windows ESM entrypoints as file URLs (0.556458ms)\n✔ upgrade manifest generation runs after runtime mutation hooks (0.168417ms)\n✔ preserves an explicit certificate hash for duplicate named identities (0.511875ms)\n✔ falls back to the identity resolved by electron-builder (0.095917ms)\n✔ recognizes thin and universal Mach-O headers (0.12ms)\n✔ skips ordinary resources without skipping native runtime code (0.107667ms)\n✔ fails closed when a candidate cannot be inspected (0.0735ms)\n✔ preserves existing string, array, and function ignore rules (0.07725ms)\n✔ returns one function so osx-sign does not discard the ignore option (0.054667ms)\n✔ both desktop builders resolve the signing hook from the GUI project (0.374375ms)\n✔ production provider construction disables implicit updater actions (1.305084ms)\n✔ bundled reconciliation rejects unqualified manifests before Core (0.970542ms)\n✔ electron-updater adapter disables implicit download and install (5.191459ms)\n✔ release-manifest resolution errors stay on the adapter event surface (0.659792ms)\n✔ published manifest resolver binds updater version and platform (1.091292ms)\n✔ unqualified remote manifests fail closed before download (0.351459ms)\n✔ manifest resolver rejects a cross-platform release identity (0.138166ms)\n✔ CLI bridge stays inside runtime upgrade and carries stale-plan fences (3.949875ms)\n✔ desktop installer handoff requires a Core download plan (1.542667ms)\n✔ installer handoff replans after download before restarting the app (0.359042ms)\n✔ update-not-available revokes stale download authority (0.471167ms)\n✔ an unsolicited available event cannot grant transport authority (0.105958ms)\n✔ a stale available event cannot replace an active download (0.55675ms)\n✔ a delayed available plan cannot replace Core reconciliation (0.410583ms)\n✔ a delayed available-plan failure cannot erase Core reconciliation (0.21725ms)\n✔ a second check invalidates an earlier pending available plan (0.164208ms)\n✔ an unsolicited downloaded event cannot grant installer authority (0.193ms)\n✔ stale progress cannot revive a revoked download (0.221375ms)\n✔ a failed update check clears previous transport authority (0.241208ms)\n✔ a failed updater download revokes transport authority (0.213583ms)\n✔ an updater error event revokes transport authority (0.18575ms)\n✔ stale updater events cannot erase an active Core receipt (0.2785ms)\n✔ a failed installer handoff revokes transport authority (0.267916ms)\n✔ a restarted check returns to idle without stale authority (0.0705ms)\n✔ a restarted downloaded update must re-enter the updater download path (0.281667ms)\n✔ a restarted in-progress download becomes an explicit retry (0.06625ms)\n✔ a persisted available update requires a fresh updater check (0.112791ms)\n✔ an incoherent restarted download fails closed (0.059666ms)\n✔ an interrupted installer handoff is never replayed automatically (0.0945ms)\n✔ event persistence failure becomes a recoverable in-memory error (0.176042ms)\n✔ download does not start when its state cannot be persisted (0.153042ms)\n✔ concurrent reconciliation of one release stages only once (0.253083ms)\n✔ concurrent reconciliation rejects a different release identity (0.159292ms)\n✔ reentrant reconciliation during install joins the active release (0.134583ms)\n✔ an update check cannot replace active runtime reconciliation (0.145833ms)\n✔ an update check cannot overlap an active download (0.131291ms)\n✔ runtime reconciliation cannot overlap an active download (0.130667ms)\n✔ startup reconciliation activates only an idle Core plan (0.116334ms)\n✔ active incompatible work defers without staging or killing work (0.110708ms)\n✔ readiness failure is reconciled through the Core rollback receipt (0.118459ms)\n✔ a readiness probe crash is reconciled as a failed readiness check (0.607334ms)\n✔ a bundled runtime install failure revokes stale update authority (0.191833ms)\n✔ a Core reconcile failure preserves the current recovery receipt (0.252125ms)\n✔ a persisted reconciling receipt resumes without staging again (0.109625ms)\n✔ a staged receipt cannot cross a changed release identity (0.12375ms)\n✔ a stale downloaded target cannot replace the current Core plan (0.145417ms)\n✔ a downloaded manifest must preserve the exact planned release identity (0.094834ms)\n✔ release identity comparison ignores JSON object key order (0.109709ms)\n✔ a failed Core plan becomes recoverable controller state (3.34225ms)\n✔ saved desktop update state round-trips through the canonical file (2.235959ms)\n✔ a truncated canonical state recovers as an explainable error (1.643917ms)\n✔ a schema-valid but incomplete state cannot regain update authority (1.022667ms)\n✔ an interrupted temporary write cannot replace canonical state (1.50325ms)\n✔ bundled manifest binds exact runtime bytes and source product identity (3.067208ms)\n✔ bundled manifest binds internal symlinks and rejects tree escape (13.176125ms)\n✔ desktop finalization binds installer bytes and stays fail-closed locally (7.555625ms)\n✔ external manifest asset names are deterministic and platform-specific (0.099459ms)\n✔ CLI finalization adds an exact archive without losing desktop evidence (3.992041ms)\n✔ both desktop builders retain the bundled upgrade identity outside runtime (0.738917ms)\nℹ tests 69\nℹ suites 0\nℹ pass 69\nℹ fail 0\nℹ cancelled 0\nℹ skipped 0\nℹ todo 0\nℹ duration_ms 270.956792\n\n[source-acceptance] tooling type check\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node node_modules/typescript/bin/tsc -p tsconfig.tools.json\n\n[source-acceptance] changed web source format and lint\n[source-acceptance] $ /Users/dkr/.local/opt/node-v24.16.0-darwin-arm64/bin/node node_modules/@biomejs/biome/bin/biome check --no-errors-on-unmatched developer/sdk/src/sdk.js scripts/adr-migration.mjs scripts/adr-migration.test.mjs scripts/check-kfd7-library-boundary.test.mjs\nChecked 4 files in 59ms. No fixes applied.\n\n[source-acceptance] build-free source gate passed\\n- TAP version 13\n# Subtest: plans deterministic ID-only renames from an exact Git tree\nok 1 - plans deterministic ID-only renames from an exact Git tree\n  ---\n  duration_ms: 593.557333\n  type: 'test'\n  ...\n# Subtest: keeps regeneration declarations immutable across plans\nok 2 - keeps regeneration declarations immutable across plans\n  ---\n  duration_ms: 515.054791\n  type: 'test'\n  ...\n# Subtest: applies a reviewed manifest idempotently and preserves historical bytes\nok 3 - applies a reviewed manifest idempotently and preserves historical bytes\n  ---\n  duration_ms: 478.664417\n  type: 'test'\n  ...\n# Subtest: completes only after declared regeneration checks and output closure\nok 4 - completes only after declared regeneration checks and output closure\n  ---\n  duration_ms: 439.196542\n  type: 'test'\n  ...\n# Subtest: fails closed on expected-root or working-file drift\nok 5 - fails closed on expected-root or working-file drift\n  ---\n  duration_ms: 370.668083\n  type: 'test'\n  ...\n# Subtest: fails closed unless the legacy publication pattern occurs exactly once\nok 6 - fails closed unless the legacy publication pattern occurs exactly once\n  ---\n  duration_ms: 901.794166\n  type: 'test'\n  ...\n# Subtest: fails closed when revision rewriting changes a target ADR root again\nok 7 - fails closed when revision rewriting changes a target ADR root again\n  ---\n  duration_ms: 426.984875\n  type: 'test'\n  ...\n1..7\n# tests 7\n# suites 0\n# pass 7\n# fail 0\n# cancelled 0\n# skipped 0\n# todo 0\n# duration_ms 3784.047542\\n- TAP version 13\n# KFD-7 library boundary contract: ok\n# Subtest: scripts/check-kfd7-library-boundary.test.mjs\nok 1 - scripts/check-kfd7-library-boundary.test.mjs\n  ---\n  duration_ms: 176.15\n  type: 'test'\n  ...\n1..1\n# tests 1\n# suites 0\n# pass 1\n# fail 0\n# cancelled 0\n# skipped 0\n# todo 0\n# duration_ms 180.954417\\n- {\n  \"schema\": \"kungfu.sdk.contract-policy-write/v1\",\n  \"ok\": true,\n  \"source\": \"framework/contract/kungfu-agent-first-canonical-policy.json\",\n  \"artifact\": \"config/kungfu-agent-first-canonical-policy.json\",\n  \"previousHash\": \"sha256:e77be4fdea188eac89bcf697992e6e82cdf66c0324eeebdd50825fece5251fef\",\n  \"previousArtifactHash\": \"sha256:e77be4fdea188eac89bcf697992e6e82cdf66c0324eeebdd50825fece5251fef\",\n  \"hash\": \"sha256:e77be4fdea188eac89bcf697992e6e82cdf66c0324eeebdd50825fece5251fef\",\n  \"artifactHash\": \"sha256:e77be4fdea188eac89bcf697992e6e82cdf66c0324eeebdd50825fece5251fef\",\n  \"changed\": false\n}\\n- {\n  \"schema\": \"kungfu.sdk.contract-policy-check/v1\",\n  \"ok\": true,\n  \"status\": \"current\",\n  \"source\": \"framework/contract/kungfu-agent-first-canonical-policy.json\",\n  \"artifact\": \"config/kungfu-agent-first-canonical-policy.json\",\n  \"hash\": \"sha256:e77be4fdea188eac89bcf697992e6e82cdf66c0324eeebdd50825fece5251fef\",\n  \"artifactHash\": \"sha256:e77be4fdea188eac89bcf697992e6e82cdf66c0324eeebdd50825fece5251fef\",\n  \"renderedHash\": \"sha256:e77be4fdea188eac89bcf697992e6e82cdf66c0324eeebdd50825fece5251fef\"\n}\\n- staged pre-commit gate",
          "author": "dongkeren",
          "createdAt": "2026-07-23T16:47:33Z",
          "mergedAt": "2026-07-23T17:00:25Z",
          "additions": 99,
          "deletions": 13,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1367,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1367",
          "title": "fix(cli): refresh installed help catalog roots",
          "body": "## Summary\n\n- refresh the generated CLI surface catalog for the current `cut` and `update` help summaries\n- propagate the resulting catalog digest through KFD-2 release claims and KFD-3 prebuild evidence\n- restore packaged `--help-json` parity with `agent capabilities --json`\n- replace #1365 with a single linear commit because the dev merge queue uses `REBASE`; #1365 had a correct final tree but its merge-resolution history was rejected as `merge_conflict`\n\n## Evidence\n\nThe real macOS Alpha build run `30022985357` completed product packaging but failed product CLI qualification because the packaged live Click tree and checked-in Agent catalog had different contract roots. The exact drift was limited to existing command summaries.\n\n## Validation\n\n- native-backed `./shifu test:cli-surface-contract` (29 passed)\n- `./shifu kfd:buildchain`\n- `./shifu check:source`\n- staged commit gate\n- linear history: exactly one commit above current `dev/v4/v4.0`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This refreshes generated CLI surface and KFD evidence after existing command help changes without changing product or architecture contracts.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T17:15:45Z",
          "mergedAt": "2026-07-23T17:22:25Z",
          "additions": 18,
          "deletions": 18,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1370,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1370",
          "title": "fix(adr): close migration source formatting",
          "body": "<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"Close deterministic web-source formatting inside ADR migration plan and apply roots\"}\n-->\n\n## Summary\n\n- format rewritten JS, TS, JSON, and CSS bytes with the exact source-snapshot Biome policy before sealing migration afterRoot values\n- pin the installed formatter to the exact repository version and invoke the native platform binary with a bounded timeout\n- preserve deterministic plans across working-tree config drift and cover line-width, formatter-version, and idempotent-apply behavior\n\n## Verification\n\n- `./shifu adr:migrate:test`\n- real 152-record plan generated twice byte-identically with 0 problems\n- `./shifu check:source`\n- staged pre-commit gate",
          "author": "dongkeren",
          "createdAt": "2026-07-23T17:59:03Z",
          "mergedAt": "2026-07-23T18:05:30Z",
          "additions": 329,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1369,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1369",
          "title": "fix(ci): defer macOS signature verification to credential island",
          "body": "## Summary\n\n- treat the declared macOS credential island as the final signature authority\n- keep the pre-sign release probe structural and fail closed on incomplete policy\n- preserve local codesign verification when no credential-island policy is declared\n\n## Verification\n\n- `node --test scripts/run-release-qualification.test.mjs`\n- `node --test scripts/alpha-promotion-preflight.test.mjs product/scripts/cli-surface-qualification.test.mjs scripts/upgrade-publication-admission.test.mjs`\n- repository pre-commit `check:staged`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This restores the declared credential-island verification boundary without changing product or architecture contracts.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T17:55:26Z",
          "mergedAt": "2026-07-23T18:08:26Z",
          "additions": 191,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1371,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1371",
          "title": "ci(dev): deduplicate exact merge-group native proofs",
          "body": "## Summary\n\nDeduplicate repeated native validation only when the same merge-group candidate is retried with an exact proof identity. The proof remains fail-closed across base, candidate source tree, affected plan, partitions, and the complete observed hosted toolchain.\n\n## Related issue\n\nAtlas goal: 2026-07-17-kungfu-dev-gate-latency-slo\n\nSupersedes #1368 after dev advanced again. This successor replays only the proof change, local Go hierarchy CLI bridge, and WorkRef completion fix on exact dev base `e621c0a0ed`, then creates one fresh parentless Project Cut. No cross-base proof or Cut reuse is introduced.\n\n## Changes\n\n- Scope duplicate-run concurrency to the identical merge-group head SHA with `cancel-in-progress:false`.\n- Reuse one successful merge-group native proof only after exact repository, event, candidate SHA, base/source trees, plan, partition, runner image, compiler, CMake, and Ninja checks.\n- Carry the probe descriptor unchanged into aggregate admission; independently recheck base/source/plan without substituting a later non-native runner's toolchain.\n- Require every native shard receipt to match the complete probe toolchain, including hosted `ImageVersion`.\n- Keep changed bases, ambiguous artifacts, incomplete identities, and every lookup/download/verification failure on the full-run path.\n- Document that base-forward proof reuse is forbidden.\n- Carry the owning workspace identity root through the Atlas compatibility CLI so parent/dependency WorkRefs remain exact under the current Mission Control contract.\n- Make tracked completion recognize exact `parent_assignment_ref` WorkRefs while retaining legacy `parent_goal_id` compatibility.\n\n## Verification\n\n- Focused gate-latency suite passed 36/36.\n- WorkRef parent regression passed 1/1; Python format and lint passed.\n- Complete staged repository gate passed 99/99 on the current base; the focused gate-latency suite passed 36/36.\n- Parentless Project Cut `34ef532f734e4a8d4a77f77cc52842dfef94f7afe76e626e0091c915b607d9ff` binds source projection `24b5fed03ba2e8e35f3de2b5ab1bf781c47bc735a51a6da58e9cd3cdd5be0296`, published commit `d29da1ec94787b414dcb9ae46c91aeadc01f1d1b`, and empty diagnostics.\n- Completion Claim `completion-816fd0a000fc8be7511e69c1` binds the exact published commit and proof root `eb1147377cc6b3438ef27de9434a9e1429023b4f20b788f68544ca5a852f5084`.\n- Prior merge-group evidence proved moved bases remain `reuse:false` and take the full-run path.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Bind native proof reuse to one exact merge-group candidate and toolchain without base-forward semantics\",\n  \"verification\": [\"./shifu test:gate-latency\", \"WorkRef parent regression\", \"full staged repository gate 99/99\", \"Project Cut 34ef532f\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release-evidence boundary is constrained by exact proof identity validation and fail-closed fallback to a full native run.\n\n## Expected first queue observation\n\nThe first merge-group run for this PR must report `reuse:false` and execute all required native shards. Reuse is only expected on a retry of that unchanged exact merge-group SHA.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T18:16:33Z",
          "mergedAt": "2026-07-23T18:59:30Z",
          "additions": 569,
          "deletions": 84,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1372,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1372",
          "title": "fix(adr): close native source formatting in migration",
          "body": "<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"Close deterministic Python and C/C++ source formatting inside ADR migration plan and apply roots\"}\n-->\n\n## Summary\n\n- bind ADR migration Python formatting to the source snapshot Ruff lock and pyproject policy\n- bind C/C++ formatting to the source snapshot clang-format lock and style policy\n- support exact preinstalled CI formatters with a locked uv fallback\n- include formatted Python/C++ bytes in deterministic afterRoot closure\n- add migration fixtures covering both source families\n\n## Verification\n\n- `./shifu adr:migrate:test` (9/9)\n- direct preinstalled Ruff/clang-format test lane (9/9)\n- two byte-identical real-repository migration plans, 0 problems\n- `./shifu check:source`\n\nADR-neutral migration tooling fix.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T18:47:48Z",
          "mergedAt": "2026-07-23T19:03:11Z",
          "additions": 189,
          "deletions": 31,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1581,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1581",
          "title": "fix(ci): disable credential input recompression",
          "body": "## Summary\n\nDisable outer artifact recompression for the already sealed macOS credential-island ZIP. This avoids a redundant streaming compression layer during the large cross-runner signer handoff.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- set `compression-level: 0` on the sealed credential input upload\n- lock the behavior in the credential-island workflow contract test\n- document why the handoff does not recompress the sealed ZIP\n\n## Verification\n\n- `pnpm run check:workflows`\n- `pnpm run test:unit` (779 passed)\n- downstream evidence to follow from `train/v2/v2.3/macos-credential-island` at `3f0ac41e74aab335edd50ebcc4423d480cafa0eb`\n\n## Governance risk check\n\n- [x] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects only the credential-island artifact transport boundary. It does not add, expose, or move credential values.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-23T19:06:53Z",
          "mergedAt": "2026-07-23T19:14:57Z",
          "additions": 8,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1582,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1582",
          "title": "fix(release): promote macOS credential upload transport",
          "body": "Promotes the reviewed macOS credential-island upload transport fix into the v2.14 alpha channel.\n\nEvidence:\n- PR #1581 merged through the dev merge queue\n- PR checks: unit, workflow, generated-site contract\n- Queue run: https://github.com/kungfu-systems/buildchain/actions/runs/30037051218\n\nThis channel promotion is required because the change touches the outer reusable `.build.yml` workflow and cannot be validated by a runtime train alone.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T19:17:14Z",
          "mergedAt": "2026-07-23T19:20:23Z",
          "additions": 8,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1583,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1583",
          "title": "Release v2.14.17 from qualified v2.14.17-alpha.4",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.17-alpha.4`\n- Candidate SHA: `8d7ead86465c1dae2f6c4fd53ca1453ea979851f`\n- Selection: `latest-qualified`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-23T20:10:43Z",
          "mergedAt": "2026-07-23T20:12:03Z",
          "additions": 1121,
          "deletions": 96,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1373,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1373",
          "title": "fix(ci): consume credential upload workflow shell",
          "body": "## Summary\n\n- pin Build and release promotion to the reviewed Buildchain `v2.14.17-alpha.9` workflow shell\n- consume the credential-island input upload transport fix from Buildchain PR #1582\n- refresh the closed-world workflow authority and binding contracts atomically\n- admit GitHub-hosted runner image rollouts without weakening OS, architecture, compiler, CMake, or Ninja identity checks\n\n## Queue finding\n\nThe first authoritative queue run, `30038897328`, completed both affected-native partitions successfully, then exposed a nondeterministic cross-job identity mismatch: the probe job ran image `20260720.247.2`, while both partition jobs ran image `20260714.240.1`. GitHub can assign independent jobs from adjacent hosted image rollout revisions.\n\nThe v3 proof identity excludes only volatile `runner.imageVersion` from cross-job compatibility. Every partition receipt still retains the observed image version, and stable runner/toolchain drift remains fail-closed. The actual failed-run artifacts replayed successfully with proof root `sha256:bea38fe2a86460abf1af5a275bd12a212aa02e828357b02832d21a1e2c007dd5`.\n\n## Verification\n\n- `./shifu check:gate-catalog`\n- `node --test scripts/release-promotion-rehearsal.test.mjs`\n- `node --test scripts/affected-native-proof.test.mjs` (8/8)\n- replay of both real partition receipts from queue run `30038897328`\n- `./shifu check:source`\n- repository pre-commit `check:staged`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This updates one reviewed immutable Buildchain workflow shell and corrects volatile hosted-runner proof identity without changing Kungfu product or architecture contracts.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T19:36:34Z",
          "mergedAt": "2026-07-23T20:34:42Z",
          "additions": 67,
          "deletions": 16,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1375,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1375",
          "title": "fix(cli): refresh generated surface authority",
          "body": "## Summary\n\n- refresh the checked-in CLI surface catalog after the `create-go` option expansion\n- refresh the exact projected surface root and dependent KFD evidence\n- restore equality between installed human help roots and Agent capabilities\n\n## Failure evidence\n\nAlpha diagnostic Build run `30042835074` failed closed during product dist with `human help roots do not match the Agent catalog`; the credential-island signing job was safely skipped.\n\n## Verification\n\n- `./shifu check:cli-catalog-parity`\n- live `help_projection` and Agent catalog root equality assertion\n- `node --test product/scripts/cli-surface-qualification.test.mjs`\n- `./shifu check:source`\n- repository pre-commit `check:staged`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This refreshes generated CLI and KFD projections after an already-merged additive option; it does not change product or architecture semantics.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T20:54:09Z",
          "mergedAt": "2026-07-23T21:28:06Z",
          "additions": 28,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1584,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1584",
          "title": "fix(artifacts): upload sealed macOS app directly",
          "body": "## Summary\n- upload the pre-sealed macOS app ZIP with upload-artifact v7 direct-file mode\n- transfer the source-bound credential manifest as a separate small artifact\n- reconstruct the same signer input root without checkout or consumer code execution\n\n## Motivation\nTwo exact-source Kungfu alpha attempts completed build and verification but the outer archive stream failed with `write EPIPE` while uploading the 259 MB sealed input. Direct-file upload avoids the redundant archive stream while preserving the manifest digest and size checks.\n\n## Validation\n- `pnpm check`\n- 779 unit tests passed\n- workflow lint and five bundled-action integrity checks passed\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-23T22:40:51Z",
          "mergedAt": "2026-07-23T22:45:59Z",
          "additions": 34,
          "deletions": 11,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1585,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1585",
          "title": "fix(release): promote direct macOS credential upload",
          "body": "Promotes the reviewed direct-file credential-island handoff into the v2.14 alpha channel.\n\nEvidence:\n- PR #1584 merged through the dev merge queue\n- Queue run: https://github.com/kungfu-systems/buildchain/actions/runs/30050907645\n- Full Buildchain check: workflow lint, generated contract, 779 unit tests, and five bundled-action integrity checks\n- Two exact-source Kungfu alpha attempts proved the previous outer archive stream failed with `write EPIPE`; this change uses the official upload-artifact v7 single-file direct mode while keeping the manifest digest/size verification and no-checkout signer boundary.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-23T22:47:29Z",
          "mergedAt": "2026-07-23T22:50:43Z",
          "additions": 34,
          "deletions": 11,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1376,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1376",
          "title": "fix(ci): pin direct macOS credential upload runtime",
          "body": "## Summary\n\n- pin the alpha Build and release-promotion consumers to Buildchain `v2.14.18-alpha.0` (`8aa540bc2bed4a94b3755c7328bef70ee40de80f`)\n- adopt the direct single-file credential-island upload transport from Buildchain PR #1584/#1585\n- refresh the source-bound workflow authority, workflow bindings, and promotion rehearsal contract\n\n## Failure evidence\n\nMac-only Build run `30046454214` failed twice while streaming the redundant outer artifact archive (`write EPIPE`); the sealed unsigned ZIP had already been built and verified, and the signer job did not start.\n\n## Verification\n\n- `./shifu check:gate-catalog`\n- `node --test scripts/release-promotion-rehearsal.test.mjs` (9/9)\n- `./shifu check:source`\n- repository pre-commit `check:staged`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This updates an immutable Buildchain runtime pin and its generated workflow authority projections without changing Kungfu product or architecture semantics.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-23T23:06:10Z",
          "mergedAt": "2026-07-23T23:27:04Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1374,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1374",
          "title": "docs(adr): cut over corpus to UUIDv7 identities",
          "body": "<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"SHIFU-ADR-019f86ff-a8d6-7431-ae05-0ec95fdb7ace\"],\"summary\":\"Cut over the existing ADR corpus and current canonical references to deterministic UUIDv7 identities with ID-only filenames\",\"verification\":[\"./shifu adr:migrate:test\",\"./shifu adr:identity:test\",\"./shifu adr:audit -- --json\",\"./shifu invariant:verify -- --sync-roots --json\",\"./shifu check:cli-catalog-parity\",\"./shifu check\"]}\n-->\n\n## Summary\n\n- migrate 152 canonical ADR records to deterministic UUIDv7 identities\n- rename 140 legacy ADR files to ID-only paths and rewrite 456 current canonical references\n- preserve historical aliases and append-only evidence according to the migration policy\n- repair four invalid generated stub annotations exposed by source-completion mypy\n\n## Migration receipts\n\n- source root: `sha256:2cc3a2b9ecf4528e88e2fba35dd6fcbfdd159be93f69f114fdec936b3082c16a`\n- manifest root: `sha256:3184817d9c58832dfb8eb0ae90e5206b1eb30285809837e999c5debcb65c6d2d`\n- result root: `sha256:eb8a2d00d08c21adf6e28e96c86eeb165b014890391f906351ef63352449d745`\n- converged Git tree: `4a023505c8758403c14d62d0b0df4f9312572b89`\n\n## Verification\n\n- `./shifu adr:migrate:test`\n- `./shifu adr:identity:test`\n- `./shifu adr:audit -- --json`\n- `./shifu invariant:verify -- --sync-roots --json`\n- `./shifu check:cli-catalog-parity`\n- `./shifu check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-23T20:39:46Z",
          "mergedAt": "2026-07-24T00:07:06Z",
          "additions": 3443,
          "deletions": 3519,
          "changedFiles": 490
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1378,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1378",
          "title": "chore(project-cut): seal ADR corpus identity rewrite",
          "body": "<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"Publish exact Project Cut and successor Xinfa Atlas artifacts for the already merged ADR corpus migration\"}\n-->\n\n## Summary\n\n- seal the exact Project Cut for the UUIDv7 ADR corpus migration\n- publish successor Xinfa Atlas baseline `sha256:d235086afa2bf3bcb2015294e404b952716ab1b67e0590277063bddfbee02fea`\n- bind cut `sha256:0da7ed18c971338f91f137408bbab76f8cfab34ffbed86c5ed703653866a5aaf` to the merged migration tree\n\n## Verification\n\n- `node framework/project-cut/bin/project-cut.mjs verify --state .kungfu/runtime/project-cut/settlements/0da7ed18c971338f91f137408bbab76f8cfab34ffbed86c5ed703653866a5aaf/state.json --root \"$PWD\" --json`\n- `./shifu check:staged`\n- `git diff --cached --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-24T00:07:51Z",
          "mergedAt": "2026-07-24T00:18:34Z",
          "additions": 7,
          "deletions": 0,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1586,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1586",
          "title": "fix(artifacts): relay macOS credential input through S3",
          "body": "## Summary\n- relay the sealed macOS credential-island input through the existing S3 handoff on self-hosted runners\n- upload the verified input as a distinct GitHub artifact from the hosted relay job\n- keep the direct GitHub artifact path unchanged and fail closed before signing if relay fails\n\n## Verification\n- `corepack pnpm@11.7.0 check`\n- `node --test tests/build-surface.test.mjs tests/macos-credential-island.test.mjs` (93/93)\n- `corepack pnpm@11.7.0 run check:workflows`\n- `node scripts/check-action-bundles.mjs`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-24T00:17:13Z",
          "mergedAt": "2026-07-24T00:22:00Z",
          "additions": 68,
          "deletions": 9,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1587,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1587",
          "title": "release: promote v2.14 dev to alpha",
          "body": "## Summary\nPromote the verified `dev/v2/v2.14` head to `alpha/v2/v2.14`.\n\nIncludes the macOS credential-island S3 handoff from #1586.\n\n## Source\n- dev SHA: `35af8043bbb4532e82cdbfbeddd336518d3c627a`\n- queue verification: https://github.com/kungfu-systems/buildchain/actions/runs/30055894956",
          "author": "dongkeren",
          "createdAt": "2026-07-24T00:22:32Z",
          "mergedAt": "2026-07-24T00:25:27Z",
          "additions": 68,
          "deletions": 9,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1379,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1379",
          "title": "fix(assignment): preserve native admission diagnostics",
          "body": "## Summary\n- route source Assignment commands through the current checkout's complete `pykungfu` assembly and keep cold-checkout failures machine-readable\n- preserve intentional structured CLI exits instead of wrapping them as a second diagnosis\n- refresh a newly initialized workspace identity before resolving local Assignment references\n\n## Related issue\n\nNative Initiative/Assignment admission qualification.\n\n## Changes\n\n- require both the binding and build metadata before source Assignment dispatch\n- return one actionable JSON diagnosis for missing or partial assemblies\n- isolate first-write regression tests from the developer workspace catalog\n\n## Verification\n\n- `./shifu test:shifu-xinfa-source` (26 passed)\n- `PYTHONPATH=framework/core/build/Release:framework/core/src/python ./shifu exec -- uv run --project framework/core --frozen pytest -q framework/core/tests/python/test_assignment_orchestration.py` (14 passed)\n- `./shifu check:source`\n- native dogfood: capture, current-checkout admission, claim, kickoff, and run gate\n- independent review: approved after two findings were resolved\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix restores the existing native Assignment admission contract without changing an architecture decision.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not required; diagnostics preserve the documented contract)\n\nMade with [Cursor](https://cursor.com)",
          "author": "dongkeren",
          "createdAt": "2026-07-24T00:19:43Z",
          "mergedAt": "2026-07-24T00:48:06Z",
          "additions": 134,
          "deletions": 8,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1381,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1381",
          "title": "fix(ci): pin S3 credential relay runtime",
          "body": "## Summary\n\n- pin Build and release promotion to Buildchain `v2.14.18-alpha.1` runtime `0484f4516d6d68a04b72d89a370df2f88cb9db4c`\n- refresh workflow authority digests and bindings\n- bind the promotion rehearsal contract to the same immutable runtime\n\n## Provenance\n\n- Buildchain implementation: https://github.com/kungfu-systems/buildchain/pull/1586\n- Buildchain alpha promotion: https://github.com/kungfu-systems/buildchain/pull/1587\n- Buildchain promotion run: https://github.com/kungfu-systems/buildchain/actions/runs/30056198732\n\n## Verification\n\n- `./shifu gate:workflow-authority:refresh`\n- `./shifu check:gate-catalog`\n- `./shifu release:promotion:rehearse`\n- `./shifu check:source`\n- staged repository gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This updates an immutable Buildchain runtime pin and its generated workflow authority projections without changing Kungfu product or architecture semantics.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-24T00:39:01Z",
          "mergedAt": "2026-07-24T01:06:21Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 118,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/118",
          "title": "feat(about): publish Kungfu bootstrap essay",
          "body": "## Summary\n\nPublish a deep About essay that explains Kungfu as a bootstrapping system for durable agent work, while keeping current evidence, strategic hypotheses, and long-term aspirations visibly separate.\n\n## Changes\n\n- add `/about/bootstrapping/` with an agent-assisted reading prompt and a falsifiable account of the bootstrap thesis\n- acknowledge Douglas Engelbart's bootstrapping and collective-intelligence work with primary-source links\n- add a restrained deep-reading entry from `/about/`\n- add route and content assertions to the site build and check scripts\n- document the public/private and maturity boundaries in the repository README\n\n## Verification\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `git diff --check`\n- Playwright at 1440x1000 and 390x844: no horizontal overflow and no console errors or warnings\n- official Douglas Engelbart Institute references returned HTTP 200\n\n## Governance risk check\n\n- [x] Changes official branding, naming, redirects, or domain behavior\n- [x] Touches release evidence, provenance, publication, or deployment surfaces\n- [ ] Changes legal, privacy, data handling, or compliance language\n- [ ] Changes commercial, pricing, licensing, sponsorship, or fund-raising language\n- [ ] Adds or changes executable code, automation, or runtime behavior\n- [ ] Creates or changes external operational dependencies\n\nThe page uses only public sources and public product concepts. It does not expose Atlas, Mission/go coordination, private company material, or unpublished operating details. Product maturity is stated conservatively: Kungfu v4 remains coming soon, and existing slices are not represented as one generally available product.\n\n## Checklist\n\n- [x] Content scope is explicit.\n- [x] Verification steps are recorded.\n- [x] Public/private boundary has been reviewed.\n- [x] Maturity claims have been reviewed.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T01:49:17Z",
          "mergedAt": "2026-07-24T01:53:07Z",
          "additions": 376,
          "deletions": 2,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 119,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/119",
          "title": "Release production from 5cfab821f42e",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `5cfab821f42e790f432fc04cdffb91ac63923e2d`\n- Artifact hash: `1ea1361be0bab497f0e4de7d8226c712ce0203c2d2158f79f37621a72ca8b5dd`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30060156034)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-5cfab821f42e`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-24T01:55:14Z",
          "mergedAt": "2026-07-24T01:58:05Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1588,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1588",
          "title": "feat(governance): seal GitHub authority receipts",
          "body": "## Summary\n\n- define a versioned, public-safe GitHub governance authority and explicit TCB/non-claims\n- aggregate CODEOWNERS, classic protection, rulesets, roles, plan capability, and API completeness into short-lived immutable receipts\n- add root-bound rollout/rollback planning plus scheduled and PR/merge-group drift enforcement\n- require exact qualifying governance receipts before release, package, paper, binary, or web production publication\n- protect the authority, auditor, rollout planner, and publication consumer with @kungfu-origin CODEOWNERS\n\n## Bootstrap state\n\nThe exact pre-rollout audit remains fail-closed: 0 of 16 managed repositories qualify. This PR installs the verifier and consumer hooks; it does not claim that live organization policy has already been reconciled. Private repositories remain anonymous and non-authoritative on the current unsupported plan.\n\nNo branch protection, organization role, billing plan, repository visibility, Environment, or Actions setting is changed by this PR.\n\n## Verification\n\n- pnpm run check (791 tests, inventory/site/workflow/action-bundle checks passed)\n- exact read-only 16-repository audit bound to commit 792741b337a325eda531d624c78d9b20184e84ec\n- git diff --check\n\n## Rollout safety\n\nLive protection changes require a fresh read-only inventory, frozen rollback snapshot, exact plan root confirmation, post-change read-back, and stop-on-drift behavior. The existing affected-native base/candidate merge-tree proof identity is unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T02:14:27Z",
          "mergedAt": "2026-07-24T02:18:13Z",
          "additions": 2636,
          "deletions": 96,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1590,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1590",
          "title": "fix(governance): preserve required check app bindings",
          "body": "## Summary\n\n- preserve the observed GitHub App id for existing required checks\n- require an explicit positive app id for every newly added required check\n- compare context and app_id together during post-apply read-back\n- reject context-only plans that would broaden which producer can satisfy a gate\n\n## Why\n\nThe initial rollout planner serialized every check with app_id null. That would weaken the existing check binding even when the context text stayed unchanged. No live protection mutation was executed with that plan.\n\n## Verification\n\n- pnpm run check (793 tests and all generated-surface checks passed)\n- targeted governance tests cover preservation, explicit new bindings, invalid ids, and read-back shape\n- git diff --check\n\nNo live GitHub setting is changed by this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T02:22:15Z",
          "mergedAt": "2026-07-24T02:25:32Z",
          "additions": 120,
          "deletions": 24,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1591,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1591",
          "title": "fix(governance): enforce classic bypass removal",
          "body": "## Summary\n\n- include classic branch-protection bypass allowances in the effective governance policy\n- write explicit empty user/team/App bypass allowances during reconciliation\n- require post-apply read-back to prove every classic bypass list is empty\n- add regression coverage for classic bypass detection and explicit removal bodies\n\n## Live canary finding\n\nThe first bounded Buildchain canary showed that GitHub preserves bypass allowances when the PUT body omits that field. The old verifier incorrectly emitted an applied receipt. The exact frozen rollback was executed immediately and restored the original branch protection before this PR was opened. No bulk rollout followed.\n\n## Verification\n\n- pnpm run check (794 tests and all generated-surface checks passed)\n- targeted classic bypass and rollout tests\n- rollback receipt plus live read-back confirmed restoration\n\nThis PR itself changes no live GitHub setting.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T02:28:25Z",
          "mergedAt": "2026-07-24T02:31:51Z",
          "additions": 86,
          "deletions": 15,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1392,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1392",
          "title": "fix(shifu): keep Windows quality dispatch reachable",
          "body": "Restore the Windows `xinfa:quality` dispatch used by the required merge-queue workspace check. The implementation block is mechanically moved next to the route table, and the entry contract now preserves that placement.\n\nValidation:\n- `./shifu xinfa:quality --check`\n- Shifu entry/lifecycle contract tests\n- `./shifu check:source`\n- pre-commit gates\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repositions an existing Windows batch dispatch target and adds a regression assertion without changing architecture, runtime, protocol, qualification, or release contracts\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-24T02:28:33Z",
          "mergedAt": "2026-07-24T02:36:30Z",
          "additions": 41,
          "deletions": 31,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1592,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1592",
          "title": "feat(governance): add root-bound ruleset rollback",
          "body": "## Summary\n- add source-bound planning for removing ruleset bypass actors\n- preserve the full observed ruleset and carry an exact inverse rollback\n- fail closed on snapshot, plan, or live-state drift before applying\n\n## Validation\n- `pnpm run check` (795 tests, 5 action bundles)\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-24T02:38:11Z",
          "mergedAt": "2026-07-24T02:42:04Z",
          "additions": 297,
          "deletions": 23,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1395,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1395",
          "title": "fix(shifu): bypass adjacent quality target",
          "body": "Restore ordinary Windows command dispatch after the `xinfa:quality` target was moved next to the route table. Without the explicit bypass, `shifu.cmd gate run ...` falls through into the quality argument parser.\n\nThis adds one `goto projectcut` and a regression assertion that preserves both routes.\n\nValidation:\n- Shifu entry/lifecycle contract tests\n- `./shifu check:source`\n- pre-commit gates\n- failure reproduced from Windows merge-group run `30062072460`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Restores existing Windows batch control flow and adds a regression assertion without changing architecture, runtime, protocol, qualification, or release contracts\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-24T02:43:22Z",
          "mergedAt": "2026-07-24T02:49:48Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 121,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/121",
          "title": "chore(governance): add code owner authority",
          "body": "## Summary\n- assign site ownership to `@kungfu-origin`\n- explicitly protect CODEOWNERS, deployment workflow, and site build/check surfaces\n\n## Validation\n- CODEOWNERS owner resolves as an active organization member\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-24T02:50:17Z",
          "mergedAt": "2026-07-24T02:52:58Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 73,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/73",
          "title": "chore(governance): add code owner authority",
          "body": "## Summary\n- assign paper ownership to `@kungfu-origin`\n- explicitly protect CODEOWNERS, workflows, Buildchain locks, and publication surfaces\n\n## Validation\n- CODEOWNERS owner resolves as an active organization member\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-24T02:54:37Z",
          "mergedAt": "2026-07-24T02:56:31Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 117,
          "url": "https://github.com/kungfu-systems/libnode/pull/117",
          "title": "chore(governance): add code owner authority",
          "body": "## Summary\n- assign repository ownership to `@kungfu-origin`\n- explicitly protect CODEOWNERS, workflow, Buildchain contract, and release-control surfaces\n\n## Validation\n- CODEOWNERS owner resolves as an active organization member\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-24T02:47:41Z",
          "mergedAt": "2026-07-24T02:59:14Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 10,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/10",
          "title": "chore(governance): add code owner authority",
          "body": "## Summary\n- assign tap ownership to `@kungfu-origin`\n- explicitly protect CODEOWNERS, workflows, Buildchain locks, managed updater, and tap manifest\n\n## Validation\n- `node scripts/check-tap.mjs`\n- `git diff --check`\n- CODEOWNERS owner resolves as an active organization member\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-24T02:58:16Z",
          "mergedAt": "2026-07-24T03:00:56Z",
          "additions": 11,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1387,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1387",
          "title": "docs(concepts): explain Kungfu self-bootstrap",
          "body": "## Summary\n\nAdd a public deep-reading article that explains Kungfu as a bootstrapping system: agents help build the infrastructure that makes later agent work more durable, inspectable, and recoverable. The article separates present evidence, strategic hypotheses, and long-term aspirations, and it does not disclose private coordination material.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add `docs/concepts/bootstrapping-agent-work.md`\n- provide an agent-assisted reading prompt for readers who want a plain-language or critical interpretation\n- distinguish Session continuity from Work continuity and explain Kungfu's Fact/Claim/Proof/Decision/Admission boundary\n- acknowledge Douglas Engelbart's bootstrapping and collective-intelligence work using primary-source links\n- route the article from the repository README, docs reading order, docs map, and concepts index\n- register the document in the public metadata registry\n\n## Verification\n\n- `./shifu docs inventory --json`\n- `./shifu docs context --task \"Explain Kungfu as a bootstrapping system for durable agent work\" --role implementer --budget 30000 --route kungfu-agent-surfaces --json`\n- `./shifu docs:check`\n- `./shifu docs:prose` (0 errors; advisory warnings only)\n- `./shifu check:source`\n- repository pre-commit gate, including documentation, invariant, and source checks\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Adds an explanatory public document and navigation links without changing any runtime, protocol, architecture, qualification, or release contract\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\nThe article is an explanatory public document. It preserves the existing product contract and states maturity boundaries conservatively.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T01:49:58Z",
          "mergedAt": "2026-07-24T03:01:59Z",
          "additions": 289,
          "deletions": 6,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 300,
          "url": "https://github.com/kungfu-systems/build-images/pull/300",
          "title": "chore(governance): add code owner authority",
          "body": "## Summary\n- assign image-pipeline ownership to `@kungfu-origin`\n- explicitly protect CODEOWNERS, workflows, Buildchain, publish scripts, and release policy\n\n## Validation\n- `pnpm run check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-24T03:04:17Z",
          "mergedAt": "2026-07-24T03:05:25Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 261,
          "url": "https://github.com/kungfu-systems/kfd/pull/261",
          "title": "chore(governance): add code owner authority",
          "body": "## Summary\n- assign canonical KFD stewardship to `@kungfu-origin`\n- explicitly protect CODEOWNERS, workflows, governance, decisions, schemas, and release controls\n\n## Validation\n- `node scripts/check.mjs`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-24T03:04:32Z",
          "mergedAt": "2026-07-24T03:16:46Z",
          "additions": 14,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 53,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/53",
          "title": "chore(governance): add code owner authority",
          "body": "## Summary\n- assign Hub implementation ownership to `@kungfu-origin`\n- explicitly protect CODEOWNERS, workflows, Buildchain config, package, and release surfaces\n\n## Validation\n- `npm run check` (14 tests, runtime-100, build)\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-24T03:04:47Z",
          "mergedAt": "2026-07-24T03:16:50Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-episodes-to-primitives",
          "number": 9,
          "url": "https://github.com/kungfu-systems/paper-episodes-to-primitives/pull/9",
          "title": "chore(governance): bootstrap code owner authority",
          "body": "## Summary\n- assign repository ownership to `@kungfu-origin`\n- add a minimal public-safe governance check for the otherwise empty bootstrap repository\n- explicitly protect CODEOWNERS and the governance workflow from ownership self-modification\n\n## Validation\n- workflow YAML parses locally\n- governance assertions pass locally\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-24T03:11:08Z",
          "mergedAt": "2026-07-24T03:16:54Z",
          "additions": 33,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 66,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/66",
          "title": "chore(governance): add code owner authority",
          "body": "## Summary\n- assign research-paper ownership to `@kungfu-origin`\n- explicitly protect CODEOWNERS, workflows, Buildchain locks, and publication surfaces\n\n## Validation\n- `make check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-24T03:10:48Z",
          "mergedAt": "2026-07-24T03:18:57Z",
          "additions": 75,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 73,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/73",
          "title": "chore(governance): add code owner authority",
          "body": "## Summary\n- assign white-paper ownership to `@kungfu-origin`\n- explicitly protect CODEOWNERS, workflows, Buildchain locks, and release-impact surfaces\n\n## Validation\n- `make check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-24T03:10:34Z",
          "mergedAt": "2026-07-24T03:20:00Z",
          "additions": 76,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 202,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/202",
          "title": "chore(governance): add code owner authority",
          "body": "## Summary\n- assign developer-site ownership to `@kungfu-origin`\n- explicitly protect CODEOWNERS, workflows, Buildchain config, deployment, and dogfood publication surfaces\n\n## Validation\n- `pnpm run build`\n- `pnpm run check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-24T03:10:20Z",
          "mergedAt": "2026-07-24T03:21:40Z",
          "additions": 11,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1396,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1396",
          "title": "fix(mission-control): authenticate native completion evidence",
          "body": "## Summary\n- authenticate native Assignment completion evidence from the sealed fact source and exact work-definition root\n- include native child Assignments through workspace-scoped parent references\n- reject legacy authority fields and cross-workspace or forged native projections\n\n## Verification\n- `./shifu check`\n- focused Mission Control storage tests (2 passed)\n- Ruff format and lint checks\n- independent review: approved after all findings were resolved\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix enforces the existing native Assignment completion-review authority without changing an architecture decision.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not required; this restores the existing contract)\n\nMade with [Cursor](https://cursor.com)",
          "author": "dongkeren",
          "createdAt": "2026-07-24T03:00:01Z",
          "mergedAt": "2026-07-24T03:26:20Z",
          "additions": 217,
          "deletions": 7,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1386,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1386",
          "title": "refactor(adr): complete UUIDv7 identity cutover",
          "body": "<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"SHIFU-ADR-019f86ff-a8d6-7431-ae05-0ec95fdb7ace\"],\"summary\":\"Remove ADR identity transition surfaces and qualify canonical UUIDv7-only authority\",\"verification\":[\"./shifu adr:identity:test\",\"./shifu adr:audit -- --json\",\"./shifu docs:check\",\"./shifu check:source\"]}\n-->\n\n## Summary\n\n- remove the frozen sequential identity inventory and one-time migration command/tests\n- accept only canonical owner-prefixed UUIDv7 identities and ID-only paths\n- reject retired sequential identity tokens across current tracked authority while preserving content-addressed historical stores\n- rewrite remaining current source, documentation, and fixture references to canonical identities\n- remove the KFD-7 merge-base migration compatibility parser\n\n## Concurrency qualification\n\n- 100 UUIDv7 identities generated at one fixed timestamp remain unique\n- 128 independent writers converge byte-for-byte under forward and reverse application order\n- two real Git branches merge in both orders without identity or shared-index conflict\n\n## Verification\n\n- `./shifu adr:identity:test`\n- `./shifu adr:audit -- --json` (`152` records, `0` structural findings)\n- `./shifu docs:check`\n- `./shifu check:source`\n- KFD Buildchain and durability evidence regenerated and checked\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T01:33:04Z",
          "mergedAt": "2026-07-24T04:23:07Z",
          "additions": 604,
          "deletions": 3775,
          "changedFiles": 88
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1593,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1593",
          "title": "fix(governance): bind managed targets to live authority",
          "body": "## Summary\n\n- bind every managed public target to its exact branch, required check contexts, GitHub App producers, and strict-update policy\n- admit private repositories by stable provider identity roots while keeping Free-plan enforcement non-qualifying\n- collect branch and organization inventory across pages and publish only a freshly recollected App-authenticated audit\n- constrain generated channel bookkeeping to the exact GitHub Actions App and reject user, team, or alternate App bypass actors\n- harden release-line bootstrap protection and CODEOWNERS coverage for every governance mutation surface\n\n## Validation\n\n- `pnpm run check` (802 tests, 5 action bundles)\n- live `buildchain` `dev/v2/v2.14` audit: exact `check` / App 15368 binding passed; only development least privilege remains non-qualifying\n- full live inventory audit: 16 repositories, 36 authoritative targets, 0 qualifying before rollout and human gates\n\n## Boundaries\n\nThis change does not demote the development administrator, enforce private repositories on the current Free plan, or enable the Governance receipt as a required check. Those actions remain gated by the independent recovery rehearsal, paid-plan capability, and dedicated read-only Governance Auditor App installation.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T04:30:26Z",
          "mergedAt": "2026-07-24T04:34:04Z",
          "additions": 1061,
          "deletions": 399,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1397,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1397",
          "title": "docs(adr): close identity implementation",
          "body": "<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"implemented\",\"adrs\":[\"SHIFU-ADR-019f86ff-a8d6-7431-ae05-0ec95fdb7ace\"],\"summary\":\"Bind the completed UUIDv7 ADR identity cutover to its reachable implementation, review, and qualification evidence\",\"verification\":[\"./shifu adr:audit -- --json\",\"node --test scripts/document-metadata-contract.test.mjs scripts/adr-release-gate.test.mjs\",\"./shifu check:source\"]}\n-->\n\n## Summary\n\n- mark the distributed UUIDv7 ADR identity decision implemented\n- bind all five rebased implementation commits and merged PR #1386\n- bind the exact qualification report and executable tests\n- record maintainer review and the implemented body projection\n\n## Verification\n\n- ADR audit: 152 records, 0 structural findings, 41 implemented\n- metadata and release-gate tests: 40/40\n- source acceptance: 84/85 plus isolated promotion rehearsal 9/9; the sole combined-run failure was the known shared Git branch/tag concurrency race\n- PR #1386 merge-group: full native shards, KFD, and Windows/macOS/Ubuntu Shifu matrix passed",
          "author": "dongkeren",
          "createdAt": "2026-07-24T04:27:51Z",
          "mergedAt": "2026-07-24T04:43:02Z",
          "additions": 9,
          "deletions": 5,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1594,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1594",
          "title": "fix(governance): compile effective ruleset rollout",
          "body": "## Summary\n\n- compile one exact repository ruleset from the admitted target governance descriptor\n- replace user/team drift with the exact target-bound App authority set\n- preserve unrelated rules and exact branch conditions while tightening review and check policy\n- keep rollback frozen and root-bound\n\n## Verification\n\n- `node --test tests/github-governance-authority.test.mjs`\n- `pnpm run generate:site`\n- `pnpm run check` (803 tests, 5 action bundles)\n- read-only live plan canary for Buildchain `alpha/v2/v2.14` ruleset `19518955`\n\nThe live canary performed no GitHub mutation.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T04:49:43Z",
          "mergedAt": "2026-07-24T04:54:12Z",
          "additions": 415,
          "deletions": 51,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1595,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1595",
          "title": "feat(web-surface): qualify installer publications",
          "body": "## Summary\n\nAdd a reusable Buildchain seam that validates bootstrap installer publication manifests, protects immutable paths, applies explicit cache metadata, and verifies public route bytes after deployment.\n\n## Related issue\n\nAtlas Goal 2026-07-24-kungfu-cli-signed-bootstrap-installer\n\n## Changes\n\n- validate friendly and immutable installer bytes against one source-bound publication manifest\n- fail closed unless immutable installer paths are covered by append-only archive policy\n- publish immutable assets with one-year immutable caching and friendly routes with short must-revalidate caching\n- add public read-back evidence for bytes, content type, cache, redirects, ETag, and object version identity\n- regenerate the checked-in site bundle\n\n## Verification\n\n- pnpm run check: 660 tests passed and four Actions built\n- installer and web-surface focused tests: 52 passed\n- AWS CLI locally confirms sync supports no-overwrite, content-type, and cache-control\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change plans existing S3 and CloudFront operations only. No credentials or infrastructure policy changes are included.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-24T04:56:47Z",
          "mergedAt": "2026-07-24T04:59:41Z",
          "additions": 868,
          "deletions": 23,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1596,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1596",
          "title": "fix(governance): separate ruleset bypass boundary",
          "body": "## Summary\n\n- distinguish an effective-policy allowlist from the desired actor set for one provider layer\n- default repository ruleset reconciliation to no bypass actors\n- keep explicit installed-App actor compilation independently tested\n- document that the built-in GitHub Actions allowance, when needed, belongs to classic branch protection\n\n## Verification\n\n- `node --test tests/github-governance-authority.test.mjs`\n- `pnpm run generate:site`\n- `pnpm run check` (803 tests, 5 action bundles)\n- read-only live plan canary for Buildchain `alpha/v2/v2.14` ruleset `19518955`\n\nThe live canary performed no GitHub mutation.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T04:58:36Z",
          "mergedAt": "2026-07-24T05:02:10Z",
          "additions": 49,
          "deletions": 27,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 123,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/123",
          "title": "feat(site): add CLI installation surface",
          "body": "## Summary\n\nAdd the canonical Kungfu CLI installation page and navigation while explicitly keeping installer routes unavailable until protected Alpha publication and public read-back complete.\n\n## Changes\n\n- add the public installation and first-stage trust page\n- document future POSIX and PowerShell convenience routes without claiming they are live\n- describe immutable inspection, ownership, and no-silent-mutation boundaries\n- add Install CLI to shared navigation and build checks\n\n## Verification\n\n- pnpm run build: passed\n- pnpm run check: passed\n- shared layout, infra output, white paper, dogfood proof, and trademark checks: passed\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe page deliberately leaves install.sh and install.ps1 absent. It does not publish product bytes or make an unqualified release claim.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-24T04:56:49Z",
          "mergedAt": "2026-07-24T05:05:40Z",
          "additions": 197,
          "deletions": 2,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1597,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1597",
          "title": "feat(web-surface): qualify signed installer publication",
          "body": "## Summary\n\n- validate Kungfu signed bootstrap publication manifests and exact friendly/immutable byte agreement\n- preserve installer evidence roots in web-surface manifests and public read-back\n- publish immutable installer roots with one-year immutable cache metadata and friendly routes with bounded revalidation\n- retain the v2.14 generic immutable cache-control behavior for non-installer archives\n- document and test the cross-repository ownership boundary\n- remove the governance workflow's pre-Corepack pnpm cache request, which otherwise deterministically failed every PR before audit execution\n\n## Release-line correction\n\nPR #1595 carried the source change to the historical v2.12 line. This PR ports the reviewed change to the active v2.14 development line consumed by `v2-alpha` and site-kungfu-tech. The port was regenerated against v2.14 and resolves its newer cache-control contract without merging release-line histories.\n\n## Verification\n\n- `pnpm run check`\n- 809 unit tests passed\n- generated site bundle check passed\n- `pnpm run check:workflows`\n- workflow and action bundle integrity checks passed\n\n## Safety\n\nBuildchain verifies and transports generated installer bytes; Kungfu remains the installer and signed-channel authority. No credential material or production mutation is introduced by this source PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:17:28Z",
          "mergedAt": "2026-07-24T05:26:18Z",
          "additions": 871,
          "deletions": 27,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1599,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1599",
          "title": "chore(release): promote v2.14 development to alpha",
          "body": "## Release intent\n\nPromote the current protected Buildchain v2.14 development line into Alpha.\n\nThis release includes the signed bootstrap installer publication seam required by Kungfu's public `/install.sh` and `/install.ps1` delivery, plus the intervening protected governance fixes already merged through the dev merge queue.\n\n## Exact source\n\n- source ref: `dev/v2/v2.14`\n- source SHA: `4fe7c40e89e9b0c755d803d68d217762208ce093`\n- target ref: `alpha/v2/v2.14`\n- current target SHA: `0484f4516d6d68a04b72d89a370df2f88cb9db4c`\n\n## Safety\n\nThe PR expresses release intent only. Buildchain's protected Alpha workflow must select the next version, run release verification, publish npm/exact and floating refs, and retain transaction evidence. No direct ref or package mutation is requested.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:27:12Z",
          "mergedAt": "2026-07-24T05:31:06Z",
          "additions": 5234,
          "deletions": 361,
          "changedFiles": 54
        },
        {
          "repository": "kungfu-systems/paper-episodes-to-primitives",
          "number": 10,
          "url": "https://github.com/kungfu-systems/paper-episodes-to-primitives/pull/10",
          "title": "chore(governance): add code owner authority",
          "body": "## Summary\n\nPropagate the exact authoritative CODEOWNERS source blob from `main` into the governed development line.\n\n## Safety\n\n- single-file change\n- exact source content; no ownership broadening\n- no required-check, bypass, or proof-identity relaxation",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:30:54Z",
          "mergedAt": "2026-07-24T05:32:11Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1394,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1394",
          "title": "feat(agent): qualify KFD Agent Hub 20",
          "body": "## Summary\n\nAdd a product-owned Kungfu Work Agent Hub profile and qualify its installed macOS arm64 artifact against the exact KFD Agent Hub 20 suite.\n\nThe first linear successor was #1383. After #1392 landed a different Windows dispatch fix, its temporary rescue commit no longer rebased cleanly. This v2 branch starts at #1392.s protected target and replays only the reviewed Agent Hub commits.\n\nThe result is deliberately bounded: one Kungfu artifact passes 20/20 vectors across two isolated local authority domains. It does not claim a second independent-product adoption.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add `kungfu agent hub`, `capabilities`, and `handle` surfaces over one product-owned Hub implementation\n- add a thin KFD adapter, exact alpha.46 lock, responsibility map, honest 0/20 baseline, and offline release verifier\n- regenerate KFD-3 capability and CLI catalogs\n- retain source-bound installed-product qualification evidence and document the embedding boundary\n- replay the reviewed delivery on the current UUIDv7 target and regenerate every derived catalog from that exact source\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu check:staged`\n- `./shifu test:kfd-agent-hub-20`\n- `./shifu kfd:agent-hub:qualify --kungfu /usr/local/bin/kungfu --output-dir tests/qualification/agent-hub-20/evidence/installed-macos-arm64-ff8f5e27f`\n- `./shifu kfd:agent-hub:verify --kungfu /usr/local/bin/kungfu --qualification-dir tests/qualification/agent-hub-20/evidence/installed-macos-arm64-ff8f5e27f`\n- installed artifact: 20/20, release gate valid, exact source `ff8f5e27f85fcdb23dc1f7d7ac6a3011d586d9fd`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-786d-aa24-a97705e13917\"],\n  \"summary\": \"Complete the bounded installed-product KFD Agent Hub 20 qualification stage without widening the reality-kernel boundary or external-adoption claim\",\n  \"verification\": [\"check:source\", \"check:staged\", \"KFD Agent Hub 20 installed-product qualification and offline verifier\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe retained evidence is source-bound, offline-verifiable, path/secret audited, and expressly limited to one installed Darwin arm64 artifact.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-24T02:40:18Z",
          "mergedAt": "2026-07-24T05:34:16Z",
          "additions": 6027,
          "deletions": 61,
          "changedFiles": 48
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 262,
          "url": "https://github.com/kungfu-systems/kfd/pull/262",
          "title": "chore(governance): promote code owner authority to alpha",
          "body": "## Summary\n\nPromote the independently reviewed CODEOWNERS authority from the governed development line to alpha.\n\n## Scope\n\n- forward-only channel promotion\n- exactly the CODEOWNERS authority commit and its merge commit\n- no required check, bypass, or proof-identity relaxation",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:30:12Z",
          "mergedAt": "2026-07-24T05:38:06Z",
          "additions": 14,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 54,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/54",
          "title": "chore(governance): promote code owner authority to alpha",
          "body": "## Summary\n\nPromote the independently reviewed CODEOWNERS authority from the governed development line to alpha.\n\n## Scope\n\n- forward-only channel promotion\n- exactly the CODEOWNERS authority commit and its merge commit\n- no required check, bypass, or proof-identity relaxation",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:30:14Z",
          "mergedAt": "2026-07-24T05:38:11Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-episodes-to-primitives",
          "number": 12,
          "url": "https://github.com/kungfu-systems/paper-episodes-to-primitives/pull/12",
          "title": "chore(governance): promote code owner authority to alpha",
          "body": "## Summary\n\nPromote the independently reviewed CODEOWNERS authority from the governed development line to alpha.\n\n## Scope\n\n- forward-only channel promotion\n- exactly the CODEOWNERS authority commit and its merge commit\n- no required-check, bypass, or proof-identity relaxation",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:33:19Z",
          "mergedAt": "2026-07-24T05:38:17Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 68,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/68",
          "title": "chore(governance): add code owner authority",
          "body": "## Summary\n\nPropagate the exact authoritative CODEOWNERS source blob from `main` into the governed development line.\n\n## Safety\n\n- single-file change\n- exact source content; no ownership broadening\n- no required-check, bypass, or proof-identity relaxation",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:32:32Z",
          "mergedAt": "2026-07-24T05:38:22Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 74,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/74",
          "title": "chore(governance): add code owner authority",
          "body": "## Summary\n\nPropagate the exact authoritative CODEOWNERS source blob from `main` into the governed development line.\n\n## Safety\n\n- single-file change\n- exact source content; no ownership broadening\n- no required-check, bypass, or proof-identity relaxation",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:32:40Z",
          "mergedAt": "2026-07-24T05:38:27Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 74,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/74",
          "title": "chore(governance): add code owner authority",
          "body": "## Summary\n\nPropagate the exact authoritative CODEOWNERS source blob from `main` into the governed development line.\n\n## Safety\n\n- single-file change\n- exact source content; no ownership broadening\n- no required-check, bypass, or proof-identity relaxation",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:32:46Z",
          "mergedAt": "2026-07-24T05:38:32Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 119,
          "url": "https://github.com/kungfu-systems/libnode/pull/119",
          "title": "chore(governance): promote code owner authority to alpha",
          "body": "## Summary\n\nPromote the independently reviewed CODEOWNERS authority from the governed development line to alpha.\n\n## Scope\n\n- forward-only channel promotion\n- exactly the CODEOWNERS authority commit and its merge commit\n- no required check, bypass, or proof-identity relaxation",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:30:09Z",
          "mergedAt": "2026-07-24T05:41:58Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 70,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/70",
          "title": "chore(governance): promote code owner authority to alpha",
          "body": "## Summary\n\nPromote the independently reviewed CODEOWNERS authority from the governed development line to alpha.\n\n## Scope\n\n- forward-only channel promotion\n- exactly the CODEOWNERS authority commit and its merge commit\n- no required-check, bypass, or proof-identity relaxation",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:39:16Z",
          "mergedAt": "2026-07-24T05:42:02Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 75,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/75",
          "title": "chore(governance): promote code owner authority to alpha",
          "body": "## Summary\n\nPromote the independently reviewed CODEOWNERS authority from the governed development line to alpha.\n\n## Scope\n\n- forward-only channel promotion\n- exactly the CODEOWNERS authority commit and its merge commit\n- no required-check, bypass, or proof-identity relaxation",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:39:20Z",
          "mergedAt": "2026-07-24T05:42:07Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 75,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/75",
          "title": "chore(governance): promote code owner authority to alpha",
          "body": "## Summary\n\nPromote the independently reviewed CODEOWNERS authority from the governed development line to alpha.\n\n## Scope\n\n- forward-only channel promotion\n- exactly the CODEOWNERS authority commit and its merge commit\n- no required-check, bypass, or proof-identity relaxation",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:39:22Z",
          "mergedAt": "2026-07-24T05:42:12Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1601,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1601",
          "title": "feat(release): commit consumer publication authority last",
          "body": "## Summary\n- publish explicitly selected PR-stage payloads as immutable GitHub Release assets\n- add a fail-closed consumer publication commit point that runs only after artifacts and passports are public\n- validate exact source/release identity, canonical HTTPS read-back, payload root, and prior-authority recovery evidence\n\n## Safety\n- rejects a final authority commit when GitHub Release publication is disabled\n- rejects deferred standalone distribution after the authority commit\n- never interprets or logs the optional consumer publication credential\n- leaves the previous well-known authority authoritative when the consumer command fails\n\n## Verification\n- `pnpm run check` (813 tests, workflow checks, generated site contract, 5 action bundles)\n- targeted publication commit / RC resolver / router tests (116 passed)\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:47:20Z",
          "mergedAt": "2026-07-24T05:52:17Z",
          "additions": 718,
          "deletions": 50,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1603,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1603",
          "title": "feat(governance): compile classic protection policy",
          "body": "## Summary\n\nAdd an authoritative classic-branch-protection plan mode that compiles exact target policy instead of requiring manual check bindings.\n\n## Safety\n\n- preserves descriptor-declared App bindings and intentional `app_id: null` contexts\n- retains frozen inventory, plan root, snapshot root, drift check, read-back, and exact rollback\n- does not alter affected-native proof identity or reuse semantics\n\n## Validation\n\n- `node --test tests/github-governance-authority.test.mjs` (24/24)\n- `pnpm run check` (inventory, generated site, workflows, full unit suite, action bundles)\n- read-only Kungfu alpha plan preserved `build:null`, `signoff@15368`, and `validate@15368`",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:54:38Z",
          "mergedAt": "2026-07-24T06:02:10Z",
          "additions": 139,
          "deletions": 22,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1605,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1605",
          "title": "fix(governance): bind provider ruleset defaults",
          "body": "## Summary\n\nCompile GitHub provider canonical defaults when a managed pull-request or required-status-check rule is first synthesized.\n\n## Why\n\nThe dev ruleset PUT correctly produced the desired policy, but GitHub added documented provider defaults during read-back. The old expected root therefore failed closed after a successful write. This patch makes the frozen expected root match the exact provider representation.\n\n## Safety\n\n- existing rule parameters remain preserved\n- only defaults for newly synthesized managed rules are made explicit\n- bypass, checks, strictness, review settings, conditions, rollback, and unrelated rules retain their current semantics\n- no affected-native proof identity or reuse change\n\n## Validation\n\n- targeted governance tests 24/24\n- `pnpm run check`\n- live dev ruleset was recovered with a second canonical-state root-bound plan; targeted audit now fails only development least privilege",
          "author": "dongkeren",
          "createdAt": "2026-07-24T06:04:24Z",
          "mergedAt": "2026-07-24T06:08:36Z",
          "additions": 88,
          "deletions": 15,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1389,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1389",
          "title": "fix(core): stabilize generated binding annotations",
          "body": "## Summary\n\n- canonicalize host-dependent unresolved pybind11 stub annotations to `typing.Any`\n- preserve function-body and default-value ellipses\n- add the normalization case to the Core tooling suite\n\n## Failure evidence\n\n- alpha Build run `30058447310` built successfully but release verification failed because macOS stub generation changed tracked `runtime.pyi` from `typing.Any` to `...`\n- the patch was checked against the exact dirty stub retained by that runner; normalization reproduces the committed canonical bytes\n\n## Verification\n\n- Core tooling tests: 19 passed\n- `node node_modules/typescript/bin/tsc -p tsconfig.tools.json`\n- `node --test framework/core/tests/gen-stubs.test.js`\n- full `./shifu check:source` reached the final tooling type-check and the reported TS7006 was fixed and rechecked\n- staged repository gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This makes an existing generated binding-stub representation deterministic across build hosts without changing the binding, public API, or architecture semantics.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-24T02:00:49Z",
          "mergedAt": "2026-07-24T06:17:57Z",
          "additions": 51,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 301,
          "url": "https://github.com/kungfu-systems/build-images/pull/301",
          "title": "chore(governance): add alpha code owner authority",
          "body": "## Summary\n\nAdd the exact authoritative CODEOWNERS source blob to this protected target without merging unrelated channel history.\n\n## Safety\n\n- branch created from the frozen target base SHA\n- single-file `.github/CODEOWNERS` change\n- DCO-signed commit and independent `kungfu-origin` review\n- no direct protected-ref write, administrator merge, required-check relaxation, or affected-native proof change",
          "author": "dongkeren",
          "createdAt": "2026-07-24T06:19:36Z",
          "mergedAt": "2026-07-24T06:21:23Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 303,
          "url": "https://github.com/kungfu-systems/build-images/pull/303",
          "title": "chore(governance): add publish-gate code owner authority",
          "body": "## Summary\n\nAdd the exact authoritative CODEOWNERS source blob to this protected target without merging unrelated channel history.\n\n## Safety\n\n- branch created from the frozen target base SHA\n- single-file `.github/CODEOWNERS` change\n- DCO-signed commit and independent `kungfu-origin` review\n- no direct protected-ref write, administrator merge, required-check relaxation, or affected-native proof change",
          "author": "dongkeren",
          "createdAt": "2026-07-24T06:19:50Z",
          "mergedAt": "2026-07-24T06:21:29Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1606,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1606",
          "title": "chore(governance): add release code owner authority",
          "body": "## Summary\n\nAdd the exact authoritative CODEOWNERS source blob to this protected target without merging unrelated channel history.\n\n## Safety\n\n- branch created from the frozen target base SHA\n- single-file `.github/CODEOWNERS` change\n- DCO-signed commit and independent `kungfu-origin` review\n- no direct protected-ref write, administrator merge, required-check relaxation, or affected-native proof change",
          "author": "dongkeren",
          "createdAt": "2026-07-24T06:19:29Z",
          "mergedAt": "2026-07-24T06:22:42Z",
          "additions": 22,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 302,
          "url": "https://github.com/kungfu-systems/build-images/pull/302",
          "title": "chore(governance): add release code owner authority",
          "body": "## Summary\n\nAdd the exact authoritative CODEOWNERS source blob to this protected target without merging unrelated channel history.\n\n## Safety\n\n- branch created from the frozen target base SHA\n- single-file `.github/CODEOWNERS` change\n- DCO-signed commit and independent `kungfu-origin` review\n- no direct protected-ref write, administrator merge, required-check relaxation, or affected-native proof change",
          "author": "dongkeren",
          "createdAt": "2026-07-24T06:19:43Z",
          "mergedAt": "2026-07-24T06:22:48Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 55,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/55",
          "title": "fix(governance): restore release authority checks",
          "body": "## Summary\n\nRestore the exact authoritative CODEOWNERS source and the required `Verify` workflow on the historical release line.\n\n## Why two files\n\nThe release branch protection requires `check / check`, but the base branch had no `.github/workflows/verify.yml`; the first single-file PR correctly remained blocked even though its legacy build workflow passed. The workflow is copied byte-for-byte from the admitted alpha line so the protected required check can run.\n\n## Safety\n\n- branch created from the frozen release target base SHA\n- only `.github/CODEOWNERS` and `.github/workflows/verify.yml` change\n- both files are exact authoritative-source blobs\n- DCO-signed commits and a new independent `kungfu-origin` review after the latest push\n- no direct protected-ref write, administrator merge, required-check relaxation, or affected-native proof change",
          "author": "dongkeren",
          "createdAt": "2026-07-24T06:19:57Z",
          "mergedAt": "2026-07-24T06:27:42Z",
          "additions": 29,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 125,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/125",
          "title": "feat(release): project signed bootstrap publication",
          "body": "## Summary\n- verify the Ed25519 Alpha channel and exact installer publication before any site projection\n- preserve every immutable channel and installer prefix in the existing Buildchain archive-policy manifest\n- update only canonical mutable routes after all inputs pass and reject immutable byte replacement\n\n## Verification\n- `pnpm run build`\n- `pnpm run check`\n- 3/3 import boundary tests\n\nThis prepares the protected site publication consumer. It does not publish an Alpha channel or installer by itself.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T06:13:03Z",
          "mergedAt": "2026-07-24T06:36:45Z",
          "additions": 876,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 126,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/126",
          "title": "Release production from 6d3c513d556b",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `6d3c513d556b2d8b6e456ab074e64c6488d8013c`\n- Artifact hash: `f53fb6ec1871f3613ef7d5613b5afb0c53f380ef1d5a0b3342fe2b7efab3e027`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30072788466)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-6d3c513d556b`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-24T06:38:41Z",
          "mergedAt": "2026-07-24T06:41:24Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1604,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1604",
          "title": "fix(release): separate publication signing input",
          "body": "## Summary\n\nExpose the consumer publication dispatch/API credential and private channel-signing material as two independent reusable-workflow secrets.\n\n## Why\n\nThe final Kungfu publication command must sign the release channel under product ownership and then dispatch the already-signed static bundle to the site publication boundary. Reusing one secret slot for both would merge unrelated authority and make least-privilege review impossible.\n\n## Safety\n\n- both values are available only to the final publication commit command\n- Buildchain does not log, persist, or interpret either value\n- no signing material enters source, artifacts, Release Passport, or controller evidence\n\n## Verification\n\n- 97 targeted workflow/surface/router tests passed\n- inventory, generated site contract, and workflow validation passed\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:57:15Z",
          "mergedAt": "2026-07-24T06:42:33Z",
          "additions": 61,
          "deletions": 36,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1398,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1398",
          "title": "docs(adr): add generated human navigation map",
          "body": "## Summary\n\nAdd a generated, human-readable navigation map for the complete Kungfu ADR corpus.\nThe map uses progressive disclosure: a compact domain overview, explicit\nfrontmatter-authoritative `supersedes` relations, and expandable domain tables\nwith bounded navigation-only neighborhoods.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- generate `docs/architecture/adr-map.md` and `adr-map.json` from the canonical ADR audit\n- cover all 152 current ADRs across eight deterministic domains\n- hide UUID filenames behind decision titles and compact keys\n- label authoritative and inferred navigation relations separately\n- explain every navigation-only relation and cap each neighborhood at four ADRs\n- expose stable links from the documentation and ADR entrypoints\n- register paired Human and Agent Xinfa routes over the same exact surfaces\n- reject stale generated output in documentation and source gates\n\n## Verification\n\n- `./shifu adr:map:check`\n- `node --test scripts/adr-audit.test.mjs scripts/adr-navigation.test.mjs scripts/shifu-documentation-surfaces.test.mjs` (17/17)\n- `./shifu docs:check` (88/88)\n- `node --test --test-concurrency=1 scripts/release-promotion-rehearsal.test.mjs` (9/9)\n- `./shifu docs final-ready --since origin/dev/v4/v4.0 --parity-group kungfu-adr-navigation --human-route kungfu-adr-navigation-human --agent-route kungfu-adr-navigation-agent --intent \"browse ADR relationships\" --task \"independently review ADR navigation authority and coverage\" --budget 120000 --json` (paired routes complete and matched; review required)\n- independent exact-commit review: PASS, no blocking findings\n- required GitHub source-acceptance CI\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-7cef-a31b-bf3c50bd7cf7\",\n    \"SHIFU-ADR-019f86da-4f90-73bd-a6a9-5d39752151d6\"\n  ],\n  \"summary\": \"Implement a generated ADR navigation surface and paired Human/Agent Xinfa routes without creating a second semantic authority.\",\n  \"verification\": [\n    \"./shifu adr:map:check\",\n    \"./shifu docs:check\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T04:43:37Z",
          "mergedAt": "2026-07-24T06:44:11Z",
          "additions": 6936,
          "deletions": 9,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 263,
          "url": "https://github.com/kungfu-systems/kfd/pull/263",
          "title": "feat(agent-hub): expose first-party qualification path",
          "body": "## Summary\n- publish the direct `kungfu agent hub qualify/verify` product path in the Agent Hub authority, KFD-3 guide, package README, map, and generated site bundle\n- expose the same bounded command, ownership split, and non-certifying claim boundary to human and Agent readers\n- add quiet runner and file-output verifier internals for the bundled product projection without changing the public KFD CLI contract\n\n## Verification\n- `npm run check`\n- packaged Hub 20 run and offline verifier output-file smoke\n\n## Claim boundary\nThe KFD suite and verifier remain KFD-owned. Kungfu owns product behavior, isolated execution, artifact binding, and explanation. Passing is not certification, security assessment, production fitness, remote-network interoperability, external adoption, or unobserved-platform evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T06:42:33Z",
          "mergedAt": "2026-07-24T06:46:01Z",
          "additions": 220,
          "deletions": 105,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 264,
          "url": "https://github.com/kungfu-systems/kfd/pull/264",
          "title": "chore(kfd): anchor agent hub alpha 47",
          "body": "## Summary\n- advance the immutable KFD prerelease coordinate to `1.0.0-alpha.47`\n- publish the direct Kungfu Agent Hub qualification projection introduced by #263\n- regenerate KFD-1/2/3 witnesses against the alpha.47 package coordinate\n\n## Verification\n- `npm run update:evidence`\n- `npm run check`\n- `npm pack --dry-run --json`\n- `git diff --check`\n\n## Boundary\nThis release exposes an exact first-party product proof path. It does not establish KFD certification, security, production fitness, remote-network interoperability, external adoption, or unobserved-platform support.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T06:48:28Z",
          "mergedAt": "2026-07-24T06:51:46Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1607,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1607",
          "title": "fix(release): relay governance auditor credential",
          "body": "Declare the dedicated read-only governance auditor private-key secret through both reusable promotion workflow boundaries. This preserves fail-closed governance collection; it does not broaden permissions or add a bypass.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T06:45:44Z",
          "mergedAt": "2026-07-24T06:51:59Z",
          "additions": 55,
          "deletions": 24,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1602,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1602",
          "title": "chore(release): promote v2.14 publication commit point to alpha",
          "body": "## Summary\n\nPromote the protected `dev/v2/v2.14` head containing:\n\n- signed installer publication qualification\n- immutable PR-stage product payload uploads to GitHub Release\n- fail-closed final consumer publication authority commit and read-back evidence\n\n## Exact source\n\n- dev head: `20371fc75c03c87dc30ba54424b0c3d07834ee15`\n- source feature head: `82e911c3935c3a0081a57db5b7b7bbebe155536a`\n- tree parity: `a3025325d5034587385897aa57b1a41775e3bce2`\n\n## Publication boundary\n\nThe follow-on Buildchain promotion remains fail-closed until the dedicated read-only governance auditor GitHub App is configured. This PR does not bypass that gate and does not itself move npm or floating public tags.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T05:52:53Z",
          "mergedAt": "2026-07-24T06:57:15Z",
          "additions": 984,
          "deletions": 70,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 266,
          "url": "https://github.com/kungfu-systems/kfd/pull/266",
          "title": "docs(kfd): clarify alpha promotion actor sequencing",
          "body": "## Summary\n\n- record the actor sequencing required by the protected alpha promotion flow\n- preserve `dev/v1/v1.0` as the exact Buildchain source\n- avoid last-push approval deadlocks without bypassing branch protection\n\n## Verification\n\n- `git diff --check`\n\n## Release impact\n\nDocumentation-only release-governance clarification; no package or protocol surface changes.\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T06:59:01Z",
          "mergedAt": "2026-07-24T07:02:45Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 265,
          "url": "https://github.com/kungfu-systems/kfd/pull/265",
          "title": "release(kfd): promote Agent Hub alpha 47",
          "body": "## Release\nPromote reviewed `dev/v1/v1.0` to `alpha/v1/v1.0` for immutable `@kungfu-tech/kfd@1.0.0-alpha.47` publication.\n\n## Included surface\n- direct first-party `kungfu agent hub qualify/verify` discovery in KFD authority, KFD-3 guidance, and generated site bundle\n- human-first explanation plus stable machine command projection\n- explicit KFD-suite / Kungfu-product ownership split and non-certifying boundary\n- governance authority seal already merged on the dev line\n\n## Evidence\n- capability PR #263 independently approved, green, and merged\n- alpha.47 anchor PR #264 independently approved, green, and merged\n- full KFD package, verifier parity, clean extraction, Hub 20, and four-language starter checks passed\n- clean npm pack reports `@kungfu-tech/kfd@1.0.0-alpha.47`\n\n## Boundary\nThis promotion does not establish KFD certification, security, production fitness, remote-network interoperability, external adoption, or unobserved-platform support.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T06:52:09Z",
          "mergedAt": "2026-07-24T07:07:02Z",
          "additions": 253,
          "deletions": 132,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1609,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1609",
          "title": "fix(governance): remove dev merge queue human bypass",
          "body": "## Summary\n\n- remove the configured human bypass from the protected dev merge queue\n- lock the repository controller policy to zero app, user, and team bypass actors\n\n## Verification\n\n- `pnpm run check`\n- `node --test tests/dev-merge-queue.test.mjs tests/buildchain-config.test.mjs`\n- dry-run provider plan resolves `bypass_actors` to an empty array",
          "author": "dongkeren",
          "createdAt": "2026-07-24T07:07:48Z",
          "mergedAt": "2026-07-24T07:13:02Z",
          "additions": 20,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1399,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1399",
          "title": "chore(project-cut): publish ADR identity settlement",
          "body": "<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"implemented\",\"adrs\":[\"SHIFU-ADR-019f86ff-a8d6-7431-ae05-0ec95fdb7ace\"],\"summary\":\"Publish the self-contained Project Cut witness for the completed ADR identity qualification\",\"verification\":[\"./shifu check:source\",\"./shifu project-cut prepare --request <runtime-request> --json\"]}\n-->\n\n## Summary\n\n- publish the exact-root Project Cut settlement for ADR identity final qualification\n- preserve the admitted Xinfa Atlas root as a self-contained first published Cut\n- add no Product changes\n\n## Validation\n\n- dry-run and execute produced the same Cut root\n- full local pre-commit source checks passed through ADR/documentation qualification\n- `git diff --cached --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T04:55:01Z",
          "mergedAt": "2026-07-24T07:19:38Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 127,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/127",
          "title": "fix(site): retain version-addressed installer snapshots",
          "body": "Closes the remaining immutable-route acceptance gap for the signed Kungfu CLI bootstrap publication.\n\n- Require every installer snapshot path to include the exact product version and full signed channel payload root.\n- Record product version and payload root separately in the append-only public manifest.\n- Preserve byte-for-byte friendly/immutable verification and reject moving a published version.\n\nValidation: `npm run check`.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T07:20:32Z",
          "mergedAt": "2026-07-24T07:23:37Z",
          "additions": 37,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 128,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/128",
          "title": "Release production from 61868702e8c5",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `61868702e8c5a773de2b40f043c7fbd44f38cf49`\n- Artifact hash: `f53fb6ec1871f3613ef7d5613b5afb0c53f380ef1d5a0b3342fe2b7efab3e027`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30075315787)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-61868702e8c5`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-24T07:25:38Z",
          "mergedAt": "2026-07-24T07:28:21Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1401,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1401",
          "title": "fix(core): canonicalize generated enum fields",
          "body": "## Summary\n\n- commit the canonical `typing.Any` form produced for four unresolved enum-backed fields\n- extend stub normalization coverage to a class-field annotation\n- eliminate the exact `types.pyi` drift that blocked alpha release qualification\n\n## Failure evidence\n\n- alpha Build run `30072005023` built successfully but Episode qualification rejected a dirty source tree\n- the only tracked drift was `framework/core/stubs/pykungfu/yijinjing/types.pyi`\n- the patched file matches the exact runner-generated output byte-for-byte\n\n## Verification\n\n- `node --test framework/core/tests/gen-stubs.test.js`\n- `pnpm exec biome check --no-errors-on-unmatched framework/core/tests/gen-stubs.test.js`\n- complete staged repository gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This commits the existing deterministic representation for unresolved generated enum-backed annotations without changing the binding, public API, or architecture semantics.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-24T06:51:54Z",
          "mergedAt": "2026-07-24T07:55:31Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 129,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/129",
          "title": "feat(site): expose installed Agent Hub proof",
          "body": "## Summary\n\nGive every major kungfu.tech first entry a direct path to the installed Kungfu Agent Hub qualification. The new human page answers four immediate questions, while JSON and llms.txt preserve the same KFD-owned facts and bounded claim for Agents.\n\n## Changes\n\n- consume `@kungfu-tech/kfd@1.0.0-alpha.47` as the single Agent Hub fact authority\n- generate `/agent-hub/` and `/agent-hub.json`\n- append direct run/verify guidance to `/llms.txt`\n- add the proof path to the homepage, Agent Builders journey, and shared Developers navigation\n- keep certification, security, production fitness, remote networking, external adoption, and unobserved platforms outside the claim\n\n## Verification\n\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- desktop visual QA at 1440px: command, four questions, verifier, ownership boundary, no horizontal overflow\n- mobile visual QA at 390px: command wraps, no command or page overflow\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe site projects the exact KFD alpha.47 bundle and does not create a second suite, verdict, or release authority. Production deployment remains behind the repository Buildchain release flow.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T07:58:32Z",
          "mergedAt": "2026-07-24T08:12:10Z",
          "additions": 202,
          "deletions": 9,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 122,
          "url": "https://github.com/kungfu-systems/libnode/pull/122",
          "title": "chore(governance): add release code owner authority",
          "body": "## Summary\n\nAdd the exact authoritative CODEOWNERS source blob to this protected target without merging unrelated channel history.\n\n## Safety\n\n- branch created from the frozen target base SHA\n- single-file `.github/CODEOWNERS` change\n- DCO-signed commit and independent `kungfu-origin` review\n- no direct protected-ref write, administrator merge, required-check relaxation, or affected-native proof change",
          "author": "dongkeren",
          "createdAt": "2026-07-24T06:19:22Z",
          "mergedAt": "2026-07-24T08:22:07Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 130,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/130",
          "title": "Release production from e867043cf573",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `e867043cf5739fef3f19ff8a993538c13b965519`\n- Artifact hash: `febcadb0177f33fd2d873443261417eb1c942b090bb36b28f7aa420e0f82cc29`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30078094886)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-e867043cf573`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-24T08:14:28Z",
          "mergedAt": "2026-07-24T08:30:15Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1388,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1388",
          "title": "feat(core): weld generated artifacts and registries",
          "body": "## Summary\n\nWeld generated Work lifecycle SDK artifacts and generic framework-to-config registry projections to exact source roots. This provides reusable generator and registry infrastructure without absorbing domain item schemas or the Primitive Catalog compiler.\n\n## Related issue\n\nAtlas parent goal `2026-07-24-kungfu-repo-audit-closure` and child goal `2026-07-24-kungfu-welding-registry-infra`.\n\n## Changes\n\n- bind the Work lifecycle generator, its shared executable helper, and all four generated SDK outputs in the native contract\n- extract shared loading, canonical-root, output-set, generator-closure, and write/check operations while preserving existing layered and Work lifecycle output bytes\n- define `kungfu.registry-envelope/v1` with registry-specific schema validation, independently unique identity fields, exact projection roots, and fail-closed drift checks\n- migrate contract and invariant registries and make the config Work lifecycle matrix a scoped generated projection of the framework authority\n- publish a bounded adoption contract for future Primitive Catalog generator reuse\n- add negative tests for output mutation, shared-helper mutation, duplicate registry identities, projection drift, and unrelated scoped-write side effects\n\n## Verification\n\n- `./shifu check:source` (build-free source gate passed; 587 Node tests: 584 passed and 3 platform skips; 114 runtime upgrade tests; 69 desktop adapter tests)\n- `./shifu sdk:layered:check`\n- `./shifu sdk:work-lifecycle:check` (9/9)\n- `./shifu registry:check` (4/4)\n- `./shifu check:work-lifecycle-operation-matrix` (6/6)\n- TypeScript tooling check, Biome, documentation gate, and staged pre-commit gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f8c53-6105-71e5-8f34-53f2a81ee61c\"],\n  \"summary\": \"Weld the shared Work lifecycle SDK generator closure and registry projections without widening Core or domain authority.\",\n  \"verification\": [\"full source acceptance\", \"four-language Work lifecycle SDK root checks\", \"registry envelope schema and drift tests\", \"scoped projection side-effect test\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change welds source and generated artifact provenance only. It does not publish packages, deploy services, or widen release qualification claims.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T01:57:04Z",
          "mergedAt": "2026-07-24T08:31:19Z",
          "additions": 1153,
          "deletions": 72,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1611,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1611",
          "title": "fix(signing): load osx-sign commonjs runtime",
          "body": "## Summary\n- bundle the valid CommonJS entry of `@electron/osx-sign` into the ESM GitHub Action runtime\n- execute the committed credential-island bundle in regression tests\n- prevent recurrence of the `module is not defined` startup failure\n\n## Verification\n- `pnpm run check`\n- `node --test tests/macos-credential-island.test.mjs`\n\nThis contains no credentials or private signing material.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T08:32:39Z",
          "mergedAt": "2026-07-24T08:37:40Z",
          "additions": 88,
          "deletions": 66,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1612,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1612",
          "title": "release: promote v2.14 dev to alpha",
          "body": "## Summary\nPromote the verified `dev/v2/v2.14` head to `alpha/v2/v2.14`.\n\nIncludes the macOS credential-island bundle runtime fix from #1611.\n\n## Source\n- dev SHA: `7c0967875e2297df5ac2c107e562262beb02be5c`\n- merge queue verification: https://github.com/kungfu-systems/buildchain/actions/runs/30079496290",
          "author": "dongkeren",
          "createdAt": "2026-07-24T08:38:06Z",
          "mergedAt": "2026-07-24T08:39:45Z",
          "additions": 108,
          "deletions": 67,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 204,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/204",
          "title": "feat(kfd): publish alpha.47 Agent Hub qualification entry",
          "body": "## Outcome\n\nPublishes the KFD alpha.47 release propagation cut and renders its package-owned `agentHubPage` as a human and agent first-entry surface.\n\n## Human entry\n\n- adds `/agent-hub/` with installed Kungfu run and verify commands at the top;\n- puts the same commands on the KFD overview;\n- retains KFD ownership, 20-vector scope, and the non-certification claim boundary.\n\n## KFD-3 agent entry\n\n- adds Agent Hub to `manifest.json` human/agent entries and read order;\n- projects the full package-owned Agent Hub contract without site-owned semantic forks;\n- adds the run/verify commands, ownership, and boundary to `llms.txt`.\n\n## Release binding\n\n- `@kungfu-tech/kfd@1.0.0-alpha.47`\n- KFD source `b7e7773c9c310a6a30f70e83fb8b890d45cd63ba`\n- npm integrity `sha512-tFyFev5UKm2snujWB0FXwHkwLpKhWxmE16MPjn1zSyl0X/y7QTERG7oCL0TIBuMpKC20QnNi6r0oVKRawyQ7fA==`\n\n## Validation\n\n- exact alpha.47 `pnpm run build`\n- exact alpha.47 `pnpm run check`\n- `bash -n scripts/check-site.sh`\n- `shellcheck scripts/check-site.sh`\n- `git diff --check`\n- 1440x1100 rendered-page visual review\n\nReplaces #201 because that propagation PR was authored by the sole CODEOWNER and therefore could not satisfy independent CODEOWNER approval.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T08:37:41Z",
          "mergedAt": "2026-07-24T08:46:23Z",
          "additions": 199,
          "deletions": 19,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 131,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/131",
          "title": "feat(about): balance stewardship layout",
          "body": "## Summary\n\n- make Public and auditable the full-width foundation of the stewardship section\n- align Commercial stewardship and Capital & stewardship as equal sibling cards\n- add a restrained capital accent and a clearer Capital page call to action\n- preserve the mobile single-column reading flow and add structural checks\n\n## Validation\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- desktop visual check at 1440px\n- mobile visual check at 390px with no horizontal overflow",
          "author": "dongkeren",
          "createdAt": "2026-07-24T08:52:54Z",
          "mergedAt": "2026-07-24T08:56:46Z",
          "additions": 42,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 132,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/132",
          "title": "Release production from 788f82a57075",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `788f82a57075a49e00680c8f8286decc752e22c9`\n- Artifact hash: `33e0680dfd0fb358494287f6051aa4f24228f71ea2f6f32e44e9db5bea9f561e`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30080748268)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-788f82a57075`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-24T08:58:45Z",
          "mergedAt": "2026-07-24T09:01:44Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1613,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1613",
          "title": "chore(release): publish v3.0.0",
          "body": "## Summary\n\nPromote the protected `release/v2/v2.14` source line through the explicit major publication gate and publish Buildchain v3.0.0.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- merge `release/v2/v2.14` into `publish-gate/major`\n- let the protected post-verify promotion workflow create the exact v3.0.0 release state\n- create or move the v3 release and channel refs defined by the major-gate contract\n- prepare the next v3.0 alpha development state\n\nSource head: `eb6a87dd4e6e7603515f2a4195ac75534f54dad2`\nGate base before merge: `0fbe5b86304ca79b661cd0f0de313bcd882646e1`\n\n## Verification\n\n- require the release-pair verifier to accept `release/v2/v2.14 -> publish-gate/major`\n- require the repository required checks and Code Owner review\n- merge only through the normal protected pull-request path\n- verify the resulting exact tag, release record, floating refs, channel branches, and publication evidence\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis pull request is the explicit protected major-release authorization. No protection, bypass, or source-lock requirement is weakened.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-24T08:59:50Z",
          "mergedAt": "2026-07-24T09:01:53Z",
          "additions": 145225,
          "deletions": 16447,
          "changedFiles": 606
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 205,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/205",
          "title": "fix(hub): expose installed Agent Hub qualification",
          "body": "## Summary\n\n- expose the installed Kungfu Agent Hub qualification command directly on the libkungfu.dev Hub first entry\n- project the same run, verify, ownership, and claim-boundary facts into the root agent entry\n- fail closed when either first entry drifts from the KFD package-owned contract\n\n## Validation\n\n- exact @kungfu-tech/kfd@1.0.0-alpha.47 source preparation\n- pnpm install --frozen-lockfile\n- pnpm run build\n- pnpm run check\n- bash -n scripts/check-site.sh\n- shellcheck scripts/check-site.sh\n- node --check scripts/render-site.mjs\n- visual inspection at 1440x1100\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-24T08:51:18Z",
          "mergedAt": "2026-07-24T09:05:08Z",
          "additions": 27,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1382,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1382",
          "title": "feat(core): add derived primitive management plane",
          "body": "## Summary\n\n- derive one Root-bearing Primitive Catalog from six existing authorities without creating a second intake\n- inventory nine baseline primitives with honest language and maturity evidence, plus fail-closed promotion rules\n- weld the catalog into KFD-1, KFD-3, release admission, native action runtime, and a default-dry-run primitive birth command\n\n## Validation\n\n- `./shifu check:source` reached all implementation gates; its one transient promotion-rehearsal failure passed 9/9 on isolated rerun\n- pre-commit staged gate passed, including docs 99/99, KFD evidence, architecture, Biome, and clang-format\n- `./shifu build:core` passed and `kungfu_action_runtime_tests` passed\n- primitive catalog, gate catalog, and release admission targeted suites passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"KF-ADR-019f917f-d116-70e8-b4a1-2e0209598aec\"],\"summary\":\"Deliver the derived Primitive Catalog and evidence-backed lifecycle management plane\",\"verification\":[\"source acceptance, native runtime, KFD buildchain, release admission, documentation, and negative fixtures\"]}\n-->\n\n## Non-claims\n\n- no primitive is promoted beyond its retained evidence\n- this PR does not publish a Kungfu release or alter branch protection",
          "author": "dongkeren",
          "createdAt": "2026-07-24T00:44:15Z",
          "mergedAt": "2026-07-24T09:20:29Z",
          "additions": 2816,
          "deletions": 76,
          "changedFiles": 44
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 207,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/207",
          "title": "Release production from 3416c1f2b9ae",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `3416c1f2b9ae2046e609052d0e973ef97b5cb048`\n- Artifact hash: `8bd71bd4a46526d6a29f94aa27e4f8956e6beeefdf71ea82ee98eedf5904db51`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/30081271318)\n- Required label: `buildchain-release`\n- Release branch: `release/production-3416c1f2b9ae`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-24T09:18:58Z",
          "mergedAt": "2026-07-24T09:32:48Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1400,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1400",
          "title": "feat(release): add signed CLI bootstrap installers",
          "body": "## Summary\n\nAdd deterministic, signed-channel-bound POSIX and PowerShell bootstrap installers for the standalone Kungfu CLI. This PR implements source mechanics and documentation only; public routes remain unavailable until the protected Alpha publication and native qualification complete.\n\n## Related issue\n\nAtlas Goal 2026-07-24-kungfu-cli-signed-bootstrap-installer\n\n## Changes\n\n- generate immutable and friendly installer assets from one verified signed channel\n- verify staged archive bytes, product identity, platform trust, release roots, and Release Passport before activation\n- retain a rooted bootstrap receipt and expose it through update status\n- document ownership, first-stage trust, inspection, rollback, and honest pre-publication behavior\n\n## Verification\n\n- ./shifu test:release-channel: Node 17 passed; Python 115 passed\n- staged repository gate: passed\n- POSIX sh syntax and shellcheck fixtures: passed\n- Ruff and Biome checks: passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7718-8d1f-6402a87408a7\"],\n  \"summary\": \"Adds the signed-channel bootstrap projection without creating a second update authority\",\n  \"verification\": [\"release-channel and bootstrap negative tests\", \"staged repository gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo private signing material is present. Public trust anchors and release identities are admitted only through the existing signed channel.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-24T04:56:44Z",
          "mergedAt": "2026-07-24T09:43:55Z",
          "additions": 1616,
          "deletions": 9,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1405,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1405",
          "title": "docs: define format authority and ADR links",
          "body": "## Summary\n\nDefine one auditable human entry for the current `.kungfu` format authority,\nconnect it to Docs and Xinfa navigation, and make authored ADR citations\nclickable and regression-gated.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add a public `.kungfu` format status index that distinguishes implemented and\n  staged workspace contracts from the still pre-normative portable format;\n- add matching human/agent Xinfa routes, public metadata, and Docs map entries;\n- repair 170 ADR citations across 48 authored Markdown files without editing\n  generated or historical append-only material;\n- add a lifecycle-aware docs gate for naked, missing, malformed, and\n  target-mismatched ADR references, including code and inline-HTML exclusions.\n\n## Verification\n\n- `./shifu docs:check` (92/92 tests; 367 Markdown files)\n- `node --test scripts/adr-reference-links.test.mjs` (4/4)\n- `node scripts/adr-reference-links.mjs --check`\n- `./shifu adr:audit`\n- `./shifu adr:map:check`\n- `./shifu docs final-ready --since 70e1e59a21dba8ee0a330ed66a590cf037f0a819 --parity-group kungfu-format-contract --json`\n- independent read-only review: PASS\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This documentation and static-analysis change composes existing format and ADR identity authority without changing an ADR decision, implementation status, or release obligation.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T08:29:10Z",
          "mergedAt": "2026-07-24T10:11:00Z",
          "additions": 687,
          "deletions": 153,
          "changedFiles": 60
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1616,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1616",
          "title": "fix(ci): support caller-owned macOS signing",
          "body": "## Summary\n\n- add an explicit caller-owned macOS credential-island mode for cross-repository reusable workflows\n- keep sealing, source binding, immutable runtime upload, and artifact relay in Buildchain while delegating the protected signing job to the consumer workflow\n- keep the built-in signer compatible for same-repository environments and document the secret-boundary rationale\n\n## Verification\n\n- `node --test tests/macos-credential-island.test.mjs`\n- `pnpm run check:workflows`\n- `pnpm run check` (816 tests passed)\n\n## Security boundary\n\nCaller-owned mode does not pass signing credentials through `workflow_call` and does not widen environment secrets into repository secrets. The exported runtime and sealed input remain source- and runtime-bound.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T10:12:38Z",
          "mergedAt": "2026-07-24T10:16:53Z",
          "additions": 134,
          "deletions": 56,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1617,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1617",
          "title": "release(alpha): promote caller-owned macOS signing",
          "body": "## Promotion intent\n\nPromote the caller-owned credential-island mode from protected `dev/v2/v2.14` to `alpha/v2/v2.14`.\n\nSource dev head: `13851f742581078f41c22e7555eb7d9d18345503`\n\nThis keeps signing credentials in the Kungfu consumer environment while Buildchain exports only the immutable runtime and sealed source-bound application input.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T10:17:34Z",
          "mergedAt": "2026-07-24T10:19:38Z",
          "additions": 134,
          "deletions": 56,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1406,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1406",
          "title": "fix(ci): pin macOS signer bundle runtime",
          "body": "## Summary\n\n- pin Build and release promotion to the immutable Buildchain alpha branch runtime `2e57d4000c5ad4e410ae5495867570eeb2adb73d`\n- refresh workflow authority digests and structured Gate bindings\n- bind the promotion rehearsal contract to the same runtime\n\n## Provenance\n\n- Buildchain implementation: https://github.com/kungfu-systems/buildchain/pull/1611\n- Buildchain alpha promotion PR: https://github.com/kungfu-systems/buildchain/pull/1612\n- Buildchain alpha merge commit: `2e57d4000c5ad4e410ae5495867570eeb2adb73d`\n\nThe downstream tag transaction is independently blocked by the newly introduced, unconfigured governance auditor App. This PR uses the immutable alpha branch commit and does not weaken that gate.\n\n## Verification\n\n- `./shifu gate:workflow-authority:refresh`\n- `./shifu check:gate-catalog`\n- `./shifu release:promotion:rehearse`\n- `./shifu check:source`\n- staged repository gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This updates an immutable Buildchain runtime pin and its generated workflow authority projections without changing Kungfu product or architecture semantics.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-24T08:52:23Z",
          "mergedAt": "2026-07-24T10:28:00Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1618,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1618",
          "title": "fix(publication): verify non-strict ruleset transactions",
          "body": "## Summary\n\n- preserve the intentional non-strict alpha/release ruleset policy that avoids a source-up-to-date ancestry loop\n- require exact provider transaction evidence when a readable managed ruleset is non-strict\n- bind the merged PR, independent approval, required check producer/result, PR head SHA, source SHA, and protected target head\n- retain the existing static-policy path for strict rulesets\n\n## Failure reproduced\n\nBuildchain Ref Promotion run 30085849530 reached the managed publication control-plane audit and failed only `branch-policy`: the live alpha ruleset is intentionally non-strict, while the audit stopped before collecting the already-valid protected dev-to-alpha transaction.\n\n## Verification\n\n- `node --test tests/publication-control-plane-script.test.mjs tests/publication-authority.test.mjs tests/build-surface.test.mjs`\n- `pnpm run check`\n- positive regression: non-strict managed ruleset + exact protected transaction qualifies\n- negative regression: failed required check remains non-qualifying\n\nNo GitHub protection setting, ruleset, token, release ref, or artifact is changed by this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T10:35:23Z",
          "mergedAt": "2026-07-24T10:40:38Z",
          "additions": 130,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1619,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1619",
          "title": "chore(release): promote publication transaction audit to alpha",
          "body": "## Summary\n\nPromote the protected dev merge point containing PR #1618 to alpha so Buildchain Ref Promotion can re-evaluate the managed publication control plane with exact provider-transaction evidence.\n\n## Bound source\n\n- dev head: `fcd1ea922d5ba46a618fbcd259ecde569a1021a7`\n- included fix: PR #1618 / `fix(publication): verify non-strict ruleset transactions`\n- full `pnpm run check`: passed\n- merge-group `check`: passed\n- merge-group governance receipt: passed\n\nThis PR does not change GitHub rulesets or weaken the intentional non-strict alpha policy. Publication still fails closed unless merged PR lineage, independent approval, exact required-check producer/result, PR head SHA, and target head all match.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T10:41:14Z",
          "mergedAt": "2026-07-24T10:42:56Z",
          "additions": 130,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1408,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1408",
          "title": "fix(workspace): close installed Work graph",
          "body": "## Summary\n\n- read each Workspace through its pinned runtime and exact Profile root\n- aggregate complete, partial, unknown, degraded, and unavailable Work without false-zero results\n- bind dogfood receipts to the installed qualified Product and exact multi-root evidence\n- make local Product promotion fail closed and expose an executable exact rollback path\n\n## Validation\n\n- ./shifu check:source\n- staged pre-commit gate\n- cargo test --workspace\n- focused Python Workspace, Assignment, and update suites\n- live 35-component multi-root read and strict partial-result check\n\n## Governance\n\n- Release provenance / promotion changes reviewed: yes\n- Credential, signing, or release-island changes: no\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repairs installed-controller observability and fail-closed promotion within existing workspace federation and Product authority contracts; no ADR decision changes.\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T10:00:02Z",
          "mergedAt": "2026-07-24T11:07:30Z",
          "additions": 1908,
          "deletions": 160,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1621,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1621",
          "title": "fix(publication): recover protected version state through PRs",
          "body": "## Summary\n\n- recover strict Alpha target bookkeeping through a same-repository `buildchain/version-state/*` pull request when direct protected-ref updates are rejected\n- apply the same resumable PR path to the subsequent dev reconciliation step\n- keep exact and floating tags unmoved until the provider-enforced PR transaction lands, then allow an idempotent promotion rerun to continue\n- document the protected zero-bypass recovery behavior\n\n## Validation\n\n- `node --test tests/promote-buildchain-ref.test.mjs` (127 passed)\n- `pnpm run check` (819 passed; workflows, inventory, site bundle, and 5 action bundles passed)\n\nCloses #1620",
          "author": "dongkeren",
          "createdAt": "2026-07-24T11:10:21Z",
          "mergedAt": "2026-07-24T11:23:27Z",
          "additions": 236,
          "deletions": 109,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1622,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1622",
          "title": "fix(publication): recover protected version state through PRs",
          "body": "## Summary\n\n- recover strict Alpha target bookkeeping through a same-repository `buildchain/version-state/*` pull request when direct protected-ref updates are rejected\n- apply the same resumable PR path to the subsequent dev reconciliation step\n- keep exact and floating tags unmoved until the provider-enforced PR transaction lands, then allow an idempotent promotion rerun to continue\n- document the protected zero-bypass recovery behavior\n\n## Validation\n\n- `node --test tests/promote-buildchain-ref.test.mjs` (127 passed)\n- `pnpm run check` (819 passed; workflows, inventory, site bundle, and 5 action bundles passed)\n\nSupersedes #1621.\nCloses #1620",
          "author": "dongkeren",
          "createdAt": "2026-07-24T11:12:59Z",
          "mergedAt": "2026-07-24T11:23:28Z",
          "additions": 236,
          "deletions": 109,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1409,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1409",
          "title": "feat(agent-hub): define Docker starter concept contract",
          "body": "## Summary\n\nDefine the Docker-first Kungfu Hub Starter as a concept-only product contract before any image or Compose bundle exists. The change separates Starter lifecycle UX from KFD protocol/scaffold authority, the clean-room demo witness, and production Hub implementation responsibility.\n\n## Related issue\n\nNone. This delivery is tracked by Kungfu Assignment `2026-07-24-kungfu-hub-starter-docker-concept`.\n\n## Changes\n\n- Add a versioned Hub Starter contract and Draft 2020-12 schema covering topology, single-writer volumes, private networking, durable identity, lifecycle, version compatibility, upgrade, recovery, security, observability, evidence tiers, and explicit non-claims.\n- Add an accepted ADR and architecture guide with a bounded responsibility map and acceptance matrix.\n- Add a deterministic checker plus negative tests and wire both into source acceptance.\n- Register the pre-release welded surface and refresh documentation/ADR navigation.\n\nNo Dockerfile or Compose bundle is added. No image was built, pulled, published, signed, or run; no Docker daemon was contacted; no real user data or production volume was touched.\n\n## Verification\n\n- `./shifu check:hub-starter-docker` — contract/schema pass; 5/5 negative test groups pass.\n- `./shifu check:source` — build-free source gate passes; 598 Node tests (588 pass, 10 conditional skips), Python suites (5 + 41 + 114 pass), 69 desktop update tests, TypeScript checking, formatting, documentation, ADR, architecture, and version gates pass.\n- Commit-time staged gate passes for both signed-off commits.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f9388-a139-7355-b9f2-f6dd9aa91042\"],\n  \"summary\": \"Complete the concept-only Docker-first Hub Starter contract and static fail-closed qualification stage\",\n  \"verification\": [\"./shifu check:hub-starter-docker\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR specifies a future deployment surface but performs no deployment or publication. Static evidence is explicitly bounded to `concept-static`; all Compose, daemon, restart, recovery, upgrade, security, SLO, production, and stable-release tiers remain future and fail closed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T10:08:39Z",
          "mergedAt": "2026-07-24T11:25:04Z",
          "additions": 998,
          "deletions": 9,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1623,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1623",
          "title": "fix(release): promote protected version-state recovery",
          "body": "Promote the zero-bypass protected version-state PR recovery fix from dev to alpha.\n\nThis unblocks idempotent completion of the pending Buildchain v3 major publication without weakening branch protection.\n\nSource dev head: `a059e39c58a41c6a6fc1c7c83481b67728705e22`\n\nRelated: #1620",
          "author": "dongkeren",
          "createdAt": "2026-07-24T11:27:49Z",
          "mergedAt": "2026-07-24T11:31:13Z",
          "additions": 236,
          "deletions": 109,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1412,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1412",
          "title": "feat(governance): enforce primitive intake closure",
          "body": "## Summary\n\nEnforce the incubation passport as the only Primitive intake and close the repository-wide machine-artifact boundary. Keep human and agent guidance in parity through dedicated Xinfa routes, contributor guidance, AGENTS instructions, MAP navigation, and the accepted ADR.\n\n## Related issue\n\nFollow-up to the Primitive Management Plane delivery.\n\n## Changes\n\n- discover machine-readable Primitive JSON artifacts across all tracked and unignored repository paths\n- reject unregistered, mismatched, marker-free, and multiply owned Primitive artifacts\n- emit matching `primitiveId` markers from the birth scaffold and cover off-path bypasses with negative tests\n- document the exact birth, promotion, source-acceptance, and protected-channel workflow for humans and agents\n\n## Verification\n\n- `./shifu fix`\n- `./shifu check:primitive-catalog`\n- `./shifu docs validate --json`\n- `./shifu docs:check`\n- `./shifu docs authoring --since origin/dev/v4/v4.0 --json`\n- `./shifu check:source`\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f917f-d116-70e8-b4a1-2e0209598aec\"],\n  \"summary\": \"Close Primitive intake mechanically across the repository and publish matching human and agent guidance\",\n  \"verification\": [\"Primitive Catalog gate\", \"Candidate source acceptance\", \"documentation parity routes\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change strengthens source-acceptance evidence and protected-channel enforcement. It does not publish packages or deploy a runtime service; the full source gate and documentation contracts passed locally.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T10:53:11Z",
          "mergedAt": "2026-07-24T11:42:16Z",
          "additions": 412,
          "deletions": 29,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1625,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1625",
          "title": "fix(publication): grant protected PR fallback permission",
          "body": "## Summary\n\n- grant pull request write permission to protected version-state fallback\n- propagate the permission through generated/public promotion workflows\n- add regression coverage and regenerate the site contract\n\n## Validation\n\n- pnpm run check\n- 819 tests passed\n- 5 action bundles passed integrity checks\n\nCloses #1624",
          "author": "dongkeren",
          "createdAt": "2026-07-24T11:46:21Z",
          "mergedAt": "2026-07-24T11:50:28Z",
          "additions": 19,
          "deletions": 4,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1626,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1626",
          "title": "fix(publication): grant protected PR fallback permission (trusted checks)",
          "body": "Trusted-check carrier for the exact immutable SHA reviewed in #1625. The fork PR remains the canonical merge candidate; this PR exists only to run trusted repository checks.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-24T11:48:45Z",
          "mergedAt": "2026-07-24T11:50:28Z",
          "additions": 19,
          "deletions": 4,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1413,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1413",
          "title": "fix(shifu): preserve full build provenance SHA",
          "body": "## Summary\n- keep registry slot names compact while preserving the full 40-character Git revision in KUNGFU_BUILD_SHA\n- align registrar output with the exact-mainline and Product-manifest checks enforced by shifu promote\n- cover clean and dirty build identities with a regression test\n\n## Why\nPR #1408 correctly made promotion fail closed on exact source identity, but the registrar still truncated KUNGFU_BUILD_SHA to 9 characters. A clean, qualified build from exact protected mainline was therefore registered as invalid and could not be promoted.\n\n## Validation\n- full pre-commit gate passed\n- cargo fmt --manifest-path crates/Cargo.toml --all --check\n- cargo test --manifest-path crates/Cargo.toml -p shifu (31 passed)\n- cargo clippy --workspace --all-targets -- -D warnings\n- cargo test --workspace\n\nFollow-up required to finish 2026-07-24-kungfu-installed-work-graph-closure.\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"Repair registrar provenance truncation so the existing exact-SHA promotion contract can accept qualified mainline builds; no ADR or product contract changes.\"}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-24T11:23:11Z",
          "mergedAt": "2026-07-24T11:55:12Z",
          "additions": 31,
          "deletions": 9,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1627,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1627",
          "title": "fix(release): promote protected PR fallback permission",
          "body": "Promotes the protected version-state fallback permission fix from dev/v2/v2.14 into alpha/v2/v2.14 through the normal protected channel chain.\n\nIncludes #1625 at immutable merge commit 62f421b2491b798ac742947a283bfffd4acca0d5.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T11:51:58Z",
          "mergedAt": "2026-07-24T11:55:13Z",
          "additions": 19,
          "deletions": 4,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 304,
          "url": "https://github.com/kungfu-systems/build-images/pull/304",
          "title": "fix(comparator): tolerate transient Aeron file removal",
          "body": "## Summary\n\n- measure the Aeron data tree from file-visitor attributes instead of reopening each path\n- tolerate only descendant files that disappear during concurrent publication cleanup\n- keep missing roots and all other I/O failures fail-closed\n\n## Verification\n\n- `pnpm run check`\n- patched JAR compiled with JDK 21 and verified to use `Files.walkFileTree`\n- the previously failing Aeron schedule identity passed 20 consecutive probes\n- an unscored 666-identity shadow completed `666/666`; the former failure at index 638 passed and Docker residue was zero\n- selective image planning chooses only `comparator-formal-runner`\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, billing, quota, or usage-attribution change\n- [x] No hosted-service or branding change\n- [x] Existing image name, contract major, tag scheme, and release identity are unchanged\n- [x] Release evidence remains governed by Buildchain",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:02:45Z",
          "mergedAt": "2026-07-24T12:05:49Z",
          "additions": 29,
          "deletions": 8,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1629,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1629",
          "title": "fix(publication): route recovery PRs through promotion token",
          "body": "## Summary\n\n- use the existing BUILDCHAIN_PROMOTION_TOKEN only for the main promotion client that creates protected recovery PRs\n- retain run-scoped github.token for generated status checks and generated ref updates\n- add regression coverage and regenerate the site contract\n\n## Validation\n\n- pnpm run check\n- 819 tests passed\n- 5 action bundles passed integrity checks\n\nFollow-up to #1625 and the promotion failure recorded by run 30091301240.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:04:33Z",
          "mergedAt": "2026-07-24T12:10:21Z",
          "additions": 8,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1630,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1630",
          "title": "fix(publication): route recovery PRs through promotion token (trusted checks)",
          "body": "Trusted-check carrier for the exact immutable SHA reviewed in #1629. The fork PR remains the canonical merge candidate; this PR exists only to run trusted repository checks.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-24T12:04:58Z",
          "mergedAt": "2026-07-24T12:10:21Z",
          "additions": 8,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1414,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1414",
          "title": "docs(adr): close primitive intake delivery",
          "body": "## Summary\n\nClose the Primitive Management Plane ADR after the repository-wide intake enforcement landed in PR #1412, and regenerate the human ADR navigation projection.\n\n## Changes\n\n- mark the ADR implementation as `implemented`\n- bind closure evidence to merged PR #1412\n- report the intake closure as delivered rather than staged\n- regenerate `adr-map.md` and `adr-map.json` so human and machine status agree\n\n## Verification\n\n- `./shifu docs validate --json`\n- `./shifu adr:map`\n- `./shifu docs:check`\n- `./shifu check:source`\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f917f-d116-70e8-b4a1-2e0209598aec\"],\n  \"summary\": \"Record merged Primitive intake closure evidence and synchronize the human ADR map\",\n  \"verification\": [\"documentation gate\", \"source acceptance\", \"closure PR reachability\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes only ADR closure evidence and its generated navigation projection; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T11:52:14Z",
          "mergedAt": "2026-07-24T12:10:52Z",
          "additions": 5,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1631,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1631",
          "title": "fix(release): promote recovery PR token routing",
          "body": "Promotes the least-privilege recovery PR token routing fix from dev/v2/v2.14 into alpha/v2/v2.14 through the normal protected channel chain.\n\nIncludes #1629 at immutable merge commit 9a4b80efce26fd031128a44f968d6608abbdbf20.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:10:51Z",
          "mergedAt": "2026-07-24T12:14:04Z",
          "additions": 8,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 305,
          "url": "https://github.com/kungfu-systems/build-images/pull/305",
          "title": "chore(images): accept v1.3.0-alpha.13 baseline",
          "body": "## Summary\n\n- accept the published v1.3.0-alpha.13 image evidence as the selective-publish baseline\n- bind all nine public GHCR digests to the alpha.13 source and promotion run\n\n## Validation\n\n- `pnpm run check`\n- 114 comparator tests passed\n- publish provenance, image lock, KFD123, and both Buildchain contract locks passed\n\nThis PR is intentionally rooted at the v1.3.0-alpha.13 release commit so the baseline acceptance contains no unreleased image changes.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:11:14Z",
          "mergedAt": "2026-07-24T12:18:08Z",
          "additions": 90,
          "deletions": 90,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1632,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1632",
          "title": "fix(governance): grant publication audit read permissions",
          "body": "## Summary\n\n- grant the reusable publication authority job read-only access to check runs and pull-request review lineage\n- propagate the same least-privilege permissions from every in-repository caller\n- lock the permission contract in tests and generated public documentation\n\n## Evidence\n\n- fixes the fail-closed `branch-policy` result observed in Buildchain Ref Promotion run 30079790392 attempt 3 after the dedicated auditor App governance receipt qualified\n- preserves exact source/runtime binding; the failed historical transaction is not reused\n\n## Validation\n\n- `pnpm install --frozen-lockfile`\n- `node --test tests/github-governance-authority.test.mjs tests/build-surface.test.mjs` (109 passed)\n- `pnpm run check` (819 passed; workflow/site/action-bundle checks passed)",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:11:11Z",
          "mergedAt": "2026-07-24T12:19:27Z",
          "additions": 61,
          "deletions": 20,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 306,
          "url": "https://github.com/kungfu-systems/build-images/pull/306",
          "title": "chore(release): prepare v1.3.0-alpha.14",
          "body": "## Summary\n\n- prepare build-images v1.3.0-alpha.14\n- refresh KFD evidence against the accepted alpha.13 image baseline\n- retain the Buildchain v2 dual-channel contract locks without drift\n\n## Selective publish plan\n\n- build: `comparator-formal-runner`\n- reuse: the other eight image families from v1.3.0-alpha.13\n- global invalidators: none\n\n## Validation\n\n- `pnpm run check`\n- 114 comparator tests passed\n- KFD123 and both Buildchain contract locks passed\n- selective planner reports one built image and eight reused images",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:20:29Z",
          "mergedAt": "2026-07-24T12:23:26Z",
          "additions": 24,
          "deletions": 24,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 307,
          "url": "https://github.com/kungfu-systems/build-images/pull/307",
          "title": "chore(release): promote v1.3.0-alpha.14",
          "body": "## Release\n\nPromote build-images v1.3.0-alpha.14 from the v1.3 development channel to the alpha publication channel.\n\n## Published image plan\n\n- build and publish `comparator-formal-runner` with the Aeron transient file-removal fix\n- reuse the other eight image digests from v1.3.0-alpha.13\n- publish the GitHub release and Release Passport through Buildchain v2\n\n## Evidence\n\n- runner fix: #304\n- accepted alpha.13 image baseline: #305\n- release preparation: #306\n- selective planner: one built image, eight reused images, no global invalidators",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:23:45Z",
          "mergedAt": "2026-07-24T12:26:39Z",
          "additions": 143,
          "deletions": 122,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1634,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1634",
          "title": "chore(release): promote governance authority fix to v2.14 alpha",
          "body": "## Summary\n\nPromote the current protected dev head into the v2.14 alpha channel so the publication authority permission fix is validated and released from an exact new source tree.\n\n## Source binding\n\n- dev head: `ee474fcb6a249f89f0729e2d6c8087d6e865cf03`\n- no proof from the previous alpha base is reused\n- Alpha Verify and Ref Promotion must run from the resulting merge tree",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:23:02Z",
          "mergedAt": "2026-07-24T12:27:03Z",
          "additions": 61,
          "deletions": 20,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1635,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1635",
          "title": "fix(publication): isolate recovery PR authority",
          "body": "## Summary\n\n- add a dedicated generated-pull-request-token client for protected version-state recovery PRs\n- keep governance reads, generated checks, and generated ref updates on run-scoped github.token\n- bind only BUILDCHAIN_PROMOTION_TOKEN to the recovery PR client\n- add split-client regression coverage and regenerate bundles/contracts\n\n## Validation\n\n- pnpm run check\n- 819 tests passed\n- 5 action bundles passed integrity checks\n\nFollow-up to #1629 and promotion run 30092426203.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:29:20Z",
          "mergedAt": "2026-07-24T12:35:15Z",
          "additions": 130,
          "deletions": 109,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1636,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1636",
          "title": "fix(publication): isolate recovery PR authority (trusted checks)",
          "body": "Trusted-check carrier for the exact immutable SHA reviewed in #1635. The fork PR remains the canonical merge candidate; this PR exists only to run trusted repository checks.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-24T12:29:43Z",
          "mergedAt": "2026-07-24T12:35:16Z",
          "additions": 130,
          "deletions": 109,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1639,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1639",
          "title": "fix(release): promote isolated recovery PR authority",
          "body": "Promotes the split recovery PR authority fix from dev/v2/v2.14 into alpha/v2/v2.14 through the normal protected channel chain.\n\nIncludes #1635 at immutable merge commit 84878ee7f97c3bddf5aef30f3cab48d5b4bf458e.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:39:33Z",
          "mergedAt": "2026-07-24T12:43:08Z",
          "additions": 130,
          "deletions": 109,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1415,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1415",
          "title": "feat(release): complete signed Alpha bootstrap publication",
          "body": "## Summary\n\nComplete the final signed Alpha publication boundary for the standalone Kungfu CLI bootstrap installers. The final publication commit verifies immutable native artifacts and Release Passport evidence, emits the signed Alpha discovery index last, and binds the public trust anchor without creating a second release authority.\n\n## Related issue\n\nAtlas Goal 2026-07-24-kungfu-cli-signed-bootstrap-installer\n\n## Changes\n\n- commit signed Alpha discovery only after native artifacts, read-back evidence, and Release Passport admission\n- generate immutable version and payload-root installer snapshots plus bounded friendly routes\n- retain adjacent-publication comparison and rollback evidence\n- add the public Ed25519 Alpha trust anchor and reject key, URL, or active-set drift\n- relay the dedicated read-only governance auditor App credential into promotion\n\n## Verification\n\n- `./shifu check:source`: passed on base `2eab56a84776ee8e6d61086462214c234c099062`\n- staged repository gate: passed, including Rust fmt/clippy/workspace tests and documentation contracts\n- bootstrap/release-channel/publication tests: 29 passed\n- `./shifu check:gate-catalog`: 38 gates, 18 closed-world workflows aligned\n- `./shifu release:promotion:rehearse`: passed with no tracked-file, ref, remote, or credential side effects\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7718-8d1f-6402a87408a7\"],\n  \"summary\": \"Completes the final signed Alpha bootstrap publication commit while retaining the existing release-channel authority\",\n  \"verification\": [\"full source acceptance\", \"staged repository gate\", \"signed bootstrap negative tests\", \"side-effect-free promotion rehearsal\"]\n}\n-->\n\n## Governance risk check\n\n- [x] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo private signing material is present in the branch. GitHub Actions receives only named repository/organization secrets; the repository contains the public Ed25519 trust anchor.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:22:34Z",
          "mergedAt": "2026-07-24T12:43:28Z",
          "additions": 1285,
          "deletions": 121,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1638,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1638",
          "title": "fix(promotion): observe opaque protected branches",
          "body": "## Summary\n\n- treat GitHub's opaque 404 for non-admin branch-protection reads like its existing 403 path\n- verify the provider branch summary is already protected and enforces the exact required check for everyone\n- keep the full independent App-authenticated publication governance audit authoritative\n- never interpret an opaque response as permission to rewrite branch policy with a developer token\n\n## Validation\n\n- `node --test --test-name-pattern=\"managed channels reuse provider-enforced policy\" tests/promote-buildchain-ref.test.mjs`\n- `pnpm run check` (819 tests)\n- action bundle integrity check (5 bundles)",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:37:52Z",
          "mergedAt": "2026-07-24T12:45:28Z",
          "additions": 75,
          "deletions": 48,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1640,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1640",
          "title": "release(v2.14): promote authority-isolated candidate",
          "body": "## Summary\n\nPromote exact development source `a60fea0a6383f2f1afb9dc6b52c23fad3410829f` after isolating recovery-PR authority and hardening opaque branch-protection observation.\n\nThis promotion keeps the read-only governance App authoritative, leaves the developer account without repository administration, and performs a fresh alpha validation for the new source/base/runtime identity. No earlier publication proof is reused.\n\n## Included fixes\n\n- #1635 isolates the classic token to generated recovery-PR operations\n- #1638 treats provider-hidden 403/404 protection details as fail-closed observation of an already protected branch\n\n## Validation\n\n- full repository check: 819/819\n- action bundle integrity: 5/5\n- PR and merge-group governance receipts passed",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:46:06Z",
          "mergedAt": "2026-07-24T12:49:08Z",
          "additions": 75,
          "deletions": 48,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1641,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1641",
          "title": "Prepare v2.14.18-alpha.5",
          "body": "Create the generated version-state commit for v2.14.18-alpha.5.\n\nBuildchain generated this PR because protected branch alpha/v2/v2.14 rejected direct generated bookkeeping.\n\nRejected update: 13b001a82ed1e6845b864028e0cce5b72c5d36c7 -> 8cc6340f912d75c90c74aead6b9f2e3ce1245099\n\nGitHub response: Repository rule violations found\n\nChanges must be made through a pull request.\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:48:48Z",
          "mergedAt": "2026-07-24T12:50:40Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1644,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1644",
          "title": "fix(release): finalize protected alpha transactions",
          "body": "## Summary\n- resume only the exact already-published alpha transaction after its protected version-state PR merges\n- keep source, release material, tooling, evidence, version, and target identity unchanged; never authorize the newer composite channel tree\n- defer binary dispatch, controller evidence, and consumer publication while finalization is pending\n\n## Validation\n- corepack pnpm run check\n- 820 tests passed\n- 5 action bundles verified\n\n## Release safety\n- no provider publish command is replayed during contained finalization\n- exact and floating tags bind the durable transaction release SHA\n- a different source tree still requires a fresh version and release candidate",
          "author": "dongkeren",
          "createdAt": "2026-07-24T13:08:43Z",
          "mergedAt": "2026-07-24T13:13:55Z",
          "additions": 463,
          "deletions": 91,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1403,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1403",
          "title": "feat(agent-hub): make qualification self-explanatory",
          "body": "## Summary\n\nMake the installed Kungfu Agent Hub qualification understandable without decoding a raw KFD report. The same command now runs the fixed Hub 20 suite, explains the result and bounded claim to a human, retains rooted evidence, and exposes stable JSON plus KFD-3 guidance for Agents.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- add `kungfu agent hub qualify` and `kungfu agent hub verify`\n- bind the exact bundled `@kungfu-tech/kfd@1.0.0-alpha.47` suite and verifier\n- keep each embedded-libnode KFD step in an isolated Kungfu subprocess\n- preserve the public CLI catalog while exposing run/verify guidance through docs, Agent brief, Codex/Claude skills, command pack, and KFD-3 registry\n- state what ran, whether it passed, what it means, and what it does not mean\n\n## Verification\n\n- `./shifu test:kfd-agent-hub-20` (5 Node tests and 8 Python tests)\n- `./shifu kfd:buildchain` (154 KFD-3 surfaces)\n- `./shifu check:agent-pack` and `./shifu check:cli-catalog-parity`\n- full staged source, documentation, ADR, lint, and Buildchain KFD gates\n- `./shifu build:core && ./shifu product cli dist`\n- installed `/usr/local/bin/kungfu agent hub qualify`: 20/20, offline verification passed, exact source `54680f08a8ccf78827887dbe15b72db34a8f3200`, pristine source, real `~/.kungfu` metadata unchanged\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-786d-aa24-a97705e13917\"],\n  \"summary\": \"Expose the already qualified product-owned Agent Hub stage as a direct installed-product human and Agent verification surface without widening its claim.\",\n  \"verification\": [\"./shifu test:kfd-agent-hub-20\", \"./shifu kfd:buildchain\", \"installed /usr/local/bin/kungfu Agent Hub qualification 20/20\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change consumes the exact published KFD alpha.47 package and binds local evidence to one exact Kungfu artifact. It does not publish Kungfu, claim a stable line, or widen KFD certification, security, production, network, adoption, or platform claims.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T07:58:13Z",
          "mergedAt": "2026-07-24T13:22:06Z",
          "additions": 1760,
          "deletions": 110,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1646,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1646",
          "title": "chore(release): reconcile alpha finalization ancestry",
          "body": "## Summary\n- merge the current alpha.5 version-state ancestry into the current dev authority fix\n- resolve the single generated site-contract conflict by deterministic regeneration\n- preserve package version 2.14.18-alpha.5 and the protected finalization implementation\n\n## Validation\n- corepack pnpm run check\n- 820 tests passed\n- 5 action bundles verified\n\nThis is ancestry reconciliation only; it does not publish, tag, or reuse release-candidate proof.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T13:17:43Z",
          "mergedAt": "2026-07-24T13:23:20Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1645,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1645",
          "title": "fix(release): recover protected alpha finalization",
          "body": "## Summary\n- promote the exact dev tree containing protected alpha transaction finalization\n- preserve the existing alpha.5 source/material/tooling identity while completing only its pending finalization\n- require a fresh PR-stage release candidate for this new alpha merge tree before any subsequent publication\n\n## Source\n- dev/v2/v2.14: c9c159cb3d8c3a44d8ae4f11b3609a06c0136fa7\n- alpha/v2/v2.14 base: f28be9588fd5d03ea8f8faf0bd0d4a0b109e5449",
          "author": "dongkeren",
          "createdAt": "2026-07-24T13:14:39Z",
          "mergedAt": "2026-07-24T13:26:08Z",
          "additions": 463,
          "deletions": 91,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1647,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1647",
          "title": "fix(release): pass nested authority read permissions",
          "body": "## Summary\n- pass the reusable publication authority read permissions through the public binary asset caller\n- lock the nested permission contract with a build-surface regression assertion\n\n## Evidence\n- observed Binary Release Assets run 30097303302 fail before job creation with `startup_failure`\n- `node --test tests/build-surface.test.mjs`\n- `pnpm run check` (820 tests, 5 action bundles)\n\n## Security boundary\nThis adds only `checks: read` and `pull-requests: read`; the existing release asset job remains the sole `contents: write` publisher.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T13:36:03Z",
          "mergedAt": "2026-07-24T13:41:05Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1648,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1648",
          "title": "fix(release): propagate binary authority permissions",
          "body": "## Summary\nPromote the nested publication-authority permission fix from protected dev to the v2.14 alpha channel.\n\n## Evidence\n- source PR #1647 merged through the dev merge queue at `049a42bc060adb9948517e402740aa0d1df0cb72`\n- PR and merge-group Verify/Governance checks passed\n- local `pnpm run check`: 820 tests and 5 action bundles\n\n## Release recovery\nAfter this alpha merge, the current verifier can replay sealed Binary Distribution run `30097172376` for existing exact tag `v2.14.18-alpha.5` without republishing npm.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T13:41:39Z",
          "mergedAt": "2026-07-24T13:44:42Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1649,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1649",
          "title": "fix(release): pass nested authority secret",
          "body": "## Summary\n- forward repository secrets across both reusable-workflow boundaries in Binary Release Assets\n- preserve the existing read-only governance App authority and asset-only write boundary\n- lock both secret forwarding edges with regression assertions\n\n## Live evidence\nBinary Release Assets run `30098137203` passed transaction resolution, then failed closed because the nested authority received an empty App private key.\n\n## Validation\n- `node --test tests/build-surface.test.mjs`\n- `pnpm run check` (820 tests, 5 action bundles)",
          "author": "dongkeren",
          "createdAt": "2026-07-24T13:47:28Z",
          "mergedAt": "2026-07-24T13:52:37Z",
          "additions": 7,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1651,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1651",
          "title": "fix(release): propagate nested authority secret",
          "body": "## Summary\nPromote the reusable-workflow secret forwarding fix from dev to the v2.14 alpha channel.\n\n## Evidence\n- source PR #1649 merged through dev merge queue at `cc28258240b4172aac9c99a6accf4e0f5ef46783`\n- merge-group Verify and GitHub Governance Authority Audit passed on the exact composite tree\n- local `pnpm run check`: 820 tests and 5 action bundles\n\n## Recovery target\nAfter merge, replay sealed Binary Distribution run `30097172376` for existing `v2.14.18-alpha.5`; npm and tags remain untouched.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T13:53:11Z",
          "mergedAt": "2026-07-24T13:57:55Z",
          "additions": 7,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1391,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1391",
          "title": "feat(dogfood): add native feedback loop",
          "body": "## Summary\n\n- add a first-party Dogfood Domain Profile with immutable Findings, owned Issues, explicit transitions, bounded relevance, consideration receipts, and starvation policy\n- integrate mandatory dogfood consideration with Assignment admission, kickoff, and closeout gates\n- add lossless, source-root-bound Atlas JSONL migration with idempotent retry and retained-byte verification\n- package Dogfood with Product KFD-3 evidence and a generic Work Dashboard Profile intent bridge\n\n## Related issue\n\nAtlas Assignment: `2026-07-24-kungfu-native-dogfood-feedback-loop`\n\n## Changes\n\n- native CLI/API JSON envelopes for capture, admission, transition, query, consideration, gating, starvation, import, and export\n- federated project/Home query semantics retain independent component cuts and unavailable members\n- checked-in installed-product fixtures and qualification record\n\n## Verification\n\n- 21 targeted Python tests passed\n- Work Dashboard: 28 tests passed\n- CLI catalog parity and Domain Profile authoring checks passed\n- macOS arm64 Product build and single-runtime bundle audit passed\n- installed lifecycle gate passed; KFD-3 qualified/current/active exact root\n- Atlas migration verified 197/197 revisions, retained source bytes, and stable already-present retry\n- documentation gate passed; one unrelated promotion rehearsal was transient once and passed on immediate isolated rerun\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-71be-a2aa-c8744fa340d8\"],\n  \"summary\": \"Complete the bounded native dogfood feedback-loop delivery stage\",\n  \"verification\": [\"targeted Python and Dashboard tests, generated contracts, Product build, installed lifecycle, KFD-3, and lossless Atlas migration qualification\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe Product KFD-3 manifest and qualification record change release evidence only; no publication or deployment is performed by this PR.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-24T02:14:23Z",
          "mergedAt": "2026-07-24T14:02:55Z",
          "additions": 5270,
          "deletions": 54,
          "changedFiles": 52
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1653,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1653",
          "title": "fix(release): authorize exact historical source",
          "body": "## Summary\n- admit an exact historical publication source only when it is the reviewed PR head and remains an ancestor of the protected branch\n- bind independent approval and required checks to the exact PR head SHA\n- preserve fail-closed behavior when source lineage is absent or rewritten\n\n## Validation\n- `pnpm run check` (821 tests, 5 action bundles)\n- targeted publication authority tests (25/25)\n- live alpha.5 control-plane audit (6/6 facts pass)\n\nThis does not reuse affected-native proofs or relax source/base/toolchain identity.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T14:07:44Z",
          "mergedAt": "2026-07-24T14:13:36Z",
          "additions": 74,
          "deletions": 15,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1654,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1654",
          "title": "fix(release): authorize exact historical source",
          "body": "## Summary\nPromote the exact historical publication-source authorization fix from dev to the v2.14 alpha channel.\n\n## Evidence\n- source PR #1653 merged through dev merge queue at `4efdd7014eb23247e73c323baa0f038956bba8c1`\n- merge-group Verify and GitHub Governance Authority Audit passed on the exact composite tree\n- local `pnpm run check`: 821 tests and 5 action bundles\n- live alpha.5 control-plane audit: 6/6 facts pass\n\n## Safety boundary\nThe recovery accepts only the exact reviewed PR head, exact-head approval/checks, and protected-branch ancestry. It does not reuse affected-native proofs or expand base-forward semantics.\n\n## Recovery target\nAfter merge, replay Binary Release Assets for existing `v2.14.18-alpha.5`; npm and tags remain untouched.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T14:15:31Z",
          "mergedAt": "2026-07-24T14:19:24Z",
          "additions": 74,
          "deletions": 15,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1418,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1418",
          "title": "feat(site): add auditable product positioning bundle",
          "body": "## Summary\n\nAdd an independent framework/site package that projects the complete Kungfu product promise and adoption map without moving technical authority into the site layer.\n\n## Related issue\n\nAtlas go: 2026-07-24-kungfu-framework-site-bundle-full-product-positioning\n\n## Changes\n\n- generate an integrity-bound site bundle, agent index, ADR map, and JSON Schema\n- cover .kungfu format, primitives, runtime, ABI, SDKs, KFX/Profile, complete products, qualification, decisions, and domain horizons\n- bind every product claim to an exact repository source and content root\n- keep maturity and explicit non-claims visible for public consumers\n\n## Verification\n\n- ./shifu --filter @kungfu-tech/site build\n- ./shifu --filter @kungfu-tech/site verify\n- ./shifu --filter @kungfu-tech/site test\n- ./shifu docs:check\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7c91-9cc2-6dbd18d68dff\"],\n  \"summary\": \"Publish the complete product-layer architecture as an independently consumable, source-rooted site bundle.\",\n  \"verification\": [\"framework/site build, verify, and test\", \"deterministic documentation gate\", \"staged repository gate\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe package is public-source-only, publishes no secret, and records exact content roots plus a clean source revision. This PR defines the package and its evidence contract; publication remains a separate explicit action.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-24T13:09:13Z",
          "mergedAt": "2026-07-24T14:28:48Z",
          "additions": 1576,
          "deletions": 4,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1417,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1417",
          "title": "chore(release): reconcile Alpha channel history",
          "body": "## Summary\n\nReconcile the existing Alpha branch as an ancestry-only parent of current dev before the first signed bootstrap publication. The merge uses the ours strategy, so the resulting tree remains byte-identical to protected dev.\n\n## Verification\n\n- merge commit tree equals first-parent dev tree: 2c402f9c5a9eb6eba1236bbb1baa37917259dcf8\n- second parent is current alpha head: b9632daebcc1071ad7bc29b882c1c0fa54a2a292\n- no files changed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Ancestry-only Alpha history reconciliation with a tree identical to protected dev\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Tree identity and both parents verified",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:46:12Z",
          "mergedAt": "2026-07-24T14:31:42Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1656,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1656",
          "title": "fix(release): seal deferred authority state",
          "body": "## Summary\n- require the publication Environment to authorize the exact protected branch being audited\n- preserve promotion evidence when protected version-state finalization is pending\n- emit an explicit nonqualifying `partial / promotion-finalization-pending` controller receipt instead of failing with a missing artifact\n\n## Live evidence\n- `buildchain-release-assets` now has an exact `alpha/v2/v2.14` branch policy\n- Binary Release Assets run `30100628518` succeeded and uploaded the alpha.5 archives\n- alpha.8 promotion run `30100613290` exposed the missing deferred receipt artifact after publishing npm and opening PR #1655\n\n## Validation\n- final `pnpm run check`: 821 tests, 5 action bundles\n- workflow + targeted authority suite: 110/110\n- live alpha.5 audit with exact branch admission: 6/6 facts pass\n\nAffected-native source/base/toolchain proof identity is unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T14:29:45Z",
          "mergedAt": "2026-07-24T14:39:00Z",
          "additions": 57,
          "deletions": 11,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1657,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1657",
          "title": "chore(release): promote dev to alpha",
          "body": "## Summary\n- promote the exact protected dev head `af7114cc8d7b85a9a5163580537600eb6e57073c` to `alpha/v2/v2.14`\n- carry the deferred finalization receipt and exact Environment branch admission fixes\n\n## Validation\n- dev merge-group Verify: success\n- dev merge-group Governance Authority Audit: success\n- merge-group candidate: `af7114cc8d7b85a9a5163580537600eb6e57073c`\n\nAffected-native source/base/toolchain proof identity remains exact; no base-forward reuse is introduced.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T14:39:33Z",
          "mergedAt": "2026-07-24T14:42:33Z",
          "additions": 57,
          "deletions": 11,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1660,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1660",
          "title": "fix(release): preserve partial finalization evidence",
          "body": "## Summary\n- allow `partial` as an explicit nonqualifying controller stage state\n- preserve candidate and publish evidence while protected version-state finalization is pending\n- require release-passport and publication-commit evidence only after finalization is complete\n\n## Live failure reproduced\n- alpha.9 transaction `30102237449` published the package and opened #1658\n- evidence bundling failed because the pending transaction has no release passport yet\n- controller receipt creation rejected the explicit `partial` stage status\n\n## Validation\n- targeted controller/build-surface tests: 98/98\n- final `pnpm run check`: 821/821 tests, 5 action bundles\n- generated site contract: current\n\nThe receipt remains fail-closed: partial is never qualifying. Affected-native source/base/toolchain proof identity is unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T14:53:01Z",
          "mergedAt": "2026-07-24T14:58:26Z",
          "additions": 24,
          "deletions": 10,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1661,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1661",
          "title": "chore(release): promote dev to alpha",
          "body": "## Summary\n- promote exact dev merge-group head `c0afcc02adad10d5ad5f2b12e27dc442c0047bee` to `alpha/v2/v2.14`\n- carry explicit partial/nonqualifying controller receipt support for deferred version-state finalization\n\n## Validation\n- dev merge-group Verify: success\n- dev merge-group Governance Authority Audit: success\n\nAffected-native source/base/toolchain proof identity remains exact; no base-forward reuse.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T14:58:45Z",
          "mergedAt": "2026-07-24T15:02:05Z",
          "additions": 24,
          "deletions": 10,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1662,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1662",
          "title": "Prepare v2.14.18-alpha.10",
          "body": "Create the generated version-state commit for v2.14.18-alpha.10.\n\nBuildchain generated this PR because protected branch alpha/v2/v2.14 rejected direct generated bookkeeping.\n\nRejected update: dd874a40c2a6c55f2b7939760104249f60017807 -> 9d8bcc83a21abc17b6539fac4ae2c1b50b8554fb\n\nGitHub response: Repository rule violations found\n\nChanges must be made through a pull request.\n\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-24T15:07:56Z",
          "mergedAt": "2026-07-24T15:11:04Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1426,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1426",
          "title": "fix(stubs): sync generated runtime annotations",
          "body": "## Summary\n\nSync the checked-in `pykungfu.runtime` stub with the exact Linux package-build output so Episode qualification retains its clean-source guarantee.\n\n## Related issue\n\nFound by the Hub Starter exact-source package qualification run.\n\n## Changes\n\n- replace four generator-normalized placeholder annotations with `typing.Any`\n- make the checked-in stub byte-identical to the native Linux builder output\n\n## Verification\n\n- generated runner blob: `6835ae7a778391a858a147cc9198304fd4ee1e3d`\n- patched source blob: `6835ae7a778391a858a147cc9198304fd4ee1e3d`\n- `python3 -m py_compile framework/core/stubs/pykungfu/runtime.pyi`\n- staged hook: pass (26 gate-latency/cache tests, 17 invariant tests, 92 docs/ADR tests, contract gates)\n- failing exact-source run before patch: https://github.com/kungfu-systems/kungfu/actions/runs/30097780785\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This generated-stub synchronization restores the already-required clean-source qualification invariant without changing runtime behavior or an architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change restores a clean-source release-evidence prerequisite; it does not publish or promote a Kungfu release.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (no authored behavior change)",
          "author": "dongkeren",
          "createdAt": "2026-07-24T13:59:31Z",
          "mergedAt": "2026-07-24T15:12:33Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1663,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1663",
          "title": "fix(release): admit durable transaction recovery",
          "body": "## Summary\n\n- add an explicit durable transaction recovery dispatch mode\n- require an exact current channel SHA for recovery\n- mint fresh GitHub-hosted publication admission through the existing auditor path\n- preserve fail-closed manual apply behavior outside recovery\n\n## Validation\n\n- node --test tests/build-surface.test.mjs (85/85)\n- pnpm run check (821/821; workflow and 5 action bundle checks passed)\n\n## Recovery target\n\nThis unblocks finalization of the already-published 2.14.18-alpha.10 durable transaction after its protected version-state PR merged. It does not weaken or alter affected-native proof identity or reuse rules.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T15:21:09Z",
          "mergedAt": "2026-07-24T15:26:47Z",
          "additions": 51,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1427,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1427",
          "title": "feat(primitive): weld authoring context and product discovery",
          "body": "## Summary\n\nMake Primitive Management operational at the authoring boundary and discoverable in the installed product without introducing a second authority. Agent-managed writes now require the exact current Task Chart projection Root; human writes remain explicit and auditable.\n\n## Related issue\n\nAtlas Assignment `2026-07-24-kungfu-primitive-context-welding`.\n\n## Changes\n\n- Bind deterministic `kungfu-primitive-management-agent` context evidence into Primitive dry-run, write validation, and v2 authoring receipts.\n- Add read-only `kungfu primitive list|show|explain --json` commands backed by the shipped derived catalog.\n- Project the commands into KFD-3, CLI catalogs, and the installed Agent documentation pack.\n- Synchronize contributor, architecture, map, ADR, and Agent guidance.\n- Add negative authoring tests and packaged CLI tests.\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu check:primitive-catalog` (11 tests)\n- `./shifu test:cli-surface-contract` (32 tests)\n- `./shifu check:cli-catalog-parity`\n- `./shifu kfd:buildchain` (158 KFD-3 surfaces)\n- `./shifu core:affected -- --execute` and receipt verification at exact revision `dba9ee9185ac376ebc362a18c3844cc2f1f24887`\n- `./shifu build:core`\n- Isolated installed-wheel qualification for Primitive list/show/explain, unknown-id exit behavior, catalog Root parity, and packaged Agent docs\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f917f-d116-70e8-b4a1-2e0209598aec\"],\n  \"summary\": \"Weld exact Primitive Management context evidence to authoring and expose the derived catalog through the installed CLI and Agent pack\",\n  \"verification\": [\"source acceptance\", \"affected-native exact-revision receipt\", \"installed-wheel Primitive CLI qualification\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe CLI change is a read-only projection of the existing Primitive Catalog authority. Source and installed-wheel qualification prove stable JSON behavior and exact catalog Root parity.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-24T14:00:27Z",
          "mergedAt": "2026-07-24T15:36:51Z",
          "additions": 1519,
          "deletions": 122,
          "changedFiles": 38
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1665,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1665",
          "title": "chore(release): reconcile v2.14 channel ancestry",
          "body": "Record the protected release line as an ancestor of the current dev line while preserving the already-validated dev tree byte-for-byte.\n\nThis removes the channel-history conflict without directly mutating a protected ref. The PR and later channel merge are validated as fresh exact candidates; no affected-native proof is reused across a changed base/candidate tree.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-24T15:44:07Z",
          "mergedAt": "2026-07-24T15:49:24Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1666,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1666",
          "title": "release: promote reconciled v2.14 dev to alpha",
          "body": "Promote the protected dev line after reconciling the release-line ancestry.\n\nThe merge candidate must be revalidated against the exact alpha base; no affected-native proof is reused across base or candidate-tree changes. This is the declared dev-to-alpha release path.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-24T15:49:43Z",
          "mergedAt": "2026-07-24T15:53:17Z",
          "additions": 51,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1423,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1423",
          "title": "feat(workspace): close federated work projection",
          "body": "## Summary\n\nClose the installed federated Work reader into a strict, clean user projection while preserving every workspace authority boundary and every degraded observation.\n\n## Related issue\n\nAtlas go: 2026-07-24-kungfu-global-work-view-strict-clean-closure\n\n## Changes\n\n- add explicit active, retired, test-only, and quarantined Catalog lifecycle with dry-run-first exact-entry maintenance receipts\n- isolate pytest discovery from the persistent user Catalog unless an exact config home is explicitly supplied\n- compose authority-qualified canonical Work identities, fold only proven replicas, and preserve label collisions and divergent conflicts\n- resolve typed and legacy references against the complete federated identity index, including verified retained Assignment seals\n- provide one-row-per-canonical-Work human output plus progressive component, replica, conflict, unresolved, and proof details\n- fail strict reads on required component, proof, Catalog churn, identity, or reference defects while retaining policy-valid exclusions\n\n## Verification\n\n- ./shifu test:workspace-continuation (67 passed)\n- ./shifu check:workspace-continuation\n- Home and explicit workspace strict scope=all: complete=true, canonical_work_count=75 before child orchestration, writes=0, same canonical identity-root set\n- persistent Catalog maintenance receipts retained for 5 test-only and 4 retired locators; no workspace authority was modified\n- full staged pre-commit gate, including release rehearsal (92 passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f8e99-9354-7ab6-a9ba-b166f83f25a3\"],\n  \"summary\": \"Close the staged workspace federation reader with strict Catalog lifecycle, canonical Work identity, reference closure, and user projection semantics.\",\n  \"verification\": [\"workspace continuation suite\", \"strict Home and project read parity\", \"staged repository gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nCatalog maintenance is dry-run-first, exact-entry-bound, receipt-producing, and does not rewrite workspace authority. Installed Product promotion remains a separate post-merge Shifu step.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Contract and tests updated for behavior changes\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T13:48:41Z",
          "mergedAt": "2026-07-24T16:03:53Z",
          "additions": 1813,
          "deletions": 75,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1667,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1667",
          "title": "fix(signing): label credential-island security failures",
          "body": "Summary:\n- preserve redaction for credential-bearing macOS security commands\n- attach safe operation labels to temporary keychain, PKCS#12 import, and ACL failures\n- assert the diagnostic labels in the credential-island contract test\n\nWhy:\nThe first real Kungfu alpha credential-island run failed inside a redacted security command. The existing error only identified the security binary, so operators could not distinguish a PKCS#12 password/import failure from temporary-keychain setup or key ACL configuration without exposing sensitive output.\n\nValidation:\n- corepack pnpm check: 821 tests passed\n- credential-island bundle integrity check passed\n- git diff --check passed\n\nSecurity:\nSensitive stdout and stderr remain withheld. The added labels contain no paths, arguments, identities, or credential material.\n\nDCO signed off. No secrets or private logs are included.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T15:54:08Z",
          "mergedAt": "2026-07-24T16:03:55Z",
          "additions": 28,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1668,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1668",
          "title": "Prepare v2.14.18-alpha.11",
          "body": "Create the generated version-state commit for v2.14.18-alpha.11.\n\nBuildchain generated this PR because protected branch alpha/v2/v2.14 rejected direct generated bookkeeping.\n\nRejected update: 89243e5a9cb346e8c52cec5c69733ada91dcd153 -> bcdf00393ddec9886fd294a8e5d7830ffaf19f6c\n\nGitHub response: Repository rule violations found\n\nChanges must be made through a pull request.\n\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-24T16:01:11Z",
          "mergedAt": "2026-07-24T16:04:16Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 208,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/208",
          "title": "feat(core): consume full product site bundle",
          "body": "## Summary\n\n- replace the hand-written narrow Core runtime fixture with the exact `@kungfu-tech/site@4.0.0-alpha.1` bundle\n- render the complete product stack across 11 stable Core routes while preserving the mmap runtime depth page\n- expose byte-identical site bundle, agent index, ADR map, and schema machine entries\n- vendor the 41 KB source-bound package tarball from clean Kungfu dev SHA `7ae0c173b3e4ed721bb82f5474cf6b3753525098`; pnpm integrity and embedded source/content roots remain enforced\n- advance KFD consumption to `@kungfu-tech/kfd@1.0.0-alpha.47`\n\n## Validation\n\n- `npm run build`\n- `npm run check`\n- `bash -n scripts/check-site.sh scripts/build-site.sh`\n- `shellcheck scripts/check-site.sh scripts/build-site.sh`\n- `git diff --check`\n- all 11 Core routes return HTTP 200\n- all four Core machine entries return parseable JSON\n- headless Chrome desktop/mobile smoke\n\n## Boundary\n\nThe vendored tarball is an immutable transport cache, not a semantic authority. Core claims, maturity boundaries, source digests, ADR relations, and non-claims remain owned by Kungfu `framework/site`. Production publication is intentionally out of scope for this closeout; normal `main` staging behavior remains unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T15:27:49Z",
          "mergedAt": "2026-07-24T16:05:21Z",
          "additions": 723,
          "deletions": 393,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 1,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/1",
          "title": "feat: deliver Docker-first Hub Starter runtime",
          "body": "## Summary\n\n- add a source-bound Docker-first Hub Starter development runtime\n- project real Kungfu Initiative, Assignment, Episode, review, decision, and sealed state through a thin Web/Node adapter\n- add exact package/source/digest publication and retained Compose, two-instance, restart, and security smoke workflows\n\n## Bootstrap boundary\n\nThis is the protected repository/workflow bootstrap PR. GitHub only permits `workflow_dispatch` for a workflow that already exists on the default branch, so the exact GHCR image cannot be produced before this PR lands. The lock remains explicitly `awaiting-qualified-image`; a separate minimal protected follow-up PR will bind the produced digest, exact package checksum, source SHA, and qualification run. No placeholder is presented as qualified.\n\n## Validation\n\n- `npm run check` (source identity, Compose boundary, policy, adapter tests)\n- `bash -n scripts/smoke-image.sh`\n- `shellcheck scripts/smoke-image.sh`\n- actionlint and DCO checks\n- exact source package build/verify passed at Kungfu source `7ae0c173b3e4ed721bb82f5474cf6b3753525098`\n- frozen Linux Phase B package qualification passed in run `30104518605`; the unrelated custom-matrix macOS notarization job correctly produced no Hub input and is not claimed\n\n## Claim boundary\n\nPre-Alpha, localhost-only, non-production, unauthenticated, single-user development candidate. No Docker socket, host network, host path, real Home, credentials, privilege, added capabilities, or automatic volume deletion.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T12:44:06Z",
          "mergedAt": "2026-07-24T16:32:33Z",
          "additions": 1720,
          "deletions": 0,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1434,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1434",
          "title": "fix(release): restore Windows Alpha build",
          "body": "## Summary\n\nRestore the frozen Alpha publication build on Windows without changing the release contract, frozen version, signing authority, or publication semantics.\n\n## Related issue\n\nAtlas Goal `2026-07-24-kungfu-cli-signed-bootstrap-installer`; follow-up to Alpha Build run `30101932608`.\n\n## Changes\n\n- compare the generated primitive catalog root through explicit `std::string` values so MSVC does not face ambiguous nlohmann JSON/string-view overloads\n- skip two POSIX launcher execution tests on Windows while retaining the native `shifu.cmd` diagnosis contract test\n\n## Verification\n\n- `./shifu check:source`: passed (600 tests: 590 pass, 10 intentional skips; 41 Python source tests; 116 runtime-upgrade tests; 69 desktop-update tests)\n- `node --test scripts/check-shifu-entry-contract.test.mjs`: 19/19 passed on macOS\n- staged repository gate: passed\n- C++ clang-format and changed JavaScript Biome checks: passed\n- authoritative Windows compile remains required in the protected merge-group and replacement Alpha Build\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This platform-compatibility bugfix restores compilation and makes POSIX-only launcher tests platform-accurate without changing architecture, release authority, installer behavior, or public API.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo signing material is read or changed by this patch. The prior failed Alpha run passed its trust, exact-source, and material-anchoring gates before the Windows compiler failure.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (no authored behavior change)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T15:13:12Z",
          "mergedAt": "2026-07-24T16:42:42Z",
          "additions": 9,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1670,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1670",
          "title": "Release v2.14.18 from qualified v2.14.18-alpha.11",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.14.18-alpha.11`\n- Candidate SHA: `bcdf00393ddec9886fd294a8e5d7830ffaf19f6c`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.14`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T16:44:11Z",
          "mergedAt": "2026-07-24T16:46:09Z",
          "additions": 10627,
          "deletions": 606,
          "changedFiles": 97
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1671,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1671",
          "title": "Release v2.14.18",
          "body": "Create the generated version-state commit for v2.14.18.\n\nBuildchain generated this PR because protected branch release/v2/v2.14 rejected direct generated bookkeeping.\n\nRejected update: aa1bea6f12a7a815793fb223cfaea9db691c1908 -> 1dc4da559a0d9cd353c51f30b2ca34c0be5d9cdc\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T16:51:30Z",
          "mergedAt": "2026-07-24T16:52:52Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1425,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1425",
          "title": "fix(product): ship executable Agent Hub qualification",
          "body": "## Summary\n\nFix the Kungfu CLI product archive so the already documented Agent Hub qualification is actually executable from the installed product. The archive now carries the exact KFD package locked by Hub 20 and fails packaging if `qualify` or offline `verify` cannot produce the bounded 20/20 verdict.\n\n## Related issue\n\nFollow-up to #1403.\n\n## Changes\n\n- align the SDK authoring/runtime dependency with `@kungfu-tech/kfd@1.0.0-alpha.47`\n- require the installed KFD executable, Hub runner, and report verifier in the product manifest smoke\n- execute `kungfu agent hub qualify --json` and `verify --json` from the extracted archive under an isolated HOME\n- assert 20/20 coverage, human meaning, non-claims, rooted evidence, real-home isolation, and the next verification command\n- bind the package version and executable files to the retained Hub 20 KFD lock\n- refresh the generated KFD-3 product projections for the exact packaged dependency\n\n## Verification\n\n- `./shifu test:cli-surface-qualification` (29/29)\n- `./shifu test:kfd-agent-hub-20` (5 Node tests and 8 Python tests)\n- `./shifu kfd:buildchain:check` (155 KFD-3 surfaces)\n- `./shifu dist:cli` (`CLI installed-layout smoke passed`)\n- extracted product `kungfu agent hub qualify`: 20/20, human meaning and non-claims shown, real `~/.kungfu` metadata unchanged\n- extracted product `kungfu agent hub verify`: 20/20 and all seven offline checks passed\n- staged source, docs, ADR, lint, and Buildchain KFD hooks passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This packaging bugfix makes the already implemented and qualified Agent Hub surface executable in the CLI archive without changing its architecture contract or claim boundary.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe fix changes the exact KFD package carried by the Kungfu CLI archive and strengthens installed-product release evidence. It does not publish a Kungfu release or claim KFD certification, security assessment, production fitness, remote-network interoperability, external adoption, stable status, or unobserved platform support.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T13:56:45Z",
          "mergedAt": "2026-07-24T17:05:46Z",
          "additions": 161,
          "deletions": 31,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1673,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1673",
          "title": "fix(release): bind stable finalization candidate",
          "body": "## Summary\n- bind stable canary admission to the exact alpha candidate resolved by the publication planner\n- reject candidate/publication version drift during durable stable finalization\n- expose the binding through the promote action and generated contract\n\n## Verification\n- `pnpm run check`\n- 821 tests passed\n- action bundle integrity check passed\n\n## Incident evidence\nThis repairs the fail-closed recovery discovered in Ref Promotion run 30110895857. The release branch already carried generated stable version state, so reading `package.json` no longer identified the original exact alpha candidate. The planner still resolves that candidate from the durable transaction and release lineage; this change binds admission to that exact value.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T17:02:57Z",
          "mergedAt": "2026-07-24T17:06:50Z",
          "additions": 73,
          "deletions": 40,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1674,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1674",
          "title": "fix(release): recover stable candidate binding",
          "body": "## Summary\n- apply the planner-bound exact alpha candidate fix to the active v2.14 release transaction\n- preserve the existing `2.14.18` durable publication identity and release-line ancestry\n- fail closed when candidate and planned stable versions disagree\n\n## Verification\n- `pnpm run check`\n- 821 tests passed\n- action bundle integrity check passed\n\n## Recovery scope\nThis is a line-scoped finalization recovery for Ref Promotion run 30110895857. It does not alter package version state, published artifacts, or affected-native proof reuse semantics.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T17:09:20Z",
          "mergedAt": "2026-07-24T17:10:23Z",
          "additions": 73,
          "deletions": 40,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1676,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1676",
          "title": "fix(release): admit exact recovery transaction",
          "body": "## Summary\n- admit only exact line-scoped release recovery PRs at the provider-enforced channel entrance\n- retain explicit audit evidence for tree-equivalent recovery sources\n- reject recovery branches targeting another release line\n\n## Validation\n- `pnpm run check` (823 tests passed)\n- action bundle integrity passed\n\nThis is a fail-closed recovery for the partially completed v2.14.18 stable transaction.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T17:21:19Z",
          "mergedAt": "2026-07-24T17:25:04Z",
          "additions": 146,
          "deletions": 54,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1436,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1436",
          "title": "fix(cli): refresh global work surface catalog",
          "body": "## Summary\n\nRefresh the deterministic CLI surface catalog after the strict global Work commands changed the live Click tree, and propagate the new exact root into Buildchain KFD evidence.\n\n## Related issue\n\nAtlas go: 2026-07-24-kungfu-global-work-view-strict-clean-closure\nFollow-up to #1423.\n\n## Changes\n\n- regenerate the complete CLI surface catalog with catalog-maintain and the new Work projection options\n- refresh the registry expected surface root\n- refresh KFD-2 onboarding and release claim hashes plus the KFD-3 prebuild source witness\n\n## Verification\n\n- CLI catalog generator --check\n- ./shifu check:cli-catalog-parity\n- CLI surface contract tests: 20 passed\n- ./shifu test:cli-surface-qualification: 28 passed\n- full staged pre-commit gate, including KFD evidence and docs 92/92\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f8e99-9354-7ab6-a9ba-b166f83f25a3\"],\n  \"summary\": \"Close the strict global Work delivery by refreshing its deterministic installed CLI catalog and downstream KFD evidence.\",\n  \"verification\": [\"CLI catalog parity\", \"CLI surface contract tests\", \"staged repository gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR refreshes generated release evidence only; it does not publish a release.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Generated artifacts and downstream claims are synchronized\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T16:19:19Z",
          "mergedAt": "2026-07-24T17:28:29Z",
          "additions": 163,
          "deletions": 22,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1677,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1677",
          "title": "fix(release): admit exact recovery transaction",
          "body": "## Summary\n- admit only exact line-scoped release recovery PRs at the provider-enforced channel entrance\n- retain explicit audit evidence for tree-equivalent recovery sources\n- reject recovery branches targeting another release line\n\n## Validation\n- `pnpm run check` (823 tests passed)\n- action bundle integrity passed\n\nThis keeps the release recovery contract on dev after the v2.14 line recovery.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T17:23:57Z",
          "mergedAt": "2026-07-24T17:28:46Z",
          "additions": 146,
          "deletions": 54,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1680,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1680",
          "title": "fix(release): bind recovery to exact candidate base",
          "body": "## Summary\n- validate the recovery PR by its immutable base/head SHA pair\n- require the base to equal the selected alpha or exact qualified release candidate\n- require merged promotion tree equality with the reviewed recovery head\n\n## Validation\n- promotion action tests: 130 passed\n- workflow and bundle integrity checks passed\n\nThis is the exact-line recovery for the partially completed v2.14.18 transaction; affected-native proof reuse semantics are unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T17:39:21Z",
          "mergedAt": "2026-07-24T17:42:42Z",
          "additions": 108,
          "deletions": 52,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1679,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1679",
          "title": "fix(release): bind recovery to exact candidate base",
          "body": "## Summary\n- validate an exact release-line recovery PR using its own immutable base/head SHA pair\n- require the recovery base to equal either the selected alpha or the exact qualified release candidate\n- require the merged promotion tree to equal the reviewed recovery head tree\n- keep cumulative unrelated changes outside the recovery admission decision\n\n## Validation\n- `node --test tests/promote-buildchain-ref.test.mjs` (130 passed)\n- `pnpm run check` (full suite passed)\n- action bundle integrity passed\n\nThis remains fail-closed and does not alter affected-native proof reuse semantics.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T17:38:23Z",
          "mergedAt": "2026-07-24T17:45:54Z",
          "additions": 108,
          "deletions": 52,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1683,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1683",
          "title": "fix(release): bind generated state to exact recovery RC",
          "body": "## Summary\n- release-line recovery copy of #1682\n- carry exact RC identity into generated stable version-state validation\n- validate the latest recovery PR over its own base/head diff, then validate only declared version-state changes from its exact RC-bound merge commit\n\n## Safety\n- exact promotion SHA and tree must equal the selected RC target\n- recovery head tree must equal that promotion tree\n- no affected-native proof reuse or identity semantics changed\n\n## Validation\n- focused exact RC/recovery tests passed\n- workflow validation passed\n- action bundle integrity passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T18:00:45Z",
          "mergedAt": "2026-07-24T18:02:23Z",
          "additions": 288,
          "deletions": 50,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1682,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1682",
          "title": "fix(release): bind generated state to exact recovery RC",
          "body": "## Summary\n- carry exact RC identity through generated stable version-state validation\n- validate a recovery PR only over its own base/head diff when its merge commit and tree equal the exact RC target\n- validate the generated version-state commit separately from that exact recovery parent\n\n## Safety\n- preserves fail-closed exact source/tree binding\n- does not change affected-native proof reuse or base/candidate merge-tree identity\n- falls back to the existing cumulative alpha comparison when no exact RC binding exists\n\n## Validation\n- `pnpm check` (824 tests passed)\n- focused release recovery and exact RC tests passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T18:00:13Z",
          "mergedAt": "2026-07-24T18:05:12Z",
          "additions": 288,
          "deletions": 50,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1438,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1438",
          "title": "fix(product): close installed profile suites",
          "body": "## Summary\n\nClose the exact installed Mission Control and Dogfood Profile Suite member sets so Assignment admission behaves the same in a CLI archive as it does in a source checkout. Keep custom Linux-only qualification runs from starting an unrelated macOS signing job.\n\n## Related issue\n\nNative dogfood Issue `issue-installed-mission-control-suite-closure`.\n\n## Changes\n\n- Materialize every declared first-party Suite member from sibling extensions when pnpm hoisting leaves the Suite-local dependency path absent, then fail closed unless each member resolves exactly once.\n- Add a hoisted-dependency regression and an exact installed-product Assignment capture/admission smoke to CLI archive qualification.\n- Skip the caller-owned macOS credential island for custom matrices that do not contain `macos-arm64`, and refresh the closed-world workflow authority digest.\n\n## Verification\n\n- `node --test scripts/documentation-product-pack.test.mjs scripts/alpha-promotion-preflight.test.mjs`\n- `./shifu test:cli-surface-qualification`\n- `./shifu check`\n- `./shifu check:source`\n- Linux exact-archive counterfactual: after materializing the two declared `work-dashboard` members, installed `kungfu assignment admit` returned `kungfu.assignment-orchestration.admission/v1` with Initiative and Assignment Episode receipts.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix restores the already-declared installed Profile Suite and qualification contracts without changing their architecture semantics.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe package boundary is covered by exact installed-layout admission, CLI qualification, source acceptance, and closed-world workflow authority validation. No publication is performed by this PR.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-24T17:12:05Z",
          "mergedAt": "2026-07-24T18:11:37Z",
          "additions": 242,
          "deletions": 2,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1686,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1686",
          "title": "fix(release): retry transient ref reads",
          "body": "## Summary\n- release-line copy of #1685\n- reuse the bounded GitHub read retry for ref reads and next-minor existence checks\n- preserve 404-as-missing behavior\n\n## Incident\nRecovery run 30115595633 failed twice on a transient 500 reading `tags/v2.15`.\n\n## Safety\nNo proof reuse, source identity, release identity, or allowed-path behavior changes.\n\n## Validation\n- focused transient-ref and exact recovery tests passed\n- action bundle integrity passed\n- full dev suite: 824 passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T18:16:23Z",
          "mergedAt": "2026-07-24T18:18:03Z",
          "additions": 71,
          "deletions": 68,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1685,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1685",
          "title": "fix(release): retry transient ref reads",
          "body": "## Summary\n- route protected-channel ref reads and next-minor tag existence checks through the existing bounded GitHub read retry\n- preserve 404-as-missing semantics while retrying only transient 5xx/socket failures\n- add production-shaped coverage for an initial 500 followed by a missing next-minor tag\n\n## Incident evidence\nStable recovery run 30115595633 failed twice on `GET git/ref/tags/v2.15` with `500 other side closed`; the same read succeeds as 404 outside the transient outage.\n\n## Safety\n- four attempts with bounded backoff already defined by `retryGitHubOperation`\n- no proof reuse, source identity, release identity, or allowed-path semantics changed\n\n## Validation\n- `pnpm check` (824 tests passed)\n- action bundle integrity passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T18:15:59Z",
          "mergedAt": "2026-07-24T18:20:30Z",
          "additions": 71,
          "deletions": 68,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1689,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1689",
          "title": "fix(release): admit explicit durable finalization",
          "body": "## Summary\n- release-line copy of #1688\n- wire explicit durable recovery into the publication action\n- permit finalization-only recovery under strict identity, artifact, state, and ancestry guards\n\n## Safety\nNo provider publication replay and no transaction identity rewrite. The old release material must be contained by the new release commit. No affected-native semantics change.\n\n## Validation\n- focused recovery tests passed\n- workflow validation passed\n- action bundle integrity passed\n- full dev suite: 825 passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T18:31:15Z",
          "mergedAt": "2026-07-24T18:33:00Z",
          "additions": 187,
          "deletions": 40,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1688,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1688",
          "title": "fix(release): admit explicit durable finalization",
          "body": "## Summary\n- pass the explicit durable-recovery signal from the dispatch workflow through the reusable promotion workflow into the action\n- allow that explicit override to select finalization-only recovery for an already published transaction\n- regenerate the public workflow and site contract projections\n\n## Fail-closed boundary\nRecovery still requires the same version, exact tag, target ref, terminal published/finalizing/complete state, complete required artifacts, and ancestry containment of the old release or release material by the new release commit. It does not replay provider publication and does not rewrite the original transaction identity.\n\n## Incident evidence\nRun 30116555150 proved exact RC and GitHub authority admission, then failed because `recover-durable-transaction` was not wired to `publish-transaction-override`.\n\n## Validation\n- `pnpm check` (825 tests passed)\n- workflow generation/check passed\n- action bundle integrity passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T18:30:23Z",
          "mergedAt": "2026-07-24T18:37:37Z",
          "additions": 187,
          "deletions": 40,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1439,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1439",
          "title": "fix(release): disambiguate Windows catalog assertion",
          "body": "## Summary\n\nRestore the frozen Alpha publication build on Windows and make native qualification planning select the full CMake profile that owns its scheduled test targets.\n\n## Related evidence\n\n- Supersedes the test compile failure in Alpha Build run `30110562445`.\n- Supersedes the merge-group planner failure in run `30113131223`, where the journal profile did not define the scheduled qualification targets.\n- Production comparison was already fixed and merge-queue qualified in #1434.\n\n## Changes\n\n- compare the generated primitive catalog root through explicit `std::string` values in `action_runtime_tests.cpp`\n- force the `full` native profile whenever `core-native-qualification` owns an affected path\n- extend the planner self-test so qualification paths cannot regress to the default journal profile\n\n## Verification\n\n- `node scripts/run-core-affected-native.mjs --self-test`: 28/28 fixtures passed\n- direct qualification-path reproduction: `profile=full`, seven qualification targets\n- `node --test scripts/run-core-affected-native.test.mjs`: 3/3 passed\n- `pnpm exec biome check --no-errors-on-unmatched scripts/run-core-affected-native.mjs`: passed\n- staged repository gate: passed, including 92/92 documentation fixtures\n- authoritative MSVC compile remains required in the protected merge-group and replacement Alpha Build\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This platform-compatibility and qualification-planning bugfix restores the declared native test targets without changing architecture, release authority, installer behavior, or public API.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo signing material is read or changed by this patch.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (planner invariant covered by self-test)",
          "author": "dongkeren",
          "createdAt": "2026-07-24T17:14:02Z",
          "mergedAt": "2026-07-24T18:49:59Z",
          "additions": 5,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1691,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1691",
          "title": "fix(release): make scoped recovery actionable",
          "body": "## Summary\n\n- keep release-line recovery fail-closed on the existing exact path allowlist\n- report the exact follow-up recovery procedure and allowed paths\n- rebuild the committed promotion action bundle\n\n## Validation\n\n- `pnpm run check` (825 tests passed)\n- `git diff --check`\n\n## Recovery intent\n\nThis PR is the exact line-scoped relay anchor for the durable v2.14 finalization transaction. It contains the preceding release candidate without broadening the recovery allowlist.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T18:46:44Z",
          "mergedAt": "2026-07-24T18:52:13Z",
          "additions": 45,
          "deletions": 40,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1692,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1692",
          "title": "fix(release): relay durable finalization recovery",
          "body": "## Summary\n\n- preserve the existing exact release-line recovery allowlist\n- carry the durable finalization runtime through a follow-up line-scoped recovery anchor\n- make future out-of-scope recovery failures report the exact safe follow-up procedure\n\n## Validation\n\n- inherited from PR #1691: `pnpm run check` (825 tests passed)\n- release diff is limited to `actions/promote-buildchain-ref/`\n\n## Transaction safety\n\nThis recovery candidate contains the preceding release candidate. It does not republish provider artifacts, rewrite transaction identity, or broaden the recovery allowlist.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T18:53:16Z",
          "mergedAt": "2026-07-24T18:56:12Z",
          "additions": 45,
          "deletions": 40,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1693,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1693",
          "title": "Release v2.14.18",
          "body": "Create the generated version-state commit for v2.14.18.\n\nBuildchain generated this PR because protected branch release/v2/v2.14 rejected direct generated bookkeeping.\n\nRejected update: d180f53024e3ab863d38e74e592def619bbedcb5 -> a95253d5c782c46fa3e719db4f9af55a69db2517\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T19:00:33Z",
          "mergedAt": "2026-07-24T19:03:21Z",
          "additions": 9,
          "deletions": 9,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1441,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1441",
          "title": "fix(product): stabilize installed profile closure",
          "body": "## Summary\n\nEnsure installed first-party Profile Suites never depend on transient pnpm `node_modules` links. Materialize declared external members under the stable `members/` closure so the installed Assignment smoke observes the same package set after archive packaging.\n\n## Related evidence\n\n- Native dogfood Issue `issue-installed-mission-control-suite-closure`.\n- Exact source build run 30116119822 reproduced the failure after build lifecycle, proving the transient-link branch was still incomplete.\n\n## Changes\n\n- Exclude `node_modules` from installed first-party Profile copies.\n- Materialize missing declared members under `members/<key>` from the sibling first-party extension authority.\n- Add a regression where a Suite-local workspace symlink exists during freeze but must not survive in the installed closure.\n\n## Verification\n\n- `node --test scripts/documentation-product-pack.test.mjs`\n- `./shifu check:source`\n- full staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix makes the already-declared installed Profile Suite closure independent of transient package-manager layout without changing architecture semantics.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change is limited to deterministic installed package closure and its regression. No publication is performed by this PR.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-24T18:30:41Z",
          "mergedAt": "2026-07-24T19:18:13Z",
          "additions": 35,
          "deletions": 24,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1696,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1696",
          "title": "fix(release): bind exact candidate version parent",
          "body": "## Summary\n- accept a generated stable version-state commit only when its parent SHA and tree exactly match the PR-stage RC passport promotion-channel binding\n- still require a merged same-repository target PR and allow only declared version-state paths between parent and generated commit\n- preserve the existing release-recovery path allowlist without expansion\n\n## Validation\n- targeted exact recovery parent tests: 2 passed\n- `pnpm run check`: 826 passed, 0 failed\n- action bundle integrity: passed\n- `git diff --check`: passed\n\nThis does not change affected-native proof reuse or source/base/toolchain identity semantics.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T19:13:13Z",
          "mergedAt": "2026-07-24T19:19:19Z",
          "additions": 277,
          "deletions": 53,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1440,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1440",
          "title": "fix(cli): settle deprecated alias authority",
          "body": "## Summary\n\nCorrect the pre-release CLI alias settlement from repository evidence. `kungfu env` remains the native installed-runtime authority and `kungfu sdk` remains the public SDK/KFD authority. Their `kungfu dev ...` routes are quiet identity-preserving compatibility paths. The other 25 aliases remain deprecated and blocked from removal until external usage evidence and a separate major-release decision exist.\n\nThis linear successor supersedes #1435 after the protected queue merged #1425 and #1436. It preserves the Agent Hub qualification outputs, the global Work surface catalog, and all prior dogfood and Primitive CLI families while combining them with the alias evidence authority and regenerating 158 KFD-3 surfaces.\n\n## Related issue\n\nSupersedes #1435, #1431, #1422, and #1420.\n\n## Changes\n\n- add machine-readable disposition profiles, evidence, gate states, and next actions for every alias\n- emit deprecation warnings only for aliases whose status is `deprecated`\n- migrate the authored schema example while retaining the legacy route\n- preserve the merged Agent Hub, global Work, dogfood, and Primitive command families while combining registry authorities\n- regenerate the CLI catalog, canonical policy, and KFD evidence from their registered generators\n- add negative and behavior tests for missing evidence, quiet compatibility aliases, and blocked removals\n\n## Verification\n\n- focused CLI and Primitive tests (44 passed)\n- `./shifu check:cli-catalog-parity`\n- `./shifu kfd:buildchain:check` (158 KFD-3 surfaces)\n- `./shifu check:source` (605 tests: 595 pass, 10 skip; 116 runtime-upgrade; 69 desktop-update)\n- staged pre-commit gate\n- Project Cut merge-queue admission on the #1436 merge-group base (`decision=qualified`, `compositionChanged=false`)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix corrects pre-release CLI canonical-path metadata and publishes removal evidence without changing an architecture contract or removing a public command.\"\n}\n-->\n\n## Governance risk check\n\n- [x] No CLI route is removed.\n- [x] Deprecated aliases remain callable and warn consistently.\n- [x] Quiet compatibility aliases preserve native command identity.\n- [x] Removal is blocked without external usage evidence and a separate major-release decision.\n- [x] Release evidence and KFD projections were regenerated from registered generators.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T17:30:06Z",
          "mergedAt": "2026-07-24T19:42:34Z",
          "additions": 868,
          "deletions": 230,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1523,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1523",
          "title": "fix(release): bind exact candidate version parent",
          "body": "Recovered release-line relay of #1696 after GitHub new-PR creation repeatedly returned HTTP 500. This PR was originally authored by dongkeren and never merged; its existing publish-gate head was joined to the current release base with an exact-tree merge before adding the three-file validator fix. No force push or protected-ref write occurred. The final diff is limited to the action source, generated bundle, and regression test. Exact candidate SHA/tree only; source/base/toolchain identity remains fail-closed. Validation: pnpm run check; git diff --check.",
          "author": "dongkeren",
          "createdAt": "2026-07-22T05:39:21Z",
          "mergedAt": "2026-07-24T19:49:56Z",
          "additions": 277,
          "deletions": 53,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1697,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1697",
          "title": "Release v2.14.18",
          "body": "Create the generated version-state commit for v2.14.18.\n\nBuildchain generated this PR because protected branch release/v2/v2.14 rejected direct generated bookkeeping.\n\nRejected update: 0c16188fc95f0b966f36f4af274374ee522f1837 -> 23e48409a4e234870d1962c9d3e358f30eec9e63\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T19:56:35Z",
          "mergedAt": "2026-07-24T19:59:41Z",
          "additions": 9,
          "deletions": 9,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1700,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1700",
          "title": "Release v2.14.18",
          "body": "Create the generated version-state commit for v2.14.18.\n\nBuildchain generated this PR because protected branch release/v2/v2.14 rejected direct generated bookkeeping.\n\nRejected update: 2b2ee6aebeb801730d645843156ebed3810e3cd7 -> e56bd96ceeffc78fe1eedc4f5a4f0496e378373e\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T20:11:57Z",
          "mergedAt": "2026-07-24T20:15:22Z",
          "additions": 9,
          "deletions": 9,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1704,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1704",
          "title": "fix(release): stabilize durable finalization lifecycle",
          "body": "## Summary\n\n- preserve an already-published durable transaction's lifecycle timestamp/source identity when the protected release branch contains its exact release material\n- continue running the declared lifecycle verification and generate a new version-state commit for any real derived-content change\n- stop merge-SHA/timestamp-only version-state PR churn during stable finalization\n\n## Verification\n\n- `pnpm run check` (826 tests passed)\n- action bundle integrity check passed\n\nThis does not change affected-native proof identity or base/candidate merge-tree binding.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T20:31:13Z",
          "mergedAt": "2026-07-24T20:36:12Z",
          "additions": 157,
          "deletions": 64,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1706,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1706",
          "title": "fix(release): stabilize durable finalization lifecycle",
          "body": "## Summary\n\nBackport the dev-reviewed durable finalization fix from #1704 to the protected v2.14 release line.\n\n- preserve the contained published transaction lifecycle identity on recovery\n- keep lifecycle verification fail-closed for real derived-content changes\n- stop merge-SHA/timestamp-only version-state PR churn\n\n## Verification\n\n- identical implementation/test/dist tree to reviewed PR #1704\n- `pnpm run check` on that exact tree: 826 tests passed\n\nThis does not change affected-native proof identity or base/candidate merge-tree binding.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T20:39:19Z",
          "mergedAt": "2026-07-24T20:42:14Z",
          "additions": 157,
          "deletions": 64,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1709,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1709",
          "title": "chore(release): reconcile reviewed major gate history",
          "body": "## Summary\n\nReconcile the already reviewed and merged #1613 major-gate commit into the current protected v2.14 release history so the next `release/v2/v2.14 -> publish-gate/major` PR is up to date.\n\n## Invariant\n\nThis merge commit has the exact same tree as its first parent `63f8ca194fae1d70fd2794b4e3e64d28c579c114`; it changes history only and introduces no file-content delta.\n\n## Verification\n\n- first-parent tree: `97379cca4b6d8e34c27dcd87720b8d4300937d4b`\n- candidate tree: `97379cca4b6d8e34c27dcd87720b8d4300937d4b`\n- second parent: independently reviewed #1613 merge `0eb1db96d2c4d788f5d0ff0d8c8d690ceeb8cc64`\n\nNormal protected PR checks and exact-head independent approval remain required.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T20:56:37Z",
          "mergedAt": "2026-07-24T21:00:08Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1444,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1444",
          "title": "fix(product): bind installed profile invocation source",
          "body": "## Summary\n\nKeep every installed Mission Control member action bound to the exact Profile Suite source that invoked it, so a packaged product cannot rediscover a second checkout with a different Suite root.\n\n## Related evidence\n\n- Native dogfood Issue `issue-installed-mission-control-suite-closure`.\n- Exact package build run 30120404083 reproduced the distinct-root rejection.\n- The failed package was preserved and instrumented on agent-120; adapter invocation received the installed source while domain rediscovery selected the repository extension copy.\n\n## Changes\n\n- Bind the adapter invocation source through a scoped ContextVar for the complete Mission Control operation.\n- Preserve direct domain discovery when no adapter source is bound.\n- Add an installed-layout regression proving member actions use the copied Suite root.\n- Refresh primitive catalog and KFD projections after the source change.\n\n## Verification\n\n- Patched exact package smoke on agent-120 completed Assignment capture and admission successfully.\n- `./shifu check:source`\n- full staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix preserves the already-declared exact Profile Suite authority across installed adapter invocation without changing architecture semantics.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change is limited to exact installed Profile source binding and regression evidence. No publication is performed by this PR.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-24T20:17:06Z",
          "mergedAt": "2026-07-24T21:01:18Z",
          "additions": 123,
          "deletions": 36,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1710,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1710",
          "title": "chore(release): refresh major gate approval identity",
          "body": "## Summary\n\nCreate a protected, independently reviewed zero-content recovery point so the `publish-gate/major` last-push approval can be satisfied by a different identity from the release updater.\n\n## Invariant\n\nThe candidate commit tree is exactly identical to its first parent. No source, workflow, generated state, proof identity, or release material changes.\n\nThis PR must be approved by `kungfu-origin` and merged normally by `dongkeren`; no administrator bypass is permitted.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T21:05:32Z",
          "mergedAt": "2026-07-24T21:08:35Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1711,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1711",
          "title": "release: finalize v3.0.0 from current v2.14 line",
          "body": "## Summary\n\nPromote the current protected `release/v2/v2.14` line through the reviewed major gate so v3 publication uses the admitted Governance Auditor runtime and all fail-closed release fixes.\n\n## Identity\n\n- exact head: `93752dffc96acb9a6e8983ca9fd072f879a64762`\n- the head contains the already reviewed #1613 major-gate history\n- the latest release update was normally merged by `dongkeren`, so `kungfu-origin` can satisfy the fresh last-push Code Owner approval\n\n## Acceptance\n\nAfter clean checks and independent exact-head approval, merge normally and verify `v3.0.0`, floating v3 refs, next-alpha refs, npm, GitHub Release/passport, and controller receipt.\n\nReplaces #1708. Relates to #1643.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T21:13:11Z",
          "mergedAt": "2026-07-24T21:15:23Z",
          "additions": 11633,
          "deletions": 721,
          "changedFiles": 97
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1445,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1445",
          "title": "fix(product): align installed SDK alias qualification",
          "body": "## Summary\n\nAlign the installed product CLI surface qualification with the current SDK alias authority: `kungfu sdk` is canonical and `kungfu dev sdk` is a non-deprecated compatibility path.\n\n## Related evidence\n\n- Exact Phase B source build run 30126438108 passed installed Assignment/Profile qualification, then failed with `[product] failed: SDK alias is missing`.\n- The registry and generated Agent catalog already identify `kungfu sdk` as canonical; only the product qualifier and fixture retained the inverse assertion.\n\n## Changes\n\n- Qualify `kungfu sdk` as canonical and `kungfu dev sdk` as its compatibility path.\n- Assert neither corrected canonical path nor compatibility path emits a deprecation warning.\n- Update the installed qualification receipt projection and fixture.\n\n## Verification\n\n- `node --test product/scripts/cli-surface-qualification.test.mjs`\n- `./shifu check:source`\n- full staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix aligns an installed-product qualifier with the already-declared SDK alias authority without changing CLI architecture or behavior.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change updates installed product qualification only. It performs no publication.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-24T21:22:59Z",
          "mergedAt": "2026-07-24T21:29:24Z",
          "additions": 20,
          "deletions": 17,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1713,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1713",
          "title": "fix(release): bind major gate to exact candidate lineage",
          "body": "## Summary\n- trace major-gate admission through its exact merged release head\n- require that release head to equal the selected release PR merge SHA\n- reuse only the release PR Build Surface Fixture candidate; downstream authority still verifies the admitted major source tree\n\n## Validation\n- `node --test tests/release-candidate.test.mjs` (19/19)\n- `pnpm run check` (828/828)\n- live read-only resolver rehearsal: major `c18c9e3` -> release PR #1710 -> run 30126503376 -> candidate `352fa9d`\n\nNo affected-native proof identity or base/candidate merge-tree binding is changed.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T21:27:38Z",
          "mergedAt": "2026-07-24T21:32:22Z",
          "additions": 190,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1714,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1714",
          "title": "fix(release): backport exact major candidate lineage",
          "body": "Backports the exact dev fix from #1713.\n\n- requires major -> release head -> exact release PR merge lineage\n- preserves downstream source-tree equality verification\n- does not alter affected-native proof identity\n\nValidation: `node --test tests/release-candidate.test.mjs` (19/19); dev full suite 828/828.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T21:33:10Z",
          "mergedAt": "2026-07-24T21:36:03Z",
          "additions": 190,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1716,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1716",
          "title": "chore(release): refresh major gate approver",
          "body": "Zero-content, tree-preserving release PR. Its sole purpose is to make the protected release head last-pushed by dongkeren so kungfu-origin can satisfy the independent last-push approval on the downstream major-gate PR.\n\nNo files or proof identities change; normal release checks must still pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T21:38:48Z",
          "mergedAt": "2026-07-24T21:41:52Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1718,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1718",
          "title": "chore(release): refresh major reviewable push identity",
          "body": "Tree-equivalent two-commit history refresh:\n\n1. revert the exact major-candidate lineage patch\n2. replay the identical signed-off patch\n\nThe final tree is byte-for-byte identical to release/v2/v2.14, while the most recent reviewable content push is explicitly authenticated as dongkeren. This lets CODEOWNER kungfu-origin supply the independent last-push approval for the downstream major gate without weakening policy.\n\nValidation: final tree equality asserted; release-candidate tests 19/19.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T21:51:34Z",
          "mergedAt": "2026-07-24T21:54:52Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1719,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1719",
          "title": "chore(release): promote v2.14 authority fix to major gate",
          "body": "Promotes release/v2/v2.14 after #1714 and the tree-equivalent reviewable-push identity refresh #1718.\n\n- final source tree is unchanged by #1718\n- latest reviewable content push is explicitly dongkeren\n- kungfu-origin remains the CODEOWNER reviewer\n- resolver requires exact major -> release head -> release PR merge lineage and downstream source-tree equality\n\nSupersedes closed #1715 and #1717 without changing base content or proof semantics.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T21:55:14Z",
          "mergedAt": "2026-07-24T21:57:54Z",
          "additions": 190,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1720,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1720",
          "title": "fix(release): admit exact release passport for major",
          "body": "## Summary\n- map the major publication channel to release-candidate evidence from the exact release line\n- preserve exact admitted source-tree, controller, artifact, and governance bindings\n- reject alpha passport substitution for a major publication\n\n## Verification\n- `corepack pnpm exec node --test tests/publication-authority.test.mjs tests/release-candidate.test.mjs` (42 pass)\n- `corepack pnpm run check` (829 pass; workflow/site/action bundle checks pass)",
          "author": "dongkeren",
          "createdAt": "2026-07-24T22:03:56Z",
          "mergedAt": "2026-07-24T22:08:59Z",
          "additions": 39,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1721,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1721",
          "title": "fix(release): backport major passport channel admission",
          "body": "Backports #1720 to the v2.14 release line so the next exact release merge tree can produce qualifying release-channel passport evidence for major promotion.\n\nPreserves exact source-tree, controller, artifact, and governance bindings.\n\nVerification: 42 focused tests pass; generated site contract check passes.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T22:09:47Z",
          "mergedAt": "2026-07-24T22:12:42Z",
          "additions": 39,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1723,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1723",
          "title": "chore(release): refresh major passport reviewable push",
          "body": "Refreshes the latest reviewable content push under dongkeren for independent CODEOWNER approval of the subsequent major promotion.\n\nThis is a two-commit revert/replay. The final tree is exactly identical to release head before this PR:\n\n`10d1fe25d21b87cef271e561fb86e74737f7244d`\n\nNo release content or evidence semantics change.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T22:15:32Z",
          "mergedAt": "2026-07-24T22:18:55Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1725,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1725",
          "title": "chore(release): seal dongkeren major review authority",
          "body": "Second tree-equivalent two-commit revert/replay refresh. Final tree remains exactly `10d1fe25d21b87cef271e561fb86e74737f7244d`.\n\nRequired merge choreography: kungfu-origin approves this PR; dongkeren performs the release merge so the subsequent major PR has an independent CODEOWNER reviewer.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T22:21:09Z",
          "mergedAt": "2026-07-24T22:24:13Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1393,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1393",
          "title": "fix(core): extinguish Python semantic fallbacks",
          "body": "## Summary\n\nExtinguish silent Python semantic authority in Action runtime paths and establish explicit canonical JSON protocols with one language-neutral conformance corpus.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- require native Action Runtime for public Domain Profile and Action Geometry operations, with explicitly gated Python conformance oracles\n- define Action, Python identity, and Workspace canonical JSON v1 protocols and shared positive/negative vectors\n- run Python and native C++ conformance against the same corpus\n- project Episode record vocabulary from one authoritative typed native inspection without a second storage read\n- pin the synthetic source qualification helper with exact vectors and update the incubation passport\n\n## Verification\n\n- `./shifu check:source`\n- `cmake --build framework/core/build --target pykungfu kungfu_action_geometry_tests --parallel 8`\n- `ctest --test-dir framework/core/build -R '^kungfu_action_geometry_tests$' --output-on-failure`\n- focused native/Python canonical, Action shadow, typed storage, Mission Control, and Exit tests\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f87cb-b4e7-7cda-80ec-be5aceb7b500\"],\n  \"summary\": \"Close the canonical JSON protocol and native Action authority boundary without reinterpreting historical identity bytes\",\n  \"verification\": [\"source acceptance\", \"shared Python and C++ canonical vectors\", \"single-read typed Episode projection\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T02:29:43Z",
          "mergedAt": "2026-07-24T22:25:53Z",
          "additions": 1001,
          "deletions": 260,
          "changedFiles": 52
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1726,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1726",
          "title": "release: promote sealed v2.14 authority to major",
          "body": "Promotes the exact release/v2/v2.14 head produced by #1725 into publish-gate/major.\n\nThe release tree remains `10d1fe25d21b87cef271e561fb86e74737f7244d`; the release merge was performed by dongkeren after independent kungfu-origin approval. Resolver must bind #1725 and Build Surface run 30130684490.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T22:24:27Z",
          "mergedAt": "2026-07-24T22:26:05Z",
          "additions": 39,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1728,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1728",
          "title": "fix(release): admit release passport in major promotion",
          "body": "## Summary\n- map major publication validation to the release passport evidence channel\n- keep exact source tree binding unchanged\n- cover release acceptance and non-release rejection for major promotion\n\n## Verification\n- `node --test tests/promote-buildchain-ref.test.mjs` (134 pass)\n- `corepack pnpm run check` (830 pass)",
          "author": "dongkeren",
          "createdAt": "2026-07-24T22:34:55Z",
          "mergedAt": "2026-07-24T22:39:48Z",
          "additions": 72,
          "deletions": 25,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1447,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1447",
          "title": "fix(release): lock promotion builds to source gate",
          "body": "## Summary\n\nLock Alpha and release promotion builds to the exact `publish-gate/*` source branch instead of allowing Buildchain to fall back to the synthetic pull-request merge commit.\n\n## Changes\n\n- Pass the promotion PR head as Buildchain `publish-source-ref` only when it is a governed `publish-gate/*` branch.\n- Weld that source-lock requirement into the release-promotion rehearsal.\n- Refresh the closed-world workflow authority digest.\n\n## Verification\n\n- `./shifu check:source`\n- focused release-promotion and source-acceptance tests\n- full staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This release-control fix closes exact source provenance without changing product architecture or accepted ADR delivery.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change narrows release provenance and performs no publication itself.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T22:08:00Z",
          "mergedAt": "2026-07-24T22:43:02Z",
          "additions": 8,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1730,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1730",
          "title": "fix(release): backport major passport promotion admission",
          "body": "## Summary\n- backport #1728 to the v2.14 release line\n- admit release-channel passports for major promotion only\n- preserve exact source-tree binding\n\n## Verification\n- `node --test tests/promote-buildchain-ref.test.mjs` (134 pass)",
          "author": "dongkeren",
          "createdAt": "2026-07-24T22:46:16Z",
          "mergedAt": "2026-07-24T22:49:52Z",
          "additions": 72,
          "deletions": 25,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1731,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1731",
          "title": "release: promote sealed v2.14 promotion admission to major",
          "body": "## Summary\n- promote the reviewed v2.14 release-line head to the major publication gate\n- source evidence: release PR #1730, Build Surface run 30131925402\n- preserve exact source-tree binding; major consumes the release-channel passport for the same tree\n\n## Lineage\n- dev fix: #1728\n- release backport: #1730\n- release merge: bb7db73517deeb200f18ff6ad3f04c29a82869a3",
          "author": "dongkeren",
          "createdAt": "2026-07-24T22:50:24Z",
          "mergedAt": "2026-07-24T22:52:02Z",
          "additions": 72,
          "deletions": 25,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1733,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1733",
          "title": "fix(release): bound major self-dogfood bootstrap",
          "body": "## Summary\n- permit the adjacent-major bootstrap only inside publish-gate/major version-state verification\n- bound the exception to N.0.0 and N.0.1-alpha.x while preserving the prior accepted self-dogfood lock\n- keep normal inventory checks strict and add fail-closed boundary tests\n\n## Verification\n- `node --test tests/promote-buildchain-ref.test.mjs` (134 pass)\n- `corepack pnpm run check` (831 pass)\n\n## Follow-up\nAfter v3-alpha exists, migrate the new dev/v3 line to an exact v3-alpha self-dogfood lock so the bootstrap context is no longer needed for normal checks.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T23:04:04Z",
          "mergedAt": "2026-07-24T23:09:54Z",
          "additions": 164,
          "deletions": 8,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1734,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1734",
          "title": "fix(release): bound major self-dogfood bootstrap",
          "body": "Backports the bounded major bootstrap context to the v2.14 release line. Normal self-dogfood validation remains exact-major and fail-closed; only the major promotion action enables the adjacent N.0.0/N.0.1-alpha.0 bootstrap allowance.\\n\\nValidation: `node --test tests/promote-buildchain-ref.test.mjs`; `corepack pnpm run check` (831/831).",
          "author": "dongkeren",
          "createdAt": "2026-07-24T23:12:10Z",
          "mergedAt": "2026-07-24T23:15:19Z",
          "additions": 164,
          "deletions": 8,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1736,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1736",
          "title": "chore(release): reconcile major promotion ancestry",
          "body": "Reconciles the prior `publish-gate/major` merge ancestry into the release line so the next major PR satisfies strict up-to-date protection. The resulting tree remains exactly `450f548815f1c43ede2184147673c0aa745c4508`; this PR changes history only, not content.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T23:17:14Z",
          "mergedAt": "2026-07-24T23:20:20Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1735,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1735",
          "title": "chore(release): promote v2.14 to major channel",
          "body": "Promotes the sealed v2.14 release candidate through the major publication gate. Candidate source is the exact release merge dda52d75d75d90592caa62ae2aa92be35a7564a8 with tree 450f548815f1c43ede2184147673c0aa745c4508. The bounded major self-dogfood bootstrap applies only inside the major promotion action.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T23:15:40Z",
          "mergedAt": "2026-07-24T23:21:58Z",
          "additions": 164,
          "deletions": 8,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1738,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1738",
          "title": "fix(release): isolate major bootstrap verification",
          "body": "Closes the two fail-closed gaps exposed by major promotion run 30133647351 and the history-only release rerun 30133570678. Preserved publication identity now explicitly clears inherited lifecycle identity variables. The explicit adjacent-major bootstrap projects only the major line for prior-alpha contract evaluation while continuing to reject any breaking surface digest drift.\\n\\nValidation: targeted build-surface + promotion tests (220/220); full `pnpm run check` (831/831); bundle integrity.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T23:34:27Z",
          "mergedAt": "2026-07-24T23:39:07Z",
          "additions": 139,
          "deletions": 35,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1407,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1407",
          "title": "fix(docs): close ADR and authority consistency gaps",
          "body": "## Summary\n\nClose the repository-audit documentation and ADR consistency findings without\nrewriting historical decision prose. The change distinguishes partial\namendment from supersession, separates authority availability from\nlanguage-envelope parity, and makes Mission/Go compatibility explicit and\nfail-closed.\n\n## Related issue\n\nRepository-wide documentation and architecture consistency audit.\n\n## Changes\n\n- add reciprocal, acyclic `amends` / `amended_by` metadata for three partial\n  ADR corrections while preserving the accepted remainder of each earlier ADR\n- close stale ADR-0003/0004/0005/TUI status and repair the ADR-0001\n  implementation path without rewriting historical analysis\n- render Work lifecycle authority availability separately from\n  language-envelope parity so native `missing` routes are visibly unavailable\n- align Project Cut and Mission Control documentation with current\n  Initiative/Assignment authority and bounded Mission/Go compatibility\n- govern Mission/Go compatibility vocabulary, prose policy, action metadata,\n  and Profile SDK successor-authority conservation\n- document exact frontmatter-only metadata coverage as 124 registry + 173\n  inline = 297 documents with no overlap\n\n## Verification\n\n- complete staged pre-commit gate\n- deterministic documentation gate: 368 linted Markdown files, 367\n  contract-checked files, 93 negative fixtures, ADR structural findings 0\n- prose gate: 292 files, 0 errors\n- Work lifecycle operation matrix contract tests: 6/6\n- Profile SDK suite: 60/60 against the current installed native binding\n- source acceptance: 585 Node tests passed, 3 skipped; Python, type, format,\n  runtime surface, and `git diff --check` passed\n- Project Cut run gate on the final source head\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-70c5-b572-89ec183b37de\",\n    \"KF-ADR-019f86da-4f90-7179-a900-c40bdb498910\",\n    \"KF-ADR-019f86da-4f90-76ce-8957-f95affe9341a\",\n    \"KF-ADR-019f86da-4f90-77c0-827b-fe1a3aa43e2b\",\n    \"KF-ADR-019f86da-4f90-7828-9142-46f9bca4b0f5\",\n    \"KF-ADR-019f86da-4f90-7c76-bf49-3e804d3ba63f\",\n    \"KF-ADR-019f86da-4f90-7cb5-b65c-b463768e7ae8\",\n    \"KF-ADR-019f86da-4f90-7d72-bf9f-1d5913bbb0d5\"\n  ],\n  \"summary\": \"Close bounded ADR, documentation authority, compatibility vocabulary, and generated lifecycle presentation gaps.\",\n  \"verification\": [\n    \"complete staged and documentation gates\",\n    \"reciprocal amendment graph negative tests\",\n    \"Work lifecycle availability projection tests\",\n    \"Profile alias successor-authority validation\",\n    \"Project Cut exact-source run gate\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change updates ADR implementation/closure evidence and exact Profile\nartifact hashes. It does not publish packages, deploy services, or widen\nrelease qualification claims.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T09:08:07Z",
          "mergedAt": "2026-07-24T23:40:04Z",
          "additions": 702,
          "deletions": 153,
          "changedFiles": 43
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1739,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1739",
          "title": "fix(release): isolate major bootstrap verification",
          "body": "Backports #1738 and reconciles current `publish-gate/major` ancestry in the same reviewed release PR. This prevents another history-only promotion trigger. Tree includes only the six-file bootstrap isolation patch over the release content.\\n\\nValidation: targeted 220/220; full 831/831; bundle integrity.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T23:41:58Z",
          "mergedAt": "2026-07-24T23:44:00Z",
          "additions": 139,
          "deletions": 35,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1740,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1740",
          "title": "chore(release): promote v2.14 bootstrap isolation",
          "body": "Promotes the reviewed bootstrap-isolation release candidate. Exact source is release merge `851fe8ed5e1a61503e425d8518d8bd0649f84305`, tree `c7c8f6fa20daf8947cc661f9d37e3157a10c5480`. The release history already contains current major ancestry.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T23:45:29Z",
          "mergedAt": "2026-07-24T23:47:13Z",
          "additions": 139,
          "deletions": 35,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1742,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1742",
          "title": "fix(release): admit bounded bootstrap recovery files",
          "body": "Extends release recovery scope by exactly three bootstrap support files: `packages/core/self-dogfood-version.js`, `scripts/check-inventory.mjs`, and `tests/build-surface.test.mjs`. Other core, generator, and contract test paths remain rejected.\\n\\nValidation: targeted promotion tests 135/135; full check 832/832; bundle integrity.",
          "author": "dongkeren",
          "createdAt": "2026-07-24T23:55:34Z",
          "mergedAt": "2026-07-25T00:00:32Z",
          "additions": 67,
          "deletions": 35,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1449,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1449",
          "title": "fix(product): accept installed runtime path aliases",
          "body": "## Summary\n\nAccept filesystem-equivalent installed runtime roots so Windows long paths and 8.3 short-path aliases cannot falsely downgrade a manifest-bound Kungfu installation to foreign provenance.\n\n## Changes\n\n- Preserve the lexical installed-runtime boundary and add a `Path.samefile()` fallback for filesystem aliases.\n- Add a focused regression for an installed binding reached through an alias root.\n- Remove the premature PR-stage `publish-source-ref`; post-merge promotion remains responsible for source locking.\n- Weld the PR-stage source-lock boundary into the release-promotion rehearsal and refresh workflow authority.\n\n## Failure evidence\n\n- Alpha Build run `30128140371` resolved the same pull-merge tree under two Windows path spellings, then failed Assignment admission because the binding path and runtime root were lexically different.\n- Diagnostic run `30131920234` confirmed that a PR-stage publish source lock incorrectly targeted the post-merge channel branch before the release candidate was merged.\n\n## Verification\n\n- `./shifu check:source`\n- `node --test scripts/release-promotion-rehearsal.test.mjs` (10 passed)\n- `PYTHONPATH=framework/core/src/python:framework/core/build/Release uv run --project framework/core --frozen pytest -q framework/core/tests/python/test_assignment_orchestration.py` (17 passed)\n- full staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix preserves the installed provenance boundary while recognizing filesystem-equivalent paths; it does not change accepted product architecture.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change narrows release admission to filesystem identity and performs no publication itself.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T23:16:14Z",
          "mergedAt": "2026-07-25T00:02:44Z",
          "additions": 56,
          "deletions": 6,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 2,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/2",
          "title": "fix: qualify the Docker-first Hub Starter runtime",
          "body": "## Summary\n- bind the installed Kungfu provenance contract and exact qualified CLI package\n- make the documented loopback Compose path and direct two-instance smoke genuinely host-reachable\n- retain fail-closed machine-readable image identity, readiness, isolation, settlement, restart, and security evidence\n- lock the development-pre-alpha image by digest for bare docker compose up\n\n## Evidence\n- Kungfu Build + Phase B: https://github.com/kungfu-systems/kungfu/actions/runs/30128094872\n- Runtime image qualification: https://github.com/kungfu-systems/runtime-images/actions/runs/30135228454\n- Image: ghcr.io/kungfu-systems/runtime-images/hub-starter@sha256:5016b10da41984838ee3b815ea24f6e20be9f3fbd770fec321a40dfb2a64ba9b\n\nThis remains a source-built development-pre-alpha candidate, not an official Alpha, stable, production, authenticated, multi-user, or HA release.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T00:05:16Z",
          "mergedAt": "2026-07-25T00:05:51Z",
          "additions": 81,
          "deletions": 26,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1743,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1743",
          "title": "fix(release): admit bounded bootstrap recovery files",
          "body": "## Summary\n\n- admit exactly the three v3 bootstrap recovery files required by the v2 release line\n- keep release-line recovery fail-closed for all other paths\n- retain the current publish-gate/major ancestry so the follow-up major PR is not behind\n\n## Verification\n\n- node --test tests/promote-buildchain-ref.test.mjs (135/135)\n- corepack pnpm run check (832/832)\n- action bundle integrity check passed (5 bundles)\n\nThis change does not alter affected-native proof identity or its exact source/base/toolchain binding.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T00:02:49Z",
          "mergedAt": "2026-07-25T00:06:32Z",
          "additions": 67,
          "deletions": 35,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1744,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1744",
          "title": "promote: recover bounded v3 bootstrap scope to major",
          "body": "## Promotion evidence\n\n- release merge: c500b6b4fdfd653bde8cdb4b0e343af27793bf70\n- release tree: 07cce01c23ad11fe8847a4ae542872253ab05e6b\n- publish-gate/major is an ancestor of this release head\n- PR #1743 passed check, try, governance, and Build Surface\n\nThis is a pure release-to-major promotion. No affected-native proof identity semantics are changed.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T00:06:57Z",
          "mergedAt": "2026-07-25T00:08:37Z",
          "additions": 67,
          "deletions": 35,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1747,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1747",
          "title": "fix(release): admit bounded breaking major bootstrap",
          "body": "## Summary\n\n- keep the old-major self-dogfood contract evaluation visibly incompatible when v3 changes a breaking digest\n- admit that incompatible evaluation only inside the already-bounded adjacent-major 3.0.0/3.0.1-alpha bootstrap transaction\n- preserve normal dev and PR fail-closed behavior when the explicit major-bootstrap signal is absent\n\n## Verification\n\n- node --test tests/build-surface.test.mjs\n- BUILDCHAIN_MAJOR_VERSION_BOOTSTRAP=true BUILDCHAIN_VERSION=3.0.0 node scripts/check-inventory.mjs\n- corepack pnpm run check (832/832)\n- action bundle integrity check passed (5 bundles)\n\nThis does not alter affected-native proof identity or exact source/base/toolchain reuse semantics.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T00:19:07Z",
          "mergedAt": "2026-07-25T00:24:34Z",
          "additions": 34,
          "deletions": 8,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1751,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1751",
          "title": "fix(release): admit bounded breaking major bootstrap",
          "body": "## Summary\n\n- propagate the explicit adjacent-major bootstrap admission to the v2.14 release line\n- preserve current publish-gate/major ancestry\n- retain normal self-dogfood breaking-contract rejection outside the explicit major transaction\n- use a policy-compliant release-line branch first pushed by dongkeren for independent approval\n\n## Verification\n\n- node --test tests/build-surface.test.mjs\n- BUILDCHAIN_MAJOR_VERSION_BOOTSTRAP=true BUILDCHAIN_VERSION=3.0.0 node scripts/check-inventory.mjs\n- corepack pnpm run check (832/832)\n- action bundle integrity check passed (5 bundles)\n\nTree: 5cd791c867667624db86c7dba3fe7b92cd2bd3fa. This does not alter affected-native proof identity or exact source/base/toolchain reuse semantics.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T00:40:05Z",
          "mergedAt": "2026-07-25T00:43:31Z",
          "additions": 34,
          "deletions": 8,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1752,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1752",
          "title": "promote: admit bounded breaking major bootstrap",
          "body": "## Promotion evidence\n\n- release PR: #1751\n- release merge: 9d953b1295e317288eabca0a57b19d80eec31ecc\n- release tree: 5cd791c867667624db86c7dba3fe7b92cd2bd3fa\n- publish-gate/major is an ancestor of this release head\n- exact independent approval and required checks passed\n\nThis is a pure release-to-major promotion. No affected-native proof identity semantics are changed.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T00:43:50Z",
          "mergedAt": "2026-07-25T00:45:20Z",
          "additions": 34,
          "deletions": 8,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1450,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1450",
          "title": "feat: close primitive management planes",
          "body": "## Summary\n\nSeparate Primitive definition, evidence admission, and perspective-bound runtime availability while keeping the catalog a deterministic read-only projection.\n\n## Changes\n\n- replace the scalar maturity label with a derived seven-axis admission vector\n- add rooted typed relation graph and strict semantic admission threshold\n- add fail-closed CLI and native availability reports\n- project the new surfaces through KFD-3 and installed product artifacts\n\n## Verification\n\n- ./shifu check:source\n- node --test scripts/check-primitive-catalog.test.mjs\n- framework/core/build/Release/kungfu_action_runtime_tests\n- installed CLI qualification for primitive list, graph, and availability\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f9659-5560-7d9d-a143-78766f19ec85\"],\n  \"summary\": \"Close the Primitive definition, admission, and availability planes\",\n  \"verification\": [\"source gate\", \"native runtime tests\", \"installed CLI qualification\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change updates deterministic release projections and verifies them through source and installed-product qualification; it does not publish a release.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-24T23:32:34Z",
          "mergedAt": "2026-07-25T01:00:31Z",
          "additions": 5201,
          "deletions": 1279,
          "changedFiles": 49
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1755,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1755",
          "title": "fix(release): align major bootstrap impact line",
          "body": "## Summary\n\n- align the version-bound release impact line when a protected major promotion materializes the next major version\n- fail closed if the requested major line does not match the exact version\n- keep ordinary alpha and stable line version-state behavior unchanged\n\n## Validation\n\n- `node --test tests/promote-buildchain-ref.test.mjs`\n- `corepack pnpm@11.7.0 run check` (833 tests, 5 action bundles)",
          "author": "dongkeren",
          "createdAt": "2026-07-25T00:58:32Z",
          "mergedAt": "2026-07-25T01:04:24Z",
          "additions": 122,
          "deletions": 46,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1756,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1756",
          "title": "fix(release): propagate major impact-line alignment",
          "body": "## Summary\n\n- propagate the reviewed major-bootstrap release-impact line alignment to the protected v2.14 release source\n- retain exact version/line validation before any publication mutation\n\n## Validation\n\n- `corepack pnpm@11.7.0 run check` (833 tests, 5 action bundles)",
          "author": "dongkeren",
          "createdAt": "2026-07-25T01:06:42Z",
          "mergedAt": "2026-07-25T01:09:58Z",
          "additions": 122,
          "deletions": 46,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1757,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1757",
          "title": "chore(release): refresh v3 major publication gate",
          "body": "## Summary\n\n- advance the reviewed v2.14 release source into the protected major publication gate\n- include bounded major-bootstrap compatibility and release-impact line materialization fixes\n\n## Validation\n\n- release propagation PR #1756 passed Release Verify, Verify, governance audit, and Build Surface Fixture",
          "author": "dongkeren",
          "createdAt": "2026-07-25T01:10:31Z",
          "mergedAt": "2026-07-25T01:12:15Z",
          "additions": 122,
          "deletions": 46,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1455,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1455",
          "title": "fix(product): admit Windows runtime entrypoint",
          "body": "## Summary\n\nAccept the platform-declared `kungfu.exe` entrypoint when validating an installed Windows runtime, while preserving fail-closed platform identity.\n\n## Related issue\n\nAlpha Build run 30135544687 exposed the Windows installed Assignment admission failure.\n\n## Changes\n\n- derive the expected installed runtime entrypoint from the native binding platform\n- require `.pyd` packages to declare `kungfu.exe` and Unix packages to declare `kungfu`\n- cover both accepted platform pairs and reject a mismatched Windows manifest\n\n## Verification\n\n- `./shifu check:source`\n- runtime upgrade control-plane tests: 116 passed\n- changed Python format and lint\n- Python type baseline: 191 source files\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix aligns installed Windows provenance validation with the existing platform-specific manifest contract without changing architecture authority.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change tightens installed-product provenance and is exercised by the complete build-free source acceptance gate; it does not publish a release.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not required; existing platform manifest contract is unchanged)",
          "author": "dongkeren",
          "createdAt": "2026-07-25T00:41:40Z",
          "mergedAt": "2026-07-25T01:24:54Z",
          "additions": 56,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1759,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1759",
          "title": "fix(release): derive major bootstrap impact line",
          "body": "## Summary\n- derive the major bootstrap release-impact line from the exact planned version\n- avoid depending on the major rule placeholder, which has no concrete line\n- keep invalid planned versions fail-closed and cover the production call shape\n\n## Verification\n- `corepack pnpm check`\n- 833/833 unit tests; 5 action bundles verified\n\n## Evidence\nThe v3 major planning run failed with `expected v3.0, got <empty>` because the caller passed the major rule placeholder. This patch writes `release.line = v3.0` from planned version `3.0.0`.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T01:22:21Z",
          "mergedAt": "2026-07-25T01:27:54Z",
          "additions": 12,
          "deletions": 15,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1760,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1760",
          "title": "fix(release): derive major bootstrap impact line",
          "body": "## Summary\n- propagate the reviewed major-bootstrap impact-line derivation to the protected v2.14 release source\n- derive `v3.0` from planned version `3.0.0` instead of the major rule placeholder\n- retain fail-closed invalid-version behavior\n\n## Verification\n- `corepack pnpm check`\n- 833/833 unit tests; 5 action bundles verified\n\n## Provenance\nCherry-picked exact reviewed implementation from dev PR #1759.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T01:29:56Z",
          "mergedAt": "2026-07-25T01:33:11Z",
          "additions": 12,
          "deletions": 15,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1762,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1762",
          "title": "release: retry v3 major bootstrap with derived impact line",
          "body": "## Summary\n- advance the protected v2.14 release source to the reviewed major gate\n- include the fail-closed major bootstrap inventory fix and the exact `v3.0` impact-line derivation\n\n## Provenance\n- dev implementation: #1759\n- protected release propagation: #1760\n- source merge: `ea0546abc4ccb3b17f7ab1c34f4327dbf7d88df9`\n\n## Expected publication\n- `@kungfu-tech/buildchain@3.0.0`\n- `v3.0.0`, `v3.0`, `v3`\n- `v3.0.1-alpha.0`, `v3.0-alpha`, `v3-alpha`\n- new `release/v3/v3.0`, `alpha/v3/v3.0`, and `dev/v3/v3.0` lines",
          "author": "dongkeren",
          "createdAt": "2026-07-25T01:34:08Z",
          "mergedAt": "2026-07-25T01:36:01Z",
          "additions": 12,
          "deletions": 15,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1765,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1765",
          "title": "test(release): admit bounded major bootstrap state",
          "body": "## Summary\n- make self-dogfood assertions evaluate the same bounded major-bootstrap admission used by inventory\n- retain raw contract-compatibility assertions outside the explicit bootstrap environment\n- keep the exception limited by `resolveSelfDogfoodMajor` to adjacent `N.0.0` / `N.0.1-alpha.*` transitions\n\n## Verification\n- normal `corepack pnpm check`: 833/833, 5 bundles\n- generated `3.0.0` version-state in a disposable detached worktree\n- `BUILDCHAIN_MAJOR_VERSION_BOOTSTRAP=true node scripts/check-inventory.mjs`\n- `BUILDCHAIN_MAJOR_VERSION_BOOTSTRAP=true node --test tests/build-surface.test.mjs`: 86/86\n\n## Failure reproduced\nRun #30138852294 passed exact version planning and inventory, then failed only the two self-dogfood assertions after version-state generation changed the contract to 3.0.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T01:49:01Z",
          "mergedAt": "2026-07-25T01:54:37Z",
          "additions": 36,
          "deletions": 9,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1766,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1766",
          "title": "test(release): admit bounded major bootstrap state",
          "body": "## Summary\n- propagate the reviewed bounded major-bootstrap self-dogfood assertions to the protected release source\n- retain normal raw compatibility enforcement outside the explicit bootstrap environment\n\n## Verification\n- `corepack pnpm check`: 833/833, 5 bundles\n- exact generated 3.0.0 state was separately verified on dev in #1765\n\n## Provenance\nCherry-picked exact reviewed implementation from dev PR #1765.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T01:57:19Z",
          "mergedAt": "2026-07-25T02:00:30Z",
          "additions": 36,
          "deletions": 9,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1452,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1452",
          "title": "feat(workspace): bind lifecycle execution to dry-run receipt",
          "body": "## Summary\n\nBind Workspace Catalog lifecycle execution to the exact dry-run plan root so managed-worktree closeout can delete first and still apply only the preflighted entry.\n\n## Changes\n\n- accept an explicit transition timestamp and expected plan root at execution\n- fail before writes when the recomputed lifecycle plan differs\n- expose the binding through the generated CLI surface\n- retain zero Workspace-authority writes\n\n## Verification\n\n- 15 focused workspace tests\n- ./shifu check:cli-catalog-parity\n- staged Python format/lint, KFD evidence, documentation, and invariant gates\n- Project Cut merge-queue admission\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f8e99-9354-7ab6-a9ba-b166f83f25a3\"],\n  \"summary\": \"Bind exact Catalog lifecycle execution to its write-free dry-run plan and receipt boundary\",\n  \"verification\": [\"15 focused workspace tests\", \"CLI catalog parity\", \"KFD and staged repository gates\", \"Project Cut merge-queue admission\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-25T00:16:09Z",
          "mergedAt": "2026-07-25T02:00:34Z",
          "additions": 145,
          "deletions": 22,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1767,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1767",
          "title": "release: retry v3 major bootstrap with bounded self-dogfood state",
          "body": "## Summary\n- advance the protected v2.14 release source after the bounded self-dogfood bootstrap fix\n- preserve exact major inventory and impact-line derivation\n\n## Provenance\n- bounded bootstrap dev fix: #1765\n- protected release propagation: #1766\n- exact release head: `bf71b3e4960f4d6d5a54d52a1f340e145dd4a217`\n\n## Expected publication\n- `@kungfu-tech/buildchain@3.0.0`\n- stable and alpha v3 tags and branches",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:00:47Z",
          "mergedAt": "2026-07-25T02:02:38Z",
          "additions": 36,
          "deletions": 9,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1769,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1769",
          "title": "fix(release): bind major KFD claim version state",
          "body": "## Summary\n- admit the exact generated KFD claim sidecar during major version-state verification\n- preserve the configured version-state allowlist for alpha and release channels\n- keep all other generated paths fail-closed\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs tests/build-surface.test.mjs (223/223)\n- corepack pnpm check\n- exact 3.0.0 runVersionVerification reproduction in a disposable worktree",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:14:38Z",
          "mergedAt": "2026-07-25T02:20:50Z",
          "additions": 88,
          "deletions": 61,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1770,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1770",
          "title": "fix(release): propagate exact major KFD version state",
          "body": "## Summary\n- propagate the reviewed dev fix into release/v2/v2.14\n- admit only dist/site/kfd-claims.json as the deterministic major version-state sidecar\n- retain fail-closed checks for every other generated path\n\n## Verification\n- corepack pnpm check (834/834)",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:22:10Z",
          "mergedAt": "2026-07-25T02:23:46Z",
          "additions": 88,
          "deletions": 61,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1771,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1771",
          "title": "release: promote exact KFD-bound major bootstrap",
          "body": "## Summary\n- promote the reviewed release/v2/v2.14 recovery state to the major publication gate\n- include the exact generated KFD claim sidecar admission\n- preserve all durable transaction and source identity checks\n\n## Verification\n- release propagation PR #1770 merged\n- corepack pnpm check (834/834)",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:24:09Z",
          "mergedAt": "2026-07-25T02:25:44Z",
          "additions": 88,
          "deletions": 61,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1773,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1773",
          "title": "fix(release): admit generated major version-state checks",
          "body": "## Summary\n- enable bounded major bootstrap only for generated publish-gate/major version-state PR checks\n- keep ordinary PRs and all other targets on the normal self-dogfood contract\n- retain the adjacent-major and 0.0 code-level boundary\n\n## Verification\n- bash scripts/check-workflows.sh\n- node --test tests/build-surface.test.mjs (86/86)\n- corepack pnpm check (834/834)",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:35:16Z",
          "mergedAt": "2026-07-25T02:40:39Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1404,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1404",
          "title": "feat(core): admit native Work journal ownership",
          "body": "## Summary\n\n- move durable Agent Work payload, ActionEnvelope, Root, frame, replay, and manifest ownership behind the existing libkungfu runtime-action ABI\n- preserve exact historical FBS/BFBS, payload, envelope, and reader behavior through a committed cross-language golden corpus\n- qualify the owner cutover with fail-before-write checks, no-rewrite evidence, an admission receipt, and incubation-passport closure\n\n## Related issue\n\nAssignment `2026-07-24-kungfu-work-native-admission`.\n\n## Changes\n\n- add the native Work journal service and batch writer path\n- cut Python WorkStore over to semantic native requests while retaining independent compatibility replay\n- move the byte-identical Work schema authority into libkungfu\n- extend the shared native admission runner, API contracts, passport governance, and regression fixtures\n\n## Verification\n\n- `./shifu build:core`\n- `./shifu test:native-kfx-admission`\n- `./shifu check:source`\n- `./shifu check`\n- independent defect review completed with no findings\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\n    \"KF-ADR-019f8c53-6105-71e5-8f34-53f2a81ee61c\",\n    \"KF-ADR-019f8759-ab29-7627-bc04-6aba547ea45f\"\n  ],\n  \"summary\": \"Admit one native Agent Work journal owner through the existing runtime-action ABI while preserving exact historical bytes and readers.\",\n  \"verification\": [\n    \"Shared native admission runner with C ABI and cross-language golden replay\",\n    \"Full source acceptance and repository checks\",\n    \"Independent defect review with no findings\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for the native owner cutover\n\nMade with [Cursor](https://cursor.com)",
          "author": "dongkeren",
          "createdAt": "2026-07-24T08:01:39Z",
          "mergedAt": "2026-07-25T02:42:10Z",
          "additions": 1855,
          "deletions": 318,
          "changedFiles": 46
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1774,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1774",
          "title": "fix(release): propagate generated major check admission",
          "body": "## Summary\n- propagate the bounded generated-major version-state check admission to release/v2/v2.14\n- keep ordinary checks unchanged\n\n## Verification\n- identical to reviewed dev PR #1773\n- bash scripts/check-workflows.sh\n- corepack pnpm check (834/834)",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:41:54Z",
          "mergedAt": "2026-07-25T02:43:45Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1778,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1778",
          "title": "chore(release): hand off protected branch authority",
          "body": "No file changes. This empty signed commit transfers the protected release branch's most-recent-push authority from kungfu-origin to dongkeren so the independent origin approval on the major promotion can satisfy require_last_push_approval without an admin bypass.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:48:50Z",
          "mergedAt": "2026-07-25T02:50:27Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1777,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1777",
          "title": "feat: retain product release evidence in passports",
          "body": "## Summary\n\n- let product release gates generate exact-coordinate evidence before passport collection\n- retain each evidence index as an independently downloadable GitHub Release asset\n- verify document digests, contracts, source SHA, tag, and channel during public readback\n- expose the reusable-workflow and action inputs in the generated site bundle\n\n## Validation\n\n- pnpm run build\n- pnpm run check (663 tests passed)\n- git diff --check\n\n## Safety\n\nThis is an additive contract. Products opt in explicitly; existing release behavior is unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:47:29Z",
          "mergedAt": "2026-07-25T02:51:19Z",
          "additions": 577,
          "deletions": 111,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1780,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1780",
          "title": "chore(release): sync major gate ancestry",
          "body": "No file tree changes. This signed merge synchronizes the current publish-gate/major ancestry into release/v2/v2.14 through the protected PR path, allowing the release-to-major PR to satisfy strict up-to-date checks without direct branch writes.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:52:08Z",
          "mergedAt": "2026-07-25T02:53:53Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1781,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1781",
          "title": "release: admit generated v3 version-state verification",
          "body": "## Summary\n- advance publish-gate/major with the bounded generated-version-state PR check admission\n- unblock exact v3.0.0 transaction finalization without changing its generated head\n- keep all ordinary PR checks fail-closed\n\n## Verification\n- dev PR #1773 merged\n- release PR #1774 merged\n- authority handoff #1778 and ancestry sync #1780 merged by dongkeren\n- corepack pnpm check (834/834)",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:56:06Z",
          "mergedAt": "2026-07-25T02:58:47Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1461,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1461",
          "title": "fix(release): bound GitHub source fallback",
          "body": "## Summary\n\nRetain a bounded 20-minute GitHub fallback for protected Alpha and release candidate source checkout when the synthetic merge ref is absent from the LAN mirror.\n\n## Related evidence\n\nAlpha Build run 30138755620 attempt 1 timed out after the default 600-second GitHub fetch and left a stale shallow lock. Attempt 2 passed source checkout on all three platforms, confirming the issue was the bounded fallback window rather than candidate identity.\n\n## Changes\n\n- set the release-candidate GitHub checkout fallback to 1200 seconds\n- keep PR-stage qualification on the GitHub synthetic merge tree\n- weld the timeout into the promotion rehearsal and workflow authority digest\n- reject a regression back to 600 seconds\n\n## Verification\n\n- `./shifu check:source`\n- source contract tests: 600 passed, 10 skipped\n- Assignment tests: 42 passed\n- runtime upgrade tests: 116 passed\n- desktop update tests: 69 passed\n- staged pre-commit gate: 99 documentation fixtures passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This reliability fix preserves the existing protected release-candidate source identity and only widens the bounded GitHub transport window after an observed timeout.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects source acquisition timing only. It does not weaken exact-SHA verification, event trust, merge-tree qualification, signing, or publication authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Workflow authority projection refreshed",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:35:15Z",
          "mergedAt": "2026-07-25T02:59:41Z",
          "additions": 29,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1772,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1772",
          "title": "Release v3.0.0",
          "body": "Create the generated version-state commit for v3.0.0.\n\nBuildchain generated this PR because protected branch publish-gate/major rejected direct generated bookkeeping.\n\nRejected update: 173df79be292987e76383a1955c8a9d31b0cb499 -> 9e904de2c85dbea7c799780ee166510b3336d812\n\nGitHub response: Changes must be made through a pull request. Required status check \"check\" is expected.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:31:17Z",
          "mergedAt": "2026-07-25T03:02:24Z",
          "additions": 33,
          "deletions": 33,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 134,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/134",
          "title": "feat: publish immutable UNGFU acquisition evidence",
          "body": "## Summary\n\n- keep the committed install page truthful before an Alpha publication exists\n- project an adjacent Kungfu UNGFU™ software description and installer action only after signed-publication import\n- retain immutable human- and machine-readable acquisition evidence bound to the source, channel root, artifacts, and Release Passport\n- expose a well-known discovery pointer without making first-use or legal conclusions\n\n## Validation\n\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- git diff --check\n\n## Safety\n\nNo released acquisition claim is present in the committed pre-release site. The projection is activated only by the existing signed Alpha publication import.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:50:20Z",
          "mergedAt": "2026-07-25T03:06:48Z",
          "additions": 221,
          "deletions": 5,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1784,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1784",
          "title": "fix(release): admit major gate push verification",
          "body": "## Summary\n- keep generated major version-state PR checks bounded\n- also enable the same adjacent-major bootstrap for push verification on publish-gate/major\n- leave dev, release, ordinary PR, and merge-group checks unchanged\n\n## Verification\n- bash scripts/check-workflows.sh\n- node --test tests/build-surface.test.mjs (86/86)\n- corepack pnpm check (834/834)",
          "author": "dongkeren",
          "createdAt": "2026-07-25T03:05:06Z",
          "mergedAt": "2026-07-25T03:11:39Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 135,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/135",
          "title": "Release production from d231e5caddfd",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `d231e5caddfd3c301db892feee71027dadefd614`\n- Artifact hash: `33e0680dfd0fb358494287f6051aa4f24228f71ea2f6f32e44e9db5bea9f561e`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30141652569)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-d231e5caddfd`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-25T03:09:09Z",
          "mergedAt": "2026-07-25T03:13:19Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1785,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1785",
          "title": "fix(release): admit major gate push verification",
          "body": "Propagates the bounded major-gate push bootstrap check from dev to the v2.14 release line.\\n\\nThe bootstrap remains enabled only for generated version-state PRs targeting `publish-gate/major` and pushes to that exact gate; release and alpha verification remain unchanged.\\n\\nValidation: `bash scripts/check-workflows.sh`; `node --test tests/build-surface.test.mjs` (86/86); `corepack pnpm check` (834/834).",
          "author": "dongkeren",
          "createdAt": "2026-07-25T03:15:49Z",
          "mergedAt": "2026-07-25T03:19:06Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 136,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/136",
          "title": "fix(ci): pass live governance receipt",
          "body": "## Summary\n\n- mint a bounded read-only governance auditor token only for trusted production decisions\n- audit the exact `site-kungfu-tech/main` policy with the exact stable Buildchain runtime\n- pass one fresh qualifying receipt into the managed production authority gate\n- keep fork previews and non-production events outside the credentialed job\n\n## Validation\n\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `actionlint .github/workflows/buildchain-web-surface.yml`\n- live read-only audit at Buildchain `bcdf00393ddec9886fd294a8e5d7830ffaf19f6c`: 1/1 target qualifying\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T03:23:17Z",
          "mergedAt": "2026-07-25T03:25:33Z",
          "additions": 100,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1787,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1787",
          "title": "fix(release): admit exact major handoff verification",
          "body": "Bounds major bootstrap verification to three exact contexts: generated version-state PRs targeting `publish-gate/major`, the formal `release/v2/v2.14` to `publish-gate/major` handoff, and pushes to the exact major gate. All other PRs, release pushes, and alpha paths remain fail-closed.\\n\\nValidation: workflow syntax, 86/86 targeted tests, 834/834 full checks.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T03:24:48Z",
          "mergedAt": "2026-07-25T03:29:53Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 137,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/137",
          "title": "Release production from 1564945d1d45",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `1564945d1d452fc38ab4189df8991088fe53400e`\n- Artifact hash: `33e0680dfd0fb358494287f6051aa4f24228f71ea2f6f32e44e9db5bea9f561e`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30142229618)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-1564945d1d45`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-25T03:27:50Z",
          "mergedAt": "2026-07-25T03:32:01Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1789,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1789",
          "title": "fix(release): admit exact major handoff verification",
          "body": "Propagates the exact release-to-major bootstrap admission from dev to the v2.14 release line. It remains bounded to base `publish-gate/major` and head `release/v2/v2.14`.\\n\\nValidation: workflow syntax; 86/86 targeted tests; 834/834 full checks.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T03:32:11Z",
          "mergedAt": "2026-07-25T03:35:13Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1463,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1463",
          "title": "fix(cli): remove all pre-release aliases",
          "body": "## Summary\n\nRemove every pre-release deprecated CLI route and compatibility alias so every callable command has one globally unique canonical path before the first public release.\n\nThis supersedes #1460 after #1404 added native Work journal ownership and changed generated Primitive/KFD evidence. The replacement is one DCO-signed commit whose parent is the exact current `dev/v4/v4.0` head; all overlapping projections were regenerated from the combined source tree.\n\n## Related issue\n\nNative Assignment: `2026-07-25-kungfu-cli-canonical-only`\n\n## Changes\n\n- remove 25 deprecated routes, 2 quiet compatibility routes, and the `kfc` console-script alias\n- register developer and Mission Control commands only at their canonical paths\n- delete alias warning/disposition/removal-gate machinery and forbid aliases in source/product gates\n- migrate authored docs, tests, Agent catalogs, KFD-3 registries, SDK projections, and Buildchain evidence\n- add negative coverage for all 27 removed routes and canonical-path uniqueness\n\n## Verification\n\n- `./shifu test:cli-surface-contract` (36 passed)\n- `./shifu test:cli-surface-qualification` (29 passed)\n- `./shifu check:cli-catalog-parity`\n- `./shifu check:primitive-catalog` (14 passed)\n- `./shifu kfd:buildchain:check` (4 KFD-2 claims, 161 KFD-3 surfaces)\n- staged gate: 98 documentation contract tests plus Python/JS/KFD checks\n\nCurrent catalog: 436 surfaces, 436 unique canonical paths, 0 aliases, 0 duplicate paths, 0 deprecated/compatibility maturity values.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Pre-release defect cleanup removes redundant CLI names without changing surviving command semantics, action identities, schemas, receipts, or mutation authority\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR removes a Python console entrypoint alias and regenerates current KFD/Buildchain evidence; it does not publish a release.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:43:28Z",
          "mergedAt": "2026-07-25T03:40:17Z",
          "additions": 710,
          "deletions": 2956,
          "changedFiles": 61
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 138,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/138",
          "title": "fix(ci): freeze governance runtime",
          "body": "## Summary\n- resolve the floating Buildchain v2 verifier to one exact SHA\n- use that same SHA for live governance audit and the reusable web-surface runtime\n- add a caller contract check that prevents the two runtime bindings from drifting\n\n## Validation\n- `git diff --check`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `actionlint .github/workflows/buildchain-web-surface.yml`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-25T03:35:57Z",
          "mergedAt": "2026-07-25T03:44:22Z",
          "additions": 15,
          "deletions": 13,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 139,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/139",
          "title": "feat(install): publish honest unavailable bootstrap routes",
          "body": "## Summary\n\n- Publish canonical install.sh and install.ps1 entrypoints before a CLI release is qualified.\n- Return one machine-readable unavailable contract and fail nonzero without downloads, installation, or machine changes.\n- Preserve the existing signed-publication importer as the only path that can replace these friendly routes with qualified installer bytes.\n\n## Safety boundary\n\n- This change does not build, sign, promote, or publish an Alpha product release.\n- The unavailable entrypoints perform no network access and no filesystem, PATH, profile, registry, service, or package-manager mutation.\n\n## Validation\n\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- sh -n public/install.sh\n- bash -n scripts/check-site.sh\n- install.sh returns exit code 69 with the exact availability JSON",
          "author": "dongkeren",
          "createdAt": "2026-07-25T03:43:09Z",
          "mergedAt": "2026-07-25T03:45:04Z",
          "additions": 39,
          "deletions": 5,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 141,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/141",
          "title": "Release production from ed9c99d309a4",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `ed9c99d309a437a81e38977c63c4b4cdce28c80a`\n- Artifact hash: `f1953e3f2df388d0d67c5446b535683bb423b24ef30ba285ccfd5d258714b559`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30142816394)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-ed9c99d309a4`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-25T03:47:12Z",
          "mergedAt": "2026-07-25T03:49:27Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 142,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/142",
          "title": "fix(ci): retain official Buildchain channel",
          "body": "## Summary\n- keep the live governance audit sourced from the current floating Buildchain v2 verifier\n- retain the reusable production workflow on the official `v2` channel instead of passing an exact-SHA PR-event override\n- fail the caller contract if a governance runtime SHA is wired into `buildchain-ref` again\n\n## Validation\n- `git diff --check`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `actionlint .github/workflows/buildchain-web-surface.yml`\n\n## Production evidence\nRun 30142939037 proved the fresh governance receipt succeeds and Buildchain rejects exact-SHA overrides outside trusted workflow dispatch. This patch preserves that trust boundary.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-25T03:51:48Z",
          "mergedAt": "2026-07-25T03:52:51Z",
          "additions": 10,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1791,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1791",
          "title": "fix(signing): define dirname in credential bundle",
          "body": "## Summary\n\n- inject an ESM-compatible `__dirname` binding into the macOS credential-island bundle\n- keep the compatibility shim scoped to the credential action\n- fail bundle tests when an unresolved `__dirname` remains\n\n## Evidence\n\nKungfu canary run 30141451085 reached the hosted credential island, then failed before PKCS#12 import with `__dirname is not defined`.\n\n## Verification\n\n- `node --test tests/macos-credential-island.test.mjs` (10/10)\n- `pnpm run check` (834/834; 5 action bundles current)",
          "author": "dongkeren",
          "createdAt": "2026-07-25T03:48:01Z",
          "mergedAt": "2026-07-25T03:53:11Z",
          "additions": 118,
          "deletions": 108,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1462,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1462",
          "title": "feat(primitive): close authority consumption paths",
          "body": "## Summary\n\n- close Primitive authority producers and runtime readers into one source-checked set\n- reject undeclared catalog consumers, alternate passport readers, direct passport reach-through, and catalog write paths\n- make CODEOWNER intent explicit for Primitive authority and gate files\n- document the static-analysis boundary for deliberately opaque code\n\n## Verification\n\n- `./shifu check:primitive-catalog` (19/19)\n- `./shifu check:source`\n- pre-commit staged gate (98/98 documentation negative fixtures)\n- live ruleset verification: CODEOWNER review required; merge queue and required checks unchanged\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f9659-5560-7d9d-a143-78766f19ec85\"],\n  \"summary\": \"Close Primitive authority consumption paths and bind their review ownership\",\n  \"verification\": [\"source gate\", \"Primitive authority negative fixtures\", \"CODEOWNER ruleset verification\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis change hardens source and review admission. It does not publish a release or mutate product runtime data.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:39:51Z",
          "mergedAt": "2026-07-25T03:57:27Z",
          "additions": 393,
          "deletions": 7,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 144,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/144",
          "title": "Release production from 66d0da513255",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `66d0da5132551d381c0021a4390211d21cc79e8f`\n- Artifact hash: `f1953e3f2df388d0d67c5446b535683bb423b24ef30ba285ccfd5d258714b559`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30143037058)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-66d0da513255`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-25T03:54:47Z",
          "mergedAt": "2026-07-25T03:57:28Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1467,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1467",
          "title": "fix(product): isolate assignment admission smoke home",
          "body": "## Summary\n\nKeep the installed Assignment admission smoke inside the product archive's isolated user home so it cannot register temporary workspaces in the operator Workspace Catalog.\n\n## Changes\n\n- bind both `HOME` and `USERPROFILE` to an install-root-local smoke home\n- retain the existing isolated Kungfu runtime home and installed product invocation\n- add a regression that preserves sentinel operator Catalog bytes while proving both capture and admit use the isolated home\n\n## Verification\n\n- `./shifu test:cli-surface-qualification` (30/30)\n- `pnpm exec biome check product/scripts/dist.mjs product/scripts/dist.test.mjs`\n- staged repository pre-commit gates\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Correct test-process environment isolation without changing Workspace authority or an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [x] No Workspace authority is scanned, excluded, settled, or rewritten\n- [x] No secrets, credentials, release publication, or external API compatibility change\n- [x] none of the above template governance boundaries\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Regression coverage added for the behavior change\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T03:33:50Z",
          "mergedAt": "2026-07-25T04:00:52Z",
          "additions": 92,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 145,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/145",
          "title": "fix(release): admit governance on main pushes",
          "body": "## Summary\n\n- mint the required fresh governance receipt on protected main pushes\n- bind main-push release execution to the official v2 runtime and stable contract lock\n- add a regression check for the production push governance path\n\n## Why\n\nThe protected release PR merge correctly produced a main push, but the governance receipt job was skipped on that push. Buildchain failed closed before production apply. The PR-closed run remains unable to deploy because the production environment correctly permits only main.\n\n## Validation\n\n- actionlint .github/workflows/buildchain-web-surface.yml\n- node scripts/check-infra-outputs.mjs\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-25T04:02:41Z",
          "mergedAt": "2026-07-25T04:04:07Z",
          "additions": 15,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 146,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/146",
          "title": "Release production from dd0303593099",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `dd03035930990d11a410e9e77824a7551441304b`\n- Artifact hash: `f1953e3f2df388d0d67c5446b535683bb423b24ef30ba285ccfd5d258714b559`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30143369988)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-dd0303593099`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-25T04:06:42Z",
          "mergedAt": "2026-07-25T04:09:40Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1793,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1793",
          "title": "fix(release): skip legacy verify for exact major handoff",
          "body": "## Summary\n\n- mark the legacy `Release - Verify` workflow inapplicable only for the exact `release/v2/v2.14` to `publish-gate/major` handoff\n- keep the general `Verify` major-bootstrap path authoritative for that transition\n- add a workflow-surface regression assertion for the bounded condition\n\n## Validation\n\n- `corepack pnpm@11.7.0 run check` (834 tests passed)\n- `corepack pnpm@11.7.0 exec node --test tests/build-surface.test.mjs` (86 tests passed)\n- `corepack pnpm@11.7.0 run check:workflows`",
          "author": "dongkeren",
          "createdAt": "2026-07-25T04:19:41Z",
          "mergedAt": "2026-07-25T04:25:30Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1795,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1795",
          "title": "fix(release): propagate bounded major handoff verify skip",
          "body": "## Summary\n\n- propagate the exact reviewed fix from #1793 into `release/v2/v2.14`\n- skip the legacy `Release - Verify` workflow only for the exact `release/v2/v2.14` → `publish-gate/major` handoff PR\n- retain general `Verify` and governance checks for the major promotion path\n\n## Verification\n\n- release-line version parser accepts the head/base pair (`patch`)\n- cherry-pick patch bytes exactly match `c6ca0007c0070051b9f2aafea421803e977cb9a5`\n- original targeted test: 86/86 passed\n- original full check: 834/834 passed\n- release-line GitHub checks provide independent base-line verification\n\nSupersedes #1794, which used a non-conforming branch name.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-25T04:29:17Z",
          "mergedAt": "2026-07-25T04:32:28Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1796,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1796",
          "title": "chore(release): refresh major gate approver",
          "body": "Zero-content, tree-preserving release PR. Its sole purpose is to make the protected release head last-pushed by `dongkeren` so `kungfu-origin` can satisfy the independent last-push approval on downstream major-gate PR #1786.\n\nNo files or proof identities change; normal release checks must still pass. This follows the established recovery pattern from #1716.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-25T04:36:40Z",
          "mergedAt": "2026-07-25T04:39:57Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1798,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1798",
          "title": "chore(release): sync major gate ancestry",
          "body": "No file tree changes. This signed `ours` merge synchronizes the current `publish-gate/major` ancestry into `release/v2/v2.14` through the protected PR path, allowing major PR #1786 to satisfy strict up-to-date checks without direct branch writes.\n\nProof:\n- merge parent 1: `6a7d5d863241be3b26f978013669cb5a074c6d9c`\n- merge parent 2: `0c8d85ca5660ad8bac2880628a353d35b7aa1197`\n- merge tree equals parent 1 tree\n- PR file diff is empty\n\nThis follows the established recovery pattern from #1780.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-25T04:44:42Z",
          "mergedAt": "2026-07-25T04:48:02Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1786,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1786",
          "title": "fix(release): admit major gate push verification",
          "body": "Propagates the bounded major-gate push verification fix into the v3 publication gate.\\n\\nThe three-dot diff is exactly `.github/workflows/verify.yml` plus its contract test. The release branch is not updated from the v3 gate, so the v2 line remains isolated.\\n\\nValidated on #1785 and locally: workflow check, 86/86 targeted tests, 834/834 full checks.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T03:20:19Z",
          "mergedAt": "2026-07-25T04:49:36Z",
          "additions": 44,
          "deletions": 35,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1466,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1466",
          "title": "feat(release): gate UNGFU evidence bundle",
          "body": "## Summary\n\nClose the protected Alpha evidence path for Kungfu UNGFU without converting the current Coming Soon state into a released-use, first-use, registration, or legal claim.\n\n## Related issue\n\nAssignment: `2026-07-25-kungfu-ungfu-release-evidence-bundle`\n\n## Changes\n\n- add one versioned three-layer release-evidence index: acquisition/product specimen, per-Class-9 released capability truth, and supporting brand archive\n- keep the committed candidate in preparation state with no public acquisition record, artifact root, use date, or legal conclusion\n- require exact source/tag/version/channel/deployment/artifact-root binding and public readback before `releasedUseClaim` can become true\n- bind installed CLI product identity and archive qualification to the same release evidence\n- retain the complete evidence JSON through Buildchain PR #1777 and the Release Passport\n- wire the protected promotion workflow to the merged Buildchain runtime\n- document the public site projection while preserving the current pre-release state\n\n## Verification\n\n- staged pre-commit gate passed, including 98 documentation contract tests and generated authority checks\n- `node --test scripts/prepare-ungfu-release-evidence.test.mjs product/scripts/cli-surface-qualification.test.mjs` (8 passed)\n- `./shifu check:gate-catalog` (38 gates, 6 profiles, 25 invocations, 18 workflows aligned)\n- `./shifu release:promotion:rehearse`\n- `./shifu check:source` in an isolated Git clone with its own ref namespace\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f8cc4-e796-7b0e-9a16-50c08614e848\"],\n  \"summary\": \"Close the exact three-layer UNGFU release-evidence bundle and protected readback path while retaining the pre-release no-claim boundary.\",\n  \"verification\": [\n    \"isolated-clone source gate\",\n    \"release-evidence negative and readback fixtures\",\n    \"promotion rehearsal\",\n    \"Buildchain retained-evidence integration\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR only prepares and verifies evidence. It cannot publish the Alpha, claim first use, select a filing date, infer registration, or bypass counsel review. The current candidate deliberately fails the released-use gate.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and generated workflow authority projections updated\n- [x] No released-use or legal conclusion is asserted\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T03:27:16Z",
          "mergedAt": "2026-07-25T05:00:41Z",
          "additions": 1079,
          "deletions": 20,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1801,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1801",
          "title": "fix(release): resume major finalization transaction",
          "body": "## Summary\n- resume a durable published/finalizing major transaction before selecting a new patch\n- preserve the advanced major channel tip while finalizing release refs from recorded material\n- restore the original transaction identity and avoid rerunning the registry provider\n- prepare the next alpha only after the interrupted major release finishes\n\n## Validation\n- `node --test --test-name-pattern=\"publish-gate/major\" tests/promote-buildchain-ref.test.mjs`\n- `pnpm run check`\n- action bundle integrity check passed",
          "author": "dongkeren",
          "createdAt": "2026-07-25T05:09:05Z",
          "mergedAt": "2026-07-25T05:14:54Z",
          "additions": 446,
          "deletions": 106,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1469,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1469",
          "title": "fix(assignment): keep mission parents advisory",
          "body": "## Summary\n\nPrevent Atlas mission hierarchy metadata from being projected as a workspace-local Assignment parent edge. Local parent shorthand remains explicit through parent_goal, while exact cross-workspace edges remain owned by parent_assignment_ref.\n\n## Changes\n\n- keep mission_parent_goal losslessly inside the admitted work definition without turning it into parent_assignment_id\n- preserve the conflict guard for explicit parent_goal plus parent_assignment_ref\n- qualify both advisory-only and advisory-plus-exact-WorkRef projections\n\n## Verification\n\n- assignment orchestration tests: 21 passed\n- staged repository gate passed, including Python format/lint, Gate catalog, docs 99/99, and promotion rehearsal\n- git diff --check\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"Correct an Atlas adapter projection bug without changing Assignment graph authority or the accepted exact WorkRef architecture.\"}\n-->\n\n## Governance risk check\n\n- [x] no credentials, publication, provider, or release mutation\n- [x] no Assignment authority is copied across workspaces\n- [x] exact parent WorkRefs remain authoritative\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Regression coverage added",
          "author": "dongkeren",
          "createdAt": "2026-07-25T04:52:00Z",
          "mergedAt": "2026-07-25T05:25:43Z",
          "additions": 53,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1804,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1804",
          "title": "fix(release): resume major finalization transaction",
          "body": "## Summary\n- propagate the reviewed major finalization recovery from dev to the active v2.14 release line\n- preserve exact patch identity from commit 447cfcd8\n- avoid registry republish while completing the durable v3.0.0 transaction\n\n## Validation\n- stable patch-id matches dev commit 447cfcd8\n- `node --test --test-name-pattern=\"publish-gate/major\" tests/promote-buildchain-ref.test.mjs`\n- `pnpm run check`\n\nSupersedes #1802 and #1803, which established the correct authority target and the required version-bearing release-line head form.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T05:22:46Z",
          "mergedAt": "2026-07-25T05:26:34Z",
          "additions": 446,
          "deletions": 106,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1806,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1806",
          "title": "chore(release): sync major gate after finalization fix",
          "body": "## Summary\n- record current publish-gate/major as the second parent of the release line\n- preserve the release tree byte-for-byte\n- make the final release-to-major handoff strict-up-to-date without importing v3 tree changes\n\n## Verification\n- parent 1: 31c05a9b8521a70e989842258da0e463dca1d532\n- parent 2: bf3d682fdc1280794f5b3b3f249b560679879024\n- commit tree equals parent-1 tree: d3cf912205465929fc55bbd63535194a0e154b3b",
          "author": "dongkeren",
          "createdAt": "2026-07-25T05:30:12Z",
          "mergedAt": "2026-07-25T05:34:36Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1805,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1805",
          "title": "fix(release): carry major finalization recovery",
          "body": "## Summary\n- carry the reviewed finalization-only recovery into the protected major gate\n- resume durable v3.0.0 authority instead of selecting v3.0.1\n- preserve the current major tip and avoid a second registry publication\n\n## Provenance\n- dev PR #1801\n- release PR #1804\n- exact release tip 31c05a9b8521a70e989842258da0e463dca1d532",
          "author": "dongkeren",
          "createdAt": "2026-07-25T05:27:12Z",
          "mergedAt": "2026-07-25T05:36:34Z",
          "additions": 446,
          "deletions": 106,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1810,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1810",
          "title": "fix(release): finish completed major finalization",
          "body": "## Summary\n- bind configured release-impact projection to the active major line during passport finalization\n- resume a contained complete major transaction when post-release alpha/dev bookkeeping is still missing\n- retain provider idempotency and reject accidental v3.0.1 stable selection\n\n## Verification\n- targeted major recovery and impact projection tests\n- pnpm run check (835 tests; action bundles consistent)\n\n## Live failure addressed\n- Buildchain Ref Promotion run 30146102303 completed v3.0.0 tags and durable transaction, then failed closed on a v2.14/v3.0 passport impact-line mismatch.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T05:55:17Z",
          "mergedAt": "2026-07-25T05:58:25Z",
          "additions": 111,
          "deletions": 36,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1458,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1458",
          "title": "feat(runtime): enforce cross-language authority membrane",
          "body": "## Summary\n\nEstablish one closed Work lifecycle authority membrane across C++, Python, Node.js, and Rust while preserving native runtime semantic ownership.\n\n## Related issue\n\nAtlas Assignment: 2026-07-25-kungfu-cross-language-authority-membrane\n\n## Changes\n\n- close the 47-operation Work lifecycle inventory with explicit owners, availability, and cross-language projection states\n- expose lossless raw request and result transport in all four SDKs without client-side defaults or semantic fallbacks\n- preserve unsupported, unavailable, degraded, stale, unknown, invalid-request, and bypass-not-admitted outcomes\n- retain a clean-source macOS arm64 installed SDK qualification and a bounded KFD-2 release claim\n- bind the implemented ADR closure to this protected PR\n\n## Verification\n\n- ./shifu build:core\n- ./shifu pack:sdk\n- ./shifu sdk:work-lifecycle:check\n- ./shifu check:work-lifecycle-operation-matrix\n- ./shifu layers:qualify:sdk -- --report docs/qualification/evidence/authority-membrane/2026-07-25-macos-arm64/sdk-report.json\n- ./shifu kfd:buildchain:check\n- framework/core/build/Release/kungfu_action_runtime_tests\n- staged commit gate including documentation, C++, Python, Rust, and KFD checks\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f8c53-6105-71e5-8f34-53f2a81ee61c\"],\n  \"summary\": \"Close the native authority inventory and qualify lossless four-language projections without upgrading projected surfaces to semantic owners.\",\n  \"verification\": [\"Retained macOS arm64 installed four-language SDK report bound to clean implementation commit d2de5e9092cfdc8bc200d0f06e76c0f966ea7a92\", \"Work lifecycle matrix and generated SDK drift checks\", \"Native runtime and staged repository gates\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release evidence boundary is limited to a KFD-2 claim and a retained local-platform qualification report. It does not publish packages or claim other platforms.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-25T01:55:00Z",
          "mergedAt": "2026-07-25T05:58:50Z",
          "additions": 4856,
          "deletions": 1291,
          "changedFiles": 68
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1812,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1812",
          "title": "fix(release): finish completed major finalization",
          "body": "## Summary\n- propagate the exact dev-reviewed major finalization completion patch to the current release line\n- bind release-impact projection to v3.0 during passport finalization\n- resume complete v3.0.0 transactions without provider replay or v3.0.1 stable selection\n\n## Provenance\n- source commit: cf5b800c9ae0c0d926b1771230773cf854315270\n- release commit: 8c41b3eb6b41c96d1990ae3fcf23ce2703eb56cb\n- stable patch-id: 2b97613468621889d0bfbdb8745134b8a98ee62b\n- dev merge: PR #1810 / 9261956a3e738577aff283988218f1e7c0ad6146\n\n## Verification\n- pnpm run check (835 tests; action bundles consistent)",
          "author": "dongkeren",
          "createdAt": "2026-07-25T06:00:52Z",
          "mergedAt": "2026-07-25T06:02:16Z",
          "additions": 111,
          "deletions": 36,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1813,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1813",
          "title": "chore(release): sync major gate after completed finalization",
          "body": "## Summary\n\n- record the current `publish-gate/major` tip as release ancestry\n- preserve the `release/v2/v2.14` tree byte-for-byte\n- unblock strict up-to-date propagation of the completed-major finalization fix\n\n## Verification\n\n- `git diff --exit-code HEAD^1 HEAD`\n- second parent is `243103a766b7ddc650b04f93417ddb56d6956301`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-25T06:05:28Z",
          "mergedAt": "2026-07-25T06:06:41Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1814,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1814",
          "title": "fix(release): finish completed major finalization",
          "body": "## Summary\n\n- propagate the completed-major recovery fix from `release/v2/v2.14`\n- project configured release impact to the active major line\n- resume finalization from durable `complete` state without replaying npm publication\n- reconstruct the next alpha/dev channel after a contained major handoff\n\n## Provenance\n\n- source patch: `cf5b800c9ae0c0d926b1771230773cf854315270`\n- release patch: `8c41b3eb6b41c96d1990ae3fcf23ce2703eb56cb`\n- stable patch-id: `2b97613468621889d0bfbdb8745134b8a98ee62b`\n- release merge: `7312fc003ac0b52fe74310dc56fc24d74d55d7d4`\n- ancestry sync merge: `0056b8123d9ab8a079656eb82d28cfac1bf10408`\n\n## Verification\n\n- `pnpm run check`: 835/835 tests passed\n- action bundles consistent\n- current `publish-gate/major` is an ancestor of the release head\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-25T06:07:15Z",
          "mergedAt": "2026-07-25T06:08:24Z",
          "additions": 111,
          "deletions": 36,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1468,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1468",
          "title": "feat(format): define portable authority composition",
          "body": "## Summary\n\nDefine the portable format as a composition of independently owned Fact, Episode, journal, manifest, schema, layout, package, and content-root authorities.\n\n## Changes\n\n- add the accepted authority ADR and machine-readable composition contract\n- add fail-closed source and identity drift checks\n- refresh the human ADR map and `.kungfu` authority index\n- serialize Git-sensitive documentation fixtures and isolate the promotion event index\n\n## Verification\n\n- `./shifu check:portable-format-authority`\n- `./shifu adr:audit`\n- `./shifu adr:map:check`\n- `./shifu docs:check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f96a2-c686-76e1-9261-f6106aa50429\"],\n  \"summary\": \"Stage the portable format authority composition and drift gate\",\n  \"verification\": [\"portable format authority checks\", \"ADR audit and map check\", \"deterministic documentation gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-25T04:07:28Z",
          "mergedAt": "2026-07-25T06:16:29Z",
          "additions": 873,
          "deletions": 119,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 147,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/147",
          "title": "feat(release): consume sealed installer bundles",
          "body": "Summary:\n- add the site-owned installer publication source pin and consumer adapter\n- require exact Kungfu GitHub Release roots plus a complete Buildchain seal before projection\n- preserve the committed honest-unavailable installer state by default\n\nValidation:\n- site build passed\n- site checks passed\n- positive and negative bundle resolver tests passed\n\nBoundary:\n- this source PR keeps status unavailable and does not publish or deploy installer availability.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T06:28:41Z",
          "mergedAt": "2026-07-25T06:40:04Z",
          "additions": 686,
          "deletions": 3,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1820,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1820",
          "title": "feat(release): seal installer publication bundles",
          "body": "Summary:\n- validate package-owned installer bundle topology, identity, MIME, cache, paths, and release coordinates\n- independently read back the public manifest and every unique GitHub Release asset\n- emit a content-addressed Buildchain seal for downstream site consumers\n\nValidation:\n- pnpm check: 838 unit tests passed\n- action bundle integrity passed\n- focused installer and web-surface negative tests passed\n\nBoundary:\n- this source PR performs no release, signing, site mutation, or deployment.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T06:28:41Z",
          "mergedAt": "2026-07-25T06:42:06Z",
          "additions": 544,
          "deletions": 19,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1819,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1819",
          "title": "fix(release): hand off alpha authority to v3",
          "body": "## Summary\n\n- move Buildchain alpha and release authority targets to the v3 lines while default dev remains on v2 during the transition\n- route alpha/stable promotion shells and self-dogfood through v3 refs\n- refresh the accepted alpha contract lock, generated workflow/site data, and coverage\n\n## Verification\n\n- `node --test tests/promotion-channel-router.test.mjs tests/github-governance-authority.test.mjs tests/build-surface.test.mjs` (122/122)\n- `pnpm run generate:site`\n- `pnpm run check` (834/834; 5 action bundles consistent)\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-25T06:28:34Z",
          "mergedAt": "2026-07-25T06:51:21Z",
          "additions": 115,
          "deletions": 112,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1818,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1818",
          "title": "Prepare v3.0.1-alpha.0",
          "body": "Create the generated version-state commit for v3.0.1-alpha.0.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: 85b4b69c3a76f3e64e8e96d8357d87cac62c9f16 -> a664c5e5068569355365a5c3b3d54432dcec8de1\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T06:19:10Z",
          "mergedAt": "2026-07-25T06:53:24Z",
          "additions": 6,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1470,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1470",
          "title": "feat(site): publish installer handoff bundle",
          "body": "## Summary\n\n- add the package-owned, closed-world installer publication bundle and schema\n- publish only exact Kungfu GitHub Release assets after signed channel admission\n- remove every site checkout, mutation, commit, push, PR, and deploy operation from Kungfu publication\n\n## Verification\n\n- Shifu package tests and release-channel tests\n- release promotion rehearsal with no side effects\n- full build-free source acceptance\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7718-8d1f-6402a87408a7\"],\n  \"summary\": \"Stage the package-owned installer publication bundle, independent Buildchain seal, and site-consumption boundary\",\n  \"verification\": [\"installer publication contract tests\", \"release promotion rehearsal\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n\nThis PR changes source contracts only. It does not run Alpha or Stable publication, signing, deployment, or make public installers available.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for the bounded architecture stage",
          "author": "dongkeren",
          "createdAt": "2026-07-25T06:28:40Z",
          "mergedAt": "2026-07-25T06:59:28Z",
          "additions": 920,
          "deletions": 221,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1822,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1822",
          "title": "Prepare v3.0.1-alpha.0",
          "body": "Create the generated version-state commit for v3.0.1-alpha.0.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: 9c920e414f58089379034f8994be1e9dc336a931 -> 3c21a05fb22a91491119c5a032745518f434afba\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T06:58:44Z",
          "mergedAt": "2026-07-25T07:00:37Z",
          "additions": 9,
          "deletions": 9,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1823,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1823",
          "title": "fix(release): settle contained version-state updates",
          "body": "Treat a protected generated version-state update as settled when the exact generated head still exists and the protected branch already contains that commit through a merged PR.\n\nThis prevents major finalization retries from attempting a non-fast-forward ref update and opening a duplicate PR after the generated next-alpha PR has already merged.\n\nValidation:\n- targeted containment and release recovery tests\n- pnpm run build\n- pnpm run check (839/839 tests; 5/5 action bundles)",
          "author": "dongkeren",
          "createdAt": "2026-07-25T07:18:42Z",
          "mergedAt": "2026-07-25T07:22:02Z",
          "additions": 217,
          "deletions": 52,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1825,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1825",
          "title": "fix(release): settle contained version-state updates",
          "body": "Release-head-specific propagation of the reviewed containment fix after the dev-based propagation PR #1824 proved non-mergeable.\n\nSource dev PR: #1823\nSource fix commit: e48ffe7ebc1563c1b2944073c5082d12d0060f26\nRelease cherry-pick: a0e50343\n\nValidation:\n- targeted major containment regression passes on the release base\n- action bundle integrity passes (5/5)",
          "author": "dongkeren",
          "createdAt": "2026-07-25T07:25:15Z",
          "mergedAt": "2026-07-25T07:26:32Z",
          "additions": 217,
          "deletions": 52,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1826,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1826",
          "title": "fix(release): settle contained version-state updates",
          "body": "Propagate the contained generated version-state settlement fix from protected release/v2/v2.14 into publish-gate/major so the existing v3 finalization transaction can resume.\n\nRelease PR: #1825\nRelease merge: e7e39b120ae70b7e8fe4167ed58638ea805b4344\n\nThe diff is limited to the promotion controller source, its checked-in action bundle, and the regression test.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T07:27:26Z",
          "mergedAt": "2026-07-25T07:28:52Z",
          "additions": 217,
          "deletions": 52,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1471,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1471",
          "title": "feat(format): define required reader contract",
          "body": "## Summary\n\nDefine one machine-readable required-reader contract that separates preservation, inspection, structural verification, semantic verification, canonical fold, admission, and execution.\n\n## Changes\n\n- add deterministic read, degraded, preserve-only, migration-required, and reject outcomes\n- preserve unknown bytes while refusing unknown semantics at fold, admission, and execution\n- mark Episode fsck degraded when unknown records are present and retain Fact export refusal\n- derive the public Spec reader profiles and error dictionary from the authority contract\n\n## Verification\n\n- `./shifu check:portable-format-authority`\n- `./shifu test:episode-control` (46 passed)\n- `npm --prefix framework/spec run build`\n- `npm --prefix framework/spec run verify`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f96a2-c686-76e1-9261-f6106aa50429\"],\n  \"summary\": \"Implement the required-reader authority and fail-closed unknown-material boundary\",\n  \"verification\": [\"required-reader contract checks\", \"Episode control native tests\", \"generated Spec bundle verification\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-25T06:52:12Z",
          "mergedAt": "2026-07-25T07:49:12Z",
          "additions": 811,
          "deletions": 57,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1829,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1829",
          "title": "fix(release): skip settled default branch updates",
          "body": "## Summary\n- read the repository default branch before requesting an update\n- treat an already-set default branch as an idempotent promotion settlement\n- avoid requiring repository-administration permission on resumed promotions\n\n## Verification\n- targeted promote-buildchain-ref regression\n- `pnpm run build`\n- `pnpm run check` (839/839 tests; 5/5 action bundles)",
          "author": "dongkeren",
          "createdAt": "2026-07-25T07:49:15Z",
          "mergedAt": "2026-07-25T07:53:10Z",
          "additions": 22,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1830,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1830",
          "title": "fix(release): skip settled default branch updates",
          "body": "## Summary\n- propagate the tested default-branch idempotency fix to the active release line\n- avoid repeating an admin-only repository update when the target is already default\n\n## Verification\n- source commit passed `pnpm run build` and `pnpm run check` (839/839 tests; 5/5 action bundles)\n- this release-line cherry-pick is revalidated by protected-branch CI",
          "author": "dongkeren",
          "createdAt": "2026-07-25T07:56:23Z",
          "mergedAt": "2026-07-25T07:58:29Z",
          "additions": 22,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1831,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1831",
          "title": "chore(release): advance major finalization idempotency",
          "body": "## Summary\n- advance the active v2.14 release line into the major publication gate\n- include contained version-state settlement and default-branch idempotency\n- resume v3 finalization without replaying the already-published npm transaction\n\n## Expected outcome\n- current major promotion recognizes the already-set `dev/v3/v3.0` default branch\n- promotion completes under the workflow App without repository-administration mutation",
          "author": "dongkeren",
          "createdAt": "2026-07-25T07:58:48Z",
          "mergedAt": "2026-07-25T08:00:17Z",
          "additions": 22,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1834,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1834",
          "title": "chore(governance): complete v3 authority handoff",
          "body": "## Summary\n- carry the complete major-finalization recovery chain onto the v3 development line\n- settle contained version-state updates and already-set default branches idempotently\n- move the authoritative Buildchain development target from `dev/v2/v2.14` to `dev/v3/v3.0`\n- regenerate package-owned public site facts and documentation examples\n\n## Verification\n- governance authority tests: 24/24\n- major finalization recovery regressions: 2/2\n- `pnpm run build`\n- `pnpm run check`: 836/836 tests; 5/5 action bundles",
          "author": "dongkeren",
          "createdAt": "2026-07-25T08:24:12Z",
          "mergedAt": "2026-07-25T08:26:11Z",
          "additions": 744,
          "deletions": 148,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1465,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1465",
          "title": "feat(release): close Core npm platform distribution",
          "body": "## Summary\n\nClose the npm identity and native distribution gap for Kungfu v4. The lightweight `@kungfu-tech/core` entrypoint now resolves one of three exact native platform packages, while the former `framework/sdk` storage workspace is correctly named `framework/storage` without changing its public `@kungfu-tech/storage` identity.\n\n## Related issue\n\nAssignment: `2026-07-25-kungfu-npm-core-platform-distribution-closure`\n\n## Changes\n\n- Rename the live storage workspace and update every active authority, generator, contract, test, documentation, workspace, and Buildchain reference.\n- Add exact Core platform package contracts for macOS arm64, Linux x64, and Windows x64, source-pack refusal, payload pruning, post-pack content checks, size gates, and digest receipts.\n- Keep the main Core package platform-neutral and below 100 KiB, with exact optional dependencies injected only into generated release artifacts.\n- Add a closed Node native export authority, generated TypeScript declarations, exact export parity, and no-spawn in-process semantic tests.\n- Expand the protected npm Release inventory from 25 to 28 packages; remove every workspace `private` boundary, generate all 28 exact tarballs, and bind them into trusted publishing, Buildchain collection, preflight, public digest verification, rollback, and CODEOWNERS.\n- Pack Core npm artifacts as part of Product distribution.\n\n## Verification\n\n- `./shifu check:source`\n- latest-head source and KFD gates at `9b8a01176eb1368e89d997446de87a865344cb1d`\n- staged pre-commit gate, including Rust clippy/workspace tests and Xinfa native/Wasm equivalence\n- Core package/tooling tests: 25 passing\n- npm registry and targeted publication/release tests: 16 passing\n- all 19 portable workspace tarballs generated locally and accepted by `npm publish --dry-run --access public --tag alpha`; the six generated native packages plus three dedicated workspace packers complete the exact 28-package set\n- full four-language SDK artifact build, pack, installed-artifact semantic/wire/work-lifecycle qualification passing on macOS arm64; the report binds `framework/storage/kungfu-storage.contract.json`\n- exact installed-tarball smoke: native storage capability call with every `child_process` entry disabled, CLI resolution, and executable frozen Python\n- macOS arm64 Core platform receipt: 85,530,382 compressed bytes, 1,153 files, normal size status, prohibited-content gate passing\n- complete pre-base-advance `./shifu dist` from clean task commit `ff9d34649c10a0302e2c359dbcdfc0636bb1ccbe`; Developer ID signed app, CLI installed-layout smoke, and Shifu build `20260725T054503Z-ff9d34649`; an exact integrated-head Product build remains required before promotion\n- Linux x64 and Windows x64 native package qualification are delegated to the protected PR matrix and remain required before merge\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-70c5-b572-89ec183b37de\",\n    \"KF-ADR-019f86da-4f90-7e5e-ae22-2a8fc24086f1\",\n    \"KF-ADR-019f86da-4f90-7c91-9cc2-6dbd18d68dff\"\n  ],\n  \"summary\": \"Stage the exact three-platform Core npm distribution, live storage workspace identity, Node in-process authority, and fully packable 28-package protected Release inventory.\",\n  \"verification\": [\n    \"./shifu check:source\",\n    \"exact installed-tarball no-spawn smoke\",\n    \"19 portable workspace tarballs pass npm publish dry-run with the derived alpha tag\",\n    \"pre-base-advance clean macOS Product build 20260725T054503Z-ff9d34649; integrated-head Product build required before promotion\",\n    \"protected native platform matrix before merge\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes package identity and protected publication surfaces without adding credentials, manual tokens, install-time downloads, source builds, or direct publication. Exact package inventory, OIDC workflow, CODEOWNERS, digest verification, rollback policy, and native runner boundaries are machine checked.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and generated authority projections updated\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T03:09:08Z",
          "mergedAt": "2026-07-25T08:30:05Z",
          "additions": 2151,
          "deletions": 329,
          "changedFiles": 90
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1833,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1833",
          "title": "feat(release): add cross-repository activation transaction",
          "body": "## Summary\n- add strict ordered activation transaction and authoritative receipt-set contracts\n- pin production web-surface apply to an exact reviewed consumer SHA\n- synthesize released product evidence only after publication, read-back, and qualification receipts agree\n\n## Validation\n- node --test tests/release-activation-transaction.test.mjs\n- bash scripts/check-workflows.sh\n- node scripts/check-inventory.mjs\n- pnpm check:site\n- node scripts/check-action-bundles.mjs\n- serial release/web-surface regression set: 216 passed\n\nDownstream validation pins exact Buildchain commit 420784a128cab230f840a11e82225c255cf58500.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T08:20:04Z",
          "mergedAt": "2026-07-25T08:34:14Z",
          "additions": 882,
          "deletions": 45,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1836,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1836",
          "title": "chore(release): reconcile activation transaction ancestry",
          "body": "Record `alpha/v2/v2.14` as an ancestor of the reviewed activation transaction head while preserving the dev tree byte-for-byte.\n\nThis follows the existing v2.14 channel ancestry reconciliation pattern (for example #1665), removes the dev-to-alpha history conflict, and requires the eventual channel candidate to be revalidated.\n\n- pre-reconciliation dev head: `2826967b674febd5db869c1a43007505f5b0fd9f`\n- reconciled head: `0e0e7e42`\n- tree invariant: first-parent tree equals reconciliation tree\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-25T08:42:11Z",
          "mergedAt": "2026-07-25T08:50:51Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1474,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1474",
          "title": "feat(format): define migration and repair protocol",
          "body": "## Summary\n\nDefine feature- and protocol-aware format negotiation, explicit cold-path migration, downgrade refusal, idempotent reconciliation, and evidence-preserving repair.\n\n## Changes\n\n- compare journal, layout, record, payload, root, bundle, and capability axes instead of package semver\n- expose only declared directed cold-path edges and reject downgrade before writes\n- bind target-protocol-proved successor roots and retained source evidence in deterministic receipts\n- keep structural repair separate from semantic migration and preserve damage evidence\n\n## Verification\n\n- `./shifu check:portable-format-authority` (21 passed)\n- `./shifu check:types`\n- `./shifu docs:check`\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f96a2-c686-76e1-9261-f6106aa50429\"],\n  \"summary\": \"Implement the portable format migration, downgrade refusal, and evidence-preserving repair protocol\",\n  \"verification\": [\"portable format authority checks\", \"deterministic migration and repair scenarios\", \"source acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-25T08:28:30Z",
          "mergedAt": "2026-07-25T08:51:39Z",
          "additions": 974,
          "deletions": 19,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1835,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1835",
          "title": "release: promote activation transaction to v2 alpha",
          "body": "Promote the reviewed cross-repository release activation transaction from `dev/v2/v2.14` to the v2 alpha channel.\n\nThis makes the public promotion router and its advanced workflow shell agree on the activation receipt-set inputs used by Kungfu Alpha.\n\nBuildchain delivery PR: #1833\n\nValidation: Buildchain Verify and Build Surface Fixture passed on the exact reviewed source.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T08:39:24Z",
          "mergedAt": "2026-07-25T08:54:17Z",
          "additions": 4131,
          "deletions": 521,
          "changedFiles": 49
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 149,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/149",
          "title": "feat(release): publish exact activation status",
          "body": "## Summary\n- publish a strict truthful release-status endpoint and schema\n- pin Buildchain workflow shell/runtime to exact reviewed commit 420784a128cab230f840a11e82225c255cf58500\n- require exact production activation source/environment/root and stop on partial inputs\n- generate current-release status only from signed publication import\n- document installed `kungfu release status` verification\n\n## Validation\n- pnpm build\n- pnpm check\n- cross-repository Buildchain activation shadow receipt validation\n\nThis PR does not activate or publish an Alpha release; the committed endpoint remains `unavailable`.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T08:21:27Z",
          "mergedAt": "2026-07-25T08:56:57Z",
          "additions": 358,
          "deletions": 30,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1837,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1837",
          "title": "Prepare v2.14.19-alpha.0",
          "body": "Create the generated version-state commit for v2.14.19-alpha.0.\n\nBuildchain generated this PR because protected branch alpha/v2/v2.14 rejected direct generated bookkeeping.\n\nRejected update: 22974861f653c475febd15dd67dcc5cc01fb6f83 -> aec03d7a9532d912383d430aafe60cefd2d0a290\n\nGitHub response: Repository rule violations found\n\nChanges must be made through a pull request.\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T09:05:09Z",
          "mergedAt": "2026-07-25T09:09:03Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 124,
          "url": "https://github.com/kungfu-systems/libnode/pull/124",
          "title": "feat(packages): publish Linux ARM64 libnode",
          "body": "## Summary\n\n- add the native `@kungfu-tech/libnode-linux-arm64` platform package\n- build it on GitHub's native `ubuntu-24.04-arm` runner\n- require the fourth platform artifact in release promotion and KFD evidence\n- advance the immutable package set to `22.22.3-kf.5-alpha.1` after the existing `kf.4` stable release\n\n## Verification\n\n- `corepack pnpm verify-release`\n- `corepack pnpm verify-kfd-witnesses`\n- `corepack pnpm verify-package-source`\n- `actionlint .github/workflows/build.yml .github/workflows/release-verify.yaml .github/workflows/release-new-version.yml`\n- `git diff --check`\n\nThe PR build is the native four-platform qualification, including Linux ARM64.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T04:05:21Z",
          "mergedAt": "2026-07-25T09:29:36Z",
          "additions": 72,
          "deletions": 30,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1473,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1473",
          "title": "feat(core): qualify native Work lifecycle adapter",
          "body": "## Summary\n\nComplete and qualify the native Work lifecycle adapter for all six governed operations through the single Core authority.\n\n## Related issue\n\nAtlas Assignment: 2026-07-25-kungfu-native-work-lifecycle-adapter-qualification\n\n## Changes\n\n- implement inspect, create, update, transition, export, and import in the native Work journal authority\n- bind mutations to exact request, expected-state, and native receipt roots with idempotent no-second-write behavior\n- preserve exact ActionEnvelope bytes across export/import, including unknown future envelopes\n- remove missing operation-matrix rows and keep generated C++, Python, Node.js, and Rust projections mechanically aligned\n- retain macOS arm64 installed-SDK qualification and refresh KFD release evidence\n\n## Verification\n\n- ./shifu check:source\n- ./shifu build:core\n- ./shifu build:core:sdk\n- ./shifu pack:sdk\n- ./shifu layers:qualify:sdk -- --report docs/qualification/evidence/authority-membrane/2026-07-25-macos-arm64/sdk-report.json\n- framework/core/build/Release/kungfu_api_contract_tests\n- framework/core/build/Release/kungfu_action_runtime_tests\n- targeted ctest: 2/2 passed\n- SDK projection checks: 14/14; operation matrix: 13/13; Node combined: 19/19\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f8c53-6105-71e5-8f34-53f2a81ee61c\"],\n  \"summary\": \"Complete the six-operation native Work lifecycle authority and qualify its exact-root mutation and four-language projection boundaries.\",\n  \"verification\": [\"Native ABI and action-runtime tests including malformed import, stale basis, idempotency, and unknown-envelope round trip\", \"Retained macOS arm64 installed four-language SDK qualification report\", \"Full build-free source acceptance and generated projection drift gates\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release evidence boundary is limited to retained local-platform SDK qualification and KFD claims. This PR does not publish packages or widen claims to other platforms.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-25T07:58:29Z",
          "mergedAt": "2026-07-25T09:45:06Z",
          "additions": 1335,
          "deletions": 351,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1476,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1476",
          "title": "feat(format): add retained real-byte vectors",
          "body": "## Summary\n\nQualify the portable-format authority with an append-only, content-rooted retained byte corpus and native/independent reader agreement.\n\n## Changes\n\n- retain eight journal-page and Fact-root byte vectors across all five required-reader outcomes\n- verify exact byte roots, release root, migration retry reconciliation, and evidence-preserving repair refusal\n- exercise three journal vectors through the native yijinjing mmap reader\n- project the qualified v1 corpus into the Spec bundle and human format contract\n\n## Verification\n\n- `./shifu build:core`\n- `./shifu test:mmap`\n- `./shifu check:portable-format-authority` (24 passed)\n- `pnpm --dir framework/spec run build && pnpm --dir framework/spec run verify`\n- `./shifu check:types`\n- `./shifu docs:check`\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f96a2-c686-76e1-9261-f6106aa50429\"],\n  \"summary\": \"Qualify portable format compatibility with retained real-byte vectors and native-independent reader agreement\",\n  \"verification\": [\"portable format authority checks\", \"native mmap retained-vector tests\", \"Spec bundle verification\", \"source acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-25T09:35:00Z",
          "mergedAt": "2026-07-25T10:10:21Z",
          "additions": 765,
          "deletions": 22,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 308,
          "url": "https://github.com/kungfu-systems/build-images/pull/308",
          "title": "feat(images): add OpenCode local-model CI runner",
          "body": "## Summary\n\n- add a pinned non-root OpenCode CI image for external OpenAI-compatible local-model endpoints\n- require independent JSONL evidence verification and fail closed on false-success tool runs\n- add deterministic positive/negative fixtures, selective publish coverage, image contracts, and CI gating\n\n## Verification\n\n- pnpm run check\n- native linux/amd64 clean image build on agent-120\n- deterministic read/write/bash fixture passed\n- false-success fixture was rejected by the independent verifier\n- qwen3-coder:30b-opencode-64k passed read/write/bash verification with a 65,536-token context declaration\n\n## Safety boundary\n\nThe image contains no model weights, credentials, host addresses, Docker socket, or login state. Runtime endpoint and model coordinates are supplied explicitly.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T09:28:54Z",
          "mergedAt": "2026-07-25T10:18:28Z",
          "additions": 667,
          "deletions": 117,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1477,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1477",
          "title": "fix(release): restore Buildchain workflow input contract",
          "body": "## Summary\n\nRestore the immutable Buildchain workflow pin to a provider revision whose reusable Build and Promotion input contracts exactly match the Kungfu callers. This fixes remote workflow startup failure without changing the product or architecture contract.\n\n## Related issue\n\nFollow-up to #1465 and failed exact-head Build run 30151983289.\n\n## Changes\n\n- Pin Build and Promotion to Buildchain commit 420784a128cab230f840a11e82225c255cf58500 from Buildchain PR #1833.\n- Refresh the governed workflow authority digest and static binding projections.\n- Keep the release rehearsal contract aligned with the same immutable provider revision.\n\n## Verification\n\n- Machine comparison: Build caller/provider inputs 35/35; Promotion caller/provider inputs 38/38; zero missing inputs.\n- `./shifu check:source`\n- `./shifu test:alpha-promotion-preflight` (11/11)\n- targeted release and gate tests (34/34)\n- `./shifu check:gate-catalog` (38 gates, 6 profiles, 25 invocations, 18 workflows)\n- full pre-commit hook, including deterministic documentation and ADR authority checks\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix only restores an immutable reusable-workflow provider pin whose declared inputs match the existing Kungfu caller contract; it does not alter product or architecture behavior.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release boundary is limited to immutable workflow bindings. Source gates, caller/provider input comparison, and an exact merged-head remote Build will provide the evidence.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-25T10:05:08Z",
          "mergedAt": "2026-07-25T10:27:39Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 309,
          "url": "https://github.com/kungfu-systems/build-images/pull/309",
          "title": "chore(release): prepare v1.3.0-alpha.15",
          "body": "## Summary\n\n- advance the v1.3 alpha version state to `1.3.0-alpha.15`\n- include the merged OpenCode local-model CI runner from #308 in the next alpha transaction\n- leave the failed, unpublished alpha.14 transaction as historical evidence instead of reusing its version\n\n## Verification\n\n- `pnpm run check`\n- KFD-1/2/3 and release-passport smoke passed\n- 114 qualification tests passed\n\n## Release note\n\nThe previous alpha.14 promotion failed before publication while reading opaque branch protection. Current Buildchain `v2-alpha` includes the later `fix(promotion): observe opaque protected branches` compatibility fix.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T10:29:20Z",
          "mergedAt": "2026-07-25T10:32:35Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 310,
          "url": "https://github.com/kungfu-systems/build-images/pull/310",
          "title": "chore(release): promote v1.3.0-alpha.15",
          "body": "## Summary\n\nPromote the reviewed `dev/v1/v1.3` line to `alpha/v1/v1.3` for the `v1.3.0-alpha.15` Buildchain publish transaction.\n\nThis release includes:\n\n- OpenCode local-model CI runner from #308\n- fresh alpha.15 version state from #309\n- no reuse of the failed, unpublished alpha.14 transaction\n\n## Verification\n\n- #308 merged with all required checks green\n- #309 merged with all required checks green\n- agent-120 native amd64 deterministic fixture passed\n- agent-120 + Qwen3-Coder 30B real-model qualification passed with independent verifier\n\nAfter this PR merges and the alpha Verify workflow succeeds, `Buildchain Ref Promotion` is expected to publish the exact OCI family and release passport.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T10:32:54Z",
          "mergedAt": "2026-07-25T10:35:40Z",
          "additions": 669,
          "deletions": 119,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 127,
          "url": "https://github.com/kungfu-systems/libnode/pull/127",
          "title": "feat(packages): promote Linux ARM64 libnode to alpha",
          "body": "## Summary\n\nPromote the reviewed Linux ARM64 platform package and native ARM64 lane on a branch that already contains the current alpha baseline.\n\n## Scope\n\n- publish `@kungfu-tech/libnode@22.22.3-kf.5-alpha.1`\n- publish four platform packages, including the new `linux-arm64` package\n- retain reviewed four-platform Buildchain evidence and trusted npm publication\n\n## Evidence\n\n- implementation PR: #124\n- exact-head trusted run: 30150580971\n- implementation merge: `f617d10b63c23c167ee9b3886e2015e3f99a3aa6`\n- promotion merge: `5039898`\n- supersedes #126, whose head could not satisfy strict alpha-base ancestry without modifying protected `dev`",
          "author": "dongkeren",
          "createdAt": "2026-07-25T09:39:34Z",
          "mergedAt": "2026-07-25T11:02:24Z",
          "additions": 72,
          "deletions": 30,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1838,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1838",
          "title": "fix(promotion): admit opaque protected channel reads",
          "body": "## Summary\n\n- treat an opaque GitHub 404 from the full branch-protection endpoint like the already-supported 403\n- preserve the existing provider-transaction fallback, which requires the branch summary, exact required check, immutable merged PR head, and independent approval\n- add regression coverage through the public `assertProtectedChannel` path for both 403 and 404\n- rebuild the committed promote action bundle\n\n## Triggering evidence\n\n`kungfu-systems/build-images` alpha promotions failed before publication in runs 30093266480 and 30154818923 because `GET /branches/alpha%2Fv1%2Fv1.3/protection` returned an intentionally opaque 404. The adjacent managed-policy observer already handles both 403 and 404, but the pre-promotion assertion handled only 403.\n\n## Verification\n\n- targeted 403/404 regression test passed\n- `pnpm run check` passed\n- 843 unit tests passed\n- 5 action bundles passed integrity verification\n\n## Train\n\n- ref: `train/v2/v2.3/opaque-protected-channel-404`\n- SHA: `4bda49c047fad7d3ef7a9009ba2c11ef049871e1`\n\nThe downstream caller uses the promotion action from an outer `workflow_run` workflow stored on its default branch, so a train cannot be injected without changing that control-plane workflow. The regression reproduces the exact provider response and the durable downstream recheck will occur after `v2-alpha` advances.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T10:46:40Z",
          "mergedAt": "2026-07-25T11:09:45Z",
          "additions": 53,
          "deletions": 38,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1839,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1839",
          "title": "chore(release): promote opaque protected channel fix to v2.14 alpha",
          "body": "## Summary\n\nPromote the reviewed opaque protected-channel read fix from `dev/v2/v2.14` to `alpha/v2/v2.14`.\n\n## Evidence\n\n- source PR: #1838\n- dev merge: `b31b522fc0486622a589e31e57de4325cb435c46`\n- full repository checks and merge-queue checks passed\n- provider fallback remains strict: exact PR head, independent approval, protected branch summary, and required check/app evidence\n\n## Downstream qualification\n\nAfter the resulting `v2-alpha` release advances, rerun the failed build-images alpha promotion that currently receives an opaque 404 from GitHub branch protection reads.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T11:10:17Z",
          "mergedAt": "2026-07-25T11:13:31Z",
          "additions": 53,
          "deletions": 38,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1478,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1478",
          "title": "feat(agent): add provider-neutral OpenCode runner",
          "body": "## Summary\n\nAdd a provider-neutral `kungfu run agent` path with verified Runtime Profiles and an OpenCode adapter. The runner records a native Runtime Episode, isolates OpenCode provider state, binds WorkRef/continuation evidence, and keeps process exit or agent self-report separate from Work settlement.\n\nAdd a reproducible two-session OpenCode continuity qualification using `opencode/north-mini-code-free`. The qualification requires distinct provider session identities, zero prior transcript bytes, zero human task restatement, an independent partial assessment, an exact continuation oracle, verified Episode frames, a successor Project Cut receipt, and deterministic semantic replay.\n\nThis linear delivery supersedes #1472, whose equivalent tree was repeatedly rejected by the repository's rebase merge queue because its accumulated merge commits replayed generated KFD artifacts.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- discover, configure, and verify OpenCode Runtime Profiles alongside Codex and Claude\n- expose `kungfu run agent` through the CLI catalog and generated KFD/SDK projections\n- add bounded process execution, environment allowlisting, fresh XDG isolation, and fail-closed provider JSONL parsing\n- add the free-model two-session continuity qualification, negative contract tests, operator documentation, synchronized ADR delivery projections, and refreshed KFD claims\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu docs:check`\n- `./shifu kfd:buildchain:check`\n- `./shifu test:run-agent-opencode-continuity`\n- `./shifu test:agent-console-contract`\n- `./shifu test:cli-surface-contract`\n- `./shifu test:continuity-pilot`\n- `./shifu adr:identity:test`\n- `./shifu qualify:run-agent-opencode-continuity`\n\nThe final-head qualification at `84d06b40de0367263577230c758d3a774a211eb1` passed with OpenCode 1.18.3 and `opencode/north-mini-code-free`. It used distinct sessions `ses_0671b0f79ffefr9FbWis4iKvhH` and `ses_0671ae440ffeIh6tvwFnx50pxC`, provider-reported cost 0 for both runs, zero prior transcript bytes, zero human re-explanations, oracle success, verified frames for both Episodes, successor Cut `sha256:fd063ec5e88330fb470537066e7b30097592d20ed0d5e7349ffd716d8c1c02b1`, valid receipt `sha256:3954df58a6811ff1fc1d61abc236175a2af1344fe33ae3ac7a095591321b1a5d`, and matching semantic replay root `sha256:0c9dbed6bf480e1df3bf9a6de4db8f9f4dd3f375eafc2456cfb8ec7f8337d7b3`.\n\nAn earlier attempt was deliberately rejected because the free model transcribed the base64 payload incorrectly; no settlement was admitted. Passing runs at earlier heads were superseded by the final-head qualification above after syncing the latest dev mainline.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-7977-9cfc-85d26d41780b\",\n    \"KF-ADR-019f86da-4f90-786d-aa24-a97705e13917\"\n  ],\n  \"summary\": \"Stage a provider-neutral direct runner and a real two-session OpenCode continuity proof without treating process exit or self-report as Work settlement\",\n  \"verification\": [\n    \"build-free source acceptance\",\n    \"free-model two-session continuity qualification\",\n    \"Episode frame fsck and deterministic successor Cut replay\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe implementation invokes only the user-selected provider CLI, never reads private provider session stores, reports environment keys but not values, preserves provider-reported cost and usage observations, and does not bypass provider billing or quota.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T10:50:50Z",
          "mergedAt": "2026-07-25T11:19:15Z",
          "additions": 2591,
          "deletions": 103,
          "changedFiles": 43
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1840,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1840",
          "title": "Prepare v2.14.19-alpha.1",
          "body": "Create the generated version-state commit for v2.14.19-alpha.1.\n\nBuildchain generated this PR because protected branch alpha/v2/v2.14 rejected direct generated bookkeeping.\n\nRejected update: 315ef133384ca3e6d8f086213c3f893ca1882917 -> 2838dd20eb0cb23c841d8049448730a0ada9b3c7\n\nGitHub response: Repository rule violations found\n\nChanges must be made through a pull request.\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T11:19:32Z",
          "mergedAt": "2026-07-25T11:23:02Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 311,
          "url": "https://github.com/kungfu-systems/build-images/pull/311",
          "title": "fix(release): separate promotion token duties",
          "body": "## Summary\n\nAlign the direct build-images promotion workflow with Buildchain’s current token-duty separation:\n\n- use the workflow-scoped GitHub token for primary API, durable state, tag, release, and generated ref writes;\n- retain `BUILDCHAIN_PROMOTION_TOKEN` only for generated protected-branch pull requests;\n- apply the same routing to alpha and stable promotion.\n\n## Trigger\n\nBuild-images alpha promotion run `30156379810` passed governance and failed before publication when the legacy promotion PAT received an opaque 404 from `POST /repos/kungfu-systems/build-images/git/blobs` while preparing durable release state.\n\n## Validation\n\n- `pnpm run check`\n- workflow token routing matches Buildchain `.release-candidate-promote.yml`\n\nNo image, tag, release, or durable state was created by the failed run.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T11:37:42Z",
          "mergedAt": "2026-07-25T11:40:56Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 312,
          "url": "https://github.com/kungfu-systems/build-images/pull/312",
          "title": "chore(release): promote publication token routing to v1.3 alpha",
          "body": "## Summary\n\nPromote the reviewed workflow-only token-duty fix from `dev/v1/v1.3` to `alpha/v1/v1.3`.\n\n## Evidence\n\n- source PR: #311\n- dev merge: `629452b9b5e3df178e0267326231a86da0b95617`\n- local and PR repository checks passed\n- release version remains `1.3.0-alpha.15`\n\nAfter merge, a successful alpha Verify will resume the same unpublished alpha.15 transaction using the workflow-scoped GitHub token for durable state and ref writes.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T11:41:32Z",
          "mergedAt": "2026-07-25T11:44:53Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1479,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1479",
          "title": "feat(spec): generate rooted portable authority bundle",
          "body": "## Summary\n\nGenerate the portable format Spec bundle from accepted authority contracts as deterministic, content-addressed artifacts that remain verifiable after package installation.\n\n## Changes\n\n- generate eight rooted authority artifacts from exact accepted source roots\n- bind artifact roots into one canonical normative root with mutable build provenance excluded\n- validate the complete manifest schema, committed generation, retained vector bytes, and installed-package roots\n- expose authority inspection and verification through the package CLI and Node API\n- route historical Spec 0.1 prose exclusively as non-normative history\n\n## Verification\n\n- `pnpm --filter @kungfu-tech/spec verify`\n- `./shifu check:portable-format-authority` (24 passed)\n- `./shifu layers:gate:format`\n- `./shifu check:types`\n- `./shifu docs:check`\n- byte-identical double build manifest comparison\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f96a2-c686-76e1-9261-f6106aa50429\"],\n  \"summary\": \"Generate the rooted portable format authority bundle from qualified source contracts\",\n  \"verification\": [\"deterministic generated-artifact checks\", \"portable format authority checks\", \"installed Spec package root verification\", \"format layer qualification\", \"documentation gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-25T11:14:52Z",
          "mergedAt": "2026-07-25T11:53:13Z",
          "additions": 2800,
          "deletions": 664,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 315,
          "url": "https://github.com/kungfu-systems/build-images/pull/315",
          "title": "fix(release): route promotion writes through GitHub token",
          "body": "## Summary\n\n- use the workflow GitHub token for durable release-state and ref updates\n- reserve `BUILDCHAIN_PROMOTION_TOKEN` for generated pull requests\n- apply the routing fix on the default branch, which supplies `workflow_run` workflow shells for every release line\n\n## Validation\n\n- `pnpm run check`\n- reproduced the stale default-branch workflow shell in promotion run 30156841761\n\n## Governance\n\nThis contributor-fork branch was created after the fork and pushed by `dongkeren`, so the independent `kungfu-origin` code-owner review can satisfy the default branch last-pusher rule. It supersedes #313 and #314.\n\n## Rollback\n\nRevert this commit to restore the previous token routing.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T11:55:30Z",
          "mergedAt": "2026-07-25T11:56:38Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 316,
          "url": "https://github.com/kungfu-systems/build-images/pull/316",
          "title": "Prepare v1.3.0-alpha.15",
          "body": "Create the generated version-state commit for v1.3.0-alpha.15.\n\nBuildchain generated this PR because protected branch dev/v1/v1.3 rejected direct generated bookkeeping.\n\nRejected update: 629452b9b5e3df178e0267326231a86da0b95617 -> 7bc9d076ce85558703dd24313ace7103c68ff045\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T12:11:46Z",
          "mergedAt": "2026-07-25T12:15:08Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 317,
          "url": "https://github.com/kungfu-systems/build-images/pull/317",
          "title": "chore(release): finalize v1.3.0-alpha.15 publication",
          "body": "## Summary\n\n- promote the generated version-state checkpoint from `dev/v1/v1.3` back to `alpha/v1/v1.3`\n- resume the durable `v1.3.0-alpha.15` release transaction from `finalizing` to `complete`\n- create the immutable exact tag and GitHub Release passport assets\n\n## Evidence\n\n- publication run `30157192214` succeeded\n- release-state ref `buildchain/release-state/1-3-0-alpha-15` records all 10 required OCI artifacts\n- `opencode-ci` published digest: `sha256:4083ee089fa9a419f4915505094a6c1bcce433ff77455605ce8993af3b684ed3`\n- generated version-state PR #316 passed all checks and merged\n\n## Rollback\n\nRevert the resulting alpha merge if finalization must be retried from the durable release-state branch.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T12:15:30Z",
          "mergedAt": "2026-07-25T12:18:26Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1480,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1480",
          "title": "fix(assignment): keep starting cut as native context",
          "body": "## Summary\n\nKeep an authenticated Kungfu-native Assignment under Assignment request authority when its admitted record carries a starting Project Cut root. The Project Cut remains bounded input context; it no longer misclassifies the completion review as a legacy Go settlement.\n\nThis fixes the exact closeout failure recorded by dogfood Finding `sha256:3dc35e0a0e2fc948d9db543dd6d74a63549c9d5b0300405626daa94eb0f52043` and Issue `sha256:c015b9a801db13874f1068b5231b2e57ddb5de53ba025d1c51fa54ed9e0eda9b`.\n\n## Related issue\n\nNative dogfood Issue `issue-native-assignment-project-cut-context-misclassified`.\n\n## Changes\n\n- remove the starting Project Cut absence check from authenticated native Assignment detection\n- retain exact request/work-definition/source authority checks\n- prove that a starting Cut does not invoke the legacy Project Cut verifier\n- preserve the legacy Go completion path and fail-closed fallback tests\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python:framework/core/build/Release uv run --project framework/core --frozen pytest -q framework/core/tests/python/test_atlas_storage.py -k 'tracked_completion or native_assignment_completion'` — 3 passed\n- `./shifu test:mission-authority-cutover` — 28 dashboard tests and 7 authority tests passed\n- `./shifu kfd:buildchain:check`\n- repository staged pre-commit gate\n\nThe full `test_atlas_storage.py` run completed 83/85 tests; the two failures are pre-existing local native-build projection drift unrelated to this patch: the Fact type catalog reports the Initiative/Assignment successor names and the linked binding exposes the additional `action_runtime` operation. The targeted evidence and Mission authority suites pass.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix restores the existing native Assignment request-authority boundary and does not alter an architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation is unchanged because this restores the already-declared native Assignment authority contract\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T11:37:06Z",
          "mergedAt": "2026-07-25T12:33:22Z",
          "additions": 47,
          "deletions": 44,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1484,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1484",
          "title": "feat(site): project portable format authority",
          "body": "## Summary\n\nProject the verified `@kungfu-tech/spec` portable-format authority into `@kungfu-tech/site` without creating a second semantic authority or requiring consumers to reach into the monorepo.\n\n## Changes\n\n- verify the exact workspace Spec package before every site build\n- copy the complete Spec distribution byte-for-byte into the site package\n- bind the package coordinate, manifest byte root, normative root, pre-release status, conformance release, and upstream non-claims\n- expose stable package-local routes for the authority overview, reader contract, version matrix, registry, and retained vectors\n- validate the complete site schema and fail closed on undeclared format promotion, artifact drift, or retained-vector drift\n- replace stale pre-normative site assertions with the exact upstream-derived state\n\n## Verification\n\n- `./shifu --filter @kungfu-tech/site test` (Spec 6 passed; site 7 passed)\n- `./shifu docs:check:readonly` (103 passed)\n- `./shifu adr:map:check`\n- `pnpm pack` plus clean isolated install and all five package-local route reads\n- staged repository gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f96a2-c686-76e1-9261-f6106aa50429\"],\n  \"summary\": \"Project the exact rooted portable format authority into the self-contained site package\",\n  \"verification\": [\"verified Spec package pickup\", \"site schema and package tests\", \"isolated installed-package route verification\", \"retained-vector tamper rejection\", \"documentation and ADR map gates\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T12:38:03Z",
          "mergedAt": "2026-07-25T13:13:24Z",
          "additions": 736,
          "deletions": 51,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 128,
          "url": "https://github.com/kungfu-systems/libnode/pull/128",
          "title": "fix(ci): grant release promotion action writes",
          "body": "## Summary\n\nGrant the exact Actions permission required by the current Buildchain reusable release-promotion interface.\n\n## Evidence\n\n- alpha package candidate PR #127 passed the full four-platform build and merged normally\n- push run 30155542605 failed before job startup because the called workflow requests `actions: write` while this caller granted only `actions: read`\n- no npm package was partially published\n- the patch changes only the caller workflow permission and passes actionlint\n\n## Publication boundary\n\nThe follow-up alpha merge will reuse its protected PR candidate and OIDC trusted publisher. No branch protection or npm token bypass is requested.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T11:06:52Z",
          "mergedAt": "2026-07-25T13:53:05Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1483,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1483",
          "title": "fix(assignment): admit native empty-delta reviews",
          "body": "## Summary\n\nAllow an exact-head Kungfu-native Assignment review to recognize its authority-bound empty evidence delta. Native Assignment completion deliberately has no legacy Project Cut; a valid tracked checkout with `authority=kungfu-assignment-request` and `cut={}` can now close the sole missing-Episode gap.\n\nThis fixes the exact closeout failure recorded by dogfood Finding `sha256:30e2555b13beb64c3b527f5e10fb2e2962204aa0d49e1f12eb907ec877e9fb86` and Issue `sha256:4198fed0c054e16f187e808cbc949e67cdb962a451798ade18ff6ee63af0a8e8`.\n\n## Related issue\n\nNative dogfood Issue `issue-native-assignment-empty-delta-review-unverifiable`.\n\n## Changes\n\n- recognize an empty native Assignment checkout delta only under authenticated Assignment request authority\n- preserve the existing legacy Project Cut empty-Episode rule\n- prove the new predicate admits the native authority case and rejects the same empty object under a foreign authority\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python:framework/core/build/Release uv run --project framework/core --frozen pytest -q framework/core/tests/python/test_atlas_storage.py -k native_assignment_completion_treats_starting_project_cut_as_context` — 1 passed\n- `uv run --project framework/core --frozen ruff format --check ...` — passed\n- `uv run --project framework/core --frozen ruff check ...` — passed\n- repository staged pre-commit gate — passed\n\nThe adjacent `independent_completion_review_and_exact_continuation` test still hits the same two pre-existing local native-build projection drifts documented in #1480; the targeted native authority and empty-delta regression passes.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix completes the existing native Assignment request-authority closeout behavior and does not alter an architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation is unchanged because this restores the already-declared native Assignment closeout contract\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T12:34:57Z",
          "mergedAt": "2026-07-25T13:55:59Z",
          "additions": 87,
          "deletions": 42,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 319,
          "url": "https://github.com/kungfu-systems/build-images/pull/319",
          "title": "feat(images): add auditable demo renderer",
          "body": "## Summary\n\n- add a consumer-neutral, content-addressed demo renderer contract\n- pin the Playwright base image, Node, Playwright, Chromium toolchain, ffmpeg/ffprobe, locale, and redistribution-licensed font inventory\n- render transcript-traceable MP4, WebM, GIF, poster, probe, manifest, and checksums as a non-root process\n- add a path-scoped GitHub-hosted qualification workflow with deterministic smoke, SPDX SBOM, Trivy evidence, provenance, and content-addressed artifact upload\n\n## Verification\n\n- `pnpm run check`\n- `actionlint -color=false .github/workflows/demo-renderer-qualification.yml`\n- `python3 scripts/resolve-image-dag.py --json --changed-path images/demo-renderer/Dockerfile`\n\nThe container build and deterministic media smoke run on the new GitHub-hosted qualification job so the large MCR base image does not consume the shared office overseas link. Image publication remains behind the protected Buildchain alpha release transaction.\n\n## Release impact\n\nAdditive `image-family` / `image-contracts` change on v1.3. The new manifest stays `pending-first-publish` until a protected alpha transaction records the immutable public digest.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T13:51:40Z",
          "mergedAt": "2026-07-25T13:56:37Z",
          "additions": 1034,
          "deletions": 109,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 320,
          "url": "https://github.com/kungfu-systems/build-images/pull/320",
          "title": "chore(release): prepare v1.3.0-alpha.16",
          "body": "## Summary\n\n- advance the v1.3 alpha version state to `1.3.0-alpha.16`\n- bind the release impact ledger to the new auditable `demo-renderer` image contract merged in #319\n- preserve the previous alpha.15 transaction as the immutable published baseline\n\n## Verification\n\n- `pnpm run check`\n- 114 qualification tests passed\n- KFD-1/2/3 and release-passport smoke passed\n- renderer qualification run `30160435982` passed before trusted-branch projection\n- protected PR #319 merged at `fae70fc9fb23d4eea3937ea86a02b3b5a4f82694`\n\n## Release note\n\nAfter this version PR merges, the normal protected `dev/v1/v1.3` to `alpha/v1/v1.3` promotion will publish the new image and produce the immutable digest and Release Passport. No manual or production publication is requested.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T13:58:24Z",
          "mergedAt": "2026-07-25T14:01:50Z",
          "additions": 11,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 321,
          "url": "https://github.com/kungfu-systems/build-images/pull/321",
          "title": "chore(release): promote v1.3.0-alpha.16",
          "body": "## Summary\n\nPromote the reviewed `dev/v1/v1.3` line to `alpha/v1/v1.3` for the `v1.3.0-alpha.16` Buildchain publish transaction.\n\nThis release includes:\n\n- auditable, consumer-neutral `demo-renderer` from #319\n- alpha.16 version and Release Passport impact ledger from #320\n- deterministic media smoke, SPDX SBOM, vulnerability report, and provenance qualification evidence\n\n## Verification\n\n- #319 merged with required `check`, renderer qualification, and independent review\n- #320 merged with required `check` and independent review\n- renderer qualification run `30160435982` passed\n- exact dev head: `8501dfb8c0804947164f0d9a57c18435f8538b1c`\n\nAfter this protected PR merges and the alpha Verify workflow succeeds, `Buildchain Ref Promotion` is expected to publish the exact OCI family and Release Passport. This is alpha-only; no production promotion is requested.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T14:02:12Z",
          "mergedAt": "2026-07-25T14:05:10Z",
          "additions": 1045,
          "deletions": 113,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 322,
          "url": "https://github.com/kungfu-systems/build-images/pull/322",
          "title": "Prepare v1.3.0-alpha.16",
          "body": "Create the generated version-state commit for v1.3.0-alpha.16.\n\nBuildchain generated this PR because protected branch dev/v1/v1.3 rejected direct generated bookkeeping.\n\nRejected update: 8501dfb8c0804947164f0d9a57c18435f8538b1c -> 999b370743f3e64e4f0b634d5131bd1d3d6b83ba\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T14:26:29Z",
          "mergedAt": "2026-07-25T14:29:15Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 323,
          "url": "https://github.com/kungfu-systems/build-images/pull/323",
          "title": "chore(release): finalize v1.3.0-alpha.16 publication",
          "body": "## Summary\n\n- promote the generated version-state checkpoint from `dev/v1/v1.3` back to `alpha/v1/v1.3`\n- resume the durable `v1.3.0-alpha.16` release transaction from `finalizing` to `complete`\n- create the immutable exact tag and GitHub Release passport assets\n\n## Evidence\n\n- publication run `30161040563` succeeded\n- release-state ref `buildchain/release-state/1-3-0-alpha-16` records the required OCI artifacts\n- `demo-renderer` published digest: `sha256:cb5e1dec368d21c7d4e8baded99ac75f12f7eff0d19505751888cf974086efa6`\n- generated version-state PR #322 passed all checks and merged\n\n## Rollback\n\nRevert the resulting alpha merge if finalization must be retried from the durable release-state branch.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T14:29:47Z",
          "mergedAt": "2026-07-25T14:36:24Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1486,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1486",
          "title": "fix(release): close cross-platform npm build gaps",
          "body": "## Summary\n\nClose the remaining cross-platform failures exposed by exact-head Build run 30154618243 so the 28-package public npm publication set can proceed to a real dry-run rehearsal.\n\n## Changes\n\n- Accept the actual ELF libnode soname `libnode.so.127` while retaining the macOS and Windows native library contracts.\n- Run installed Agent Hub qualification through the product Python-free Node variant, avoiding the Windows embedded-runtime `spawn EINVAL` boundary.\n- Add regressions for both platform boundaries.\n- Rebase the fix as one linear commit on the current protected base; the already-merged generated-authority prepack change supplies `@kungfu-tech/spec/dist/capabilities.json`.\n\n## Verification\n\n- `./shifu check:source`\n- `pnpm --dir framework/core test:tooling` (25 pass, 2 native-only skips)\n- `./shifu test:kfd-agent-hub-20` (5 Node tests and 8 Python tests)\n- full pre-commit hook\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix closes platform-specific package assembly and installed-product execution defects within the already accepted npm distribution contract; it does not introduce a new architecture decision.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release boundary remains rehearsal-only: the follow-up workflow will use `execute=false`, and no npm package is published by this PR.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T14:09:38Z",
          "mergedAt": "2026-07-25T14:37:36Z",
          "additions": 41,
          "deletions": 22,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1485,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1485",
          "title": "chore(project-cut): bind docs closure to current dev",
          "body": "## Summary\n\nPublish the exact Project Cut evidence for the already-merged documentation and ADR consistency closure, preserving the complete successor lineage through the current development baseline.\n\n## Changes\n\n- publish Project Cut ed0d2592 at exact commit 4a364c4c16\n- preserve predecessor c0180552 and its earlier lineage\n- bind the existing Xinfa Atlas projections without changing product behavior\n\n## Verification\n\n- repository staged gate passed, including 103 documentation tests and Biome\n- native Completion Claim completion-94282c40 binds exact commit and Cut roots\n- independent review review-68150526f21b1fd9c0d838e9 is fit with no diagnostics\n- Atlas Project Cut closeout gate passes\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This PR publishes content-addressed Project Cut and Xinfa evidence for an already-merged docs/ADR closure; it does not change architecture contracts, implementation behavior, or ADR records.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe changed files are content-addressed Project Cut and Xinfa provenance artifacts only.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-25T13:18:49Z",
          "mergedAt": "2026-07-25T14:53:57Z",
          "additions": 7,
          "deletions": 0,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 129,
          "url": "https://github.com/kungfu-systems/libnode/pull/129",
          "title": "fix(ci): grant release promotion pull request writes",
          "body": "## Summary\n\n- grant the reusable release-promotion workflow the `pull-requests: write` permission required by the current `buildchain@v2-alpha` contract\n- refresh the exact KFD-1 release-workflow witness\n- retain protected alpha promotion with full native four-platform verification\n\n## Evidence\n\n- release run `30160579028` failed at workflow startup after PR #128 added `actions: write`\n- the current reusable workflow interface also requires `pull-requests: write`\n- `corepack pnpm verify-kfd-witnesses` passes\n- `actionlint .github/workflows/release-new-version.yml` passes",
          "author": "dongkeren",
          "createdAt": "2026-07-25T13:57:06Z",
          "mergedAt": "2026-07-25T15:17:26Z",
          "additions": 3,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1841,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1841",
          "title": "feat: add auditable demo artifact gate",
          "body": "## Summary\n\n- add a consumer-neutral reusable Gate for exact same-run GitHub Artifacts\n- run checked-in adapters with a reduced environment and bind transcript/projection/scene outputs to an immutable, network-disabled renderer smoke\n- expose content-addressed Gate evidence on every invocation and optional full media only from the exact passing Gate\n- publish the workflow, manual, permission classification, release impact, and generated site contract\n\n## Verification\n\n- `pnpm run check`\n- 847/847 unit tests passed\n- workflow static checks and site closed-world registry passed\n- action bundle integrity passed for all 5 bundles\n- `git diff --check`\n\n## Release impact\n\nAdditive minor surface on v2.14; no production publication or deployment authority is introduced.\n\n## Renderer coordinate\n\nQualified alpha image: `ghcr.io/kungfu-systems/build-images/demo-renderer@sha256:cb5e1dec368d21c7d4e8baded99ac75f12f7eff0d19505751888cf974086efa6`",
          "author": "dongkeren",
          "createdAt": "2026-07-25T14:35:51Z",
          "mergedAt": "2026-07-25T15:23:14Z",
          "additions": 2096,
          "deletions": 59,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1843,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1843",
          "title": "fix(promotion): close stable workflow input surface",
          "body": "## Summary\n\n- stop forwarding the alpha-only `github-release-payload-patterns` input to the immutable stable promotion shell\n- stop forwarding the alpha-only `publication-commit-command` input to the immutable stable promotion shell\n- regenerate the channel wrapper and public contract projection\n\n## Failure evidence\n\nlibnode release run `30163318101` failed at workflow startup with GitHub annotations naming both inputs as undefined in the referenced stable workflow. GitHub validates both reusable-workflow jobs even when channel routing later selects alpha.\n\n## Validation\n\n- `node --test tests/promotion-channel-router.test.mjs`\n- `pnpm run check:workflows`\n- `pnpm run check`",
          "author": "dongkeren",
          "createdAt": "2026-07-25T15:29:23Z",
          "mergedAt": "2026-07-25T15:34:49Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1846,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1846",
          "title": "chore(release): reconcile alpha promotion ancestry",
          "body": "Record current `alpha/v2/v2.14` as an ancestor of the reviewed dev head while preserving the dev tree byte-for-byte.\n\nThis follows the established reconciliation pattern in #1836, removes the dev-to-alpha history conflict, and keeps the stable input closure from #1843 unchanged.\n\n- pre-reconciliation dev head: `b34a3f1a40d9a68d014d76dae356621bc1dc2d52`\n- reconciled head: `c7165489`\n- first-parent tree: `941dc2940b345689c87cc69d0a93474261c68bd4`\n- merge tree: `941dc2940b345689c87cc69d0a93474261c68bd4`",
          "author": "dongkeren",
          "createdAt": "2026-07-25T15:41:38Z",
          "mergedAt": "2026-07-25T15:46:56Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1847,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1847",
          "title": "chore(release): reconcile alpha version state into dev",
          "body": "## Summary\\n\\n- reconcile the protected alpha/v2/v2.14 version-state history into protected dev/v2/v2.14\\n- preserve the current alpha version 2.14.19-alpha.1 and regenerate contract projections\\n- retain the auditable demo workflow already merged through protected dev PR #1841\\n- define stable ordering for producer-owned artifact coordinates\\n\\nThis makes the standard dev/v2/v2.14 -> alpha/v2/v2.14 promotion conflict-free without changing branch protection or bypassing independent review.\\n\\n## Verification\\n\\n- pnpm run check (850 tests; 5 action bundles)\\n- protected dev PR #1841 and merge-queue checks passed\\n\\nSigned-off-by: Codex <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-25T15:42:22Z",
          "mergedAt": "2026-07-25T15:48:45Z",
          "additions": 30,
          "deletions": 29,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1842,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1842",
          "title": "feat(release): promote auditable demo pipeline to v2.14 alpha",
          "body": "## Summary\n\nPromote the reviewed auditable demo Gate/render workflow and producer-owned artifact coordinate contract from `dev/v2/v2.14` to `alpha/v2/v2.14`.\n\n## Evidence\n\n- source PR: #1841\n- protected dev merge: `0d48707c03b119e71e2b34cca12ecb2ebd9fd47a`\n- full repository verification: 850 tests passed\n- merge-queue Verify and GitHub Governance Authority Audit passed\n- immutable renderer: `ghcr.io/kungfu-systems/build-images/demo-renderer@sha256:cb5e1dec368d21c7d4e8baded99ac75f12f7eff0d19505751888cf974086efa6`\n\n## Downstream qualification\n\nAfter the protected Alpha publication advances, Kungfu will pin the resulting exact Buildchain runtime SHA and run its exact retained Linux artifact through the required Gate plus selective full render.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T15:24:06Z",
          "mergedAt": "2026-07-25T15:51:57Z",
          "additions": 2102,
          "deletions": 62,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1848,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1848",
          "title": "Prepare v2.14.19-alpha.2",
          "body": "Create the generated version-state commit for v2.14.19-alpha.2.\n\nBuildchain generated this PR because protected branch alpha/v2/v2.14 rejected direct generated bookkeeping.\n\nRejected update: 1af0d85e3b72750f2e38107573d4e16c1dc6fcb5 -> 2f6259760cb6831ad129065d3bb6ccc3a5869939\n\nGitHub response: Repository rule violations found\n\nChanges must be made through a pull request.\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T15:57:37Z",
          "mergedAt": "2026-07-25T16:00:48Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1849,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1849",
          "title": "fix(promotion): complete stable workflow input closure",
          "body": "## Summary\n\n- exclude the remaining alpha-only publication inputs from the immutable stable promotion shell\n- regenerate the channel router and public contract bundle\n- assert the stable route omits both unsupported fields\n\n## Validation\n\n- `node --test --test-name-pattern=\"stable route\" tests/promotion-channel-router.test.mjs`\n- `pnpm run check`\n- `git diff --check`\n\nThis repairs the workflow-validation failure observed when libnode calls `release-candidate-promote.yml@v2-alpha`; no stable workflow or protected release ref is modified directly.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T16:10:13Z",
          "mergedAt": "2026-07-25T16:13:41Z",
          "additions": 8,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1850,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1850",
          "title": "chore(release): reconcile alpha promotion ancestry",
          "body": "## Summary\n\n- record the current alpha version-state merge as dev ancestry\n- preserve the exact current dev tree byte-for-byte\n- unblock the protected dev-to-alpha promotion without content conflict\n\n## Evidence\n\n- first-parent tree: `c783534aacb6757569f8e0fda9bdbd3f27cfc322`\n- merge tree: `c783534aacb6757569f8e0fda9bdbd3f27cfc322`",
          "author": "dongkeren",
          "createdAt": "2026-07-25T16:14:54Z",
          "mergedAt": "2026-07-25T16:18:45Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1851,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1851",
          "title": "fix(promotion): promote complete stable input closure to alpha",
          "body": "## Summary\n\nPromote the fully closed stable workflow input surface from `dev/v2/v2.14` into the protected alpha channel after the ancestry-only reconciliation.\n\nThis carries the two remaining exclusions required by the immutable stable workflow: `publication-commit-evidence-path` and `release-activation-command`.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T16:19:05Z",
          "mergedAt": "2026-07-25T16:20:29Z",
          "additions": 24,
          "deletions": 20,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1487,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1487",
          "title": "refactor(core): compress repeated authority adapters",
          "body": "## Summary\n\nCompress repeated mechanical adapter code while preserving each semantic authority boundary. The branch is rebased onto exact `dev/v4/v4.0` commit `edbc57295368d6bb29c5965dc55479f6251e36b3` and is sealed by the native Assignment closeout at `sha256:e6861ff94810c44cb3543b681c42783d5b448d1b5b4f42d6d7813128627d06e2`.\n\n## Related issue\n\n- Atlas goal: `2026-07-24-kungfu-abstraction-compression`\n\n## Changes\n\n- derive action-runtime dispatch and capabilities from one descriptor table;\n- publish one typed evidence envelope while preserving receipt, witness, claim, and manifest non-substitution;\n- generate Cut/Episode lifecycle matrix rows and SDK projections from authoritative catalogs;\n- converge Node storage/runtime-action paths at the SDK boundary;\n- centralize Rust FFI declarations without changing the public ABI.\n\n## Verification\n\n- `./shifu build:core`\n- `./shifu check:source` (646 tests: 643 passed, 3 skipped) on the rebased semantic series\n- `./shifu check:work-lifecycle-operation-matrix` (15 passed)\n- `./shifu check:primitive-catalog` (21 passed)\n- `./shifu registry:check` (5 passed)\n- `./shifu check:layered-api-encoding-boundary` (9 passed)\n- `node --test scripts/check-evidence-envelope.test.mjs` (4 passed)\n- `node scripts/generate-work-lifecycle-sdk.mjs --check`\n- `cargo fmt --check`; `kungfu-sdk` 3/3; `kungfu-embedding` 3/3\n- native Assignment exact-checkout review verdict: `fit`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f8c53-6105-71e5-8f34-53f2a81ee61c\",\n    \"KF-ADR-019f86da-4f90-732e-826c-e994acc20716\"\n  ],\n  \"summary\": \"Compress repeated runtime, evidence, lifecycle, Node, and Rust adapter shells while preserving their declared authority boundaries.\",\n  \"verification\": [\n    \"current-checkout core build\",\n    \"source acceptance\",\n    \"lifecycle and primitive projection gates\",\n    \"typed evidence envelope tests\",\n    \"native Assignment exact-checkout review\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe generated KFD and release-evidence projections are mechanically refreshed and covered by registry, KFD, lifecycle, and source-acceptance checks; no publication or deployment is performed by this PR.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T15:14:25Z",
          "mergedAt": "2026-07-25T16:22:31Z",
          "additions": 2990,
          "deletions": 416,
          "changedFiles": 59
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1852,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1852",
          "title": "Prepare v2.14.19-alpha.3",
          "body": "Create the generated version-state commit for v2.14.19-alpha.3.\n\nBuildchain generated this PR because protected branch alpha/v2/v2.14 rejected direct generated bookkeeping.\n\nRejected update: 9175e356f54ceece4cacc4a12bfece88b07ef0a7 -> 95bdec323b307fb4a574b9bfd3e40635884ce1ad\n\nGitHub response: Repository rule violations found\n\nChanges must be made through a pull request.\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T16:26:10Z",
          "mergedAt": "2026-07-25T16:27:31Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1853,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1853",
          "title": "fix(promotion): enforce complete stable input closure",
          "body": "## Summary\n\n- derive the complete set of current alpha inputs absent from the immutable stable workflow\n- omit all eleven unsupported inputs from the stable call surface\n- verify every configured unsupported input is absent from the generated stable block\n\n## Validation\n\n- exact current-vs-immutable input set comparison: closed\n- targeted stable-route tests: pass\n- `pnpm run check`: pass\n- `git diff --check`: pass",
          "author": "dongkeren",
          "createdAt": "2026-07-25T16:40:48Z",
          "mergedAt": "2026-07-25T16:44:15Z",
          "additions": 16,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1854,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1854",
          "title": "chore(release): reconcile alpha promotion ancestry",
          "body": "## Summary\n\nRecord the current alpha version-state commit as dev ancestry while preserving the exact dev tree.\n\n- first-parent tree: `e931ae13cad6f33c9d1c307536f1d71199deb9d1`\n- merge tree: `e931ae13cad6f33c9d1c307536f1d71199deb9d1`",
          "author": "dongkeren",
          "createdAt": "2026-07-25T16:45:02Z",
          "mergedAt": "2026-07-25T16:48:36Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1855,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1855",
          "title": "fix(promotion): promote complete stable input closure to alpha",
          "body": "## Summary\n\nPromote the exact, complete 11-field stable input exclusion set to `alpha/v2/v2.14` after tree-preserving ancestry reconciliation.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T16:48:55Z",
          "mergedAt": "2026-07-25T16:50:17Z",
          "additions": 32,
          "deletions": 28,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1856,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1856",
          "title": "Prepare v2.14.19-alpha.4",
          "body": "Create the generated version-state commit for v2.14.19-alpha.4.\n\nBuildchain generated this PR because protected branch alpha/v2/v2.14 rejected direct generated bookkeeping.\n\nRejected update: 668f38f65632de1eee3a0f3e0660eb527365257f -> 66f819a138f79aa02fe3e63380bb909a39748dd1\n\nGitHub response: Repository rule violations found\n\nChanges must be made through a pull request.\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T16:56:19Z",
          "mergedAt": "2026-07-25T16:57:32Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1390,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1390",
          "title": "chore(repo): close legacy orphan audit",
          "body": "## Summary\n\nClose the bounded L1-L5 legacy-orphan audit. The change replaces implicit test\ndiscovery with a fail-closed manifest check, gives every audited loose script\nand test a terminal disposition, retires narrowly verified compatibility\nresidue, and updates the staged Workspace Federation ADR's historical\nfixture-coordinate evidence.\n\n## Related issue\n\nAtlas parent goal `2026-07-24-kungfu-repo-audit-closure` and child goal\n`2026-07-24-kungfu-legacy-orphan-cleanup`.\n\n## Changes\n\n- add `scripts/check-test-manifest.mjs` plus negative tests; the source/staged\n  gate now proves all 257 tracked Node/Python test files are registered\n- wire the audited unexecuted tests and preserve every retained helper through\n  an explicit package, workflow, or source-acceptance route\n- retain and prove `.githooks/pre-commit` -> `scripts/precommit.mjs`; expose\n  documentation material-bundle and Project Cut queue-admission tasks\n- delete only `scripts/prebuild.mjs` and\n  `scripts/capture-gate-controller-measurement.mjs` after proving zero live\n  references and maintained successor paths\n- document explicit retirement conditions for `host-spike` and\n  `libwasm-spike`\n- remove the deprecated C++ lazy-I/O overload after migrating its caller,\n  classify the documentation provider as an explicit compatibility alias, and\n  remove bounded GUI keyword residue\n- preserve the ledger ABI name while adding public `Fact`/`Episode` successor\n  aliases\n- publish Project Cut\n  `sha256:e524e79e396a2c4a5b2f8c3366fcfc8a5b8c8cca6742420ecac349f896077c9d`\n  at exact commit `c5b5d2df4dc0235a691b7a3785fd07d12dd3ac23`\n\n## Deletion evidence\n\n- `scripts/prebuild.mjs`: zero live references; historical automatic repository\n  sync/format behavior is superseded by explicit checked tasks and staged gates\n- `scripts/capture-gate-controller-measurement.mjs`: zero live references;\n  focused gate measurement and receipt recovery are the maintained path\n- deletion is limited to these two individually reviewed files; intentional\n  yijinjing guards and historical ADR evidence remain untouched\n\n## Verification\n\n- `./shifu check:source` at exact implementation head: 646 Node tests total,\n  643 passed and 3 platform skips; Python Phase B 5, agent-work 7, core 42,\n  runtime-upgrade 116; desktop adapter 69; TypeScript, Biome, and clang-format\n  passed\n- `./shifu check:test-manifest`: 257/257 tracked tests registered\n- focused changed-surface verification: 10/10 tests passed\n- `./shifu build:core`: strict current-checkout `pykungfu` binding built\n- final Project Cut staged gate passed before the exact evidence commit\n- native independent completion review\n  `review-b6f089483a6112083fe9cfec` returned `fit` for exact head\n  `c5b5d2df4dc0235a691b7a3785fd07d12dd3ac23`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f8e99-9354-7ab6-a9ba-b166f83f25a3\"],\n  \"summary\": \"Synchronize the staged Workspace Federation ADR with its bounded historical-fixture clarification while closing the repository orphan audit.\",\n  \"verification\": [\"full source acceptance\", \"257-test manifest closure\", \"Workspace Federation qualification references\", \"exact-head Project Cut review\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR publishes a content-addressed Project Cut and wires existing\nrelease/qualification checks; it does not publish a package, deploy a service,\nor broaden a release claim.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-24T02:07:58Z",
          "mergedAt": "2026-07-25T17:42:44Z",
          "additions": 419,
          "deletions": 212,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1491,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1491",
          "title": "feat(ci): add auditable demo artifact pipeline",
          "body": "## Summary\n\nAdd an auditable, content-addressed demo evidence lane for exact Kungfu Linux build artifacts. Every eligible artifact runs the Buildchain Gate; full media rendering is selective and produces bounded GitHub Artifacts plus a Release Passport without deployment authority.\n\nThis linear reconciliation supersedes #1489 after GitHub merge queue rejected that otherwise green candidate twice as `invalid_merge_commit` because of its nested synchronization history. The content delta is the same feature plus the independently verified SDK expectation correction.\n\n## Changes\n\n- resolve exact Buildchain artifact coordinates and fail closed on source, digest, name, or expiry drift\n- call the immutable Buildchain reusable workflow and renderer digest\n- execute the installed `kungfu agent brief` surface in an isolated disposable environment\n- emit deterministic transcript, projection, scene, Gate, media, and Release Passport artifacts\n- add README projection tooling and qualification documentation with explicit claims and non-claims\n- close the workflow authority registry over the new jobs\n- derive SDK KFD expectations from their owning Buildchain/projection authorities\n\n## Verification\n\n- `./shifu check` passed on the reconciled content before linearization\n- `./shifu check:source` (630 tests: 620 passed, 10 intentional skips)\n- `./shifu pnpm run test:auditable-demo` (15 passed)\n- `./shifu pnpm --filter @kungfu-tech/sdk run build` (32 passed)\n- `actionlint -color .github/workflows/build.yml`\n- `./shifu docs:check:readonly` (383 Markdown files; 103 tests)\n- `./shifu check:gate-catalog` (38 gates, 6 profiles, 25 structured invocations, 18 workflows)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-786d-aa24-a97705e13917\"],\n  \"summary\": \"Qualify the exact installed agent brief from built product bytes through content-addressed Gate, media, and Release Passport evidence\",\n  \"verification\": [\"exact artifact coordinate and source binding\", \"installed agent brief isolated execution\", \"content-addressed Gate and media artifacts\", \"Release Passport verification\", \"workflow authority and documentation gates\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe workflow only reads exact build artifacts and writes retained GitHub Artifacts. It has no package publication, deployment, environment, secret, or identity-token authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-25T17:47:25Z",
          "mergedAt": "2026-07-25T18:12:19Z",
          "additions": 2025,
          "deletions": 33,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1492,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1492",
          "title": "fix(release): compact Linux platform package payload",
          "body": "## Summary\n\nKeep the new Core platform-package 100 MiB hard ceiling by removing projection-only duplication and unneeded Linux Release symbols found by the first exact distribution measurement.\n\n## Changes\n\n- materialize the declared `python3` entrypoint but omit its duplicate `python3.13` payload copy from the npm projection\n- strip only an explicit set of Kungfu-owned Linux Release `.so`, `.node`, and helper executables\n- exclude embedded Python extensions and the pinned upstream libnode binary from this stripping step\n- keep the 100/85/70 MiB hard, normal, and optimization bands unchanged\n- record exact source run `30169439213` and retained-package inspection in the owning ADR\n\n## Verification\n\n- `node --test framework/core/tests/core-platform-package.test.js` (7 passed)\n- pre-commit repository gates, including docs, invariant, KFD, Gate catalog, and latency suites\n- exact Actions measurement: 123,472,874 bytes in run `30169439213`\n- retained diagnostic rebuild: 123,541,699 bytes before compaction; member inspection found the duplicated 31.5 MB interpreter and unstripped declared native payloads\n- temporary-copy probes showed about 18.7 MB compressed savings before the smaller helper/libwasm savings, while leaving source outputs unchanged\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7e5e-ae22-2a8fc24086f1\"],\n  \"summary\": \"Keep the Core platform package budget by removing projection-only interpreter duplication and unneeded Linux Release symbols\",\n  \"verification\": [\"exact Actions byte measurement\", \"retained tar member inspection\", \"explicit Linux strip candidate test\", \"prohibited payload rejection remains enforced\", \"repository pre-commit gates\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis compacts only a temporary npm package projection. It does not mutate source build outputs or grant publication/deployment authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T18:39:42Z",
          "mergedAt": "2026-07-25T19:31:33Z",
          "additions": 120,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 132,
          "url": "https://github.com/kungfu-systems/libnode/pull/132",
          "title": "chore(governance): transfer protected topology baton",
          "body": "## Summary\n\n- add a tree-equivalent, signed-off governance commit\n- transfer the latest protected push away from the CODEOWNER identity\n- unblock the independently reviewed alpha-to-dev topology reconciliation without administrator bypass\n\n## Validation\n\n- no source tree changes\n- commit DCO sign-off enforced locally\n- protected Alpha build remains required\n\nThis PR deliberately changes ancestry only; its tree is byte-identical to the current Alpha head.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T18:35:40Z",
          "mergedAt": "2026-07-25T19:57:24Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1488,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1488",
          "title": "feat(work): converge mutation authority and live global view",
          "body": "## Summary\n\nConverge Kungfu Work on one mutation authority and make the desktop Work view automatically observe every active local workspace.\n\n## Changes\n\n- retire the parallel Assignment and WorkStore mutation paths in favor of the canonical `kungfu work` lifecycle\n- federate Home and active Project Work into one rooted global projection\n- move observation into one app-lifetime main-process observer with durable Fact cursors and cached component recomposition\n- push typed snapshots to the dashboard without renderer polling, filesystem access, or manual refresh\n- recover from catalog cuts and changelog gaps while keeping normal workspace-local propagation bounded\n\n## Verification\n\n- `./shifu check:source`\n- 39 workspace federation Python tests\n- 29 Work Dashboard tests\n- 2 Electron observer host tests\n- GUI production build and changed-file TypeScript/Biome checks\n- live 42-workspace source dogfood: 1.22-1.24s incremental propagation, 3.60-3.83s recovery, 0ms cache resume\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f8759-ab29-7627-bc04-6aba547ea45f\",\n    \"KF-ADR-019f87e8-6b8b-735c-b036-fa42d7cee8cf\",\n    \"KF-ADR-019f8c53-6105-71e5-8f34-53f2a81ee61c\"\n  ],\n  \"summary\": \"Converge Work mutation authority and deliver the automatically live global desktop projection\",\n  \"verification\": [\n    \"build-free source gate\",\n    \"workspace federation and observer tests\",\n    \"desktop and dashboard tests\",\n    \"live multi-workspace latency dogfood\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T16:14:22Z",
          "mergedAt": "2026-07-25T20:13:28Z",
          "additions": 9268,
          "deletions": 20818,
          "changedFiles": 150
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1494,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1494",
          "title": "feat(evidence): bind demo artifacts to retained expiry",
          "body": "## Summary\n\nClose the auditable demo Release Passport over the exact retention window of every source, Gate, and media artifact, then route README readers to the dedicated evidence page.\n\nThis linear reconciliation supersedes #1493 after #1488 changed shared generated KFD evidence while #1493 was queued.\n\n## Changes\n\n- query only artifacts retained by the current workflow run with read-only Actions authority\n- require exact id, name, digest, live expiry, and same-run membership for Gate and optional media outputs\n- canonicalize each artifact expiry into the content-addressed Release Passport\n- refresh the governed workflow authority projection for the added pinned action\n- route the generated README proof link to `/how-tested/auditable-demo/`\n\n## Verification\n\n- `./shifu pnpm run test:auditable-demo` (16 passed)\n- Gate catalog check\n- KFD evidence check on the latest protected base\n- full pre-commit repository gates before ready-for-review\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-786d-aa24-a97705e13917\"],\n  \"summary\": \"Bind every auditable demo artifact coordinate to its exact same-run retention expiry\",\n  \"verification\": [\"current-run artifact lookup\", \"exact name and digest comparison\", \"live expiry validation\", \"canonical Passport root\", \"workflow authority gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe added job permission is read-only `actions: read`; it grants no package publication, deployment, environment, secret, or identity-token authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation projection refreshed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T20:17:36Z",
          "mergedAt": "2026-07-25T20:40:08Z",
          "additions": 145,
          "deletions": 32,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1496,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1496",
          "title": "fix(gui): keep global Work observer app-scoped",
          "body": "## Summary\n\nKeep the installed global Work observer truly app-scoped after live dogfood exposed renderer subscription churn and orphaned recovery workers.\n\n## Changes\n\n- retain the single main-process observer when the renderer view unsubscribes or remounts\n- keep the latest shell notification target in a ref so renderer re-renders do not restart observation\n- handle `SIGTERM` in the observer CLI and let an active ProcessPool close before exit\n- prove unsubscribe/resubscribe reuses one child and app disposal performs the one shutdown\n\n## Verification\n\n- `./shifu test:work-authority`\n- 39 workspace federation Python tests\n- 3 main-process and renderer observer tests\n- GUI production build\n- KFD buildchain check\n- live SIGTERM during an active recovery ProcessPool: exit 0, orphaned children 0\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fix renderer subscription churn and graceful observer shutdown without changing the accepted Work authority or federation contracts\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T20:32:14Z",
          "mergedAt": "2026-07-25T20:43:00Z",
          "additions": 22,
          "deletions": 8,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1497,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1497",
          "title": "fix(product): use canonical work CLI in installed smoke",
          "body": "## Summary\n\nRepair the installed product admission smoke after the canonical CLI route moved from `kungfu assignment` to `kungfu work`.\n\n## Root cause\n\nThe protected product build for auditable demo run 30174217514 passed the unchanged 100 MiB package ceiling at 103,388,024 compressed bytes, then failed because the installed archive smoke still invoked the retired `assignment` route. The native CLI has exposed the same authority under `work` since f83febb30f70f34f461085ec60bf6f53ac05007c.\n\n## Changes\n\n- invoke `work capture` and `work admit` in the installed archive smoke\n- assert both exact canonical route prefixes in the unit test\n- keep Workspace Catalog isolation and admission receipt checks unchanged\n\n## Verification\n\n- `./shifu node --test product/scripts/dist.test.mjs` (23 passed)\n- targeted Biome check\n- full pre-commit repository gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair a stale installed-product smoke invocation after the already-governed canonical CLI route moved from assignment to work; no contract or ADR projection changes\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes only a build-time installed-archive qualification invocation. It adds no publication, deployment, package write, secret, or identity-token authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Exact failed build evidence cited\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T21:02:10Z",
          "mergedAt": "2026-07-25T21:11:40Z",
          "additions": 11,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 133,
          "url": "https://github.com/kungfu-systems/libnode/pull/133",
          "title": "chore(governance): retain protected topology baton",
          "body": "## Summary\n\n- retain a tree-equivalent, signed-off governance commit after GitHub rebase correctly elided the first empty baton\n- merge this PR with the normal merge strategy so Alpha receives a real two-parent ancestry node pushed by `dongkeren`\n- preserve byte-identical source while satisfying CODEOWNER/latest-push separation for PR #131\n\n## Validation\n\n- zero changed files\n- DCO sign-off enforced locally\n- protected Alpha build required\n- no administrator bypass and no branch-protection changes",
          "author": "dongkeren",
          "createdAt": "2026-07-25T19:58:17Z",
          "mergedAt": "2026-07-25T21:27:42Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1498,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1498",
          "title": "fix(workspace): keep repeated catalog observations stable",
          "body": "## Summary\n\nKeep the app-scoped global Work observer incremental across separate semantic writes by making repeated observation of an unchanged Workspace locator write-free.\n\n## Changes\n\n- preserve the existing Catalog entry, epoch, bytes, and cut when a qualified locator is semantically unchanged\n- continue updating the Catalog when identity, locator, availability, or candidate replacement actually changes\n- avoid persisting read-only Catalog projection fields during real updates\n- prove repeated observation does not reorder entries or mutate Catalog bytes\n\n## Verification\n\n- ./shifu check:source\n- ./shifu test:workspace-continuation with the exact 700b1214a5 native artifact: Node 8/8, Python 76/76\n- staged commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fix repeated locator observation churn without changing Workspace identity, Catalog lifecycle, or global Work federation semantics\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-25T21:06:36Z",
          "mergedAt": "2026-07-25T21:36:20Z",
          "additions": 96,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1500,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1500",
          "title": "fix(agent-hub): scope embedded Node entry",
          "body": "## Summary\n\nBind the private embedded-Node variant to the exact KFD script entry so Agent Hub qualification can launch the installed Kungfu product as its public adapter without leaking Node routing into that child process.\n\n## Root cause\n\nAuditable-demo build run 30175240748 reached the installed `kungfu agent hub qualify` smoke. The qualification correctly launched the KFD runner through the Python-free `KUNGFU_AS_VARIANT=node` path, but that marker was inherited when the runner spawned the packaged Kungfu front door as `kungfu agent hub adapter`. The Rust trunk then treated the first public argument `agent` as a Node module path and failed with `Cannot find module .../agent`.\n\n## Changes\n\n- bind internal Node dispatch to the exact KFD runner or verifier argv entry\n- preserve unscoped Node-variant behavior for existing callers\n- clear the private marker when a scoped Node process starts a different child entry, restoring normal public CLI routing\n- test exact-entry admission, mismatch rejection/cleanup, full Rust workspace behavior, and the Python qualification boundary\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python uv run --project framework/core --frozen pytest -q framework/core/tests/python/test_agent_hub_profile.py` (8 passed)\n- `./shifu node --test product/scripts/dist.test.mjs` (23 passed)\n- `cargo test --manifest-path crates/trunk/Cargo.toml variant::tests::dispatch_falls_through_except_for_ownable_variants`\n- full pre-commit repository gate, including `cargo clippy --workspace --all-targets -- -D warnings` and `cargo test --workspace`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair environment isolation at an existing installed-product qualification subprocess boundary; no contract, authority, or ADR projection changes\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes only internal dispatch scope for a build-time installed-archive qualification subprocess. It adds no publication, deployment, package write, secret, or identity-token authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Exact failed build evidence cited",
          "author": "dongkeren",
          "createdAt": "2026-07-25T21:41:13Z",
          "mergedAt": "2026-07-25T22:09:13Z",
          "additions": 51,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1501,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1501",
          "title": "fix(gui): keep installed bundle immutable",
          "body": "## Summary\n\nKeep the installed Developer ID-signed app bundle immutable while its global Work observer runs.\n\n## Changes\n\n- force the observer child process to disable Python bytecode writes\n- preserve all inherited observer environment values\n- prove a conflicting caller value is overridden and unrelated values survive\n\n## Verification\n\n- framework/gui/node_modules/.bin/tsx --test framework/gui/src/main/global-work-observer-host.test.ts (2/2)\n- ./shifu check:source\n- staged commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Prevent runtime cache files from mutating the signed desktop bundle without changing Work observer semantics\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-25T22:03:25Z",
          "mergedAt": "2026-07-25T22:12:15Z",
          "additions": 13,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1502,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1502",
          "title": "fix(gui): protect packaged Python resources",
          "body": "## Summary\n\nSet Python bytecode suppression at the packaged desktop entry before any child process can touch signed bundle resources.\n\n## Changes\n\n- protect the packaged desktop environment before main-process startup work\n- preserve development behavior while retaining the observer-level defense\n- cover packaged override, existing environment preservation, and development behavior\n\n## Verification\n\n- targeted desktop test: 3/3 passed\n- `./shifu check:source` passed\n- startup-level experiment kept strict deep codesign valid after the live observer started\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Keep packaged desktop resources immutable across all Python child launches without changing Work authority or observer semantics\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-25T22:27:42Z",
          "mergedAt": "2026-07-25T22:34:10Z",
          "additions": 24,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1503,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1503",
          "title": "fix(cli): bind help to governed catalog",
          "body": "## Summary\n\nBind installed human help to the same governed, content-addressed CLI catalog exposed through Agent capabilities, closing the product-only root drift that blocked the auditable-demo build.\n\n## Root cause\n\nAuditable-demo build run 30177108755 assembled the exact CLI archive, then failed the installed product qualification with `human help roots do not match the Agent catalog`. Human help refolded the live Click tree inside the installed archive while Agent capabilities consumed the source-accepted governed catalog, leaving two runtime projections for the same roots.\n\n## Changes\n\n- make progressive help consume the governed Agent CLI catalog by default\n- preserve explicit contract injection for isolated projection tests\n- add a regression proving default human help binds the catalog contract and registry roots\n- keep the installed qualification fail-closed; no check is relaxed or skipped\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python uv run --project framework/core --frozen pytest -q framework/core/tests/python/test_cli_progressive_help.py` (4 passed, 2 native-only skipped)\n- `node --test product/scripts/cli-surface-qualification.test.mjs` (4 passed)\n- `node scripts/check-cli-catalog-parity.mjs`\n- `uv run --project framework/core --frozen ruff format --check framework/core/src/python/kungfu/cli/help_projection.py framework/core/tests/python/test_cli_progressive_help.py`\n- actual pre-commit staged repository gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair an existing installed-product parity invariant by selecting its already governed catalog as the single projection source; no public CLI or authority contract changes\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes only the source used by an existing offline installed-product help projection. It adds no deployment, publication write, secret, or identity-token authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Exact failed build evidence cited",
          "author": "dongkeren",
          "createdAt": "2026-07-25T22:35:22Z",
          "mergedAt": "2026-07-25T23:03:52Z",
          "additions": 15,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1862,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1862",
          "title": "fix(release): converge v3 publication authority",
          "body": "## Summary\n\n- restore v3 self-dogfood startup by propagating the reusable workflow `actions: read` permission\n- forward the remaining v2.14 semantic contracts: credential-island diagnostics and dirname compatibility, installer publication sealing, release activation receipts, opaque protected-channel fallback, auditable demo Gate, and producer-owned artifact coordinates\n- retain the v3-native stable input closure instead of copying the v2 frozen-shell compatibility list\n- declare v3 as the sole shared npm `alpha` authority; paired v2 closure: #1861\n- regenerate public site facts and embedded action bundles\n- replaces fork-context PR #1860 so protected CI can run in the upstream trust boundary\n\n## Validation\n\n- `pnpm run generate:site && pnpm run build && pnpm run check`\n- 851 tests passed, 0 failed\n- workflow/actionlint checks passed\n- site bundle check passed\n- 5 action bundle integrity checks passed\n- `git diff --check`\n\n## Risk\n\nThe authority change is fail-closed and does not mutate npm dist-tags during this PR. The self-dogfood startup repair still requires a live post-merge workflow run to prove GitHub graph admission.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T23:41:04Z",
          "mergedAt": "2026-07-25T23:44:36Z",
          "additions": 4002,
          "deletions": 339,
          "changedFiles": 60
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1860,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1860",
          "title": "fix(release): converge v3 publication authority",
          "body": "## Summary\n\n- restore v3 self-dogfood startup by propagating the reusable workflow `actions: read` permission\n- forward the remaining v2.14 semantic contracts: credential-island diagnostics and dirname compatibility, installer publication sealing, release activation receipts, opaque protected-channel fallback, auditable demo Gate, and producer-owned artifact coordinates\n- retain the v3-native stable input closure instead of copying the v2 frozen-shell compatibility list\n- declare v3 as the sole shared npm `alpha` authority; paired v2 closure: #1859\n- regenerate public site facts and embedded action bundles\n\n## Validation\n\n- `pnpm run generate:site && pnpm run build && pnpm run check`\n- 851 tests passed, 0 failed\n- workflow/actionlint checks passed\n- site bundle check passed\n- 5 action bundle integrity checks passed\n- `git diff --check`\n\n## Risk\n\nThe authority change is fail-closed and does not mutate npm dist-tags during this PR. The self-dogfood startup repair still requires a live post-merge workflow run to prove GitHub graph admission.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T23:26:06Z",
          "mergedAt": "2026-07-25T23:44:38Z",
          "additions": 4002,
          "deletions": 339,
          "changedFiles": 60
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1861,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1861",
          "title": "fix(release): close v2 shared alpha authority",
          "body": "## Summary\n\n- declare Buildchain v3 as the sole writer of the shared npm `alpha` dist-tag\n- route v2.14 alpha publication to the line-specific `v2.14-alpha` tag\n- fail closed when a non-authority major explicitly requests the shared `alpha` tag\n- regenerate every action bundle that embeds the publication contract\n- replaces fork-context PR #1859 so protected CI can run in the upstream trust boundary\n\n## Validation\n\n- `pnpm run build && pnpm run check` (851 tests passed before the ancestry-only base refresh)\n- `node --test tests/buildchain-config.test.mjs tests/promote-buildchain-ref.test.mjs` (174 tests passed after rebasing onto current `dev/v2/v2.14`)\n- `node scripts/check-action-bundles.mjs` (5 bundles passed)\n- `git diff --check`\n\n## Risk\n\nThis changes only future v2 alpha routing. It does not mutate npm dist-tags during the PR and preserves v2.14 publication through `v2.14-alpha`.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T23:40:56Z",
          "mergedAt": "2026-07-25T23:46:29Z",
          "additions": 192,
          "deletions": 110,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1859,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1859",
          "title": "fix(release): close v2 shared alpha authority",
          "body": "## Summary\n\n- declare Buildchain v3 as the sole writer of the shared npm `alpha` dist-tag\n- route v2.14 alpha publication to the line-specific `v2.14-alpha` tag\n- fail closed when a non-authority major explicitly requests the shared `alpha` tag\n- regenerate every action bundle that embeds the publication contract\n\n## Validation\n\n- `pnpm run build && pnpm run check` (851 tests passed before the ancestry-only base refresh)\n- `node --test tests/buildchain-config.test.mjs tests/promote-buildchain-ref.test.mjs` (174 tests passed after rebasing onto current `dev/v2/v2.14`)\n- `node scripts/check-action-bundles.mjs` (5 bundles passed)\n- `git diff --check`\n\n## Risk\n\nThis changes only future v2 alpha routing. It does not mutate npm dist-tags during the PR and preserves v2.14 publication through `v2.14-alpha`.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T23:25:52Z",
          "mergedAt": "2026-07-25T23:46:30Z",
          "additions": 192,
          "deletions": 110,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1504,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1504",
          "title": "fix(cli): admit qualified catalog diagnostics",
          "body": "## Summary\n\nAllow progressive help to consume the source-accepted governed CLI catalog, whose stable projection intentionally omits transient fold diagnostics, while keeping every non-catalog contract fail-closed.\n\n## Root cause\n\nAuditable-demo build run 30178806617 reached assembled help-manifest generation and failed with `surface contract diagnostics failed`. PR #1503 correctly selected the governed catalog as the shared Human/Agent projection, but the builder still treated the catalog schema as an unqualified live fold because the stable catalog has no `diagnostics` field.\n\n## Changes\n\n- accept missing transient diagnostics only for exact schema `kungfu.cli-surface-catalog/v1`\n- preserve explicit diagnostic failure behavior\n- reject every non-catalog contract that omits diagnostics\n- update the governed-catalog regression to match the actual packaged catalog shape\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python uv run --project framework/core --frozen pytest -q framework/core/tests/python/test_cli_progressive_help.py` (5 passed, 2 native-only skipped)\n- `node --test product/scripts/cli-surface-qualification.test.mjs` (4 passed)\n- `node scripts/check-cli-catalog-parity.mjs`\n- `uv run --project framework/core --frozen ruff format --check framework/core/src/python/kungfu/cli/help_projection.py framework/core/tests/python/test_cli_progressive_help.py`\n- actual pre-commit staged repository gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Complete the existing Human and Agent catalog parity repair by recognizing the already qualified stable catalog schema; no public CLI or authority contract changes\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis narrows one existing offline build-time schema distinction. It adds no publication, deployment, secret, or identity-token authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Exact failed build evidence cited",
          "author": "dongkeren",
          "createdAt": "2026-07-25T23:20:44Z",
          "mergedAt": "2026-07-25T23:48:41Z",
          "additions": 18,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1865,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1865",
          "title": "docs(versioning): link v3 authority convergence",
          "body": "## Summary\n\n- link the v3.0 authority-convergence decision-log entry to its merged source PR\n- land this documentation-only follow-up through the newly reconciled v3 dev merge queue\n\n## Validation\n\n- `git diff --check`\n- canonical Buildchain worktree and commit-identity guards\n\nThis PR intentionally makes no runtime or governance-code changes.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T00:01:45Z",
          "mergedAt": "2026-07-26T00:08:35Z",
          "additions": 13,
          "deletions": 13,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1864,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1864",
          "title": "chore(release): promote v3 authority convergence to alpha",
          "body": "## Promotion intent\n\nPromote the reviewed Buildchain v3 authority-convergence change through the canonical protected channel path.\n\n- reviewed source PR: #1862\n- reviewed source commit: `72cf6180776dcef1f6fcec4937effe0126931460`\n- merged dev commit: `8fe3464838cd602d1e98b46ca537b32b5507a53f`\n- validation train: `train/v3/v3.0/authority-convergence` at `72cf6180776dcef1f6fcec4937effe0126931460`\n- source channel: `dev/v3/v3.0`\n- target channel: `alpha/v3/v3.0`\n- paired v2 shared-alpha closure: #1861\n\n## Evidence\n\n- repository checks: 851 passed, 0 failed\n- same-repository protected Verify, governance audit, and Build Surface Fixture passed\n- Linux, macOS, and Windows fixture jobs passed\n- producer-owned artifact coordinates and controller receipts were generated successfully\n- the canonical channel PR lets Release - Verify bind the exact dev/alpha lineage before promotion\n\nThe protected alpha merge and automatic Buildchain Ref Promotion remain authoritative for tag movement, npm trusted publishing, release evidence, and v3-alpha self-dogfood.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T23:50:46Z",
          "mergedAt": "2026-07-26T00:11:48Z",
          "additions": 4681,
          "deletions": 422,
          "changedFiles": 63
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1866,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1866",
          "title": "Prepare v3.0.1-alpha.1",
          "body": "Create the generated version-state commit for v3.0.1-alpha.1.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: a0cda81b67a212b3555e10d041c8d39b4c1b8dce -> de7b691ccbc1a0380b4fadcdfe37cc4125b74caf\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T00:15:55Z",
          "mergedAt": "2026-07-26T00:19:00Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1505,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1505",
          "title": "fix(spec): preserve executable bin source mode",
          "body": "## Summary\n\nTrack the declared `@kungfu-tech/spec` CLI entry as executable so the package-manager install lifecycle cannot dirty an otherwise exact release source.\n\n## Root cause\n\nAuditable-demo build run 30180137847 completed the Linux build and 71/72 release checks, but Episode qualification correctly rejected its Trust Report because installation changed `framework/spec/bin/kungfu-spec.js` from Git mode 0644 to 0755. The file is the declared `kungfu-spec` package bin and already carries a Node shebang, so the source mode was inconsistent with its package contract.\n\n## Changes\n\n- record `framework/spec/bin/kungfu-spec.js` as mode 0755\n- make the install lifecycle idempotent with respect to the checked-out source tree\n- preserve the clean-source Trust Report boundary instead of weakening or ignoring it\n\n## Verification\n\n- `./shifu install` after staging the executable mode; no unstaged source drift\n- `pnpm --filter @kungfu-tech/spec verify` (6 tests passed; exact authority bundle verified)\n- `./framework/spec/bin/kungfu-spec.js authority`\n- `./framework/spec/bin/kungfu-spec.js authority-verify`\n- actual pre-commit staged repository gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Align an existing declared package-bin source mode with its install-time executable contract; no public behavior or authority model changes\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis repairs source reproducibility only. It adds no publication, deployment, secret, or identity-token authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Exact failed build evidence cited",
          "author": "dongkeren",
          "createdAt": "2026-07-26T00:12:04Z",
          "mergedAt": "2026-07-26T00:21:34Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1867,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1867",
          "title": "fix(self-dogfood): bind stable v3 contract lock",
          "body": "## Summary\n- regenerate the stable Buildchain contract lock from the live `v3` contract\n- keep stable and alpha self-dogfood consumers in the same v3 compatibility world\n- add a regression assertion preventing the stable consumer from falling back to a v2 lock\n\n## Verification\n- `node --test tests/build-surface.test.mjs` (86/86)\n- `node --test tests/buildchain-contract.test.mjs tests/buildchain-channel-router.test.mjs` (19/19)\n- exact live `v3` contract lock evaluation: unchanged and compatible\n- `git diff --check`\n\nThis closes the second-layer runtime failure exposed after the v3 self-dogfood startup permission fix.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T00:31:25Z",
          "mergedAt": "2026-07-26T00:37:12Z",
          "additions": 24,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1868,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1868",
          "title": "fix(runtime): fall back to trusted artifact binder",
          "body": "## Summary\n- keep the aggregate job bound to the selected stable runtime for existing behavior\n- checkout the exact trusted workflow-shell SHA for additive aggregate helpers\n- fall back to the workflow-shell artifact coordinate binder when the stable runtime predates it\n- scope regression assertions to the summarize job\n\n## Live failure addressed\nBuildchain Alpha Self-Dogfood run 30181476377 proved both alpha and stable builds, but stable aggregation failed because `v3` lacks `scripts/resolve-artifact-coordinates.mjs` while the `v3-alpha` workflow shell requires the additive producer-coordinate surface.\n\n## Verification\n- `node --test tests/build-surface.test.mjs` (86/86)\n- `node --test tests/resolve-artifact-coordinates.test.mjs` (3/3)\n- focused reusable-build workflow contract test\n- `bash scripts/check-workflows.sh`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-26T00:47:41Z",
          "mergedAt": "2026-07-26T00:55:16Z",
          "additions": 48,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1871,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1871",
          "title": "chore(release): sync v3 alpha version state to dev",
          "body": "## Why\nThe first v3 alpha publication created protected alpha-only version-state commits. Without back-syncing that immutable published state, the next canonical `dev/v3/v3.0 -> alpha/v3/v3.0` promotion is structurally conflicted.\n\n## What\n- merge the current alpha lineage and current protected dev lineage\n- retain published `3.0.1-alpha.1` version state\n- include the already-queued stable lock and workflow-shell compatibility fixes\n- regenerate the combined contract bundle\n\n## Verification\n- merged tree build-surface 86/86\n- focused contract/channel/artifact-coordinate 22/22\n- inventory, site bundle, actionlint and diff checks\n\nAfter this dev queue merge, the canonical dev-to-alpha promotion can proceed under the existing release policy.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T01:06:44Z",
          "mergedAt": "2026-07-26T01:12:10Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1872,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1872",
          "title": "chore(release): promote v3 runtime compatibility to alpha",
          "body": "## Promotion scope\n- advance the protected v3 dev lineage into alpha after version-state ancestry convergence\n- publish the stable contract-lock correction and trusted workflow-shell artifact binder fallback\n- preserve stable `v3` while advancing only the v3 alpha channel\n\n## Evidence\n- #1867, #1868, and #1871 merged through the v3 merge queue\n- each merge-group Verify and Governance passed\n- merged tree build-surface 86/86; focused contract/channel/artifact-coordinate 22/22\n- inventory, site, actionlint and diff checks passed\n- live run 30181476377 proved alpha success and isolated the exact stable-runtime helper gap now fixed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T01:12:34Z",
          "mergedAt": "2026-07-26T01:15:55Z",
          "additions": 72,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1506,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1506",
          "title": "fix(ci): keep manual artifacts on GitHub",
          "body": "## Summary\n\nKeep trusted manual evidence builds on direct GitHub Actions Artifact transfer while preserving the existing S3 transit mode for protected Alpha and Release pull-request promotion.\n\n## Safety trigger\n\nManual auditable-demo run 30181124335 reached `Upload payload to S3 artifact relay`. This task has no separate AWS/NAS relay authority, so the run was cancelled before a relay manifest or GitHub payload artifact was emitted. A manual diagnostic/render run does not need the protected promotion transit path.\n\n## Changes\n\n- select `github-artifacts` for every `workflow_dispatch` build\n- retain `s3-to-github-artifacts` for pull-request promotion events\n- bind the exact expression into the governed workflow controller contract\n- refresh the generated workflow authority digest\n- add an explicit regression assertion for the manual safety boundary\n\n## Verification\n\n- `node --test scripts/auditable-demo-workflow.test.mjs` (4 passed)\n- `node scripts/kungfu-workflow-authority.mjs --check`\n- `node scripts/check-kungfu-gate-catalog.mjs`\n- actual pre-commit staged repository gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Route manual evidence artifacts through the already supported direct GitHub transfer mode while preserving the governed protected-promotion path; no public product or authority model changes\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis narrows manual-run side effects. It adds no publication, deployment, secret, or identity-token authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Exact cancelled run evidence cited",
          "author": "dongkeren",
          "createdAt": "2026-07-26T00:58:31Z",
          "mergedAt": "2026-07-26T01:19:08Z",
          "additions": 8,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1873,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1873",
          "title": "Prepare v3.0.1-alpha.2",
          "body": "Create the generated version-state commit for v3.0.1-alpha.2.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: 563a000b882460cdc7f632cb3d2c4f415e7119a2 -> 658f93fa8667a47555246c016cf0b5ec0f5ec53d\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T01:20:43Z",
          "mergedAt": "2026-07-26T01:23:54Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1874,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1874",
          "title": "fix(governance): isolate dev queue authority token",
          "body": "## Summary\n\n- use a dedicated governance credential island for dev merge-queue reconciliation\n- retain the promotion token and workflow token only as migration fallbacks\n- contract-test the credential precedence\n\n## Verification\n\n- `pnpm exec node --test tests/build-surface.test.mjs` (86/86)\n- `pnpm exec actionlint .github/workflows/dev-merge-queue-governance.yml`\n- `git diff --check`\n\nThe repository secret `BUILDCHAIN_GOVERNANCE_TOKEN` is configured from the protected `kungfu-origin` administration identity; its value was never printed or persisted in the worktree.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T01:22:44Z",
          "mergedAt": "2026-07-26T01:28:47Z",
          "additions": 5,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1464,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1464",
          "title": "fix(release): qualify the installed runtime cross-platform",
          "body": "## Summary\n\nRepair the exact Alpha publication failures observed on Linux and Windows without weakening release qualification.\n\n## Related evidence\n\nAlpha Build run 30138755620 attempt 2 proved two independent failures: Linux regenerated a tracked binding stub, and Windows passed the public `.cmd` launcher to the KFD runner, which cannot spawn command scripts directly.\n\n## Changes\n\n- prefer the installed manifest runtime executable for KFD Agent Hub qualification\n- retain the public launcher as a legacy manifest fallback\n- cover both manifest forms with regression tests\n- commit the idempotently regenerated Python binding stub\n\n## Verification\n\n- `./shifu build:core`\n- stub regeneration SHA-256 remained `a33ecb906d1bdbc9c314569d405ffb0bc16ac097ae82f150eaa8f90bacffc080`\n- `./shifu test:kfd-agent-hub-20`: Node 5 passed; Python 9 passed\n- `./shifu check:source`: 600 passed, 10 skipped; Assignment 42; runtime upgrade 116; desktop update 69; mypy 192 files\n- staged pre-commit gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix restores the already-declared cross-platform installed-product qualification semantics and refreshes the generated binding projection.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change preserves fail-closed manifest resolution and exact tracked-stub cleanliness.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Generated stub is idempotent",
          "author": "dongkeren",
          "createdAt": "2026-07-25T02:49:52Z",
          "mergedAt": "2026-07-26T02:35:17Z",
          "additions": 34,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1507,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1507",
          "title": "fix(ci): normalize artifact expiry precision",
          "body": "## Summary\n\nNormalize producer and GitHub artifact expiry timestamps before equality comparison while preserving the exact producer-owned downstream coordinate.\n\n## Root cause\n\nExact-source run 30182763118 produced matching artifact id, name, digest, URL, and expiry instant, but the producer coordinate used `.000Z` while the GitHub API returned `Z`. Raw string equality rejected that semantically identical RFC3339 timestamp.\n\n## Changes\n\n- parse both expiry representations and compare their canonical UTC instants\n- keep id, name, digest, source, run, and URL matching unchanged\n- preserve the producer-owned expiry representation in downstream outputs\n- add executable regression coverage for precision normalization and a real one-second drift\n- refresh the closed-world workflow authority digest\n\n## Verification\n\n- `./shifu test:auditable-demo` (17 passed)\n- `./shifu check:staged` (passed)\n- `node scripts/check-kungfu-gate-catalog.mjs` (passed)\n- failed exact-source probe: https://github.com/kungfu-systems/kungfu/actions/runs/30182763118/job/89747271425\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Normalize two equivalent RFC3339 expiry representations at an existing exact artifact-coordinate boundary; no public behavior or authority model changes\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis preserves fail-closed coordinate binding and adds no publication, deployment, secret, or identity-token authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Exact failed run evidence cited",
          "author": "dongkeren",
          "createdAt": "2026-07-26T02:41:42Z",
          "mergedAt": "2026-07-26T03:08:32Z",
          "additions": 102,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1509,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1509",
          "title": "docs(readme): map the open Kungfu system",
          "body": "## Summary\n\nMake the root README an explicit source map for Kungfu as an open system, so readers arriving through the product repository can discover the protocol, release infrastructure, build environments, public sites, and the complete organization.\n\n## Changes\n\n- Link Buildchain, KFD, Build Images, and both public site repositories.\n- Link the complete kungfu-systems organization repository list.\n\n## Verification\n\n- `./shifu docs:check`\n- `./shifu docs:prose:required`\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This documentation-only source map does not alter an architecture or release contract\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T03:03:41Z",
          "mergedAt": "2026-07-26T03:19:47Z",
          "additions": 18,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1510,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1510",
          "title": "feat(product): add unified agent qualification lab",
          "body": "## Summary\n\nUnify GUI and TUI startup around one Core-owned Agent Qualification Lab. Verified existing local Work routes directly to the Work graph; only an authoritatively empty state enters the Lab, while unknown or incomplete states fail closed. Interactive bare `kungfu` enters the TUI, non-interactive bare invocation keeps governed help, and the unreleased `cockpit` product path is removed without compatibility semantics.\n\n## Related issue\n\nNative Assignment `2026-07-26-kungfu-unified-ui-agent-qualification-entry`.\n\n## Changes\n\n- Add the shared startup resolver, deterministic offline two-fresh-process continuity demo, exact local-agent plan/run identity binding, qualification lifecycle, and shared API/KFD capability.\n- Project the same canonical Lab actions and receipts into GUI and TUI, with a permanent return path from the Work experience.\n- Make `kungfu tui` the sole terminal product command and add automation-safe `kungfu --qualification-lab-demo`.\n- Remove all active tracked-tree `cockpit` product-path references and refresh governed catalogs, KFD evidence, docs, and package surfaces.\n\n## Verification\n\n- `./shifu check`\n- Focused Core/Work tests: 47 passed; qualification suite: 8 passed\n- API: 28 passed plus build; TUI: 20 passed plus build; GUI observer: 3 passed plus production build; SDK: 32 passed\n- KFD buildchain: 5 KFD-2 claims and 163 KFD-3 surfaces; Agent pack: 16 files and 176 commands\n- `./shifu product cli dist` and installed-layout smoke\n- Final archive E2E: zero-write bare help, verified-empty Lab route, deterministic two-fresh-process qualification, root demo, TUI non-interactive guard, unknown `cockpit`, and real-home Work-graph routing\n- Final archive SHA-256: `946fdb054aedf3c843f7e51724581847a062cd064e8ce81c2aa4a71fe22952fb`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-73ff-9543-f0a4f0beef05\",\n    \"KF-ADR-019f86da-4f90-7a4b-b1a3-256ce6fa3f06\"\n  ],\n  \"summary\": \"Deliver the shared boot-safe Qualification Lab, terminal entry convergence, and governed CLI projections as a bounded development stage.\",\n  \"verification\": [\n    \"Full Shifu check\",\n    \"Focused Core API GUI TUI SDK and KFD qualification\",\n    \"Installed archive empty-state live-Work and two-process continuity E2E\"\n  ]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe local-agent launcher contract stores only explicit executable identity, digest, version, model, argv/wrapper/backend, platform, and exact qualification roots; it never reads or copies credentials, provider homes, prompts, or prior transcripts. Product-entry naming and release evidence are covered by catalog/KFD regeneration, source gates, clean distribution build, installed-layout smoke, and archive-level E2E.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T03:42:33Z",
          "mergedAt": "2026-07-26T04:11:10Z",
          "additions": 4573,
          "deletions": 391,
          "changedFiles": 51
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1875,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1875",
          "title": "fix(auditable-demo): bind adapter environment",
          "body": "## Summary\n\n- pass the explicitly bounded adapter environment to `spawnSync`\n- add a real executable-adapter regression covering isolated HOME and deterministic environment values\n- preserve the existing auditable-demo workflow and evidence schemas\n\n## Evidence\n\n- Kungfu run `30185774420` built and resolved the exact source artifact, then failed closed in the required Gate with `auditable-demo: env is not defined`\n- diagnostic Artifact `8627511338` retained the failed Gate coordinate without marking it qualified\n\n## Validation\n\n- `node --test tests/auditable-demo.test.mjs` (5 tests passed)\n- `pnpm run check` (852 tests passed; 5 action bundles verified)\n- `git diff --check`\n\n## Risk\n\nThe change is limited to the adapter child-process environment binding. It does not alter workflow inputs, artifact naming, receipt schemas, renderer identity, or publication authority.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T04:29:20Z",
          "mergedAt": "2026-07-26T04:34:42Z",
          "additions": 65,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1876,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1876",
          "title": "fix(auditable-demo): promote adapter environment binding to alpha",
          "body": "## Summary\n\nPromote the protected Buildchain v2.14 development line containing PR #1875 into the Alpha channel.\n\n## Qualification\n\n- PR #1875 passed repository `check` and the full Linux/macOS/Windows libnode-shaped dogfood matrix\n- the change fixes the exact `env is not defined` failure retained by Kungfu run `30185774420`\n- workflow inputs, evidence schemas, renderer identity, and publication authority remain unchanged\n\n## Release intent\n\nThis PR expresses Alpha promotion intent only. The owning automation must generate and merge the exact version-state PR before any tag or release is treated as published.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T04:35:32Z",
          "mergedAt": "2026-07-26T04:39:22Z",
          "additions": 257,
          "deletions": 111,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1511,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1511",
          "title": "fix(ci): keep dev patrol on active Buildchain runtime",
          "body": "## Summary\n\n- resolve the official stable `v2` Buildchain runtime for standing dev patrols\n- preserve trusted manual train and exact-SHA overrides\n- bind the runtime selection in the closed-world workflow authority\n\nThe immutable reusable-workflow commit remains pinned. Only its runtime selection changes, preventing a diverged historical source SHA from being redirected to a retained self-hosted Git bundle that no longer contains that object.\n\n## Verification\n\n- `./shifu exec -- node --test scripts/check-kungfu-gate-catalog.test.mjs`\n- `./shifu check:gate-catalog`\n- `./shifu check:source`\n- pre-commit repository gates\n\nCloses #1061\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"CI runtime routing repair; no architecture contract changes.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-26T04:19:08Z",
          "mergedAt": "2026-07-26T04:42:24Z",
          "additions": 30,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1877,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1877",
          "title": "Prepare v2.14.19-alpha.5",
          "body": "Create the generated version-state commit for v2.14.19-alpha.5.\n\nBuildchain generated this PR because protected branch alpha/v2/v2.14 rejected direct generated bookkeeping.\n\nRejected update: a86d39d9cf264b8c14d6574ec02edd990175f715 -> 9531e4fa2849a48d4f45e7c6dc2516e2a9ddb787\n\nGitHub response: Repository rule violations found\n\nChanges must be made through a pull request.\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T04:44:34Z",
          "mergedAt": "2026-07-26T04:47:38Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1512,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1512",
          "title": "chore(deps-dev): update setuptools and classify Core lock changes",
          "body": "## Summary\n\n- update the Core development toolchain from setuptools 80.10.2 to 83.0.0\n- classify `framework/core/uv.lock` as a global native and SDK qualification input\n- add a fail-closed self-test for lock-only dependency updates\n\nSupersedes #1208.\n\n## Verification\n\n- `./shifu exec -- node scripts/run-core-affected-native.mjs --self-test`\n- `./shifu exec -- node scripts/run-core-affected-native.mjs --changed-file framework/core/uv.lock --json`\n- repository pre-commit staged gate\n- `git diff --check`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Routine development dependency maintenance and CI impact classification; no architecture contract changes.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-26T04:34:17Z",
          "mergedAt": "2026-07-26T05:19:09Z",
          "additions": 26,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1878,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1878",
          "title": "fix(gates): isolate runtime checkout from stale caches",
          "body": "## Summary\n- bootstrap the locked checkout helper in the hosted Gate planning job\n- use isolated, SHA-verified checkout with bounded GitHub fallback on self-hosted Gate runners\n- publish checkout diagnostics and expose the cache policy as reusable workflow inputs\n\n## Validation\n- `pnpm run check` (852 tests, workflow/site/inventory/action bundle checks)\n- `git diff --check`\n\nDownstream evidence: kungfu-systems/kungfu#1061",
          "author": "dongkeren",
          "createdAt": "2026-07-26T05:27:16Z",
          "mergedAt": "2026-07-26T05:30:28Z",
          "additions": 207,
          "deletions": 32,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1515,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1515",
          "title": "fix(ci): pin auditable demo to Buildchain alpha.5",
          "body": "## Summary\n\nPin every Kungfu auditable-demo and release-promotion Buildchain boundary to protected `v2.14.19-alpha.5` commit `9531e4fa2849a48d4f45e7c6dc2516e2a9ddb787`.\n\n## Root cause\n\nExact-source run 30185774420 reached the required checked-in consumer adapter but exposed a Buildchain runtime variable binding defect. Buildchain PRs #1875, #1876, and #1877 fixed, promoted, and released the regression-tested correction as `v2.14.19-alpha.5`.\n\n## Changes\n\n- pin build, auditable-demo Gate, and release promotion reusable workflows to the protected alpha.5 commit\n- bind the Release Passport to the same exact Buildchain commit\n- refresh structured workflow bindings, release rehearsal contract, and closed-world workflow authority evidence\n- update the executable workflow contract assertion\n\n## Verification\n\n- `./shifu test:auditable-demo` (17 passed)\n- `./shifu check:staged` (passed)\n- pre-commit staged gate (passed)\n- failed exact-source diagnostic: https://github.com/kungfu-systems/kungfu/actions/runs/30185774420\n- fixed Buildchain release: https://github.com/kungfu-systems/buildchain/releases/tag/v2.14.19-alpha.5\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Advance an existing immutable Buildchain workflow boundary to its regression-tested protected patch release; no product behavior or authority model changes\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis preserves fail-closed exact-source and exact-output evidence binding and adds no publication, deployment, secret, or identity-token authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Exact failed run and protected fix release cited\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T04:59:46Z",
          "mergedAt": "2026-07-26T05:35:15Z",
          "additions": 18,
          "deletions": 18,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1519,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1519",
          "title": "ci(alpha): rerun builds on source updates",
          "body": "## Summary\n\nRerun the protected Alpha and release Build workflow whenever a pull request head is synchronized. This closes the stale-source gap that left Alpha PR #1448 building an older generated runtime stub while preserving the existing exact-source preflight, per-promotion concurrency cancellation, and full cross-platform Buildchain qualification.\n\nThe active dev merge-queue ruleset was also updated separately from `max_entries_to_build=1` to `2`; all required checks, ALLGREEN grouping, REBASE, review policy, and one-at-a-time merge semantics remain unchanged.\n\n## Related issue\n\nRelates to #1448.\n\n## Changes\n\n- Add `synchronize` to the Alpha/release Build pull-request events.\n- Add a structural workflow regression test for the complete event set.\n- Refresh the generated workflow-authority digest.\n\n## Verification\n\n- `./shifu build:core` (clean tracked source after generated binding output)\n- `actionlint .github/workflows/build.yml`\n- `node --test scripts/auditable-demo-workflow.test.mjs`\n- `./shifu test:alpha-promotion-preflight`\n- `./shifu check:source`\n- Local pre-commit gate suite\n- GitHub ruleset `19057118` read-back after the concurrency update\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This changes pull-request event orchestration and its generated workflow digest without changing a runtime, schema, architecture, or release-policy contract.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: the Build workflow owns Alpha/release qualification evidence. The change only adds a missing head-update event; the exact-source preflight, current-head checkout, concurrency cancellation, pinned Buildchain runtime, and cross-platform gates are unchanged and covered by the workflow contract tests and source acceptance.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T05:46:54Z",
          "mergedAt": "2026-07-26T06:09:45Z",
          "additions": 11,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1517,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1517",
          "title": "fix(ci): make dev patrol cache non-semantic",
          "body": "## Summary\n\n- pin Dev Verify Patrol to the locked-checkout Gate Profile runtime\n- use checkout cache in `auto` mode with mandatory GitHub fallback\n- refresh the closed-world Gate binding and workflow authority evidence\n\n## Validation\n\n- `./shifu exec -- node --test scripts/check-kungfu-gate-catalog.test.mjs` (23/23)\n- `./shifu check:gate-catalog`\n- `./shifu check:source` (646 Node tests, 40 Python tests, 116 upgrade tests, 69 desktop tests)\n- staged pre-commit gate\n\nDepends on kungfu-systems/buildchain#1878. Closes #1061.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"CI checkout reliability repair; no architecture contract changes.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-26T05:35:09Z",
          "mergedAt": "2026-07-26T06:09:46Z",
          "additions": 13,
          "deletions": 10,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 134,
          "url": "https://github.com/kungfu-systems/libnode/pull/134",
          "title": "build: upgrade Buildchain workflows to v3",
          "body": "## Summary\n\n- move Buildchain reusable workflows and validation actions from v2 to v3\n- refresh stable and alpha contract locks\n- refresh the KFD witness and Buildchain release documentation\n\n## Validation\n\n- frozen pnpm install\n- Buildchain 3.0.0 config validation\n- release contract verification\n- KFD witness verification\n- package source verification\n- git diff check",
          "author": "dongkeren",
          "createdAt": "2026-07-26T04:40:17Z",
          "mergedAt": "2026-07-26T06:17:29Z",
          "additions": 56,
          "deletions": 31,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 135,
          "url": "https://github.com/kungfu-systems/libnode/pull/135",
          "title": "docs(governance): require distinct protected review identities",
          "body": "## Summary\n\n- document that protected content pushes and CODEOWNER approvals use distinct identities\n- create a real reviewable push by `dongkeren` so the existing last-push approval rule can be satisfied without self-review\n- leave every CODEOWNERS pattern and owner unchanged\n\n## Validation\n\n- one comment-only line changed\n- DCO sign-off enforced locally\n- protected four-platform build remains required\n- no administrator bypass or protection-rule mutation",
          "author": "dongkeren",
          "createdAt": "2026-07-26T05:13:50Z",
          "mergedAt": "2026-07-26T06:34:08Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1521,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1521",
          "title": "fix(sdk): use canonical engage subprocess path",
          "body": "## Summary\n\n- route SDK Python-AOT PDM and Nuitka subprocesses through the sole canonical `kungfu dev engage` path\n- route Nuitka data-composer and SCons re-entry through the same canonical path\n- add a regression that rejects the removed top-level `kungfu engage` path in internal subprocess owners\n\nThis fixes the real product.verify-full failure exposed after the Dev Patrol checkout repair and is a follow-up to #1061.\n\n## Testing\n\n- `./shifu --filter @kungfu-tech/sdk build` (32/32)\n- targeted CLI surface regression (1/1)\n- `./shifu check:source` (646 Node tests, 40 Python tests, 116 upgrade tests, 69 desktop tests; Ruff, Biome, mypy passed)\n- staged pre-commit gate passed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Internal CLI subprocess routing repair; no architecture contract changes.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-26T06:23:25Z",
          "mergedAt": "2026-07-26T07:25:09Z",
          "additions": 28,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1880,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1880",
          "title": "fix(control-plane): suppress release amplification",
          "body": "## Summary\n\nReduce Buildchain control-plane amplification by stabilizing workflow-friction incident identity, suppressing duplicate production release PR replay, and binding the self release-impact summary to the current release line.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Exclude per-occurrence release intent, source ref, and source SHA from workflow-friction fingerprints while retaining those facts in incident comments.\n- Query pull requests associated with the source commit before production release PR mutation and suppress the handoff when one qualifying merged release PR already exists.\n- Correct the v3.0 release-impact summary and make inventory validation reject stale summary lines.\n- Regenerate the issue-reporting action bundle and site contract digests.\n\n## Verification\n\n- `pnpm run check`\n- 857 unit tests passed.\n- Workflow, site bundle, inventory, and five action bundle integrity checks passed.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change adds a read-only associated-PR query before any release branch or PR mutation. The regression test proves that a qualifying merged release push performs no POST request, while the ordinary push path retains its existing create behavior.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T07:20:20Z",
          "mergedAt": "2026-07-26T07:25:23Z",
          "additions": 233,
          "deletions": 19,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1514,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1514",
          "title": "build: upgrade Buildchain consumers to v3",
          "body": "## Summary\n\n- upgrade stable Buildchain consumers to 3.0.0 and the alpha workflow shell to 3.0.1-alpha.2\n- move reusable workflows and actions to the protected v3 refs and immutable v3 SHAs\n- refresh contract locks, release admission policy, workflow authority, KFD evidence, Shifu bootstrap fallback, and current documentation\n- raise the KFD release-evidence minimum Buildchain version to 3.0.0\n\n## Validation\n\n- Buildchain v3 config validation\n- KFD evidence write/check\n- release promotion rehearsal\n- release admission tests\n- source acceptance and auditable demo workflow tests\n- focused Shifu bootstrap test\n\nThe controller binding measurement will be refreshed from the first successful GitHub candidate preflight job before merge.\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"KF-ADR-019f86da-4f90-7b6b-ae6d-76cea57487f2\"],\"summary\":\"Complete the bounded Buildchain v3 consumer authority migration across dependencies, workflow pins, contract locks, KFD evidence, and Shifu bootstrap.\",\"verification\":[\"Buildchain v3 config validation\",\"KFD evidence check\",\"release promotion rehearsal\",\"release admission tests\",\"source acceptance tests\",\"Shifu bootstrap test\"]}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-26T04:47:36Z",
          "mergedAt": "2026-07-26T07:41:20Z",
          "additions": 311,
          "deletions": 216,
          "changedFiles": 65
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1523,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1523",
          "title": "fix(gui): make agent qualification handoffs visual",
          "body": "## Summary\n\nTurn Agent Qualification Lab into a legible two-session experiment for a first-time Kungfu user. The shell navigation now remains available while the Lab is open, the three qualification scales share one mode selector, and the two fresh sessions are compared side by side with explicit good, bad, warning, handoff, and value states.\n\n## Related issue\n\nNative Assignment `2026-07-26-kungfu-agent-qualification-visual-experiment`.\n\n## Changes\n\n- Keep the primary shell sidebar mounted while Agent Qualification Lab is open, including a direct Back to Work action.\n- Replace separate run paths with one Test mode selector for offline demo, same-agent continuity, and cross-agent handoff.\n- Present Session 1 and Session 2 in responsive comparison columns with a visible Kungfu evidence bridge.\n- Explain the experiment, correct continuation, undesirable restart/context behavior, residual warnings, and the final Kungfu value in product language.\n- Preserve canonical Core authority: while the atomic action is running, the UI waits for evidence instead of fabricating Session 2 progress.\n- Add focused visual-contract and navigation regression tests to the Profile Suite.\n\n## Verification\n\n- `./shifu check:source` in a clean review worktree: passed; 636 Node tests passed, 10 environment-gated skips, 0 failures, plus Python, type, format, and source gates.\n- `./shifu test:kfx-profile-suite`: passed, including 6 new Lab visual-contract tests and 11 Python contract fixtures.\n- `./shifu build:app`: production Electron renderer/main/preload build passed.\n- Staged repository gate and DCO hook passed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"GUI presentation and navigation refinement over the existing canonical Agent Qualification Lab authority; no runtime semantics, schema, architecture contract, or release policy changes.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Focused tests and production GUI build passed\n- [x] Documentation impact is contained in self-explanatory product UI copy\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T07:46:53Z",
          "mergedAt": "2026-07-26T07:54:06Z",
          "additions": 979,
          "deletions": 225,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1524,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1524",
          "title": "fix(ci): restore proven dev patrol workflow",
          "body": "## Summary\n\n- restore the immutable Buildchain Gate workflow pin proven by #1517\n- keep the standing Patrol runtime on the proven `v2` channel\n- preserve the rest of the Buildchain v3 consumer migration\n- refresh the governed workflow bindings and authority manifest\n\n## Evidence\n\nLatest-main workflow dispatches 30193291386 and 30193403981 fail at startup with zero jobs after the Patrol caller moved to Buildchain v3. The prior immutable workflow pin expands correctly and reaches the three-platform Gate matrix.\n\n## Validation\n\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs` (23/23)\n- `./shifu check:source`\n- staged pre-commit gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"CI reusable-workflow startup repair; no architecture contract changes.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-26T07:52:18Z",
          "mergedAt": "2026-07-26T08:19:53Z",
          "additions": 12,
          "deletions": 15,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 325,
          "url": "https://github.com/kungfu-systems/build-images/pull/325",
          "title": "chore(images): accept OpenCode alpha.15 digest",
          "body": "## Summary\n- project the reviewed `v1.3.0-alpha.15` release evidence into `images.lock.json`\n- accept `opencode-ci` at `sha256:4083ee089fa9a419f4915505094a6c1bcce433ff77455605ce8993af3b684ed3`\n- retire the temporary `pending-first-publish` marker and refresh KFD witnesses\n\n## Evidence\n- release: https://github.com/kungfu-systems/build-images/releases/tag/v1.3.0-alpha.15\n- publish run: https://github.com/kungfu-systems/build-images/actions/runs/30157192214\n- trusted reviewed-SHA verification: https://github.com/kungfu-systems/build-images/actions/runs/30194243230\n- anonymous GHCR manifest and consumer digest pulls passed\n\n## Validation\n- `pnpm install --frozen-lockfile`\n- `pnpm check`\n- OpenCode deterministic fixture passed\n- trusted Buildchain `check` passed for exact head SHA `4fbeb851ac4b1228ead0bbe4a44b4efdba6d8363`\n\nSupersedes #324 because fork events are intentionally rejected by the privileged Buildchain trust gate.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-26T08:18:51Z",
          "mergedAt": "2026-07-26T08:22:22Z",
          "additions": 143,
          "deletions": 116,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1526,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1526",
          "title": "fix(qualification): stabilize macOS process sampling",
          "body": "## Summary\n\nKeep macOS SDK qualification fixtures observable long enough for the cross-platform resident-memory sampler to record a real RSS value under loaded native runners.\n\n## Root cause\n\nExact-source Build run 30192925949 completed install, product build, clean installed CLI/Agent Hub smoke, verify, live-Peer continuity, runtime activation, upgrade, and zero-burden desktop qualification. The final `layers.sdk` gate failed because the Rust `kungfu-sdk-call` fixture exited inside the 100 ms macOS hold before `ps` returned its first RSS sample. Linux and Windows already use a 1000 ms hold.\n\n## Changes\n\n- use the existing 1000 ms observation hold on macOS as well as Linux and Windows\n- keep the 100 ms fallback for unknown platforms\n- bind the platform policy in the process-metrics unit test\n\n## Verification\n\n- `node --test tests/qualification/layers/process-metrics.test.mjs` (2 passed, 1 Windows-only skipped)\n- full pre-commit repository gate passed on the identical two-file commit before rebasing onto the current dev base\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair a timing race in an existing qualification measurement fixture; no product, package, authority, or ADR projection changes\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes only the observation window of a qualification fixture. It adds no publication, deployment, credential, package write, or token authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Exact failed Build evidence cited\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T08:22:36Z",
          "mergedAt": "2026-07-26T08:52:42Z",
          "additions": 6,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1529,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1529",
          "title": "fix(demo): bound long-output projection cues",
          "body": "## Summary\n\nKeep every auditable-demo visual cue within Buildchain’s 1–80 transcript-line contract while retaining the complete installed-product transcript.\n\n## Root cause\n\nExact-source run 30189805076 installed and executed the real Linux artifact successfully, then failed closed because `kungfu agent brief` emitted more than 160 lines and the adapter split stdout into two oversized cues.\n\n## Changes\n\n- cap each stdout visual cue at 80 exact transcript references\n- preserve the complete stdout in `complete-transcript.txt`\n- use the exact output tail for the continuation cue when the output exceeds the visual budget\n- add a 181-line installed-launcher regression fixture\n\n## Verification\n\n- `./shifu test:auditable-demo` (19 passed)\n- `./shifu check:staged` (passed)\n- pre-commit staged gate, Ruff, Biome, invariant and docs suites (passed)\n- failed exact-source diagnostic: https://github.com/kungfu-systems/kungfu/actions/runs/30189805076\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Correct an existing checked adapter to satisfy the already-governed Buildchain cue-size contract for real long stdout; no authority or product behavior changes\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe correction remains fail-closed and grants no publication, deployment, secret, or identity-token authority.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Exact failed run and regression fixture are cited",
          "author": "dongkeren",
          "createdAt": "2026-07-26T08:50:29Z",
          "mergedAt": "2026-07-26T08:58:20Z",
          "additions": 53,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1881,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1881",
          "title": "feat(observability): record control-plane outcomes",
          "body": "## Summary\n\n- emit local JSONL outcomes for workflow-friction classification and incident reuse\n- emit production release-intent outcomes, including merged-PR suppression reasons\n- add additive control-plane summary metrics for incident reuse and release-intent suppression\n- retain the outcome log in promotion and web-surface handoff artifacts\n- refresh generated site/API facts and document the local-only telemetry boundary\n\n## Invariants\n\n- no change to workflow-friction fingerprint identity\n- no change to release-intent suppression decisions or PR mutation behavior\n- logging remains local and non-fatal by default\n- v3 release-impact semantics remain unchanged\n\n## Validation\n\n- `pnpm run check` (859 tests passed)\n- `node --test tests/release-impact-contract.test.mjs tests/promote-buildchain-ref.test.mjs` (142 tests passed)\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org/`\n\n## Runtime train\n\n`buildchain-ref=train/v3/v3.0/control-plane-observability`\n\nKeep committed workflow references on `@v3`; use the train only through the trusted `workflow_dispatch` override for real-run validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T09:10:06Z",
          "mergedAt": "2026-07-26T09:18:53Z",
          "additions": 401,
          "deletions": 94,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 137,
          "url": "https://github.com/kungfu-systems/libnode/pull/137",
          "title": "fix(release): reconcile Alpha permissions with Buildchain v3",
          "body": "## Summary\n\n- merge the reviewed Alpha publication fixes onto the current dev Buildchain v3 baseline\n- retain `v3-alpha`, `actions: write`, and `pull-requests: write` together\n- regenerate the exact KFD-1 workflow witness\n- retain the distinct protected-pusher/CODEOWNER guidance\n\n## Validation\n\n- `node .gyp/libnode-kfd-witnesses.js check`\n- `node .gyp/libnode-release-verify.js`\n- `git diff --check`\n- KFD3 artifact verifier requires the CI-built release tarball and is delegated to protected build\n\nNo administrator bypass or branch-protection mutation.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T06:41:00Z",
          "mergedAt": "2026-07-26T09:20:04Z",
          "additions": 5,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 131,
          "url": "https://github.com/kungfu-systems/libnode/pull/131",
          "title": "chore(release): reconcile alpha publication fixes to dev",
          "body": "Bring the already-reviewed alpha release-governance fixes back into the development line so the protected dev-to-alpha promotion topology can be re-established without changing the qualified release material.",
          "author": "dongkeren",
          "createdAt": "2026-07-25T17:08:43Z",
          "mergedAt": "2026-07-26T09:20:06Z",
          "additions": 5,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1882,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1882",
          "title": "fix(release): suppress deterministic intent duplicates",
          "body": "## Summary\n\n- fall back to the deterministic release-intent head when commit-associated PR lookup only returns the preceding source PR\n- keep the lookup read-only and exact to repository, base, head prefix, merged state, and release label\n- add regression coverage for the live GitHub response shape\n\n## Live dogfood\n\nA GET-only probe against `kungfu-systems/site-kungfu-tech` source `dd03035930990d11a410e9e77824a7551441304b` now resolves merged release-intent PR #146 and returns `suppressed-merged-release-pr`. The fail-closed probe rejects any non-GET request.\n\n## Validation\n\n- `pnpm run check` (860/860)\n- `node --test tests/release-impact-contract.test.mjs tests/promote-buildchain-ref.test.mjs` (142/142)\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-26T09:28:47Z",
          "mergedAt": "2026-07-26T09:34:08Z",
          "additions": 65,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1885,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1885",
          "title": "chore(release): sync v3 alpha state to dev",
          "body": "## Summary\n\n- merge the protected v3 alpha version state back into dev\n- preserve the published 3.0.1-alpha.2 identity\n- regenerate the v3 site contracts from the reconciled tree\n- unblock the dev-to-alpha control-plane observability promotion\n\n## Validation\n\n- `pnpm run check` (860 tests)\n- `node --test tests/release-impact-contract.test.mjs tests/promote-buildchain-ref.test.mjs` (142 tests)\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-26T09:46:16Z",
          "mergedAt": "2026-07-26T09:52:28Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1884,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1884",
          "title": "release(v3): promote control-plane observability to alpha",
          "body": "## Summary\n\nPromote the current v3 development channel into alpha after the control-plane observability and deterministic release-intent suppression work landed.\n\n## Evidence\n\n- PR #1881 and #1882 merged with required checks\n- local full check: 860/860\n- release-impact and promotion contract tests: 142/142\n- live GET-only workflow dogfood: run 30196764923\n- duplicate release intent for site-kungfu-tech PR #146 was suppressed with `suppressionRate=1`\n\n## Release invariants\n\n- preserve v3 release-impact version, line, and summary semantics\n- keep workflow-friction fingerprint identity stable\n- publish only through the protected alpha channel and trusted publishing transaction",
          "author": "dongkeren",
          "createdAt": "2026-07-26T09:41:15Z",
          "mergedAt": "2026-07-26T09:56:05Z",
          "additions": 698,
          "deletions": 110,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1475,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1475",
          "title": "feat(release): harden alpha activation transaction",
          "body": "## Summary\n- add installed `kungfu release status|verify|explain` with stable human and JSON results, strict receipt/root verification, KFD-3 catalog discovery, and generated KFD evidence\n- synthesize released evidence only from the five authoritative activation receipts and add a deterministic non-claiming shadow activation\n- bind promotion to the merged Buildchain activation shell and exact site publication/readback contract\n- qualify the first Windows Alpha as unsigned PE bytes protected by signed-channel digest and installed-product readback; no Authenticode or publisher claim\n\n## Cross-repository delivery\n- Buildchain transaction contract: kungfu-systems/buildchain#1833\n- Buildchain alpha channel promotion: kungfu-systems/buildchain#1835\n- Site truthful status and exact-ref activation: kungfu-systems/site-kungfu-tech#149\n\n## Validation\n- Python release verifier/channel: 19 passed\n- release evidence, bootstrap, and upgrade suites: 40 passed\n- release promotion rehearsal: 12 passed\n- KFD evidence: KFD-1 witness, 5 KFD-2 claims, 164 KFD-3 surfaces\n- `./shifu gate run docs.contracts`: pass (104 tests)\n- staged repository gate: pass\n- protected PR CI owns Linux-only `source.acceptance` and `docs.prose`\n\n## Claim boundary\nThis is a non-claiming, stage-ready hardening change. It does not perform the actual Kungfu Alpha publication and makes no first-use, registration, legal-sufficiency, or Windows code-signing claim.\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"KF-ADR-019f8cc4-e796-7b0e-9a16-50c08614e848\"],\"summary\":\"Stage one replayable Alpha activation transaction with authoritative receipt synthesis, installed and KFD-3 release verification, truthful site readback, and unsigned Windows Alpha integrity qualification.\",\"verification\":[\"staged repository gate\",\"docs.contracts\",\"release promotion rehearsal\",\"release verifier and unsigned Windows qualification suites\",\"Buildchain and site protected PR checks\"]}\n-->\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-25T08:56:08Z",
          "mergedAt": "2026-07-26T09:57:11Z",
          "additions": 2882,
          "deletions": 206,
          "changedFiles": 49
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 326,
          "url": "https://github.com/kungfu-systems/build-images/pull/326",
          "title": "ci(buildchain): migrate managed surfaces to v3",
          "body": "## Summary\n\n- migrate active Buildchain workflows, actions, and consumer contract locks to `v3` / `v3-alpha` where present;\n- update Buildchain package pins, runtime assertions, documentation, and generated evidence owned by this repository;\n- preserve the repository's existing release-line and protected-mainline behavior.\n\n## Validation\n\n- repository-native checks passed locally on macOS;\n- `git diff --check` passed;\n- the commit carries the required DCO sign-off.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T09:44:32Z",
          "mergedAt": "2026-07-26T10:01:05Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1886,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1886",
          "title": "Prepare v3.0.1-alpha.3",
          "body": "Create the generated version-state commit for v3.0.1-alpha.3.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: 7bbc59abd8516132b06c588bdc191f7bc5fbdef9 -> de9e4e6176a4716c59a831e0ec58b68bbf2c204d\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T10:00:30Z",
          "mergedAt": "2026-07-26T10:05:16Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 151,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/151",
          "title": "ci(buildchain): migrate managed surfaces to v3",
          "body": "## Summary\n\n- migrate active Buildchain workflows, actions, and consumer contract locks to `v3` / `v3-alpha` where present;\n- update Buildchain package pins, runtime assertions, documentation, and generated evidence owned by this repository;\n- preserve the repository's existing release-line and protected-mainline behavior.\n\n## Validation\n\n- repository-native checks passed locally on macOS;\n- `git diff --check` passed;\n- the commit carries the required DCO sign-off.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T09:44:30Z",
          "mergedAt": "2026-07-26T10:08:13Z",
          "additions": 71,
          "deletions": 45,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 211,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/211",
          "title": "ci(buildchain): migrate managed surfaces to v3",
          "body": "## Summary\n\n- migrate active Buildchain workflows, actions, and consumer contract locks to `v3` / `v3-alpha` where present;\n- update Buildchain package pins, runtime assertions, documentation, and generated evidence owned by this repository;\n- preserve the repository's existing release-line and protected-mainline behavior.\n\n## Validation\n\n- repository-native checks passed locally on macOS;\n- `git diff --check` passed;\n- the commit carries the required DCO sign-off.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T09:44:30Z",
          "mergedAt": "2026-07-26T10:15:04Z",
          "additions": 80,
          "deletions": 63,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 4,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/4",
          "title": "ci(buildchain): migrate managed surfaces to v3",
          "body": "## Summary\n\n- migrate active Buildchain workflows, actions, and consumer contract locks to `v3` / `v3-alpha` where present;\n- update Buildchain package pins, runtime assertions, documentation, and generated evidence owned by this repository;\n- preserve the repository's existing release-line and protected-mainline behavior.\n\n## Validation\n\n- repository-native checks passed locally on macOS;\n- `git diff --check` passed;\n- the commit carries the required DCO sign-off.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T10:17:45Z",
          "mergedAt": "2026-07-26T10:23:01Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 57,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/57",
          "title": "ci(buildchain): migrate managed surfaces to v3",
          "body": "## Summary\n\n- migrate active Buildchain workflows, actions, and consumer contract locks to `v3` / `v3-alpha` where present;\n- update Buildchain package pins, runtime assertions, documentation, and generated evidence owned by this repository;\n- preserve the repository's existing release-line and protected-mainline behavior.\n\n## Validation\n\n- repository-native checks passed locally on macOS;\n- `git diff --check` passed;\n- the commit carries the required DCO sign-off.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T10:17:45Z",
          "mergedAt": "2026-07-26T10:23:02Z",
          "additions": 37,
          "deletions": 27,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 72,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/72",
          "title": "ci(buildchain): migrate managed surfaces to v3",
          "body": "## Summary\n\n- migrate active Buildchain workflows, actions, and consumer contract locks to `v3` / `v3-alpha` where present;\n- update Buildchain package pins, runtime assertions, documentation, and generated evidence owned by this repository;\n- preserve the repository's existing release-line and protected-mainline behavior.\n\n## Validation\n\n- repository-native checks passed locally on macOS;\n- `git diff --check` passed;\n- the commit carries the required DCO sign-off.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T10:17:45Z",
          "mergedAt": "2026-07-26T10:23:02Z",
          "additions": 86,
          "deletions": 21,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 77,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/77",
          "title": "ci(buildchain): migrate managed surfaces to v3",
          "body": "## Summary\n\n- migrate active Buildchain workflows, actions, and consumer contract locks to `v3` / `v3-alpha` where present;\n- update Buildchain package pins, runtime assertions, documentation, and generated evidence owned by this repository;\n- preserve the repository's existing release-line and protected-mainline behavior.\n\n## Validation\n\n- repository-native checks passed locally on macOS;\n- `git diff --check` passed;\n- the commit carries the required DCO sign-off.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T10:17:45Z",
          "mergedAt": "2026-07-26T10:23:02Z",
          "additions": 104,
          "deletions": 36,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 77,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/77",
          "title": "ci(buildchain): migrate managed surfaces to v3",
          "body": "## Summary\n\n- migrate active Buildchain workflows, actions, and consumer contract locks to `v3` / `v3-alpha` where present;\n- update Buildchain package pins, runtime assertions, documentation, and generated evidence owned by this repository;\n- preserve the repository's existing release-line and protected-mainline behavior.\n\n## Validation\n\n- repository-native checks passed locally on macOS;\n- `git diff --check` passed;\n- the commit carries the required DCO sign-off.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T10:17:45Z",
          "mergedAt": "2026-07-26T10:23:02Z",
          "additions": 92,
          "deletions": 22,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1531,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1531",
          "title": "fix(gui): stream qualification progress",
          "body": "## Summary\n\nMake Agent Qualification Lab feel live without fabricating progress. Core now publishes real qualification milestones as each boundary completes, CLI/API/GUI stream the same events, the two session columns reveal command-like safe output progressively, and the final assessment emphasizes each verdict in sequence.\n\n## Related issue\n\nNative Assignment `2026-07-26-kungfu-unified-ui-agent-qualification-entry` follow-up.\n\n## Changes\n\n- Publish plan, session start/completion, and assessment milestones directly from the Core demo and real-agent execution paths.\n- Stream newline-delimited qualification events through CLI, TypeScript capability API, and the Electron renderer process instead of waiting for an atomic stdout buffer.\n- Pace the two visual session streams from real events, keep the fresh-session handoff visible, and never expose raw provider output.\n- Reveal final oracle checks, residuals, and value statements one at a time with focused pass/fail/warning emphasis.\n- Respect reduced-motion preferences while preserving ordered state transitions.\n- Add Core, API, and GUI regression coverage for event order, report parity, safe rendering, animation, and fallback behavior.\n\n## Verification\n\n- `./shifu check:source` in a clean review worktree: passed; 636 Node tests passed, 10 environment-gated skips, 0 failures, plus Python, TypeScript, ruff, mypy, and source gates.\n- `./shifu test:kfx-profile-suite`: passed, including 7 Agent Qualification Lab visual-contract tests.\n- `./shifu --filter @kungfu-tech/core exec env PYTHONPATH=src/python:build/Release uv run --frozen pytest -q tests/python/test_qualification_lab.py`: 8 passed.\n- `./shifu --filter @kungfu-tech/api test:query`: 29 passed.\n- `./shifu --filter @kungfu-tech/gui build`: production Electron build passed.\n- Exact affected-native plan for the PR head/base: passed after removing the unrelated development-wrapper change.\n- Staged repository gates and DCO hooks passed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Bugfix and progressive presentation over the existing Agent Qualification Lab authority; no new product authority, schema ownership, release policy, or architecture contract is introduced.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Focused tests, clean source acceptance, and production GUI build passed\n- [x] Documentation impact is contained in self-explanatory product UI copy\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T09:44:51Z",
          "mergedAt": "2026-07-26T10:23:22Z",
          "additions": 700,
          "deletions": 108,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 268,
          "url": "https://github.com/kungfu-systems/kfd/pull/268",
          "title": "ci(buildchain): migrate managed surfaces to v3",
          "body": "## Summary\n\n- migrate active Buildchain workflows, actions, and consumer contract locks to `v3` / `v3-alpha` where present;\n- update Buildchain package pins, runtime assertions, documentation, and generated evidence owned by this repository;\n- preserve the repository's existing release-line and protected-mainline behavior.\n\n## Validation\n\n- repository-native checks passed locally on macOS;\n- `git diff --check` passed;\n- the commit carries the required DCO sign-off.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T10:17:45Z",
          "mergedAt": "2026-07-26T10:23:48Z",
          "additions": 118,
          "deletions": 48,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 13,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/13",
          "title": "ci(buildchain): migrate managed surfaces to v3",
          "body": "## Summary\n\n- migrate active Buildchain workflows, actions, and consumer contract locks to `v3` / `v3-alpha` where present;\n- update Buildchain package pins, runtime assertions, documentation, and generated evidence owned by this repository;\n- preserve the repository's existing release-line and protected-mainline behavior.\n\n## Validation\n\n- repository-native checks passed locally on macOS;\n- `git diff --check` passed;\n- the commit carries the required DCO sign-off.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T10:17:45Z",
          "mergedAt": "2026-07-26T10:34:18Z",
          "additions": 90,
          "deletions": 78,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1527,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1527",
          "title": "Establish Alpha attention and community intake readiness",
          "body": "## Summary\n\nEstablish a GitHub-native public-attention operating system and a versioned two-layer community-health baseline without publishing Alpha or changing live repository settings.\n\n## Related issue\n\n- Assignment `2026-07-26-kungfu-alpha-attention-operations-readiness`\n- Assignment `2026-07-26-kungfu-systems-community-health-baseline`\n\n## Changes\n\n- replace free-form issue templates with repository-local structured Issue Forms and deterministic provenance markers\n- add public routing, label, queue, agent-safety, Known Issues, Alpha Status, moderation, and T-24 to T+48 operating contracts\n- add an inert public-safe candidate for `kungfu-systems/.github`, shared taxonomy, reusable least-privilege admission workflow, consumer coordinates, and inheritance readback\n- isolate automation findings from external demand and add pure fixture rehearsals for bypass, edits, prompt injection, secret-looking input, duplicates, bot load, thresholds, and rollback\n\n## Verification\n\n- `./shifu test:alpha-attention-operations`\n- `./shifu test:community-health-baseline`\n- `./shifu docs:check`\n- `./shifu check:source`\n- pre-commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This changes GitHub community intake, public operations documentation, and fixture-only rehearsal surfaces without altering a Kungfu architecture contract or publishing a release channel.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\nThe candidate documents exact human-gated plans for future GitHub configuration, but this PR performs no live Discussions, label, moderation, repository-creation, Alpha publication, or channel mutation.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T08:37:48Z",
          "mergedAt": "2026-07-26T10:43:33Z",
          "additions": 3889,
          "deletions": 81,
          "changedFiles": 46
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1533,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1533",
          "title": "fix(verify): restore dev patrol contract coverage",
          "body": "## Summary\n- realign Dev Patrol fixtures with the current schema, provider set, read-only global Work view, and single Work mutation authority\n- preserve report, receipt, and remote-sync coverage through externally authoritative Work references instead of restoring the retired WorkStore\n- return the Fact kernel contract-specific relation endpoint failure and refresh its rooted generated evidence\n\n## Verification\n- all nine previously failing fixtures pass locally\n- storage Node binding: 19/19 tests pass\n- staged pre-commit gate passes, including C++ format, Python lint/format, KFD evidence, and documentation checks\n- `./shifu build:core` and `./shifu freeze` pass\n\nFollow-up for #1516. The standing Dev Verify Patrol will close the issue only after the merged mainline is green on all supported platforms.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Restore current Dev Patrol fixture and Fact kernel failure-code coverage without changing architecture contracts.\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T09:51:51Z",
          "mergedAt": "2026-07-26T10:43:33Z",
          "additions": 191,
          "deletions": 184,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1537,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1537",
          "title": "fix(product): keep desktop CLI runtime immutable",
          "body": "## Summary\n\nPrevent the installed desktop CLI from writing Python bytecode into the signed app bundle.\n\n## Related issue\n\nFollow-up found during local promotion verification of PR #1531.\n\n## Changes\n\n- export `PYTHONDONTWRITEBYTECODE=1` before the desktop companion CLI enters the bundled runtime\n- lock the invariant with a launcher contract test\n\n## Verification\n\n- `sh -n framework/gui/resources/cli/kungfu`\n- `./shifu test:cli-surface-qualification` (31/31)\n- `./shifu --filter @kungfu-tech/gui build`\n- signed source candidate verifies before CLI execution; the installed bundle previously failed only after CLI rewrote `__pycache__`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This packaging bug fix preserves the existing CLI and runtime architecture while preventing post-signing bytecode mutation.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe fix protects the already-signed desktop bundle; verification is listed above.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not required: internal packaging invariant only)",
          "author": "dongkeren",
          "createdAt": "2026-07-26T10:50:39Z",
          "mergedAt": "2026-07-26T10:57:10Z",
          "additions": 17,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1887,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1887",
          "title": "chore(v3): move active consumer references to v3",
          "body": "## Summary\n\n- move active Buildchain workflow and action examples from v2 channels to v3\n- make repository scaffolds emit v3 reusable workflow references\n- move Buildchain patrol defaults to v3-alpha\n- refresh generated site and public contract facts\n- preserve retired v2 compatibility fixtures and third-party action versions\n\n## Validation\n\n- `pnpm install --frozen-lockfile`\n- `pnpm run check` (860 tests, 0 failures)\n- active v2 management reference scan: 0\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T10:52:53Z",
          "mergedAt": "2026-07-26T10:58:00Z",
          "additions": 275,
          "deletions": 275,
          "changedFiles": 46
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 153,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/153",
          "title": "docs(trust): point Buildchain passport to v3",
          "body": "## Summary\n- update the public trust-page Buildchain release-passport link from the retired v2 line to dev/v3/v3.0\n- keep the change limited to the published trust surface\n\n## Validation\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-26T11:03:30Z",
          "mergedAt": "2026-07-26T11:04:45Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1538,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1538",
          "title": "feat(format): qualify portable alpha packages",
          "body": "## Summary\n\nComplete the internally controllable portable-format P0/P1 boundary and make `@kungfu-tech/spec` and `@kungfu-tech/site` independently packable, installable, and renderable alpha artifacts. This PR does not publish npm coordinates, modify a downstream site repository, or claim stable compatibility.\n\n## Related issue\n\n- Assignment `2026-07-26-kungfu-portable-format-alpha-npm-release`\n- Portable format authority ADR `KF-ADR-019f96a2-c686-76e1-9261-f6106aa50429`\n\n## Changes\n\n- freeze a mechanically checked pre-stable v4 alpha compatibility baseline and fail closed on unknown tuple axes or undeclared successor mutations\n- expand the retained public-safe corpus to 16 vectors across every declared compatibility axis and all five required outcomes\n- add a disposable-workspace migration and evidence-preserving repair campaign with preview, no-op, refusal, interruption recovery, idempotent retry, source preservation, and exact receipts\n- ship a standalone stdlib-only Python reference reader inside the packed Spec contract\n- qualify deterministic Spec and Site tarballs through clean installation, CLI/API checks, independent reader execution, and rendering of all 11 package-owned page models\n\n## Verification\n\n- `./shifu check:portable-format-authority` — 29 tests, 16 vectors, 5 outcomes, 8 axes\n- `./shifu layers:gate:format` — passing exact packed Spec artifact gate\n- `./shifu qualify:portable-format-packages -- --output <temp> --report <temp>/report.json` — clean source, clean install, Spec CLI/API, standalone Python reader, Site verification, and 11 rendered page models\n- staged repository gate on the exact PR head, including docs, source contracts, Ruff, Biome, Rust clippy, and Rust tests\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f96a2-c686-76e1-9261-f6106aa50429\"],\n  \"summary\": \"Qualify the pre-stable v4 portable-format baseline, migration and repair campaign, independent reader, retained corpus, and clean-consumer Spec/Site alpha package boundary.\",\n  \"verification\": [\"./shifu check:portable-format-authority\", \"./shifu layers:gate:format\", \"./shifu qualify:portable-format-packages\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR defines and qualifies exact public package names and alpha metadata, but performs no registry publication. Publication remains a separate exact-artifact action after protected merge and registry collision checks; `latest` and stable compatibility remain explicitly out of scope.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T10:55:21Z",
          "mergedAt": "2026-07-26T11:26:09Z",
          "additions": 2356,
          "deletions": 126,
          "changedFiles": 50
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1890,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1890",
          "title": "fix(gate): expose user cargo toolchains",
          "body": "## Summary\n\n- expose the conventional user Cargo bin directory before reusable build and Gate execution\n- keep the existing local user bin exposure unchanged\n- regenerate the public Buildchain contract digest for the workflow change\n\n## Validation\n\n- corepack pnpm@11.7.0 run check:workflows\n- corepack pnpm@11.7.0 run check (860 tests passed)\n\n## Consumer evidence\n\n- https://github.com/kungfu-systems/kungfu/actions/runs/30198817396\n\nCloses #1888",
          "author": "dongkeren",
          "createdAt": "2026-07-26T11:23:52Z",
          "mergedAt": "2026-07-26T11:28:01Z",
          "additions": 20,
          "deletions": 8,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1891,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1891",
          "title": "docs(v3): align current examples with v3",
          "body": "## Summary\n- align current Buildchain install, CLI, runtime-train, release-passport, propagation, and agent examples with v3\n- refresh generated site facts after the documentation changes\n- label v2.14.16 as the verified legacy standalone-binary line because v3.0.0 publishes evidence assets but no platform archives\n\n## Validation\n- `node scripts/check-inventory.mjs`\n- `pnpm run check:site`\n- `pnpm run check:workflows`\n- `node scripts/check-action-bundles.mjs`\n- `git diff --check`\n- unit suite: 859/860 passed locally; the unchanged standalone SEA test fails on Homebrew Node 22.22.3 because postject cannot find the Node SEA sentinel\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T11:43:03Z",
          "mergedAt": "2026-07-26T11:46:21Z",
          "additions": 144,
          "deletions": 155,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1535,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1535",
          "title": "fix(deps): resolve transitive security advisories",
          "body": "## Summary\n\n- pin patched transitive releases for axios, fast-uri, js-yaml, markdown-it, postcss, and tar\n- converge brace-expansion on 5.0.8 while preserving the callable CommonJS surface used by minimatch 3/5 and the default ESM export used by minimatch 9\n- refresh the pnpm lockfile without changing application code or public package APIs\n\n## Validation\n\n- `./shifu sync`\n- `./shifu audit --audit-level low` — no known vulnerabilities\n- `./shifu check:source`\n- `./shifu build:app`\n- compatibility smoke across minimatch 3.1.4, 3.1.5, 5.1.9, and 9.0.9\n- Lerna workspace enumeration and wsrun CLI smoke\n\nThe broader `./shifu check` passed the affected dependency, documentation, layer, Electron-builder, and tooling suites after generating the Spec artifact. It later reached an existing SDK KFD baseline mismatch (`alpha.21` installed versus `alpha.41` expected), which is unchanged by this dependency-only diff.\n\n## Security impact\n\nThe resolved lockfile contains none of the versions covered by the 20 open Dependabot alerts present on the base branch at the start of this change.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Transitive dependency security maintenance and compatibility preservation only; no architecture contract or public API changes.\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T10:46:21Z",
          "mergedAt": "2026-07-26T11:49:40Z",
          "additions": 179,
          "deletions": 154,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 155,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/155",
          "title": "feat: align UNGFU brand surfaces",
          "body": "## Summary\n\n- use Kungfu UNGFU™ as the shared header signature across public pages\n- align homepage and social metadata plus human and Agent entrypoints\n- state the unsigned Windows Alpha trust boundary without requiring Authenticode\n\n## Validation\n\n- corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- desktop and 390px browser layout checks with zero horizontal overflow\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] Official branding is changed intentionally\n- [x] Release identity and production activation are unchanged\n- [x] Staging only after ordinary main integration; production remains approval-gated",
          "author": "dongkeren",
          "createdAt": "2026-07-26T11:52:04Z",
          "mergedAt": "2026-07-26T11:53:32Z",
          "additions": 54,
          "deletions": 32,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 214,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/214",
          "title": "feat: align UNGFU brand surfaces",
          "body": "## Summary\n\n- use Kungfu UNGFU™ with Developer Platform as the shared header lockup\n- add consistent application, Open Graph, and Twitter metadata\n- expose the same product and trademark boundary in manifest.json and llms.txt\n\n## Validation\n\n- pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/\n- pnpm run build\n- pnpm run check\n- desktop and 390px browser layout checks with zero horizontal overflow\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] Official branding is changed intentionally\n- [x] Upstream KFD, Buildchain, and Kungfu product facts are unchanged\n- [x] Staging only after ordinary main integration; production remains approval-gated",
          "author": "dongkeren",
          "createdAt": "2026-07-26T11:52:04Z",
          "mergedAt": "2026-07-26T11:53:38Z",
          "additions": 61,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1540,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1540",
          "title": "fix(ci): pin cargo-aware gate workflow",
          "body": "## Summary\n\nPin the dev Patrol Gate profile to the merged Buildchain revision that exposes user Cargo toolchains on Windows and POSIX runners. This lets source-fresh Shifu bootstrap use the runner's installed Rust toolchain instead of falling back to a missing prebuilt release.\n\n## Related issue\n\n- Closes #1516 after the next fully green three-platform Patrol\n- Upstream: kungfu-systems/buildchain#1890\n\n## Changes\n\n- pin the reusable Gate workflow to Buildchain `619c3a3c786038e3a72394eb68d2e2a6e0455ff9`\n- refresh the closed-world workflow binding and authority projection\n- update the drift fixture to enforce the new exact SHA\n\n## Verification\n\n- `./shifu check:gate-catalog`\n- `./shifu check:source`\n- Buildchain workflow fixtures and Windows x64 job: https://github.com/kungfu-systems/buildchain/actions/runs/30200047293\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This maintenance fix updates an exact reusable-workflow pin and its generated authority projection without changing an architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe exact reusable-workflow SHA is covered by the Gate catalog, source acceptance, and the upstream Buildchain Windows fixture.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T11:35:13Z",
          "mergedAt": "2026-07-26T11:54:49Z",
          "additions": 5,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 215,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/215",
          "title": "fix: preserve immutable paper archives",
          "body": "## Summary\n\n- keep the Kungfu UNGFU™ lockup on current and mutable developer surfaces\n- preserve historical publication archive HTML byte-for-byte\n- add a regression gate that rejects brand changes leaking into immutable archives\n\n## Evidence\n\n- pnpm run build\n- pnpm run check\n- generated episodes-to-primitives immutable HTML is byte-identical to the pre-brand baseline\n- addresses the staging immutable-object digest mismatch from run 30200996006\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] Immutable release evidence is preserved\n- [x] Production activation is unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-26T12:00:34Z",
          "mergedAt": "2026-07-26T12:02:20Z",
          "additions": 18,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1894,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1894",
          "title": "fix(gates): port locked checkout to v3",
          "body": "## Summary\n\nPort the locked source/runtime checkout contract from the v2 maintenance line to v3 while preserving the v3 Gate runner Cargo PATH fix. Without this parity, current Kungfu callers fail at workflow startup because v3 does not declare the checkout-cache inputs.\n\n## Related issue\n\n- Follow-up to #1878\n- Preserves #1888 / #1890\n- Unblocks kungfu-systems/kungfu#1516\n\n## Changes\n\n- add the locked checkout-cache inputs and exact-SHA fallback flow to the v3 reusable Gate profile\n- keep both `.local/bin` and `.cargo/bin` on Windows and POSIX runner PATHs\n- regenerate the Buildchain site contract projections\n- combine both capability sets in the reusable workflow fixture\n\n## Verification\n\n- targeted reusable Gate workflow contract test\n- `pnpm run check:workflows`\n- `pnpm run check` (860 tests; action bundle integrity passed)\n- observed Kungfu startup failure: https://github.com/kungfu-systems/kungfu/actions/runs/30201044580\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes the reusable Gate checkout evidence surface. Exact-SHA resolution, fallback behavior, generated contract projections, and the complete repository check are verified.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T12:01:46Z",
          "mergedAt": "2026-07-26T12:07:33Z",
          "additions": 207,
          "deletions": 32,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1539,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1539",
          "title": "fix(ci): qualify dev gate latency evidence",
          "body": "## Summary\n\n- discover required contexts from GitHub effective branch rules and fail closed on retained-baseline drift\n- bind native cache evidence to the exact merge-group SHA while reporting coalesced group plans explicitly\n- cancel active affected-native merge-group runs after an authoritative dequeue from a trusted-base, least-privilege workflow\n- retain the latest 30-PR required-gate baseline and the still-failing historical delivery cohort without rewriting it\n\n## Current evidence\n\n- required contexts: Candidate source acceptance / check; affected-native / linux\n- required latency: 30 samples, 20 native, P50 167 s, P95 358 s, cache unknown 0 — qualified\n- delivery: 57 completed samples, P50 24.9 min, P90 76.3 min, dequeue cohort 16/63 — not yet qualified\n\n## Validation\n\n- ./shifu test:gate-latency (43 passed)\n- ./shifu check:source (passed)\n- node --test scripts/check-kungfu-gate-catalog.test.mjs (23 passed)\n- actionlint .github/workflows/cancel-dequeued-merge-group.yml (passed)\n\nThe dequeue controller is prospective. This PR does not claim that historical delivery samples already meet the SLO.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This CI qualification change does not alter an architecture contract or ADR record\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundaries are limited to GitHub Actions workflow-run cancellation and retained qualification evidence. The controller uses a trusted base checkout, exact PR branch matching, actions:write only, and fail-closed API handling.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T11:32:08Z",
          "mergedAt": "2026-07-26T12:12:23Z",
          "additions": 598,
          "deletions": 94,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 136,
          "url": "https://github.com/kungfu-systems/libnode/pull/136",
          "title": "chore(release): restore standard dev-to-alpha lineage",
          "body": "## Summary\n\n- merge the current protected `dev/v22/v22.22` head into Alpha through the standard same-repository PR path\n- admit concurrent Buildchain v3 workflow upgrade `a0769ef` before reconciling Alpha publication fixes back to dev\n- restore the exact lineage required by the OIDC publication gate\n\n## Validation\n\n- protected Alpha preflight and four-platform native build required\n- independent CODEOWNER approval required\n- no administrator bypass",
          "author": "dongkeren",
          "createdAt": "2026-07-26T06:36:29Z",
          "mergedAt": "2026-07-26T12:23:42Z",
          "additions": 56,
          "deletions": 31,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1896,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1896",
          "title": "fix(auditable-demo): bind adapter environment on v3",
          "body": "## Summary\n\n- pass the constructed bounded adapter environment to `spawnSync` on the v3 line\n- add an execution regression test that proves HOME, TZ, and SOURCE_DATE_EPOCH reach the checked-in adapter\n- restore the reusable auditable-demo Gate for exact artifact consumers\n\n## Evidence\n\n- `node --test tests/auditable-demo.test.mjs` (5/5)\n- `pnpm run check` (861/861; action bundle integrity passed)\n- downstream failure: kungfu Actions run 30195697999, diagnostic artifact 8631839439\n\nThis is the v3 port of the independently tested v2 fix in #1875.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T12:24:30Z",
          "mergedAt": "2026-07-26T12:27:47Z",
          "additions": 65,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1541,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1541",
          "title": "fix(ci): pin complete v3 gate workflow",
          "body": "## Summary\n\nPin the dev Patrol to the complete Buildchain v3 Gate workflow that combines locked checkout/cache fallback with runner Cargo PATH exposure. This replaces the incomplete v3 SHA that failed workflow startup before any platform job could run.\n\n## Related issue\n\n- #1516\n- Upstream: kungfu-systems/buildchain#1894\n\n## Changes\n\n- pin the reusable Gate workflow to Buildchain `a9e1826da969dc0932fdd9c5668a1c6363267ae2`\n- refresh the closed-world workflow binding and authority projection\n- update the drift fixture to enforce the complete v3 SHA\n\n## Verification\n\n- `./shifu check:gate-catalog`\n- `./shifu check:source`\n- upstream Buildchain complete check (860 tests) and merge-group: https://github.com/kungfu-systems/buildchain/actions/runs/30201397854\n- reproduced predecessor startup failure: https://github.com/kungfu-systems/kungfu/actions/runs/30201044580\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This maintenance fix updates an exact reusable-workflow pin and its generated authority projection without changing an architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe exact reusable-workflow SHA is covered by the Gate catalog, source acceptance, and the upstream v3 merge-group.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T12:13:28Z",
          "mergedAt": "2026-07-26T12:34:15Z",
          "additions": 5,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1898,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1898",
          "title": "chore(release): sync v3 alpha state for adapter fix",
          "body": "## Summary\n\n- merge the protected v3 alpha version state back into dev\n- preserve the published `3.0.1-alpha.3` identity\n- regenerate the v3 site contract bundle from the reconciled tree\n- unblock the reviewed auditable-demo adapter correction for dev-to-alpha promotion\n\n## Validation\n\n- `pnpm run check` (861/861)\n- action bundle integrity passed\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-26T12:35:21Z",
          "mergedAt": "2026-07-26T12:38:23Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1897,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1897",
          "title": "release(v3): promote auditable demo adapter fix to alpha",
          "body": "## Release intent\n\nPromote the reviewed v3 auditable-demo adapter environment correction from protected `dev/v3/v3.0` to `alpha/v3/v3.0`.\n\n## Included evidence\n\n- protected implementation PR #1896\n- independent approval on exact source commit `e471ae0c26eb677ef7ec6f37e31b38748a524681`\n- repository check 861/861\n- downstream failure retained at kungfu Actions run 30195697999 with diagnostic artifact 8631839439\n\nThe promotion must publish an immutable exact prerelease before Kungfu updates its Buildchain contract lock.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T12:30:22Z",
          "mergedAt": "2026-07-26T12:39:57Z",
          "additions": 644,
          "deletions": 404,
          "changedFiles": 55
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1899,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1899",
          "title": "fix(promotion): close v3 stable input surface",
          "body": "## Summary\n- declare the four alpha-only activation inputs unsupported by the stable v3 workflow shell\n- regenerate the public promotion router without invalid stable calls\n- cover the exact stable input closure in regression tests\n\n## Verification\n- `node --test tests/promotion-channel-router.test.mjs`\n- `pnpm run check:workflows`\n- `pnpm run check` (861 tests, action bundle integrity passed)\n\n## Consumer impact\nUnblocks external `@v3-alpha` release-candidate promotion workflows that currently fail GitHub startup validation before any job is created.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T12:39:59Z",
          "mergedAt": "2026-07-26T12:46:36Z",
          "additions": 20,
          "deletions": 9,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1900,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1900",
          "title": "Prepare v3.0.1-alpha.4",
          "body": "Create the generated version-state commit for v3.0.1-alpha.4.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: 3a01e45adedac327dd6095cff8cc83106fb7aa67 -> 3a93cc3ce87fd8c5239c5199f705fb14b55c7808\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T12:44:22Z",
          "mergedAt": "2026-07-26T12:49:22Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 157,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/157",
          "title": "feat: add Get Kungfu acquisition path",
          "body": "## Summary\n- reorder the primary navigation around supply chain, builders, developers, papers, and about\n- promote Get Kungfu to a top-level acquisition CTA\n- turn the install route into a GUI and CLI landing page with honest per-surface availability\n- preserve the signed CLI publication boundary and command-line anchor after activation\n\n## Validation\n- corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- bash -n scripts/check-site.sh\n- shellcheck scripts/check-site.sh\n- node --check scripts/import-bootstrap-publication.mjs\n- browser QA at 1440x900, 1024x900, and 390x844 with zero horizontal overflow\n\n## Release boundary\nMerge to main should publish staging and open/update the production handoff. This change does not authorize production deployment.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T12:46:23Z",
          "mergedAt": "2026-07-26T12:49:58Z",
          "additions": 189,
          "deletions": 77,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1543,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1543",
          "title": "fix(gui): render qualification sessions as live transcripts",
          "body": "## Summary\n\nMake Agent Qualification Lab read like two real, side-by-side agent terminals instead of a static scripted reveal. Public activity now advances one event per second, while verdict findings receive a sequential 520 ms emphasis after completion.\n\nThe transcript deliberately projects canonical action boundaries rather than exposing private chain-of-thought or unbounded provider stdout.\n\nThis branch also repairs two pre-existing mainline contract projections uncovered by the full build: the primitive policy root and the Buildchain 3.0.0 KFD metadata/evidence now align with KFD 1.0.0-alpha.41.\n\n## Related issue\n\nUser dogfood feedback: Agent Qualification Lab terminal realism and verdict pacing.\n\n## Changes\n\n- render user prompts, public agent progress, tool calls, bounded outputs, status, and a live cursor in both session panes\n- pace transcript entries at 1000 ms across offline, same-agent, and cross-agent modes\n- reveal verdict findings sequentially at 520 ms\n- keep navigation outside the Lab and reset playback when mode or agent selection changes\n- refresh canonical policy and Buildchain KFD evidence after upstream dependency drift\n\n## Verification\n\n- `./shifu check`\n- `./shifu build`\n- `./shifu test:kfx-profile-suite` (Agent Qualification Lab 7/7)\n- `./shifu exec node developer/sdk/src/sdk.js contract audit --json` (`ok: true`, `status: current`)\n- staged repository gate after merging `origin/dev/v4/v4.0`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix changes Lab playback presentation and refreshes generated contract projections without changing an architecture contract.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (in-product Lab guidance and visual contract)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T12:21:44Z",
          "mergedAt": "2026-07-26T12:57:18Z",
          "additions": 613,
          "deletions": 152,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1902,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1902",
          "title": "chore(release): reconcile v3 alpha input-closure ancestry",
          "body": "Merge the current protected Alpha version-state lineage back into dev so PR #1901 can promote the reviewed stable-input-closure fix without a generated contract conflict.\n\nThe only conflict was `dist/site/buildchain-contract.json`; it was regenerated from the merged source and verified with `pnpm run check:site` plus the 12 promotion-router tests.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T12:54:28Z",
          "mergedAt": "2026-07-26T12:57:47Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1901,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1901",
          "title": "Promote v3 stable input closure to Alpha",
          "body": "Promote the current protected v3 development head to Alpha after PR #1899 closed the public router's stable input surface.\n\nThis release intent is required to move `v3-alpha` to a workflow revision that external consumers can compile.\n\nConsumer proof: libnode release run 30201967474 fails at startup because the prior router passes four undeclared stable inputs; the regression now prevents that invalid call shape.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T12:47:54Z",
          "mergedAt": "2026-07-26T12:59:07Z",
          "additions": 20,
          "deletions": 9,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1904,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1904",
          "title": "fix(gates): provision declared Rust capability",
          "body": "## Summary\n\nMake the reusable Shifu Gate workflow fulfill its declared `rust` runner capability instead of only exposing pre-existing Cargo paths.\n\n- provision a per-job Rust toolchain on Windows using the same rustup path already proven by the reusable Build workflow\n- provision the requested pinned toolchain on POSIX runners with the pinned `dtolnay/rust-toolchain` action\n- expose Rust mirror and Cargo registry inputs to consumers\n- regenerate the published workflow contract projections\n\nCloses #1888.\n\n## Evidence\n\nKungfu Patrol run 30202335420 reached all three Gate runners after the exact-SHA checkout fix, but Windows exited 127 because `shifu.cmd` could not find `fnm`/Cargo after the prebuilt runtime 404. The formal Windows Build job provisions Rust per job and succeeds; this ports that capability contract to Gate runners.\n\n## Verification\n\n- `pnpm run generate:site`\n- targeted `build-surface.test.mjs`\n- `pnpm run check:workflows`\n- `pnpm run check` (861 tests, 5 action bundles)\n\n## Governance\n\nThis changes only runners whose gate matrix declares the `rust` capability. Toolchain and mirror selection remain caller-controlled inputs; no release or publication authority is added.\n\n## Checklist\n\n- [x] DCO sign-off\n- [x] Generated contracts refreshed\n- [x] Full local verification passed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T12:57:08Z",
          "mergedAt": "2026-07-26T13:03:46Z",
          "additions": 132,
          "deletions": 21,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1905,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1905",
          "title": "Prepare v3.0.1-alpha.5",
          "body": "Create the generated version-state commit for v3.0.1-alpha.5.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: 993ca925115cecaff32f0552d2b6ba1c1d448d0f -> 1bab2b21407df2ccec16bd511fbfd3b2a59c8815\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T13:03:17Z",
          "mergedAt": "2026-07-26T13:06:29Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1893,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1893",
          "title": "feat(workflow): allow configurable control runners",
          "body": "## Summary\n\n- add an additive `control-runner-json` input to the v3 channel router and advanced reusable build\n- route channel resolution, trust evaluation, contract resolution, controller evidence, artifact transfer, and aggregation through the declared control runner\n- preserve `[\"ubuntu-24.04\"]` as the compatibility default and document the self-hosted trust boundary\n- regenerate the public workflow and contract registries\n\nCloses #1892.\n\n## Validation\n\n- `pnpm run check`\n- generated channel workflow parity\n- 9 advanced and 4 public-router control jobs asserted against the configurable runner contract\n\n## Downstream validation\n\nTemporary validation ref: `train/v3/v3.0/control-runner-routing`. The `infra-kungfu-sites` consumer will exercise the complete reusable workflow on its governed self-hosted runner before this capability is promoted to the floating v3 channel.\n\n## Version impact\n\nMinor, additive workflow-contract surface. Existing callers retain the current GitHub-hosted default.\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider mutation or billing behavior\n- [x] No hosted-service branding or release identity change\n- [x] Release-impact and generated contract evidence updated",
          "author": "dongkeren",
          "createdAt": "2026-07-26T11:56:02Z",
          "mergedAt": "2026-07-26T13:25:04Z",
          "additions": 129,
          "deletions": 55,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1528,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1528",
          "title": "feat(release): optimize Alpha promotion critical path",
          "body": "## Summary\n\n- require the exact successful dev Alpha preflight receipt before promotion and fail closed on commit, tree, workflow, gate, toolchain, policy, platform, and age drift\n- preserve build-once/promote-many lineage and precompute the non-secret publication tail in parallel with macOS signing and notarization\n- emit a machine-readable candidate-to-public-readback timeline with queue, execution, cache, retry, side-effect, artifact-lineage, and low-sample SLO accounting\n- codify P50 <= 60 minutes and P90 <= 90 minutes without weakening fresh signing, notarization, publication, passport, or public-readback gates\n- retain warm-standby as a measured follow-up only; this change makes no runner, service, credential, or network mutation\n\n## Validation\n\n- `./shifu test:alpha-promotion-preflight` (26/26)\n- `actionlint .github/workflows/build.yml .github/workflows/release-new-version.yml`\n- `./shifu docs:check` (103/103)\n- `./shifu check:source` on `ddf2381ba8` against `1a21d38f4d` (Node 636 pass / 10 platform skips; Python 40 + 116 pass; type and format checks pass)\n\n## Release safety\n\n- rehearsal receipts are excluded from real Alpha SLO samples\n- fewer than five real releases remains explicitly low-sample\n- merging this optimization does not trigger publication or transfer production authority; the existing first-public-Alpha goal retains ownership of the live release transaction\n- the first public Alpha after this merge is the protected canary and first real timeline sample; the historical 1.5–2 hour path remains a low-confidence comparison baseline\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"KF-ADR-019f86da-4f90-7b6b-ae6d-76cea57487f2\"],\"summary\":\"Complete a bounded Alpha promotion critical-path stage with exact dev receipt reuse, build-once lineage, parallel non-secret tail preparation, and auditable release SLO receipts.\",\"verification\":[\"Alpha promotion preflight and timeline tests\",\"Build DAG and publication transaction tests\",\"workflow actionlint\",\"documentation gate\",\"source acceptance gate\"]}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-26T08:50:22Z",
          "mergedAt": "2026-07-26T13:33:20Z",
          "additions": 2064,
          "deletions": 16,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1908,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1908",
          "title": "fix(release): reconcile v3 alpha ancestry for control runner promotion",
          "body": "Merges the current protected `alpha/v3/v3.0` ancestry into `dev/v3/v3.0` so PR #1907 can use the governed dev-to-alpha path without bypassing branch protection.\\n\\nThe only conflict was the generated `dist/site/buildchain-contract.json`; it was regenerated from the merged source. Local validation passed: site generation check, workflow check, and 92/92 targeted build-surface/release-impact tests.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T13:32:39Z",
          "mergedAt": "2026-07-26T13:35:46Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 159,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/159",
          "title": "fix: align navigation styling and product language",
          "body": "## Summary\n- give ordinary navigation links and the Developers trigger one shared visual system\n- retain only the chevron as the functional distinction for the dropdown\n- describe the desktop surface through stable Agent Work Management value instead of internal product-route names\n- add a site gate against reintroducing Mission Control, Agent Qualification Lab, or Work graph on the Get Kungfu page\n\n## Validation\n- corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- bash -n scripts/check-site.sh\n- shellcheck scripts/check-site.sh\n- browser QA at 1440x900, 1024x900, and 390x844\n- verified equal color, weight, decoration, and 38px interaction height for ordinary navigation and Developers\n- verified zero horizontal overflow and no internal route terminology\n\n## Release boundary\nMerge to main should publish staging and open a production handoff. Production deployment is not authorized by this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T13:33:22Z",
          "mergedAt": "2026-07-26T13:35:47Z",
          "additions": 31,
          "deletions": 7,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1907,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1907",
          "title": "release(v3): promote configurable control runners to alpha",
          "body": "Promotes the reviewed v3 development line to alpha after #1893 added the additive `control-runner-json` reusable workflow input.\\n\\nEvidence:\\n- #1893 merged through the protected dev merge queue.\\n- Verify and GitHub Governance Authority Audit passed.\\n- Build Surface Fixture passed on Linux, macOS, and Windows.\\n- Private consumer `infra-kungfu-sites` completed both repository checks and the full nested infrastructure contract on its repo-scoped agent-120 runner using the train ref.\\n\\nThis PR preserves the governed dev -> alpha -> release publication path; no floating ref is moved manually.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T13:27:54Z",
          "mergedAt": "2026-07-26T13:37:04Z",
          "additions": 246,
          "deletions": 61,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1545,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1545",
          "title": "fix(ci): provision Rust for dev patrol gates",
          "body": "## Summary\n\nBind Dev Verify Patrol to the Buildchain Gate capability contract merged in buildchain#1904 and explicitly request Kungfu’s Rust toolchain inputs.\n\n- pin `.gate-profile.yml` to Buildchain commit `6ddbca28231ecfc1eb62d9d3764a21a3f8813b0b`\n- request Rust 1.96.0 with the existing rsproxy rustup mirrors and Cargo registry variable\n- refresh the closed-world Gate invocation binding and workflow authority digest\n\nThis closes the remaining Windows failure observed in Patrol run 30202335420: the Gate runner declared `rust`, but the prior workflow exposed paths without provisioning the toolchain.\n\n## Related issue\n\n- Closes #1516 after the next fully green three-platform Patrol\n- Upstream: kungfu-systems/buildchain#1904\n\n## Verification\n\n- `./shifu gate:workflow-authority:refresh`\n- `./shifu check:gate-catalog`\n- `./shifu check:source`\n- commit hooks (Gate catalog, workflow authority, docs, invariant checks)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This maintenance fix updates an exact reusable-workflow pin and its generated authority projection without changing an architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe exact reusable-workflow SHA is covered by the Gate catalog, local source acceptance, and the upstream Buildchain three-platform fixture and merge-group.\n\n## Follow-up\n\nAfter merge, dispatch Dev Verify Patrol on `dev/v4/v4.0`; a three-platform green receipt will close #1516 automatically.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T13:12:16Z",
          "mergedAt": "2026-07-26T13:38:43Z",
          "additions": 16,
          "deletions": 7,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1909,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1909",
          "title": "Prepare v3.0.1-alpha.6",
          "body": "Create the generated version-state commit for v3.0.1-alpha.6.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: ac206ef3a65a93d2e7b342c63d07d5d3fbc45d54 -> a0e63dd5dfa62491a57ae94a7e2d1e9571f9066a\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T13:41:51Z",
          "mergedAt": "2026-07-26T13:43:06Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1911,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1911",
          "title": "Release v3.0.1 from qualified v3.0.1-alpha.6",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v3.0.1-alpha.6`\n- Candidate SHA: `a0e63dd5dfa62491a57ae94a7e2d1e9571f9066a`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v3/v3.0`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T13:50:07Z",
          "mergedAt": "2026-07-26T13:51:28Z",
          "additions": 6371,
          "deletions": 1025,
          "changedFiles": 119
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 161,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/161",
          "title": "fix: fingerprint shared stylesheet assets",
          "body": "## Summary\n- fingerprint the shared stylesheet from its exact SHA-256 content during every site build\n- rewrite every generated HTML entry to the fingerprinted asset path\n- verify fingerprint bytes and reject stale stylesheet references in the site gate\n\n## User-visible fix\nExisting browsers could retain `/assets/site.css` for one hour and combine old navigation styles with newly deployed HTML. Content-addressed asset paths prevent that cache mismatch.\n\n## Validation\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- bash -n scripts/build-site.sh scripts/check-site.sh\n- shellcheck scripts/build-site.sh scripts/check-site.sh\n- node --check scripts/fingerprint-site-assets.mjs\n- verified 17 generated HTML references use `/assets/site.d98b9ae22ebb.css`\n- browser network QA confirmed a 200 response from the fingerprinted path and equal navigation computed styles\n\n## Release boundary\nMerge to main should publish staging and open a production handoff. Production deployment is not authorized by this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T13:51:31Z",
          "mergedAt": "2026-07-26T13:53:00Z",
          "additions": 74,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1912,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1912",
          "title": "Release v3.0.1",
          "body": "Create the generated version-state commit for v3.0.1.\n\nBuildchain generated this PR because protected branch release/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: 3988275b9a08a1619041a6a041aceb0ecb00fd58 -> 5c28cea6fbef341794bb0b808b0af87526246cdc\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T13:55:58Z",
          "mergedAt": "2026-07-26T13:59:05Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1906,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1906",
          "title": "refactor(buildchain): refine internal module boundaries",
          "body": "## Summary\n\n- split promotion policy, version-state, GitHub adapter, and durable transaction internals\n- move trust/release CLI dispatch and workflow routing mechanics into capability-owned modules\n- add a machine-readable capability-to-test index and fail-closed dependency checks\n\n## Validation\n\n- pnpm run check (866 tests; 5 action bundles)\n- pnpm run package\n- public CLI, Node API, Action, Workflow, promotion export, compatibility digest, and release-impact sets match the base branch",
          "author": "dongkeren",
          "createdAt": "2026-07-26T13:12:39Z",
          "mergedAt": "2026-07-26T14:07:37Z",
          "additions": 2409,
          "deletions": 1719,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1546,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1546",
          "title": "fix(ci): consume repaired auditable demo runtime",
          "body": "## Summary\n\nConsume the immutable Buildchain `v3.0.1-alpha.4` source that repairs the auditable-demo environment binding while preserving the accepted v3 compatibility surface.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- pin the alpha reusable build, auditable-demo, and promotion workflows to `3a93cc3ce87fd8c5239c5199f705fb14b55c7808`\n- update the alpha contract lock to contract digest `sha256:0cd86ea80b137c5f5a43e8ca14565773fa8958fd946bdcff71856fde940d4e6b`\n- update the isolated alpha npm alias and exact consumer tests\n- refresh workflow authority and release-admission projections\n- keep the standalone Shifu binary pin unchanged because this Buildchain release does not publish standalone platform archives\n\n## Verification\n\n- `./shifu test:auditable-demo` (19 passed)\n- `./shifu test:release-admission` (5 passed)\n- `./shifu check:gate-catalog`\n- `./shifu release:promotion:rehearse -- --report /tmp/kungfu-alpha4-release-promotion-rehearsal.json`\n- `./shifu check`\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix consumes an already reviewed immutable Buildchain runtime and preserves the accepted v3 compatibility and Kungfu architecture contracts.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change updates immutable reusable-workflow and contract coordinates only. Source acceptance, release admission, workflow authority, and promotion rehearsal all pass.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T13:35:21Z",
          "mergedAt": "2026-07-26T14:17:24Z",
          "additions": 33,
          "deletions": 33,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1547,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1547",
          "title": "ci(release): scope portable alpha publishing",
          "body": "## Summary\n\nAdd one fail-closed trusted-publishing mode that publishes only `@kungfu-tech/spec` and `@kungfu-tech/site` from an exact successful Actions source SHA. The existing full-layer publication path remains unchanged.\n\n## Changes\n\n- add the explicit `portable-format-alpha` workflow-dispatch scope\n- rebuild and qualify only the two portable-format archives at the exact bound source revision\n- refuse occupied versions before entering the credential island\n- publish only those archives through the existing GitHub OIDC environment\n- skip Cargo, PyPI, GitHub Release assets, every other npm package, and `latest`\n- verify public registry integrity and run a fresh API/CLI/Python/11-page consumer after publication\n\n## Verification\n\n- `actionlint .github/workflows/publish-layer-artifacts.yml`\n- `./shifu check:npm-package-registry`\n- `./shifu release:promotion:rehearse`\n- `./shifu docs:check` — 105 tests, 0 failures\n- `./shifu check:source` — 648 tests, 638 pass, 10 platform skips, 0 failures\n- staged repository gate passed on commit `0932a32d1c`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7c91-9cc2-6dbd18d68dff\", \"KF-ADR-019f96a2-c686-76e1-9261-f6106aa50429\"],\n  \"summary\": \"Add an exact-source OIDC publication scope restricted to the portable Spec and Site alpha packages, with public-byte and clean-consumer verification.\",\n  \"verification\": [\"actionlint .github/workflows/publish-layer-artifacts.yml\", \"./shifu check:npm-package-registry\", \"./shifu release:promotion:rehearse\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe mode owns a production publication boundary, but it uses no long-lived npm token and is closed to exactly two alpha packages.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T13:56:47Z",
          "mergedAt": "2026-07-26T14:22:23Z",
          "additions": 324,
          "deletions": 33,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 163,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/163",
          "title": "feat: explain the agent-native bootstrap thesis",
          "body": "## Summary\n\n- distinguish Kungfu bootstrapping from ordinary software dogfood\n- explain the minimal human sovereign core and hidden Work Runtime thesis\n- connect relative isolation to the infrastructure forcing condition\n- add desktop navigation separators and bring the bootstrap route under the shared layout\n\n## Verification\n\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- responsive browser checks at 1440px, 1024px, and 390px\n- `git diff --check`\n- `bash -n scripts/check-site.sh scripts/build-site.sh`\n- `shellcheck scripts/check-site.sh scripts/build-site.sh`",
          "author": "dongkeren",
          "createdAt": "2026-07-26T14:22:57Z",
          "mergedAt": "2026-07-26T14:24:25Z",
          "additions": 153,
          "deletions": 56,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1914,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1914",
          "title": "fix(release): admit tree-equivalent recovery receipts",
          "body": "## Summary\n- accept a controller receipt across durable stable recovery only when built-source and promotion-channel tree SHAs are both present and equal\n- retain the existing source-aligned tree-equivalence path\n- add a regression test for the v3.0.1 recovery failure\n\n## Verification\n- `node --test tests/release-passport.test.mjs tests/promote-buildchain-ref.test.mjs` (206/206)\n- `pnpm run check` (867/867; action bundle integrity passed)\n\nFixes #1913",
          "author": "dongkeren",
          "createdAt": "2026-07-26T14:22:48Z",
          "mergedAt": "2026-07-26T14:28:20Z",
          "additions": 108,
          "deletions": 48,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1915,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1915",
          "title": "Release v3.0.1",
          "body": "Create the generated version-state commit for v3.0.1.\n\nBuildchain generated this PR because protected branch release/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: 7f9e762b8a95c6154e279be9f4d430bf12ea43a9 -> 513d46c8727c43ed67c477b48b554a58ca730cc4\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T14:35:05Z",
          "mergedAt": "2026-07-26T14:38:49Z",
          "additions": 9,
          "deletions": 9,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1548,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1548",
          "title": "fix(verify): make dev patrol deterministic",
          "body": "## Summary\n\nMake the final Dev Verify Patrol product gate deterministic across Windows and Linux.\n\n- keep the SDK fallback Python resolution explicitly frozen so Windows cannot update the canonical Core uv lock\n- give the bounded 1k-Episode smoke workload enough time on the slower Linux qualification runner\n- replace the LangChain cross-writer timestamp ordering assertion with stronger semantic evidence that the final model turn consumed the real tool output\n\n## Related issue\n\n- Closes #1516 after the next fully green three-platform Patrol\n- Follow-up to #1545\n\n## Verification\n\n- `./shifu check:source`\n- `pnpm --filter @kungfu-tech/sdk run build` (32/32)\n- `node --test scripts/source-acceptance.test.mjs` (21/21)\n- staged Ruff, Biome, documentation, invariant, Gate catalog, and KFD evidence checks\n- Linux and Windows root causes reproduced from Patrol run 30204489159 receipts and full job logs\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This maintenance fix corrects cross-platform verification determinism without changing an architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Follow-up\n\nAfter merge, dispatch Dev Verify Patrol on `dev/v4/v4.0`; a three-platform green receipt will close #1516 automatically.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T14:33:31Z",
          "mergedAt": "2026-07-26T14:46:50Z",
          "additions": 87,
          "deletions": 23,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1919,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1919",
          "title": "fix(release): converge completed stable recovery",
          "body": "## Summary\n- treat a complete-but-not-yet-settled stable transaction as published material during protected version-state recovery\n- preserve the transaction lifecycle identity instead of regenerating source-bound site files on every retry\n- cover convergence after the protected version-state merge\n\n## Validation\n- `node --test tests/promote-buildchain-ref.test.mjs` (139/139)\n- `pnpm run check` (867/867; action bundle integrity passed)\n\nFixes #1917",
          "author": "dongkeren",
          "createdAt": "2026-07-26T14:53:59Z",
          "mergedAt": "2026-07-26T14:57:28Z",
          "additions": 5,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1549,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1549",
          "title": "docs: clarify the agent-native bootstrap thesis",
          "body": "## Summary\n\nClarify why Kungfu bootstraps from a deliberately minimal human sovereign core: not as ordinary dogfood or a small-team boast, but to expose and externalize the hidden human Work Runtime before participation scales.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- distinguish the bootstrap thesis from ordinary product dogfooding\n- explain how human organizations can mask missing memory, coordination, fact, permission, and acceptance infrastructure\n- define the sequence from minimal sovereign core to machine-readable Work Runtime to broader participation\n- explain why relative isolation was a forcing condition rather than incidental project mythology\n- align the public essay linked from kungfu.tech with the staging-site narrative\n\n## Verification\n\n- `./shifu docs context --task \"Align the public bootstrapping essay with the minimal human sovereign core and hidden Work Runtime thesis\" --role implementer --budget 16000 --route kungfu-agent-surfaces --json`\n- `./shifu docs:check`\n- `./shifu docs:prose` (0 errors; 6 advisory warnings)\n- `./shifu docs authoring --since origin/dev/v4/v4.0 --json` (bounded; human review required)\n- `./shifu check:source`\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This documentation-only clarification does not alter runtime behavior or an architecture contract\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T14:45:16Z",
          "mergedAt": "2026-07-26T15:01:45Z",
          "additions": 128,
          "deletions": 73,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1922,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1922",
          "title": "fix(release): carry stable recovery runtime onto release line",
          "body": "## Summary\n\n- admit tree-equivalent release-candidate controller receipts during durable recovery\n- preserve completed stable transaction lifecycle identity during protected release-line recovery\n- regenerate the exact action and public-site bundles from the release line\n\n## Why this targets the release line\n\nThe recovery workflow shell is dispatched from dev, but the governed promotion runtime is pinned to the protected release channel commit. The already-reviewed dev fixes in #1914 and #1919 therefore need this reviewed release-line carry before the durable v3.0.1 transaction can converge.\n\n## Validation\n\n- `node --test tests/release-passport.test.mjs` (67/67)\n- `node --test tests/promote-buildchain-ref.test.mjs` (139/139)\n- `pnpm run check` (862/862; 5 action bundles current)\n\nThis does not republish npm and does not move the immutable `v3.0.1` tag.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T15:15:20Z",
          "mergedAt": "2026-07-26T15:18:42Z",
          "additions": 111,
          "deletions": 51,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1923,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1923",
          "title": "feat(kfd): add governed product gates",
          "body": "## Summary\n\n- accept product-declared KFD-3 collaboration surfaces and report the exact verification mode\n- add governed, fail-closed product gates for KFD-4, KFD-5, and KFD-7 using the real KFD WASM verifier\n- add a 13-row support projection and release-passport evidence that prevents candidate, unsupported, or draft claims from widening into shipped support\n- publish the contracts through CLI, Node API, generated site schemas, docs, reusable workflow inputs, and the bundled promotion action\n\n## Verification\n\n- `pnpm run check` — 873 tests passed; architecture, inventory, site reproducibility, workflows, and all 5 action bundles passed\n- positive and adversarial tests cover stale evidence, source drift, symlink escape, recomputed projection tampering, and release-passport sibling tampering\n- real Kungfu KFD-3 query passes 166 declared capabilities with `verificationMode=product-declared-registry`\n\n## Claim boundary\n\nKFD-4 and KFD-5 remain candidate-only; KFD-6 remains unsupported; KFD-8 through KFD-13 remain draft. KFD-7 can qualify only through an activated domain profile, independent review, product witnesses, and all 13 required obligation categories. No gate self-certifies shipped support.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T15:20:38Z",
          "mergedAt": "2026-07-26T15:23:51Z",
          "additions": 2777,
          "deletions": 234,
          "changedFiles": 66
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1925,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1925",
          "title": "docs(release): bind line-scoped finalization recovery",
          "body": "## Summary\n\n- document the exact machine-verifiable release-line recovery branch contract\n- regenerate public site projections from the protected v3 release line\n- establish a valid line-scoped recovery PR lineage for the already-reviewed runtime fixes in #1922\n\n## Validation\n\n- `pnpm run check:site`\n- `git diff --check`\n- same runtime source from #1922 already passed 862/862 full checks\n\nThis PR does not publish packages or move immutable release tags.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T15:23:04Z",
          "mergedAt": "2026-07-26T15:27:03Z",
          "additions": 12,
          "deletions": 7,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1928,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1928",
          "title": "fix(release): reconcile v3 alpha ancestry for KFD gate promotion",
          "body": "## Summary\n\nReconcile the current `alpha/v3/v3.0` ancestry into `dev/v3/v3.0` before promoting the governed KFD product gates. This follows the existing v3 recovery pattern used by #1908 and makes the open dev-to-alpha release-intent PR #1927 mergeable.\n\n## Scope\n\n- preserve the current alpha version state `3.0.1-alpha.6`\n- regenerate the seven version-bound site and release-impact files\n- retain the KFD-3, KFD-4, KFD-5, KFD-7, support-projection, and release-passport contracts from #1923\n- no support claim is widened by the ancestry merge\n\n## Verification\n\n- `pnpm run check`\n- 873 tests passed\n- architecture, inventory, site reproducibility, workflows, and all 5 Action bundles passed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T15:31:05Z",
          "mergedAt": "2026-07-26T15:35:27Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1927,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1927",
          "title": "release(v3): promote governed KFD product gates to alpha",
          "body": "## Release intent\n\nPromote the current reviewed `dev/v3/v3.0` line to `alpha/v3/v3.0` so the governed KFD product-gate contracts become available on the v3 alpha train.\n\n## Included KFD boundaries\n\n- KFD-3 product-declared collaboration surfaces are source-bound and report their verification mode\n- KFD-4 and KFD-5 remain candidate-only\n- KFD-6 remains unsupported\n- KFD-7 requires an activated domain profile, independent review, product witnesses, and all 13 obligation categories\n- KFD-8 through KFD-13 remain draft\n- support projection and release-passport evidence fail closed against claim widening\n\n## Evidence\n\n- source delivery: #1923\n- `pnpm run check`: 873 tests passed, including architecture, inventory, site reproducibility, workflows, and Action bundle integrity\n- merge-queue verification passed on exact dev merge commit `bc581a0212a509c32ac74f240177d3359cece569`",
          "author": "dongkeren",
          "createdAt": "2026-07-26T15:25:54Z",
          "mergedAt": "2026-07-26T15:36:48Z",
          "additions": 5186,
          "deletions": 1893,
          "changedFiles": 81
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1931,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1931",
          "title": "Prepare v3.0.2-alpha.0",
          "body": "Create the generated version-state commit for v3.0.2-alpha.0.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: ed47430f8cadfc327c52004aae9e5ef62aaa6e37 -> b8aafa654c622c8a3bdab5ca29b071f8377be7f6\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T15:43:58Z",
          "mergedAt": "2026-07-26T15:45:24Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1929,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1929",
          "title": "feat: add structured cache evidence and ruleset creation",
          "body": "## Summary\n\n- add content-addressed cache operation receipts and evidence sets with exact source, runtime, toolchain, policy, platform, and profile bindings\n- classify hit, miss, partial, bypassed, poisoned, and unavailable outcomes with honest measured durations, bytes, and saved-time provenance\n- add generic GitHub ruleset create/readback/rollback support and create governance plan output directories safely\n- regenerate reusable workflows, site contracts, and bundled actions\n\n## Verification\n\n- pnpm check\n- 873 tests passed\n- workflow/site generation checks passed\n- action bundle integrity passed\n- live read-only Kungfu Alpha ruleset plan succeeded against kungfu-systems/kungfu\n\n## Consumer validation\n\nKungfu Alpha consumer tests pass against this exact train SHA; the downstream PR will pin the merged Buildchain commit before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T15:32:34Z",
          "mergedAt": "2026-07-26T15:49:31Z",
          "additions": 1277,
          "deletions": 113,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1553,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1553",
          "title": "feat(dogfood): harden operational feedback loop",
          "body": "## Summary\n\nHarden the native Dogfood Feedback Domain Profile so operators can diagnose exact Profile-root drift without mutation, explicitly recover with a rooted plan, inspect one Finding or Issue locally, propose owned Issues, reconcile evidence without automatic transitions, and project truthful deduplicated health.\n\n## Related issue\n\nNative Assignment `2026-07-26-kungfu-dogfood-operational-hardening`.\n\n## Changes\n\n- add read-only Profile diagnosis and exact-root recovery planning/application\n- add local lookup, deterministic Issue proposals, read-only reconciliation, and operational health projections\n- expose the new surfaces through the installed CLI and generated KFD/CLI contracts\n- cover real dogfood regression roots, lifecycle legality, no-write reads, idempotent recovery, and installed-product behavior\n\n## Verification\n\n- `./shifu build:core`\n- focused Dogfood and Workspace Federation regression suite: 50 passed\n- `./shifu test:kfx-profile-suite`\n- `./shifu test:profile-kfd3-qualification`\n- `./shifu check:cli-catalog-parity`\n- `./shifu kfd:buildchain:check`\n- signed macOS Product build plus disposable installed-workspace capture/admit/transition/show/query/health/reconcile qualification\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-71be-a2aa-c8744fa340d8\"],\n  \"summary\": \"Deliver the bounded operational-hardening stage for the native Dogfood responsibility loop.\",\n  \"verification\": [\"Dogfood and Workspace Federation regression suite\", \"KFX Profile Suite\", \"KFD-3 qualification\", \"installed macOS Product dogfood\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T15:20:34Z",
          "mergedAt": "2026-07-26T16:19:49Z",
          "additions": 1696,
          "deletions": 57,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1554,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1554",
          "title": "fix(ci): normalize MSVC patrol diagnostics",
          "body": "## Summary\n\nKeep the Windows Dev Verify Patrol inside its bounded Gate output contract.\n\n- set `VSLANG=1033` for the cross-platform Gate environment so MSVC emits the English `/showIncludes` prefix that Ninja recognizes and filters\n- prevent localized dependency diagnostics from filling the 256 MiB synchronous process buffer\n- bind the workflow change through source acceptance and refresh its governed workflow digest\n\n## Related issue\n\n- Follow-up to #1516\n- Root cause observed in Dev Verify Patrol run 30206822276\n\n## Verification\n\n- `./shifu check:source`\n- `node --test scripts/source-acceptance.test.mjs` (23/23)\n- `git diff --check`\n- staged documentation, Gate catalog, source acceptance, workflow authority, Biome, invariant, and KFD evidence checks\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This CI maintenance fix normalizes compiler diagnostics without changing an architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Follow-up\n\nAfter merge, dispatch Dev Verify Patrol on `dev/v4/v4.0`; a three-platform green receipt will close #1516 automatically.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T15:55:36Z",
          "mergedAt": "2026-07-26T16:19:50Z",
          "additions": 10,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1557,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1557",
          "title": "feat(release): harden Alpha evidence and governance",
          "body": "Supersedes #1555 with the exact same verified tree on a single linear commit because this repository merge queue uses REBASE and rejected the earlier merge-commit history.\n\n## Summary\n\nHarden the Alpha release path so exact dev evidence is reused without duplicate builds, every cache decision and latency phase is machine-auditable, and the candidate branch is governed by an exact fail-closed ruleset contract.\n\nThis PR does not publish Alpha or run the release workflow.\n\n## Related work\n\n- Native Assignment: 2026-07-26-kungfu-alpha-release-protection-telemetry-hardening\n- Buildchain train: https://github.com/kungfu-systems/buildchain/pull/1929\n\n## Changes\n\n- consume the merged Buildchain cache-evidence runtime and preserve exact build-once candidate lineage\n- classify cache outcomes as hit, miss, partial, bypassed, poisoned, or unavailable with source, toolchain, artifact, duration, byte, and saved-time bindings\n- emit structured release timelines covering queue, execution, retries, side effects, public readback, and honest low-sample SLO accounting\n- append completed release evidence to a bounded content-addressed Git history while excluding rehearsals and incompatible contracts from real Alpha percentiles\n- check in an exact alpha/v4/v4.0 ruleset contract plus inspect, plan, apply, readback, rollback, and negative-drift tests\n- retain fresh signing, notarization, publication, passport, and readback authority\n\n## Verification\n\n- ./shifu test:alpha-promotion-preflight: 39 passed\n- release admission, auditable demo, and source acceptance focused suite: 33 passed\n- ./shifu check: passed after merging current dev/v4/v4.0\n- staged DCO and documentation gates: passed\n- Buildchain PR #1929: merged after full macOS, Linux, Windows, governance, and merge-queue checks\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7b6b-ae6d-76cea57487f2\"],\n  \"summary\": \"Complete the Alpha release protection and telemetry hardening stage with exact candidate reuse, structured cache and latency evidence, durable history, and exact branch governance.\",\n  \"verification\": [\"Alpha promotion preflight suite\", \"release admission and source acceptance suites\", \"full Shifu check\", \"Buildchain cross-platform merge-queue validation\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change adds no bypass actor and grants no new secret-bearing step. Live candidate-branch rules will be applied only from the merged contract with exact readback and rollback evidence.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated\n- [x] No Alpha publication is triggered by this PR",
          "author": "dongkeren",
          "createdAt": "2026-07-26T16:31:08Z",
          "mergedAt": "2026-07-26T16:51:54Z",
          "additions": 2049,
          "deletions": 91,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1934,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1934",
          "title": "fix(gates): stream long profile output",
          "body": "## Summary\n\nKeep long Shifu Gate executions outside the bounded JSON capture buffer.\n\n- stream `gate run` stdout/stderr directly to the runner log\n- retain the 16 MiB bounded capture for plan and receipt-validation JSON commands\n- prove a Gate producing 17 MiB of output still writes and validates its receipt and execution record\n\n## Evidence\n\nKungfu Dev Verify Patrol run 30210195339 produced a passing, qualifying Windows receipt for source `59ad881852bf3debb181b9e91953ce8700b071d5`, but the reusable Buildchain wrapper exited before receipt validation because its outer `spawnSync` capture remained capped at 16 MiB. The uploaded artifact contained `receipt.json` but no `validation.json` or `execution.json`.\n\nFollow-up to kungfu-systems/kungfu#1516.\n\n## Verification\n\n- `node --test tests/gate-profile.test.mjs` (9/9)\n- 17 MiB output regression fixture\n- `pnpm run check` (868/868 tests, workflow checks, site bundle, 5 action bundles)\n- `pnpm exec prettier --check scripts/shifu-gate-profile.mjs tests/gate-profile.test.mjs`\n- `git diff --check`\n\n## Governance\n\nThis changes only subprocess output transport for the long Gate execution. Plan and validation JSON remain bounded and captured; Gate policy, receipt semantics, release authority, and publication authority are unchanged.\n\n## Checklist\n\n- [x] DCO sign-off\n- [x] Full local verification passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T17:10:06Z",
          "mergedAt": "2026-07-26T17:15:12Z",
          "additions": 126,
          "deletions": 22,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1560,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1560",
          "title": "fix(ci): allow manual S3 artifact relay",
          "body": "## Summary\n\n- expose the existing Buildchain `s3-to-github-artifacts` transport as an explicit manual Build input\n- keep `github-artifacts` as the manual default while preserving S3 relay for protected alpha/release events\n- refresh workflow authority bindings and lock the input contract with tests\n\nSupersedes #1552 and #1558 with a linear branch based on the latest protected dev head.\n\n## Evidence\n\n- `./shifu test:auditable-demo` (19/19)\n- `./shifu check:gate-catalog` (38 gates, 19 workflows aligned)\n- full managed staged gate passed at `c96e0f473f`\n- prior exact-source Build run `30195629750` completed all Linux, Windows, and macOS lifecycle qualification; only direct GitHub artifact upload failed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Expose an explicit existing artifact-transfer adapter for trusted manual diagnostics; no package, product, or ADR semantics change\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change selects an already protected relay using existing least-privilege OIDC roles. It adds no secret material, publication authority, deployment authority, or package write.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Exact failed Build and annotations cited\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T16:56:43Z",
          "mergedAt": "2026-07-26T17:16:04Z",
          "additions": 21,
          "deletions": 6,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1936,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1936",
          "title": "fix(build): reuse artifacts across workflow attempts",
          "body": "## Summary\n\n- force reusable-build artifact downloads onto the REST-backed token path\n- allow failed-job reruns to consume exact artifacts retained by a prior workflow attempt\n- add a contract test that rejects any unauthenticated reusable-build artifact download\n- refresh the generated public contract digest\n\n## Evidence\n\n- `pnpm run check` (880 tests; workflow, site-contract, bundle checks passed)\n- the prior-attempt controller plan from consumer run 30206241930 is downloadable through the REST endpoint with exact digest, while the default attempt-local action path returned 404\n\nCloses #1935\nRelated: #1932",
          "author": "dongkeren",
          "createdAt": "2026-07-26T17:19:21Z",
          "mergedAt": "2026-07-26T17:28:38Z",
          "additions": 28,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1937,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1937",
          "title": "chore(release): sync v3 alpha state for artifact recovery",
          "body": "## Summary\n\n- merge the protected v3 Alpha version state `3.0.2-alpha.0` back into current dev\n- preserve the reviewed cross-attempt artifact download repair from #1936\n- preserve the current Gate-profile output fixes\n- regenerate the public Buildchain contract bundle from the reconciled tree\n\n## Validation\n\n- `pnpm run check:site`\n- `pnpm run check:workflows`\n- `node --test tests/build-surface.test.mjs tests/gate-profile.test.mjs` (98/98)\n- `git diff --check`\n\nThis reconciliation makes the protected dev-to-alpha promotion conflict-free without rewriting either channel.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T17:33:51Z",
          "mergedAt": "2026-07-26T17:38:57Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1562,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1562",
          "title": "fix(ci): pin streamed Gate runtime",
          "body": "## Summary\n\nPin Dev Verify Patrol to the Buildchain runtime that streams long Gate output.\n\n- align the reusable workflow shell and default runtime at Buildchain merge `f8ef93be41b0badd75eb35cc1506c2be12198984`\n- update the closed-world Gate binding and governed workflow digest\n- retain trusted manual exact-SHA/train overrides\n\n## Related issue\n\n- Follow-up to #1516\n- Consumes kungfu-systems/buildchain#1934\n- Patrol run 30210195339 proved Windows `product.verify-full` passes but the prior outer 16 MiB wrapper failed before receipt validation\n\n## Verification\n\n- `./shifu check:source`\n- `node scripts/check-kungfu-gate-catalog.mjs`\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs` (23/23)\n- `node --test scripts/source-acceptance.test.mjs` (23/23)\n- staged governance, documentation, invariant, Gate catalog, Biome, and KFD evidence checks\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This CI maintenance pin consumes a bounded output-transport fix without changing an architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Follow-up\n\nAfter merge, dispatch Dev Verify Patrol on `dev/v4/v4.0`; a three-platform green receipt is the completion gate.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Governance projections updated\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T17:21:17Z",
          "mergedAt": "2026-07-26T17:41:11Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1938,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1938",
          "title": "release(v3): promote artifact recovery to Alpha",
          "body": "## Release intent\n\nPromote the reviewed reusable artifact recovery and current Gate-profile fixes from protected `dev/v3/v3.0` to `alpha/v3/v3.0`.\n\n## Included evidence\n\n- implementation PR #1936, independently approved and merged at protected commit `1094b83655bc40823d42b37c1fec38fbd698cc79`\n- public incident #1935 and consumer run 30206241930 attempt 2 proving the attempt-local download failure\n- protected Alpha-state reconciliation PR #1937\n- same-head repository checks and libnode-shaped multi-platform reusable-build proof\n- local `pnpm run check` before reconciliation (880/880) plus focused reconciled tests (98/98)\n\nThe promotion must publish a new immutable `v3.0.2-alpha.*` release before Kungfu updates its Buildchain contract lock.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T17:39:26Z",
          "mergedAt": "2026-07-26T17:42:17Z",
          "additions": 1428,
          "deletions": 135,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1939,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1939",
          "title": "Prepare v3.0.2-alpha.1",
          "body": "Create the generated version-state commit for v3.0.2-alpha.1.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: e2907057b177af48316db8d85549539c61432a4f -> bfe43b0fe5577f15d2af01bc542de8a8ce587457\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T17:46:39Z",
          "mergedAt": "2026-07-26T17:47:51Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1563,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1563",
          "title": "fix(trunk): preserve signed Python runtime bytes",
          "body": "## Summary\n\nPrevent direct Product trunk dispatch from rewriting precompiled Python bytecode inside a signed application bundle. The desktop wrapper already disables bytecode writes, but Product callers may invoke the trunk binary directly and bypass that wrapper environment.\n\n## Related issue\n\nNative Assignment `2026-07-26-kungfu-dogfood-operational-hardening`; independent closeout review found the signed-bundle regression path.\n\nThis PR supersedes #1561 with the same bounded patch replayed from the latest\n`dev/v4/v4.0` base after merge-queue admission detected duplicated squash\nhistory in the original branch.\n\n## Changes\n\n- pass Python `-B` from the trunk before `-m kungfu`\n- set `PYTHONDONTWRITEBYTECODE=1` at the same process boundary as a second guard\n- lock the Product dispatch argv and environment in a Rust unit test\n\n## Verification\n\n- staged Rust format and clippy checks\n- `cargo test --workspace` through the repository staged gate: 149 tests passed, including `product_python_dispatch_disables_signed_tree_bytecode_writes`\n- signed Product probe: wrapper Dogfood and Work routes preserved the complete App content digest and deep codesign\n- clean Product build and direct-trunk no-bytecode probe will be repeated on the merged candidate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-71be-a2aa-c8744fa340d8\"],\n  \"summary\": \"Keep signed Product Python runtime bytes immutable across direct trunk dispatch.\",\n  \"verification\": [\"staged Rust gate\", \"signed Product direct-trunk probe\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T17:43:08Z",
          "mergedAt": "2026-07-26T18:03:48Z",
          "additions": 54,
          "deletions": 10,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1564,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1564",
          "title": "fix(ci): pin cross-attempt demo runtime",
          "body": "## Summary\n\nConsume the immutable Buildchain `v3.0.2-alpha.1` source that repairs cross-attempt GitHub Artifact downloads for the auditable-demo controller while preserving the accepted v3 compatibility surface.\n\n## Related issue\n\n- https://github.com/kungfu-systems/buildchain/issues/1935\n\n## Changes\n\n- pin every alpha reusable build, auditable-demo, promotion, and Passport Buildchain surface to tag commit `bfe43b0fe5577f15d2af01bc542de8a8ce587457`\n- update the alpha package to `@kungfu-tech/buildchain@3.0.2-alpha.1`\n- update the alpha contract lock to `sha256:b267a2e659ab75433deca4d8f257cee075ca764497132be34c6d2c2f0a0a47c3`\n- preserve compatibility digest `sha256:008b1c5a90a787cf30106829ac7aca68ab501f6d9c375e415d9c5c6b89039f46`\n- refresh workflow authority and release-admission projections\n- keep the standalone Shifu binary pin unchanged because this Buildchain release does not publish standalone platform archives\n\n## Verification\n\n- `./shifu test:auditable-demo` (19 passed)\n- `./shifu test:release-admission` (5 passed)\n- `./shifu check:gate-catalog`\n- `./shifu release:promotion:rehearse -- --report /tmp/kungfu-alpha1-release-promotion-rehearsal.json`\n- `./shifu check:source`\n- `./shifu check` (changed-scope gate passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix consumes an already reviewed immutable Buildchain runtime and preserves the accepted v3 compatibility and Kungfu architecture contracts.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change updates immutable reusable-workflow, package, and contract coordinates only. Source acceptance, release admission, workflow authority, and promotion rehearsal all pass.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T18:16:14Z",
          "mergedAt": "2026-07-26T19:07:36Z",
          "additions": 33,
          "deletions": 33,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1565,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1565",
          "title": "fix(ci): extend Episode qualification budget",
          "body": "## Summary\n\nGive the unchanged load-bearing Episode qualification smoke a bounded 30-minute budget on slower Linux Patrol runners.\n\n- retain the exact MVP smoke profile, seed, 1,000-Episode accumulation, and contention matrix\n- raise only the subprocess timeout from 15 to 30 minutes\n- update the source contract assertion so the budget cannot drift silently\n\n## Related issue\n\n- Follow-up to #1516\n- Patrol run 30213113136 reached the final workers=10 contention lane and then timed out exactly at the prior 15-minute bound\n- macOS and Windows passed on the same exact source SHA; Linux produced complete streamed receipt artifacts and failed only this bounded timeout\n\n## Verification\n\n- `node --test scripts/source-acceptance.test.mjs` (23/23)\n- `./shifu check:source` (651 Node tests: 641 pass, 10 environment skips; Python 40 + 116 pass; documentation, contracts, type checks, and Biome pass)\n- staged governance, documentation, invariant, Gate catalog, Biome, and KFD evidence checks\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This CI maintenance change adjusts only a bounded qualification timeout without changing the workload or an architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Follow-up\n\nAfter merge, dispatch Dev Verify Patrol on `dev/v4/v4.0`; a three-platform green receipt is the completion gate.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Workload shape and deterministic seed remain unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-26T18:37:58Z",
          "mergedAt": "2026-07-26T19:07:37Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1559,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1559",
          "title": "feat(kfd): govern Kungfu support claims",
          "body": "## Summary\n\nGovern Kungfu's KFD support as one exact, release-bound matrix: KFD-1, KFD-2, KFD-3, and KFD-7 are the bounded Alpha shipped-support set; KFD-4 remains a passed non-shipped candidate; KFD-5 remains a failed non-shipped candidate; KFD-6 is unsupported; KFD-8 through KFD-13 remain draft adopter evidence.\n\n## Related issue\n\n- Atlas go `2026-07-26-kungfu-kfd-support-governance`\n- Buildchain product-gate delivery: https://github.com/kungfu-systems/buildchain/pull/1923\n\n## Changes\n\n- Upgrade the Buildchain Alpha consumer to `@kungfu-tech/buildchain@3.0.2-alpha.0` and bind the exact protected workflow SHA and contract lock.\n- Remove Kungfu's local KFD-3 fallback and require Buildchain's product-declared registry audit for all 166 declared capabilities.\n- Generate exact-source KFD-4, KFD-5, and KFD-7 product gates and include them with the support matrix in the release passport.\n- Enforce the exact shipped-support set KFD-1/KFD-2/KFD-3/KFD-7 with fail-closed matrix checks and negative fixtures.\n- Expose the governed KFD-1 through KFD-13 matrix through the SDK and generated documentation.\n- Preserve non-widening boundaries: KFD-4 is candidate-only, KFD-5 retains explicit missing qualification evidence, KFD-6 is unsupported, and KFD-8 through KFD-13 are non-conforming drafts.\n\n## Verification\n\n- `./shifu check`\n- `./shifu lint`\n- `./shifu check:types`\n- `./shifu kfd:buildchain`\n- `./shifu kfd:buildchain:check`\n- `./shifu kfd:support-matrix`\n- `./shifu kfd:support-matrix:check`\n- `./shifu --filter @kungfu-tech/sdk run build`\n- `./shifu test:release-admission`\n- `./shifu test:auditable-demo`\n- Buildchain `@kungfu-tech/buildchain@3.0.2-alpha.0` binary, self-dogfood, and stable-candidate qualification workflows\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-7d81-90a0-d144fc27fe03\",\n    \"KF-ADR-019f86da-4f90-712d-b871-24090476e338\",\n    \"KF-ADR-019f86da-4f90-786d-aa24-a97705e13917\"\n  ],\n  \"summary\": \"Deliver one fail-closed KFD support matrix and exact Buildchain release-passport integration for Kungfu.\",\n  \"verification\": [\n    \"full Shifu check\",\n    \"Buildchain product gates for KFD-4, KFD-5, and KFD-7\",\n    \"negative support-claim fixtures\"\n  ]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR updates the exact Buildchain Alpha package/workflow identity and extends the Kungfu release passport with content-addressed KFD support evidence. It does not add credentials or publishing authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T16:48:32Z",
          "mergedAt": "2026-07-26T19:57:46Z",
          "additions": 3251,
          "deletions": 593,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1566,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1566",
          "title": "fix(spec): normalize canonical LF projections",
          "body": "Fix the Windows-only portable Spec projection and qualification failures exposed by Build run 30212554008. The generator normalizes declared canonical-LF JSON authorities and committed projections before byte-rooting/comparison while retaining strict rejection of semantic drift. Package-manager and Python launchers now resolve native Windows commands, failed npm pack output remains observable, and the independent Python-reader measurement uses an explicit qualification hold wrapper.\n\nValidation:\n- node framework/spec/scripts/generate.js --check\n- node framework/spec/scripts/aggregate.js\n- node framework/spec/scripts/verify.js\n- node --test framework/spec/index.test.js scripts/platform-command.test.mjs\n- ./shifu pack:spec\n- ./shifu layers:qualify:format -- --report product/release/qualification/layer-format-report.json\n- ./shifu qualify:portable-format-packages\n- npm pack --dry-run --foreground-scripts --json\n- full staged pre-commit gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Cross-platform correctness fix for canonical portable Spec projections and their qualification harness; no ADR status or product semantics change.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-26T19:23:42Z",
          "mergedAt": "2026-07-26T20:51:13Z",
          "additions": 131,
          "deletions": 24,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1567,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1567",
          "title": "fix(product): accept governed KFD shipped support",
          "body": "## Summary\n\nRestore Alpha product qualification by aligning the installed KFD smoke with the governed support-matrix contract. The SDK intentionally reports KFD-3 as `source-supported` before Alpha settlement, with separate machine evidence proving that the support is release-qualified and shipped.\n\n## Related issue\n\n- Atlas go `2026-07-26-kungfu-kfd-support-governance`\n- Follow-up to #1559\n- Alpha promotion #1448\n\n## Changes\n\n- Accept the legacy `supported` status for compatibility.\n- Accept `source-supported` only when KFD-3 also has passed verification, a passed Buildchain gate, the `release-qualified-support` claim class, an Alpha release-passport qualification, and `shippedSupport: true`.\n- Add positive and fail-closed negative unit coverage for the installed-product predicate.\n\n## Verification\n\n- `./shifu test:cli-surface-qualification` — 32 passed\n- `./shifu --filter @kungfu-tech/spec run verify` — 7 passed\n- `./shifu check:source` — passed, including KFD evidence, the 13-row support matrix, and all support-matrix negative fixtures\n- Commit-time staged gate — passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix preserves the governed KFD support contract and corrects a stale product-smoke expectation without changing architecture authority or widening support claims.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change tightens product qualification against the already-governed KFD release evidence. It adds no publishing authority and does not weaken the KFD product gates.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not required; the implementation now matches the documented support matrix)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T20:31:37Z",
          "mergedAt": "2026-07-26T20:51:14Z",
          "additions": 60,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1941,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1941",
          "title": "fix(demo): align renderer input normalization",
          "body": "## Summary\n\n- normalize scene defaults and hexadecimal colors before retained root verification\n- normalize optional projection annotations to the renderer's retained contract\n- write the canonical qualified inputs into the Gate bundle and bind its receipt to those bytes\n- make the regression fixture model the renderer's retained normalized inputs across both Gate and full-media verification\n\nCloses #1940.\n\n## Evidence\n\nThe downstream failure was `auditable-demo: renderer scene input root mismatch` after a successful network-disabled render. Kungfu's valid adapter scene used uppercase colors; the renderer retained lowercase colors by contract.\n\n## Verification\n\n- `node --test tests/auditable-demo.test.mjs`\n- `pnpm run check` (882 tests passed; bundle integrity passed)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T20:48:24Z",
          "mergedAt": "2026-07-26T20:51:48Z",
          "additions": 50,
          "deletions": 16,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1942,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1942",
          "title": "chore(release): sync v3 alpha state for renderer normalization",
          "body": "## Summary\n\n- merge the protected v3 Alpha version state `3.0.2-alpha.1` back into current dev\n- preserve the renderer input normalization fix from #1941\n- regenerate the public Buildchain contract bundle from the reconciled tree\n\n## Validation\n\n- `pnpm run check:site`\n- `pnpm run check:workflows`\n- `node --test tests/auditable-demo.test.mjs` (5/5)\n- `git diff --check`\n\nThis reconciliation makes the protected dev-to-alpha promotion conflict-free without rewriting either channel.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T20:53:10Z",
          "mergedAt": "2026-07-26T20:56:25Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1943,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1943",
          "title": "release(v3): promote renderer normalization to Alpha",
          "body": "## Release intent\n\nPromote the reviewed auditable-demo renderer input normalization from protected `dev/v3/v3.0` to `alpha/v3/v3.0`.\n\n## Included evidence\n\n- incident #1940 with exact downstream workflow failure evidence\n- implementation PR #1941, independently approved and merged at protected commit `c738ee984b4f9bd418efd03fbe5226c340f84534`\n- protected Alpha-state reconciliation PR #1942\n- local `pnpm run check` (882/882) and exact Gate/full-media regression (5/5)\n- same-head repository checks and libnode-shaped multi-platform reusable-build proof\n\nThe promotion must publish a new immutable `v3.0.2-alpha.*` release before Kungfu updates its Buildchain contract lock.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T20:56:44Z",
          "mergedAt": "2026-07-26T20:59:30Z",
          "additions": 50,
          "deletions": 16,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1944,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1944",
          "title": "Prepare v3.0.2-alpha.2",
          "body": "Create the generated version-state commit for v3.0.2-alpha.2.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: 86ae13f5a6f0bc49736d843f9026976b779e4286 -> 625384b4927222022a2cd0758399afbf9333ccdc\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T21:03:44Z",
          "mergedAt": "2026-07-26T21:05:00Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1551,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1551",
          "title": "feat(maintainability): add read-only governance floor",
          "body": "## Summary\n\n- add build-free zero-write Shifu discovery routes for architecture, invariants, complexity, amplification, and task-graph queries\n- add a repository-wide code-complexity baseline and P1 regression ratchet with fail-closed waiver validation and anti-gaming fixtures\n- add semantic-amplification and task-graph projections over existing authorities, plus four explicitly retained dependent Assignments for convergence, hotspot decomposition, Linux qualification, and Windows qualification\n- record the accepted staged maintainability-governance ADR and keep its machine navigation projection compact and deterministic\n- make the merge-queue Shifu workspace checkout portable by fetching the target base history on every runner\n- install the frozen workspace inside the existing POSIX and Windows Shifu qualification steps before dependency-backed Gate catalog checks\n\n## Validation\n\n- `./shifu check:source`\n- `./shifu core:architecture:health --json`\n- `./shifu maintainability:complexity --json`\n- `./shifu maintainability:amplification --check --json`\n- `./shifu maintainability:query cli-agent-surface`\n- `./shifu core:affected --base dd91e29f1c70aa4af0e43ef08f04bb8692f150d5 --head e36ecd152c106f255a11eabaa8af2fa291a4ebd1 --json`\n\nAffected-native resolves to the GitHub-hosted Linux native tier, with SDK, Shifu workspace, and KFD queue qualifications required. The final head `e36ecd152c106f255a11eabaa8af2fa291a4ebd1` has full local source acceptance, Project Cut, the workflow authority, recalibrated complexity ratchet, semantic amplification, Gate catalog, Shifu entry contract, staged gate, and diff checks passing against `dd91e29f1c70aa4af0e43ef08f04bb8692f150d5`; GitHub source acceptance re-runs on that exact head.\n\n## Claim boundary\n\nThis PR proves source and protected-checkout behavior on the current macOS checkout. It does not claim Linux or Windows installed-product qualification, physical durability, public release, or completion of the retained authority/hotspot decomposition children.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f9f04-f8bd-7002-a702-1b9f66827ec0\"],\n  \"summary\": \"Stage the read-only composite maintainability regression ratchet for protected review while retaining platform and decomposition follow-ups.\",\n  \"verification\": [\n    \"./shifu check:source\",\n    \"./shifu maintainability:complexity --json\",\n    \"./shifu maintainability:amplification --check --json\",\n    \"./shifu core:affected --base dd91e29f1c70aa4af0e43ef08f04bb8692f150d5 --head e36ecd152c106f255a11eabaa8af2fa291a4ebd1 --json\"\n  ]\n}\n-->\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for the supported read-only routes and claim boundaries\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T15:05:00Z",
          "mergedAt": "2026-07-26T21:40:54Z",
          "additions": 38917,
          "deletions": 6227,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 139,
          "url": "https://github.com/kungfu-systems/libnode/pull/139",
          "title": "Prepare v22.22.2-alpha.0",
          "body": "Create the generated version-state commit for v22.22.2-alpha.0.\n\nBuildchain generated this PR because protected branch dev/v22/v22.22 rejected direct generated bookkeeping.\n\nRejected update: 48c7ebd527bfe3c353968abeaec1b779738c1b3b -> ac2acc85275dc1a22936677d502f185065aac145\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T13:29:15Z",
          "mergedAt": "2026-07-26T21:51:17Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1933,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1933",
          "title": "feat(governance): add exact-source channel candidate patrol",
          "body": "## Summary\n- add a reusable exact-SHA development-to-channel candidate controller\n- require successful same-SHA Dev Patrol and Alpha preflight evidence\n- create only immutable source-lock branches and protected candidate PRs\n- expose the new governance surface in Buildchain documentation and generated registries\n\n## Safety boundary\nThe patrol never merges a candidate PR, moves the target branch directly, publishes npm, creates tags or releases, or changes branch protection.\n\n## Validation\n- `pnpm check` (881 tests; all checks and 5 action bundles passed)\n- live read-only Kungfu dry-run failed closed because the current dev SHA has no successful same-SHA Dev Patrol evidence\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-26T16:14:45Z",
          "mergedAt": "2026-07-26T22:05:38Z",
          "additions": 976,
          "deletions": 23,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1569,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1569",
          "title": "fix(spec): use pinned Python on Windows",
          "body": "## Summary\n\n- Route an unconfigured Windows Python reader invocation through the pinned Shifu uv project instead of assuming a system python.exe.\n- Preserve explicit PYTHON executables and the existing POSIX python3 behavior.\n- Apply the same invocation contract to source-package, clean-install, and layer-format qualification paths.\n\n## Failure evidence\n\n- Alpha Build attempt 2: https://github.com/kungfu-systems/kungfu/actions/runs/30219911489\n- Windows failed after KFD-1/2/3 evidence passed because framework/spec/index.test.js raised spawnSync python.exe ENOENT.\n\n## Validation\n\n- Xinfa Task Chart: kungfu-format-contract-agent, projection sha256:8a04963faebfe937bdab8878f22b34c87c3807b79cf3328bdfdc66d4d89577df\n- ./shifu --filter @kungfu-tech/spec run verify\n- ./shifu pack:spec\n- ./shifu qualify:portable-format-packages\n- ./shifu check\n- ./shifu check:source\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Cross-platform qualification fix for the pinned Python launcher; no format, KFD, or product semantics change.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-26T21:47:30Z",
          "mergedAt": "2026-07-26T22:13:41Z",
          "additions": 128,
          "deletions": 34,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1570,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1570",
          "title": "fix(release): require S3 artifact relay",
          "body": "## Summary\n\nRequire every Kungfu Alpha, release, and manual evidence build to transfer native artifacts through the configured S3 relay. Direct GitHub artifact transfer is no longer selectable.\n\n## Related issue\n\nContinues `2026-07-25-kungfu-npm-core-platform-distribution-closure`.\n\n## Changes\n\n- remove the manual direct-GitHub artifact transfer input\n- pin the Buildchain adapter to `s3-to-github-artifacts` for every activation path\n- update the closed-world workflow binding, authority digest, and maintainability projection\n- document the fail-closed relay and downstream rehydration boundary\n\n## Verification\n\n- `./shifu test:auditable-demo` (19 passed)\n- `./shifu docs:check` (passed)\n- `./shifu check:gate-catalog` (38 gates, 6 profiles, 25 invocations, 19 workflows aligned)\n- `./shifu check:source` (passed; 656 tests passed, 10 platform-conditional skips)\n- staged pre-commit gate (passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This release-transport hardening preserves the accepted Buildchain promotion architecture while removing a diagnostic fallback path.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe workflow references the existing three relay role secrets without changing their values or widening permissions. Contract tests and source acceptance prove the transfer route is literal and fail-closed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T22:20:16Z",
          "mergedAt": "2026-07-26T22:41:44Z",
          "additions": 57,
          "deletions": 30,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1571,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1571",
          "title": "fix(ci): normalize auditable demo renderer inputs",
          "body": "## Summary\n\nConsume immutable Buildchain `v3.0.2-alpha.2`, close the auditable-demo Gate over renderer-normalized retained inputs, and preserve the release-admission mappings required by the current maintainability governance floor. This is a linear-history replacement for #1568; the net patch is byte-for-byte equivalent by stable patch-id, while avoiding the merge-queue replay conflict caused by the prior branch history.\n\n## Related evidence\n\n- Superseded PR: https://github.com/kungfu-systems/kungfu/pull/1568\n- Buildchain incident: https://github.com/kungfu-systems/buildchain/issues/1940\n- Buildchain fix: https://github.com/kungfu-systems/buildchain/pull/1941\n- Immutable release: https://github.com/kungfu-systems/buildchain/releases/tag/v3.0.2-alpha.2\n- Prior exact Kungfu run exposing the mismatch: https://github.com/kungfu-systems/kungfu/actions/runs/30216301917\n\n## Changes\n\n- pin every alpha reusable build, auditable-demo, promotion, and Passport Buildchain surface to tag commit `625384b4927222022a2cd0758399afbf9333ccdc`\n- update the alpha package to `@kungfu-tech/buildchain@3.0.2-alpha.2`\n- update the alpha contract lock to `sha256:d27853cb9230d3288b3c8ce62522e7ad61be04f09890846da01ca22b304584e2`\n- preserve compatibility digest `sha256:008b1c5a90a787cf30106829ac7aca68ab501f6d9c375e415d9c5c6b89039f46`\n- regenerate workflow authority digests and release-admission projections\n- map the three governed release-admission surfaces\n- keep the standalone Shifu binary pin and renderer image digest unchanged\n\n## Verification\n\n- stable patch-id matches #1568 exactly: `82731cba063810ec8f02f7979ee9e7d695842b6c`\n- `./shifu node --test framework/maintainability/semantic-amplification.test.mjs scripts/auditable-demo-workflow.test.mjs scripts/verify-kungfu-release-admission.test.mjs` (16 passed)\n- `./shifu run check:gate-catalog` (38 gates, 6 profiles, 25 invocations, 19 workflows)\n- staged pre-commit gate passed, including deterministic documentation and governance rehearsals\n- full source acceptance is enforced by required PR checks\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix consumes an already reviewed immutable Buildchain runtime and preserves the accepted v3 compatibility, Kungfu architecture contracts, and maintainability governance already present on the protected baseline.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change updates immutable reusable-workflow, package, contract, and governance coordinates only. It grants no publication or deployment authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T22:25:57Z",
          "mergedAt": "2026-07-26T23:36:11Z",
          "additions": 78,
          "deletions": 49,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1573,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1573",
          "title": "feat(governance): schedule dev to alpha candidate patrol",
          "body": "## Summary\n- move Dev Verify Patrol to 04:00 Asia/Shanghai\n- add a thin scheduled Dev-to-Alpha candidate caller at 06:00 Asia/Shanghai\n- pin the reusable Buildchain controller by exact commit\n- require exact same-SHA Dev Patrol and Alpha preflight evidence before creating a source-lock PR\n\n## Related issue\n\nNative Assignment `2026-07-26-kungfu-dev-alpha-patrol`.\n\n## Changes\n\n- register the new workflow and qualification tests in the closed-world Gate authority\n- extend the existing Shifu Gate control-plane ADR with the candidate observation boundary\n- keep Alpha merge, publication, tags, releases, and branch protection outside patrol authority\n\n## Verification\n\n- repository staged gate passed, including workflow authority, docs, invariants, KFD evidence, and formatting\n- candidate/Alpha contract tests: 10/10 passed\n- Gate catalog and candidate tests: 26/26 passed\n- Buildchain controller PR: kungfu-systems/buildchain#1933\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-019f86da-4f90-79a1-bc85-4b542fecf011\"],\n  \"summary\": \"Stage an exact-source Dev-to-Alpha candidate observation after the standing Dev Patrol without granting merge or publication authority.\",\n  \"verification\": [\"repository staged gate\", \"Gate catalog and candidate tests\", \"Buildchain exact-source controller suite\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change observes release evidence and may open a protected candidate PR, but it cannot merge or publish.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T23:00:39Z",
          "mergedAt": "2026-07-26T23:36:12Z",
          "additions": 181,
          "deletions": 9,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1945,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1945",
          "title": "fix(runtime): close native release evidence gaps",
          "body": "## Summary\n\n- force every macOS nested code object to use the Buildchain-owned entitlements file\n- add a four-platform Kungfu native runner preset including GitHub-hosted Linux ARM64\n- regenerate action and site bundles\n\n## Validation\n\n- `pnpm run check`\n- 883/883 unit tests passed\n- workflow, site, and action bundle integrity checks passed\n\n## Downstream\n\nUnblocks the exact-SHA Kungfu v4 release rehearsal for the 29-package npm distribution set. Alpha/release artifact transfer remains S3 relay.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T00:21:44Z",
          "mergedAt": "2026-07-27T00:32:52Z",
          "additions": 153,
          "deletions": 84,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1574,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1574",
          "title": "feat(spec): publish progressive reader journey",
          "body": "## Summary\n\nPublish a progressive, integrity-bound reader journey for the portable format so humans and agents can move from orientation and one verified pickup into task guides, conformance evidence, and complete reference without flattening every detail onto the format landing page.\n\n## Related issue\n\nNative Assignment: `2026-07-27-kungfu-spec-site-progressive-reading`\n\n## Changes\n\n- add a five-level, seven-guide reader journey owned by `@kungfu-tech/spec`\n- expose complete Node API, `kungfu-spec` CLI, independent Python reader, and retained-corpus guidance\n- add corpus inspect, verify, and individual-vector API/CLI surfaces\n- root every guide and project it byte-for-byte into `@kungfu-tech/site`\n- expose integrity-bound Site guide models while keeping `/format/` concise\n- add `./shifu pack:site` and package-local link/API/CLI coverage gates\n\n## Verification\n\n- `./shifu exec pnpm --filter @kungfu-tech/site run test`\n- `./shifu qualify:portable-format-packages`\n- `./shifu check:npm-package-registry`\n- `node scripts/run-docs-check.mjs`\n- `./shifu pack:spec`\n- `./shifu pack:site`\n- fresh tarball consumer: Site-only render, Spec Node API, Spec CLI, and stdlib Python reader\n- exact provenance commit: `636d95b2ac3b207ecc5ea6bc41afb229e3c66f93`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f96a2-c686-76e1-9261-f6106aa50429\"],\n  \"summary\": \"Adds the progressive human and agent consumption layer over the existing rooted portable-format authority and exact Site projection.\",\n  \"verification\": [\"Spec 12 tests\", \"Site and installer 10 tests\", \"portable-format package qualification\", \"documentation gate\", \"npm inventory gate\", \"fresh packed-artifact consumer\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes package contents, pack commands, and provenance-bound Site/Spec projections. It does not publish npm coordinates or deploy a downstream site. Exact-task-commit pack and fresh consumer verification passed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-26T23:30:21Z",
          "mergedAt": "2026-07-27T00:33:20Z",
          "additions": 1784,
          "deletions": 40,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1575,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1575",
          "title": "fix(release): admit regenerated pull merge tree",
          "body": "## Summary\n\n- Persist the Buildchain source tree in Episode release evidence.\n- Keep exact commit identity as the default, while admitting a regenerated refs/pull/N/merge commit only when its anchored tree matches the checked-out source tree.\n- Fail closed for branch refs, missing trees, and mismatched trees, and print the exact failed gate evidence.\n\n## Failure evidence\n\n- Alpha Build attempt 2: https://github.com/kungfu-systems/kungfu/actions/runs/30223060587/attempts/2\n- GitHub regenerated the PR merge commit from 3f2585bfbf1e3e7266dbd5031767c15843e21753 to 33cd317f766bc0ca91d082e4c4dacdb9d13e4013 with identical parents and tree 7ceaf3c3252762100d3d8d39601a08088b900456.\n- Episode qualification passed 13/14 gates; ci_source_revision was the only failed gate.\n\n## Validation\n\n- node --test framework/core/tests/episode-release-evidence.test.mjs (9/9)\n- biome check on the changed JavaScript files\n- node --check on the changed JavaScript files\n- release evidence schema parses with jq\n- full staged pre-commit gate, including KFD-7, KFD Agent Runtime, invariants, ADR, and documentation gates\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Release-evidence identity correction that mirrors the existing Buildchain locked-source pull-merge tree rule; no KFD, format, or product semantics change.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-27T00:19:26Z",
          "mergedAt": "2026-07-27T00:48:06Z",
          "additions": 86,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1947,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1947",
          "title": "chore(release): reconcile v3 alpha state for native closure",
          "body": "Reconcile the protected v3 Alpha version-state ancestry back into dev before promoting the native runner and macOS signing closure.\\n\\nThis is the same two-parent channel reconciliation pattern used by the prior v3 Alpha promotions. It preserves the reviewed runtime changes at aa59fb7216f78e959e2bdd1ff8c147804e3814a6 and adopts the current Alpha version projection 3.0.2-alpha.2.\\n\\nValidation: pnpm run check passed (891 tests, 5 action bundles).",
          "author": "dongkeren",
          "createdAt": "2026-07-27T00:57:05Z",
          "mergedAt": "2026-07-27T01:02:28Z",
          "additions": 14,
          "deletions": 23,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1946,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1946",
          "title": "release(v3): promote native runner and signing closure to Alpha",
          "body": "Promote the reviewed Buildchain v3 runtime that adds the hosted Linux ARM64 runner preset and closes nested macOS credential-island entitlements.\\n\\nSource runtime: aa59fb7216f78e959e2bdd1ff8c147804e3814a6\\nDownstream purpose: Kungfu four-platform evidence with a bounded Linux ARM64 Core lane and signed Alpha/Release artifacts.\\n\\nValidation: PR #1945 check suite passed; protected Alpha promotion checks remain authoritative.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T00:48:43Z",
          "mergedAt": "2026-07-27T01:06:03Z",
          "additions": 1130,
          "deletions": 117,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1948,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1948",
          "title": "Prepare v3.0.2-alpha.3",
          "body": "Create the generated version-state commit for v3.0.2-alpha.3.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: 8b1b52cc9dc5eb0a89f2aae3acfd08a22dae6934 -> ebc7b2d86ecce1de835c8f8ba4436bcac65a62c2\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T01:12:14Z",
          "mergedAt": "2026-07-27T01:15:51Z",
          "additions": 23,
          "deletions": 14,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 219,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/219",
          "title": "feat: render published Core Spec bundle",
          "body": "Summary:\n- consume the public @kungfu-tech/site 4.0.0-alpha.1 package instead of the temporary vendored tarball\n- generate the Core /format/ page and machine authority routes from the packaged site-bundle\n- explain .kungfu first as a portable, verifiable record of real work\n- show a concrete Work, Retain, Continue handoff for a fresh agent\n- distinguish preservation, inspection and action in plain language\n- keep package framing, reader profiles, compatibility axes, roots and artifacts complete inside a closed implementer and auditor disclosure\n- publish the packaged format authority artifacts byte-for-byte on Core routes\n- refresh every Kungfu package used by this site to its latest published version\n\nVerification:\n- frozen dependency state and exact package pickup\n- site build and repository checks\n- shell syntax and ShellCheck\n- Node syntax and git diff checks\n- desktop and mobile browser inspection\n- closed and opened disclosure behavior with no horizontal overflow\n- byte equality checks for every packaged format artifact\n\nBoundary:\n- preview only; no staging or production deployment\n- no Kungfu source-repository changes\n- upstream site-bundle human-model improvements remain a separate follow-up",
          "author": "dongkeren",
          "createdAt": "2026-07-27T01:27:14Z",
          "mergedAt": "2026-07-27T01:29:09Z",
          "additions": 590,
          "deletions": 66,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 217,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/217",
          "title": "feat: render published Core Spec bundle",
          "body": "Summary:\n- consume the public @kungfu-tech/site 4.0.0-alpha.1 package instead of the temporary vendored tarball\n- generate the Core /format/ page and machine authority routes from the packaged site-bundle\n- explain .kungfu first as a portable, verifiable record of real work\n- show a concrete Work, Retain, Continue handoff for a fresh agent\n- distinguish preservation, inspection and action in plain language\n- keep package framing, reader profiles, compatibility axes, roots and artifacts complete inside a closed implementer and auditor disclosure\n- publish the packaged format authority artifacts byte-for-byte on Core routes\n- refresh every Kungfu package used by this site to its latest published version\n\nVerification:\n- frozen dependency state and exact package pickup\n- site build and repository checks\n- shell syntax and ShellCheck\n- Node syntax and git diff checks\n- desktop and mobile browser inspection\n- closed and opened disclosure behavior with no horizontal overflow\n- byte equality checks for every packaged format artifact\n\nBoundary:\n- preview only; no staging or production deployment\n- no Kungfu source-repository changes\n- upstream site-bundle human-model improvements remain a separate follow-up",
          "author": "dongkeren",
          "createdAt": "2026-07-26T23:15:49Z",
          "mergedAt": "2026-07-27T01:29:11Z",
          "additions": 590,
          "deletions": 66,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1581,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1581",
          "title": "fix(ci): normalize Passport artifact digests",
          "body": "## Summary\n\nNormalize raw 64-hex `actions/upload-artifact` digests before comparing them with the GitHub API canonical `sha256:<hex>` coordinates. The Passport generator now consumes the verified API digest rather than the provider-specific raw representation.\n\nCloses #1579.\n\n## Failure evidence\n\n- Build run: https://github.com/kungfu-systems/kungfu/actions/runs/30225695823\n- Gate artifact `8639472306` and media artifact `8639492343` both completed successfully.\n- Passport failed closed because reusable-workflow output exposed raw 64-hex while the same-run API returned canonical `sha256:<hex>`.\n\n## Validation\n\n- `./shifu test:auditable-demo` — 20 passed\n- `./shifu check:staged` — passed, including workflow authority refresh and governance checks\n- Test executes the embedded workflow script and proves raw normalization, canonical output, malformed-digest rejection, and real mismatch rejection.\n\n## Safety\n\n- Existing same-run artifact id/name/digest binding remains fail closed.\n- No claim-scope, publication-authority, deployment, or production behavior change.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix normalizes one provider digest representation at the existing Passport boundary without changing product architecture, claim scope, publication authority, or deployment behavior.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-27T01:31:13Z",
          "mergedAt": "2026-07-27T01:52:18Z",
          "additions": 97,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 167,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/167",
          "title": "feat: make the bootstrap thesis concrete",
          "body": "## Summary\n\nTurn the bootstrapping essay from a primarily conceptual manifesto into a concrete, falsifiable explanation for readers who do not yet know Kungfu, and make the agent-reading path visible before the argument begins.\n\n## Changes\n\n- place the complete Read this with your agent invitation at the top of the article\n- enforce that placement in the site check\n- explain Kungfu in plain language before introducing the claim boundary\n- add a before-and-after Work example showing what remains hidden in a human organization and what must become machine-readable\n- ground the example in the public PR, exact staging run, and separate production approval path for the previous page revision\n- identify the strongest objection to a minimal sovereign core and make external adoption part of the falsification boundary\n- shorten the architecture catalog and stop linking to the intentionally unsynchronized Kungfu repository essay\n- refresh every Kungfu package used by the site to its latest published version\n\n## Verification\n\n- frozen pnpm install from the public npm registry\n- site build and repository checks\n- shell syntax and ShellCheck\n- Node syntax and git diff checks\n- desktop and mobile browser review with no horizontal overflow\n- public site PR, staging run, and release-handoff links returned HTTP 200\n\nThe Doug Engelbart Institute links are unchanged from the previous page and timed out during the final local reachability check; no new claim depends on their availability.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change revises the official Kungfu bootstrap narrative and links only public, exact site delivery evidence. It does not change domain configuration, package identity, release mechanics, or production authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T01:59:39Z",
          "mergedAt": "2026-07-27T02:03:08Z",
          "additions": 169,
          "deletions": 126,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 166,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/166",
          "title": "feat: make the bootstrap thesis concrete",
          "body": "## Summary\n\nTurn the bootstrapping essay from a primarily conceptual manifesto into a concrete, falsifiable explanation for readers who do not yet know Kungfu, and make the agent-reading path visible before the argument begins.\n\n## Changes\n\n- place the complete Read this with your agent invitation at the top of the article\n- enforce that placement in the site check\n- explain Kungfu in plain language before introducing the claim boundary\n- add a before-and-after Work example showing what remains hidden in a human organization and what must become machine-readable\n- ground the example in the public PR, exact staging run, and separate production approval path for the previous page revision\n- identify the strongest objection to a minimal sovereign core and make external adoption part of the falsification boundary\n- shorten the architecture catalog and stop linking to the intentionally unsynchronized Kungfu repository essay\n- refresh every Kungfu package used by the site to its latest published version\n\n## Verification\n\n- frozen pnpm install from the public npm registry\n- site build and repository checks\n- shell syntax and ShellCheck\n- Node syntax and git diff checks\n- desktop and mobile browser review with no horizontal overflow\n- public site PR, staging run, and release-handoff links returned HTTP 200\n\nThe Doug Engelbart Institute links are unchanged from the previous page and timed out during the final local reachability check; no new claim depends on their availability.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change revises the official Kungfu bootstrap narrative and links only public, exact site delivery evidence. It does not change domain configuration, package identity, release mechanics, or production authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-26T22:24:00Z",
          "mergedAt": "2026-07-27T02:03:10Z",
          "additions": 169,
          "deletions": 126,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 168,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/168",
          "title": "Release production from aa8670731d2a",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `aa8670731d2af92a98257fe4e7b1a5a8f5a9695e`\n- Artifact hash: `f7cd3063313480980d68ca3af1f9ae1b41a780e0e02883d431d890ac9ed1d53f`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30231231010)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-aa8670731d2a`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-27T02:05:49Z",
          "mergedAt": "2026-07-27T02:09:05Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1582,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1582",
          "title": "feat(release): normalize publication control plane",
          "body": "## Summary\n\n- introduce one versioned release/publication registry and nine-invariant protocol\n- bind every current Kungfu publication surface to the common protocol or an audited isolation with an owner, review date, risk, and sunset condition\n- add credential-safe status, live ruleset/Buildchain readback, source admission, and non-publishing rehearsal commands\n- gate the existing promotion path without changing its Buildchain pin, artifact reuse, platform qualification, signing, notarization, or protected publication controller\n\n## Live readback\n\n- the exact Buildchain 3.0.2-alpha.2 workflow inventory is closed\n- the Alpha ruleset matches its checked-in contract\n- stable and major rulesets remain intentionally absent; their surfaces are isolated and publication-denied until their declared governance/topology conditions are met\n- no release or ruleset mutation was performed\n\n## Validation\n\n- `./shifu check:release-publication-control-plane`\n- `./shifu test:release-publication-control-plane`\n- `./shifu release:publication:status -- --live`\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7b6b-ae6d-76cea57487f2\"],\n  \"summary\": \"Normalize all Kungfu publication surfaces under the accepted Buildchain release-governance contract.\",\n  \"verification\": [\n    \"Release publication control-plane contract and eight negative/positive tests\",\n    \"Full build-free source acceptance\",\n    \"Credential-safe live Buildchain inventory and Alpha ruleset readback\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] credentials, tokens, secrets, or private logs\n\nThe change adds fail-closed admission and read-only status evidence. It does not publish artifacts, mutate rulesets, or weaken signing, notarization, trusted publishing, compatibility, or protected delivery.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T01:57:15Z",
          "mergedAt": "2026-07-27T02:52:27Z",
          "additions": 1421,
          "deletions": 13,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 169,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/169",
          "title": "feat(site): publish auditable exact-output demo",
          "body": "## Summary\n\nPublish a no-login, static demonstration generated from one exact retained Kungfu Linux artifact after the reusable Buildchain Gate passed. The page exposes bounded video, GIF, poster, transcript, machine-readable Passport, and exact evidence coordinates.\n\n## Changes\n\n- import the qualified Release Passport and exact 13-member media bundle;\n- publish content-addressed evidence under `/evidence/auditable-demo/<passport-root>/`;\n- replace the placeholder `/how-tested/auditable-demo/` block with the exact proof and non-claims;\n- expose `/auditable-demo.json` for machine readers;\n- retain Gate, media, source, Buildchain, renderer, run, digest, and expiry coordinates.\n\n## Verification\n\n- source run: https://github.com/kungfu-systems/kungfu/actions/runs/30230901970\n- Passport root: `sha256:0c44a9618fd4114340ca460a6fd7e3a391ada4c7a540d76b4136c3173373391e`\n- `node scripts/import-auditable-demo.mjs --check`\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n\nThe imported Passport is qualified, publication is `github-artifacts-only`, and `productionDeployment` is `false`.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR copies only public-safe, checksum-verified GitHub Artifact evidence. Normal merge automation may publish staging; this is not a `buildchain-release` PR and grants no production authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-27T02:59:55Z",
          "mergedAt": "2026-07-27T03:05:36Z",
          "additions": 2812,
          "deletions": 1,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 141,
          "url": "https://github.com/kungfu-systems/libnode/pull/141",
          "title": "fix(runtime): resolve Linux ARM64 libnode package",
          "body": "## Summary\n- resolve the already-published `@kungfu-tech/libnode-linux-arm64` optional dependency from the main package\n- add a focused entrypoint contract test for Linux ARM64\n- run that test in the Buildchain verify lifecycle and refresh the KFD-1 witness\n- advance the immutable alpha package set to `22.22.3-kf.5-alpha.2`\n\n## Why\nKungfu exact-SHA hosted ARM64 qualification reached the native core build and failed because the main libnode entrypoint rejected `linux-arm64`, even though the platform package is already part of the published package set.\n\n## Verification\n- `node --test .gyp/libnode-entrypoint.test.js`\n- `corepack pnpm verify-release`\n- `corepack pnpm verify-package-source`\n- `corepack pnpm verify-kfd-witnesses`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-27T01:24:35Z",
          "mergedAt": "2026-07-27T03:21:56Z",
          "additions": 53,
          "deletions": 13,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1949,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1949",
          "title": "fix(governance): select latest qualified dev candidate",
          "body": "Summary\n\n- Select the newest Dev ancestor with fresh successful same-SHA Dev Verify and Alpha preflight evidence.\n- Bind the observed Dev HEAD, selected SHA, and skipped newer commit count into the decision and candidate PR.\n- Keep the exact source lock and no-merge/no-publication boundary.\n\nOperational evidence\n\n- A current-HEAD-only patrol repeatedly became stale while the three-platform Dev Verify was still running.\n- Dev Verify run 30231336508 completed successfully for 0c584fc0e6446a07a5bdb1462738ffab47dddadb after Dev advanced.\n- Alpha preflight run 30230804584 completed successfully for the same SHA.\n\nValidation\n\n- corepack pnpm@11.7.0 run check\n- 893 unit tests passed\n- workflow checks and five action bundle integrity checks passed",
          "author": "dongkeren",
          "createdAt": "2026-07-27T03:18:36Z",
          "mergedAt": "2026-07-27T03:26:02Z",
          "additions": 523,
          "deletions": 120,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1534,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1534",
          "title": "feat(work-control): cut over native work authority",
          "body": "## Summary\n\n- establish the versioned `kungfu.work-control` Profile as native Initiative/Assignment authority\n- cut CLI, TUI, GUI, Agent, lifecycle, and generated SDK surfaces over to Work Control vocabulary\n- preserve exact legacy Mission/Go read compatibility behind explicit compatibility boundaries\n- require exact parent-card admission evidence when Atlas projects an Initiative\n\n## Validation\n\n- `./shifu check:source`\n- Work Control Profile, orchestration, GUI, TUI, KFX, SDK, primitive catalog, vocabulary, and documentation contract suites\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f9771-4c20-7e2c-8e7c-3f3cb3f1b9bd\"],\n  \"summary\": \"Cut over Kungfu native Work Control authority and product vocabulary\",\n  \"verification\": [\"./shifu check:source\", \"Work Control focused contract suites\"]\n}\n-->\n\nSigned commits and protected dual-account review are required.",
          "author": "dongkeren",
          "createdAt": "2026-07-26T10:11:02Z",
          "mergedAt": "2026-07-27T03:48:24Z",
          "additions": 2733,
          "deletions": 1395,
          "changedFiles": 115
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1591,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1591",
          "title": "fix(governance): pin live candidate selector",
          "body": "Summary\n\n- Pin Dev to Alpha Candidate Patrol to merged Buildchain commit e95c0251390f4948b7aa00de63c49f018ef1f6ff.\n- Refresh the closed-world workflow authority manifest.\n- Refresh the release publication control-plane source root.\n\nWhy\n\nThe current-HEAD-only selector repeatedly became stale while native Dev Verify was still running. Buildchain PR 1949 now selects the newest qualified Dev ancestor while preserving exact same-SHA evidence and the no-merge/no-publication boundary.\n\nValidation\n\n- shifu test:alpha-promotion-preflight: 42 passed\n- shifu check:gate-catalog: passed\n- shifu check:source: passed\n- staged pre-commit gates: passed\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Pin the merged Buildchain candidate selector and refresh derived authority roots without changing an architecture contract.\"\n}\n-->",
          "author": "kungfu-origin",
          "createdAt": "2026-07-27T03:54:17Z",
          "mergedAt": "2026-07-27T04:14:23Z",
          "additions": 6,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 142,
          "url": "https://github.com/kungfu-systems/libnode/pull/142",
          "title": "fix(runtime): promote Linux ARM64 resolver alpha",
          "body": "## Summary\n\nPromote the reviewed Linux ARM64 libnode resolver and immutable `22.22.3-kf.5-alpha.2` package set through the standard protected dev-to-alpha lineage.\n\n## Evidence\n\n- implementation PR: #141\n- trusted exact-SHA four-platform run: `30229615444`\n- Linux ARM64 job: success, 79m51s\n- Linux ARM64 artifact: `libnode-linux-arm64-fc436b2c4f1c8fa6cc175f9d194af98185ad9a34` (44,273,485 bytes)\n- implementation merge: `35e1a1fe7a36663247a2be1e58625ee296a7f9b8`\n\nThe alpha PR must build and publish the same four-platform package set through Buildchain trusted publishing.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T03:22:24Z",
          "mergedAt": "2026-07-27T04:40:59Z",
          "additions": 53,
          "deletions": 13,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 172,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/172",
          "title": "feat: publish bootstrap public work evidence",
          "body": "## Summary\n\nTrusted preview mirror of #171 at exact source commit `72d4cd42d865623f6889b06de0a31e06f336dd53`.\n\nPublish a bounded empirical companion to the Bootstrap thesis, with a first-party declaration, public GitHub evidence, a conventional-organization comparison, and reproducible source material.\n\n## Changes\n\n- add `/about/bootstrapping/evidence/` and link it from the Bootstrap article\n- separate publicly verifiable facts, first-party declarations, and conclusions not established by the sample\n- describe visible work streams and conventional organizational functions without assigning a person-month estimate\n- publish the fixed GitHub sample, collector, Agent-written reference analysis, and a SHA-256 manifest\n- add data consistency, claim-boundary, build-output, and route checks\n\n## Verification\n\n- full site build and repository checks\n- Bash syntax, ShellCheck, Node syntax, and Git diff checks\n- 9 published evidence files verified against manifest byte counts and SHA-256 digests\n- desktop 1440px and mobile 390px browser review with no horizontal overflow\n- all linked local evidence resources returned HTTP 200\n\n## Claim boundary\n\nGitHub can verify public accounts, artifacts, timestamps, reviews, and releases. The one-human and Agent-execution statement is explicitly first-party and not independently proved by the public record. The report does not claim that this sample proves the Bootstrap method.\n\n## Deployment boundary\n\nThis is a preview candidate only. It does not request merge or production deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Data and interpretation limits are documented",
          "author": "dongkeren",
          "createdAt": "2026-07-27T03:39:44Z",
          "mergedAt": "2026-07-27T04:47:18Z",
          "additions": 24539,
          "deletions": 2,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1953,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1953",
          "title": "fix(workflows): preserve stable promotion input compatibility",
          "body": "## Summary\n\n- keep the generated `v3-alpha` router compatible with the current stable `v3` hidden workflow contract\n- stop forwarding two alpha-only KFD Passport inputs into the stable shell lane\n- add regression coverage for the generated stable lane\n\n## Evidence\n\n- `node --test tests/promotion-channel-router.test.mjs`\n- `node scripts/generate-channel-promotion-workflow.mjs --check`\n- `node scripts/check-inventory.mjs`\n- `actionlint .github/workflows/release-candidate-promote.yml .github/workflows/.release-candidate-promote.yml`\n- consumer startup failure: https://github.com/kungfu-systems/libnode/actions/runs/30237760588\n\nFixes #1951",
          "author": "dongkeren",
          "createdAt": "2026-07-27T04:46:56Z",
          "mergedAt": "2026-07-27T04:52:44Z",
          "additions": 9,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 173,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/173",
          "title": "Release production from 7bcf74495a8f",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `7bcf74495a8f63f2469e65f55909f4d2dc96a84a`\n- Artifact hash: `4ba58d0a113c0f0b2db849a61cf384ed615bb72bec28f76719db203887d89c9d`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30238031371)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-7bcf74495a8f`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-27T04:49:58Z",
          "mergedAt": "2026-07-27T04:52:45Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1955,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1955",
          "title": "merge(alpha): reconcile KFD input promotion state",
          "body": "## Summary\n\nMerge the current protected Alpha channel state back into dev so the KFD input compatibility promotion can remain ancestry-preserving and conflict-free. Generated site contracts were rebuilt from the merged source.\n\n## Verification\n\n- `corepack pnpm run check`\n- 894 tests passed, 0 failed\n- action bundle integrity passed\n\nUnblocks #1954.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T04:57:43Z",
          "mergedAt": "2026-07-27T05:02:35Z",
          "additions": 23,
          "deletions": 14,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1954,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1954",
          "title": "release(v3): promote KFD input compatibility to Alpha",
          "body": "## Summary\n\nPromote the validated `v3-alpha` router compatibility fix so alpha consumers can start release-candidate promotion while the stable `v3` hidden shell still exposes the previous input surface.\n\n## Qualification\n\n- implementation PR: #1953\n- consumer train validation: https://github.com/kungfu-systems/libnode/actions/runs/30238128134\n- original consumer startup failure: https://github.com/kungfu-systems/libnode/actions/runs/30237760588\n- Buildchain issue: #1951\n\nAfter this promotion completes, `kungfu-systems/libnode` will rerun its alpha publication through the corrected official `v3-alpha` channel.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T04:53:14Z",
          "mergedAt": "2026-07-27T05:05:35Z",
          "additions": 531,
          "deletions": 124,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1957,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1957",
          "title": "Prepare v3.0.2-alpha.4",
          "body": "Create the generated version-state commit for v3.0.2-alpha.4.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: ba9a63a1960beab3660cacaca76ceed02ea9a0f1 -> 24162b91a4cb6b5a4f8186cea3febfdb234717d5\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T05:10:00Z",
          "mergedAt": "2026-07-27T05:13:07Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1595,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1595",
          "title": "fix(work-control): reopen nonterminal review cycles",
          "body": "## Summary\n\n- ensure nonterminal Work Control continuation decisions begin a new completion cycle\n- keep failed independent reviews fail-closed until a later claim and review\n- preserve append-only historical claims, reviews, and decisions\n- synchronize the accepted Work Control ADR with the completion-cycle invariant\n\n## Validation\n\n- `./shifu check:source`\n- `framework/core/tests/python/test_assignment_orchestration.py`\n- staged documentation and ADR authority gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f9771-4c20-7e2c-8e7c-3f3cb3f1b9bd\"],\n  \"summary\": \"Keep Work Control completion cycles fail-closed after nonterminal review decisions\",\n  \"verification\": [\"./shifu check:source\", \"Assignment orchestration regression suite\", \"ADR authority gate\"]\n}\n-->\n\nSigned commits and protected dual-account review are required.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T04:11:39Z",
          "mergedAt": "2026-07-27T05:16:26Z",
          "additions": 196,
          "deletions": 68,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1956,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1956",
          "title": "feat(attestation): add GitHub keyless Linux provenance",
          "body": "## Summary\n\n- add a GitHub-hosted OIDC/Sigstore attester for Linux release artifacts\n- bind immutable attestation policy and provider evidence to Release Passport, exact source/workflow/artifact digests, and original runner manifest evidence\n- integrate fail-closed staging, offline verification, promotion, and GitHub Release evidence read-back\n- keep signer-bootstrap identity distinct from the later Buildchain runtime identity\n\n## Validation\n\n- `pnpm run check`\n- `node --test tests/github-artifact-attestation.test.mjs` (12/12, including subject tamper, wrong source/signer/passport, and missing evidence)\n- `node --test tests/public-surface-audit.test.mjs` (2/2)\n\n## Qualification boundary\n\n- target line: `dev/v3/v3.0`\n- signer bootstrap: `ad57ae0fee5072a1de7a0b0182f70c0c41e45abb`\n- real Kungfu Linux Alpha artifact, GitHub Release read-back, and retained Sigstore evidence will be attached before final closure.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-27T05:04:08Z",
          "mergedAt": "2026-07-27T05:19:44Z",
          "additions": 3589,
          "deletions": 209,
          "changedFiles": 63
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1597,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1597",
          "title": "feat(site): generate shared human and agent reader experiences",
          "body": "## Summary\n\nMove the verified human and Agent reading experience into `@kungfu-tech/site` so downstream sites provide only content and configuration while the bundle owns consistent rendering, navigation, machine entry points, and verification.\n\nThis linear delivery replaces the history-conflicted candidate in #1593 without force-pushing or deleting its audit trail.\n\n## Changes\n\n- add package-owned first-screen guidance for human and Agent co-reading\n- keep human orientation first and progressively disclose technical detail\n- publish exact KFD-3 machine entry links and rooted machine artifacts\n- enforce Kungfu UNGFU™ brand and navigation consistency\n- generate deterministic HTML, `manifest.json`, `agent-index.json`, and `llms.txt`\n- validate a closed consumer configuration schema and fail closed on byte drift\n- verify the packed tarball in a clean consumer\n\n## Verification\n\n- `./shifu --filter @kungfu-tech/site test`\n- `./shifu pack:site`\n- `./shifu docs:check`\n- `./shifu check:source`\n- desktop and mobile visual inspection of generated output\n- Project Cut replay qualification against `694cd703ae7f396f9ab2401db86777c8821dbd1c`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7c91-9cc2-6dbd18d68dff\"],\n  \"summary\": \"Moves the verified human-first and Agent-readable site experience into the independently consumable product-layer bundle.\",\n  \"verification\": [\"Site and Spec package tests\", \"packed clean-consumer smoke test\", \"deterministic documentation gate\", \"complete source acceptance\", \"desktop and mobile visual inspection\", \"Project Cut replay qualification\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes the source package and its evidence contract. It does not publish npm packages, modify downstream site repositories, or deploy a site.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-27T04:44:15Z",
          "mergedAt": "2026-07-27T05:31:17Z",
          "additions": 1732,
          "deletions": 8,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1959,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1959",
          "title": "fix(workflows): materialize promotion shell before use",
          "body": "## Summary\n- checkout the selected immutable promotion workflow shell in the promote job\n- prove the checkout precedes shell-owned routing evidence execution\n- refresh the generated site contract digest\n\n## Validation\n- `node --test tests/promotion-routing-evidence.test.mjs tests/promotion-channel-router.test.mjs`\n- `node scripts/generate-channel-promotion-workflow.mjs --check`\n- `corepack pnpm run check` (907 tests)\n\nFixes #1958",
          "author": "dongkeren",
          "createdAt": "2026-07-27T05:27:06Z",
          "mergedAt": "2026-07-27T05:32:48Z",
          "additions": 27,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1961,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1961",
          "title": "chore(release): reconcile promotion shell alpha state",
          "body": "Merge the current alpha version-state transaction back into dev after #1959, preserving `3.0.2-alpha.4` and regenerating the combined site contract. This makes #1960 conflict-free.\n\n## Validation\n- `node --test tests/promotion-routing-evidence.test.mjs tests/promotion-channel-router.test.mjs`\n- `corepack pnpm run check` (907 tests)",
          "author": "dongkeren",
          "createdAt": "2026-07-27T05:37:28Z",
          "mergedAt": "2026-07-27T05:42:49Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1960,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1960",
          "title": "chore(release): promote v3 development to alpha",
          "body": "Promote the current Buildchain v3 development line to alpha after validating the promotion-shell materialization fix.\n\nIncludes #1959.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T05:33:06Z",
          "mergedAt": "2026-07-27T05:45:51Z",
          "additions": 3613,
          "deletions": 209,
          "changedFiles": 64
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1600,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1600",
          "title": "docs(bootstrap): align public evidence boundaries",
          "body": "## Summary\n\nAlign the repository documentation and installed Agent brief with the current Kungfu Bootstrap argument and its bounded public evidence report.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add the ordinary-Work before/after example and the latest source/production PR coordinates\n- publish the one-week mechanical sample while separating public facts, first-party declaration, and inference\n- expose the evidence report and manifest from the repository README, documentation guide, map, and installed Agent brief\n- preserve the explicit non-claims around causality, general validity, release maturity, and independent adoption\n\n## Verification\n\n- `./shifu docs:check`\n- `./shifu docs:prose:required`\n- `./shifu check:source`\n- `./shifu docs final-ready --since origin/dev/v4/v4.0 --budget 66560 --json` (Human/Agent parity matched; authored prose requires review)\n- production Bootstrap, evidence, manifest, collector, raw PR data, and Buildchain URLs returned HTTP 200\n- site source PR #172 and production PR #173 are merged\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This documentation change clarifies an existing bootstrap thesis and evidence boundary without changing an architecture contract, runtime behavior, or release claim.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR updates public Kungfu positioning and links to existing official domains. It does not change product identity, domain ownership, release authority, or deployment configuration. All linked public surfaces were read back successfully.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-27T05:29:23Z",
          "mergedAt": "2026-07-27T05:48:33Z",
          "additions": 115,
          "deletions": 11,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1962,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1962",
          "title": "fix(release): propagate attestation permissions",
          "body": "## Summary\n- propagate `artifact-metadata: write` and `attestations: write` through the Buildchain Ref Promotion caller\n- lock the reusable-workflow permission contract with a regression assertion\n\n## Evidence\n- repairs startup failure in run 30240737524\n- `corepack pnpm run check` (907/907 tests)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T05:53:27Z",
          "mergedAt": "2026-07-27T05:56:34Z",
          "additions": 3,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1963,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1963",
          "title": "release: promote Buildchain v3 dev to alpha",
          "body": "Promote the verified dev line to alpha.\n\nIncludes the reusable promotion caller permission fix required for GitHub artifact attestations.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T05:57:05Z",
          "mergedAt": "2026-07-27T05:58:22Z",
          "additions": 3,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1964,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1964",
          "title": "fix(release): align attestation signer contract",
          "body": "## Summary\n- pin the promotion signer workflow to immutable Buildchain commit `375b2d4b8a904776453773a33b4c4e4556c8c999`, which declares the required `source-sha` input\n- lock the exact signer contract in regression coverage\n- refresh the generated public contract digest\n\n## Evidence\n- repairs startup failure in run 30241315946\n- `corepack pnpm run check` (907/907 tests)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T06:06:39Z",
          "mergedAt": "2026-07-27T06:09:53Z",
          "additions": 8,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1965,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1965",
          "title": "release: promote Buildchain v3 signer contract to alpha",
          "body": "Promote the verified signer-interface repair from dev to alpha.\n\nThis replaces the stale immutable signer pin that caused startup failure in run 30241315946.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T06:10:16Z",
          "mergedAt": "2026-07-27T06:11:33Z",
          "additions": 8,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1966,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1966",
          "title": "Prepare v3.0.2-alpha.5",
          "body": "Create the generated version-state commit for v3.0.2-alpha.5.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: edd5b7573394e8724e26a2d47500705dc9b06d9d -> 2123ee9c76013f09888d3a01543e66762a6b5819\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T06:16:50Z",
          "mergedAt": "2026-07-27T06:18:06Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1601,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1601",
          "title": "fix(release): close alpha publication tail",
          "body": "Linear replacement for #1596 after GitHub merge queue repeatedly rejected its non-linear branch topology as `merge_conflict`. This candidate is based directly on current dev `71e15894fc9b68298d6f479dd73eb66f6fa83398` and preserves the exact clean merged tree `86ea3e23c9d870734f1ff457c729434ef0891a2a`.\n\n## Summary\n\nClose the remaining Alpha publication failures after the KFD support-governance delivery. This upgrades the pinned Buildchain Alpha runtime to v3.0.2-alpha.3 with bundled macOS entitlements, corrects the immutable setup-node reference, and admits regenerated pull-merge SHAs only through sealed Episode tree-equivalence evidence.\n\n## Related issue\n\n- KFD support governance Alpha release follow-up\n\n## Changes\n\n- pin Buildchain Alpha workflows, package alias, lock, and release-admission policy to v3.0.2-alpha.3\n- refresh workflow authority and semantic-amplification projections\n- validate resealed pull-merge evidence before adapting the auditable demo artifact\n- retain fail-closed rejection for arbitrary source mismatches and non-pull refs\n\n## Verification\n\n- candidate DCO, source acceptance, and affected-native proof probe: run 30240230318\n- clean merged tree against current dev: `86ea3e23c9d870734f1ff457c729434ef0891a2a`\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This linear replacement changes no ADR record; it preserves the already-delivered Work Control and KFD release-tail implementation tree while repairing merge-queue topology.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release-evidence boundary is covered by sealed canonical-digest verification, exact pull-merge/tree bindings, negative fixtures, release-admission tests, source acceptance, and the full changed-scope gate.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-27T05:36:30Z",
          "mergedAt": "2026-07-27T06:22:20Z",
          "additions": 255,
          "deletions": 66,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1594,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1594",
          "title": "ci(opencode): add local-model runner canary",
          "body": "## Summary\n\nAdd a manual, fail-closed OpenCode canary for the trusted agent-120 self-hosted runner using the published immutable opencode-ci image and the local Qwen3-Coder endpoint.\n\n## Related issue\n\nSupersedes #1592, whose feature branch prefix incorrectly required product ADR delivery intent.\n\n## Changes\n\n- add a workflow_dispatch-only canary pinned to agent-120 and an immutable image digest\n- require the preloaded image and narrow host-only Ollama tunnel endpoint\n- run the container read-only with dropped capabilities and no credentials or source checkout\n- verify model, OpenCode, tool-use, and deterministic output evidence independently\n- register the workflow in the closed-world workflow and release-publication control planes\n\n## Verification\n\n- ./shifu check:source\n- ./shifu check:release-publication-control-plane\n- ./shifu test:release-publication-control-plane\n- exact released-image canary on agent-120 with qwen3-coder:30b-opencode-64k: passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded CI qualification canary does not alter a product architecture contract or publication surface\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe workflow reaches only the host-bound local OpenAI-compatible model endpoint, passes no API key, and uploads bounded diagnostic evidence. It is explicitly registered as non-publication.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-27T04:10:03Z",
          "mergedAt": "2026-07-27T06:45:08Z",
          "additions": 318,
          "deletions": 211,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1585,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1585",
          "title": "feat(product): unify agent qualification experience",
          "body": "## Summary\n\nUnify the GUI and TUI Agent Qualification Lab around one visible two-session experiment, and make interactive bare kungfu the only terminal-product entry.\n\n## Changes\n\n- route interactive bare kungfu directly to the bundled TUI and remove the tui subcommand\n- choose Work or Qualification Lab startup from admitted local Work facts\n- stream two-session Agent activity with fixed reports, focus-aware title bars, progress feedback, result details, and next-mode coaching\n- keep GUI and TUI qualification timing, provider-output admission, and verdict language aligned\n\n## Verification\n\n- ./shifu check:source\n- repository pre-commit gate, including Rust workspace tests and KFD/SDK/documentation closure\n- TUI tests: 46 passed\n- GUI file-scoped TypeScript check passed\n- signed macOS Product build and installed readback passed before submission\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-73ff-9543-f0a4f0beef05\",\n    \"KF-ADR-019f86da-4f90-7a4b-b1a3-256ce6fa3f06\"\n  ],\n  \"summary\": \"Extend the shared boot-safe Qualification Lab and terminal-entry convergence with live two-session playback, fixed reports, and guided mode progression.\",\n  \"verification\": [\"build-free source acceptance\", \"TUI 46-test suite\", \"GUI TypeScript check\", \"Rust workspace tests\", \"signed macOS Product build and installed readback\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe provider boundary remains admitted public output only; raw tool output and private reasoning stay redacted. The command-surface and release-evidence projections are regenerated and verified.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-27T02:36:03Z",
          "mergedAt": "2026-07-27T07:12:37Z",
          "additions": 3642,
          "deletions": 619,
          "changedFiles": 48
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1608,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1608",
          "title": "fix(governance): authorize candidate pull request",
          "body": "Pass the existing repository-owned promotion token to the reusable Dev→Alpha Candidate Patrol, so the patrol can create or reuse the exact-SHA source-lock PR under the organization policy that disables the default Actions token for PR creation.\n\nValidation:\n- ./shifu test:alpha-promotion-preflight (42/42)\n- ./shifu check:gate-catalog\n- ./shifu check:release-publication-control-plane\n- ./shifu check:source\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Pass the existing repository-owned promotion token to the candidate patrol without changing an architecture contract.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-27T06:52:57Z",
          "mergedAt": "2026-07-27T07:13:18Z",
          "additions": 18,
          "deletions": 10,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 6,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/6",
          "title": "feat: add course business reference",
          "body": "Adds a bounded PostgreSQL course-business vertical slice with learner registration and sessions, strict per-account homework isolation, transactional outbox coordination, a versioned AgentWorkPort, and an explicitly simulated deterministic adapter.\n\nIncludes a loopback-only Compose topology, qualification harness, contract and security tests, and a complete primary Web workflow. This change intentionally does not integrate Kungfu.\n\nQualification:\n- 19 repository and contract tests pass; ShellCheck and npm audit pass with zero vulnerabilities\n- Native linux/arm64 Compose qualification passes on a clean database and fresh named volumes\n- Browser flow passes through the explicitly simulated seal with zero console errors\n- Native linux/amd64 qualification on agent-120 passes at 240ab821 with three-account isolation, Origin/CSRF/body/rate-limit checks, forced RLS, concurrent idempotency, adapter-timeout and post-adapter-crash recovery, backup/restore equality, and database/application restart recovery\n- The amd64 image runs as non-root node; PostgreSQL is internal-only and the runtime role has NOBYPASSRLS with four FORCE ROW LEVEL SECURITY tables\n\nAll qualification projects stop without deleting their named volumes. The existing Hub Starter deployment and its data are not modified.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T07:37:09Z",
          "mergedAt": "2026-07-27T08:01:05Z",
          "additions": 2459,
          "deletions": 1,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 145,
          "url": "https://github.com/kungfu-systems/libnode/pull/145",
          "title": "fix(release): propagate attestation permissions",
          "body": "## Summary\n- propagate artifact metadata and attestation write permissions into the reusable release workflow\n- refresh the exact KFD workflow witness after the permission change\n\n## Validation\n- actionlint\n- release contract verification\n- KFD witness verification\n- platform source verification\n- Build run 30243358897: Linux x64, Linux ARM64, macOS ARM64, and Windows x64 all passed at head 8465b9d0b16f2c1462f804a50a59f12518ebf3c9\n\nReplaces #144 solely to restore the required distinct PR author and CODEOWNER reviewer identities; source SHA is unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T08:01:17Z",
          "mergedAt": "2026-07-27T08:02:48Z",
          "additions": 4,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1614,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1614",
          "title": "fix(product): admit installed Assignment with explicit identities",
          "body": "## Summary\n\n- pass the canonical Initiative and Assignment identities to the installed-product admission smoke\n- keep the work-definition projection and source identity aligned\n- preserve the product distribution complexity budget and refresh the governed semantic-amplification report\n- replace #1611 after its merge-queue preview became dirty behind newly merged dev work\n\n## Validation\n\n- `./shifu test:cli-surface-qualification` (32 tests passed)\n- `./shifu maintainability:amplification --check`\n- `node scripts/code-complexity-budget.mjs`\n- staged repository gate (including invariant, docs, ADR, KFD-7, and Biome checks)\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"This bug fix restores the installed qualification smoke to the already-governed Assignment admission contract and does not change an architecture decision.\"}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-27T07:18:47Z",
          "mergedAt": "2026-07-27T08:03:32Z",
          "additions": 23,
          "deletions": 11,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1617,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1617",
          "title": "fix(product): bind installed admission identities",
          "body": "## Summary\n\n- bind the packaged Assignment admission smoke to explicit Initiative and Assignment identities\n- lock the generated installed-product request with a direct regression assertion\n- preserve the grandfathered distribution module line budget\n- supersede #1610 and #1615 without force-pushing their published histories\n\n## Evidence\n\n- reproduces the fail-closed Alpha build diagnosis from run 30242582583\n- `node --test product/scripts/dist.test.mjs`: 24/24 pass\n- `node scripts/code-complexity-budget.mjs`: pass\n- `./shifu maintainability:amplification --check`: pass\n- complete staged pre-commit gate: pass\n- Project Cut merge-queue admission: qualified, one replayed commit\n\n## Release impact\n\nThis is a release-tail correctness fix for the existing Alpha PR #1448. It does not widen KFD shipped support or create a second release intent.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix makes the packaged Assignment admission smoke comply with the already-delivered explicit identity contract; it changes no ADR authority and does not widen KFD support claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change repairs installed-product qualification without adding publishing authority or weakening release gates.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not required; the smoke now matches the existing Assignment identity contract)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T08:09:20Z",
          "mergedAt": "2026-07-27T08:17:18Z",
          "additions": 18,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1967,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1967",
          "title": "feat(release): serialize dev alpha candidates",
          "body": "## Outcome\n\nIntroduces a single-flight Dev to Alpha candidate controller with durable PR-body state, exact-source evidence, next-candidate coalescing, and fail-closed duplicate detection.\n\n## Control model\n\n- read-only observation is separated from permissioned settlement\n- at most one managed candidate PR may be active per Alpha target\n- newer qualified Dev SHAs are retained as nextCandidate and supersede older queued SHAs\n- retries reuse the active candidate instead of creating a new heavy build\n- GitHub API reads use bounded retries and foreign human Alpha PRs remain outside the controller\n\n## Verification\n\n- pnpm run check: 915 tests passed\n- actionlint passed\n- targeted candidate controller suite: 19 tests passed\n- generated site and workflow registries are current\n- git diff --check passed\n\n## Consumer validation\n\nKungfu consumes the exact workflow commit through train/v3/v3.0/dev-alpha-candidate-single-flight; a no-write workflow_dispatch dry-run is being used to validate the real repository state before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T08:30:39Z",
          "mergedAt": "2026-07-27T08:36:15Z",
          "additions": 929,
          "deletions": 125,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 7,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/7",
          "title": "fix: support idempotency keys on plain LAN HTTP",
          "body": "## Summary\n\n- use Web Crypto random bytes when `crypto.randomUUID()` is unavailable outside a secure context\n- preserve RFC 4122 version and variant bits without falling back to `Math.random()`\n- add regression coverage for native, fallback, and fail-closed paths\n\n## Validation\n\n- `npm run check` (22 tests)\n- `docker compose config --quiet` with synthetic development passwords\n- `bash -n course-business-reference/scripts/compose-qualification.sh`\n- `shellcheck course-business-reference/scripts/compose-qualification.sh`",
          "author": "dongkeren",
          "createdAt": "2026-07-27T09:04:17Z",
          "mergedAt": "2026-07-27T09:05:13Z",
          "additions": 54,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 8,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/8",
          "title": "feat(course): add outline copilot version workflow",
          "body": "## Summary\n- add a private course collection with business-owned immutable outline versions\n- make the Mock Agent generate and revise visible course outlines\n- let creators approve one version without overwriting prior drafts\n\n## Validation\n- npm run check\n- bash -n course-business-reference/scripts/compose-qualification.sh\n- isolated Compose qualification on Linux/amd64, including RLS, idempotency, crash retry, backup/restore, and restart recovery",
          "author": "dongkeren",
          "createdAt": "2026-07-27T09:29:25Z",
          "mergedAt": "2026-07-27T09:30:11Z",
          "additions": 1069,
          "deletions": 281,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1590,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1590",
          "title": "fix(ci): enforce queue-inclusive dev gate latency",
          "body": "## Summary\n\n- Measure queue-inclusive dev required-gate latency from first enqueue through the successful merged queue round.\n- Preserve failed dequeue and wasted-runner evidence instead of reporting PR-head diagnostics as delivery latency.\n- Promote only exact successful merge-group native caches into trusted default-branch scope.\n- Cancel dequeued merge-group work and prevent blind re-admission after exact-head failure or conflict.\n\n## Validation\n\n- `./shifu check:all`\n- `./shifu check:source`\n- `./shifu test:gate-latency`\n- `./shifu check:gate-catalog`\n- Project Cut merge-queue admission against `dev/v4/v4.0`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-019f86da-4f90-79a1-bc85-4b542fecf011\"],\n  \"summary\": \"Make the required Gate control plane queue-inclusive, source-bound, cache-promotable only from successful merge groups, and fail-fast after dequeue without weakening any required gate.\",\n  \"verification\": [\"whole-tree check\", \"build-free source acceptance\", \"43 queue latency and cache contract tests\", \"Project Cut merge-queue admission\"]\n}\n-->\n\n## Safety\n\nNo required gate is removed or weakened. Cache promotion requires exact successful merge-group evidence, and dequeue handling remains least-privilege and fail closed.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T03:46:04Z",
          "mergedAt": "2026-07-27T09:32:38Z",
          "additions": 2004,
          "deletions": 383,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 9,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/9",
          "title": "fix(course): scope UI control state",
          "body": "## Summary\n- keep browser event objects out of user-facing messages\n- disable only course-workspace controls during Agent requests\n- retain the account logout action after generation and revision\n\n## Validation\n- npm run check (23 tests)\n- live browser finding reproduced against the LAN preview",
          "author": "dongkeren",
          "createdAt": "2026-07-27T09:34:06Z",
          "mergedAt": "2026-07-27T09:34:52Z",
          "additions": 10,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1623,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1623",
          "title": "fix(ci): prefetch production membrane crates",
          "body": "## Summary\n\n- prefetch both spike and production libwasm Cargo manifests before the offline native build\n- prevent late missing-crate failures such as foldhash after C++ compilation has started\n- regress the complete crate-family prefetch contract\n\n## Evidence\n\n- reproduces the exact Alpha release-tail failure from run 30249771030 / job 89924992257\n- `node --test scripts/qualify-embedding-membranes.test.mjs`: pass\n- `./shifu check:staged`: pass\n- complete staged pre-commit gate: pass\n- Project Cut merge-queue admission: qualified, one replayed commit\n\n## Release impact\n\nThis is a release-tail CI correctness fix for the existing Alpha PR #1448. It creates no release intent and does not widen KFD shipped support.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix aligns dependency prefetch with the production Cargo manifests already consumed by the offline membrane build; it changes no ADR authority and does not widen KFD support claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change repairs release qualification without adding publishing authority or weakening release gates.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not required; qualification now matches the existing offline-build contract)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T08:42:49Z",
          "mergedAt": "2026-07-27T09:36:41Z",
          "additions": 15,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1619,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1619",
          "title": "fix(workspace): isolate catalog identity verification failures",
          "body": "## Summary\n\nPrevent one malformed or unreadable Workspace identity from aborting verification of the entire Catalog. The verifier now reports a structured per-entry problem and remains read-only.\n\n## Verification\n\n- `./shifu build:core`\n- `./shifu test:workspace-continuation`\n- `./shifu check:workspace-continuation`\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix preserves Workspace and Catalog authority semantics; it only isolates diagnostics for invalid locator identity material.\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation impact reviewed; no contract change required\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T08:25:21Z",
          "mergedAt": "2026-07-27T09:39:34Z",
          "additions": 68,
          "deletions": 20,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1626,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1626",
          "title": "feat(release): qualify Linux artifact attestation",
          "body": "## Summary\n\nBind the Kungfu v4 Linux CLI release candidate to Buildchain v3 GitHub keyless artifact attestation.\n\n## Related issue\n\n- Buildchain qualification: kungfu-systems/buildchain#1956\n\n## Changes\n\n- request attestation for the Linux x64 CLI tarball in the reusable build workflow\n- grant the promotion workflow only the GitHub OIDC and attestation permissions required by the signer\n- bind the release rehearsal contract to the exact Buildchain runtime, signer, platform, subject path, policy, and environment\n- refresh workflow authority and binding evidence\n\n## Verification\n\n- `./shifu release:promotion:rehearse`\n- `./shifu check:gate-catalog`\n- staged pre-commit gate completed successfully\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7b6b-ae6d-76cea57487f2\"],\n  \"summary\": \"Bind the v4 Linux CLI release candidate to Buildchain v3 keyless GitHub artifact attestation\",\n  \"verification\": [\"./shifu release:promotion:rehearse\", \"./shifu check:gate-catalog\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change is bounded to GitHub-hosted OIDC artifact attestation and exact release-evidence bindings. No long-lived signing credential is introduced.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n\n\n\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T09:33:28Z",
          "mergedAt": "2026-07-27T09:55:04Z",
          "additions": 153,
          "deletions": 40,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 221,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/221",
          "title": "feat(site): add local core bundle preview",
          "body": "Merge feature/local-site-bundle-preview into main (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-27T09:51:49Z",
          "mergedAt": "2026-07-27T10:03:41Z",
          "additions": 413,
          "deletions": 1,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 10,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/10",
          "title": "feat(course): expose agent work handoffs",
          "body": "## Summary\n- expose the Agent run behind every course outline version\n- show a five-step creator/app/Agent/PostgreSQL/approval handoff\n- distinguish first drafts, revisions, and alternative drafts\n\n## Validation\n- npm run check\n- agent-120 isolated Compose qualification on 127.0.0.1:18092\n- PostgreSQL backup/restore counts matched (3:3:2:3:5)",
          "author": "dongkeren",
          "createdAt": "2026-07-27T10:10:14Z",
          "mergedAt": "2026-07-27T10:10:58Z",
          "additions": 210,
          "deletions": 19,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 11,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/11",
          "title": "fix(course): clarify legacy agent summaries",
          "body": "## Summary\n- give pre-handoff versions an action-derived delivery summary\n- state when an older version lacks structured per-change data\n\n## Validation\n- npm run check\n- browser review against the live PostgreSQL-backed legacy versions",
          "author": "dongkeren",
          "createdAt": "2026-07-27T10:14:14Z",
          "mergedAt": "2026-07-27T10:14:58Z",
          "additions": 14,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1625,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1625",
          "title": "feat(site): publish complete progressive reader bundle",
          "body": "## Summary\n\nPublish the complete progressive reader contract for the Kungfu site bundle so downstream sites can render one consistent human-first and Agent-readable product experience from content and bounded configuration.\n\n## Changes\n\n- add progressive topic and child-page navigation across the complete product route\n- expose exact source provenance and KFD-3 machine entry points\n- centralize first-screen guidance, Agent co-reading, and Kungfu UNGFU brand metadata\n- record the implemented reader closure in the layer-complete product ADR and refresh the generated ADR map\n\n## Verification\n\n- ./shifu --filter @kungfu-tech/site test\n- ./shifu adr:audit -- --json\n- staged repository gate, including documentation links, ADR map freshness, portable format authority, and Biome\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7c91-9cc2-6dbd18d68dff\"],\n  \"summary\": \"Complete the package-owned progressive reader and machine-entry site bundle surface\",\n  \"verification\": [\"site and spec package tests\", \"ADR audit and navigation freshness gate\", \"staged repository gate\"]\n}\n-->\n\n## Governance risk check\n\nThis changes official brand, documentation, package, and machine-entry presentation surfaces. The package schemas, deterministic generator, verifier, exact-source roots, and tests retain the authority boundary.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated with behavior\n- [x] Generated ADR navigation refreshed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T09:28:43Z",
          "mergedAt": "2026-07-27T10:17:57Z",
          "additions": 1895,
          "deletions": 55,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1631,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1631",
          "title": "ci(release): serialize dev alpha candidates",
          "body": "## Outcome\n\nMakes Dev to Alpha candidate patrol event-driven after both qualification workflows, with an offset 30-minute recovery patrol and single-flight settlement from Buildchain.\n\n## Behavior\n\n- workflow_run observes Dev Verify Patrol and Alpha promotion preflight completions for dev/v4/v4.0\n- recovery schedule runs at minute 17 and 47 instead of once daily\n- observer remains read-only; only the settlement job receives write permissions\n- manual dry-runs remain non-mutating\n- reusable workflow and runtime are pinned to merged immutable Buildchain commit 1ccbb93811ccd52cd83eda156d89fba05cc60c75\n\n## Evidence\n\n- ./shifu check:source passed\n- source acceptance included 679 Node contract tests, 116 runtime upgrade tests, and all publication/workflow authority gates\n- targeted patrol and publication-control tests passed\n- actionlint passed\n- live no-write run 30250144602 detected existing managed PR #1613 in state active\n- settlement job was skipped and no second Alpha PR was created\n\nBuildchain dependency kungfu-systems/buildchain#1967 is merged. Supersedes #1620 and #1621. The replacement branch is linear because the protected dev merge queue uses REBASE; final tree identity with #1621 head 89b3a24a22ae2091b4a762364d5c0d330dce0d0a is exact.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This delivery changes release qualification scheduling and candidate settlement control without changing a product architecture decision.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-27T10:09:23Z",
          "mergedAt": "2026-07-27T10:17:58Z",
          "additions": 40,
          "deletions": 17,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1632,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1632",
          "title": "fix(ci): reuse exact successful queue proof",
          "body": "## Summary\n\n- reuse one exact, successful merge-group affected-native proof when native or SDK work is required\n- bind proof v2 to sdkRequired and fail closed on missing, ambiguous, expired, drifted, or unsuccessful producer evidence\n- skip duplicated native/SDK/Shifu/KFD heavy validation only after exact proof verification; keep first-run validation unchanged\n\n## Why\n\nPR #1590 produced two merge-group runs for the same exact SHA. Concurrency serialized them, but the second run still repeated the full native/SDK gate because proof reuse excluded sdk-required runs. This change closes that observed duplicate-validation jitter without weakening the required gate.\n\n## Validation\n\n- ./shifu check:source\n- ./shifu check:release-publication-control-plane\n- ./shifu kfd:buildchain:check\n- ./shifu adr:map:check\n- node --test scripts/affected-native-proof.test.mjs scripts/run-core-affected-native.test.mjs scripts/check-kungfu-gate-catalog.test.mjs\n- node scripts/kungfu-workflow-authority.mjs\n- git diff --check\n- Project Cut: qualified, compositionChanged=false\n\n## Safety\n\nThe first exact candidate run still executes the full required gate. Any lookup, artifact, producer, descriptor, schema, repository, SHA, workflow, or sdkRequired mismatch falls back to full validation.\n\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\", \"kind\": \"adr-neutral\",\n  \"reason\": \"Exact fail-closed CI proof reuse closes duplicate validation jitter without changing an architecture contract\"\n}\n\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-27T10:25:33Z",
          "mergedAt": "2026-07-27T10:47:04Z",
          "additions": 105,
          "deletions": 30,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 12,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/12",
          "title": "feat(course): add guided workflow motion",
          "body": "## Summary\n- accept visible placeholder examples with Tab while preserving keyboard navigation\n- animate generate, improve, and approve as honest one-second lifecycle stages\n- add entry, exit, completion, failure, waiting, mobile, and reduced-motion states\n\n## Validation\n- node --check course-business-reference/web/app.js\n- npm run check (25 tests)\n- agent-120 isolated Compose qualification on 127.0.0.1:18093\n- PostgreSQL backup/restore counts matched (3:3:2:3:5)",
          "author": "dongkeren",
          "createdAt": "2026-07-27T10:47:37Z",
          "mergedAt": "2026-07-27T10:48:21Z",
          "additions": 247,
          "deletions": 20,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1633,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1633",
          "title": "feat(product): externalize runtime caches",
          "body": "## Summary\n\nMove disposable Kungfu runtime caches outside signed artifacts and selected workspaces under one cross-platform `KF_CACHE_HOME` contract.\n\nThis is the clean-history successor to #1550. It carries the same qualified tree on top of the current `dev/v4/v4.0` base so the protected rebase merge queue can evaluate it without replaying #1550's historical base-sync merge commits.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Resolve `KF_CACHE_HOME` from explicit override, instance home, or native per-user defaults.\n- Route Python bytecode to `cache/python/<runtimeBuildId>` for native CLI and packaged Desktop processes.\n- Exclude `.pyc` and `__pycache__` from staging and both Electron builder configurations.\n- Add a signed macOS directory Product qualification and the accepted architecture decision record.\n\n## Verification\n\n- `cargo test --manifest-path crates/Cargo.toml -p kungfu-trunk`\n- targeted GUI and product Node tests\n- `cargo clippy --workspace --all-targets -- -D warnings`\n- `./shifu docs:check`\n- `./shifu docs validate --json`\n- `./shifu qualify:product-cache-home` (Developer ID signature valid before and after; app digest unchanged; 367 external bytecode files)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f9ec5-fa5d-76a3-9adb-71611ee67005\"],\n  \"summary\": \"Deliver and qualify the external versioned product cache contract on the signed macOS directory Product\",\n  \"verification\": [\"Rust, GUI, and product tests\", \"Shifu documentation gates\", \"signed Product immutable-tree qualification\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe packaging boundary changes only cache placement and bytecode exclusion. It does not publish a release; retained qualification verifies the existing Developer ID signature without mutating the Product.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T10:29:51Z",
          "mergedAt": "2026-07-27T10:58:29Z",
          "additions": 1107,
          "deletions": 75,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 147,
          "url": "https://github.com/kungfu-systems/libnode/pull/147",
          "title": "fix(release): promote attestation permissions to alpha",
          "body": "## Summary\n- merge the validated dev release permission fix into alpha through an up-to-date promotion branch\n- retain both protected branch histories without writing directly to dev or using admin bypass\n- produce the exact four-platform release-candidate set for `22.22.3-kf.5-alpha.2`\n\n## Evidence\n- dev fix merged in #145 at `4516ff3a128e01845c81b346074f89e4131127bd`\n- predecessor #146 run 30248380195 attempt 2 passed Linux x64, Linux ARM64, macOS ARM64, and Windows x64\n- promotion merge commit is signed off and includes current alpha ancestry",
          "author": "dongkeren",
          "createdAt": "2026-07-27T09:37:39Z",
          "mergedAt": "2026-07-27T11:00:25Z",
          "additions": 4,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1635,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1635",
          "title": "fix(core): bound generated catalog literals",
          "body": "## Summary\n\n- Split the generated primitive catalog JSON into UTF-8-safe C++ raw-string chunks capped at 8 KiB.\n- Reassemble the chunks at compile time while preserving the existing CATALOG_JSON string_view, JSON bytes, and catalog root.\n- Add regression coverage for chunk bounds, Unicode boundaries, byte identity, and generated projection drift.\n\n## Failure evidence\n\n- Exact Alpha candidate run 30256169258 failed only on Windows with MSVC C2026 at primitive_catalog_v2.hpp because one generated raw string exceeded the compiler limit.\n- macOS and Linux membrane jobs passed on the same exact source.\n\n## Verification\n\n- ./shifu node --test scripts/check-primitive-catalog.test.mjs (15/15)\n- ./shifu node scripts/generate-primitive-catalog.mjs --check\n- ./shifu check:staged\n- C++23 syntax-only compile of the generated header\n- Maximum generated line: 8234 bytes\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fixes compiler portability of an existing generated projection without changing primitive semantics, catalog identity, or the public C++ contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; contract is unchanged)",
          "author": "dongkeren",
          "createdAt": "2026-07-27T10:45:53Z",
          "mergedAt": "2026-07-27T11:16:55Z",
          "additions": 105,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1968,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1968",
          "title": "fix(promotion): propagate attestation authority",
          "body": "## Summary\n- propagate artifact-metadata and attestations permissions through the public promotion wrapper and alpha/stable reusable jobs\n- keep the generated workflow and public site contract synchronized\n- make release-passport checkedAt injectable end-to-end so KFD support verification is deterministic instead of wall-clock flaky\n\n## Validation\n- targeted build-surface tests: 89/89\n- targeted KFD release-passport test: 1/1\n- full `corepack pnpm run check`: 915/915 unit tests and 6/6 action bundles\n\n## Downstream evidence\nFixes the startup failure exposed by libnode Release - New Version run 30260255724 after consumer-level attestation permissions were added.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T11:18:12Z",
          "mergedAt": "2026-07-27T11:23:29Z",
          "additions": 84,
          "deletions": 64,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1971,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1971",
          "title": "chore(release): promote attestation envelope to alpha",
          "body": "Promotes the current dev/v3/v3.0 release authority fixes into alpha through the policy-native publish-gate branch.\\n\\nSource dev merge: #1968\\nSupersedes: #1970 (same exact source commit)\\n\\nValidation: source PR passed Verify, Governance Authority Audit, and complete Build Surface Fixture.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T11:26:03Z",
          "mergedAt": "2026-07-27T11:28:59Z",
          "additions": 1013,
          "deletions": 189,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1973,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1973",
          "title": "Prepare v3.0.2-alpha.6",
          "body": "Create the generated version-state commit for v3.0.2-alpha.6.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: e48aadba016f39ead070e73eff9a7c4c1a25d08b -> 218934297502bffba229462aeef1baf29d1adebc\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T11:33:35Z",
          "mergedAt": "2026-07-27T11:36:58Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1972,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1972",
          "title": "fix(macos): retain safe notarization rejection evidence",
          "body": "## Summary\n\n- preserve rejected notarization submission identity and retrieve the Apple notary log inside the credential island\n- emit only a bounded allowlist of redacted rejection fields while keeping raw command output secret\n- use one injected verification time across KFD support projection, release passport generation, and verification\n- regenerate committed action and site bundles\n\n## Release evidence\n\nKungfu Alpha Build run 30256169690 reached the final credential island after all three platform builds and artifact relays passed, but job 89960917062 reported only a generic notarization rejection. This patch makes the next exact-source retry actionable without exposing credentials or raw Apple output.\n\n## Verification\n\n- `node --test tests/kfd-product-gates.test.mjs tests/macos-credential-island.test.mjs` (17/17)\n- `pnpm run check` (916/916; action bundle integrity 6/6)\n- `xcrun notarytool help log` on the protected macOS executor\n\n## Compatibility\n\nAccepted notarizations and existing `parseNotaryResult` semantics are unchanged. The broader signing-authority work in #1895 does not provide this bounded rejection diagnostic and is not coupled to this fix.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T11:29:33Z",
          "mergedAt": "2026-07-27T11:37:17Z",
          "additions": 250,
          "deletions": 91,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1638,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1638",
          "title": "feat(kfx): establish canonical manifest authority",
          "body": "## Summary\n\nEstablish `kungfu.kfx.json` as the only KFX manifest authority while preserving `package.json` as npm transport metadata.\n\nThis is the first ordered successor slice for Atlas Assignment `2026-07-27-kungfu-native-kfx-registry-foundation-conversion-ready`. It is intentionally stacked on #1624 and does not merge, queue, or independently settle the parent. Fact/Work authority and Control Suite recursive dogfood remain later ordered gates.\n\n## Changes\n\n- weld contract v9 to `kungfu.kfx.json` and migrate all first-party KFX packages and fixtures\n- reject legacy-only and dual-authority `package.json#kungfuConfig` inputs with typed diagnostics\n- move native, Python, TypeScript, SDK, product, TUI, Skill, GUI, and freeze consumers to the canonical manifest\n- refresh deterministic roots, canonical policy, Buildchain witnesses, tests, and documentation\n- preserve the protected Agent Qualification Lab boundary unchanged\n\n## Verification\n\n- `./shifu fix && ./shifu check`\n- `./shifu test:native-kfx-admission`\n- `./shifu test:kfx-profile-suite`\n- `./shifu test:agent-profile-sdk`\n- `./shifu test:profile-kfd3-qualification`\n- `./shifu check:domain-profile-authoring`\n- no tracked `package.json` authors `kungfuConfig`\n- Qualification Lab protected diff is empty\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-7ef4-b28b-ee1fbaf9e62e\"\n  ],\n  \"summary\": \"Establish kungfu.kfx.json as the sole KFX manifest authority without claiming the later Fact/Work or recursive Control Suite gates.\",\n  \"verification\": [\n    \"./shifu fix && ./shifu check\",\n    \"./shifu test:native-kfx-admission\",\n    \"./shifu test:kfx-profile-suite\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo package was published and no deployment occurred. The generated evidence is repository-local verification for this authority migration.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated\n- [x] Parent #1624 remains open and unqueued\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T11:36:59Z",
          "mergedAt": "2026-07-27T11:39:55Z",
          "additions": 1622,
          "deletions": 961,
          "changedFiles": 112
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1637,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1637",
          "title": "feat(release): embed Shifu and Xinfa distributions",
          "body": "## Summary\n\n- route `kungfu shifu ...` and `kungfu xinfa ...` in-process to the authoritative Rust libraries\n- keep npm/Core distribution limited to the Kungfu executable\n- add protected tag-only Shifu/Xinfa releases with checksums, BOMs, and source-bound GitHub attestations\n\n## Validation\n\n- full `./shifu check:source` passed on the exact candidate tree\n- component distribution 6/6, Shifu/Xinfa source 28/28, KFD 5/166, semantic amplification 6/70/0\n- six-target release rehearsal will be rerun on this exact head\n\nThis is the final linear replacement for #1583 and #1634. It is one signed-off commit directly on `017e7e1a4c7a047f9cf6d18f5ae3f1fe35c92dcb`, after the active merge queue advanced the generated governance surfaces.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-7740-812b-32762d430059\",\n    \"KF-ADR-019f86da-4f90-7ca2-8757-52f713bd3df8\",\n    \"SHIFU-ADR-019f86da-4f90-7eac-ad5f-db132ae04d50\"\n  ],\n  \"summary\": \"Complete the bounded embedded-library and independently released component distribution stage for Shifu and Xinfa.\",\n  \"verification\": [\n    \"Shifu source acceptance and Rust workspace qualification\",\n    \"full Kungfu product build and exact package boundary checks\",\n    \"native component release workflow rehearsal and protected review\"\n  ]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-27T11:07:29Z",
          "mergedAt": "2026-07-27T11:47:26Z",
          "additions": 1155,
          "deletions": 3097,
          "changedFiles": 50
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1975,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1975",
          "title": "fix(promotion): bound stable shell inputs",
          "body": "## Summary\\n\\n- stop the alpha router from forwarding alpha-only GitHub artifact attestation inputs to the stable v3 shell\\n- record the stable compatibility exclusions in the promotion routing contract\\n- assert all three inputs stay absent from the stable job\\n\\n## Root cause\\n\\nCross-repository consumers failed at workflow startup because GitHub statically validates both router lanes and stable v3 does not define these alpha-only inputs.\\n\\n## Verification\\n\\n- `node --test tests/promotion-channel-router.test.mjs tests/build-surface.test.mjs`\\n- `corepack pnpm run check` (916/916 tests, 6 action bundles)",
          "author": "dongkeren",
          "createdAt": "2026-07-27T11:50:14Z",
          "mergedAt": "2026-07-27T11:55:06Z",
          "additions": 11,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 222,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/222",
          "title": "Release production from 6c6b756abe04",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `6c6b756abe04acb8157b81831ff2cd6cc252ece5`\n- Artifact hash: `31edf20c004470f1f62e0c9c6314cd81fb220c2c80e8b6def2d52fd2e19be0c5`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/30256529931)\n- Required label: `buildchain-release`\n- Release branch: `release/production-6c6b756abe04`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-27T10:17:00Z",
          "mergedAt": "2026-07-27T11:58:35Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1976,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1976",
          "title": "chore(release): promote stable input envelope fix to alpha",
          "body": "Promotes current dev/v3/v3.0 into alpha through the policy-native publish-gate lane.\\n\\nIncludes: #1975 and the current dev head.\\n\\nThe generated Buildchain contract digest was refreshed after merging protected alpha ancestry.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T11:56:07Z",
          "mergedAt": "2026-07-27T11:59:09Z",
          "additions": 261,
          "deletions": 96,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1977,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1977",
          "title": "Prepare v3.0.2-alpha.7",
          "body": "Create the generated version-state commit for v3.0.2-alpha.7.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: c0ccc4b25d65ad0e007e36d8545dfdf06853bb89 -> c83cb444d79c2e647de6e12a0bfde68dfaf57701\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T12:03:49Z",
          "mergedAt": "2026-07-27T12:06:42Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1639,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1639",
          "title": "feat(ci): add artifact-free latency observation",
          "body": "## Summary\n\n- add an explicit --latency-only mode that keeps branch-rule, merge-queue, required-job, and source-planner authority\n- skip large native diagnostic artifact downloads while marking cache and attribution evidence unknown\n- keep qualification and retained-baseline updates fail closed, with direct gate coverage and operator documentation\n\n## Why\n\nA full 30-sample queue-inclusive refresh currently downloads hundreds of MB per native pull request and would require many GB. The latency-only observation mode produced the same required and delivery window in minutes without turning partial evidence into qualification.\n\n## Validation\n\n- ./shifu check:source\n- ./shifu test:gate-latency (61/61)\n- node scripts/code-complexity-budget.mjs\n- live PR #1635 readback completed in 11.6s with nativeArtifacts=skipped and retainedBaselineEligible=false\n- git diff --check\n\n## Safety\n\nThe default command remains full artifact-backed collection. Latency-only is explicit, native evidence remains unknown, verdict qualification stays false, and retained baselines remain ineligible.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\", \"kind\": \"adr-neutral\",\n  \"reason\": \"Artifact-free observation changes measurement transport only and cannot mint qualification or alter Gate semantics\"\n}\n\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-27T11:44:17Z",
          "mergedAt": "2026-07-27T12:11:16Z",
          "additions": 167,
          "deletions": 52,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1641,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1641",
          "title": "test(verify): align Portfolio qualification fixtures",
          "body": "## Summary\n\nAlign the existing qualification fixtures with the shipped Work Control and Portfolio terminology. This repairs Dev Verify Patrol coverage without changing product behavior or public compatibility aliases.\n\n## Related issue\n\nFollow-up to the KFD support governance release qualification.\n\n## Changes\n\n- exercise the primary `openWorkControlProfile` API in the Atlas capability fixture\n- refresh Portfolio render expectations in the live and bundled Work Dashboard fixtures\n\n## Verification\n\n- `./shifu check:source`\n- `git diff --check`\n- historical Dev Verify Patrol run 30261612021 reproduces the three stale fixture failures on macOS and Linux\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"Refresh existing qualification fixtures after the Work Control and Portfolio cutover; product behavior and architecture contracts are unchanged\"}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-27T12:10:06Z",
          "mergedAt": "2026-07-27T12:16:10Z",
          "additions": 13,
          "deletions": 13,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1643,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1643",
          "title": "fix(verify): align Work Control fixtures",
          "body": "## Summary\n\n- Preserve the inherited child process environment when fixture profiles override `KUNGFU_ATLAS_REPO`, so frozen trunk cache paths retain `HOME` and `KF_CACHE_HOME` resolution.\n- Align the Work dashboard fixture assertions with the shipped native Work Control `Portfolio` copy.\n- Repair the exact macOS and Linux fixture failures from Dev Verify Patrol run 30261612021; Windows was already qualifying in that run and independently proved the MSVC catalog-literal fix.\n\n## Failure evidence\n\n- Dev Verify Patrol 30261612021 failed only these three fixtures on macOS and Linux: `kfx-demo-atlas-capability`, `kfx-demo-work-dashboard-atlas-live`, and `kfx-demo-work-dashboard-atlas-view`.\n- The first two replaced the complete child environment and caused frozen trunk to fail with `kungfu: cannot resolve KF_CACHE_HOME: HOME is unset`.\n- The dashboard fixtures still asserted pre-cutover `Work · Live global view` copy after the product shipped `Portfolio · Live federated view`.\n\n## Verification\n\n- Focused execution of all three repaired fixtures against rebuilt Core and frozen product: passed.\n- `node scripts/source-acceptance.mjs`: passed; 681 contract tests reported 671 pass, 10 skip, 0 fail, followed by 40 Work state, 116 runtime-upgrade, and 69 desktop-update tests passing.\n- `git diff --check`: passed.\n- Commit staged gate: passed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This repairs verification fixtures for the already-shipped native Work Control vocabulary and preserves the existing profile runtime environment without changing product semantics or public contracts.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; fixture-only repair)",
          "author": "dongkeren",
          "createdAt": "2026-07-27T12:22:42Z",
          "mergedAt": "2026-07-27T12:29:35Z",
          "additions": 8,
          "deletions": 8,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1642,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1642",
          "title": "fix(release): pin safe Buildchain v3 diagnostics",
          "body": "## Summary\n\nMove the Kungfu Alpha consumer to the protected Buildchain v3 runtime that preserves sanitized Apple notarization rejection diagnostics while retaining the qualified Linux GitHub Artifact Attestation contract.\n\n## Related issue\n\n- Buildchain implementation: kungfu-systems/buildchain#1956\n- Buildchain diagnostics follow-up: kungfu-systems/buildchain#1972\n- Supersedes the Alpha runtime used by kungfu-systems/kungfu#1626\n\n## Changes\n\n- pin the reusable build and promotion workflows to Buildchain `f288ea1ab6a69fa6085f7616261fa5a6ba60f671`\n- bind the Alpha contract lock to `sha256:3757de78a7468ae8a2ec588036a41c33aa55fc77e5ec09f5db22ca222bbdc251` while retaining the compatible v3 digest\n- refresh workflow, publication, KFD, canonical-policy, and semantic-amplification evidence\n- document that sanitized Apple notarization diagnostics are retained without exposing credential material\n\n## Verification\n\n- `./shifu check`\n- `./shifu check:source`\n- `./shifu test:release-admission`\n- `./shifu release:promotion:rehearse`\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7b6b-ae6d-76cea57487f2\"],\n  \"summary\": \"Advance the qualified Linux attestation consumer to the Buildchain v3 runtime with sanitized notarization diagnostics\",\n  \"verification\": [\"./shifu check\", \"./shifu check:source\", \"./shifu test:release-admission\", \"./shifu release:promotion:rehearse\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change is bounded to an exact Buildchain v3 runtime and generated release-evidence bindings. Sanitized diagnostics are retained by Buildchain; no long-lived signing credential or private notarization response is introduced.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T12:19:32Z",
          "mergedAt": "2026-07-27T12:46:03Z",
          "additions": 41,
          "deletions": 41,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1979,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1979",
          "title": "fix(governance): admit Kungfu stable target",
          "body": "## Summary\n\nAdmit the protected Kungfu release/v4/v4.0 target into the Buildchain GitHub Governance Authority so the existing ruleset-policy planner can compile a fail-closed stable ruleset.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- bind stable to the same build, signoff, and validate identities as Kungfu Alpha\n- keep strict checks and one independent approval\n- refresh the generated Node API and Buildchain contract digests\n\n## Verification\n\n- pnpm run check\n- node --test tests/github-governance-authority.test.mjs\n- consumer ruleset-policy-plan produced an exact release/v4/v4.0 create plan with no bypass actors\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes only the admitted governance target descriptor. The generated rollout still requires exact plan-root confirmation and preserves rollback evidence.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (generated public contract digests refreshed)",
          "author": "dongkeren",
          "createdAt": "2026-07-27T12:47:03Z",
          "mergedAt": "2026-07-27T12:53:24Z",
          "additions": 43,
          "deletions": 9,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 5,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/5",
          "title": "feat(hub): deliver coursework multi-platform starter",
          "body": "## Summary\n\nDeliver a bounded single-user Agent/Kungfu coursework experience that makes claim, independent evidence review, follow-up action, and accepted re-review understandable before exposing Episode and hash-root detail. Add native Linux amd64/arm64 package staging, multi-platform image publication, and native smoke qualification.\n\n## Validation\n\n- [x] `npm run check`\n- [x] `bash -n scripts/smoke-image.sh`\n- [x] Commits are signed off (DCO)\n- [ ] Native Apple Silicon Docker coursework smoke against exact packages\n- [ ] Published native amd64 and arm64 image smoke\n\n## Image and authority boundary\n\n- [ ] Exact Kungfu source, package checksum, build-image digest, and runtime image digest are preserved (pending qualification lock)\n- [x] No floating tags, credentials, private data, real Home, host path, Docker socket, host network, privilege, or added capability\n- [x] Web/Node adapters remain projections over public Kungfu commands\n- [x] Pre-Alpha and non-production claims remain explicit\n- [x] State deletion is never automatic\n\n## Assignment\n\nAtlas Assignment: `2026-07-25-kungfu-hub-starter-coursework-multiplatform-delivery`\n\nThe PR remains draft until exact dual-architecture Kungfu package bytes pass the isolated native Apple Silicon smoke and the runtime lock is source/run/hash complete.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T01:46:58Z",
          "mergedAt": "2026-07-27T13:23:51Z",
          "additions": 1210,
          "deletions": 263,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1647,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1647",
          "title": "feat(kfx): establish Fact and Work authority",
          "body": "## Summary\n\nEstablish the Core-native Fact/Work authority for KFX registry state and lifecycle mutations while preserving the reusable parser, resolver, graph, host, and diagnostics surfaces from #1624.\n\nThis is the second ordered successor slice for Atlas Assignment `2026-07-27-kungfu-native-kfx-registry-foundation-conversion-ready`. It is intentionally stacked on #1624 and does not merge, queue, or independently settle the parent. Control Suite recursive dogfood remains the final ordered gate.\n\n## Changes\n\n- embed the typed KFX Domain Profile in Core and publish the named Fact Cut at `profiles/kfx/registry`\n- model registry packages, providers, contributions, dependencies, Work, Warrant, Episode, and Settlement as immutable Facts and relations\n- enforce exact expected-old Cut/revision CAS for every mutation\n- make package metadata, scan output, and language adapters thin observations/projections rather than authority\n- remove `registry-history.jsonl` and independent generation lifecycle authority\n- keep desired, observed, and verdict state distinct across native, Python, and TypeScript surfaces\n- preserve v1/v2 generation inputs only as frozen validate-only compatibility; v3 uses Cut/revision\n- leave the protected Agent Qualification Lab boundary unchanged\n\n## Verification\n\n- `./shifu build:core`\n- `./shifu check`\n- `./shifu kfd:buildchain`\n- `ctest --test-dir framework/core/build -R '^kungfu_native_kfx_contract_tests$' --output-on-failure`\n- Node KFX host/native binding tests: 3/3 passed\n- Python KFX contract/trust tests: 28 passed\n- affected-native exact source `327b866650d647b94d84fe466274c907584eb2e1..271725d61dbc3e34474d7b832234811a79aec1d2`: 21/21 passed\n- affected-native receipt verified with plan digest `sha256:bea855ba6b40c1cbb2ffda7181728ace50d2fb5cb13c9158820e7ad24b700f73`\n- public leak / private Atlas path / AI-maintenance scan: no matches\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-7ef4-b28b-ee1fbaf9e62e\"\n  ],\n  \"summary\": \"Establish KFX Fact and Work authority without claiming the later recursive Control Suite gate or parent settlement.\",\n  \"verification\": [\n    \"./shifu build:core\",\n    \"./shifu check\",\n    \"affected-native receipt sha256:bea855ba6b40c1cbb2ffda7181728ace50d2fb5cb13c9158820e7ad24b700f73\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo package was published and no deployment occurred. The generated evidence is repository-local verification for this authority migration.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and contracts updated\n- [x] Parent #1624 remains open and unqueued\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T13:24:32Z",
          "mergedAt": "2026-07-27T13:27:08Z",
          "additions": 1230,
          "deletions": 384,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 148,
          "url": "https://github.com/kungfu-systems/libnode/pull/148",
          "title": "chore(buildchain): accept alpha 7 contract",
          "body": "Summary:\n- Accept the exact Buildchain v3.0.2-alpha.7 contract on the alpha lane.\n- Preserve the existing major-compatible contract policy.\n\nVerification:\n- corepack pnpm verify-kfd-witnesses\n- corepack pnpm verify-release\n- git diff --check\n\nThis update establishes a fresh protected dev-to-alpha lineage for the corrected promotion workflow.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T12:17:43Z",
          "mergedAt": "2026-07-27T13:36:20Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1584,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1584",
          "title": "feat(hub): add native Linux ARM64 coursework delivery",
          "body": "## Summary\n\nAdd the native Linux ARM64 product and Hub CLI delivery path required by the coursework starter, backed by the exact public libnode ARM64 package and current Buildchain controller. This linear replacement preserves the reviewed final tree from #1572 after its long-running moving-base merge history could not be synthesized by the protected merge queue.\n\n## Related issue\n\nAtlas Assignment: 2026-07-25-kungfu-hub-starter-coursework-multiplatform-delivery\n\n## Changes\n\n- preserve Episode payload references and bare digest inputs used by the starter workflow\n- add the dedicated hosted native Linux ARM64 Hub CLI qualification lane\n- consume @kungfu-tech/libnode 22.22.3-kf.5-alpha.1 on all supported package platforms\n- register Linux ARM64 Core packaging and npm publication authority\n- bind the staged delivery to the Docker-first Hub Starter ADR\n\n## Verification\n\n- ./shifu check:source\n- commit staged gates\n- exact final tree of reviewed PR #1572, excluding six unrelated upstream Markdown whitespace lines\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f9388-a139-7355-b9f2-f6dd9aa91042\"],\n  \"summary\": \"Stage native Linux ARM64 Hub CLI and Core package delivery for the Docker-first coursework starter\",\n  \"verification\": [\"./shifu check:source\", \"node scripts/check-npm-package-registry.mjs\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe new lane is credential-free and delegates exact artifact production and evidence binding to pinned Buildchain reusable workflows. Publication remains gated by existing protected workflows.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-27T02:31:22Z",
          "mergedAt": "2026-07-27T13:43:22Z",
          "additions": 659,
          "deletions": 248,
          "changedFiles": 68
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1654,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1654",
          "title": "docs(qualification): publish auditable demo evidence",
          "body": "## Summary\n\nPublish the first content-addressed public evidence pack for the auditable exact-output demo and project it into the managed README and accepted Agent Work ADR.\n\nThe evidence binds source `0c584fc0e6446a07a5bdb1462738ffab47dddadb`, Build run `30230901970`, frozen Buildchain `625384b4927222022a2cd0758399afbf9333ccdc`, renderer image digest, Gate root, media root, and exact Release Passport root. Publication is GitHub-artifacts-only; no package publication or production deployment occurred.\n\n## Related work\n\n- Exact Build: https://github.com/kungfu-systems/kungfu/actions/runs/30230901970\n- Buildchain release: `@kungfu-tech/buildchain@3.0.2-alpha.2`\n- Staging site delivery: https://github.com/kungfu-systems/site-kungfu-tech/pull/169\n- Pipeline repair: #1581\n- Failed diagnostic run: https://github.com/kungfu-systems/kungfu/actions/runs/30225695823\n\n## Changes\n\n- retain the bounded GIF and machine-readable public evidence record under the exact Passport root\n- generate the README demo block from that evidence and lock its heading contract\n- complete the qualification narrative with exact artifact IDs, digests, roots, expiry, and non-claims\n- add the public evidence record to the accepted Agent Work ADR and refresh deterministic navigation projections\n\n## Verification\n\n- `./shifu test:auditable-demo` (21 passed)\n- `./shifu docs:check` (402 Markdown files; 105 tests; ADR, links, toolchain, and examples passed)\n- `./shifu check:staged` (passed)\n- independent frozen Buildchain Gate root verification\n- independent media checksum verification\n- exact Kungfu Release Passport verification\n- staging read-back of JSON, proof page, and MP4 from `staging.kungfu.tech`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-786d-aa24-a97705e13917\"],\n  \"summary\": \"Retain and publicly project the exact-output auditable demo evidence pack without widening its release or production claims.\",\n  \"verification\": [\"exact Build run 30230901970\", \"frozen Buildchain Gate verification\", \"media and Release Passport checksum verification\", \"full staged documentation gate\", \"staging site read-back\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR records exact public evidence and an alpha Buildchain package identity. It adds no credentials, publishing authority, production deployment, or release-channel promotion.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and deterministic ADR projections updated\n- [x] No production deployment or package publication triggered",
          "author": "dongkeren",
          "createdAt": "2026-07-27T13:58:02Z",
          "mergedAt": "2026-07-27T14:16:35Z",
          "additions": 339,
          "deletions": 61,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1658,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1658",
          "title": "feat(kfx): bind host admission identities",
          "body": "## Summary\n\nPublish one Core-owned Experience/Flow host descriptor that binds contribution, owner, graph, plan, generation, capability, authorization and receipt identities for GUI, TUI, CLI and Agent consumers.\n\nThis is the host-contract prerequisite inside the third ordered successor slice for Atlas Assignment `2026-07-27-kungfu-native-kfx-registry-foundation-conversion-ready`. It is intentionally stacked on #1624. It does not merge, queue, or independently settle the parent; the Control Suite recursive-dogfood gate remains next.\n\n## Changes\n\n- upgrade the Core host descriptor to `kungfu.kfx.experience-flow-host/v2`\n- bind the exact registry, graph, plan, Cut/revision, generation, contribution, facet, capability, trust and authorization roots\n- fail closed before execution for preview-only or mismatched exact admissions\n- expose thin TypeScript and Python projections without semantic or mutation authority\n- add representative GUI, TUI, CLI and Agent adapters that preserve the same Core identities\n- keep missing optional presentation typed as dormant while the semantic contribution remains active\n- update the one expected host receipt-dependency root\n- leave protected Agent Qualification Lab files and PR #1585 unchanged\n\n## Verification\n\n- `./shifu build:core`\n- `./shifu test:native-kfx-admission`\n- `./shifu check` (after `./shifu pack:spec` materialized the ignored Spec test prerequisite)\n- native KFX CTest: 2/2 passed\n- Python native KFX + ActionEnvelope: 13/13 passed\n- public API host/storage projection: 6/6 passed\n- Node native binding root parity: 2/2 passed\n- GUI/TUI/CLI/Agent exact-root adapter test: 2/2 passed\n- Qualification Lab / PR #1585 isolation: passed with 0 protected changes\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-72df-add3-948f3ae38c3a\"\n  ],\n  \"summary\": \"Bind one surface-neutral KFX host descriptor without claiming the later recursive Control Suite gate or parent settlement.\",\n  \"verification\": [\n    \"./shifu build:core\",\n    \"./shifu test:native-kfx-admission\",\n    \"./shifu check\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo package was published and no deployment occurred. The generated Spec artifact was ignored local verification input only.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Exact-root host and cross-language tests pass\n- [x] Parent #1624 remains open and unqueued\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T14:14:41Z",
          "mergedAt": "2026-07-27T14:16:52Z",
          "additions": 387,
          "deletions": 16,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 13,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/13",
          "title": "feat(course): add optional local and hosted inference",
          "body": "## Summary\n\n- add an OpenAI-compatible Agent Work adapter while preserving existing mock-bound courses\n- add hosted-endpoint and optional local llama.cpp/Qwen delivery overlays without embedding model weights in the core image\n- persist external work, delivery, version, and approval evidence in PostgreSQL\n- expose the Agent contribution and handoff clearly in the course UI\n- document digest/revision/checksum pinning, offline image tags, and delivery size tradeoffs\n\n## Validation\n\n- npm run check (31 tests)\n- default, hosted, and offline Docker Compose configuration rendering\n- amd64 image build with source revision label\n- local Qwen end-to-end registration, course creation, first generation, revision, and approval\n- LAN deployment health and browser smoke test\n\n## Version impact\n\nMinor: adds optional inference delivery modes and additive database migrations while keeping the default mock mode compatible.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T14:13:20Z",
          "mergedAt": "2026-07-27T14:19:08Z",
          "additions": 1153,
          "deletions": 67,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1657,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1657",
          "title": "fix(shifu): admit Linux ARM64 portable cache profile",
          "body": "## Summary\n\n- admit `linux-arm64` in the explicit-off qualification cache profile used by the native Hub CLI Build lane\n- lock the complete native Build platform set with a focused regression test\n\n## Verification\n\n- `node --test scripts/check-shifu-cache-contract.test.mjs` (28/28)\n- `./shifu check:staged`\n- observed failure repaired: Build run 30272373738 rejected `linux-arm64` before install because the profile platform set was incomplete\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Complete the existing explicit-off qualification profile platform set; no architecture, release authority, or cache mode changes\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis repairs the fail-closed platform admission boundary without adding publication authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-27T14:11:34Z",
          "mergedAt": "2026-07-27T14:20:46Z",
          "additions": 19,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1661,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1661",
          "title": "feat(agent): add repository work experiment",
          "body": "## Summary\n\nAdd an independently owned, manual repository-work experiment for two fresh OpenCode sessions backed by the local Qwen3-Coder model. Kungfu carries a content-rooted, transcript-free continuation from an investigation-only Agent A to a bounded-repair Agent B, while an external deterministic oracle remains authoritative.\n\nThe final agent-120 observation is intentionally reported as a fail-closed experimental result: Kungfu completed the two-session continuity and evidence path, but the model repair did not pass the visible or hidden oracle.\n\n## Related issue\n\nDedicated Kungfu Assignment `2026-07-27-kungfu-local-agent-repository-load-experiment`.\n\n## Delivery topology\n\nThis is the final protected-queue linear delivery following source review PR #1627 and prior delivery replays #1645 and #1652. Commit `849381ae32b192e9cc8ee143d7e0fd257cf3b06b` has protected base-at-replay `f2c7df9000f340ab62f008888245bd558ec41b23` as its single parent and combines the reviewed experiment with the protected ARM64 and Auditable Demo base changes. The original implementation commit `9bd83f8d6e017cc030522605b5f3cbfb854dddac`, source-review history, and portable seal remain preserved on #1627; no history was force-pushed or deleted.\n\n## Changes\n\n- add the fixed `incident-board-replay-v1` repository fixture, contract, hidden oracle, and reference repair\n- add a native Kungfu runner for two fresh OpenCode processes with zero transcript handoff\n- enforce a read-only Agent A Warrant and a three-file Agent B Warrant in a least-privilege container\n- retain bounded session, Episode, Warrant, visible, hidden, and failure diagnostics\n- add a manual agent-120 workflow pinned to the released OpenCode image and local model endpoint\n- register the workflow as qualification-only, non-publication authority\n- document explicit non-integration boundaries for Auditable Demo, Qualification Lab, release gates, model ranking, and public claims\n\n## Verification\n\n- `./shifu test:agent-repository-work` (10/10)\n- `./shifu check:release-publication-control-plane`\n- `node scripts/check-kungfu-gate-catalog.test.mjs` (23/23)\n- `./shifu maintainability:complexity -- --json`\n- full staged source/documentation/invariant gate on every commit\n- protected PR checks: DCO, governance, source acceptance, and affected-native\n- final exact-head agent-120 run at `849381ae32b192e9cc8ee143d7e0fd257cf3b06b` with `qwen3-coder:30b-opencode-64k`:\n  - two distinct provider sessions completed\n  - Agent A made zero workspace changes\n  - Agent B received zero prior transcript bytes and no human restatement\n  - both Kungfu Episodes passed frame fsck\n  - Agent B changed only allowlisted `incident_board/lease.py` and `incident_board/replay.py`; no scope violation occurred\n  - the independent verifier rejected the incomplete repair and both visible and hidden oracle checks failed, so the experiment failed closed\n  - elapsed model experiment time: `190462 ms`\n  - bounded report file root: `sha256:9c95e11906b1ee6d572d8db1c718be80f95cf6bdd8fceaed4604f2e0cad9812c`\n  - oracle report root: `sha256:32fa74f2ac173e4fd4b7bd352756f6265fb6410bf4e7d635ceda411e4f376ef7`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This independent bounded qualification experiment does not alter a product architecture contract, release gate, publication surface, Auditable Demo, or Qualification Lab\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe workflow invokes only the pinned OpenCode CLI image and host-bound local OpenAI-compatible endpoint without credentials. It uploads one bounded diagnostic report and is registered as non-publication.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T14:26:18Z",
          "mergedAt": "2026-07-27T14:57:52Z",
          "additions": 3736,
          "deletions": 2,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1663,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1663",
          "title": "fix(product): isolate Agent Hub smoke cache",
          "body": "## Summary\n\n- Route disposable Python bytecode and product caches from the installed Agent Hub qualification to its isolated runtime cache.\n- Preserve the stronger invariant that the isolated user HOME remains entirely absent after qualification.\n- Add a regression fence and refresh the semantic amplification projection without increasing the grandfathered dist.mjs line count.\n\n## Failure evidence\n\n- Alpha Build run 30267579084, macOS job 89983080260, failed before signing with: installed kungfu Agent Hub smoke modified its isolated user home.\n- The native launcher now derives PYTHONPYCACHEPREFIX from KF_CACHE_HOME. Without an explicit smoke cache, the platform default resolves through HOME and creates the isolated user directory.\n\n## Verification\n\n- node --test product/scripts/dist.test.mjs: 26 passed, 0 failed.\n- node scripts/source-acceptance.mjs: passed; 684 contract tests reported 674 pass, 10 skip, 0 fail, followed by 40 Agent Work, 116 runtime-upgrade, and 69 desktop-update tests passing.\n- node scripts/code-complexity-budget.mjs: passed.\n- Biome, TypeScript tooling check, git diff --check, and commit staged gate: passed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This repairs installed-product qualification after the already-implemented disposable product cache contract; it does not change public semantics or widen release claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; qualification wiring only)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T14:35:47Z",
          "mergedAt": "2026-07-27T14:57:53Z",
          "additions": 72,
          "deletions": 16,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1666,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1666",
          "title": "feat(kfx): recursively dogfood control suite",
          "body": "## Summary\n\nDeliver the ordered Control Suite recursive-dogfood gate over the already sealed Manifest, Fact/Work, and Host prerequisites. The first-party `kfx-manager` now consumes the same public KFX `status` / `plan` / `apply` lifecycle as other KFX, while Core retains only the embedded bootstrap ceiling, exact-root verification, named-Cut CAS, safe mode, and last-known-good recovery.\n\nThis PR is intentionally stacked on #1624 and targets `feature/native-kfx-registry-foundation`. It does not merge, queue, or independently settle #1624. It completes the ordered successor implementation needed to assess the parent as conversion-ready; Agent Qualification Lab remains deferred and untouched.\n\n## Changes\n\n- add a narrow `kfxControl` capability and real Control Suite UI to the first-party system KFX\n- embed a minimal Core bootstrap policy for the `kfx-manager` identity, product roles, runtime tier, and capability ceiling\n- route Control Suite install/update through the existing public KFX plan and Fact/Work named-Cut settlement path\n- require exact plan, policy, package, graph, registry, trust, Cut, revision, and authorization identities at apply time\n- preserve prior accepted bytes as Episode-referenced last-known-good recovery and enter deterministic read-only safe mode for absent or corrupt active bytes\n- expose thin CLI, Python/Agent, TUI, and GUI projections that retain one status root without becoming lifecycle authorities\n- add recursive v1 install, v2 update, self-grant refusal, post-plan mutation, restart, stale-CAS, corruption, rollback, and no-private-history tests\n- leave `package.json`, scan output, registry-history JSONL, and independent generation outside final authority\n- leave protected Agent Qualification Lab files and PR #1585 unchanged\n\n## Verification\n\n- `ninja -C framework/core/build -j4 kungfu_native_kfx_contract_tests`\n- `ctest --test-dir framework/core/build -R '^kungfu_native_kfx_contract_tests$' --output-on-failure`\n- `./shifu build:core`\n- `./shifu test:native-kfx-admission`\n- `./shifu check`\n- native recursive Control Suite contract: passed\n- Python and TypeScript host parity: passed\n- schema and journal authority gates: passed\n- Qualification Lab / PR #1585 isolation: passed with 0 protected changes\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-72df-add3-948f3ae38c3a\"\n  ],\n  \"summary\": \"Complete the ordered recursive Control Suite gate through public Fact/Work authority without merging or independently settling parent #1624.\",\n  \"verification\": [\n    \"./shifu build:core\",\n    \"./shifu test:native-kfx-admission\",\n    \"./shifu check\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo package was published and no deployment occurred.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Manifest → Fact/Work → Host → Control ordering is preserved\n- [x] Parent #1624 remains open and unqueued\n- [x] Qualification Lab remains untouched\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T14:57:50Z",
          "mergedAt": "2026-07-27T15:00:07Z",
          "additions": 1062,
          "deletions": 5,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 151,
          "url": "https://github.com/kungfu-systems/libnode/pull/151",
          "title": "chore(release): reconcile alpha ancestry",
          "body": "Merge the current protected alpha ancestry into dev without changing the source tree. This makes the pending standard dev-to-alpha promotion topology up to date while preserving the reviewed contract-lock change.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T13:39:06Z",
          "mergedAt": "2026-07-27T15:03:29Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 14,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/14",
          "title": "feat(course): add click-to-install local model runtime",
          "body": "## Summary\n- add a header AI runtime menu with explicit Mock or Local model selection\n- keep the model absent until an authenticated user clicks Download & install\n- stream progress, pin byte size and SHA-256, then atomically install the GGUF model\n- preserve existing course backend bindings while new courses use the selected runtime\n\n## Validation\n- npm run check\n- bash -n course-business-reference/scripts/compose-qualification.sh\n- bash -n scripts/smoke-image.sh\n- agent-120 empty-volume browser E2E: register, click install, select Local model, create a course, generate a real Qwen outline\n- agent-120 production candidate health and LAN UI check on port 8090",
          "author": "dongkeren",
          "createdAt": "2026-07-27T15:10:25Z",
          "mergedAt": "2026-07-27T15:11:18Z",
          "additions": 725,
          "deletions": 27,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 15,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/15",
          "title": "fix(course): keep model wait state healthy",
          "body": "## Summary\n- treat the intentional pre-install model wait as a healthy llama delivery state\n- switch to the real private llama health endpoint as soon as the verified model file appears\n- retain the no-startup-download source check\n\n## Validation\n- npm run check\n- docker compose config\n- empty production model volume on agent-120",
          "author": "dongkeren",
          "createdAt": "2026-07-27T15:13:51Z",
          "mergedAt": "2026-07-27T15:14:39Z",
          "additions": 10,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 16,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/16",
          "title": "fix(course): make local AI output explicit",
          "body": "## Summary\n- keep the AI runtime menu DOM stable while installation status is polled\n- expose each course’s persistent Mock or Local AI binding in the collection and editor\n- mark the entire right-hand outline as local-model output or deterministic Mock reference content\n\n## Verification\n- `npm run check` (37 tests passed)\n\n## Deployment scope\n- intended for the LAN-only course reference on port 8090\n- preserves PostgreSQL, app-state, and click-installed model volumes\n- does not change Hub Starter on port 8080\n\n## Checklist\n- [x] Commits are signed off (DCO)\n- [x] Public-facing text is in English\n- [x] No credentials or model bytes are included",
          "author": "dongkeren",
          "createdAt": "2026-07-27T15:28:56Z",
          "mergedAt": "2026-07-27T15:37:46Z",
          "additions": 303,
          "deletions": 49,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1578,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1578",
          "title": "refactor(maintainability): close terminal governance gaps",
          "body": "## Summary\n\n- close all source-side maintainability gaps with fail-closed complexity, waiver, baseline-transition, semantic-authority, and terminal-evidence contracts\n- execute every supported source and Agent discovery route from a physically locked cold checkout without dependency repair, network access, or cache writes\n- converge KFX manifest decisions on the canonical contract authority and extract cohesive complexity-governance and cold KFD runtime ownership\n- bind seven child Assignments to one versioned terminal evidence matrix and the exact protected commit being qualified\n\n## Exact candidate\n\n- commit: `423d1af2a115c06dae040394306cdb51b4a4975a`\n- protected base included: `f0496f12bdceecd4fde64d6a17cad67cd7443a0e`\n- PR Core source + affected-native: run `30250165783` — success\n- Linux/macOS/Windows exact-source Alpha preflight: run `30250168190` — success\n- fresh-context independent review: `kungfu-origin` approved this exact candidate; no unresolved in-scope P0, P1, or material P2 finding\n\nThe final Linux/macOS/Windows product matrix is intentionally run after merge\nagainst the exact protected merge commit. Earlier Build runs and candidate\npreflights became obsolete when the protected base advanced; they are not cited\nas qualifying evidence.\n\n## Local validation\n\n- `./shifu check:source` — passed; 687 Node contract tests (684 pass, 3 Windows-only skip, 0 fail), Python suites (40 + 116 pass), desktop update suite (69 pass), tooling type check, Ruff, and mypy over 195 source files\n- `./shifu test:workspace-continuation` — passed; 8/8 JS contract tests and 81/81 Python Workspace/Assignment orchestration tests\n- `node --test product/scripts/dist.test.mjs` — passed; 24/24 product distribution contract tests\n- `./shifu build:core` — passed; Node, Electron, and Python native products built on macOS ARM64\n- physically read-only cold source fixture — passed; declared discovery routes performed zero source writes\n- semantic amplification projection — 6 families, 70 surfaces, 0 issues\n- final-base staged repository gate, Rust clippy/tests, DCO, and `git diff --check` — passed\n\n## Claim boundary\n\nThis PR implements the source, governance, authority-convergence,\nhotspot-decomposition, and exact-evidence selectors. It does not claim public\nrelease, signing, deployment, physical durability, or live-stream safety.\nProduct qualification is accepted only from artifacts whose\n`publish-source-sha` equals the exact protected merge commit. Native Assignment\nsettlement remains a separate terminal decision after that product evidence is\ngreen.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f9f04-f8bd-7002-a702-1b9f66827ec0\"],\n  \"summary\": \"Implement terminal maintainability governance, physically read-only source acceptance, authority convergence, responsibility decomposition, and exact protected-commit evidence selectors.\",\n  \"verification\": [\n    \"PR Core run 30250165783\",\n    \"Alpha promotion preflight run 30250168190\",\n    \"framework/maintainability/terminal-evidence-matrix.test.mjs\",\n    \"scripts/readonly-agent-bootstrap.test.mjs\",\n    \"./shifu test:workspace-continuation\"\n  ]\n}\n-->\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] ADR projection and navigation map are current\n- [x] P1 baseline and transition governance are fail-closed\n- [x] Exact candidate source, affected-native, and three-platform preflight are green\n- [x] Independent exact-candidate review is approved\n- [ ] Exact protected-merge-commit three-platform product qualification is green\n- [x] No release, signing, deployment, durability, or live-stream claim is silently inferred\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T00:58:36Z",
          "mergedAt": "2026-07-27T15:42:39Z",
          "additions": 12771,
          "deletions": 5076,
          "changedFiles": 68
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1644,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1644",
          "title": "feat(ci): reuse exact PR proof in merge queue",
          "body": "## Summary\n\n- run the complete affected native, SDK, Shifu, and KFD graph on pull requests and seal an authoritative v3 proof after every dependency passes\n- reuse exactly one trusted PR proof in merge-group runs when base, checkout tree, plan, partition, tier, and toolchain identities still match\n- distinguish the GitHub run trigger head from the checked-out synthetic merge SHA so pull-request proofs remain auditable without rejecting valid synthetic checkouts\n- fail closed to the full required graph for forks, failed or expired producers, ambiguity, source drift, identity drift, or non-matching queue proofs\n\n## Validation\n\n- `node --test scripts/affected-native-proof.test.mjs scripts/check-kungfu-gate-catalog.test.mjs` (33/33)\n- `./shifu test:gate-latency` (57/57 before latest base rebase; targeted post-rebase contracts pass)\n- `node scripts/check-source-complexity.mjs`\n- `node framework/release/publication-control-plane.mjs check --qualifying`\n- `./shifu check:source` (685 source contract tests: 675 pass, 10 skip; 40 Core; 116 runtime upgrade; 69 desktop; TypeScript and Biome pass)\n\n## Live acceptance\n\nThis PR is also the producer-side live test. After its full PR graph seals the proof, the merge-group run must reuse that exact proof and skip the duplicate native/SDK/Shifu/KFD execution while retaining source and preflight checks.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-019f86da-4f90-79a1-bc85-4b542fecf011\"],\n  \"summary\": \"Restore exact PR-to-merge-group qualification proof reuse without weakening source, governance, plan, partition, or toolchain identity checks.\",\n  \"verification\": [\"focused proof and gate-catalog tests\", \"complete build-free source acceptance\", \"live PR producer and merge-group reuse qualification\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects qualification evidence only. It does not publish a product, create a release, or introduce credentials.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for the proof authority change\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T12:26:29Z",
          "mergedAt": "2026-07-27T15:46:33Z",
          "additions": 225,
          "deletions": 144,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1665,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1665",
          "title": "fix(build): bind updated portable cache profile digest",
          "body": "## Summary\n\n- bind both native Build lanes to the exact current portable-off cache profile digest\n- refresh the generated workflow authority projection\n- add a regression check that both digest bindings match the checked-in profile bytes\n\n## Validation\n\n- `node scripts/check-kungfu-gate-catalog.mjs`\n- `node --test scripts/check-shifu-cache-contract.test.mjs scripts/check-kungfu-gate-catalog.test.mjs`\n- `./shifu check:staged`\n\n## Release boundary\n\n- [x] No package or channel publication is performed by this PR.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Synchronize the exact Build cache profile digest with the already-reviewed profile bytes; no architecture or release authority changes\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-27T14:40:34Z",
          "mergedAt": "2026-07-27T16:00:36Z",
          "additions": 18,
          "deletions": 14,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1676,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1676",
          "title": "fix(ci): bind cache measurement to current profile",
          "body": "## Summary\n\n- Bind the Windows layer-gate measurement harness to the exact checked-in portable-off cache profile bytes.\n- Extend the cache-contract regression so future profile changes must update both Build lanes and the measurement harness.\n- Keep KFD support claims and release channel contracts unchanged.\n\n## Related delivery\n\n- #1665 already repaired the two Build workflow bindings and added their byte-derived regression.\n- This PR closes the remaining measurement-harness drift on top of that protected merge instead of duplicating its workflow changes.\n\n## Verification\n\n- node --test scripts/check-shifu-cache-contract.test.mjs: 28 passed, 0 failed.\n- node scripts/check-kungfu-gate-catalog.mjs: 38 gates, 6 profiles, 26 invocations, 23 workflows aligned.\n- node framework/release/publication-control-plane.mjs check: passed.\n- ./shifu check:source: passed on the rebased two-file change.\n- git diff --check: passed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix restores the exact current cache-profile digest in a qualification measurement harness and adds a regression fence; it does not change architecture or ADR delivery state.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; qualification harness wiring only)",
          "author": "dongkeren",
          "createdAt": "2026-07-27T16:11:33Z",
          "mergedAt": "2026-07-27T16:23:07Z",
          "additions": 8,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1674,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1674",
          "title": "fix(release): grant reusable promotion permissions",
          "body": "## Summary\n\nFix the Alpha/Release publication workflow startup failure by granting the exact caller permissions required by the pinned Buildchain reusable workflow.\n\n## Related issue\n\nKFD support governance release closeout.\n\n## Changes\n\n- grant `actions: write`, `checks: write`, and `pull-requests: write` to the `promote` reusable-workflow caller\n- refresh the governed workflow-authority projection\n- add a regression assertion for the Buildchain caller permission contract\n\n## Verification\n\n- `actionlint .github/workflows/release-new-version.yml`\n- `node scripts/kungfu-workflow-authority.mjs --check`\n- `node --test scripts/release-promotion-rehearsal.test.mjs` (15 passed)\n- complete staged pre-commit gate, including KFD support matrix and negative fixtures\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"This restores the permissions already required by the pinned Buildchain release contract and does not change product or architecture semantics.\"}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change is limited to GitHub Actions job permissions and is validated against the pinned reusable workflow permission request.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation projection updated for changed workflow authority\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T16:08:36Z",
          "mergedAt": "2026-07-27T16:27:05Z",
          "additions": 21,
          "deletions": 7,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1669,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1669",
          "title": "feat: add Agent Work Lab product experience",
          "body": "## Summary\n\n- introduce Agent Work Lab as a reusable KFX Suite with shared TUI framework primitives\n- add the interactive TUI command plane and aligned GUI/TUI Work search\n- open Assignment search results in the exact Work detail view and keep Profile refresh non-blocking\n- extend the accepted local artifact catalog decision with an explicitly unqualified preview promotion path\n\n## Verification\n\n- project-cut merge queue admission: qualified\n- Agent Work Lab and Profile Suite contract tests: passed\n- GUI product search tests: 4 passed\n- semantic amplification tests: 5 passed\n- complete product dist and installed CLI smoke: passed before the final rebase\n- full shifu check: all affected gates passed; the existing canonical-policy mismatch remains outside this branch diff\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-019f86da-4f90-7885-9597-bfdcb4fd4453\"],\n  \"summary\": \"Deliver the Agent Work Lab product experience and the bounded preview promotion path used for local review.\",\n  \"verification\": [\"Project Cut merge queue admission\", \"Agent Work Lab and Profile Suite contract tests\", \"GUI product search regression tests\", \"semantic amplification checks\", \"complete local product distribution and installed CLI smoke\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe preview path remains explicitly unqualified and does not create release or publication authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for the preview promotion semantics",
          "author": "dongkeren",
          "createdAt": "2026-07-27T15:28:36Z",
          "mergedAt": "2026-07-27T16:58:04Z",
          "additions": 4774,
          "deletions": 1237,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1679,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1679",
          "title": "feat(release): establish stable channel governance",
          "body": "## Summary\n\nEstablish the first-class Kungfu stable-channel control plane without publishing a stable release.\n\nThis final fresh linear candidate supersedes #1646, #1662, #1667, #1671, and #1675. Earlier candidates were displaced by merge-queue history behavior and by real generated-governance conflicts after #1661, #1578/#1644, then #1665, #1676, and #1674 merged. The last conflict was reconciled by retaining #1674 release permissions and regenerating the publication registry root. This branch replays the same Stable capability directly on the resulting exact dev head and regenerates the affected authority roots.\n\n## Related issue\n\n- Supersedes: #1646, #1662, #1667, #1671, #1675\n- Buildchain governance authority: kungfu-systems/buildchain#1979\n- Atlas goal: 2026-07-27-kungfu-stable-channel-control\n\n## Changes\n\n- add an exact-SHA pinned Stable Candidate Patrol with 24-hour soak, hold, revoke, and explicit release-now inputs\n- bind one exact release/v4/v4.0 source-lock PR to independent review and no automatic merge\n- add an external stable ruleset contract with no bypass actors and exact required checks\n- make product-stable conformant in the publication control plane with durable history, latency, readback, and rerun evidence\n- record a merged-Buildchain dry-run proving stable publication prepares v4.0.1-alpha.0 without mutating refs\n\n## Verification\n\n- linear parent: e2a123096a966a2afa96895e790e3a09aa1125a1\n- candidate tree: 4b2291fb4990ec6276b00c29bb223d502be18653\n- stable and governance targeted tests: 40 passed\n- full source acceptance completed all remaining suites; its sole stale workflow-count assertion was updated from 23 to the current closed-world count of 24 and reverified\n- Buildchain release dry-run at 7629c4b499cd2d4eebf4c020fbc81637ae1dcb39\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7b6b-ae6d-76cea57487f2\"],\n  \"summary\": \"Establish exact stable candidate governance, protected source-lock promotion, durable evidence, and next-patch Alpha continuation.\",\n  \"verification\": [\"shifu check:source\", \"alpha promotion preflight\", \"stable candidate and ruleset contract tests\", \"Buildchain release dry-run\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe workflow owns candidate selection and evidence only. It cannot approve, merge, or publish the stable candidate PR, and it is pinned to the merged Buildchain authority commit.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T16:33:04Z",
          "mergedAt": "2026-07-27T17:02:10Z",
          "additions": 417,
          "deletions": 113,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1670,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1670",
          "title": "feat(shifu): add read-only KFD source UX",
          "body": "## Summary\n\n- Add canonical build-free `./shifu kfd status|query|check` source-checkout operations with concise human output and stable Agent JSON.\n- Keep the existing KFD support matrix as the sole Kungfu authority while mechanically separating 166 declared KFD-3 surfaces from 0 hard-Gate-enforced surfaces.\n- Preserve compatibility aliases, document the source-versus-installed-product boundary, and expose deeper source and installed Agent Hub verification routes.\n- Register the KFD operations in the repository-wide read-only source route inventory without duplicating KFD support facts.\n\n## Related work\n\n- Kungfu Assignment `2026-07-27-kungfu-shifu-kfd-native-readonly-ux`\n- Assignment request root `sha256:a8af41ee74c847824de0e62de568ec3c77bfc89a989c5229c26af207781906f0`\n\n## Verification\n\n- Exact head: `e012645a642aa3414f272ed631cde85c195324e2`.\n- `./shifu test:shifu-kfd-readonly`: 39 passed, 0 failed.\n- Physically locked cold checkout and empty HOME: status, query, check, compatibility aliases, and full nested source acceptance passed twice with no checkout or HOME mutation and no cargo/corepack/curl/fnm/pnpm/uv invocation.\n- `./shifu check:source`: build-free source gate passed; 694 contract tests reported 691 passed, 3 conditional skips, and 0 failures, followed by Work 40/40, runtime-upgrade 116/116, and desktop-update 69/69.\n- KFD support authority: KFD-1/2/3 evidence check passed; support matrix check passed with 13 rows and 4 bounded shipped-support rows.\n- Commit staged gates, TypeScript, Biome, Markdown links/contracts, complexity ratchet, route inventory, DCO, and latest protected-base integration passed.\n- ADR projection now binds PR #1670 as the partial implementation slice; the obsolete legacy evidence exemption was removed and the dev `stage-ready` release gate passes locally with zero findings.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7626-861e-3fdee887abd2\"],\n  \"summary\": \"Extend the accepted Shifu bootstrap and delegation surface with one bounded build-free KFD source inspection family without creating a second support authority.\",\n  \"verification\": [\"physically locked cold-checkout zero-write fixture\", \"39 focused Shifu KFD tests\", \"complete build-free source-acceptance gate\", \"KFD authority and projection checks\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR reads and explains checked-in KFD and release-gate evidence. It adds no publication authority, release, credential use, Buildchain change, or installed-product mutation.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for human and Agent entrypoints\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T15:46:58Z",
          "mergedAt": "2026-07-27T17:58:54Z",
          "additions": 843,
          "deletions": 45,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 149,
          "url": "https://github.com/kungfu-systems/libnode/pull/149",
          "title": "chore(release): promote Buildchain alpha 7 contract",
          "body": "Promote the reviewed v3-alpha contract-lock update through the protected dev-to-alpha topology. The exact dev SHA passed all four platform builds, including Linux ARM64, in run 30265327885.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T13:36:39Z",
          "mergedAt": "2026-07-27T18:12:33Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 152,
          "url": "https://github.com/kungfu-systems/libnode/pull/152",
          "title": "Prepare v22.22.2-alpha.0",
          "body": "Create the generated version-state commit for v22.22.2-alpha.0.\n\nBuildchain generated this PR because protected branch dev/v22/v22.22 rejected direct generated bookkeeping.\n\nRejected update: 54e79f2ea0e712da57d4afc5fb8857a89a310ed3 -> 8b3d33b7fac3676267064532fe27be85c78496a2\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T18:16:00Z",
          "mergedAt": "2026-07-27T18:20:09Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1680,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1680",
          "title": "fix(ci): deduplicate exact proof producers",
          "body": "## Summary\n\n- cancel stale or duplicate pull-request workflow runs for the same PR ref while preserving non-cancelling, exact-SHA merge-group serialization\n- deterministically select the newest trusted artifact when GitHub retains multiple successful artifacts for one content-addressed proof identity\n- reject a pull-request source that cannot be replayed by the protected `REBASE` queue before native, SDK, Shifu, or KFD work starts\n- keep complete bundle, source, tree, plan, partition, producer, receipt, and toolchain verification fail-closed before any proof is reused\n\n## Related issue\n\n- Parent goal: dev required gate latency SLO and merge queue jitter closure\n- Live duplicate trigger: PR #1675 produced two concurrent full native graphs for the same head SHA\n- Live conflict trigger: #1678 was dequeued as `merge_conflict` because its conflict-resolution merge commit could not be replayed by the protected queue\n- Supersedes #1678 with a linear source revision on the exact current dev base\n\n## Changes\n\n- use the pull-request ref as the concurrency key and cancel in-progress pull-request duplicates\n- order exact trusted candidates by creation time, immutable artifact id, and workflow run id\n- retain the real candidate count and verify the selected bundle through the existing strict proof verifier\n- run the existing read-only `project-cut:queue-admission` replay in PR candidate preflight; merge-group events skip this PR-only admission\n- refresh closed-world workflow authority and publication roots and document both retained-artifact and rebase-replay behavior\n\n## Verification\n\n- focused proof, cache, Gate catalog, and queue-replay tests: 43/43\n- `node framework/release/publication-control-plane.mjs check`: qualifying, 24 workflows, 10 surfaces\n- staged pre-commit gate: 45 latency tests, 17 invariant tests, 107 documentation tests, generated roots, and Biome all pass\n- real replay fixture against repository SHAs: #1678 head returns `merge-conflict`; this linear head returns `qualified`\n- live run `30289351509` was cancelled when the updated same-ref run started; active SDK and three-platform Shifu jobs did not run to completion\n- live run `30289761750` passed `Verify protected merge-queue replay` in candidate preflight\n\n## Live acceptance\n\nPR #1675 exposed two successful full producer graphs for the exact same PR head. The updated #1680 head has now proved same-ref cancellation live. The merge-group run must still reuse only a fully verified exact proof and skip the duplicate native, SDK, Shifu, and KFD graph.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-019f86da-4f90-79a1-bc85-4b542fecf011\"],\n  \"summary\": \"Deduplicate exact pull-request proof producers, reject unreplayable queue sources early, and deterministically reuse retained exact artifacts without weakening proof verification.\",\n  \"verification\": [\"focused proof and queue-replay tests\", \"complete build-free source acceptance\", \"live same-ref producer cancellation\", \"live PR rebase admission\", \"merge-group exact proof reuse qualification\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects qualification evidence selection and workflow scheduling only. It does not publish a product, create a release, or introduce credentials.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for the proof and queue-admission authority changes\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T17:27:49Z",
          "mergedAt": "2026-07-27T18:26:11Z",
          "additions": 111,
          "deletions": 35,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1683,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1683",
          "title": "fix(qualification): declare source runtime boundary",
          "body": "## Summary\n\n- declare the named foreign-runtime allowance only for the source-checkout native coordinator fixture; production runtime guards remain unchanged\n- register the native AgentSession runtime-port test as raw terminal evidence\n- synchronize the primitive catalog policy digest and regenerate its KFD witness/release-gate projections\n\n## Validation\n\n- `./shifu node --test framework/agent-session/tests/runtime-port.native.test.mjs` (4/4, including mmap + nng native E2E)\n- `./shifu node developer/sdk/src/sdk.js contract audit --json` (`ok: true`, `status: current`)\n- `node scripts/buildchain-kfd-evidence.mjs --check --json` (`ok: true`)\n- `./shifu check` (`changed-scope gate passed`)\n\n## Release boundary\n\n- [x] No package or channel publication is performed by this PR.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Close a source-checkout qualification boundary and refresh exact derived contract evidence without changing production runtime or release authority\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-27T18:19:17Z",
          "mergedAt": "2026-07-27T18:37:29Z",
          "additions": 31,
          "deletions": 11,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1684,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1684",
          "title": "fix(core): adopt Linux ARM64 libnode package",
          "body": "## Summary\n\n- adopt `@kungfu-tech/libnode@22.22.3-kf.5-alpha.2`, including the published Linux ARM64 optional package and resolver\n- refresh the exact KFD-3 registry, collaboration witnesses, upstream aggregate, and support-matrix roots\n- keep the cold read-only source fixture projection-complete for dependency-bound KFD evidence updates\n\n## Validation\n\n- `./shifu install --lockfile-only`\n- `./shifu check:source`\n- `./shifu exec node --test scripts/readonly-agent-bootstrap.test.mjs`\n- `./shifu exec node scripts/buildchain-kfd-evidence.mjs --check`\n- `./shifu exec node scripts/kfd-support-matrix.mjs --check`\n\n## Release boundary\n\n- [x] No package or channel publication is performed by this PR.\n- [x] The exact Linux ARM64 install and build lifecycle remains a post-merge Alpha qualification requirement.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Adopt the already-reviewed libnode alpha.2 package that repairs the Linux ARM64 runtime resolver and refresh its dependency-bound KFD evidence; no architecture or release authority changes\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T18:43:43Z",
          "mergedAt": "2026-07-27T19:32:38Z",
          "additions": 54,
          "deletions": 46,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 153,
          "url": "https://github.com/kungfu-systems/libnode/pull/153",
          "title": "fix(release): bind Linux ARM64 passport evidence",
          "body": "## Summary\n- derive the KFD-3 prebuild surface set from the canonical collaboration-interface registry\n- declare Linux ARM64 in the KFD-2 four-platform package trust claim\n- advance the immutable release contract to 22.22.3-kf.5-alpha.3\n- lock registry/prebuild surface equality and four-platform trust evidence in lifecycle tests\n- refresh KFD-1/KFD-3 generated witness hashes\n\n## Verification\n- node --test .gyp/libnode-entrypoint.test.js .gyp/libnode-kfd-release-evidence.test.js\n- corepack pnpm verify-kfd-witnesses\n- corepack pnpm verify-release\n- corepack pnpm verify-package-source\n- corepack pnpm exec prettier --check .gyp/libnode-kfd-witnesses.js .gyp/libnode-kfd-release-evidence.test.js\n- git diff --check\n\nFixes the fail-closed release-passport finalization exposed by alpha.2 without bypassing KFD gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T18:29:08Z",
          "mergedAt": "2026-07-27T20:05:25Z",
          "additions": 68,
          "deletions": 17,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1689,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1689",
          "title": "fix(ci): stabilize dev latency cohort selection",
          "body": "## Summary\n\nStabilize the rolling dev required-gate latency cohort without weakening any gate. The collector now identifies the latest merged pull requests by `merged_at` and paginates until later pages cannot enter that window. Updated open pull requests can no longer evict merged delivery samples.\n\nThe delivery cohort also excludes merged pull requests outside the selected window even when older merge-group runs are still visible. Unmerged queue attempts remain included for dequeue and runner-waste evidence.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- collect a complete, bounded latest-merged pull-request window\n- keep merged delivery samples fixed to that selected window\n- retain recent unmerged queue attempts and their merge-group evidence\n- add a regression fixture with updated open pull requests and an older merged run\n\n## Verification\n\n- `./shifu test:gate-latency` — 64 tests passed\n- staged pre-commit gate — passed\n- two consecutive live latency-only reports had identical required samples, delivery samples, percentiles, dequeue counts, repeated-validation counts, and runner-waste totals\n- local source acceptance passed the changed-code, complexity, documentation, gate, and architecture checks; its broad cold-fixture suite later reported the host environment lacked `pytest` on `PATH`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix stabilizes measurement cohort selection without changing gate, release, or architecture contracts\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects only selection of retained latency evidence. It does not alter required checks, qualification thresholds, or publication authority. Regression tests and consecutive live-report equality cover the boundary.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\nNo documentation change is required because the metric contract and public CLI remain unchanged.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T19:18:25Z",
          "mergedAt": "2026-07-27T20:29:11Z",
          "additions": 101,
          "deletions": 14,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1692,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1692",
          "title": "fix(qualification): settle Windows runtime identity handoff",
          "body": "## Summary\n\nBound the Windows product-runtime smoke around the transient coordinator identity handoff observed in exact protected-main qualification. The production runtime preflight remains fail-closed.\n\n## Related issue\n\nMaintainability terminal-closure qualification follow-up; exact Build run 30295340390 reproduced runtime_identity_unverified only on Windows x64.\n\n## Changes\n\n- retry only runtime_identity_unverified from the cold runtime ensure operation\n- observe real runtime status between attempts and stop after 50 x 100 ms\n- preserve immediate failure for unrelated errors and bounded failure for persistent unknown identity\n- add positive, persistent-failure, and unrelated-failure contract tests\n\n## Verification\n\n- KUNGFU_READONLY_PYTEST=\"$PWD/framework/core/.venv/bin/pytest\" ./shifu check:source\n- ./shifu exec -- node --test framework/core/tests/qualification/runtime-activation/run.test.mjs\n- pre-commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix changes only the product qualification harness retry boundary and does not alter the runtime architecture or production preflight contract.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change is limited to the runtime-activation qualification evidence producer; exact source acceptance and cross-platform Build qualification verify the boundary.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not required: production behavior and public contracts are unchanged)",
          "author": "dongkeren",
          "createdAt": "2026-07-27T20:50:32Z",
          "mergedAt": "2026-07-27T21:15:25Z",
          "additions": 110,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 155,
          "url": "https://github.com/kungfu-systems/libnode/pull/155",
          "title": "chore(governance): transfer alpha.3 promotion baton",
          "body": "## Summary\n- add a tree-equivalent, signed-off governance commit\n- transfer the latest protected dev push away from the CODEOWNER identity\n- unblock the independently reviewed dev-to-alpha promotion under `require_last_push_approval`\n\n## Validation\n- no source tree changes\n- commit DCO sign-off enforced locally\n- protected four-platform Build remains required\n- no administrator bypass or protection-rule mutation\n\nThis follows the established protected topology baton pattern from PRs #132 and #135.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T20:09:54Z",
          "mergedAt": "2026-07-27T21:31:48Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1693,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1693",
          "title": "fix(ci): preserve KFD vector bytes on Windows",
          "body": "## Summary\n\nPreserve the canonical LF bytes of the external KFD Runtime 100 vectors on Windows so the embedding membrane qualification hashes the same source bytes on every platform.\n\n## Related issue\n\nRelease qualification follow-up for #1448.\n\n## Changes\n\n- Disable Git line-ending conversion before materializing the exact KFD checkout.\n- Add a source regression that requires the LF configuration to precede checkout.\n- Refresh the closed Gate workflow authority and release publication source roots.\n\n## Verification\n\n- ./shifu check:kfd-agent-runtime-boundary\n- ./shifu check:source\n- git diff --check\n- Staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fixes cross-platform checkout byte preservation without changing an architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe workflow authority and publication-control roots are refreshed from the checked source, and source acceptance verifies both closed-world projections.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-27T21:04:22Z",
          "mergedAt": "2026-07-27T21:37:01Z",
          "additions": 42,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1694,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1694",
          "title": "fix(release): scope ARM64 Hub qualification to CLI",
          "body": "## Summary\n- add a fail-closed `hub-cli` artifact scope to release qualification\n- retain runtime, Episode, ADR, portable-format, and invariant evidence\n- keep desktop, assembled-surface, and cross-language SDK qualification on the full Product matrix\n- bind the dedicated Linux ARM64 workflow and workflow-authority projection to the scoped command\n\n## Validation\n- `node --test scripts/run-release-qualification.test.mjs` (23/23)\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs` (23/23)\n- full repository pre-commit gate\n- `pnpm exec biome check --no-errors-on-unmatched ...`\n- `git diff --check`\n\n## Release diagnosis\nAlpha Build run 30299746748 proved that the native Linux ARM64 Hub CLI build and installed-layout smoke succeeded, then failed only because the headless lane entered `layers.sdk` (unsupported `linux-arm64`) and `layers.surfaces` (missing desktop artifact). This patch keeps those Product-wide gates fail-closed on the full matrix instead of weakening them.\n\n## ADR delivery / release declaration\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix scopes an existing headless release qualification lane to the artifacts it actually builds; it does not alter an architecture contract or weaken the full Product qualification matrix.\"\n}\n-->\n\n## Governance risk check\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n\nThe release evidence boundary is explicit: the Hub CLI lane records its artifact scope while desktop and SDK evidence remain mandatory on the full Product matrix.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T21:12:18Z",
          "mergedAt": "2026-07-27T22:09:55Z",
          "additions": 130,
          "deletions": 23,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 157,
          "url": "https://github.com/kungfu-systems/libnode/pull/157",
          "title": "Promote libnode 22.22.3-kf.5-alpha.3 to Alpha",
          "body": "## Summary\n- promote exact protected dev head `ce6d75b791bca725bd9db15938a6fbc173327283` to `alpha/v22/v22.22`\n- carry the Linux ARM64 KFD-2/KFD-3 release-passport repair and regression coverage\n- publish the immutable `22.22.3-kf.5-alpha.3` package set only after protected Alpha checks\n\n## Qualification\n- source PR #153 merged after independent review\n- protected topology baton PR #155 merged after exact four-platform Build run: https://github.com/kungfu-systems/libnode/actions/runs/30301407726\n- Linux x64, Linux ARM64, macOS ARM64, and Windows x64: success\n- Buildchain controller evidence and aggregate `build`: success\n\nThis replaces #154 without changing the source head. It is authored by the last protected pusher so dongkeren can provide the independent review required by branch protection.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-27T21:33:42Z",
          "mergedAt": "2026-07-27T22:59:25Z",
          "additions": 68,
          "deletions": 17,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 156,
          "url": "https://github.com/kungfu-systems/libnode/pull/156",
          "title": "chore(governance): hand alpha.3 baton to publisher",
          "body": "## Summary\n- add a second tree-equivalent, signed-off governance commit after PR #155 was merged by the CODEOWNER identity\n- keep this PR draft through CI so the final ready/merge window can be executed by `dongkeren`\n- satisfy `require_last_push_approval` without administrator bypass or protection mutation\n\n## Validation\n- no source tree changes\n- DCO sign-off enforced locally\n- protected four-platform Build remains required\n\nThis is the same audited protected-topology baton pattern as PRs #132 and #135, with draft state used to eliminate the concurrent merger race observed on #155.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T21:33:07Z",
          "mergedAt": "2026-07-27T23:04:48Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1696,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1696",
          "title": "fix(ci): promote caches through reused native proof",
          "body": "## Summary\n\nAllow a merge group that reuses an exact successful pull-request native proof to promote the producer's qualified cache payloads into the long-lived dev branch scope without repeating the native build or weakening current-source validation.\n\nSupersedes #1695 after the protected base advanced and its pre-queue admission correctly rejected the stale conflicting source.\n\n## Related issue\n\nDev required-Gate latency SLO follow-up to #1693.\n\n## Changes\n\n- Seal source-, run-, receipt-, partition-, and digest-bound cache payloads on successful pull-request native shards as well as direct merge-group shards.\n- Seal an immutable merge-group cache promotion authority after exact proof reuse, binding the merged head and tree to the verified proof root and producer checkout.\n- Reverify the authority on the trusted dev push, require the exact successful producer run and complete payload partition set, and keep producer receipts source-honest.\n- Separate merged target identity from payload producer identity in the promotion receipt.\n- Refresh Gate workflow authority, release publication roots, tests, and documentation on the current dev base.\n\n## Verification\n\n- `./shifu test:gate-latency`\n- `actionlint .github/workflows/affected-native-cache-promote.yml .github/workflows/affected-native-pr.yml`\n- `./shifu check:gate-catalog`\n- `node framework/release/publication-control-plane.mjs check`\n- `git diff --check`\n- Staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This repairs cache transport after an already-qualified exact proof reuse without changing the Gate scope or architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe merge-group authority, producer proof, payload receipts, workflow inventory, and publication roots are exact and fail closed; current-source configure/build/CTest remains mandatory on every restore.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T22:34:47Z",
          "mergedAt": "2026-07-27T23:06:53Z",
          "additions": 735,
          "deletions": 92,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1697,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1697",
          "title": "fix(release): preserve execution context compatibility",
          "body": "## Summary\n\n- Keep `artifactScope` local to release orchestration and qualification summaries.\n- Preserve the existing strict Gate `--execution-context` schema for Product and Hub CLI qualification.\n- Add an exact-key regression assertion so future scope metadata cannot leak into the shared protocol.\n\n## Failure evidence\n\n- Alpha Build run 30309951990, macOS job 90123376255: `shifu: --execution-context has unknown or missing fields`.\n- The product build and zero-burden suites passed before the strict Gate consumer rejected the added field.\n\n## Verification\n\n- `node --test scripts/run-release-qualification.test.mjs` — 23/23 pass.\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs` — 23/23 pass.\n- Full staged pre-commit gate — pass.\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"This compatibility fix removes orchestration-only metadata from an existing strict execution-context protocol; it does not change an architecture contract or qualification coverage.\"}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-27T23:02:22Z",
          "mergedAt": "2026-07-27T23:10:06Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 17,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/17",
          "title": "feat(course): make model binding visible and switchable",
          "body": "## Summary\n- add an auditable course-level Mock/Local model switch without rewriting historical versions\n- snapshot backend routing on every outbox command and expose current-binding versus selected-version provenance\n- make local alternatives generate independently from the business brief instead of copying the prior Mock outline\n\n## Validation\n- `npm run check` (39 tests)\n- `bash course-business-reference/scripts/compose-qualification.sh`\n- agent-120 amd64 image build and `/readyz` health check\n- browser flow: Mock v1 -> Local v2/v3 -> Mock v4 with source labels preserved\n\n## Deployment\n- candidate `kungfu-course-business-reference:e85d6d8-amd64` is healthy on LAN-only port 8090\n- PostgreSQL, llama/model volumes, and Hub Starter port 8080 were preserved",
          "author": "dongkeren",
          "createdAt": "2026-07-27T23:12:40Z",
          "mergedAt": "2026-07-27T23:13:35Z",
          "additions": 463,
          "deletions": 53,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 18,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/18",
          "title": "fix(course): separate saved input from model output",
          "body": "## Summary\n- render the saved business brief as explicit non-AI input\n- add a hard Local AI / Mock output boundary in the course draft\n- mark each generated section and strengthen local-model prompt grounding\n\n## Verification\n- npm run check\n- bash -n scripts/smoke-image.sh\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-27T23:24:59Z",
          "mergedAt": "2026-07-27T23:32:38Z",
          "additions": 130,
          "deletions": 26,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1698,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1698",
          "title": "fix(qualification): recalibrate hosted alpha budget",
          "body": "## Summary\n\nRecalibrate the fail-closed Alpha qualification budget from current exact protected-main Build timings. No Gate is skipped, shortened, or weakened; the independent 180-minute workflow ceiling remains unchanged.\n\n## Related issue\n\nMaintainability terminal-closure qualification follow-up. Exact protected-main Build run 30306399387 completed every visible Linux qualification and invariant, then failed only because the inherited 2400-second execution allowance expired. Its Windows build also established the current slowest successful upstream lifecycle.\n\n## Changes\n\n- raise Alpha end-to-end budget from 5400s to 8400s\n- raise the upstream allowance from 2400s to 4200s\n- retain the 600s reserve, yielding a 3600s execution allowance\n- regenerate the policy matrix and record exact Linux/Windows timing evidence\n- update execution-profile contract tests\n\n## Verification\n\n- `node scripts/run-release-qualification.test.mjs` (23/23)\n- `node scripts/check-kungfu-gate-catalog.mjs --write`\n- `node scripts/check-kungfu-gate-catalog.test.mjs` (23/23)\n- `PATH=/Users/dkr/Worktrees/kungfu/feature/maintainability-terminal-closure/framework/core/.venv/bin:$PATH ./shifu check:source` (698 tests: 688 pass, 10 expected skips, 0 fail; Python 40 + 116; desktop 69; tooling type check and Biome pass)\n- pre-commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This operational qualification calibration preserves the existing Gate set, workload profiles, fail-closed behavior, and outer workflow timeout; it does not alter product architecture.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change only recalibrates exact-source Alpha qualification timing from retained hosted evidence. It does not publish, deploy, or grant credentials.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and generated policy projection updated\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T23:27:46Z",
          "mergedAt": "2026-07-27T23:45:50Z",
          "additions": 24,
          "deletions": 10,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1616,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1616",
          "title": "feat(release): add Linux ARM64 Core package",
          "body": "## Summary\n\nClose the Core native distribution and npm publication gap with an exact 29-package public Release inventory. Alpha and Release use the Buildchain S3 relay path, the native runner preset adds hosted Linux ARM64, and the new ARM64 lane builds and qualifies the bounded `@kungfu-tech/core-linux-arm64` artifact while the existing three platforms retain full-product qualification.\n\n## Related issue\n\nAtlas goal `2026-07-25-kungfu-npm-core-platform-distribution-closure`.\n\n## Changes\n\n- add Linux ARM64 to the Core platform package authority and exact npm registry\n- keep all 29 release packages public and close the 39-file cross-platform artifact set\n- route Alpha and Release through Buildchain `v3.0.2-alpha.7` at immutable SHA `c83cb444d79c2e647de6e12a0bfde68dfaf57701`\n- use `kungfu-v4-native`: three full-product lanes plus one hosted Linux ARM64 Core-only lane\n- require `s3-to-github-artifacts`, four platform receipts, and the signed macOS credential-island artifact\n\n## Verification\n\n- `./shifu project-cut:queue-admission -- --base d22606161449e7c6c84fcbf890506594e55b1b62 --head f7eba3554ed7bbef29dea190257e317f437e81a3` (qualified; one replayed commit)\n- `./shifu test:npm-core-platform-distribution` (83 tests; 80 passed, 3 Windows-only skipped)\n- `./shifu check:source` (702 tests; 699 passed, 3 platform-only skipped; build-free source gate passed)\n- commit hook staged gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7c91-9cc2-6dbd18d68dff\"],\n  \"summary\": \"Implement the 29-package public inventory, Linux ARM64 Core-only distribution lane, native runner preset, and mandatory S3 relay binding.\",\n  \"verification\": [\"./shifu check:source\", \"./shifu test:npm-core-platform-distribution\", \"./shifu project-cut:queue-admission\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change adds one official package identity and modifies release publication wiring. The exact inventory, immutable Buildchain contract lock, source acceptance, gate catalog, S3 relay binding, and negative fixtures verify these boundaries without performing a Kungfu publication.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T07:32:42Z",
          "mergedAt": "2026-07-28T00:16:19Z",
          "additions": 407,
          "deletions": 107,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 158,
          "url": "https://github.com/kungfu-systems/libnode/pull/158",
          "title": "Prepare v22.22.2-alpha.1",
          "body": "Create the generated version-state commit for v22.22.2-alpha.1.\n\nBuildchain generated this PR because protected branch dev/v22/v22.22 rejected direct generated bookkeeping.\n\nRejected update: ce6d75b791bca725bd9db15938a6fbc173327283 -> 757da0cab3e94380954085693fe997d45f944fb9\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-27T23:03:16Z",
          "mergedAt": "2026-07-28T00:36:57Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 19,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/19",
          "title": "fix(course): recover from failed inference actions",
          "body": "## Summary\n- keep established course model bindings usable after generation or revision failures\n- project the latest failure into the UI with retry and model-switch guidance\n- transactionally recover existing courses incorrectly marked failed\n- increase the bounded local-model output budget and keep responses concise\n\n## Verification\n- npm run check (43 tests)\n- bash -n scripts/smoke-image.sh\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T00:34:30Z",
          "mergedAt": "2026-07-28T00:39:01Z",
          "additions": 159,
          "deletions": 7,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1700,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1700",
          "title": "fix(core): consume qualified libnode alpha.3",
          "body": "## Summary\n\n- adopt `@kungfu-tech/libnode@22.22.3-kf.5-alpha.3`, whose protected four-platform release carries the repaired Linux ARM64 passport and package set\n- refresh the exact KFD-3 registry, collaboration witnesses, upstream aggregate, and support-matrix roots from the published package\n- remove the stale blanket Buildchain-to-KFD override so stable Buildchain 3.0.0 retains its declared KFD alpha.41 metadata while Buildchain Alpha retains alpha.47, with a regression that prevents either line from silently absorbing the other\n\n## Related delivery\n\n- libnode PR #153 produced `v22.22.3-kf.5-alpha.3` from the protected Alpha source after all four platform lanes passed.\n- This PR consumes that published result; it does not duplicate the libnode release implementation.\n\n## Verification\n\n- `corepack pnpm install --lockfile-only --ignore-scripts --registry=https://registry.npmjs.org/` preserves the exact lockfile on a second run.\n- `corepack pnpm install --frozen-lockfile --ignore-scripts --offline` passes.\n- `node scripts/code-complexity-budget.mjs` passes; the lockfile is one line below its ratchet ceiling.\n- `node scripts/buildchain-kfd-evidence.mjs --check` passes with 5 KFD-2 claims and 166 KFD-3 surfaces.\n- `node scripts/kfd-support-matrix.mjs --check` passes with 13 rows and 4 bounded shipped-support rows.\n- 63 focused SDK, KFD matrix, platform-package, and release-admission tests pass.\n- The cold read-only bootstrap regression passes.\n- The complete staged pre-commit gate passes on both commits, including documentation, KFD, invariant, lint, complexity, and source checks.\n\n## Release boundary\n\n- [x] No package or channel publication is performed by this PR.\n- [x] Exact-source Dev and Alpha qualification remains required after merge before the dependency is a shipped Kungfu release.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Consume the already-qualified libnode alpha.3 release, refresh dependency-bound KFD evidence, and remove a stale dependency override without changing an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes only source-bound dependency and release-evidence inputs; publication remains downstream of protected Dev and Alpha workflows.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; generated KFD evidence and regression coverage are updated)",
          "author": "dongkeren",
          "createdAt": "2026-07-27T23:43:53Z",
          "mergedAt": "2026-07-28T01:05:46Z",
          "additions": 72,
          "deletions": 51,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1702,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1702",
          "title": "fix(ci): require native latency SLO",
          "body": "## Summary\n\nFail closed when either the overall or native queue-inclusive required-gate\nlatency stratum exceeds the dev SLO. This prevents a fast non-native majority\nfrom masking a slow native tail.\n\n## Related issue\n\nAtlas Assignment `2026-07-17-kungfu-dev-gate-latency-slo`.\n\n## Changes\n\n- Apply the P50 <= 300 seconds and P95 <= 600 seconds thresholds independently\n  to the overall and native strata.\n- Add a regression where overall P95 passes while native P95 fails.\n- Document the independent-stratum qualification rule.\n\n## Verification\n\n- `./shifu test:gate-latency` (67 passed)\n- `node scripts/code-complexity-budget.mjs`\n- `node scripts/run-docs-check.mjs`\n- Source-acceptance contract suite (690 passed, 10 skipped); its final Biome\n  finding was corrected and the Biome and complexity checks were rerun.\n- DCO and staged repository hooks passed during commit.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fail-closed bug fix corrects SLO verdict evaluation without changing an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T00:35:36Z",
          "mergedAt": "2026-07-28T01:19:35Z",
          "additions": 32,
          "deletions": 8,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1705,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1705",
          "title": "fix(build): hydrate Linux ARM64 libnode dependency",
          "body": "## Summary\n\nRestore the exact native libnode optional dependency before the Linux ARM64 Core-only Buildchain lifecycle. This closes the deterministic failure observed in final run 30317031750 without widening the ARM64 lane into a desktop build or changing publication behavior.\n\n## Related issue\n\nAtlas goal 2026-07-25-kungfu-npm-core-platform-distribution-closure; follow-up to #1616.\n\n## Changes\n\n- retain the Buildchain no-optional install boundary for full-product lanes\n- run one frozen-lock optional hydration step only for the native Linux ARM64 Core lane\n- verify the ARM64 lifecycle plan before rebuild:core\n\n## Verification\n\n- ./shifu test:npm-core-platform-distribution (83 tests; 80 passed, 3 Windows-only skipped)\n- Candidate Source Acceptance passed on the exact commit in run 30318585815\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair the Linux ARM64 dependency hydration path for the already implemented distribution ADR without changing its contract or projection.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo publication is performed. The final Alpha/Release rehearsal remains non-publishing and continues to use the mandatory S3 relay.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Tests cover the lifecycle change\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T00:57:30Z",
          "mergedAt": "2026-07-28T01:23:18Z",
          "additions": 7,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1704,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1704",
          "title": "feat(kfx): reconcile native registry foundation",
          "body": "Reconciles the reusable parser, resolver, graph, host, and diagnostics from #1624 onto current dev/v4/v4.0.\n\nAuthority boundaries:\n- `kungfu.kfx.json` is the declarative Manifest authority; `package.json` is projection metadata only.\n- Native Fact/Work authority remains in Core contracts and receipts; registry history and scan output are evidence, not authority.\n- Control Suite consumption remains a recursive dogfood projection and this PR does not independently settle the parent program.\n\nSource reconciliation:\n- source PR: #1624 @ `9ea1a09080a9f59d0113ca94e95ab3dbd182bb22`\n- source stable patch-id: `ca97d3d1e2b285095fa87e6851178ac5aa6e622d`\n- replacement implementation: `a61ea23d9ddfb2f743dadb3c5c26835dfae3abfc`\n- replacement evidence correction: `2ce1210a28`\n- base: `d4ccae814c435d4442ffb64d7b88d7f8dbc606a8`\n\nValidation:\n- `./shifu build:core`\n- `./shifu test:native-kfx-admission`\n- `./shifu test:kfx-profile-suite` (63 pass)\n- `./shifu check:source` (692 pass, 10 skip, 0 fail)\n- `./shifu docs:check` (107 pass)\n- contract policy / KFD evidence / semantic amplification readback\n\nCloses the implementation gap represented by #1624 through a current-dev replacement; parent settlement remains under its authoritative Assignment.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-72df-add3-948f3ae38c3a\",\n    \"KF-ADR-019f86da-4f90-73f3-b027-c343b2bc8bcc\",\n    \"KF-ADR-019f86da-4f90-7d6c-926a-ddd27dbde8ab\",\n    \"KF-ADR-019f86da-4f90-7ef4-b28b-ee1fbaf9e62e\"\n  ],\n  \"summary\": \"Stage the current-dev native KFX registry foundation while retaining Manifest, Fact/Work, and recursive Control Suite authority boundaries.\",\n  \"verification\": [\n    \"Core build and native KFX admission\",\n    \"KFX Profile Suite 63-pass closure\",\n    \"Build-free source acceptance 692-pass 10-skip closure\",\n    \"Documentation 107-pass and ADR authority audit\",\n    \"Contract policy, KFD evidence, and semantic amplification readback\"\n  ]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T00:50:48Z",
          "mergedAt": "2026-07-28T01:44:09Z",
          "additions": 6155,
          "deletions": 800,
          "changedFiles": 151
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 20,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/20",
          "title": "fix(course): show only persisted local output",
          "body": "## Summary\n- bound every local-model string in the provider schema so Qwen cannot exhaust the 4096-token context inside one JSON field\n- serialize per-user outbox drains and claim inference deliveries before invoking the model\n- show workflow success only after PostgreSQL returns a newly persisted outline version\n\n## Verification\n- npm run check (44 tests)\n- bash -n scripts/smoke-image.sh\n- live Qwen3-0.6B bounded-schema probe on agent-120: finish_reason=stop, valid application outline with 3 modules\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T01:56:29Z",
          "mergedAt": "2026-07-28T02:04:02Z",
          "additions": 96,
          "deletions": 37,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 269,
          "url": "https://github.com/kungfu-systems/kfd/pull/269",
          "title": "docs(kfd): publish load-bearing dogfood baseline",
          "body": "## What\n\nPublishes a progressive, non-normative pre-release evidence baseline for what the KFD primitive system is already carrying inside the founding Kungfu implementation. Adds a first-class `/under-load` site-bundle route, renderer-ready `loadBearingPage`, generic `standalonePages` discovery, navigation metadata, package roots, and fail-closed bundle checks.\n\n## Contribution type\n\n- [x] evidence, counterexample, or independent review\n- [x] decision, registry, schema, verifier, or release surface\n- [x] governance, documentation, or maintenance\n\n## Claim and evidence\n\nThe document distinguishes conceptual coherence, executability, load-bearing founding use, and general qualification. It connects public implementation witnesses across session continuity, long-cycle work, handoff, Profiles, KFX, dogfood, delivery, documentation, and CLI governance. Maturity labels and explicit non-claims prevent incomplete KFX, delivery, historical-advice, KFD-6, external adoption, and cross-domain transfer work from being promoted by narrative. Numbered decisions and accepted live-case cuts remain authoritative.\n\nThe site contract exposes the complete Markdown source with a stable route, source path, non-normative relationship, authority note, rendering kind, TOC depth, and navigation placement. `scripts/check.mjs` fails closed on route, source, page, generic discovery, reading path, and ownership drift.\n\n## Interests and review\n\nFounding-adopter and package-maintainer interest: kungfu-systems develops Kungfu and KFD. The document states that this is founding-adopter evidence, not independent external qualification.\n\n- [x] A substantive change has a reviewer other than its author\n- [ ] Activation or Foundation Revision has an independent reviewer (not applicable; this change activates or revises neither)\n\n## Compatibility and registry agreement\n\n- [x] `node scripts/check.mjs` passes\n- [x] Applicability, compatibility, migration, and supersession impact are explicit\n- [x] Published coordinates remain immutable\n- [x] After Foundation Freeze, decision texts remain append-only (no decision text changes)\n\nFull checks also pass: Hub 20, Runtime 100, native/WASM verifier parity, offline extraction, verifier artifact integrity, and clean `npm pack --dry-run`.\n\n## Version impact (per KFD-1)\n\n- [x] minor (additive documentation and site-bundle page surface)",
          "author": "dongkeren",
          "createdAt": "2026-07-28T02:21:45Z",
          "mergedAt": "2026-07-28T02:25:40Z",
          "additions": 645,
          "deletions": 90,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 21,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/21",
          "title": "feat(course): explain Kungfu work control boundary",
          "body": "## Summary\n\n- label the current course workflow as app-only coordination\n- show the missing Assignment, Evidence, independent review, decision, recovery, and seal boundary\n- expose an optional read-only link to a separate healthy Hub Starter walkthrough\n- preserve the existing PostgreSQL, model, generation, and approval contracts\n\n## Validation\n\n- `npm run check` (48 tests)\n- `bash -n scripts/smoke-image.sh`\n- `bash -n course-business-reference/scripts/compose-qualification.sh`\n- native `linux/amd64` image build on agent-120\n- browser validation for registration, course creation, generation, approval, desktop/mobile layout, and the Hub Starter link\n\n## Deployment evidence\n\n- candidate revision: `2729326c0d9e403fd378427b8d712d8de4e08424`\n- course app: healthy on the LAN-only `192.168.100.120:8090` binding\n- separate Hub Starter: ready in `executing` phase on `192.168.100.120:8080`\n\n## Boundaries\n\n- no native Kungfu course binding is claimed\n- no database, model volume, credentials, public ingress, or Hub Starter state is changed",
          "author": "dongkeren",
          "createdAt": "2026-07-28T02:27:29Z",
          "mergedAt": "2026-07-28T02:28:27Z",
          "additions": 441,
          "deletions": 2,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1706,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1706",
          "title": "fix(ci): decouple cross-platform Shifu observation",
          "body": "## Summary\n\nMove cross-platform Shifu and Xinfa diagnostics out of the dev required critical path while retaining the full required Shifu workspace gate on hosted Linux. Alpha and release qualification remain unchanged.\n\n## Verification\n\n- actionlint affected-native-pr.yml core-build-profiles.yml\n- ./shifu check:gate-catalog\n- ./shifu test:gate-latency (67/67)\n- ./shifu check:source\n- ./shifu docs:check (107/107)\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This CI scheduling change preserves existing gate authority and does not alter an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe workflow bindings, authority projection, publication roots, documentation, and contract tests are updated and verified.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-28T02:01:50Z",
          "mergedAt": "2026-07-28T02:28:38Z",
          "additions": 132,
          "deletions": 77,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 271,
          "url": "https://github.com/kungfu-systems/kfd/pull/271",
          "title": "chore(kfd): anchor alpha 48 release",
          "body": "## What\n\nAdvances the explicit KFD alpha release fact from `1.0.0-alpha.47` to `1.0.0-alpha.48` after the load-bearing dogfood baseline and renderer-ready site contract merged through PR #269. Refreshes only the version-derived KFD-1, KFD-2, and KFD-3 witnesses.\n\n## Contribution type\n\n- [x] decision, registry, schema, verifier, or release surface\n- [x] governance, documentation, or maintenance\n\n## Claim and evidence\n\nThis PR does not add or alter decision semantics. It anchors the exact package version that the protected `dev/v1/v1.0 -> alpha/v1/v1.0` promotion will publish. Full package checks, Hub 20, Runtime 100, Rust/WASM verifier parity, adversarial fixtures, and clean offline extraction pass at the anchored version.\n\n## Interests and review\n\nFounding steward and package publisher interest: kungfu-systems owns the protected KFD release line.\n\n- [x] A substantive change has a reviewer other than its author\n- [ ] Activation or Foundation Revision has an independent reviewer (not applicable)\n\n## Compatibility and registry agreement\n\n- [x] `node scripts/check.mjs` passes\n- [x] Applicability, compatibility, migration, and supersession impact are explicit\n- [x] Published coordinates remain immutable\n- [x] After Foundation Freeze, decision texts remain append-only (no decision text changes)\n\n## Version impact (per KFD-1)\n\n- [x] minor (additive site/documentation surface; anchored prerelease increment)",
          "author": "dongkeren",
          "createdAt": "2026-07-28T02:28:15Z",
          "mergedAt": "2026-07-28T02:32:36Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1707,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1707",
          "title": "fix(qualification): settle diagnostic identity handoff",
          "body": "## Summary\n\nKeep the Windows product-runtime smoke bounded retry alive when the diagnostic runtime status call observes the same transient identity handoff as runtime ensure.\n\n## Related issue\n\nMaintainability terminal-closure qualification follow-up. Exact protected-main Build run 30315492974 completed install and build on Windows, then product-runtime-smoke failed immediately because the diagnostic status call rethrew runtime_identity_unverified before the existing bounded settlement loop could retry.\n\n## Changes\n\n- treat runtime_identity_unverified from diagnostic status as the same transient settlement state\n- preserve immediate failure for unrelated status errors\n- retain the existing bounded attempt count and fail-closed terminal error\n- add recovery and persistent-failure regression coverage\n- refresh the exact-source KFD prebuild projection\n\n## Verification\n\n- node --test framework/core/tests/qualification/runtime-activation/run.test.mjs (14/14)\n- node scripts/buildchain-kfd-evidence.mjs --check (166 KFD-3 surfaces)\n- node scripts/kfd-support-matrix.mjs --check (13 rows)\n- full Shifu source acceptance (703 tests: 693 pass, 10 expected skips, 0 fail; Python 40 + 116; desktop 69; tooling type check and Biome pass)\n- DCO pre-commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix preserves the runtime activation protocol and existing bounded fail-closed policy; it only lets the qualification harness observe the already-declared transient identity handoff.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects only exact-source qualification observation and does not publish, deploy, or grant credentials.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Regression coverage and exact-source projection updated\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T02:21:33Z",
          "mergedAt": "2026-07-28T02:35:38Z",
          "additions": 48,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 272,
          "url": "https://github.com/kungfu-systems/kfd/pull/272",
          "title": "chore(kfd): promote alpha 48",
          "body": "## What\n\nPromotes the same-repository `dev/v1/v1.0` line to `alpha/v1/v1.0` for the anchored `@kungfu-tech/kfd@1.0.0-alpha.48` release. The promoted history includes PR #269 (progressive load-bearing dogfood evidence baseline plus renderer-ready `/under-load` site contract) and PR #271 (explicit alpha.48 release anchor).\n\n## Contribution type\n\n- [x] evidence, counterexample, or independent review\n- [x] decision, registry, schema, verifier, or release surface\n- [x] governance, documentation, or maintenance\n\n## Claim and evidence\n\nThis is the canonical same-repository alpha promotion path. The source branch carries the exact package, release-anchor, site-bundle, KFD-1/2/3 witness, verifier, and Buildchain contract state already checked on the protected development PRs. No cross-fork or hand-reconstructed release source is used.\n\nThe new public page remains a dated, non-normative founding-adopter evidence synthesis. It does not activate KFD-6, qualify incomplete KFX or delivery work, claim external adoption, or revise numbered decisions.\n\n## Interests and review\n\nFounding steward and package publisher interest: kungfu-systems owns both protected release branches and the npm package.\n\n- [x] A substantive change has a reviewer other than its author\n- [ ] Activation or Foundation Revision has an independent reviewer (not applicable)\n\n## Compatibility and registry agreement\n\n- [x] `node scripts/check.mjs` passes\n- [x] Applicability, compatibility, migration, and supersession impact are explicit\n- [x] Published coordinates remain immutable\n- [x] After Foundation Freeze, decision texts remain append-only (no decision text changes)\n\n## Version impact (per KFD-1)\n\n- [x] minor (additive documentation and site page surface; prerelease increment to alpha.48)",
          "author": "dongkeren",
          "createdAt": "2026-07-28T02:33:03Z",
          "mergedAt": "2026-07-28T02:36:58Z",
          "additions": 779,
          "deletions": 154,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 273,
          "url": "https://github.com/kungfu-systems/kfd/pull/273",
          "title": "fix(buildchain): grant v3 promotion permissions",
          "body": "## What\n\nRepairs the KFD Buildchain v3 promotion caller after the alpha.48 promotion exposed a GitHub Actions `startup_failure` before any job could start. The v3 reusable promotion workflow declares `artifact-metadata: write`, `attestations: write`, and `pull-requests: write`; the KFD caller had retained the narrower v2 permission set. This patch grants those permissions at the workflow and reusable-job boundaries and refreshes the exact KFD-1/2/3 workflow digests.\n\n## Contribution type\n\n- [x] evidence, counterexample, or independent review\n- [x] decision, registry, schema, verifier, or release surface\n- [x] governance, documentation, or maintenance\n\n## Claim and evidence\n\nObserved failure: Buildchain Ref Promotion run 30323685908 concluded `startup_failure`, contained no jobs or logs, and referenced the v3-alpha reusable workflow graph. The caller lacked three permissions required by that graph. `actionlint` accepts the repaired workflow; the complete KFD checks, Hub 20, Runtime 100, Rust/WASM verifier parity, and offline extraction pass after witness regeneration.\n\nThis patch does not change package content or numbered decisions. Alpha.48 remains unpublished until the repaired protected path succeeds.\n\n## Interests and review\n\nFounding steward and release operator interest: kungfu-systems owns the KFD and Buildchain release paths.\n\n- [x] A substantive change has a reviewer other than its author\n- [ ] Activation or Foundation Revision has an independent reviewer (not applicable)\n\n## Compatibility and registry agreement\n\n- [x] `node scripts/check.mjs` passes\n- [x] Applicability, compatibility, migration, and supersession impact are explicit\n- [x] Published coordinates remain immutable\n- [x] After Foundation Freeze, decision texts remain append-only (no decision changes)\n\n## Version impact (per KFD-1)\n\n- [x] patch (release-control repair; no package semantic change)",
          "author": "dongkeren",
          "createdAt": "2026-07-28T02:43:23Z",
          "mergedAt": "2026-07-28T02:47:31Z",
          "additions": 17,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 23,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/23",
          "title": "feat(course): collapse work control details by default",
          "body": "## Summary\n\nMake the course reference work-control card compact by default. The summary keeps the current app-only truth visible, while the existing governance chain, comparison, and neighboring Hub Starter link expand on click through native details/summary semantics.\n\n## Validation\n\n- [x] `npm run check` (48 tests passed)\n- [x] `bash -n scripts/smoke-image.sh`\n- [x] `bash -n course-business-reference/scripts/compose-qualification.sh`\n- [x] Real-browser desktop and 390px mobile checks cover collapsed, expanded, and collapsed-again states\n- [x] Commits are signed off (DCO)\n\n## Image and authority boundary\n\n- [x] Exact Kungfu source, package checksum, build-image digest, and runtime image digest are preserved\n- [x] No floating tags, credentials, private data, real Home, host path, Docker socket, host network, privilege, or added capability\n- [x] Web/Node authority boundaries are unchanged\n- [x] Pre-Alpha and non-production claims remain explicit\n- [x] State deletion is never automatic",
          "author": "dongkeren",
          "createdAt": "2026-07-28T02:51:15Z",
          "mergedAt": "2026-07-28T02:52:17Z",
          "additions": 95,
          "deletions": 68,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1709,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1709",
          "title": "fix(ci): fail closed on unknown latency attribution",
          "body": "## Summary\n\n- prevent the dev required-gate SLO from qualifying while any retained sample has unknown impact attribution\n- keep overall and native percentile thresholds unchanged\n- cover the fail-closed behavior and its diagnostic reason in the existing latency contract suite\n\n## Verification\n\n- `./shifu test:gate-latency` (67 passed)\n- Biome check for both changed files\n- code complexity budget passed\n- full source acceptance reached and passed the changed collector, documentation, and complexity gates; an unrelated cold read-only fixture lacked pytest on PATH\n- changed-scope acceptance passed the latency and formatting gates; later unrelated layer fixtures require unbuilt framework/spec dist artifacts\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"Measurement integrity fix with no architecture decision changes.\"}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T02:50:26Z",
          "mergedAt": "2026-07-28T02:57:42Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 275,
          "url": "https://github.com/kungfu-systems/kfd/pull/275",
          "title": "docs(kfd): clarify alpha promotion actor separation",
          "body": "## Summary\n- document the actor-separation constraint for the dev merge immediately preceding alpha promotion\n- record that a release-control repair after a failed promotion becomes the new immediately preceding merge\n- keep Buildchain v3 caller permissions visibly coupled to pre-job graph validation\n\n## Validation\n- `actionlint .github/workflows/buildchain-ref-promotion.yml`\n- `npm run update:evidence`\n- `npm run check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T02:57:43Z",
          "mergedAt": "2026-07-28T03:01:43Z",
          "additions": 16,
          "deletions": 12,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 274,
          "url": "https://github.com/kungfu-systems/kfd/pull/274",
          "title": "fix(buildchain): re-promote alpha 48 with v3 permission repair",
          "body": "## What\n\nRe-promotes the protected `dev/v1/v1.0` line to `alpha/v1/v1.0` after PR #273 repaired the Buildchain v3 reusable-workflow permission envelope. The package remains anchored at `1.0.0-alpha.48`; the prior alpha promotion did not publish npm or GitHub Release because the post-Verify promotion workflow failed before any job started.\n\n## Contribution type\n\n- [x] evidence, counterexample, or independent review\n- [x] decision, registry, schema, verifier, or release surface\n- [x] governance, documentation, or maintenance\n\n## Claim and evidence\n\nRun 30323685908 was a `startup_failure` with no jobs. PR #273 adds the `artifact-metadata`, `attestations`, and `pull-requests` permissions declared by the v3 reusable promotion graph and refreshes exact workflow witnesses. PR-stage actionlint, KFD checks, verifier suites, and Buildchain build pass.\n\nThe same alpha.48 package fact and load-bearing `/under-load` site bundle are promoted; no new decision or package semantic change is introduced.\n\n## Interests and review\n\nFounding steward and release operator interest: kungfu-systems owns both protected release branches.\n\n- [x] A substantive change has a reviewer other than its author\n- [ ] Activation or Foundation Revision has an independent reviewer (not applicable)\n\n## Compatibility and registry agreement\n\n- [x] `node scripts/check.mjs` passes\n- [x] Applicability, compatibility, migration, and supersession impact are explicit\n- [x] Published coordinates remain immutable\n- [x] After Foundation Freeze, decision texts remain append-only\n\n## Version impact (per KFD-1)\n\n- [x] patch (release-control repair; alpha.48 remains the exact unpublished target)",
          "author": "dongkeren",
          "createdAt": "2026-07-28T02:48:00Z",
          "mergedAt": "2026-07-28T03:06:12Z",
          "additions": 22,
          "deletions": 12,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1576,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1576",
          "title": "ci(alpha): isolate Linux ARM64 artifact qualification",
          "body": "## Summary\n\nIsolate GitHub-hosted Linux ARM64 from routine dev admission. The dedicated alpha and release lane proves the installed CLI and Hub artifact on native ARM64 with its own provisional 240-minute lifecycle budget.\n\n## Related issue\n\nAtlas goal `2026-07-27-kungfu-linux-arm64-alpha-qualification`; stacked on #1572.\n\n## Changes\n\n- remove Linux ARM64 from the common Build workflow and its manual input\n- add a dedicated alpha/release/manual Linux ARM64 qualification workflow\n- run `dist:cli`, whose installed package smoke covers CLI, Hub coursework, Assignment admission, KFD, and semantic checks\n- preserve exact-source preflight receipts and S3 artifact relay\n- bind the isolated lane into the Gate catalog and source-acceptance tests\n\n## Final verification\n\n- local staged pre-commit, workflow/Gate/source-acceptance suites, and full Shifu CI passed\n- exact head preflight: [run 30322692924](https://github.com/kungfu-systems/kungfu/actions/runs/30322692924), source `d4d0a0a105bfd302fee6d1448e4f5398902fd083`, conclusion `success`\n- native ARM64 qualification: [run 30322897541](https://github.com/kungfu-systems/kungfu/actions/runs/30322897541), conclusion `success`\n- Buildchain qualified exact PR merge source `568605726ae32457e04930db27c5ede607f3d070` (`refs/pull/1708/merge`), whose head parent is the preflight-bound source above\n- GitHub-hosted native ARM64 job: 39m07s; complete workflow: 42m07s\n- build command: 34m40.340s; install: 41.570s; installed semantic verification: 382ms\n- retained payload: 2 files / 203,893,461 bytes\n- archive SHA-256 `104c55c70e98fd662e67bed08aba148fa6d86ce852ade352a2574dfc002ad50a`; qualification root `42456d51e84f70bc0c8d53b95ab3196c428f790b711e8723b8ea8920218d1a53`\n- qualifying controller receipt `sha256:ba6a705b1f7374e571cb69d32e44d2f0119afb0ed0edc6ad5bc8e6a1bc3ccb33`; all required build, verify, and aggregate stages passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This changes qualification scheduling and budget without changing a public architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe lane retains exact-source preflight roots and exact artifact paths; the workflow is pinned to immutable Buildchain source and the exact PR candidate completed before merge.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-27T00:24:26Z",
          "mergedAt": "2026-07-28T03:07:58Z",
          "additions": 592,
          "deletions": 137,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 276,
          "url": "https://github.com/kungfu-systems/kfd/pull/276",
          "title": "fix(buildchain): pass governance auditor credential",
          "body": "## Summary\n- pass the dedicated read-only governance auditor private key into the Buildchain v3 promotion workflow\n- bind generated protected-ref updates to the repository's declared `BUILDCHAIN_PROMOTION_TOKEN` secret\n- refresh KFD evidence roots for the workflow contract change\n\n## Failure addressed\nBuildchain Ref Promotion run 30325063528 reached independent publication admission but failed closed while minting the governance auditor token because the reusable-workflow secret was not forwarded.\n\n## Validation\n- `actionlint .github/workflows/buildchain-ref-promotion.yml`\n- `npm run update:evidence`\n- `npm run check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T03:14:11Z",
          "mergedAt": "2026-07-28T03:18:44Z",
          "additions": 13,
          "deletions": 12,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 277,
          "url": "https://github.com/kungfu-systems/kfd/pull/277",
          "title": "release(kfd): promote alpha 48 after governance credential repair",
          "body": "## Summary\nPromote the exact protected `dev/v1/v1.0` head after forwarding the Buildchain v3 governance-auditor credential.\n\n## Release target\n- npm: `@kungfu-tech/kfd@1.0.0-alpha.48`\n- GitHub Release: `v1.0.0-alpha.48`\n- KFD page: `docs/load-bearing-dogfood.md` / `/under-load`\n\n## Prior fail-closed evidence\n- run 30325063528 reached independent publication admission and stopped before publication because the auditor App private key was not forwarded\n- PR #276 repairs the caller secret contract without bypassing admission\n\n## Gate\nMerge only after Verify and Buildchain PR build pass and `kungfu-origin` independently approves this exact dev head.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T03:18:58Z",
          "mergedAt": "2026-07-28T03:22:53Z",
          "additions": 13,
          "deletions": 12,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 278,
          "url": "https://github.com/kungfu-systems/kfd/pull/278",
          "title": "Prepare v1.0.0-alpha.49",
          "body": "Create the generated version-state commit for v1.0.0-alpha.49.\n\nBuildchain generated this PR because protected branch dev/v1/v1.0 rejected direct generated bookkeeping.\n\nRejected update: 44700087f7dd882e6537ea1f1c3e7569f058d1dc -> a09fa21a636f51929504e042d50105da972f4e72\n\nGitHub response: Changes must be made through a pull request.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-28T03:29:15Z",
          "mergedAt": "2026-07-28T03:33:03Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1710,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1710",
          "title": "fix(qualification): expose source exactness drift",
          "body": "## Summary\n\nExpose the exact bounded Git porcelain paths when live Peer continuity qualification rejects an otherwise-passing run as source-dirty. The existing fail-closed verdict is unchanged.\n\n## Changes\n\n- retain bounded source status paths in the qualification report\n- print every violation and exact source status on failure\n- preserve source revision, tree, and dirty semantics\n\n## Verification\n\n- node --test framework/core/tests/qualification/live-peer-continuity/run.test.mjs (12/12)\n- full signed-commit staged gate (47 latency/cache tests, 17 invariant tests, 107 documentation tests, Biome and repository contracts)\n- Candidate Source Acceptance passed on exact PR head in run 30325314287\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This diagnostic bugfix preserves the existing live Peer continuity protocol and fail-closed source-exactness policy; it only makes the rejected paths observable.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo publication or deployment is performed. Diagnostics are limited to repository-relative Git status entries.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Existing verdict remains fail-closed\n- [x] Targeted and full staged checks pass",
          "author": "dongkeren",
          "createdAt": "2026-07-28T03:12:59Z",
          "mergedAt": "2026-07-28T03:33:53Z",
          "additions": 23,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1711,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1711",
          "title": "feat(hub): add native Linux ARM64 coursework delivery",
          "body": "## Summary\n\nComplete the native Linux ARM64 Hub/CLI delivery while keeping routine dev admission bounded: dev continues to use Linux x64 for platform coverage, and Linux ARM64 moves to a dedicated alpha/release artifact qualification lane with a provisional 240-minute budget.\n\n## Related work\n\n- Atlas Assignment `2026-07-25-kungfu-hub-starter-coursework-multiplatform-delivery`\n- Atlas goal `2026-07-27-kungfu-linux-arm64-alpha-qualification`\n- stacked delivery #1576 (merged)\n\n## Changes\n\n- preserve Episode payload references and bare digest inputs used by the starter workflow\n- consume the public `@kungfu-tech/libnode` Linux ARM64 alpha.3 package and register native Core packaging/publication authority\n- remove Linux ARM64 from the common Build/dev admission matrix\n- add a dedicated hosted native Linux ARM64 alpha/release/manual qualification workflow\n- prove the installed CLI and Hub coursework/Assignment/KFD semantics from the produced artifact\n- bind exact-source preflight, Buildchain receipts, Gate catalog, workflow authority, publication surfaces, and portable-off cache policy\n\n## Final verification\n\n- local project pre-commit passed after replay onto current `dev/v4/v4.0`; changed-scope gate and 291-test manifest passed\n- final linear candidate: `ebdd452768729ca179b524be649b01f504b17cd8`\n- exact final source/Cargo matrix: [run 30326338464](https://github.com/kungfu-systems/kungfu/actions/runs/30326338464), Linux x64, Linux ARM64, macOS, Windows, and aggregate receipt all `success`\n- native installed-artifact proof: [run 30322897541](https://github.com/kungfu-systems/kungfu/actions/runs/30322897541), `success`\n- exact native head preflight: [run 30322692924](https://github.com/kungfu-systems/kungfu/actions/runs/30322692924), source `d4d0a0a105bfd302fee6d1448e4f5398902fd083`, `success`\n- GitHub-hosted native ARM64 job: 39m07s; complete workflow: 42m07s; build command: 34m40.340s; install: 41.570s; installed semantic verification: 382ms\n- retained payload: 2 files / 203,893,461 bytes\n- archive SHA-256 `104c55c70e98fd662e67bed08aba148fa6d86ce852ade352a2574dfc002ad50a`; qualification root `42456d51e84f70bc0c8d53b95ab3196c428f790b711e8723b8ea8920218d1a53`\n- qualifying controller receipt `sha256:ba6a705b1f7374e571cb69d32e44d2f0119afb0ed0edc6ad5bc8e6a1bc3ccb33`; required build, verify, and aggregate stages passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f9388-a139-7355-b9f2-f6dd9aa91042\"],\n  \"summary\": \"Stage native Linux ARM64 Hub CLI and Core package delivery while isolating hosted ARM64 artifact qualification from routine dev admission\",\n  \"verification\": [\"project pre-commit\", \"run 30326338464\", \"run 30322897541\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe dedicated lane is credential-free at the caller, uses the pinned Buildchain reusable workflow, retains exact-source receipts, and leaves publication behind existing protected workflow authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-28T03:20:06Z",
          "mergedAt": "2026-07-28T03:46:36Z",
          "additions": 707,
          "deletions": 529,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 279,
          "url": "https://github.com/kungfu-systems/kfd/pull/279",
          "title": "chore(kfd): anchor alpha 50 release",
          "body": "## Summary\\n- anchor the next collision-free KFD alpha at 1.0.0-alpha.50\\n- refresh generated Buildchain evidence roots for the new version identity\\n- preserve existing public alpha.48 and alpha.49 tags as historical facts\\n\\n## Validation\\n- npm run check\\n- git diff --check\\n\\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T03:46:09Z",
          "mergedAt": "2026-07-28T03:50:32Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1982,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1982",
          "title": "feat(signing): deliver native artifact authority",
          "body": "## Summary\n\n- make artifact signing a Buildchain-owned declaration and authority capability\n- route Linux binaries to detached Ed25519, macOS Mach-O to Developer ID/notarization, and Windows PE to timestamped Authenticode\n- import immutable signed results between build and verify so manifests, KFD evidence, checksums, and Release Passport inputs bind final bytes\n- keep consumer repositories free of signing credentials, Team IDs, provider environments, and signing jobs\n\n## Verification\n\n- `pnpm run check` (934 tests passed)\n- `bash scripts/check-workflows.sh`\n- `pnpm run build` and action bundle integrity\n- agent-hub-demo consumer config validation and local product tests\n\n## Dogfood\n\nValidation train: `train/v3/v3.0/artifact-signing-authority`\n\nGoal: `2026-07-27-agent-hub-demo-artifact-signing-dogfood`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T03:47:12Z",
          "mergedAt": "2026-07-28T03:53:30Z",
          "additions": 3985,
          "deletions": 336,
          "changedFiles": 53
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 280,
          "url": "https://github.com/kungfu-systems/kfd/pull/280",
          "title": "release(kfd): promote alpha 50",
          "body": "## Summary\\n- promote KFD 1.0.0-alpha.50 from the protected v1 development line\\n- publish the new KFD Under Load cognition baseline and standalone page bundle\\n- retain alpha.48/alpha.49 tag collisions as historical release-chain evidence\\n\\n## Admission\\n- dev PR #279 passed KFD check and Buildchain\\n- exact dev head independently approved before merge\\n- alpha.50 is absent from npm and GitHub tags at promotion start",
          "author": "dongkeren",
          "createdAt": "2026-07-28T03:50:48Z",
          "mergedAt": "2026-07-28T03:54:41Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1980,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1980",
          "title": "feat(auditable-demo): qualify web delivery media",
          "body": "## Summary\n\n- add opt-in Buildchain-owned media qualification profiles while preserving archive-v1 receipt compatibility\n- independently verify retained rendition roots, codec/container/audio/layout/fast-start facts, roles, and byte ceilings\n- add a path-scoped immutable renderer fixture workflow that produces content-addressed measurement evidence\n\n## Validation\n\n- pnpm check\n- 923 unit tests passed\n- workflow and generated-site checks passed\n\n## Current draft gate\n\nThe first PR run will measure the exact locked renderer fixture. The resulting evidence will be checked in and the provisional byte ceilings will be replaced or justified before review.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T03:34:39Z",
          "mergedAt": "2026-07-28T04:03:28Z",
          "additions": 1619,
          "deletions": 136,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 281,
          "url": "https://github.com/kungfu-systems/kfd/pull/281",
          "title": "Prepare v1.0.0-alpha.50",
          "body": "Create the generated version-state commit for v1.0.0-alpha.50.\n\nBuildchain generated this PR because protected branch dev/v1/v1.0 rejected direct generated bookkeeping.\n\nRejected update: 3ccd512cf3b6a1c3e78a5ce4cb514d972e50a836 -> 8370362e90655e260ae4a64e224669cc1fecd801\n\nGitHub response: Changes must be made through a pull request.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-28T04:01:34Z",
          "mergedAt": "2026-07-28T04:05:23Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1714,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1714",
          "title": "fix(build): root ARM64 package staging",
          "body": "## Summary\n\nWrite Linux ARM64 Core platform packages to the repository release directory that the exact-source qualification verifies.\n\n## Related issue\n\nMaintainability terminal-closure qualification follow-up. Exact protected-main Build run 30323776730 completed both Linux ARM64 build lifecycles, but product and Hub CLI verification could not find kungfu-tech-core-linux-arm64-4.0.0-alpha.1.tgz because the Buildchain lifecycle passed a repository-relative stage path that the Core packer resolved below framework/core.\n\n## Changes\n\n- resolve the Linux ARM64 Buildchain package stage as an absolute repository-root path\n- preserve the bounded Core-only build plan and all non-ARM64 lifecycle behavior\n- bind the regression test to an injected repository root\n\n## Verification\n\n- node --test scripts/run-shifu-lifecycle.test.mjs scripts/run-release-qualification.test.mjs (42 tests: 39 pass, 3 expected Windows skips, 0 fail)\n- exact latest-base focused suite including isolated ARM64 workflow (44 tests: 41 pass, 3 expected Windows skips, 0 fail)\n- full Shifu source acceptance (703 tests: 693 pass, 10 expected skips, 0 fail; Python 40 + 116; desktop 69; tooling type check and Biome pass)\n- DCO pre-commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix preserves the existing Linux ARM64 Core-only build and release qualification contracts; it corrects only the repository-root resolution of the declared artifact staging directory.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change only aligns the exact build artifact location with the existing qualification reader and does not publish or deploy.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Regression coverage added\n- [x] Full source acceptance passed",
          "author": "dongkeren",
          "createdAt": "2026-07-28T03:53:28Z",
          "mergedAt": "2026-07-28T04:10:29Z",
          "additions": 9,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1983,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1983",
          "title": "fix(signing): reuse macOS credential island contract",
          "body": "## Summary\n\n- reuse the established `BUILDCHAIN_MACOS_*` secret and variable names in the central artifact-signing authority\n- avoid introducing a second Apple credential namespace after the existing Credential Island dogfood\n- keep provider credentials exclusive to the Buildchain `buildchain-artifact-signing` environment\n\n## Evidence\n\n- `pnpm run check`\n- 941 tests passed\n- workflow validation passed\n- action bundle integrity passed\n- live agent-hub-demo run reached all three central provider jobs\n\n## Live dogfood finding\n\nThe current central environment exists but has no provider values. Apple material already exists under the established names in `kungfu-systems/kungfu` environment `alpha-macos-signing`; this PR makes the Buildchain authority consume that same contract after the values are securely provisioned centrally.\n\nGoal: `2026-07-27-agent-hub-demo-artifact-signing-dogfood`\nMission: `kungfu-technical-stewardship`",
          "author": "dongkeren",
          "createdAt": "2026-07-28T04:09:40Z",
          "mergedAt": "2026-07-28T04:15:07Z",
          "additions": 30,
          "deletions": 20,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 58,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/58",
          "title": "feat(release): dogfood Buildchain artifact signing",
          "body": "## Summary\n\n- declare Linux x64, macOS arm64 Mach-O, and Windows x64 PE artifacts for Buildchain-owned signing\n- keep all signing credentials, provider selection, Team IDs, timestamp configuration, and signing jobs out of the consumer repository\n- verify imported final signed bytes before checksums, KFD evidence, and Release Passport qualification\n\n## Signing expectations\n\n- Linux: detached cryptographic signature, with no OS-native claim\n- macOS: Developer ID runtime signature plus notarization and Gatekeeper evidence for the standalone Mach-O\n- Windows: Authenticode signature plus trusted timestamp; detached fallback is rejected\n\n## Buildchain authority\n\n- protected change: kungfu-systems/buildchain#1982\n- pinned train: `train/v3/v3.0/artifact-signing-authority`\n\n## Validation\n\n- `npm run check`\n- 16 tests passed\n- Runtime-100 passed\n- local Linux build passed\n- Buildchain config resolved all three declarations\n\nGoal: `2026-07-27-agent-hub-demo-artifact-signing-dogfood`\nMission: `kungfu-technical-stewardship`",
          "author": "dongkeren",
          "createdAt": "2026-07-28T03:53:12Z",
          "mergedAt": "2026-07-28T04:23:31Z",
          "additions": 223,
          "deletions": 7,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 223,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/223",
          "title": "feat(kfd): render standalone bundle pages",
          "body": "## Summary\\n- consume the finalized @kungfu-tech/kfd@1.0.0-alpha.50 package and exact Buildchain release lock\\n- render bundle-declared standalone Markdown pages, including KFD Under Load at /under-load/\\n- publish standalone page facts through the site manifest and KFD agent read order\\n- fail closed on renderer, route, content, metadata, authority, and alias drift\\n\\n## Validation\\n- node --check scripts/render-site.mjs\\n- bash -n scripts/check-site.sh\\n- npm run build\\n- npm run check\\n- Playwright browser snapshot of http://127.0.0.1:4173/under-load/\\n\\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T04:13:24Z",
          "mergedAt": "2026-07-28T04:25:41Z",
          "additions": 148,
          "deletions": 16,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1716,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1716",
          "title": "fix(qualification): budget cold Gate catalog bootstrap",
          "body": "## Summary\n\n- raise `gate.catalog` from 120 seconds to 600 seconds so a cold Dev Patrol workspace can finish the frozen install before the sub-second catalog check runs\n- keep the Gate action, command, policy mode, and fail-closed semantics unchanged\n- bind fresh exact-source Linux, macOS, and Windows measurements to the new Gate definition and regenerate the measurement coverage and semantic-amplification projections\n- supersede #1715 without changing the source tree, restoring dongkeren -> kungfu-origin review separation on the latest dev mainline\n\n## Failure evidence\n\n- Exact Dev Verify run [30319289371](https://github.com/kungfu-systems/kungfu/actions/runs/30319289371) failed on macOS because `gate.catalog` exhausted its 120-second definition budget while installing the cold 994-package workspace; the catalog action itself had not started.\n- The fresh exact-source measurements record the actual `gate.catalog` action at 469 ms on Linux, 790 ms on macOS, and 1894 ms on Windows.\n\n## Verification\n\n- `./shifu check:gate-catalog` passes.\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs` passes 23/23 tests.\n- `./shifu maintainability:amplification --write` reports 6 families, 75 surfaces, and 0 issues.\n- The complete staged pre-commit gate passes on every signed repair commit.\n- Linux exact clean receipt: `ec0d1c2f2dd406f16083c8f7204420321f35e292`, `gate.catalog` pass in 469 ms.\n- macOS exact clean receipt: same source and definition, pass in 790 ms.\n- Windows exact clean receipt: [job 90166769627](https://github.com/kungfu-systems/kungfu/actions/runs/30324447657/job/90166769627), same source and definition, pass in 1894 ms.\n\n## Release boundary\n\n- [x] No package or channel publication is performed by this PR.\n- [x] Exact-source Dev and Alpha qualification remains required after merge before the repaired budget can support an Alpha release.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair a cold-workspace qualification budget and refresh source-bound measurements without changing the Gate action or architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes only a qualification timeout and its source-bound measurement evidence; publication remains downstream of protected Dev and Alpha workflows.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for the changed timeout and generated projections",
          "author": "dongkeren",
          "createdAt": "2026-07-28T04:16:14Z",
          "mergedAt": "2026-07-28T04:41:59Z",
          "additions": 282,
          "deletions": 18,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 224,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/224",
          "title": "Release production from b5656e128c5e",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `b5656e128c5e09ec3e99742887f49c238356b726`\n- Artifact hash: `07caa5f031146ab9ea6354718249b4e20a414bc051719aa030cbe0e7d32e63a1`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/30328720357)\n- Required label: `buildchain-release`\n- Release branch: `release/production-b5656e128c5e`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-28T04:37:19Z",
          "mergedAt": "2026-07-28T04:49:04Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1717,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1717",
          "title": "fix(packaging): anchor explicit stage paths to repository",
          "body": "## Summary\n\nFix the native Linux ARM64 Hub CLI package lane so its explicit package stage directory is resolved from the repository root. The previous Core-relative resolution created an untracked `framework/core/product/` tree and correctly caused source-exact qualification to fail closed.\n\n## Changes\n\n- resolve explicit `KF_PACKAGE_STAGE_DIR` values from the repository root\n- preserve the historical Core-local default when no override is supplied\n- add a regression test for both explicit and default stage paths\n\n## Verification\n\n- `node --test framework/core/tests/core-platform-package.test.js scripts/run-shifu-lifecycle.test.mjs` (21 passed, 3 platform skips)\n- `pnpm --filter @kungfu-tech/core run test:tooling` (31 passed, 2 native-build skips)\n- `pnpm exec biome check framework/core/.gyp/core-platform-package.js framework/core/tests/core-platform-package.test.js`\n- signed-commit staged gate completed before commit\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix preserves the existing package-stage and source-exactness contracts; it corrects only the base directory used to interpret an already repository-relative lifecycle path.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo publication or deployment is performed by this change. It restores the declared repository-level package stage location.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source-exactness gate remains fail-closed\n- [x] Targeted and full staged checks pass\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T04:23:51Z",
          "mergedAt": "2026-07-28T04:56:48Z",
          "additions": 30,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1984,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1984",
          "title": "fix(signing): align macOS private-key ACL",
          "body": "## Summary\n\n- align the standalone Mach-O signer with the proven macOS credential-island key ACL\n- allow the security tool to manage the imported private key\n- retain the codesign partition required by non-interactive hosted runners\n\n## Verification\n\n- bash -n scripts/sign-macos-mach-o-request.sh\n- shellcheck scripts/sign-macos-mach-o-request.sh\n- node --test tests/native-artifact-signing-authority.test.mjs\n\n## Dogfood evidence\n\nProvider run 30330391775 imported one identity and then failed closed at set-key-partition-list before codesign. This patch removes that exact contract drift without weakening codesign, notarization, or Gatekeeper requirements.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T05:04:39Z",
          "mergedAt": "2026-07-28T05:10:13Z",
          "additions": 4,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1985,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1985",
          "title": "fix(signing): initialize macOS key partition ACL",
          "body": "## Summary\n\n- remove the pre-ACL sign-capability filter from the temporary keychain partition update\n- retain the explicit apple-tool, apple, and codesign partitions in an otherwise empty temporary keychain\n- add non-sensitive stage markers for exact provider diagnostics\n\n## Verification\n\n- bash -n scripts/sign-macos-mach-o-request.sh\n- shellcheck scripts/sign-macos-mach-o-request.sh\n- node --test tests/native-artifact-signing-authority.test.mjs\n\n## Dogfood evidence\n\nProvider runs 30330391775 and 30330995237 both imported one identity and failed closed at set-key-partition-list. GitHub current macOS runner guidance configures the partition list without the sign-capability selector, avoiding a circular lookup before the imported key ACL is initialized.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T05:17:07Z",
          "mergedAt": "2026-07-28T05:22:45Z",
          "additions": 6,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1986,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1986",
          "title": "fix(signing): expose temporary macOS keychain",
          "body": "## Summary\n\n- add the isolated temporary keychain to the user search list after its private-key ACL is initialized\n- retain the explicit keychain path and exact certificate SHA for codesign\n- assert the runner keychain visibility contract\n\n## Verification\n\n- bash -n scripts/sign-macos-mach-o-request.sh\n- shellcheck scripts/sign-macos-mach-o-request.sh\n- node --test tests/native-artifact-signing-authority.test.mjs\n\n## Dogfood evidence\n\nProvider run 30331590493 passed private-key ACL initialization and exact identity verification, then failed when codesign could not resolve the identity. This closes the remaining difference from GitHub current macOS runner certificate-install flow before codesign.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T05:27:23Z",
          "mergedAt": "2026-07-28T05:33:14Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1720,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1720",
          "title": "feat(work): add native assignment family state",
          "body": "## Summary\n\nAdd the native Initiative/Assignment family-state contract for bounded Wave execution. The parent remains an inert coordinator, children carry the executable work, terminal coverage is explicit, and continuation can create only a residual successor family from the exact prior state.\n\n## Related issue\n\nNative Assignment: `2026-07-28-kungfu-go-family-native-state-contract`\n\n## Changes\n\n- add rooted family blueprint, state, transition, and coverage projections for 3-6 Wave children\n- enforce one DAG, four terminal outcomes, expected-root fencing, and residual-only continuation within the bounded continuation window\n- expose canonical family planning, status, transition, and continuation CLI surfaces\n- update KFD, Primitive, CLI catalog, SDK, and maintainability projections without promoting KFD-12 beyond draft/advisory status\n- let an exact active successor Cut retain bounded historical replay conflicts as visible omissions while keeping active or unanchored drift fail-closed\n- preserve byte-identical cold KFD authority/SDK projections and bound generated CLI catalog formatting\n\n## Verification\n\n- `./shifu check:source` (passed; 706 contract tests: 696 passed, 10 declared skips, 0 failed; 40 Work authority tests; 116 runtime-upgrade tests; 69 desktop adapter tests)\n- `node --test --test-name-pattern='declared discovery routes are zero-write' scripts/readonly-agent-bootstrap.test.mjs` (passed)\n- Project Cut `sha256:b3f93706640ab2d63e7eadb5bed0b473c79a8f04a07e501ec4d34db4fd262e6b` published and verified at `d7a26362c25d8049eee0b619fc9eb1014b3ea761`\n- merge-queue admission against `83e75ffc8ff3cc05199e257a180eac6a7380949d` qualified with 17 replayed commits and zero diagnostics\n- staged commit gates passed for every source and Project Cut commit\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f8759-ab29-7627-bc04-6aba547ea45f\",\n    \"KF-ADR-019f87cc-bd1f-786d-896d-07ea9245861e\",\n    \"KF-ADR-019f86da-4f90-7b77-a360-0725f23aad30\"\n  ],\n  \"summary\": \"Stage the rooted native Assignment family state machine and its exact successor Project Cut admission.\",\n  \"verification\": [\n    \"./shifu check:source\",\n    \"Project Cut merge-queue admission\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change adds source CLI surfaces and refreshes bounded KFD/Project Cut evidence. It performs no publication, deployment, credential, or hosted-service mutation.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and generated projections are current\n- [x] Source acceptance and merge-queue admission pass\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T05:09:08Z",
          "mergedAt": "2026-07-28T05:46:24Z",
          "additions": 1613,
          "deletions": 30941,
          "changedFiles": 54
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1718,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1718",
          "title": "feat(kfx): require passport-bound work warrants for mutations",
          "body": "## Summary\n\nRequire every state-changing KFX registry operation to pass one Core-recomputed mutation authorization plan and a purpose-bound Work/Warrant before side effects begin.\n\nThis stage binds the Release Passport assessment, admission plan, policy, package/dependency roots, approval roots, expected-old Cut, and terminal settlement into immutable receipts. KFD compliance only reduces policy-defined friction; it does not grant mutation authority. Recovery removal remains explicit and package-independent.\n\nThis is an ordered authority-weld stage after #1624. It does not claim the later capability-grant/runtime-isolation cutover or the terminal identity-neutral qualification.\n\n## Related issue\n\nFollow-up to #1624.\n\n## Changes\n\n- add a Core-owned mutation authorization plan for install, update, enable, activate, qualify, remove, disable, and Control Suite mutation paths\n- require exact authorization-plan and Warrant roots at apply time and recompute them against current package, policy, capability, approval, and Cut inputs\n- record pre-side-effect Work/Warrant facts and post-side-effect Work settlement, Warrant consumption, Episode, Settlement, and Cut receipts\n- add explicit recovery Warrants for disable/remove without trusting the package being removed\n- expose the same authority evidence through thin Python/CLI and Node transports\n- add negative coverage for stale, revoked, expired, sibling, publisher/verifier mismatch, policy/capability drift, recovery spoofing, and direct-apply bypass\n- refresh deterministic CLI, KFD, and support-matrix projections after the governed surface change\n\n## Verification\n\n- `./shifu build:core`\n- `./shifu test:native-kfx-admission`\n- `./shifu test:cli-surface-contract` (42 passed)\n- focused KFX CLI authority tests (2 passed)\n- SDK unit tests (34 passed)\n- layer qualification harness tests (96 passed, 2 skipped)\n- `./shifu check` (`changed-scope gate passed`)\n- repository pre-commit staged gate (`staged gate passed`)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-7ef4-b28b-ee1fbaf9e62e\",\n    \"KF-ADR-019f86da-4f90-73f3-b027-c343b2bc8bcc\",\n    \"KF-ADR-019f86da-4f90-7d6c-926a-ddd27dbde8ab\",\n    \"KF-ADR-019f86da-4f90-72df-add3-948f3ae38c3a\",\n    \"KF-ADR-019f8c53-6105-71e5-8f34-53f2a81ee61c\"\n  ],\n  \"summary\": \"Weld the existing Release Passport assessment to pre-side-effect Work and Warrant authority for every KFX mutation path, with immutable settlement receipts and explicit recovery semantics.\",\n  \"verification\": [\n    \"./shifu test:native-kfx-admission\",\n    \"./shifu test:cli-surface-contract\",\n    \"./shifu check\",\n    \"repository pre-commit staged gate\"\n  ]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change consumes Release Passport and KFD evidence for local mutation admission and refreshes deterministic evidence projections. It performs no package publication or deployment and grants no authority from product identity or KFD status alone.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T04:41:25Z",
          "mergedAt": "2026-07-28T06:07:33Z",
          "additions": 1062,
          "deletions": 217,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1723,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1723",
          "title": "fix(ci): close queue lease source acceptance",
          "body": "## Summary\n\nSerialize dev merge-queue admission with an exact-head `Queue admission lease`. The lease is issued only after the queue is empty and Project Cut is replayed against the latest base, continued on the exact synthetic merge-group SHA, and permanently revoked for a dequeued head.\n\n## Changes\n\n- add a merge-group-only required-context continuation with no token permissions\n- extend the trusted dequeue controller to revoke the exact PR-head lease even when cancellation or repair-marker cleanup fails\n- declare the bounded admission contract, including position-one-only and no same-head retry after revocation\n- allow the latency collector to recognize only this declared required-context expansion without deleting or cutting over historical samples\n- refresh the closed-world workflow authority manifest\n\n## Verification\n\n- `./shifu test:gate-latency` (73 passed)\n- `./shifu check:gate-catalog` (38 gates, 6 profiles, 27 invocations, 26 workflows aligned)\n- `./shifu check` (passed after building the ignored Spec aggregate through its documented package build entry)\n- DCO staged gate completed before commit\n- `node scripts/check-project-cut-merge-queue-admission.mjs --base origin/dev/v4/v4.0 --head HEAD` (`decision=qualified`)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This operational safety fix preserves the existing required Gate and exact-proof contracts; it serializes admission so position-two source drift cannot invalidate them and adds no weaker proof path.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change uses GitHub commit-status and merge-queue APIs with exact-SHA binding. It adds no credentials, does not publish artifacts, and keeps the credential-free merge-group continuation at `permissions: {}`.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for the admission and revocation behavior\n- [x] Required Gate proof verification remains fail-closed\n- [x] Historical latency samples are not deleted or hidden behind a regime cutoff\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T05:54:59Z",
          "mergedAt": "2026-07-28T06:13:54Z",
          "additions": 476,
          "deletions": 44,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1724,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1724",
          "title": "fix(qualification): await verified runtime identity",
          "body": "## Summary\n\nMake the frozen product runtime smoke wait for both the supervisor and coordinator process identities to be verified before issuing the warm ensure command.\n\n## Related issue\n\nMaintainability terminal-closure exact Windows qualification follow-up. Build run 30328150323 passed the 72/72 base verification and every other runtime-activation suite, but product-runtime-smoke raced from process liveness into a fail-closed warm ensure before the coordinator identity handoff settled.\n\n## Changes\n\n- define product runtime readiness as running plus identityVerified for both supervisor and coordinator\n- reuse the stricter readiness predicate for cold and restart evidence\n- add regression cases for both partial identity handoffs and the fully verified state\n- refresh the KFD-3 prebuild witness\n\n## Verification\n\n- `./shifu exec node --test framework/core/tests/qualification/runtime-activation/run.test.mjs` (15 pass, 0 fail)\n- `./shifu kfd:buildchain:check` (pass)\n- `./shifu check:source` (complete pass before witness refresh; repeated source suite reached 695 pass and one environment-only failure because pytest was absent from PATH)\n- DCO pre-commit staged gate (pass)\n- `git diff --check` (pass)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix preserves the existing runtime identity fence and product qualification contract; it only prevents the qualification harness from treating PID liveness as verified process authority.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects only the exact-source product qualification readiness predicate and its content-addressed witness. It does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Regression coverage added\n- [x] Documentation is unchanged because the runtime identity contract is preserved\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T06:00:51Z",
          "mergedAt": "2026-07-28T06:25:17Z",
          "additions": 36,
          "deletions": 7,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1987,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1987",
          "title": "fix(signing): retry transient authority polling",
          "body": "## Summary\n- retry transient transport, decoding, and retryable HTTP failures while polling the signing authority\n- keep workflow dispatch POST single-attempt so a lost response cannot create duplicate signing requests\n- add regression coverage for GET recovery and POST non-replay\n\n## Evidence\n- agent-hub-demo run 30332001215 failed after 52 minutes with a single `fetch failed` while authority run 30332114725 remained in progress\n- `node --test tests/native-artifact-signing-authority.test.mjs`\n- `node --check scripts/dispatch-artifact-signing-authority.mjs`\n- `node scripts/check-internal-architecture.mjs`\n- `node scripts/check-inventory.mjs`\n- `bash scripts/check-workflows.sh`",
          "author": "dongkeren",
          "createdAt": "2026-07-28T06:54:29Z",
          "mergedAt": "2026-07-28T07:00:28Z",
          "additions": 102,
          "deletions": 17,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1988,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1988",
          "title": "fix(signing): bound macOS notarization wait",
          "body": "## Summary\n- split Apple notarization submission from status waiting\n- expose the non-secret submission identifier and a provider-owned 55 minute wait boundary\n- keep notarization and Gatekeeper verification fail-closed and bind the final status to the submitted identifier\n\n## Dogfood evidence\n- real Developer ID import and codesign completed on agent-hub-demo\n- the combined `notarytool submit --wait` then remained silent for over 100 minutes\n\n## Validation\n- `bash -n scripts/sign-macos-mach-o-request.sh`\n- `shellcheck scripts/sign-macos-mach-o-request.sh`\n- `node --test tests/native-artifact-signing-authority.test.mjs`\n- `node scripts/check-internal-architecture.mjs`\n- `node scripts/check-inventory.mjs`\n- `bash scripts/check-workflows.sh`",
          "author": "dongkeren",
          "createdAt": "2026-07-28T07:26:45Z",
          "mergedAt": "2026-07-28T07:32:33Z",
          "additions": 11,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 24,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/24",
          "title": "feat(hub): deliver coursework UX and native multiarch candidate",
          "body": "## Outcome\n\n- replaces the abstract Hub walkthrough with a deterministic Agent/Kungfu coursework flow\n- proves claim != acceptance, independent insufficient review, follow-up evidence, fit re-review, and sealed closeout\n- consumes exact x64 and arm64 Kungfu CLI packages from source commit 83e75ffc8ff3cc05199e257a180eac6a7380949d\n- publishes and locks the qualified OCI index at sha256:5a18ccea22c53aeac3d606a414da8b8b52b91578ba9d4f6669e5a8ed9de9b47a\n- bounds macOS headless Chrome smoke completion after artifacts are retained\n\n## Qualification\n\n- package staging: https://github.com/kungfu-systems/runtime-images/actions/runs/30336024117\n- multiarch image and native amd64/arm64 smoke: https://github.com/kungfu-systems/runtime-images/actions/runs/30338579458\n- upstream x64 source build: https://github.com/kungfu-systems/kungfu/actions/runs/30330617397\n- upstream arm64 source build: https://github.com/kungfu-systems/kungfu/actions/runs/30330528786\n- local Apple Silicon image, Compose, browser screenshots, two-round coursework, isolation, restart persistence, and security smoke passed\n\n## Boundary\n\nDevelopment candidate only: localhost, single-user, no authentication, not production, and not a native Windows container.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T07:35:16Z",
          "mergedAt": "2026-07-28T07:38:01Z",
          "additions": 166,
          "deletions": 82,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1725,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1725",
          "title": "feat(docs): add first-party evolution map",
          "body": "## Summary\n\nAdd a first-party longitudinal Evolution Map that lets readers learn the causal abstraction spine from the v4 journal restart to current Work Control dogfood before traversing the repository cross-section.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- define append-only Era and Stage records with exact evidence and authority transitions\n- generate deterministic timeline, current-authority, reader-route, and machine projections\n- add paired Human and Agent Xinfa routes plus documentation entrypoints\n- reject dangling history, discontinuous authority, stale projections, and settled-record mutation\n- add PR evolution-impact vocabulary and source/documentation gate integration\n\n## Verification\n\n- `./shifu evolution:map:check`\n- `./shifu docs:check`\n- `./shifu docs validate --json`\n- `./shifu docs inventory --json` (471 classified surfaces, 0 unclassified)\n- `./shifu docs context --task \"understand Kungfu evolution and authority migration before changing current architecture\" --role implementer --budget 65536 --route kungfu-evolution-map-agent --json` (pass, complete, no omissions)\n- staged repository gate (111 documentation tests and all staged checks pass)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019fa773-aae4-7f50-80a5-ce53b08490d2\"],\n  \"summary\": \"Deliver the append-only first-party Evolution Map, deterministic projections, Xinfa routes, and drift gates.\",\n  \"verification\": [\"evolution map contract tests\", \"documentation gate\", \"source acceptance\"]\n}\n-->\n\n## Evolution map impact\n\nEvolution impact: opens\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T07:14:03Z",
          "mergedAt": "2026-07-28T07:48:16Z",
          "additions": 2658,
          "deletions": 19,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1727,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1727",
          "title": "fix(ci): enforce initiative family queue single flight",
          "body": "Implements Wave 0 Initiative-family queue single-flight: latest-dev deterministic replay, exact child/head/proof lease binding, merge-group verification, and idempotent merge/dequeue/terminal release. Native Assignment state root: sha256:cba8d96c325b69ff51abd4a72ce309d6d509dede8085269f16d3d66f1f344f1f.\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"adr-neutral\",\"reason\":\"Bounded CI correctness fix for existing Project Cut and protected merge-queue control surfaces; no ADR record or architecture contract is changed.\"}\n-->\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWdvLWZhbWlseS1jb250aW51b3VzLWRlbGl2ZXJ5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtZ28tZmFtaWx5LXF1ZXVlLXNpbmdsZS1mbGlnaHQiLCJkZWxpdmVyeUNsYXNzIjoibm9uLW5hdGl2ZS1mYXN0IiwiZGV2SGVhZCI6IjZkY2I0MGY4MzU5NTc2MWM3OWE0ZDBlMmJmOWYxY2ZiOTRhNTY0YmIiLCJwdWxsUmVxdWVzdEhlYWQiOiIzMmUyMGI2ZjE4ODRlMDA5NGNmYmNhYzNhN2VjNGNhZWMzN2Q2Njk4IiwicmVwbGF5ZWRDYW5kaWRhdGUiOiJjYmMxNGE3YTA2ZWIyYTUyNDI1ZmMxMGUxZjcxYjZmOGU3N2ZiMTc2IiwicmVwbGF5ZWRUcmVlIjoiY2Y2NWFiZmVmZjM5YzE1NjkyOGQ0NzFhZTY4NDk4ZjI4ODI1NmNhMSIsInF1ZXVlQXR0ZW1wdCI6IjMyZTIwYjZmMTg4NGUwMDk0Y2ZiY2FjM2E3ZWM0Y2FlYzM3ZDY2OThANmRjYjQwZjgzNTk1NzYxYzc5YTRkMGUyYmY5ZjFjZmI5NGE1NjRiYiIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjoxNzFhY2Y2N2E4YjhmMzY1ZmJiY2UyZjk4ZjQ0OTEzY2QzY2U3MzNmNTE1M2NkMjFjMmI3NThmYTI5MmEzZTA4IiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6MGFiNjc2ZTc2NThiNGZjMmFhMzg1MmZkZmRjNDc3YWY4ZjM2MTVkOGE4MDRhZjJlOTg3YzIyYTZkMmViZGY4MyIsInNoYTI1NjoxNzFhY2Y2N2E4YjhmMzY1ZmJiY2UyZjk4ZjQ0OTEzY2QzY2U3MzNmNTE1M2NkMjFjMmI3NThmYTI5MmEzZTA4Il0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZWNhYzY3YmNlYmZhZTNiZiIsImxlYXNlUm9vdCI6InNoYTI1NjpmMDZlM2QwOTliMDI4ZWZjMDA3ZjdjZGI2OWQyM2Q0ZjIzN2YxN2FiNTRmYmExNjc1N2U4ZjI4ZWUyZGM5M2JiIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T07:38:07Z",
          "mergedAt": "2026-07-28T08:18:08Z",
          "additions": 864,
          "deletions": 32,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1729,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1729",
          "title": "feat(ci): add dedicated local agent patrol",
          "body": "## Summary\n\n- add a weekly/manual, protected-default-branch Agent Patrol isolated to agent-121\n- run the digest-pinned OpenCode CI image against the local qwen3-coder model without provider login\n- classify bounded repository-work outcomes deterministically and keep model failures advisory\n- capture novel native Dogfood Findings, deduplicate repeated failures by stable fingerprint, and prohibit automatic Issue admission\n\n## Safety boundary\n\n- no pull-request or fork execution\n- no credentials, transcripts, raw prompts, Fact store, or generated capture intent in uploaded artifacts\n- no Docker socket mount, privileged container, host networking, floating image tag, or auto-pull\n- no Dev/release required-gate authority and no publication authority\n\n## Verification\n\n- `./shifu check:source`: passed; 697 contract tests passed and 10 platform-only tests skipped\n- `./shifu test:agent-patrol`: 19/19 passed, including native source CLI capture then deduplication in an isolated workspace\n- `./shifu check:gate-catalog`: 38 gates, 6 profiles, 27 structured invocations, and 27 workflows aligned\n- staged pre-commit gate: passed\n- post-rebase release publication and workflow authority checks: passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This adds a bounded non-publication CI observation lane and native Dogfood Finding adapter under existing Agent Runtime, qualification, and Dogfood authorities; it does not change an ADR record or architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe provider boundary is local OpenAI-compatible inference only, with no account login or credentials. The release control-plane update classifies the new workflow as non-publication.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and closed-world workflow inventories updated\n- [x] Automatic Issue admission remains prohibited",
          "author": "dongkeren",
          "createdAt": "2026-07-28T08:55:56Z",
          "mergedAt": "2026-07-28T09:07:23Z",
          "additions": 1266,
          "deletions": 7,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1730,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1730",
          "title": "docs(onboarding): route system readers through evolution map",
          "body": "## Summary\n\n- Make the Evolution Map the explicit longitudinal-first orientation path for people and Agents studying Kungfu as a whole.\n- Preserve direct Xinfa routing for bounded component or operational work.\n- Require every authored reader-facing Evolution Map mention to link to a navigation target.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Added a progressive reading sequence across the repository, documentation, concepts, architecture, Profile, contribution, and Agent entry surfaces.\n- Linked existing Evolution Map mentions, including the pull-request declaration and accepted ADR body.\n- Added a repository-wide Markdown ratchet with focused positive and negative fixtures.\n- Refreshed the governed semantic-amplification projection.\n\n## Verification\n\n- `./shifu evolution:map:check`\n- `./shifu docs:check`\n- `./shifu docs validate --json`\n- `./shifu docs inventory --json`\n- `./shifu docs:prose:required`\n- `./shifu check:source`\n- commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019fa773-aae4-7f50-80a5-ce53b08490d2\"],\n  \"summary\": \"Complete the first-party longitudinal onboarding route and make its navigation guarantee fail closed\",\n  \"verification\": [\"./shifu evolution:map:check\", \"./shifu docs:check\", \"./shifu check:source\"]\n}\n-->\n\n## [Evolution Map](https://github.com/kungfu-systems/kungfu/blob/dev/v4/v4.0/docs/evolution/README.md) impact\n\nEvolution impact: none\n\nThis change improves navigation and enforcement without opening or changing an Era, Stage, capability compression, or authority transition.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T08:56:57Z",
          "mergedAt": "2026-07-28T09:15:38Z",
          "additions": 179,
          "deletions": 17,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 25,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/25",
          "title": "feat(hub): unify course delivery with Kungfu work control",
          "body": "## Outcome\n\nDeliver one Course Hub application image for commercial Builder evaluation: PostgreSQL account/course authority, selectable Mock/local/hosted inference, and real Kungfu work control per generated course version.\n\n## What changed\n\n- unify the course product, qualified Kungfu CLI, and llama.cpp runtime in one amd64/arm64 first-party image with no model weights\n- add three exact click-to-install Qwen choices with resumable size/SHA verification and explicit activation\n- add stable per-course Kungfu bindings and per-version Assignment, Evidence, independent review, typed decision, recovery, and seal lifecycle through public CLI commands\n- retain account isolation, immutable course versions, approvals, outbox idempotency, and backend provenance in PostgreSQL\n- replace sidecar/automatic model overlays with compatibility no-ops and keep hosted credentials file-mounted\n- update Compose, source contracts, image workflow, docs, and retained smoke paths\n\n## Validation\n\n- `npm run check` (46 tests)\n- `bash -n` and `shellcheck` for image/browser/local-model smoke scripts\n- Docker Compose config for root, compatibility, local, offline, and hosted overlays\n- agent-120 amd64 image build from exact Kungfu package SHA `c58add4d6530541b1a7e4233573f13502a306614a8bb79e0bd60988b78f061ca`\n- image size 327,366,005 bytes; no embedded `*.gguf`; bundled Kungfu and llama.cpp executable\n- isolated account/PostgreSQL/Kungfu/restart/security smoke passed with state seal\n- explicit Qwen3 0.6B Q4 install, activation, real local generation, and Kungfu seal smoke passed\n- real Playwright browser registration plus collapsed/expanded AI and Kungfu menus passed\n\n## Boundary\n\nPre-Alpha reference delivery only; localhost by default, no public-ingress or production security claim.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T09:39:36Z",
          "mergedAt": "2026-07-28T09:40:54Z",
          "additions": 2492,
          "deletions": 1378,
          "changedFiles": 42
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 26,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/26",
          "title": "chore(runtime): lock unified course Hub candidate",
          "body": "## Outcome\n\nMake the merged and natively qualified unified Course Hub image the exact default Compose candidate.\n\n## Locked identity\n\n- runtime source: `ab3d293ada1eeec5ac07da4526906203f785f4bc`\n- image index: `ghcr.io/kungfu-systems/runtime-images/hub-starter@sha256:d2fb8c300bb61a1dadf605fbfab2b1438c067fd17320e287ff4b1d3f4991ca9b`\n- qualification: https://github.com/kungfu-systems/runtime-images/actions/runs/30347694326\n- native amd64 and arm64 smoke: passed\n\n## Validation\n\n- `npm run check` (46 tests)\n- root Compose config\n- image index contains linux/amd64 and linux/arm64 manifests\n\nThis changes only the exact runtime lock and both canonical/compatibility Compose defaults.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T09:49:05Z",
          "mergedAt": "2026-07-28T09:50:29Z",
          "additions": 5,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1990,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1990",
          "title": "feat(signing): establish formal authority ref",
          "body": "## Summary\n\n- define authority/v3/v3.0/artifact-signing as the durable channel-neutral signing authority runtime\n- extend release verification to cover reviewed authority-ref updates\n- document shared alpha and stable credential ownership through buildchain-artifact-signing\n- retain the signing train only as a bounded migration rollback\n\n## Verification\n\n- corepack pnpm@11.7.0 run check\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs are included\n- [x] Provider and environment boundaries remain Buildchain-owned\n- [x] Release evidence and provenance continue to fail closed\n- [x] Public package names, domains, and hosted-service claims are unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-28T09:51:24Z",
          "mergedAt": "2026-07-28T09:55:19Z",
          "additions": 66,
          "deletions": 20,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1732,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1732",
          "title": "fix(buildchain): generalize dev channel authority",
          "body": "## Summary\n\nGeneralize operational development-channel authority from one exact v4 branch to the repository default admitted dev family. The family admits v4 and future version lines while explicitly excluding legacy v1-v3 lines that cannot emit the queue lease.\n\n## Changes\n\n- Resolve the active dev branch from event or repository authority across source acceptance, measurement, patrol, artifact, maintainability, and evolution-history paths.\n- Declare ruleset 19057118 as the admitted dev channel family with explicit legacy exclusions.\n- Add a fail-closed source check that rejects new operational exact dev-branch bindings.\n- Make the newly added Agent Patrol follow the protected repository default branch instead of v4.\n- Preserve exact alpha and release branch contracts because they are version-scoped publication authorities.\n\n## Verification\n\n- `./shifu test:dev-channel-authority`\n- `./shifu test:alpha-attention-operations`\n- `./shifu test:gate-latency`\n- `./shifu check:gate-catalog`\n- `./shifu check:release-publication-control-plane`\n- cold read-only source-discovery fixture\n- Project Cut queue admission on the latest base\n- staged repository gates on all three linear latest-base commits\n\nThe complete Agent Patrol workflow contract passes. Its newly landed local runtime suite also exposed three machine-environment failures in Kungfu Home/uv experiment execution; those tests are outside this branch-routing change, and the required remote source-acceptance check remains authoritative. Full local check previously reached the SDK suite; its only failure was a pre-existing canonical-policy rendered-hash mismatch reproduced from the unmodified base commit.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix changes development-channel routing and ruleset activation scope without changing an architecture contract.\"\n}\n-->\n\n## Evolution map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe artifact mainline selector now follows the repository default branch through origin/HEAD; Rust, Python, workflow authority, publication roots, and source acceptance checks cover the boundary.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-28T09:26:57Z",
          "mergedAt": "2026-07-28T09:55:28Z",
          "additions": 613,
          "deletions": 106,
          "changedFiles": 43
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 60,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/60",
          "title": "ci(signing): use protected authority ref",
          "body": "## Summary\n\n- move signing dogfood from the temporary train to the protected channel-neutral Buildchain authority ref\n- use the same Buildchain signing environment for prerelease and stable qualification\n- keep all certificate and notary configuration outside the consumer repository\n\n## Verification\n\n- npm run check\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs are included\n- [x] Provider APIs and release evidence remain Buildchain-owned\n- [x] Official branding, package names, and release identity are unchanged\n- [x] Publication remains disabled in this dogfood workflow",
          "author": "dongkeren",
          "createdAt": "2026-07-28T09:51:27Z",
          "mergedAt": "2026-07-28T09:57:02Z",
          "additions": 13,
          "deletions": 3,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1992,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1992",
          "title": "feat(runners): add bounded AWS CodeBuild burst plane",
          "body": "## Summary\n\n- Add an explicit Linux-only AWS CodeBuild runner preset for bounded overflow qualification.\n- Add a default-disabled CloudFormation plane with two-job concurrency, a USD 49 budget, idempotent admission, stale-cost fail-closed behavior, and a dedicated kill switch.\n- Keep trust evaluation on GitHub-hosted infrastructure before any cloud runner is selected.\n- No live AWS or GitHub provider resource is created or changed by this pull request.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Resolve dynamic CodeBuild labels from an exact project input.\n- Record exact source, GitHub job, and CodeBuild provenance.\n- Add the cost model, qualification verifier, IaC, tests, operator sequence, rollback, and generated public indexes.\n\n## Verification\n\n- `pnpm run check` — 671 tests passed; workflow checks and all action bundles rebuilt.\n- `aws cloudformation validate-template --profile us --region us-east-1 --template-body file://infra/aws-us-elastic-runner-burst-plane/codebuild-poc.template.yml`.\n- `node --test tests/aws-runner-burst.test.mjs tests/build-surface.test.mjs` — 86 tests passed.\n- `git diff --check`.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [x] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe stack uses a scoped CodeConnections token path and least-privilege IAM roles but contains no credential value. It is disabled until a separately approved live arm operation and records provider, cost, and cleanup evidence without publication authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "kungfu-origin",
          "createdAt": "2026-07-28T10:05:52Z",
          "mergedAt": "2026-07-28T10:09:17Z",
          "additions": 1456,
          "deletions": 46,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1991,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1991",
          "title": "fix(runtime): accept protected authority refs",
          "body": "## Summary\n- recognize protected `authority/vN/vN.M/<capability>` refs in the public channel router\n- preserve trusted-dispatch and write-permission gates for authority runtime overrides\n- expose the `authority` runtime class through the reusable build contract\n\n## Verification\n- `corepack pnpm@11.7.0 run check`\n- 942 unit tests passed\n- action bundle integrity passed\n\n## Dogfood evidence\nAgent Hub Demo run 30348765444 reached the formal authority workflow ref and failed closed at the previously train-only channel parser. This patch closes that exact gap.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T10:05:38Z",
          "mergedAt": "2026-07-28T10:11:29Z",
          "additions": 75,
          "deletions": 36,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1994,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1994",
          "title": "fix(governance): admit signing authority promotion",
          "body": "## Summary\n- admit the formal artifact-signing authority ref in Buildchain governance with exact App-bound `check` and `verify` requirements\n- require strict status checks and preserve an empty bypass set\n- validate same-line `dev` to `authority` promotion without inventing a version bump\n\n## Verification\n- `corepack pnpm@11.7.0 run check`\n- 944 unit tests passed\n- direct `verify-release-pr.mjs` authority promotion probe passed\n\n## Dogfood evidence\nBuildchain authority promotion PR #1993 failed closed on target admission and release-line classification. This patch closes only those two explicit gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T10:17:05Z",
          "mergedAt": "2026-07-28T10:22:42Z",
          "additions": 69,
          "deletions": 4,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1993,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1993",
          "title": "chore(signing): promote artifact signing authority",
          "body": "## Authority promotion\nPromote the reviewed Buildchain runtime from `dev/v3/v3.0` to the protected, channel-neutral artifact-signing authority ref.\n\nThis includes native recognition of `authority/vN/vN.M/<capability>` by both the channel router and immutable runtime resolver. Authority refs remain trusted manual overrides and still require a `workflow_dispatch` event plus write-level caller permission.\n\n## Evidence\n- Buildchain PR #1991 merged through the protected dev merge queue\n- local full `pnpm run check`: 942 tests and action bundle integrity passed\n- Agent Hub Demo run 30348765444 provided the fail-closed regression witness",
          "author": "dongkeren",
          "createdAt": "2026-07-28T10:11:52Z",
          "mergedAt": "2026-07-28T10:24:20Z",
          "additions": 143,
          "deletions": 39,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1728,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1728",
          "title": "feat(kfx): enforce explicit runtime capability grants",
          "body": "## Summary\n\nMake every executable KFX host path require one explicit, exact capability grant bound to the package, Core policy, Release Passport assessment, Work/Warrant authority, Cut/revision/generation, approvals, and runtime confinement.\n\nKFD compliance now affects only Core policy eligibility for bounded low-risk operations; it never mints authority. First-party or Product System identity does not grant capabilities or placement. Product System remains assembly/distribution metadata, while host launch re-authorizes the exact current authority roots and fails closed on drift or replay.\n\nThis is the capability-grant/runtime-isolation stage after #1718. It does not claim the later identity-neutral authority cutover, recursive Control Suite dogfood, or the sole terminal qualification.\n\n## Related issue\n\nFollow-up to #1624 and #1718.\n\n## Changes\n\n- add Core-owned capability declaration, requested/effective policy, authority-basis, capability-grant, and Warrant bindings\n- reject caller-supplied runtime tier, admission grade, Product System, lifecycle, and granted-capability authority\n- persist exact supply/admission, policy, grant, approval, Work/Warrant, Cut, revision, generation, and isolation roots in accepted snapshots and settlement facts\n- require GUI IPC sandboxing, WASM confinement, service process isolation, and disabled-by-default integrated adapters before execution\n- add exact host re-authorization across native, Python, Node, Control API, and WASM launch paths\n- separate read-only KFX host inspection from mutation-capable Control API transport\n- remove implicit System authority from bundled manifests and keep Product System metadata non-authorizing\n- add fail-closed coverage for package, policy, capability, approval, Cut, revision, generation, Warrant, confinement, and replay drift\n\n## Verification\n\n- `./shifu build:core`\n- `./shifu test:native-kfx-admission`\n- `./shifu lint`\n- `./shifu check:source`\n- `./shifu check` (`changed-scope gate passed`)\n- repository pre-commit staged gate (`staged gate passed`)\n- C++ format, Ruff format/lint, Biome, TypeScript, SDK, documentation, invariant, KFX Profile Suite, and layer qualification gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-7ef4-b28b-ee1fbaf9e62e\",\n    \"KF-ADR-019f86da-4f90-73f3-b027-c343b2bc8bcc\",\n    \"KF-ADR-019f86da-4f90-7d6c-926a-ddd27dbde8ab\",\n    \"KF-ADR-019f86da-4f90-72df-add3-948f3ae38c3a\",\n    \"KF-ADR-019f8c53-6105-71e5-8f34-53f2a81ee61c\"\n  ],\n  \"summary\": \"Require explicit Core-policy capability grants and exact runtime confinement across every KFX host path without granting authority from KFD, first-party identity, or Product System metadata.\",\n  \"verification\": [\n    \"./shifu test:native-kfx-admission\",\n    \"./shifu lint\",\n    \"./shifu check:source\",\n    \"./shifu check\",\n    \"repository pre-commit staged gate\"\n  ]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change consumes exact Release Passport and KFD evidence for local runtime admission, but grants no authority from KFD status, product identity, or package origin. It performs no publication or deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-28T08:17:56Z",
          "mergedAt": "2026-07-28T10:25:27Z",
          "additions": 1591,
          "deletions": 812,
          "changedFiles": 44
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1996,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1996",
          "title": "docs(attestation): use positional verify artifact",
          "body": "## Summary\n\n- document the artifact as the required positional argument for `buildchain verify github-artifact-attestation`\n- regenerate the v3 site bundle and public manual digests\n\n## Verification\n\n- `pnpm run check:site`\n- `node scripts/check-inventory.mjs`\n- `node --test tests/github-artifact-attestation.test.mjs tests/public-surface-audit.test.mjs`\n- `git diff --check`\n- full `pnpm run check` reaches unit tests; two existing macOS path-canonicalization failures remain in `artifact-signing-seal.test.mjs` and are unrelated to this documentation-only diff",
          "author": "dongkeren",
          "createdAt": "2026-07-28T10:38:13Z",
          "mergedAt": "2026-07-28T10:42:00Z",
          "additions": 13,
          "deletions": 13,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1734,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1734",
          "title": "fix(ci): follow default dev ruleset authority",
          "body": "## Summary\n\nUse the repository default branch as the moving GitHub merge-queue ruleset authority because GitHub rejects wildcard ref targets when merge queue is enabled. Kungfu still admits only the v4+ dev family.\n\n## Verification\n\n- dev channel authority tests pass\n- queue admission lease tests pass\n- alpha attention operations tests pass\n- gate catalog passes\n- staged repository gate passes\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix corrects a provider-constrained ruleset target without changing an architecture contract.\"\n}\n-->\n\n## Evolution map impact\n\nEvolution impact: none\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for the provider constraint",
          "author": "dongkeren",
          "createdAt": "2026-07-28T10:02:18Z",
          "mergedAt": "2026-07-28T10:46:38Z",
          "additions": 28,
          "deletions": 21,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1738,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1738",
          "title": "fix(ci): support rootless Patrol bind mounts",
          "body": "## Summary\n\n- detect rootless Docker from the daemon SecurityOptions before launching OpenCode\n- use namespace-mapped container root only for rootless daemons so runner-owned bind mounts remain writable\n- preserve invoking host UID/GID for rootful daemons and add regression coverage\n\n## Live evidence\n\n- agent-121 rootless bind mount appeared as container root and rejected UID 996 writes\n- the same digest-pinned image completed a real Qwen canary with container 0:0, which maps back to the unprivileged gha-runner host account\n- no host Docker group, privileged container, Docker socket mount, or host network was introduced\n\n## Verification\n\n- `./shifu build:core`: passed\n- `./shifu test:agent-repository-work`: 11/11 passed\n- `./shifu test:agent-patrol`: 20/20 passed\n- `./shifu check:gate-catalog`: 38 gates and 27 workflows aligned\n- staged pre-commit gate: passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This is a bounded runtime compatibility correction for the existing agent Patrol and does not change an ADR or architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Rootful least-privilege behavior is preserved\n- [x] Rootless ownership behavior is covered by tests",
          "author": "dongkeren",
          "createdAt": "2026-07-28T10:33:47Z",
          "mergedAt": "2026-07-28T10:46:39Z",
          "additions": 78,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1736,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1736",
          "title": "feat(ci): add AWS CodeBuild burst qualification",
          "body": "## Summary\n\n- Add a manual-only, canonical-repository AWS Linux burst qualification workflow.\n- Require a write-capable actor and the exact reviewed Buildchain train before cloud runner selection.\n- Build unsigned Linux Core output and retain exact source and artifact digests without publication, signing, notarization, deployment, static AWS, or long-lived GitHub credentials.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Add the bounded qualification workflow and Buildchain consumer wiring.\n- Add exact CodeBuild provenance recording and local byte verification.\n- Register the workflow as qualification and explicitly non-publication.\n\n## Verification\n\n- `./shifu check:source` passed after rebasing onto the current `dev/v4/v4.0` head.\n- `./shifu build:core` passed.\n- Workflow authority: 28 closed-world workflows aligned.\n- Publication control plane: 28 workflows, 10 surfaces, qualifying.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Adds an isolated manual CI qualification route without changing a product or architecture contract\"\n}\n-->\n\n## [Evolution Map](../docs/evolution/README.md) impact\n\nEvolution impact: none\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis workflow consumes only the default-disabled bounded provider, uses read-only repository permission, and records qualification provenance. It has no publication or release authority and receives no repository secrets.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-28T10:19:54Z",
          "mergedAt": "2026-07-28T10:51:58Z",
          "additions": 411,
          "deletions": 2,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 27,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/27",
          "title": "feat(hub): make the reference app builder-ready",
          "body": "## Summary\n- make `apps/course-hub` the canonical application and retain the former starter under `legacy/`\n- add Agent-first README/AGENTS onboarding plus architecture, API, and extension guides\n- add a source-only developer Compose overlay pinned to the qualified runtime image\n- verify the shipped KFD-3 discovery path through `kungfu agent brief` and `kungfu agent verify`\n\n## Validation\n- `npm ci --ignore-scripts --registry=https://registry.npmjs.org/`\n- `npm run check` (46 tests)\n- `bash -n` and `shellcheck` for repository shell scripts\n- `docker compose -f compose.yaml -f compose.dev.yaml config --quiet`\n- local Markdown link audit\n\n## License\nApache-2.0; existing repository license and SPDX policy retained.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T11:09:28Z",
          "mergedAt": "2026-07-28T11:10:37Z",
          "additions": 844,
          "deletions": 157,
          "changedFiles": 63
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1739,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1739",
          "title": "feat(ci): bind family delivery proof evidence",
          "body": "## Summary\n\nBind exact affected-native proof reuse to one Initiative-family delivery attempt and make merge-queue delivery evidence reconstructable through final dev ancestry. Missing, stale, disagreeing, or invalidated evidence remains unproved and falls back to fresh qualification.\n\nThis is the second linear Project Cut successor to repair-required PRs #1733 and #1737. It preserves both attempts as evidence and applies the net feature commit directly to the latest protected dev authority without force-pushing or bypassing first-parent replay.\n\nNative Assignment: `2026-07-28-kungfu-go-family-proof-evidence-binding`\nWork definition root: `sha256:050005a814a7eb2a1c98351aded01bbf923576ca5f895a2f1e4028e0277f15cf`\n\n## Related issue\n\nNone.\n\n## Changes\n\n- extend the exact proof descriptor with family, delivery-class, queue-admission, dependency, closure, and required-check bindings while preserving legacy proof readability\n- seal merge-group delivery attempts and bind cache promotion to the exact successful attempt\n- reconstruct PR head, queue rounds, dequeue reasons, repeated validation, runner use, merge commit, and final dev ancestry without rewriting historical gaps\n- add fail-closed tests and refresh generated workflow authority\n\n## Verification\n\n- `./shifu lint`\n- `./shifu test:gate-latency`\n- `./shifu check:gate-catalog`\n- `./shifu check:source`\n- `./shifu project-cut:queue-admission -- --base origin/dev/v4/v4.0 --head HEAD`\n- `actionlint .github/workflows/affected-native-pr.yml .github/workflows/affected-native-cache-promote.yml .github/workflows/cancel-dequeued-merge-group.yml`\n- `git diff --check origin/dev/v4/v4.0...HEAD`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"SHIFU-ADR-019f86da-4f90-79a1-bc85-4b542fecf011\"],\"summary\":\"Bind exact native proof reuse and cache promotion to one reconstructable Initiative-family delivery attempt without changing Gate selection or latency qualification authority.\",\"verification\":[\"./shifu lint\",\"./shifu test:gate-latency\",\"./shifu check:gate-catalog\",\"./shifu check:source\",\"protected affected-native Linux qualification\"]}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\nThis extends evidence for the current Gate control-plane Stage; it does not open or settle a new architecture authority.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change is limited to existing CI proof, cache-promotion, and delivery-measurement evidence. Exact binding validation and fail-closed fallback are covered by the checks above.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWdvLWZhbWlseS1jb250aW51b3VzLWRlbGl2ZXJ5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtZ28tZmFtaWx5LXByb29mLWV2aWRlbmNlLWJpbmRpbmciLCJkZWxpdmVyeUNsYXNzIjoibmF0aXZlLXByb29mLXJlcXVpcmVkIiwiZGV2SGVhZCI6Ijc0NmI1MmVlNmRkNmM1MGY2OWJjN2NlYTI0YjZhNzkyYTQ1NzZhMzYiLCJwdWxsUmVxdWVzdEhlYWQiOiJhNjVkZTI0ZTg2N2YyNmZiNDU0M2FkOWUyODkzZDg2M2E4OTMxY2RlIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiI2YjViYjQxZjIxNTA0MTgwMmVjYmY1YTQ0MzEzNTg2NzYxNzk0NjNmIiwicmVwbGF5ZWRUcmVlIjoiODIyMzI4MTAxMWJiMGM0ZmUzNTQ0NTBlNGMwMjdlNjQ4NmMwNWQ5YSIsInF1ZXVlQXR0ZW1wdCI6ImE2NWRlMjRlODY3ZjI2ZmI0NTQzYWQ5ZTI4OTNkODYzYTg5MzFjZGVANzQ2YjUyZWU2ZGQ2YzUwZjY5YmM3Y2VhMjRiNmE3OTJhNDU3NmEzNiIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjplYzllN2JiYzg5ZmFlNDU4NDc2YjQ3ZjQyNzhmZTUzZGQ4M2Y0ZTkyMDFiZmM5ZWQzNDk2MzQyODQ4Zjc0YzZmIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6MDUwMDA1YTgxNGE3ZWIyYTFjOTgzNTFhZGVkMDFiYmY5MjM1NzZjYTVmODk1YTJmMWU0MDI4ZTAyNzdmMTVjZiIsInNoYTI1NjplYzllN2JiYzg5ZmFlNDU4NDc2YjQ3ZjQyNzhmZTUzZGQ4M2Y0ZTkyMDFiZmM5ZWQzNDk2MzQyODQ4Zjc0YzZmIl0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZWNhYzY3YmNlYmZhZTNiZiIsImxlYXNlUm9vdCI6InNoYTI1NjphMzg5M2EzYzQ2MDVlMTJiOGI0NzNkZmJiMmEyNjg4ODA1M2ZmNTM5ZjNkOGQwMjM0NDVmOTgwNzU1Nzg4MTEwIn0 -->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T11:01:23Z",
          "mergedAt": "2026-07-28T11:43:52Z",
          "additions": 2002,
          "deletions": 145,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1743,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1743",
          "title": "fix(kfx): restore candidate qualification gates",
          "body": "## Summary\n\nRestore the exact KFX authority inputs required by the candidate qualification path so the existing KFD support claims can be verified on production artifacts.\n\n## Related issue\n\nAtlas goal: 2026-07-26-kungfu-kfd-support-governance\n\n## Changes\n\n- Bind production libwasm execution probes to an admitted KFX package and exact host contract.\n- Supply exact admission and recovery authority to install/scaffold qualification fixtures.\n- Align the Node storage assessment with the native Buildchain envelope.\n- Accept the signed JSON integer representation of a non-negative recovery revision at the native boundary.\n\n## Verification\n\n- ./shifu check:source\n- ./shifu verify --skip-episode-qualification\n- ./shifu test:native-kfx-admission\n- ./shifu --filter @kungfu-tech/core test:storage-binding\n- ./shifu exec node tests/fixtures/kfx-demo-install/run.mjs\n- ./shifu exec node tests/fixtures/kfx-demo-scaffold/run.mjs\n- ./shifu exec node --test product/scripts/compatibility.test.mjs\n- ./shifu kfd:support-matrix:check\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This repair restores qualification fixtures and exact authority binding for already accepted KFX contracts; it does not alter architecture authority or widen KFD support claims.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe changed release qualification paths remain fail-closed and are source-bound by the checks above.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (no public behavior change; qualification fixtures and exact authority binding only)\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI2LWt1bmdmdS1rZmQtc3VwcG9ydC1nb3Zlcm5hbmNlIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiI2ZTAyYzE5OGQzZWJhMjY0MDMxYjY2M2I1ZjYyYThjY2Q5YzZkZWYyIiwicHVsbFJlcXVlc3RIZWFkIjoiNzFlMzZmMDJkMmNlZjFiMDhjNjkzYTNlZjRlNTc5YTJhNjNlZjFkNSIsInJlcGxheWVkQ2FuZGlkYXRlIjoiMGU0ODc4MzY1NzgyOGNlOGEzY2ZhNGJkNTE5MmEzMGIxYzcyZmQ2YiIsInJlcGxheWVkVHJlZSI6Ijc2OTgzNjIzZDY0NjljYjUxODcxYzc2ZDU3YzE5MTUyOTY0ZjBlMWUiLCJxdWV1ZUF0dGVtcHQiOiI3MWUzNmYwMmQyY2VmMWIwOGM2OTNhM2VmNGU1NzlhMmE2M2VmMWQ1QDZlMDJjMTk4ZDNlYmEyNjQwMzFiNjYzYjVmNjJhOGNjZDljNmRlZjIiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6MGE5ZTY5M2IwYzA5N2FkYzQzMmE4ZjFhZjA5M2JhNjg3MDZiZTQwOGU5OTVjNmZhYTg4OGZlNTNlYTMyOTlkMiIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjBhOWU2OTNiMGMwOTdhZGM0MzJhOGYxYWYwOTNiYTY4NzA2YmU0MDhlOTk1YzZmYWE4ODhmZTUzZWEzMjk5ZDIiLCJzaGEyNTY6YjI4YWM4YzE1YzNkNTAzZmE5ZGYwMjVkOTc1ZjZhNzA1NjkxZGMyNmE5OTcwOTFiYjUxNWY5Y2RkNTI0ZjYyYSJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6MGRkNmU4ODc4ZTdlNjFkMDNkOTgxZTZmNTAwNTM1ODU2NmNmNjZmYzlhOGI4ODJkNjIzOGE4ZjQ1YTYwYzkxYiJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T12:01:20Z",
          "mergedAt": "2026-07-28T12:26:53Z",
          "additions": 396,
          "deletions": 60,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1997,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1997",
          "title": "fix(aws): shorten CodeConnections PoC name",
          "body": "## Summary\n\nCorrect the Phase 1 operator command after AWS rejected the original connection name at provider validation. CodeConnections allows at most 32 characters; the replacement `kungfu-linux-burst-poc` is 22 characters and remains distinct from the stack and CodeBuild project names.\n\n## Related issue\n\nNone. Discovered during the bounded provider qualification.\n\n## Changes\n\n- use the accepted short connection name in the reviewed provider sequence\n- document the 32-character provider limit\n\n## Verification\n\n- `pnpm exec prettier --check docs/aws-us-elastic-runner-burst-plane.md`\n- verified the replacement name length is 22\n- AWS `CreateConnection` accepted the replacement after rejecting the original before resource creation\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change documents a provider input constraint only. No credential material is added or read.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-28T12:27:36Z",
          "mergedAt": "2026-07-28T12:31:41Z",
          "additions": 12,
          "deletions": 8,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 28,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/28",
          "title": "feat: add one-command Course Hub installation",
          "body": "## Summary\n- publish the supported Course Hub topology as an OCI Compose application\n- generate and persist database credentials without user configuration\n- keep PostgreSQL private while allowing HUB_PORT to select the Web port\n\n## Validation\n- npm ci --ignore-scripts --registry=https://registry.npmjs.org/\n- npm run check (51 tests)\n- docker compose config with HUB_PORT override\n- image candidate run 30359339784: native linux/amd64 and linux/arm64 smoke passed\n\n## Version impact\nAdditive pre-Alpha delivery capability; no existing runtime or business API is removed.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T12:38:55Z",
          "mergedAt": "2026-07-28T12:39:48Z",
          "additions": 569,
          "deletions": 71,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 29,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/29",
          "title": "fix: publish structured Course Hub port",
          "body": "## Summary\n- express the localhost Web port with Compose long syntax required by OCI publication\n- retain HUB_PORT and loopback-only defaults\n- extend policy checks for the structured host_ip field\n\n## Validation\n- npm run check (51 tests)\n- HUB_PORT=19084 docker compose config\n- docker compose publish --dry-run completed successfully",
          "author": "dongkeren",
          "createdAt": "2026-07-28T12:42:24Z",
          "mergedAt": "2026-07-28T12:43:15Z",
          "additions": 14,
          "deletions": 7,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1999,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1999",
          "title": "feat(release): bind initiative family evidence",
          "body": "## Summary\n\n- add an optional, exact-root Initiative-family evidence envelope to release-candidate passports\n- fail promotion before side effects when required family, source, terminal, continuation, artifact, or release evidence does not verify\n- preserve non-family release compatibility and existing protected publication policy\n\n## Latest-dev replay\n\nReplayed the implementation onto `be8a8669b39a72cfcccbe5e1405f7c675bb3b52b`; generated-site conflicts were regenerated from the repository source. This PR supersedes #1998 without force-pushing its audit history.\n\n## Validation\n\n- `pnpm check` (674 tests passed after replay)\n- generated site bundle check\n- workflow contract checks\n- generated GitHub Action bundles\n- `git diff --check`\n\n## Safety\n\nNo release, channel, secret, ruleset, branch-protection, or publication-policy mutation was performed.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T12:53:33Z",
          "mergedAt": "2026-07-28T12:55:03Z",
          "additions": 752,
          "deletions": 120,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2000,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2000",
          "title": "fix(aws): keep disabled CodeBuild trigger valid",
          "body": "## Summary\n\n- keep the CodeBuild project fail-closed with its webhook disabled\n- omit webhook filter groups until the explicit create-webhook arming step\n- add a regression assertion for the CloudFormation constraint\n\n## Validation\n\n- `pnpm run check`\n- `aws cloudformation validate-template --region us-east-1 --template-body file://infra/aws-us-elastic-runner-burst-plane/codebuild-poc.template.yml`\n- live CloudFormation failure reproduced and rolled back without starting a build: disabled webhooks reject configured filter groups\n\n## Provider impact\n\nThe change creates no webhook or build. It only makes the reviewed fail-closed stack valid; workflow filters remain applied by the explicit arming command after fresh cost telemetry.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T13:05:15Z",
          "mergedAt": "2026-07-28T13:08:02Z",
          "additions": 2,
          "deletions": 7,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 30,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/30",
          "title": "fix: stabilize OCI loopback interpolation",
          "body": "## Summary\n- keep the OCI application host_ip as a literal loopback address\n- retain HUB_PORT as the only ordinary port override\n- run publication and first-fetch smoke with Docker Compose 5.1.2, matching the reported client\n\n## Validation\n- npm run check (51 tests)\n- Docker Compose 5.1.2 config with HUB_PORT=19087\n- hostile HUB_BIND_ADDRESS remains bound to 127.0.0.1\n- docker compose publish --dry-run passed\n\n## Reported failure\nFixes first remote up parsing host_ip as the literal interpolation expression.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T13:19:30Z",
          "mergedAt": "2026-07-28T13:20:25Z",
          "additions": 15,
          "deletions": 10,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2002,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2002",
          "title": "fix(candidate): carry repository PR declarations",
          "body": "Summary:\n\n- add an optional repository-owned pull request body prefix to the dev-to-Alpha candidate patrol\n- preserve governance declarations while Buildchain updates its managed candidate state\n- reject attempts to inject the Buildchain controller marker\n- publish the input through the generated site registry and document the contract\n\nVerification:\n\n- canonical TMPDIR corepack pnpm@11.7.0 run check\n- 946 tests passed; workflow and action bundle checks passed\n\nThis fixes promotion candidates that must carry repository-specific machine-readable admission manifests at creation time.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T13:31:38Z",
          "mergedAt": "2026-07-28T13:35:17Z",
          "additions": 87,
          "deletions": 11,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1989,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1989",
          "title": "fix(macos): sign native code embedded in wheels",
          "body": "## Summary\n\n- discover wheels inside the sealed macOS app before outer app signing\n- reject unsafe paths, collisions, symlinks, special entries, and ambiguous RECORD metadata before credential use\n- sign every embedded Mach-O with Developer ID, hardened runtime, and a secure timestamp\n- rebuild wheel RECORD from exact post-sign bytes, repack, and verify the archive\n- expose wheel and nested Mach-O counts in credential-island evidence\n\n## Validation\n\n- node --test tests/macos-credential-island.test.mjs (18/18)\n- node scripts/check-action-bundles.mjs\n- real ditto wheel pack/unpack RECORD roundtrip\n- pnpm run check: 944/946 pass locally; the two failures are unchanged artifact-signing-seal tests caused by macOS /var versus /private/var realpath handling and do not touch this patch\n\n## Downstream proof\n\nThe exact train ref train/v3/v3.0/macos-wheel-notary-closure will be used to rerun the Kungfu protected-main Build at source a8dba484e2ecf8ffc9f64b2af4050b75eb2922bf. The prior run failed only because Apple found three unsigned Mach-O files inside the embedded kungfu wheel.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T09:32:03Z",
          "mergedAt": "2026-07-28T13:45:51Z",
          "additions": 520,
          "deletions": 82,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2004,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2004",
          "title": "chore(release): promote macOS credential closure to alpha",
          "body": "Promotes protected dev/v3/v3.0 through merge commit b05345cc into alpha/v3/v3.0 after resolving the generated Buildchain contract summary against current alpha version state.\n\nExact downstream proof before promotion:\n- kungfu source: a8dba484e2ecf8ffc9f64b2af4050b75eb2922bf\n- Buildchain runtime: 9dac20ba056c9421e9041a8d301cfe671367a97e\n- qualification run: kungfu-systems/kungfu#30359979133\n- credential island sealed 5 Mach-O files across 1 embedded wheel and accepted the signed/notarized/stapled/Gatekeeper-verified application and DMG.\n\nLocal integration validation: `TMPDIR=/private/tmp pnpm check` passed.\n\nReplaces conflicting direct channel PR #2003.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T13:50:30Z",
          "mergedAt": "2026-07-28T13:54:43Z",
          "additions": 6426,
          "deletions": 483,
          "changedFiles": 83
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2005,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2005",
          "title": "Prepare v3.0.2-alpha.8",
          "body": "Create the generated version-state commit for v3.0.2-alpha.8.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: 4b2b4a7d5b1ca3558f15585aa24c6d1bb239f314 -> 25e3b31992ef0186cec050cf6a6023ba44d822a2\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T13:59:53Z",
          "mergedAt": "2026-07-28T14:06:41Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1747,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1747",
          "title": "fix(agent-patrol): forward rootless Docker runtime",
          "body": "## Summary\n\n- forward the workflow-selected Unix Docker host into the internal OpenCode proxy\n- allow only the default rootful socket or the invoking user rootless socket; reject TCP and cross-user sockets\n- accept the standard Shifu `--` argument separator in Patrol classification and Dogfood capture CLIs\n\n## Live evidence\n\n- agent-121 formal Patrol reached the repository-work experiment but the nested OpenCode proxy fell back to `/var/run/docker.sock`\n- the rootless daemon remains owned by the unprivileged `gha-runner` account at `/run/user/996/docker.sock`\n- no Docker group, privileged container, socket bind mount, host networking, or LAN Ollama listener is introduced\n\n## Verification\n\n- `./shifu docs context ... --route kungfu-core-development-agent --json`: pass\n- `pnpm exec biome check <six changed files>`: pass\n- `./shifu check:source`: pass\n- `./shifu check:staged`: pass, including 112/112 documentation tests and 50/50 latency contract tests\n- targeted Patrol assertions: new Docker-host and CLI-separator cases pass\n- full Patrol native suite will be rerun on agent-121 after protected merge, where the required Core native build is provisioned\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This is a least-privilege runner compatibility correction for the existing Agent Patrol and does not change an ADR or architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Rootful Docker behavior remains the default\n- [x] Rootless Docker forwarding is restricted to the current user socket\n- [x] Dogfood Issue admission remains prohibited\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI4LWt1bmdmdS1hZ2VudC1wYXRyb2wtYWdlbnQtMTIxIiwiZGVsaXZlcnlDbGFzcyI6Im5vbi1uYXRpdmUtZmFzdCIsImRldkhlYWQiOiJlOGExMWJkOWU5ZmY3ZThiNjQ1MGUxZWM1ODkyNTE1M2YxOWUwYTBlIiwicHVsbFJlcXVlc3RIZWFkIjoiOTFkYWNhOTdkNThhOTVhODA2MTBiNTk0ODYwMjEzNjVhZmFiMjliZiIsInJlcGxheWVkQ2FuZGlkYXRlIjoiYTcyMzZhZmNiNmNlMzNhY2EzZjU3Mjk5MmQ1YTQ0YjAwZWY0YjBhYiIsInJlcGxheWVkVHJlZSI6IjdjZWMwOTNlYTJhYjRjNzU2ZGYyMjMzNDE4ODcyYWY1ZjFkZjQwOTkiLCJxdWV1ZUF0dGVtcHQiOiI5MWRhY2E5N2Q1OGE5NWE4MDYxMGI1OTQ4NjAyMTM2NWFmYWIyOWJmQGU4YTExYmQ5ZTlmZjdlOGI2NDUwZTFlYzU4OTI1MTUzZjE5ZTBhMGUiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6NGI2ZWExM2YyNjQ2MGY4MGY4MGJmNTE1MGM5ZmNlM2NiYzYwYTI5OTIyNjAwYTJmZjM1OGViMThjZTJmYTljOSIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjRiNmVhMTNmMjY0NjBmODBmODBiZjUxNTBjOWZjZTNjYmM2MGEyOTkyMjYwMGEyZmYzNThlYjE4Y2UyZmE5YzkiLCJzaGEyNTY6N2Q1M2I4YTZkNTcyMzAxZWQyNjliOWIyN2VjMTk2NDhjYWM1MDcwMGJlYjRlZDcyODlmMWFkMjEyOWE0YzE4ZiJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6OTA1ODEwYzk2MGQ1YjdjMjY3ZTM5NGJlY2E0MGM3N2FhOTQ2NzFiNjRhMzg4OTQzNDQ3Y2VjOTdkN2MxNTk4ZCJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T13:48:02Z",
          "mergedAt": "2026-07-28T14:12:24Z",
          "additions": 103,
          "deletions": 3,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2007,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2007",
          "title": "fix(build): tolerate legacy runtime signing surface",
          "body": "Alpha self-dogfood run 30367168439 proved that the new outer build workflow unconditionally invoked `scripts/seal-artifact-signing-requests.mjs` while the stable `v3` runtime (f541fd28) predates that capability. The stable consumer therefore failed with MODULE_NOT_FOUND even though its validated legacy config declares no signing artifacts.\n\nThis patch keeps fail-closed signing behavior for capable runtimes while negotiating the legacy boundary:\n- if the resolved runtime contains the sealer, run it unchanged;\n- if the validated legacy runtime lacks it, emit zero requests;\n- upload/dispatch/import signing artifacts only when request-count is nonzero.\n\nValidation: `TMPDIR=/private/tmp pnpm check` passed, including workflow shellcheck, full unit suite, generated site contract, and action bundles.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T14:20:52Z",
          "mergedAt": "2026-07-28T14:27:09Z",
          "additions": 57,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 225,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/225",
          "title": "fix(site): embed latest dogfood observation",
          "body": "## Summary\n\n- resolve the public latest dogfood alias to its byte-identical immutable snapshot during every site build\n- embed the admitted snapshot in static HTML and expose its immutable URL and SHA-256 in the site manifest\n- fail closed for published builds and prevent browser-side downgrade to older evidence\n\n## Verification\n\n- pnpm run build\n- pnpm run check\n- fixture fallback and required-mode failure paths\n- Playwright local readback with no console errors\n- raw HTML readback without JavaScript\n\nBuildchain follow-up: kungfu-systems/buildchain#2006",
          "author": "dongkeren",
          "createdAt": "2026-07-28T14:10:41Z",
          "mergedAt": "2026-07-28T14:32:16Z",
          "additions": 236,
          "deletions": 30,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 31,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/31",
          "title": "fix: promote preview only after qualification",
          "body": "## Summary\n- publish only the commit-addressed Compose candidate before qualification\n- move compose-preview only after the exact candidate passes fresh-install smoke\n- promote by carbon-copying the verified OCI manifest and require digest equality\n- retain the previous preview digest and verify the promoted channel resolves\n\n## Validation\n- npm run check (51 tests)\n- actionlint .github/workflows/application.yml\n- docker compose publish --dry-run\n- docker buildx imagetools create --dry-run --prefer-index=false\n\n## Safety\nA failed candidate smoke leaves the existing compose-preview tag unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T14:33:32Z",
          "mergedAt": "2026-07-28T14:34:20Z",
          "additions": 87,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2008,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2008",
          "title": "chore(release): promote stable signing compatibility to alpha",
          "body": "## Summary\n\n- promote the independently reviewed legacy-runtime signing compatibility fix from `dev/v3/v3.0` to `alpha/v3/v3.0`\n- preserve the alpha release line version state while regenerating the Buildchain contract\n- unblock stable-consumer self-dogfood when the alpha workflow targets a stable runtime without the sealing helper\n\n## Validation\n\n- `TMPDIR=/private/tmp pnpm check`\n- `git diff --check`\n\n## Source\n\n- dev merge: `12414d5b61c1b9554665e7e3cdff12ea167bb1fc`\n- fix PR: #2007\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T14:31:02Z",
          "mergedAt": "2026-07-28T14:34:35Z",
          "additions": 57,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2009,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2009",
          "title": "fix(workflow): inherit reusable build permissions",
          "body": "## Summary\n\n- let the reusable build workflow inherit the caller's explicit token permissions\n- preserve OIDC on the channel wrapper that needs S3 artifact relay\n- update the generated public contract and generator boundary\n\n## Validation\n\n- `pnpm run check` (674 tests passed; workflow/site/inventory checks and action builds passed)\n- `actionlint -verbose .github/workflows/.build.yml`\n\n## Live regression\n\nGitHub run `kungfu-systems/kungfu#30367692905` failed at workflow startup because the least-privilege CodeBuild qualification caller could not elevate to the reusable workflow's unconditional OIDC permission. This change keeps OIDC caller-owned and allows credential-free CodeBuild qualification.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T14:33:33Z",
          "mergedAt": "2026-07-28T14:36:28Z",
          "additions": 7,
          "deletions": 13,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2010,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2010",
          "title": "Prepare v3.0.2-alpha.9",
          "body": "Create the generated version-state commit for v3.0.2-alpha.9.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: b609f2cf8e7ab3e98685c434add4913d5220f509 -> 285e955c80b8d411d11eac7aba204ab835942716\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T14:39:57Z",
          "mergedAt": "2026-07-28T14:43:54Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 227,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/227",
          "title": "Release production from be9198f2b0f9",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `be9198f2b0f9dee2a4bee5f051b015a4f48f6af7`\n- Artifact hash: `55452b277769f71412a16fb49aa60bdb6a16b0b9909e9da8d782f17a9b11c6aa`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/30368863465)\n- Required label: `buildchain-release`\n- Release branch: `release/production-be9198f2b0f9`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-28T14:46:58Z",
          "mergedAt": "2026-07-28T15:03:48Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1744,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1744",
          "title": "feat(kfx): cut over to identity-neutral authority",
          "body": "## Summary\n\nRemove every first-party, System, Product System, fixed-name, bundled-path, and installer-origin authority shortcut from KFX admission and execution.\n\nKFD conformance remains eligibility evidence only. Executable authority now requires the exact Release Passport, Core policy, Work/Warrant settlement, explicit least-authority capability grant, and runtime isolation roots. Product System is inert assembly, distribution, default-install, update-channel, and presentation metadata only.\n\nThis is the identity-neutral authority cutover after #1728. It does not settle the later Agent Work Lab recursive dogfood or the sole identity-neutral terminal qualification, and it does not close parent #1624.\n\n## Related issue\n\nFollow-up to #1624, #1718, and #1728.\n\n## Changes\n\n- replace the KFX contract with closed-world v3 identity-neutral manifest, dependency, product-role, capability, and bootstrap-TCB authority\n- delete first-party manifests, schemas, generators, baked tests, and runtime storage flags\n- require explicit capability declarations on every executable KFX facet and exact capability grants at every host boundary\n- bind native, Python, Node, GUI, TUI, Control API, service, adapter, and session-window launch to exact Passport/policy/Work/Warrant/grant/isolation roots\n- keep Product System roles inert and reject all origin-, name-, path-, signer-, sibling-, replay-, and post-plan-mutation authority\n- enumerate and test the minimal Core bootstrap, LKG, safe-mode, and owner-authorized emergency-removal TCB\n- add a reverse authority scan across 15 host/control edges and 21 shipped manifests\n- publish portable-format alpha.2 as the explicit identity-neutral successor\n\n## Verification\n\n- `./shifu build:core`\n- `./shifu build:cli`\n- `./shifu build:app`\n- `./shifu check:types`\n- `./shifu test:native-kfx-admission`\n- `./shifu test:kfx-profile-suite`\n- `./shifu --filter @kungfu-tech/spec generate:check`\n- SDK contract tests: 34/34\n- `./shifu docs validate --json`\n- `./shifu check:portable-format-authority`\n- `./shifu core:affected`\n- `./shifu check` (`changed-scope gate passed`)\n- repository pre-commit staged gate (`staged gate passed`)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-7ef4-b28b-ee1fbaf9e62e\",\n    \"KF-ADR-019f86da-4f90-73f3-b027-c343b2bc8bcc\",\n    \"KF-ADR-019f86da-4f90-7d6c-926a-ddd27dbde8ab\",\n    \"KF-ADR-019f86da-4f90-72df-add3-948f3ae38c3a\",\n    \"KF-ADR-019f8c53-6105-71e5-8f34-53f2a81ee61c\"\n  ],\n  \"summary\": \"Remove every identity and origin shortcut so KFX authority comes only from exact Passport, Core policy, Work/Warrant, explicit capability grant, and runtime isolation roots.\",\n  \"verification\": [\n    \"./shifu test:native-kfx-admission\",\n    \"./shifu test:kfx-profile-suite\",\n    \"./shifu check:types\",\n    \"./shifu check\",\n    \"repository pre-commit staged gate\"\n  ]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change consumes exact release and runtime authority evidence but performs no publication or deployment and grants no authority from product identity or origin.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWtmeC1wYXNzcG9ydC1hZ2VudC13b3JrLWxhYi10ZXJtaW5hbC1jdXRvdmVyIiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUta2Z4LWlkZW50aXR5LW5ldXRyYWwtYXV0aG9yaXR5LWN1dG92ZXIiLCJkZWxpdmVyeUNsYXNzIjoibmF0aXZlLXByb29mLXJlcXVpcmVkIiwiZGV2SGVhZCI6IjM5MWUzYTJmOTY4YjVlYzI1NWVjNjc2ODA4YzQ2YmFmNGM1NGIwMTAiLCJwdWxsUmVxdWVzdEhlYWQiOiI3MDhlYTJmMGNiOTYxNDQ4MDYwYmU4MmQyZDc1MDViNTMzOGY4Y2U0IiwicmVwbGF5ZWRDYW5kaWRhdGUiOiI2ZTgxODM2OWMzM2U1NDQwYTJlNzM1ZWU5MmVkZjJmNDQ3YmQyNzM1IiwicmVwbGF5ZWRUcmVlIjoiMWIwNjYzOGRhNzhkMzZiZjBmZTFhNzk4MmM4NjU1MmNiM2I3ZjgyOSIsInF1ZXVlQXR0ZW1wdCI6IjcwOGVhMmYwY2I5NjE0NDgwNjBiZTgyZDJkNzUwNWI1MzM4ZjhjZTRAMzkxZTNhMmY5NjhiNWVjMjU1ZWM2NzY4MDhjNDZiYWY0YzU0YjAxMCIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1Njo0ZWUzOGMzNTM2ODU0NTgxOTliNjRhY2U5NTI2NmMzODM5YTk2ZTFmMGNlYzVlMjZmYzEyZTFkODYzNGQzYTc5IiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6MmVkOTg3NzIwNTljNjBkNGQzMmRmNjQ1ZWY4OGRiZjM0NmIzYmVlNjA4OTlmMzJlMWFhNjdkMGJkN2JkMDYwYiIsInNoYTI1Njo0ZWUzOGMzNTM2ODU0NTgxOTliNjRhY2U5NTI2NmMzODM5YTk2ZTFmMGNlYzVlMjZmYzEyZTFkODYzNGQzYTc5Il0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvNWUyNWU1M2IzODg1NjEwMCIsImxlYXNlUm9vdCI6InNoYTI1Njo4MTk1ZjA4MGQwMjEyYzBiZmExYmQ3NmIwNzYyN2M1NzgyOTU3OTIxNDIyMzBlNjU3YjI5YmQ2MDlkZGY2ODRmIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T12:33:34Z",
          "mergedAt": "2026-07-28T15:04:22Z",
          "additions": 1641,
          "deletions": 3174,
          "changedFiles": 115
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1754,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1754",
          "title": "fix(profile): bind KFD view placement to Core authority",
          "body": "## Summary\n\nBind KFD-3 custom Profile view placement to the Core KFX contract instead of removed member-manifest authority hints, restoring fail-closed release qualification on the identity-neutral KFX base.\n\n## Related issue\n\nAtlas goal: 2026-07-26-kungfu-kfd-support-governance\nAssignment work-definition root: `sha256:2f12129a1391b3241c37ccd94e046870e02932f9a76a90ff4286591fbe787a22`\nSupersedes: #1750, whose exact head was retained and closed after the serialized wrapper detected a conflict with merged #1744.\n\n## Changes\n\n- Derive custom Profile view placement from `nativeRuntime.experienceFlowHost.placements.gui` in the Core KFX contract.\n- Fail closed when Core does not declare the required `sandboxed-ipc` placement.\n- Keep capability-bearing custom views rejected without depending on removed `view.runtime` or `view.system` fields.\n- Add schema regressions proving member manifests cannot reclaim runtime or system authority.\n- Align the Profile composition fixture with the identity-neutral adapter capability contract introduced by #1744.\n- Refresh the generated semantic-amplification projection.\n\n## Verification\n\n- 83 related Python tests passed across Profile SDK, KFX contract, profile composition, and Mission Control Profile.\n- Code complexity budget and semantic-amplification report checks passed.\n- Repository pre-commit staged gate passed, including 50 dev Gate latency contract tests, 17 invariant tests, 112 documentation negative tests, Python format/lint, and Biome.\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix aligns KFD-3 qualification with the already accepted Core KFX authority after member runtime and system hints were removed; it does not change architecture authority or widen KFD support claims.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe qualification repair remains fail-closed and will be accepted for release only through the protected exact-source candidate workflow.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (generated maintainability projection refreshed; no public behavior change)\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI2LWt1bmdmdS1rZmQtc3VwcG9ydC1nb3Zlcm5hbmNlIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiI0ODY0YzI0ODE5ZmE4NzY2OTY2ZDk3ZTFjYmQ5OWZmMTFmNGUzZWY1IiwicHVsbFJlcXVlc3RIZWFkIjoiYzAzOGJmOTg4ODZlNWVhNDMxMzE5MzEyODY4YTRmYzBmNDAzZTE1ZSIsInJlcGxheWVkQ2FuZGlkYXRlIjoiODUxMDBiMWM1Y2YxYmQxZWE0YTk3ZmU3ZDU1ZjYxM2M5Yjk5OGI2NiIsInJlcGxheWVkVHJlZSI6IjVkNWQwZjQ1NjhkYmRiNThlNTU4MDY5ZjEwZWMyNGIxODI0ODFjZGEiLCJxdWV1ZUF0dGVtcHQiOiJjMDM4YmY5ODg4NmU1ZWE0MzEzMTkzMTI4NjhhNGZjMGY0MDNlMTVlQDQ4NjRjMjQ4MTlmYTg3NjY5NjZkOTdlMWNiZDk5ZmYxMWY0ZTNlZjUiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6MDczNjQ0YTU4NmMxMjk2OWMyNTZjODI0YWYwZjNlNzcwYzcyM2NlZTQxM2MxY2UzNmFlZTk5N2E4NTRlOWU4NSIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjA3MzY0NGE1ODZjMTI5NjljMjU2YzgyNGFmMGYzZTc3MGM3MjNjZWU0MTNjMWNlMzZhZWU5OTdhODU0ZTllODUiLCJzaGEyNTY6MmYxMjEyOWExMzkxYjMyNDFjMzdjY2Q5NGUwNDY4NzBlMDI5MzJmOWE3NmE5MGZmNDI4NjU5MWZiZTc4N2EyMiJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6NTZlNDU5MzZhNmVkYjEyNWRmZjgzYWE1ZTI1MGZkMzg3MGZhZTViYzkyNmQzNDY2ZjFhOWJiNDIwOWM5YjEwZCJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T15:10:22Z",
          "mergedAt": "2026-07-28T15:23:43Z",
          "additions": 49,
          "deletions": 13,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 32,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/32",
          "title": "feat(release): govern Hub artifacts with Buildchain",
          "body": "## Summary\n\n- make Buildchain v3 the only non-dry-run release authority\n- publish the multi-platform Hub image and OCI Compose application in one durable transaction\n- retain exact smoke evidence, verified compose-preview promotion, and a Release Passport\n- reduce former manual publish workflows to bounded qualification-only checks\n\n## Verification\n\n- `npm run check` (51 tests)\n- `actionlint .github/workflows/*.yml`\n- `shellcheck scripts/publish-runtime-release.sh scripts/smoke-image.sh scripts/smoke-browser.sh`\n- synthetic publish-evidence contract check\n\n## Boundaries\n\nThis is an alpha release-governance change. It does not change the Course Hub domain model, inference catalog, public ingress posture, or production-readiness claims.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T15:49:07Z",
          "mergedAt": "2026-07-28T15:50:42Z",
          "additions": 809,
          "deletions": 479,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1755,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1755",
          "title": "fix(ci): grant reusable qualification issue scope",
          "body": "## Summary\n\n- Grant only `issues: write` to the maintainer-dispatch CodeBuild qualification caller.\n- Keep OIDC disabled, secrets absent, and publication disabled.\n- Refresh closed-world workflow and release-publication authority roots.\n\n## Verification\n\n- Full staged commit gate passed.\n- `actionlint .github/workflows/aws-us-linux-burst-qualification.yml`\n- 41 focused Buildchain, workflow authority, gate catalog, and publication-control tests passed.\n- Workflow authority and publication root checks passed.\n\n## Live regression\n\nRun `30367692905` failed before job creation because the reusable Buildchain workflow could not elevate caller permissions. Buildchain PR #2009 now leaves token permissions caller-owned; this caller supplies only the issue scope used by Buildchain diagnostics without granting OIDC or publication authority.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Corrects least-privilege CI caller permissions without changing a product or architecture contract\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- Provider integration and release evidence surfaces are touched only for bounded qualification.\n- No static AWS credentials, repository secrets, OIDC, signing, publication, or deployment authority is added.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Generated authority projections are refreshed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI4LWt1bmdmdS1hd3MtdXMtZWxhc3RpYy1ydW5uZXItYnVyc3QtcGxhbmUiLCJkZWxpdmVyeUNsYXNzIjoibm9uLW5hdGl2ZS1mYXN0IiwiZGV2SGVhZCI6IjIwNjYyODNkNmJhNWRmY2ViYWE2ZWRiZWUxZDhmYWYxZTYxOTU3M2EiLCJwdWxsUmVxdWVzdEhlYWQiOiI4ZjY1MDg2NzM0YjMxZjQ3NmI4ZjMwZjc5NjJiOWM1ZDA1MmQ3OTg4IiwicmVwbGF5ZWRDYW5kaWRhdGUiOiJiMDNmNjQ4YTk0ZWMxNTA1ZDc1YzQzNGZmZTA5ZTQ2YWI5NDEwOGEyIiwicmVwbGF5ZWRUcmVlIjoiOTA1ZjU1MzdiZGVkY2FiMjI4YjUwMzhhMzA5NDBjNjRkOWYwYzlkNyIsInF1ZXVlQXR0ZW1wdCI6IjhmNjUwODY3MzRiMzFmNDc2YjhmMzBmNzk2MmI5YzVkMDUyZDc5ODhAMjA2NjI4M2Q2YmE1ZGZjZWJhYTZlZGJlZTFkOGZhZjFlNjE5NTczYSIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1Njo4NGM1NmI3ZDVjZTk4Y2Q1NWMzMTEyOThjYmRmZTQ3YThjZGI0NzFjMWJkMTIwYjg4MjBjMmZmZDI5ZTgzNTc2IiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6NWNkMjJhZDgxYTdhNzc4ZjJlNWJmYWYyOWNlZTk1YjVhZTc5YjgyNDA0ZmRkZDNlYjBiNWUxYTg4MGFjZjJlZCIsInNoYTI1Njo4NGM1NmI3ZDVjZTk4Y2Q1NWMzMTEyOThjYmRmZTQ3YThjZGI0NzFjMWJkMTIwYjg4MjBjMmZmZDI5ZTgzNTc2Il0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZDk5ZjNhOTE2NjczOWUwZCIsImxlYXNlUm9vdCI6InNoYTI1NjplZGZmMjM1YmM1Zjg2ZmY4ZWZlN2MzN2JlMzMzZTE5ZjEyMjZiYTc2NjE3MWVmOGU3MjY2OTE5MzQ2NDFiNzJiIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T15:19:56Z",
          "mergedAt": "2026-07-28T15:51:12Z",
          "additions": 6,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 35,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/35",
          "title": "fix(ci): admit generated PR merge commits",
          "body": "## Summary\n\nAllow the DCO check to recognize GitHub `web-flow` merge commits with multiple parents and a canonical `Merge pull request` subject. All ordinary constituent commits remain individually checked for a DCO signoff.\n\n## Reason\n\nWithout this bounded case, a signed development change cannot propagate from a merged development PR into the protected alpha channel because GitHub itself creates the unsigned merge commit.\n\nSupersedes #34, which was closed without merge because its author/reviewer identities were reversed.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T15:56:53Z",
          "mergedAt": "2026-07-28T15:57:31Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1759,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1759",
          "title": "fix(ci): join required contexts across workflows",
          "body": "## Summary\n\nCorrect dev Gate latency evidence when required merge-queue contexts complete in separate workflows for the same merge-group source.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Collect repository-wide merge-group workflow runs instead of only Core affected-native runs.\n- Join required contexts across exact-source workflow runs.\n- Count repeated validation per workflow identity, so one lease run plus one Core run is not reported as duplicate work.\n- Add regression coverage for split source/native required contexts.\n\n## Verification\n\n- `./shifu test:gate-latency` (85 passed)\n- `node --test scripts/readonly-agent-bootstrap.test.mjs` with the workflow-pinned source tool bootstrap (1 passed)\n- Live latency-only replay for PRs #1739 and #1743 joined both exact-source workflow runs and reported zero repeated validation.\n- Staged repository gate passed during commit.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix corrects CI evidence aggregation without changing an architecture or release contract\"\n}\n-->\n\n## [Evolution Map](../docs/evolution/README.md) impact\n\nEvolution impact: none\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe measurement collector reads repository-wide GitHub Actions merge-group runs using the same authenticated read-only API surface already used by this tool. The live replay above verifies exact-source correlation across workflows.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTE3LWt1bmdmdS1kZXYtZ2F0ZS1sYXRlbmN5LXNsbyIsImRlbGl2ZXJ5Q2xhc3MiOiJub24tbmF0aXZlLWZhc3QiLCJkZXZIZWFkIjoiYzE1YzJiNGJiMWE3YTI0MWU1NDI1Yjk5Y2IwNjk2Mzc4NWQ4NjE2NCIsInB1bGxSZXF1ZXN0SGVhZCI6IjMyNGFlMzk0OGNmZGZkMTEzZTA3MGM4OWNjYTQ3NDAyOTQ0ZjI3OWIiLCJyZXBsYXllZENhbmRpZGF0ZSI6ImE2ZjM2OTZhMDhkOWNiYjk2NjZhYzIxMTE3NDEzYWQ4OGNjODdjZTUiLCJyZXBsYXllZFRyZWUiOiI4OTgyY2QyMDZhOTA3N2VkYTAyYTM1ZmVlZGE4ZTQ2ZGU1Y2MxOTc5IiwicXVldWVBdHRlbXB0IjoiMzI0YWUzOTQ4Y2ZkZmQxMTNlMDcwYzg5Y2NhNDc0MDI5NDRmMjc5YkBjMTVjMmI0YmIxYTdhMjQxZTU0MjViOTljYjA2OTYzNzg1ZDg2MTY0IiwiYWRtaXNzaW9uUHJvb2ZSb290Ijoic2hhMjU2OjllYTJkNjk4NWFlNTBiYjMxNDEwY2E5Y2Y0MWQ0Y2IwMDZiZTZiZjJmOGNkYzUwYzk2ODE5MDk5MWVkODIwZjgiLCJhZG1pc3Npb25Qcm9vZlJvb3RzIjpbInNoYTI1Njo5ZWEyZDY5ODVhZTUwYmIzMTQxMGNhOWNmNDFkNGNiMDA2YmU2YmYyZjhjZGM1MGM5NjgxOTA5OTFlZDgyMGY4Iiwic2hhMjU2OmNlNzQyNmU1NjkxYjA5NzhjYmVmN2E1Y2MyNGE2OTZkMGIxZjk4MDE4MTc5OWI0YTYyYTBmYWNiMGY1ZmYwNDAiXSwic3RhdHVzQ29udGV4dCI6IlF1ZXVlIGZhbWlseSBsZWFzZS9kOTlmM2E5MTY2NzM5ZTBkIiwibGVhc2VSb290Ijoic2hhMjU2OjBlZGFiMDA3YjRmOWVmNjE5Y2NhZjEyNWFkNWZkNzQ1YzdkN2UxY2MxMjIzOWNjZWUyMmQ0NzBmZDk2YTlhNDYifQ -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T15:37:42Z",
          "mergedAt": "2026-07-28T15:58:26Z",
          "additions": 59,
          "deletions": 41,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 33,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/33",
          "title": "chore(release): publish Hub Starter v0.2 alpha",
          "body": "## Release intent\n\nPromote the reviewed Buildchain-governed Course Hub release surface from `dev/v0/v0.2` into the protected `alpha/v0/v0.2` channel.\n\nAfter this PR passes Verify and is independently merged, Buildchain v3 selects the exact prerelease version, publishes the required multi-platform image and OCI Compose application in one durable transaction, verifies both artifacts, moves `compose-preview` only after exact fresh-install smoke and evidence generation, and creates the GitHub prerelease plus Release Passport.\n\nManual workflow dispatch remains dry-run only and cannot perform this publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T15:53:17Z",
          "mergedAt": "2026-07-28T15:59:14Z",
          "additions": 818,
          "deletions": 479,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 36,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/36",
          "title": "fix(release): align the governed v1.0 alpha line",
          "body": "## Summary\n\n- align the release impact ledger and promotion default with Buildchain v3's supported `vN.N` contract\n- keep ordinary commits under DCO while allowing GitHub-generated web-flow merge commits to propagate between protected lines\n\n## Evidence\n\nThe first `v0.2` promotion attempt failed before any registry or ref mutation with `alpha publication requires a vN.N release line; got v0.2`. This change uses the repository's original `dev/v1/v1.0` line and prepares `alpha/v1/v1.0`.\n\n- `npm run check` (51 tests)\n- `actionlint .github/workflows/*.yml`\n- `shellcheck scripts/publish-runtime-release.sh scripts/smoke-image.sh scripts/smoke-browser.sh`",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:01:32Z",
          "mergedAt": "2026-07-28T16:02:17Z",
          "additions": 20,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 37,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/37",
          "title": "chore(release): publish Hub Starter v1.0 alpha",
          "body": "## Release intent\n\nPromote the reviewed Buildchain-governed Course Hub release surface from `dev/v1/v1.0` into the protected `alpha/v1/v1.0` channel.\n\nThe earlier `v0.2` attempt failed before mutation because Buildchain requires a `vN.N` product line. This corrected channel matches the repository's original v1.0 development train.\n\nAfter Verify and independent merge, Buildchain v3 will select the exact alpha version, publish the required multi-platform image and OCI Compose application in one durable transaction, run exact artifact smoke, move `compose-preview` only after complete evidence, and create the prerelease plus Release Passport.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:03:06Z",
          "mergedAt": "2026-07-28T16:03:38Z",
          "additions": 20,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 38,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/38",
          "title": "fix(release): smoke exact platform manifests",
          "body": "## Summary\n\nResolve linux/amd64 and linux/arm64 child-manifest digests from the published OCI index, then inspect and smoke those exact coordinates independently.\n\n## Failure evidence\n\nBuildchain run 30376453551 published the exact multi-platform image and passed the amd64 full smoke, then stopped in `publish_failed` before Compose, preview, tags, or GitHub Release because Docker classic store refused to overwrite one manifest-list digest with the arm64 selection.\n\nThe transaction remains fail-closed and the next alpha slot will use the corrected adapter.\n\n## Verification\n\n- `npm run check` (51 tests)\n- `bash -n` and `shellcheck` on the publish lifecycle\n- `actionlint` on all workflows",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:11:08Z",
          "mergedAt": "2026-07-28T16:11:49Z",
          "additions": 27,
          "deletions": 13,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 39,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/39",
          "title": "chore(release): resume Hub Starter v1.0 alpha",
          "body": "## Release intent\n\nResume the Buildchain-owned v1.0 alpha after correcting platform smoke to use exact child-manifest digests.\n\nThe previous transaction is durably `publish_failed`: it produced only the exact versioned multi-platform image and passed amd64 smoke. It did not publish the Compose application, move `compose-preview`, finalize refs, or create a GitHub Release. Buildchain will reserve that failed slot and select the next exact prerelease for this reviewed source.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:12:09Z",
          "mergedAt": "2026-07-28T16:12:41Z",
          "additions": 27,
          "deletions": 13,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2012,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2012",
          "title": "fix(workflow): bound burst lifecycle jobs",
          "body": "## Summary\n- expose `lifecycle-timeout-minutes` on the reusable build and channel router contracts\n- apply the caller bound to native/container jobs and every lifecycle stage\n- enforce the fallback inside `run-lifecycle`, preserve stage-specific overrides, and report clear timeout evidence\n- regenerate bundled actions/public contract projections and add regression coverage\n\n## Why\nThe trusted AWS CodeBuild burst qualification caller already supplies a 105-minute lifecycle budget. The dedicated train rejected the call because the reusable workflow and lifecycle action did not expose the complete timeout contract, so no cloud build was started.\n\n## Validation\n- `node --test tests/aws-runner-burst.test.mjs`\n- focused command/configured-stage timeout test\n- `node scripts/generate-channel-build-workflow.mjs --check`\n- `bash scripts/check-workflows.sh`\n- `pnpm run check` (676 tests passed)",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:04:42Z",
          "mergedAt": "2026-07-28T16:14:30Z",
          "additions": 278,
          "deletions": 100,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1748,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1748",
          "title": "fix(kfx): close Alpha qualification authority drift",
          "body": "## Summary\n\nClose the exact authority drift exposed by Alpha candidate qualification and make future candidate PRs carry their repository-owned ADR settlement at creation time.\n\nThe authoritative KFX manifest contract no longer permits packages to self-declare runtime placement or system authority. This repair aligns the Python Profile audit and TypeScript projection with that contract: host policy supplies GUI confinement, source authority supplies the integrated trust verdict, and the boot-critical product role preserves recovery navigation without granting runtime authority.\n\n## Related issue\n\nAtlas goal: 2026-07-24-buildchain-linux-github-attestation\n\n## Changes\n\n- pass one bounded repository-owned PR body prefix into the merged Buildchain candidate patrol workflow\n- create Alpha candidate PRs with exactly one ADR settlement manifest\n- derive Profile custom-view placement from the native KFX host policy rather than removed manifest fields\n- remove stale TypeScript runtime and system manifest projections\n- derive non-disableable recovery navigation from the non-authorizing boot-critical product role\n- update focused Python and Node regression coverage and the public KFX architecture guide\n\n## Verification\n\n- repository pre-commit staged gate: passed, including 112/112 documentation and promotion rehearsals\n- node --test scripts/dev-alpha-candidate-patrol.test.mjs: 3/3 passed\n- ./shifu check:gate-catalog: 38 gates, 6 profiles, 27 structured invocations, 28 workflows aligned\n- ./shifu test:kfx-profile-suite: passed\n- ./shifu exec pnpm --filter @kungfu-tech/kfx build: passed\n- focused Profile facet authority smoke: passed\n- Ruff format/lint and Biome staged checks: passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This repair aligns stale language projections and candidate admission plumbing with already accepted runtime and release authority; it does not change an accepted architecture decision.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe candidate body prefix is bounded and rejects managed-controller marker injection in Buildchain. Runtime placement remains fail-closed and cannot be authored by a package manifest.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated where behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI0LWJ1aWxkY2hhaW4tbGludXgtZ2l0aHViLWF0dGVzdGF0aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJiYTAzOGQxNzYyMGE4ZTFkMWFlNTRkZDc4ZWQxYWY3NDhlYTVhODQ5IiwicHVsbFJlcXVlc3RIZWFkIjoiZWMxNDcyY2FlNDU0MGUyYmIzYjllM2JjMDc5MmNiNGUwNDJkMDRkMSIsInJlcGxheWVkQ2FuZGlkYXRlIjoiNDhkZTg1NjlmZGQ2Zjk2MTVhMjQ4NTcwNzY1YTdlZTU3OWI2NDJkMyIsInJlcGxheWVkVHJlZSI6ImFmZGZkNjRlNDUwYzczMTY3NjNiMzA2NDkxM2JkMGM5NWU5ZDQ0YjEiLCJxdWV1ZUF0dGVtcHQiOiJlYzE0NzJjYWU0NTQwZTJiYjNiOWUzYmMwNzkyY2I0ZTA0MmQwNGQxQGJhMDM4ZDE3NjIwYThlMWQxYWU1NGRkNzhlZDFhZjc0OGVhNWE4NDkiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6OTQyMmExYjJlOWQ4OGRlMWFjZWQ2ZjliY2IxMGYzZWY0N2RmNGQ5NjZmN2I2OGQzZWQ5ZmI1MTNhMjliZDk1MCIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjM5NTJhNzBlNDkzMzM2Njg5ZTk4NTVjZjgzMjU3NDIzYjQxMTg3NWFhYzJhMWRiYjNmMjQ0MDliMTQ3NDIyYWUiLCJzaGEyNTY6OTQyMmExYjJlOWQ4OGRlMWFjZWQ2ZjliY2IxMGYzZWY0N2RmNGQ5NjZmN2I2OGQzZWQ5ZmI1MTNhMjliZDk1MCJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6NjVjZTQ0M2E2NWY0M2VmMWJmOGQ1OTRiNzc0NzIxNDc0NWU1ZDJlZTUyN2JkOGMxNDU2NGVhZTIzYTRjYzU4NyJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T14:22:32Z",
          "mergedAt": "2026-07-28T16:18:49Z",
          "additions": 31,
          "deletions": 10,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 40,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/40",
          "title": "fix(release): bound arm64 QEMU qualification",
          "body": "## Summary\n\n- retain the full PostgreSQL, account-isolation, Course Hub, Kungfu settlement, restart, and security smoke on linux/amd64\n- qualify the exact linux/arm64 child manifest under QEMU with Node architecture execution, `kungfu agent verify --json`, and non-root/read-only/no-capability constraints\n\n## Failure evidence\n\nBuildchain run 30377191893 published the exact alpha.1 multi-platform image, verified both child labels, and passed the amd64 full smoke. The arm64 full business smoke then exceeded five minutes under QEMU and ended in a headers timeout. Compose, preview, refs, and GitHub Release remained untouched.\n\nThe bounded arm64 contract proves executable architecture and shipped Kungfu interface without making emulator throughput release authority.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:24:38Z",
          "mergedAt": "2026-07-28T16:27:02Z",
          "additions": 52,
          "deletions": 18,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 41,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/41",
          "title": "release: promote v1.0 alpha candidate",
          "body": "## Summary\n\nPromote the latest Buildchain-managed runtime-images candidate to the protected v1.0 alpha line.\n\n## Qualification\n\n- exact platform child manifests are recorded\n- amd64 full Hub Starter smoke remains required\n- arm64 QEMU qualification is bounded and verifies architecture, Kungfu agent availability, and hardened runtime constraints\n- Compose preview advances only after all required release evidence passes\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:27:16Z",
          "mergedAt": "2026-07-28T16:27:43Z",
          "additions": 52,
          "deletions": 18,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 43,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/43",
          "title": "fix(release): tolerate OCI application propagation",
          "body": "## Summary\n\n- retry exact OCI Compose config resolution for up to 55 seconds after publication\n- preserve fail-closed exact application validation and preview promotion ordering\n- retain the retry contract in repository verification\n\nThe alpha.2 transaction published the exact multi-architecture image and exact Compose application, then encountered GHCR eventual consistency while resolving the just-published OCI application. The preview alias and Buildchain release transaction were not committed.\n\n## Verification\n\n- `bash -n scripts/publish-runtime-release.sh`\n- `npm run check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:36:55Z",
          "mergedAt": "2026-07-28T16:37:23Z",
          "additions": 28,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 44,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/44",
          "title": "release: promote v1.0 alpha candidate",
          "body": "## Summary\n\nPromote the Buildchain-managed runtime-images candidate with bounded GHCR OCI application propagation handling to the protected v1.0 alpha line.\n\n## Qualification\n\n- exact multi-architecture Hub image and Compose application\n- full amd64 business, PostgreSQL, Kungfu, restart, and security smoke\n- bounded arm64 QEMU architecture, Kungfu CLI, and hardening qualification\n- preview alias advances only after exact application installation passes\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:37:53Z",
          "mergedAt": "2026-07-28T16:38:21Z",
          "additions": 28,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1767,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1767",
          "title": "fix(ci): disable local checkout cache for CodeBuild",
          "body": "## Summary\n\n- Set the AWS CodeBuild qualification checkout cache mode to `off`.\n- Fetch the locked Buildchain runtime and consumer source directly from GitHub on the cloud runner.\n- Add a regression assertion and refresh workflow/publication authority roots from current dev.\n\n## Verification\n\n- `node --test scripts/buildchain-install.test.mjs` (7/7)\n- `./shifu check:source` (build-free source gate passed)\n- Full staged commit gate passed on current `dev/v4/v4.0`.\n\n## Live regression\n\nRun `30377374760` proved the v4 CodeConnections webhook and CodeBuild runner path, then failed because `checkout-cache-mode: github` is outside the current `off / auto / require` contract. `off` is intentional for the cloud runner so it does not attempt the office-only `192.168.100.222` mirror before the exact GitHub fetch.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Corrects a bounded CI configuration value without changing product or architecture contracts\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- No credentials, OIDC, signing, publication, or deployment authority is added.\n- Exact-source trust gates and the dedicated reviewed Buildchain train remain unchanged.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Generated authority projections are refreshed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI4LWt1bmdmdS1hd3MtdXMtZWxhc3RpYy1ydW5uZXItYnVyc3QtcGxhbmUiLCJkZWxpdmVyeUNsYXNzIjoibm9uLW5hdGl2ZS1mYXN0IiwiZGV2SGVhZCI6ImI4YmQyZDgxMTk1NGRlZWI3MTU0NjQ0OWFkOTJiZjczNTEyYzAxMTMiLCJwdWxsUmVxdWVzdEhlYWQiOiI0NmM5YTcwOTIzZTZlNmQ1MTk3NzNmMzQyZTExNTQ0MTBlM2E2N2ZlIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiIwNzJkNzE4ZGJhYjQ1ZjMzNTdlMWFiNmNkYTkyYTRhMDQ0NTAyOGFiIiwicmVwbGF5ZWRUcmVlIjoiOWZkOTQyOTU0NzAxYzQwNjI2ZTI3MDA4N2MxZDQzNzFhZTAwYTVjOCIsInF1ZXVlQXR0ZW1wdCI6IjQ2YzlhNzA5MjNlNmU2ZDUxOTc3M2YzNDJlMTE1NDQxMGUzYTY3ZmVAYjhiZDJkODExOTU0ZGVlYjcxNTQ2NDQ5YWQ5MmJmNzM1MTJjMDExMyIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjphZDJiZjc3MGM1NWZkNDVlMjM2YzA4ZWVmZGU3OWFkN2E4MTk5NTE4ZDMzOGU2N2E1MDQxY2M0YmQwOWM5NDE3IiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6NWNkMjJhZDgxYTdhNzc4ZjJlNWJmYWYyOWNlZTk1YjVhZTc5YjgyNDA0ZmRkZDNlYjBiNWUxYTg4MGFjZjJlZCIsInNoYTI1NjphZDJiZjc3MGM1NWZkNDVlMjM2YzA4ZWVmZGU3OWFkN2E4MTk5NTE4ZDMzOGU2N2E1MDQxY2M0YmQwOWM5NDE3Il0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZDk5ZjNhOTE2NjczOWUwZCIsImxlYXNlUm9vdCI6InNoYTI1NjoxNzI1YWI2Y2MxZmZhZGQzZmI0YjQ1ZGNmOGU1OWZiMDc2NThlNmJjZmJlYWViYWNlZTk1OTZjNDY4ZWY1OWFiIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:31:22Z",
          "mergedAt": "2026-07-28T16:44:18Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 46,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/46",
          "title": "fix(release): validate propagated Compose config",
          "body": "## Summary\n\n- treat an empty or incomplete OCI Compose projection as unavailable even when Docker Compose incorrectly exits zero\n- retry until the exact image digest and localhost binding are present\n- preserve the 12-attempt bound and fail-closed publication order\n\nThe alpha.3 transaction showed Docker Compose logging a GHCR 404 while returning success with an empty config. The exact image and Compose application were published, but preview and Buildchain release state were not committed.\n\n## Verification\n\n- `bash -n scripts/publish-runtime-release.sh`\n- `npm run check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:46:51Z",
          "mergedAt": "2026-07-28T16:47:25Z",
          "additions": 4,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 47,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/47",
          "title": "release: promote v1.0 alpha candidate",
          "body": "## Summary\n\nPromote the Buildchain-managed runtime-images candidate with semantic OCI Compose propagation validation to the protected v1.0 alpha line.\n\n## Qualification\n\n- exact multi-architecture Hub image and Compose application\n- full amd64 business, PostgreSQL, Kungfu, restart, and security smoke\n- bounded arm64 QEMU architecture, Kungfu CLI, and hardening qualification\n- preview alias advances only after the exact application config and fresh installation pass\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:47:38Z",
          "mergedAt": "2026-07-28T16:48:31Z",
          "additions": 4,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1763,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1763",
          "title": "feat(work): admit post-merge delivery evidence",
          "body": "## Summary\n\nAdmit exact GitHub post-merge and Buildchain delivery evidence into native Kungfu Fact and Episode state with strict coordinate verification, idempotency, retry visibility, and raw-payload rejection.\n\n## Changes\n\n- add the versioned delivery-evidence verifier and native admission adapter\n- retain machine-visible failure, retry, lag, error-root, Episode-root, and downstream-publication state\n- document the GitHub / Buildchain / Kungfu authority boundary\n- bind the delivered slice into the accepted Fact-admission ADR projection\n\n## Verification\n\n- `./shifu test:delivery-evidence` (13 passed)\n- `./shifu check`\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7d81-90a0-d144fc27fe03\"],\n  \"summary\": \"Add a bounded native post-merge delivery-evidence admission stage without changing Fact, Episode, GitHub, or Buildchain authority.\",\n  \"verification\": [\"13 deterministic delivery-evidence tests\", \"changed-scope gate\", \"build-free source gate\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe adapter stores only exact content roots and sanitized coordinates; unknown raw payload fields fail closed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWdvLWZhbWlseS1jb250aW51b3VzLWRlbGl2ZXJ5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtZ28tZmFtaWx5LXBvc3QtbWVyZ2UtZXZpZGVuY2UtaW5nZXN0aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiI4NTVlMzNjZmQ5MGNkMGMxMDJlMmI3ZTQ5NWVhZTMwMTA1OTY0N2QwIiwicHVsbFJlcXVlc3RIZWFkIjoiYTE2NTUzNTUzZjlhNjdmZWQ0N2M1ZTgxZmY3Mjc4YTI4NTIwNTU5YyIsInJlcGxheWVkQ2FuZGlkYXRlIjoiY2UxMWUyOGNhMDY4YTkyNzhkY2JmMTdmZDYzNTJmMzBhY2UyOGMzMiIsInJlcGxheWVkVHJlZSI6IjVhOTBhYzIyZWY3NGZmNjYyY2ViYjdkMDY2NjhjMmU3OGUzYzBiNmYiLCJxdWV1ZUF0dGVtcHQiOiJhMTY1NTM1NTNmOWE2N2ZlZDQ3YzVlODFmZjcyNzhhMjg1MjA1NTljQDg1NWUzM2NmZDkwY2QwYzEwMmUyYjdlNDk1ZWFlMzAxMDU5NjQ3ZDAiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6MmUyMzdhNGIyNjZiOTkyMTdkYTFjMGFiMzMzZGFmOTJiY2YyYTlmNmM0MTU3OTBmNTQzYmRkNDI2ZTk4ODhhZCIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjJlMjM3YTRiMjY2Yjk5MjE3ZGExYzBhYjMzM2RhZjkyYmNmMmE5ZjZjNDE1NzkwZjU0M2JkZDQyNmU5ODg4YWQiLCJzaGEyNTY6NTk1MTFiYzEzYzQ1M2Q3ZjNkZjU2ZDc4YmRkOTUxYWE1ZDMxZmU3NmU4OTJiNGIxZGM4MDgzMzg3NzQ2YjI5OCJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2VjYWM2N2JjZWJmYWUzYmYiLCJsZWFzZVJvb3QiOiJzaGEyNTY6MTQ1ZGE1ZWJjMTRlNTk0NTc3OTFmNTdmOTc3ZDQ1NjI1MzIxMTFiZjhhN2I5ZmUwMmEzM2YwY2NjOTRjMjFmNCJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:14:46Z",
          "mergedAt": "2026-07-28T16:51:56Z",
          "additions": 1018,
          "deletions": 8,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1768,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1768",
          "title": "fix(rewind): bind adapter launch to exact package root",
          "body": "Atlas goal 2026-07-26-kungfu-kfd-support-governance. Fixes #1761 by binding qualification-only LangChain adapter injection to the exact package closure while keeping product execution fail-closed without explicit Core authority.\n\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix restores the qualification fixture under the already accepted exact-root Core host authority and closes a same-key package-root borrowing gap; it does not widen product adapter execution authority or change architecture authority.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI2LWt1bmdmdS1rZmQtc3VwcG9ydC1nb3Zlcm5hbmNlIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiI5MDRjM2M5YzFhNmMzNjAwZDQ0N2YwNDM4NzZiZWY0YTRiN2MxN2RmIiwicHVsbFJlcXVlc3RIZWFkIjoiNDVkZTJmZGFjNDc5NTE3ZDU5YTc1Zjk1YjU1NGM1NDc2YjBhNDY4MiIsInJlcGxheWVkQ2FuZGlkYXRlIjoiMjdlMTMzYTk5N2E1ZjBmNjg0YTliNGE1YjJlOTFlYmU1NDhhYzc2YyIsInJlcGxheWVkVHJlZSI6ImE0MmE1MTYyODcwOWY4MjcxMDlhYmU0OGMzMzJjMDc1ZDI0M2VhYTEiLCJxdWV1ZUF0dGVtcHQiOiI0NWRlMmZkYWM0Nzk1MTdkNTlhNzVmOTViNTU0YzU0NzZiMGE0NjgyQDkwNGMzYzljMWE2YzM2MDBkNDQ3ZjA0Mzg3NmJlZjRhNGI3YzE3ZGYiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6ZTU5MzY3ZjBkN2YwN2IzYzA4ZDk0YmMwNjk3NmU5NzAzMDFmMjhmNWYwNmIzMjQ0MjFjZjU3ZDMyNTM0NjhlYSIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjJmMTIxMjlhMTM5MWIzMjQxYzM3Y2NkOTRlMDQ2ODcwZTAyOTMyZjlhNzZhOTBmZjQyODY1OTFmYmU3ODdhMjIiLCJzaGEyNTY6ZTU5MzY3ZjBkN2YwN2IzYzA4ZDk0YmMwNjk3NmU5NzAzMDFmMjhmNWYwNmIzMjQ0MjFjZjU3ZDMyNTM0NjhlYSJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6ZjhiZmU2ZDhjMTY0MTUxZWY4NDljMTQ4ZGJmMTZhNWI0ODJmNTg5YzU0M2Q1YTEyNWFhNTI1MDVkZmM3ZmEwYiJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:39:52Z",
          "mergedAt": "2026-07-28T17:01:05Z",
          "additions": 191,
          "deletions": 10,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2013,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2013",
          "title": "fix(runners): provision CodeBuild native toolchain",
          "body": "## Summary\n\n- provision namespaced GCC 14 on ephemeral Amazon Linux 2023 CodeBuild jobs\n- fetch pinned CMake 3.31.6 and verify its reviewed SHA256 before use\n- retain resolved toolchain evidence beside AWS runner provenance\n\n## Validation\n\n- `pnpm run check` (677 tests passed; workflow, site, and action bundle checks passed)\n- `node --test tests/aws-runner-burst.test.mjs` (9 passed)\n\nADR impact: none. This completes the existing AWS CodeBuild runner provider contract without changing release or publication authority.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:57:33Z",
          "mergedAt": "2026-07-28T17:01:21Z",
          "additions": 256,
          "deletions": 15,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 48,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/48",
          "title": "fix(release): accept verified platform manifests",
          "body": "## Summary\n\n- accept the exact multi-architecture image index or either verified platform child in resolved OCI Compose config\n- keep the child-to-index relationship fail-closed through the existing unique platform-manifest checks\n- preserve localhost and private PostgreSQL validation before installation and preview promotion\n\nDocker Compose resolves the multi-architecture image index to the current host platform child when rendering the published OCI application. The alpha.4 logs returned complete valid config with the verified amd64 child, while the release check incorrectly required only the parent index digest.\n\n## Verification\n\n- `bash -n scripts/publish-runtime-release.sh`\n- `npm run check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T17:03:35Z",
          "mergedAt": "2026-07-28T17:04:15Z",
          "additions": 17,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 49,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/49",
          "title": "release: promote v1.0 alpha candidate",
          "body": "## Summary\n\nPromote the Buildchain-managed runtime-images candidate with exact parent-or-verified-platform Compose resolution to the protected v1.0 alpha line.\n\n## Qualification\n\n- exact multi-architecture Hub image and Compose application\n- full amd64 business, PostgreSQL, Kungfu, restart, and security smoke\n- bounded arm64 QEMU architecture, Kungfu CLI, and hardening qualification\n- resolved application images must be the exact index or one of its uniquely verified platform children\n- preview advances only after fresh installation passes\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T17:04:28Z",
          "mergedAt": "2026-07-28T17:05:18Z",
          "additions": 17,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 50,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/50",
          "title": "fix(release): render exact Compose application",
          "body": "## Summary\n\n- render the release Compose source with the exact Buildchain image digest before publication\n- validate the rendered source before creating the OCI application\n- preserve the post-publish exact-image and localhost checks\n\n## Verification\n\n- `bash -n scripts/publish-runtime-release.sh`\n- `npm run check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T17:16:58Z",
          "mergedAt": "2026-07-28T17:17:45Z",
          "additions": 8,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 51,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/51",
          "title": "chore(release): promote runtime-images alpha",
          "body": "Promote the fully qualified Buildchain-managed runtime delivery line to alpha.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T17:18:06Z",
          "mergedAt": "2026-07-28T17:18:46Z",
          "additions": 8,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 52,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/52",
          "title": "fix(release): preserve Compose port override",
          "body": "## Summary\n\n- pin only the Hub image coordinate in the temporary OCI Compose publication source\n- preserve `HUB_PORT` interpolation for fresh installs and isolated qualification\n- validate both the raw publication source and its resolved default config\n\n## Verification\n\n- `bash -n scripts/publish-runtime-release.sh`\n- `npm run check`\n- rendered-source check with `HUB_PORT=18083`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T17:29:58Z",
          "mergedAt": "2026-07-28T17:30:43Z",
          "additions": 16,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 53,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/53",
          "title": "chore(release): promote runtime-images alpha",
          "body": "Promote the qualified Buildchain-managed runtime delivery line to alpha.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-28T17:30:52Z",
          "mergedAt": "2026-07-28T17:31:20Z",
          "additions": 16,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1770,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1770",
          "title": "fix(ci): bind latency cohort activation",
          "body": "## Summary\n\nBind prospective dev-gate SLO measurements to an explicit first-enqueue activation boundary so newly visible historical workflow contexts cannot be relabeled as post-activation evidence.\n\n## Related issue\n\nAtlas Assignment `2026-07-17-kungfu-dev-gate-latency-slo`.\n\n## Changes\n\n- add a fail-closed `--cohort-start` RFC3339 CLI argument\n- exclude required and delivery samples whose first authoritative queue admission predates the boundary\n- retain excluded observations with the `before-cohort-start` reason\n- expose the boundary and filtered delivery sample set in the report\n\n## Verification\n\n- `./shifu test:gate-latency` (87/87)\n- staged source gate passed during commit\n- live replay with `--cohort-start 2026-07-28T10:47:22.936Z` selected 7 complete samples instead of the unbounded 18\n- `./shifu check` reached unrelated packaged-spec tests and failed only because this cold worktree has no generated `framework/spec/dist/manifest.json`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fixes measurement cohort selection without changing gate, proof, merge-queue, or release architecture semantics\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe collector reads GitHub pull request, Actions, and merge-queue metadata through the existing authenticated read-only API path. No permission or provider-integration behavior changes.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (the report is the machine-readable operational contract)\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTE3LWt1bmdmdS1kZXYtZ2F0ZS1sYXRlbmN5LXNsbyIsImRlbGl2ZXJ5Q2xhc3MiOiJub24tbmF0aXZlLWZhc3QiLCJkZXZIZWFkIjoiYjQ3MTdmYWUxMGRjOTZjODBlZTMxOTc0ZGYyYzVjODNlYzA1ZjgxYyIsInB1bGxSZXF1ZXN0SGVhZCI6IjVjYTBlODRkNzlmZTdiMjZkMmY1NmE3YmE4MmIxYTkxMjliY2M1NGEiLCJyZXBsYXllZENhbmRpZGF0ZSI6IjY3NDhkNzg0OGU5YmQyOGRjOWMxZjEzYTEyY2M4YjMzMTliYTY1YTgiLCJyZXBsYXllZFRyZWUiOiIyNGRkZTAxNDNmZjQ0ZTE5NmViNDY0ZjQ2N2QzMWMxMzA4Zjg5MDE0IiwicXVldWVBdHRlbXB0IjoiNWNhMGU4NGQ3OWZlN2IyNmQyZjU2YTdiYTgyYjFhOTEyOWJjYzU0YUBiNDcxN2ZhZTEwZGM5NmM4MGVlMzE5NzRkZjJjNWM4M2VjMDVmODFjIiwiYWRtaXNzaW9uUHJvb2ZSb290Ijoic2hhMjU2Ojk2Yzk4Yzc1Mjg5NDdkMzkyYTBhNmY3Y2E5NWY2ODQ2MmZiMWNlZDA3ZTQyNWMwMzMxYmIwYTUyODRlZWVkZDAiLCJhZG1pc3Npb25Qcm9vZlJvb3RzIjpbInNoYTI1Njo0ZjVmMjgyYWMxMTFmNjUwNzliOGNjYmJiNGFhZjA1NmE1ZWU2ZmUzNzU4ZDdiOWI3YzI4Zjk4YmIxMTIyOThiIiwic2hhMjU2Ojk2Yzk4Yzc1Mjg5NDdkMzkyYTBhNmY3Y2E5NWY2ODQ2MmZiMWNlZDA3ZTQyNWMwMzMxYmIwYTUyODRlZWVkZDAiXSwic3RhdHVzQ29udGV4dCI6IlF1ZXVlIGZhbWlseSBsZWFzZS9kOTlmM2E5MTY2NzM5ZTBkIiwibGVhc2VSb290Ijoic2hhMjU2OjMzNTRiNmU2NjllNjg4NWM0MDg4MzQzNmQ4MzNiZGYzMDg3NTVkMTFhZWNmOTYwYzk0ZWY5MGE0ZjNlYWU3NWEifQ -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:47:52Z",
          "mergedAt": "2026-07-28T17:47:25Z",
          "additions": 154,
          "deletions": 8,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1772,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1772",
          "title": "fix(ci): use public Cargo index for CodeBuild",
          "body": "## Summary\n\n- bind the AWS CodeBuild Linux burst qualification to the public crates.io sparse index\n- keep office-only Cargo mirror configuration out of the cloud runner contract\n- refresh governed workflow and publication projections\n\n## Verification\n\n- `node --test scripts/buildchain-install.test.mjs` (7/7)\n- `./shifu check:source` (passed)\n- staged pre-commit gate (passed)\n- workflow authority closed-world verification (passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Cloud qualification transport configuration does not alter an architecture contract\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\nThis touches a provider qualification boundary but adds no credentials, publication, or release authority. Validation is listed above.\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI4LWt1bmdmdS1hd3MtdXMtZWxhc3RpYy1ydW5uZXItYnVyc3QtcGxhbmUiLCJkZWxpdmVyeUNsYXNzIjoibm9uLW5hdGl2ZS1mYXN0IiwiZGV2SGVhZCI6IjJiZDQzNzc3ZTYxYmY3MjcyNTIyNWE4NWJmOTZiYWRhMDI0YjUwYWEiLCJwdWxsUmVxdWVzdEhlYWQiOiIwYzY4NDFhOWQxMmEyM2NkZDEzZDMyMmIxZWRmNmZkYjk1YjIwZWUyIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiIyZTgyOTZjYmM5ZGE3NmIxMmU0ODAyZmMyMDA5ZjM4YTkyMTUwNGJlIiwicmVwbGF5ZWRUcmVlIjoiODg3OWM0MTg4ZTRiMjhmYjk1ZGZjNmNhN2UxY2QwZTU4NjViODE2YSIsInF1ZXVlQXR0ZW1wdCI6IjBjNjg0MWE5ZDEyYTIzY2RkMTNkMzIyYjFlZGY2ZmRiOTViMjBlZTJAMmJkNDM3NzdlNjFiZjcyNzI1MjI1YTg1YmY5NmJhZGEwMjRiNTBhYSIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1Njo2NTU2NGQ2MDc4YmFiZDk2NjVkMDVlZmU0NDgyMzcyOWY5MzlmY2QwYmEyNmJlNDk3M2IyOTQ1ZDVkZDFjNDM5IiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6NWNkMjJhZDgxYTdhNzc4ZjJlNWJmYWYyOWNlZTk1YjVhZTc5YjgyNDA0ZmRkZDNlYjBiNWUxYTg4MGFjZjJlZCIsInNoYTI1Njo2NTU2NGQ2MDc4YmFiZDk2NjVkMDVlZmU0NDgyMzcyOWY5MzlmY2QwYmEyNmJlNDk3M2IyOTQ1ZDVkZDFjNDM5Il0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZDk5ZjNhOTE2NjczOWUwZCIsImxlYXNlUm9vdCI6InNoYTI1NjpkZTA4M2Q5ZTM2MzA5MGIwN2VmMGVjMTFiNTMxYWI1ZTMwODMzNGNmMTBhN2E0YmExODYzYmQ0Y2EyODA0MjgzIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T17:06:20Z",
          "mergedAt": "2026-07-28T17:53:20Z",
          "additions": 9,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2014,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2014",
          "title": "fix(release): sign generated version commits",
          "body": "## Summary\n- add the zone-required DCO trailer to Buildchain-generated version-state commits\n- sign generated reconciliation merge commits as well\n- verify both release-version and reconciliation paths in unit tests\n- rebuild the published promote-buildchain-ref action bundle\n\n## Verification\n- `node --test --test-name-pattern='release/v1 finalization|publish-gate/major finalization' tests/promote-buildchain-ref.test.mjs`\n- `pnpm run build`\n- `pnpm run check` (677 tests passed)\n- `git diff --check`\n\nThis restores native DCO compatibility for consumer repositories whose generated version-state PRs are protected by the zone-wide DCO gate.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T17:52:40Z",
          "mergedAt": "2026-07-28T17:59:49Z",
          "additions": 83,
          "deletions": 65,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 55,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/55",
          "title": "test(release): lock generated promotion authority",
          "body": "## Summary\n- make the consumer verification fail closed if Buildchain generated-status, generated-PR, or generated-ref token wiring regresses\n- preserve the repository secret fallback needed for protected generated version-state PRs\n- provide a fresh governed alpha source after the pre-fix alpha.7 finalization stopped at DCO\n\n## Verification\n- `npm run check` (51 tests passed)\n- `git diff --check`\n\nThe Buildchain-side DCO fix is merged on v2.12 (#2014) and is progressing through the active v3 alpha line (#2015).",
          "author": "dongkeren",
          "createdAt": "2026-07-28T18:07:57Z",
          "mergedAt": "2026-07-28T18:09:13Z",
          "additions": 3,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2015,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2015",
          "title": "fix(release): sign generated version commits",
          "body": "## Summary\n- port the reviewed generated-commit DCO fix to the active v3 alpha line\n- sign both version-state commits and generated reconciliation merge commits\n- add focused assertions for both paths\n- rebuild the published promote-buildchain-ref action bundle\n\n## Verification\n- focused release finalization tests pass\n- `pnpm run build`\n- `node scripts/check-action-bundles.mjs`\n- `git diff --check`\n\nThe same change is merged on the v2.12 line in #2014. This v3-line port is required for consumers of `@v3-alpha`, including runtime-images.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T18:01:53Z",
          "mergedAt": "2026-07-28T18:09:15Z",
          "additions": 81,
          "deletions": 63,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1774,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1774",
          "title": "feat(work): add typed Family State v2 envelope",
          "body": "## Summary\n\nAdd a backward-compatible Assignment Family State v2 typed envelope. The new\nversion binds exact Pursuit, Atlas, execution Warrant, completion judgment,\nadmission, Episode, Project Cut, and delivery-evidence references while keeping\nthe Family projection non-authoritative.\n\nThe existing v1 contract, transitions, serialized bytes, and Wave 0 retained\nstate root remain unchanged. A v1 state is read as explicitly under-typed; an\nupgrade to v2 requires caller-supplied bindings and never guesses authority.\n\n## Related issue\n\nNative Assignment:\n`2026-07-28-kungfu-assignment-family-v2-typed-envelope`\n\n## Changes\n\n- add additive v2 contract, state, transition, verification, explicit-upgrade,\n  and exact v2-to-v1 compatibility projection surfaces;\n- add typed references for Initiative direction and perspective, child Work\n  state and execution authority, terminal settlement, and delayed publication;\n- fail closed on swapped semantic references, cross-world or stale coordinates,\n  revoked Warrants, incomplete settlement, and hidden publication lag;\n- retain and verify the exact Wave 0 v1 fixture root;\n- refresh generated Primitive catalog, KFD support, semantic-amplification, and\n  Buildchain evidence projections without adding or changing a KFD Primitive.\n\n## Verification\n\n- pre-commit source hooks — passed\n- Assignment Family orchestration — 59 passed under the Kungfu-managed Python\n  3.13.14 runtime\n- Agent Work state — 7 Node contract tests and 40 Python tests passed\n- KFD support matrix — 13 rows, 4 shipped-support rows, 17 negative/determinism\n  tests passed; exact generated projections current\n- local source acceptance reached the aggregate source-contract batch; the only\n  local failure was dependency discovery inside a disposable readonly clone,\n  and that exact Agent Work lane passed independently above\n- protected PR CI remains authoritative for the affected-native closure\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f9771-4c20-7e2c-8e7c-3f3cb3f1b9bd\"],\n  \"summary\": \"Add an explicit typed v2 envelope to the native Assignment family projection while preserving v1 identity and authority boundaries\",\n  \"verification\": [\"pre-commit source hooks: passed\", \"Assignment Family orchestration: 59 passed\", \"Agent Work state: 7 Node and 40 Python tests passed\"]\n}\n-->\n\n## [Evolution Map](../docs/evolution/README.md) impact\n\nEvolution impact: extends\n\nThis adds evidence to the open Native Work Control and recursive dogfood Stage;\nit does not open or settle a new authority transition.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change refreshes generated KFD and Buildchain evidence projections. It does\nnot publish a package, alter release credentials, or grant a projection new\nauthority; source acceptance and protected CI verify the generated closure.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI4LWt1bmdmdS1hc3NpZ25tZW50LWZhbWlseS12Mi10eXBlZC1lbnZlbG9wZSIsImRlbGl2ZXJ5Q2xhc3MiOiJuYXRpdmUtcHJvb2YtcmVxdWlyZWQiLCJkZXZIZWFkIjoiODE1N2ZmNGJmNGYwNDRhNzM1NDk3YTc4Nzg3ODk5NWQ3YWRkZGZkOCIsInB1bGxSZXF1ZXN0SGVhZCI6ImM3ODNjNWFlYTRhZGZhNjczNDRjMDczMDIzYTQ2MWJhZjllMmY4MGIiLCJyZXBsYXllZENhbmRpZGF0ZSI6IjEzNmU4YWY5ZGRiNzU3YTFlMzc1ODljZWMzYzJkYWVhYzY1ZWE5ODIiLCJyZXBsYXllZFRyZWUiOiI4ODE4YzkzMzY0MzA3OTBkMzI0NGFlZTlhODEwNWEyNGZhZmY5MDc4IiwicXVldWVBdHRlbXB0IjoiYzc4M2M1YWVhNGFkZmE2NzM0NGMwNzMwMjNhNDYxYmFmOWUyZjgwYkA4MTU3ZmY0YmY0ZjA0NGE3MzU0OTdhNzg3ODc4OTk1ZDdhZGRkZmQ4IiwiYWRtaXNzaW9uUHJvb2ZSb290Ijoic2hhMjU2OjM1ZGVjMzk1NTY0NWQ5YTg2OTkyNjU3YzQyM2NmNzhhNjgzNDViOTNkMGU5NDgzNWE3YWZlN2I4NTBmZTc2NmYiLCJhZG1pc3Npb25Qcm9vZlJvb3RzIjpbInNoYTI1NjozNWRlYzM5NTU2NDVkOWE4Njk5MjY1N2M0MjNjZjc4YTY4MzQ1YjkzZDBlOTQ4MzVhN2FmZTdiODUwZmU3NjZmIiwic2hhMjU2OjRhZDM5OWFkZjI3NDJkMzU0NGJkZjcyNjlkNjFhODg3NjE4ZGE4NjQ4NjI0OTRkZjA3ODk5NjRlNmI2YTRmMzYiXSwic3RhdHVzQ29udGV4dCI6IlF1ZXVlIGZhbWlseSBsZWFzZS9kOTlmM2E5MTY2NzM5ZTBkIiwibGVhc2VSb290Ijoic2hhMjU2OmM0MGUxMTBhMmY4YjgxZDQyMWVhZGI1ZDJmYTY3YjI5MmNlM2E3YTA2OTU0OGIzYmI5NWY0ZjJhOTI2ZmYxNDAifQ -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T17:30:18Z",
          "mergedAt": "2026-07-28T18:12:55Z",
          "additions": 1275,
          "deletions": 48,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2016,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2016",
          "title": "chore(release): promote generated commit DCO to alpha",
          "body": "## Summary\n- promote the reviewed generated-commit DCO fix from `dev/v3/v3.0` to the active alpha line\n- preserve the existing alpha version state while merging the exact dev source\n- unblock protected consumer repositories whose Buildchain-generated version PRs require DCO\n\n## Verification\n- focused release finalization tests pass\n- action bundle integrity check passes\n- `git diff --check`\n\n## Source\n- dev merge: `753a6f8e0a1f277ba5fd9b63394d0177a3e469f5`\n- reviewed fix PR: #2015\n- v2.12 fix PR: #2014",
          "author": "dongkeren",
          "createdAt": "2026-07-28T18:10:25Z",
          "mergedAt": "2026-07-28T18:15:14Z",
          "additions": 81,
          "deletions": 63,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1777,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1777",
          "title": "fix(ci): install CodeBuild platform optionals",
          "body": "## Summary\n\n- let real AWS CodeBuild Linux qualification install the matching platform optional packages\n- keep `--no-optional` unchanged for every other runner and lifecycle\n- add a focused contract test for the clean-runner libnode dependency path\n\n## Verification\n\n- `node --test scripts/buildchain-install.test.mjs` (8/8)\n- `./shifu check:source` (721 tests: 711 passed, 10 skipped)\n- `git diff --check origin/dev/v4/v4.0...HEAD`\n\n## Delivery boundary\n\nTrusted exact-source qualification only. No release credentials or static cloud credentials are admitted.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Cloud qualification dependency provisioning does not alter an architecture contract\"\n}\n-->\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI4LWt1bmdmdS1hd3MtdXMtZWxhc3RpYy1ydW5uZXItYnVyc3QtcGxhbmUiLCJkZWxpdmVyeUNsYXNzIjoibm9uLW5hdGl2ZS1mYXN0IiwiZGV2SGVhZCI6ImNhMzcyZDFlNWM0ZTk3MjE5NjYzYTU3MmJkNjU3ZGU3ODBiN2JmYzYiLCJwdWxsUmVxdWVzdEhlYWQiOiIwM2JlMmQ5NGExMjhkYWYwYmQ4NzU2YzRjOGIzNmFkZmE4NzJkZTFhIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiJlYzJkYTQyYmE3OGM2YmIzNWNlZTdiODFmYjA5MzQ3OTEyNzI3M2I4IiwicmVwbGF5ZWRUcmVlIjoiMTkwOGU0ODliMTgwNzM4MGE2MWUxYjA4NWFiNzBiMjMzNmY5YTBjYSIsInF1ZXVlQXR0ZW1wdCI6IjAzYmUyZDk0YTEyOGRhZjBiZDg3NTZjNGM4YjM2YWRmYTg3MmRlMWFAY2EzNzJkMWU1YzRlOTcyMTk2NjNhNTcyYmQ2NTdkZTc4MGI3YmZjNiIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjoxNDlmOWQ5MTQ3MjdkZDI2NGIxZWRkZmM5YzM3ZGRhYTdhY2RiZTBjMjQ4NDRiMjBkOTJkNTZiNjY1ZTQwNzhmIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6MTQ5ZjlkOTE0NzI3ZGQyNjRiMWVkZGZjOWMzN2RkYWE3YWNkYmUwYzI0ODQ0YjIwZDkyZDU2YjY2NWU0MDc4ZiIsInNoYTI1Njo1Y2QyMmFkODFhN2E3NzhmMmU1YmZhZjI5Y2VlOTViNWFlNzliODI0MDRmZGRkM2ViMGI1ZTFhODgwYWNmMmVkIl0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZDk5ZjNhOTE2NjczOWUwZCIsImxlYXNlUm9vdCI6InNoYTI1Njo1ZDI4NzcyMDViMDEyMmE0MDBlYzZmOTE3NzgzMTQ1ZjkyMDAyZmEwM2I4OTAyY2UyNWFjYTJiM2NkNDA5M2FhIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T18:14:28Z",
          "mergedAt": "2026-07-28T18:23:29Z",
          "additions": 21,
          "deletions": 7,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2017,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2017",
          "title": "Prepare v3.0.2-alpha.10",
          "body": "Create the generated version-state commit for v3.0.2-alpha.10.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: 6d22340e3c2ab0202ce8d830cf1f85400ada5ae7 -> 44242696401d4456d23413501517735787db247d\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T18:20:32Z",
          "mergedAt": "2026-07-28T18:24:40Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 56,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/56",
          "title": "chore(release): promote managed release authority to alpha",
          "body": "## Summary\n- promote the Buildchain-generated authority regression guard from dev to alpha\n- retain the exact Hub application, image, and Compose release source already qualified on the previous alpha candidate\n- start a fresh alpha transaction after the Buildchain-generated DCO fix reaches `v3-alpha`\n\n## Verification\n- dev PR #55 passed DCO and all 51 runtime tests\n- this PR must pass the protected alpha Verify check before merge\n\n## Release dependency\nMerge only after Buildchain v3.0.2-alpha.10 has finalized and moved `v3-alpha` to its signed generated version state.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T18:27:26Z",
          "mergedAt": "2026-07-28T18:30:40Z",
          "additions": 3,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 57,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/57",
          "title": "Prepare v1.0.0-alpha.8",
          "body": "Create the generated version-state commit for v1.0.0-alpha.8.\n\nBuildchain generated this PR because protected branch alpha/v1/v1.0 rejected direct generated bookkeeping.\n\nRejected update: f8fcc58511cf185e53129ad8df1c68ed0d7ce2d4 -> 5a2aeacaeff6280b91bc2afd8fd9a5f2f7609b58\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T18:39:09Z",
          "mergedAt": "2026-07-28T18:39:56Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 174,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/174",
          "title": "feat(site): add Hub Starter agent builder path",
          "body": "## Summary\n- promote Agent Builders to a first-class navigation group with Overview, Hub Starter, and Verify Agent Hub\n- add `/agent-builders/hub-starter/` as a low-friction product page with the one-command Compose launch\n- explain the business app, optional local model, and Kungfu work-control boundaries without overstating the alpha\n- guide technical users to Agent-first exploration through README, AGENTS.md, and the container brief\n- update the homepage and Agent Builders overview with a direct Hub Starter path\n- include the new route in build and fail-closed site checks\n\n## Verification\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `git diff --check`\n- desktop and 390x844 Playwright review, including no horizontal overflow\n\nThe runtime alpha release is being finalized independently; the page links the durable release catalog rather than hard-coding a mutable candidate.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T18:34:08Z",
          "mergedAt": "2026-07-28T18:47:18Z",
          "additions": 676,
          "deletions": 36,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 175,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/175",
          "title": "Release production from a5ffe5f96a42",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `a5ffe5f96a425397f3466beabb630ab7e6ef66e3`\n- Artifact hash: `dcadb3a1efacd44fe5442778bdf96cf545d76725ce520093c1f0c45257a131f3`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30389030935)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-a5ffe5f96a42`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-28T18:50:15Z",
          "mergedAt": "2026-07-28T18:53:38Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1771,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1771",
          "title": "feat(kfx): migrate Agent Work Lab to first-party Suite",
          "body": "## Summary\n\nMigrate the pre-release Agent Qualification Lab directly to Agent Work Lab with no compatibility alias. The first-party KFX Suite manifest and catalog are authoritative for Suite identity, cases, capabilities, recommendations, timing, claims, non-claims and recovery guidance; package.json remains transport metadata only.\n\nCore remains the sole authority for plans, exact WorkRef, isolated execution, native Episode lifecycle, immutable receipts, assessment and recovery evidence. GUI, TUI, CLI and Agent consume the same Suite and Core path, while generic framework workbench primitives remain free of Lab identities and policy.\n\nThis child does not settle the parent or the group terminal. The sole final qualification remains 2026-07-28-kungfu-kfx-identity-neutral-terminal-qualification.\n\n## Changes\n\n- add one manifest-authoritative first-party Agent Work Lab KFX Suite and Work Continuity catalog\n- migrate API, Core, CLI, GUI, TUI, navigation, onboarding, automation and current docs to the Agent Work Lab identity\n- delete every reachable Qualification Lab command, route, schema owner and compatibility alias\n- bind two fresh sessions to exact WorkRef, native Episode roots and immutable receipt dependencies in discardable evidence homes\n- preserve offline demo, existing-Work-first startup, later Lab return, fixed report region, independent scrollback and deterministic automation\n- regenerate KFD release and SDK projections and add a permanent reverse-identity gate\n\n## Verification\n\n- ./shifu test:agent-work-lab\n- ./shifu test:kfx-profile-suite\n- ./shifu test:native-kfx-admission\n- ./shifu build:core\n- ./shifu freeze\n- assembled CLI catalog and two-session demo\n- ./shifu docs:check\n- ./shifu check\n- ./shifu check:staged\n- repository pre-commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-72df-add3-948f3ae38c3a\",\n    \"KF-ADR-019f86da-4f90-73f3-b027-c343b2bc8bcc\",\n    \"KF-ADR-019f86da-4f90-73ff-9543-f0a4f0beef05\",\n    \"KF-ADR-019f86da-4f90-7a4b-b1a3-256ce6fa3f06\",\n    \"KF-ADR-019f86da-4f90-7ef4-b28b-ee1fbaf9e62e\"\n  ],\n  \"summary\": \"Move the pre-release Lab product identity and semantics behind one first-party KFX Suite while retaining Core Work and Episode authority and no compatibility path.\",\n  \"verification\": [\n    \"./shifu test:agent-work-lab\",\n    \"./shifu test:kfx-profile-suite\",\n    \"./shifu test:native-kfx-admission\",\n    \"./shifu check\",\n    \"repository pre-commit staged gate\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change updates declared KFD and packaged Suite surfaces but performs no publication or deployment and reads no provider credentials or private transcripts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWtmeC1wYXNzcG9ydC1hZ2VudC13b3JrLWxhYi10ZXJtaW5hbC1jdXRvdmVyIiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtYWdlbnQtd29yay1sYWIta2Z4LXN1aXRlLWN1dG92ZXIiLCJkZWxpdmVyeUNsYXNzIjoibmF0aXZlLXByb29mLXJlcXVpcmVkIiwiZGV2SGVhZCI6ImEyMzdjNTk3ZTQ5NDdkOTU2MjJmMTFiYTViMWE5OTRjOTdkYjU5Y2IiLCJwdWxsUmVxdWVzdEhlYWQiOiI0NzNlY2ViOWQ1YzI3NTJjODNjOTFlYjE4MzIzNzM5NjdlMzFmZjRkIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiIzZDc0ZGI2YWM5OTE1NDRiNmQ5M2E0ZjhiNWE2NjVmYmRkODdmYjhiIiwicmVwbGF5ZWRUcmVlIjoiMDFmNWUxMDE4M2Y4ZWIxNjI4ZmFlZjkxYjM0NTE4MTMzZjY1Nzc1NCIsInF1ZXVlQXR0ZW1wdCI6IjQ3M2VjZWI5ZDVjMjc1MmM4M2M5MWViMTgzMjM3Mzk2N2UzMWZmNGRAYTIzN2M1OTdlNDk0N2Q5NTYyMmYxMWJhNWIxYTk5NGM5N2RiNTljYiIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjpiNzhlNjdlNTEyZjU4MDlhYWRmNDM0YTEzZjU4MjE2M2FiOGYxY2FiYzc4Y2QyNmJiNWQ4YTQzMzUxMzhhODY1IiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6NDU3MDBjODEyMDQ4MzkzOWMzYWM3Y2IyMmIwMDQ0NmNkZmI4NmQwMmY0OGRiNzAyNTYwNjI1MmNhMzY1Njk2NiIsInNoYTI1NjpiNzhlNjdlNTEyZjU4MDlhYWRmNDM0YTEzZjU4MjE2M2FiOGYxY2FiYzc4Y2QyNmJiNWQ4YTQzMzUxMzhhODY1Il0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvNWUyNWU1M2IzODg1NjEwMCIsImxlYXNlUm9vdCI6InNoYTI1Njo1ZDgyOTk1MzNkNjdjNDUxYTM2NDBhYmIwYjg4NDk2YmFlMGRiZDNhYzRhZGI4ODUyODAyMDhmZDgzNjYxMjRkIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T16:54:42Z",
          "mergedAt": "2026-07-28T18:55:06Z",
          "additions": 2752,
          "deletions": 2096,
          "changedFiles": 72
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 176,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/176",
          "title": "chore(release): retry production from a5ffe5f96a42",
          "body": "## Buildchain production release retry\n\nThe production release intent remains bound to the already-qualified staging artifact. This empty commit creates a fresh protected-PR merge event so the independent production environment reviewer is not also the workflow triggering actor.\n\n### Release evidence\n\n- Source SHA: `a5ffe5f96a425397f3466beabb630ab7e6ef66e3`\n- Artifact hash: `dcadb3a1efacd44fe5442778bdf96cf545d76725ce520093c1f0c45257a131f3`\n- Staging release passport: https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30389030935\n- Superseded release-intent PR: #175\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T19:01:28Z",
          "mergedAt": "2026-07-28T19:04:27Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1782,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1782",
          "title": "fix(maintainability): preserve rename budget lineage",
          "body": "## Summary\n\nPreserve code-complexity budget lineage across a protected-head advance. The previous rename bridge derived only from the candidate versus the then-current protected branch; after that candidate became `dev`, the merge base collapsed to `HEAD` and the protected branch failed its own source gate.\n\nThis bugfix reconstructs committed rename chains from the governed baseline ref and retains the existing candidate aggregate-diff fallback. It does not refresh, waive, or widen any complexity budget.\n\n## Verification\n\n- repository staged gate: passed\n- complexity ratchet on current protected `dev`: passed\n- rename-chain regression test: passed\n- `./shifu check:source`: 722 pass, 10 skip, 1 local environment failure because `pytest` was absent from the new worktree PATH; required GitHub CI is authoritative for the complete environment\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Restore persistent rename lineage in the existing complexity source gate without changing an architecture decision or budget.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Regression test added\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWdvLWZhbWlseS1jb250aW51b3VzLWRlbGl2ZXJ5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtZ28tZmFtaWx5LXBvc3QtbWVyZ2UtY29tcGxleGl0eS1yZW5hbWUtY29udGludWl0eSIsImRlbGl2ZXJ5Q2xhc3MiOiJzb3VyY2Utb25seSIsImRldkhlYWQiOiI5NzA0MWMyNGU3M2ZlMjBhZTgxNDJmZjJkODdlNzA1NzJjMjRhNzNiIiwicHVsbFJlcXVlc3RIZWFkIjoiMDgwMzA2NGE3Yzk5NjRiMTMyNDI3ZWZiMDAxOTBiODcxZmE1NGMyOSIsInJlcGxheWVkQ2FuZGlkYXRlIjoiZWU0MjkwYzZmZjI4M2UxNWU0OGQ1NWY3NzNlZjMxODMzZWFhYTEzYyIsInJlcGxheWVkVHJlZSI6IjVjZGQ1ZDEzNDJmZTlmOTdkYTJhOTkwMWVlODJlNjNlN2M2NGQwYWMiLCJxdWV1ZUF0dGVtcHQiOiIxNzgyQDk3MDQxYzI0ZTczZmUyMGFlODE0MmZmMmQ4N2U3MDU3MmMyNGE3M2IiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6YTliZWU4YjZjNTQ4NDg1MTEyZWU0NTNkYzlhNTE0ZDQ4Y2UyZWM5Mjk4NmViOWI4ODJjNGVlOGRmZjM5NmZmZCIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OmE5YmVlOGI2YzU0ODQ4NTExMmVlNDUzZGM5YTUxNGQ0OGNlMmVjOTI5ODZlYjliODgyYzRlZThkZmYzOTZmZmQiXSwic3RhdHVzQ29udGV4dCI6IlF1ZXVlIGZhbWlseSBsZWFzZS9lY2FjNjdiY2ViZmFlM2JmIiwibGVhc2VSb290Ijoic2hhMjU2OjBiNGJjMzUwZjY1MWI1ZjVjNTQyMDkyYTBiMWVlYWZhMDk4ZWJmZGQ3NmEyYTliOTY2YjgzMTQxNTUyMjM0MmMifQ -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T19:15:04Z",
          "mergedAt": "2026-07-28T19:32:18Z",
          "additions": 46,
          "deletions": 12,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1781,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1781",
          "title": "fix(ci): bound CodeBuild native parallelism",
          "body": "## Summary\n\n- cap AWS CodeBuild Linux core builds at four native compile jobs through the existing `KUNGFU_BUILD_JOBS` contract\n- record the same requested parallelism in retained Buildchain process diagnostics\n- refresh the closed-world workflow authority and non-publication source roots\n\n## Evidence\n\n`poc-03` completed install and reached 365/578 native objects, then `cc1plus` was killed while CMake used 8 jobs and Buildchain observed 20 concurrent processes. This change is scoped only to the AWS qualification workflow; local runners keep their existing host policy.\n\n## Verification\n\n- `node --test scripts/buildchain-install.test.mjs` (8/8)\n- `./shifu check:source` (721 tests: 711 passed, 10 skipped)\n- workflow authority and publication control-plane checks\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Cloud qualification resource parallelism does not alter an architecture contract\"\n}\n-->\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI4LWt1bmdmdS1hd3MtdXMtZWxhc3RpYy1ydW5uZXItYnVyc3QtcGxhbmUiLCJkZWxpdmVyeUNsYXNzIjoibm9uLW5hdGl2ZS1mYXN0IiwiZGV2SGVhZCI6ImE3ODZjMTVmODNlNjM1NDI5ZmY2OGFmMGI0MGFhNDYxY2U0ZGVkNGYiLCJwdWxsUmVxdWVzdEhlYWQiOiI2NDA2MjRlZjU5YmU4ZTJmNzQzZDhjZjQyNTNlMTUwY2ZjMWMzMjA2IiwicmVwbGF5ZWRDYW5kaWRhdGUiOiIwZWNmOTcyZjA4MTExYmY3M2EyYjczMzNhOTdhOGM4MjFkOTU4YjEyIiwicmVwbGF5ZWRUcmVlIjoiMDIxZjZkODY3NGE2M2Y3ZTUzN2IzNTNhMDYxMzBlNjczOWM3YzE1YiIsInF1ZXVlQXR0ZW1wdCI6IjY0MDYyNGVmNTliZThlMmY3NDNkOGNmNDI1M2UxNTBjZmMxYzMyMDZAYTc4NmMxNWY4M2U2MzU0MjlmZjY4YWYwYjQwYWE0NjFjZTRkZWQ0ZiIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjpkYjZiMjkyNDQ2MWM1MzkyMzMzNjM3ODQyMGE2ZDJlZGM5NDkzMTU0ZGFjMDQ0MzcyOTAyNDAyMWZhY2EyNDY5IiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6NWNkMjJhZDgxYTdhNzc4ZjJlNWJmYWYyOWNlZTk1YjVhZTc5YjgyNDA0ZmRkZDNlYjBiNWUxYTg4MGFjZjJlZCIsInNoYTI1NjpkYjZiMjkyNDQ2MWM1MzkyMzMzNjM3ODQyMGE2ZDJlZGM5NDkzMTU0ZGFjMDQ0MzcyOTAyNDAyMWZhY2EyNDY5Il0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZDk5ZjNhOTE2NjczOWUwZCIsImxlYXNlUm9vdCI6InNoYTI1NjpkZTYxYjhiYTYwNTYzNGE0ODc3N2EwNjFhN2RjY2ZmYzVjOGI0NjkyODc3NmMwZGE2YzY4NmIyOTQzNmIzYjhjIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T18:57:18Z",
          "mergedAt": "2026-07-28T19:47:50Z",
          "additions": 10,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1776,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1776",
          "title": "fix(kfx): enforce native adapter host authority",
          "body": "## Summary\n\nBind Rewind in-process adapter injection to the current Core-native KFX Fact Cut. Package names, discovery paths, caller environment, and stale descriptors no longer confer execution authority; the exact installed closure must match a current native host authorization.\n\n## Related assignment\n\nKungfu Assignment: `2026-07-24-buildchain-linux-github-attestation`\n\n## Changes\n\n- derive adapter host placement and authorization only in native Core\n- require exact cut, generation, package, manifest, capability-grant, and authorization roots before Python or Node adapter injection\n- ignore caller-provided host descriptors and reject same-key closure shadows\n- route `authorize-host` through the Python storage-service binding into native Core\n- install the packed LangChain KFX into a qualification Fact Cut before the real capture fixture runs\n- preserve the previously published KFX assessment and contract roots\n\n## Verification\n\n- repository staged gate passed, including 50/50 latency contract tests, 17/17 invariant tests, and 112/112 documentation/promotion tests\n- Linux GCC 14 affected-native qualification passed 21/21 native tests on the pre-merge feature head\n- Linux full Core build passed on the pre-merge feature head\n- exact merged-head Linux build and runtime fixture sequence are being recorded as protected-controller evidence\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix closes an adapter authority membrane and dispatcher wiring gap under the already accepted Core-native KFX lifecycle and exact-root authority; it does not change an accepted architecture decision.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change narrows in-process execution authority and retains fail-closed behavior when a current native Fact Cut or exact closure match is absent.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Focused regression coverage added\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI0LWJ1aWxkY2hhaW4tbGludXgtZ2l0aHViLWF0dGVzdGF0aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiIxMjk2OWZjYzRmMzMzMzE2ODAyNDE5ZGY5YzRiZTYwNDI2OWYxZjEzIiwicHVsbFJlcXVlc3RIZWFkIjoiN2JkZTBjN2NkN2JhODZmMzM0Yzc0OTllNWQyYjUyMmExYmY5MDk4MyIsInJlcGxheWVkQ2FuZGlkYXRlIjoiZGQwNWVmNmRiYTgxYjU5MmNmNjhmZjU3ZjFlNzhlY2YxMzljY2QyYiIsInJlcGxheWVkVHJlZSI6IjYxZTI5NmNjYTRiYzg0ZmRhZTc5MjdlMTRjMjRhODJjOWViZmU1ZDgiLCJxdWV1ZUF0dGVtcHQiOiI3YmRlMGM3Y2Q3YmE4NmYzMzRjNzQ5OWU1ZDJiNTIyYTFiZjkwOTgzQDEyOTY5ZmNjNGYzMzMzMTY4MDI0MTlkZjljNGJlNjA0MjY5ZjFmMTMiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6ZTYwMGMwNmUwMjA1ODc1MGNkZDE1YjQyYmU3YTdlYTkxYmU5MDgzNmZmMjI0MGIzNGFjOTMxZGNmMDQ0ZThkOCIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjM5NTJhNzBlNDkzMzM2Njg5ZTk4NTVjZjgzMjU3NDIzYjQxMTg3NWFhYzJhMWRiYjNmMjQ0MDliMTQ3NDIyYWUiLCJzaGEyNTY6ZTYwMGMwNmUwMjA1ODc1MGNkZDE1YjQyYmU3YTdlYTkxYmU5MDgzNmZmMjI0MGIzNGFjOTMxZGNmMDQ0ZThkOCJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6NmUyZTM0ZWUwNmU5M2RiZjM3Y2YxOTEwNjYyZDU0NGQ3ZmVkZDY5NDM2MTg5NWM3NmRhZGMzMTBmMDgwYWQ5OSJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T18:11:46Z",
          "mergedAt": "2026-07-28T20:03:47Z",
          "additions": 278,
          "deletions": 104,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1785,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1785",
          "title": "fix(release): bind pull-merge identity and wheel signing",
          "body": "Atlas goal 2026-07-26-kungfu-kfd-support-governance. Bind auditable-demo pull-merge workflow identity to the exact artifact coordinate and consume Buildchain v3.0.2-alpha.10 wheel-signing support without widening release authority.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This release bugfix restores exact pull-merge workflow identity and consumes an already qualified Buildchain wheel-signing runtime; it does not change architecture authority or widen shipped KFD support.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Validation\n\n- KUNGFU_DEV_BRANCH=dev/v4/v4.0 ./shifu check\n- KUNGFU_DEV_BRANCH=dev/v4/v4.0 ./shifu check:source\n- ./shifu test:auditable-demo\n- ./shifu test:release-admission\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI2LWt1bmdmdS1rZmQtc3VwcG9ydC1nb3Zlcm5hbmNlIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJiNzRjNjIzYzk2Yzc1YzdkY2VjZWMxZWQwYzAyODJkMTA1ODM4Y2M4IiwicHVsbFJlcXVlc3RIZWFkIjoiNjFmOWMxM2E5ZTViZWExNzliODBhZjNlNTlkYTUyYzZhZTQzM2JjYiIsInJlcGxheWVkQ2FuZGlkYXRlIjoiYTk0MmRkYjVhNGE0ZjE2OGEzMzUxYTBhOGY5YzZkZmM3ODgyOGZiOCIsInJlcGxheWVkVHJlZSI6IjQ5M2VkMjFiYzBjZDc5N2VmN2U0OGJmMjc2YWNlMDc2MmRiNmU3MmEiLCJxdWV1ZUF0dGVtcHQiOiI2MWY5YzEzYTllNWJlYTE3OWI4MGFmM2U1OWRhNTJjNmFlNDMzYmNiQGI3NGM2MjNjOTZjNzVjN2RjZWNlYzFlZDBjMDI4MmQxMDU4MzhjYzgiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6NWY5MTNlNDFiMTA0MTVkYjVjMWVhNjVkMDQ0YmEwZDYzNmVlNTMxYTczYWJiOWE0NzZjNmY5NDYzYzdjOGE1MiIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjJmMTIxMjlhMTM5MWIzMjQxYzM3Y2NkOTRlMDQ2ODcwZTAyOTMyZjlhNzZhOTBmZjQyODY1OTFmYmU3ODdhMjIiLCJzaGEyNTY6NWY5MTNlNDFiMTA0MTVkYjVjMWVhNjVkMDQ0YmEwZDYzNmVlNTMxYTczYWJiOWE0NzZjNmY5NDYzYzdjOGE1MiJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6NTgxNTE3OTQ0MjhmZGFlYzhiOGU1ZmIxYzJlNzNkNTUxM2NkYjA2YTQxZDhjNGVmODIxZGYzYmEwOGI2OWUzNiJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T20:06:04Z",
          "mergedAt": "2026-07-28T20:18:47Z",
          "additions": 66,
          "deletions": 46,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1779,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1779",
          "title": "feat(project-cut): publish settlement batches",
          "body": "## Summary\n\n- add a versioned bounded publication contract for selected sealed Episode shadows and settled Project Cuts\n- derive one content-addressed machine-ledger branch and pull-request identity per declared Wave or batch\n- keep Work Control authoritative while exposing bounded publication lag, retry, failure, and clean-clone readback evidence\n- reject protected-target pushes, invalid roots, recursive generated-ledger events, private runtime material, and divergent retries\n\nNative Assignment: `2026-07-28-kungfu-go-family-git-settlement-publication`\n\nWork Definition root: `sha256:d276b4efdbbcaa8e5b35b14f4849884c6f3f8d9f40b1aaaa84b5174d5aafd615`\n\n## Changes\n\n- add request, manifest, observation, and state schemas plus the public publication contract\n- add deterministic prepare, inspect, reconcile, and verify CLI surfaces\n- add ten end-to-end tests covering batching, concurrency, retry, recursion, failure recovery, protected-target refusal, and exact clean-clone verification\n- wire the bounded checks into build-free Source Acceptance while preserving old-checkout bootstrap compatibility\n- synchronize the accepted Project Cut publication ADR and its deterministic navigation projection\n\n## Verification\n\n- `./shifu check:project-cut-publication`\n- `./shifu test:project-cut-publication` — 10/10 passed\n- Project Cut settlement, history, and composition suites — 36/36 passed\n- cold read-only bootstrap — 1/1 passed\n- `./shifu check:source` — 733 tests (723 passed, 10 skipped, 0 failed); publication, ratchet, runtime/control-plane, desktop, docs, and Project Cut suites passed on exact PR head `5ae5c82ad48dc1567dcaef0360ab0cfedb9459a7` replayed onto `b74c623c96c75c7dcecec1ed0c0282d105838cc8`\n- GitHub required source and affected-native checks — passed on exact PR head\n- staged documentation, ADR authority, and deterministic navigation gates — passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-77d5-a9ce-e7c798e3a623\"],\n  \"summary\": \"Stage bounded protected Git publication of exact Project Cut and sealed Episode settlement batches\",\n  \"verification\": [\"full Source Acceptance\", \"publication contract and ten-case suite\", \"Project Cut settlement, history, and composition suites\", \"cold read-only bootstrap\", \"ADR authority and deterministic navigation gates\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change adds a public machine-ledger publication protocol. Tests prove that only content-addressed protocol material is admitted and that runtime-private state is excluded.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWdvLWZhbWlseS1jb250aW51b3VzLWRlbGl2ZXJ5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtZ28tZmFtaWx5LWdpdC1zZXR0bGVtZW50LXB1YmxpY2F0aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiIwOTJiZTAwYTkyNWMwODFhZGEyMzE1ZjAxMTI2YzkwZDNiM2I3YjkwIiwicHVsbFJlcXVlc3RIZWFkIjoiNWFlNWM4MmFkNDhkYzE1NjdkY2FlZjAzNjBhYjBjZmVkYjk0NTlhNyIsInJlcGxheWVkQ2FuZGlkYXRlIjoiOWYzZDJmNGIzNDZlNzFjOTY5OTI3N2JhYzRjYmMzNzEwM2JmOGIwYSIsInJlcGxheWVkVHJlZSI6IjE4YzM0MmY3YzhlMDFjYjA3MmIwMzY2YjhmMzUzYmU2MDFjNWMzMTciLCJxdWV1ZUF0dGVtcHQiOiIxNzc5QDA5MmJlMDBhOTI1YzA4MWFkYTIzMTVmMDExMjZjOTBkM2IzYjdiOTAiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6MjhkZjRhODhiZjI1Y2YzYjlkNDg0OGE0YThlMjFmZTVkNDRjNWUwZmZiOGRlNmU3YjBlZWVlZTgwNGJiMTQ0MiIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjI4ZGY0YTg4YmYyNWNmM2I5ZDQ4NDhhNGE4ZTIxZmU1ZDQ0YzVlMGZmYjhkZTZlN2IwZWVlZWU4MDRiYjE0NDIiLCJzaGEyNTY6YTE1NjhlYzM0NzI4Y2YwMTA1ZWRjMWQ5NjRjYzljMTJiMzFhZDk1MjcxOGU4ZTI3NTU4ZWU0ZTBmNmQxYjk3MCIsInNoYTI1NjpkMjc2YjRlZmRiYmNhYThlNWIzNWIxNGY0ODQ5ODg0YzZmM2Y4ZDlmNDBiMWFhYWE4NGI1MTc0ZDVhYWZkNjE1Il0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZWNhYzY3YmNlYmZhZTNiZiIsImxlYXNlUm9vdCI6InNoYTI1Njo4ZmIwYzQ2MTZhMDlkYWE2OTY0YjQxOTU5M2FlMjJlYzI4Y2ZkMDk2NThhNzU4MjE2YTcyOGE1NGY3N2NjNDE1In0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T18:22:09Z",
          "mergedAt": "2026-07-28T20:27:38Z",
          "additions": 2463,
          "deletions": 13,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2018,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2018",
          "title": "fix(runners): support Ubuntu CodeBuild toolchain",
          "body": "## Summary\n- preserve the Amazon Linux 2023 GCC 14 provisioning path\n- add Ubuntu 24.04 apt-based GCC 14 provisioning for CodeBuild\n- record the selected package manager and compiler executables in runner evidence\n- fail closed on unsupported Linux images\n\n## Verification\n- `node --test tests/aws-runner-burst.test.mjs`\n- `pnpm run test:unit` (680 passed)\n- `git diff --check`\n\n## Burst-plane context\nThe XLarge CodeBuild run completed compilation but the Amazon Linux image could not load Node 22 because its glibc is older than GLIBC_2.38. This change enables the reviewed Ubuntu 24.04 CodeBuild image without weakening existing pins or trust routing.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T20:53:38Z",
          "mergedAt": "2026-07-28T20:56:01Z",
          "additions": 114,
          "deletions": 11,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1784,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1784",
          "title": "feat(kfx): close identity-neutral terminal qualification",
          "body": "## Summary\n\nClose the sole KFX identity-neutral terminal on one protected product cut. The\nterminal proves that KFD eligibility, first-party/System identity, Product\nSystem metadata, bundle location, signer identity, and installer origin carry\nzero implicit permission.\n\nAll execution authority remains bound to the exact Release Passport, Core\npolicy, purpose-bound Work/Warrant, explicit capability grant, current Cut and\ngeneration, and host isolation roots. The recursively dogfooded Control Suite,\nall bundled KFX, and Agent Work Lab use the same public contract.\n\nThis PR also closes two packaging gaps exposed by the Mac terminal: Agent Work\nLab is now a normal workspace/product dependency, and the generated CLI/KFD\nevidence chain includes the typed Assignment family-v2 surfaces.\n\n## Verification\n\n- `./shifu qualify:kfx-identity-neutral-terminal -- --report /tmp/kfx-identity-neutral-terminal-source.json`\n- `./shifu product gui build`\n- packaged CLI catalog, offline first run, and existing-Work-first rerun\n- native Core KFX contract test\n- repository pre-commit staged gate\n- Buildchain KFD evidence and support-matrix gates\n\nNo release is published by this PR.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-72df-add3-948f3ae38c3a\",\n    \"KF-ADR-019f86da-4f90-73f3-b027-c343b2bc8bcc\",\n    \"KF-ADR-019f86da-4f90-7d6c-926a-ddd27dbde8ab\",\n    \"KF-ADR-019f86da-4f90-7ef4-b28b-ee1fbaf9e62e\"\n  ],\n  \"summary\": \"Qualify the exact identity-neutral KFX authority cut, recursive Control Suite dogfood, packaged Agent Work Lab, and inert Product System assembly metadata.\",\n  \"verification\": [\n    \"./shifu qualify:kfx-identity-neutral-terminal\",\n    \"./shifu product gui build\",\n    \"repository pre-commit staged gate\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change updates qualification and packaged-product evidence but performs no\npublication or deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWtmeC1wYXNzcG9ydC1hZ2VudC13b3JrLWxhYi10ZXJtaW5hbC1jdXRvdmVyIiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUta2Z4LWlkZW50aXR5LW5ldXRyYWwtdGVybWluYWwtcXVhbGlmaWNhdGlvbiIsImRlbGl2ZXJ5Q2xhc3MiOiJuYXRpdmUtcHJvb2YtcmVxdWlyZWQiLCJkZXZIZWFkIjoiNDA5MDY2ZWNkYTI2NjE4ZjY1YTY1ZTMyMzM1MDhhOTFkMDIwNmQ5MSIsInB1bGxSZXF1ZXN0SGVhZCI6ImVjMTg1YTA2NTJlNzNmZDczZjRjMDIxNjFiZDMwNjg2ODQ1YjkxYTQiLCJyZXBsYXllZENhbmRpZGF0ZSI6IjMyZmZiZjI4MTJhYWM0YzJlMTdlNzcwZTE3YjVjZTUzZmQ1YTcyOWUiLCJyZXBsYXllZFRyZWUiOiJhZjU1YWQ3NWEwYTQ5ZjFiOWY0YjIyMDU3Mjc3MDliZGIzNjBiOTdjIiwicXVldWVBdHRlbXB0IjoiZWMxODVhMDY1MmU3M2ZkNzNmNGMwMjE2MWJkMzA2ODY4NDViOTFhNEA0MDkwNjZlY2RhMjY2MThmNjVhNjVlMzIzMzUwOGE5MWQwMjA2ZDkxIiwiYWRtaXNzaW9uUHJvb2ZSb290Ijoic2hhMjU2OjYyZmY2YThiZmNkMzFjN2JmZWRiNWI2Y2NmZWFlZWM0YjQ0N2Q0YTEzOTI0N2RiZTA0ZGE5MzU4MDNmNDM4MzQiLCJhZG1pc3Npb25Qcm9vZlJvb3RzIjpbInNoYTI1NjowNTExODJkMzMwN2NhNDljZTIxNzNkYzU2MWUzNjYxYmJmNmIyY2M1MDQwZDRkOGRjMzdiZWNkMDFhMWRjZjFmIiwic2hhMjU2OjYyZmY2YThiZmNkMzFjN2JmZWRiNWI2Y2NmZWFlZWM0YjQ0N2Q0YTEzOTI0N2RiZTA0ZGE5MzU4MDNmNDM4MzQiXSwic3RhdHVzQ29udGV4dCI6IlF1ZXVlIGZhbWlseSBsZWFzZS81ZTI1ZTUzYjM4ODU2MTAwIiwibGVhc2VSb290Ijoic2hhMjU2OmI1ZjI3MmUxZmU1MzJiYjYyZWZiYzEyMjU1ODJjMDkzNzdkYzUxY2YyYTFjYTdiYzdhYmE2MjliMjNkMzQyOTUifQ -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T19:53:59Z",
          "mergedAt": "2026-07-28T21:03:25Z",
          "additions": 599,
          "deletions": 56,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2019,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2019",
          "title": "fix(governance): bind Kungfu Alpha build controller check",
          "body": "## Summary\n\nBind the Buildchain v3 governance descriptor for Kungfu Alpha to the exact GitHub Actions controller check emitted by the current release workflow.\n\n## Changes\n\n- replace the legacy unbound `build` context for `alpha/v4/v4.0` with `build / Finalize build controller evidence` from GitHub Actions app 15368\n- keep the stable/release descriptor unchanged\n- refresh the generated public site bundle and document the remaining legacy release context\n\n## Verification\n\n- `node --test tests/github-governance-authority.test.mjs` (28/28 passed)\n- `pnpm run check`: 950/952 tests passed; the two macOS `/tmp` realpath failures reproduce unchanged on pristine `origin/dev/v3/v3.0`\n- site bundle and workflow checks passed\n\nNo credentials or bypass actors are added. The change narrows Alpha protection to one exact GitHub Actions controller identity.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T21:06:14Z",
          "mergedAt": "2026-07-28T21:09:56Z",
          "additions": 66,
          "deletions": 35,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2020,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2020",
          "title": "fix(runners): bound XLarge CodeBuild spend",
          "body": "## Summary\n- codify Ubuntu 24.04 XLarge as the Linux CodeBuild qualification profile\n- reduce execution timeout to 40 minutes and accepted-build cap to 12\n- conservatively round the live USD 0.0798/min rate to USD 0.08\n- keep the full accepted-plus-race envelope at USD 44.80 below the USD 49 budget\n\n## Verification\n- `node --test tests/aws-runner-burst.test.mjs`\n- `pnpm run test:unit` (680 passed)\n- `aws cloudformation validate-template ...`\n- `git diff --check`\n\n## Live evidence\nThe first Ubuntu XLarge qualification has already passed toolchain preparation and install and is compiling under a separately bounded live project. This PR makes the source contract stricter for subsequent greenfield stack creation.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T21:14:14Z",
          "mergedAt": "2026-07-28T21:17:45Z",
          "additions": 42,
          "deletions": 39,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1778,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1778",
          "title": "fix(ci): separate qualification proof identity",
          "body": "## Summary\n\nMake the documented exact pull-request affected-native proof reuse path reachable by separating reusable qualification identity from transient delivery-attempt identity. Exact source, plan, hosted toolchain, partition, closure, and SDK obligations remain fail-closed; family lease and queue admission facts remain independently sealed for the current merge-group delivery.\n\n## Related issue\n\nAtlas Assignment `2026-07-17-kungfu-dev-gate-latency-slo`.\n\n## Changes\n\n- derive proof ids and artifact names from a dedicated qualification identity\n- keep family lease, required-status snapshot, and queue-attempt binding in the current descriptor, delivery attempt, and cache-promotion authority\n- reject descriptor base/tree drift against the bound delivery source\n- add exact PR-to-merge-group reuse and projection-tamper fail-closed coverage\n- document the qualification/delivery identity boundary in the Gate qualification docs\n\n## Verification\n\n- `node --test` dev latency contract suite (87/87)\n- proof, Gate catalog, workflow authority, ARM64, and Shifu entry suites (65/65)\n- rebase-after-current-head focused proof/Gate/workflow suite (42/42)\n- staged pre-commit gate passed, including latency, invariant, documentation, schema, KFD, and Biome checks\n- `./shifu check:source` ran 720 tests: 709 passed, 10 declared skips, and one unrelated local environment failure because `pytest` is not on this Mac PATH; GitHub source install remains authoritative for that lane\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fixes the affected-native proof implementation to match the existing exact PR proof reuse contract without changing source, SDK, queue-admission, or release architecture semantics\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe affected-native qualification proof is provenance-bearing CI evidence. The new schema invalidates older proof artifact names and preserves exact source/plan/toolchain/SDK checks plus an independently sealed family delivery binding. No publication credential or release workflow changes.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-28T18:20:38Z",
          "mergedAt": "2026-07-28T21:21:09Z",
          "additions": 375,
          "deletions": 94,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1792,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1792",
          "title": "docs(readme): simplify first-screen onboarding",
          "body": "## Summary\n\nSimplify the repository README's first-screen onboarding so a new reader sees\nthe product promise, intended first-release command, and availability boundary\nbefore release-governance detail.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Move the intended `kungfu run agent` path and truthful `Coming soon` boundary\n  into the opening screen.\n- Place the first-release outcomes and user value before the Agent Supply Chain\n  architecture.\n- Move trademark activation, Release Passport, and installed release-verifier\n  detail into `Project status` without changing those claims.\n- Preserve the managed auditable-demo block byte-for-byte.\n\n## Verification\n\n- `./shifu docs context ... --budget 66560 --route kungfu-documentation-control-agent --json`\n  returned a complete projection with no omissions.\n- The managed demo block SHA-256 is unchanged:\n  `1c97e97ae58d85061d29682c3289891b8561291ef587bdd7760354bff09e3614`.\n- `./shifu docs:check`\n- `./shifu docs:prose:required`\n- `./shifu docs final-ready --since HEAD^ --json` returned the expected\n  mixed-review obligation with receipt\n  `sha256:59328e3938c9c63200118243bcc19dbd45ae96c8166f0b0480a36d4c9b2814b3`.\n- The commit hook ran the staged source checks.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This documentation-only change reorders existing onboarding and qualification copy without changing an architecture, runtime, or release contract.\"\n}\n-->\n\n## [Evolution Map](../docs/evolution/README.md) impact\n\nEvolution impact: none\n\nThe change does not add an abstraction, authority transition, or historical\nclaim.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe README still carries the same Kungfu/UNGFU naming boundary, Alpha activation\nrequirements, release-verifier commands, exact retained evidence, and explicit\nnon-claims. Those details move later in the page; the managed evidence block is\nbyte-identical.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T21:16:24Z",
          "mergedAt": "2026-07-28T21:32:45Z",
          "additions": 61,
          "deletions": 60,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1783,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1783",
          "title": "fix(ci): harden merged rename evidence",
          "body": "## Summary\n\nHarden the rename-lineage repair merged in #1782 so complexity evidence remains fail-closed across the full history from the exact measured baseline.\n\n#1782 fixed the immediate #1771 post-merge regression, but its history scan retained two bypass edges: it still supplemented evidence from the mutable `origin/HEAD` merge base, and it filtered out delete/add records. A renamed hotspot could therefore be deleted and recreated at the same path while still inheriting the old grandfathered budget.\n\n## Related issue\n\nAtlas Assignment `2026-07-17-kungfu-dev-gate-latency-slo`.\n\n## Changes\n\n- require the rename-evidence base to be the exact 40-hex complexity baseline ref\n- remove the mutable protected-head supplement now that merged history is reconstructed from the baseline\n- compose per-commit Git rename records in topological order\n- include deletion and addition records and invalidate inherited lineage on delete or same-path re-add\n- retain fail-closed treatment for one-to-many splits, new helpers, threshold crossings, and malformed baseline authority\n- extend regression coverage for chained renames, mutable protected refs, and delete/re-add invalidation\n\n## Verification\n\n- `node --test scripts/code-complexity-budget.test.mjs` (14/14)\n- `node scripts/code-complexity-budget.mjs` (`pass: kungfu.code-complexity-budget-report/v1` against current dev including #1782)\n- `npx --no-install biome check scripts/code-complexity-budget.mjs scripts/code-complexity-budget.test.mjs`\n- `git diff --check`\n- repository staged pre-commit gate passed on the original patch, including latency, invariant, documentation, schema, KFD, and Biome checks\n- `./shifu check:source` reached 723 tests: 712 passed, 10 declared skips, and one local environment failure because `pytest` is not on this Mac PATH; the code-complexity gate itself passed and GitHub source install is authoritative for that lane\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This closes fail-open edges in the merged complexity rename-lineage repair without changing architecture semantics, budget thresholds, waivers, classifications, or release intent\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change hardens source-acceptance provenance for refactored files. It does not change credentials, publishing, deployment, budgets, waivers, or protected baseline authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-28T19:29:01Z",
          "mergedAt": "2026-07-28T21:43:41Z",
          "additions": 51,
          "deletions": 44,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1796,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1796",
          "title": "fix(ci): cancel doomed parallel gate runs",
          "body": "## Summary\n\nOverlap dev source acceptance with native qualification lanes and cancel the current workflow run when source acceptance fails.\n\n## Verification\n\n- `./shifu check:source`\n- `node --test scripts/affected-native-proof.test.mjs scripts/check-kungfu-gate-catalog.test.mjs`\n- workflow authority, publication, semantic amplification, complexity, and diff checks\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded CI scheduling change preserves existing gate authority and does not alter an architecture contract\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T22:09:42Z",
          "mergedAt": "2026-07-28T22:35:44Z",
          "additions": 77,
          "deletions": 28,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 177,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/177",
          "title": "docs(evidence): cross-link public evidence surfaces",
          "body": "## Summary\n\nCross-link the bounded bootstrap interpretation with the maintained public dogfood evidence chain.\n\n## Changes\n\n- Link the bootstrap evidence page to the rolling dogfood record with an explicit causality boundary.\n- Add the bounded bootstrap interpretation beside the Agent Builders human and machine dogfood links.\n- Mirror both relationships in machine-readable evidence and enforce them in site checks.\n\n## Verification\n\n- corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change only adds navigation and explicit claim boundaries to existing public evidence surfaces; the full site build and checks passed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-28T22:22:59Z",
          "mergedAt": "2026-07-28T22:41:57Z",
          "additions": 32,
          "deletions": 0,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 228,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/228",
          "title": "docs(dogfood): link bounded bootstrap interpretation",
          "body": "## Summary\n\nLink the rolling public dogfood record to its bounded first-party bootstrap interpretation without expanding the evidence claim.\n\n## Changes\n\n- Add a related interpretation panel to the dogfood page.\n- Publish the relationship and its claim boundary in dogfood-evidence.json.\n- Enforce the human and machine-readable contracts in site checks.\n\n## Verification\n\n- corepack pnpm@11.9.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/\n- corepack pnpm@11.9.0 run build\n- corepack pnpm@11.9.0 run check\n\n## Governance risk check\n\nThis change only adds navigation and explicit claim boundaries to existing public evidence surfaces. It does not change package, release, or production authority. The full site build and checks passed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Machine-readable evidence preserves the interpretation boundary",
          "author": "dongkeren",
          "createdAt": "2026-07-28T22:23:10Z",
          "mergedAt": "2026-07-28T22:41:58Z",
          "additions": 28,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1786,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1786",
          "title": "fix(release): require final build controller evidence",
          "body": "## Summary\n\nReplace the stale Alpha branch requirement for the aggregate `build` context with the exact GitHub Actions controller evidence that the current Buildchain v3 workflow emits.\n\n## Changes\n\n- require `build / Finalize build controller evidence` from GitHub Actions app 15368\n- pass the same exact context to Buildchain release-candidate promotion\n- refresh release rehearsal, workflow authority, publication registry, and semantic projections\n- preserve DCO `signoff` and Buildchain `validate` requirements unchanged\n\n## Verification\n\n- live Alpha ruleset readback confirmed the previous contract was still active\n- recent real Alpha Build check run confirmed the exact context and app id\n- focused ruleset/release/publication tests passed 29/29\n- full `./shifu check:source` passed with the pinned source toolchain\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This operational repair aligns protected-branch status-check identity with the already reviewed Buildchain v3 controller output; it does not alter an architecture decision.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo credentials are added. The change narrows acceptance to one exact GitHub Actions app and controller check context.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Focused regression coverage updated\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI0LWJ1aWxkY2hhaW4tbGludXgtZ2l0aHViLWF0dGVzdGF0aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJiOTRlMDAxNWE4M2EzOGQ5ZTZiN2Q3NzU4NTY2Y2NjMDgyNDFjODk2IiwicHVsbFJlcXVlc3RIZWFkIjoiZjY4MWE1ZDA1MTJhOGY2ZTVhODExOTM5ZTFhN2E2OWU4NGY5NzU2MiIsInJlcGxheWVkQ2FuZGlkYXRlIjoiYTBkY2QyMTNhNGJjYmQ3NzVmZjhlNzYxODE4YWQ5YWMzODc5MjdiNiIsInJlcGxheWVkVHJlZSI6IjE3NzgxY2JhOGIzMTAwMWM0OTBkZjAzZTlhMzFiZmJlNDc1MTEwNDEiLCJxdWV1ZUF0dGVtcHQiOiJmNjgxYTVkMDUxMmE4ZjZlNWE4MTE5MzllMWE3YTY5ZTg0Zjk3NTYyQGI5NGUwMDE1YTgzYTM4ZDllNmI3ZDc3NTg1NjZjY2MwODI0MWM4OTYiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6OTIwNzAxMzVlYjJmODEyM2JjNzQ1NGM1MTQxZmYyYmYyYWE5YTk5MzY4MjRlNmQ5OWMyYjYxMGM5Yzg2MWZiYSIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjkyMDcwMTM1ZWIyZjgxMjNiYzc0NTRjNTE0MWZmMmJmMmFhOWE5OTM2ODI0ZTZkOTljMmI2MTBjOWM4NjFmYmEiLCJzaGEyNTY6ZTYwMGMwNmUwMjA1ODc1MGNkZDE1YjQyYmU3YTdlYTkxYmU5MDgzNmZmMjI0MGIzNGFjOTMxZGNmMDQ0ZThkOCJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6ZWQ5MTkxNWRmMjg3MjZhYzlmOTBiODdhMDRjODYwYjQ1NWNkMTAzZDVlOGNkNjljM2IzMGIwOTE5N2RjMjQzYSJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T20:17:19Z",
          "mergedAt": "2026-07-28T23:07:41Z",
          "additions": 35,
          "deletions": 36,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2021,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2021",
          "title": "fix(governance): fail closed on mutation 404",
          "body": "## Summary\n- treat GitHub API 404 as resource absence only for read operations\n- fail closed immediately when POST, PUT, PATCH, or DELETE returns a hidden 404\n- cover every mutation method with a regression test\n\n## Evidence\n- `node --test tests/github-governance-authority.test.mjs` (29/29)\n- `git diff --check`\n- `pnpm check` reached 951/953; the two macOS artifact-signing fixture failures reproduce unchanged on the pre-patch v3 worktree (`signing artifact ... must stay inside the build workspace`)\n\n## Dogfood trigger\nA real ruleset rollout run under a push-only identity received GitHub hidden 404. The prior client classified it as absence and only failed at post-change read-back; this change preserves 404 absence handling for GET while surfacing mutation authorization failures at the exact provider call.",
          "author": "dongkeren",
          "createdAt": "2026-07-28T23:23:22Z",
          "mergedAt": "2026-07-28T23:27:00Z",
          "additions": 21,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 178,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/178",
          "title": "Release production from 9821359e4a0d",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `9821359e4a0d78f9f8e66fc49ff85822bb2767a6`\n- Artifact hash: `b8ac28cb7b577ade7082d81500b4bbbd81c1a1b12e91a445c2d0109fc190df95`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30405493954)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-9821359e4a0d`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-28T22:44:23Z",
          "mergedAt": "2026-07-28T23:37:24Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 229,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/229",
          "title": "Release production from 73fd80cb5b61",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `73fd80cb5b61cd7d69861a4954fa072a13841c6a`\n- Artifact hash: `6d593860c9c6177a3531d2a729e8d2b2338bcb0241782c42f60353af4bddd531`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/30405494881)\n- Required label: `buildchain-release`\n- Release branch: `release/production-73fd80cb5b61`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-28T22:53:34Z",
          "mergedAt": "2026-07-28T23:44:21Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1801,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1801",
          "title": "fix(project-cut): match settlement provider roots",
          "body": "Supersedes #1797. Live `dev/v4/v4.0` advanced with the overlapping affected-native provider-head repair, so this successor is rebuilt linearly from `223592b190578e3ed19d12f2df4ef36bc3887bf7` and retains only the unsettled publication fix.\n\n## Summary\n\n- match Project Cut `episodeDelta.nativeRoots` against sealed Episode provider roots\n- keep request and tracked Episode paths keyed by the existing semantic root\n- make the publication fixture exercise distinct semantic and provider roots\n- preserve the already-merged affected-native provider-head authority unchanged\n\n## Verification\n\n- focused publication/affected-native/queue contracts: 34/34 passed\n- complexity budget: `verdict=pass`, `blocking=[]`\n- `./shifu check:source`: 733 tests (723 passed, 10 skipped, 0 failed)\n- Python agent state: 40/40; runtime upgrade: 116/116; desktop update: 69/69\n- staged pre-commit gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Restore the existing settlement-publication contract across the already distinct Episode semantic and provider identities without changing either root algorithm or authority boundary.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change only repairs identity matching inside the existing protected settlement projection.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWdvLWZhbWlseS1jb250aW51b3VzLWRlbGl2ZXJ5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtZ28tZmFtaWx5LWdpdC1zZXR0bGVtZW50LXB1YmxpY2F0aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiIyMjM1OTJiMTkwNTc4ZTNlZDE5ZDEyZjJkZjRlZjM2YmMzODg3YmY3IiwicHVsbFJlcXVlc3RIZWFkIjoiZTQzMmZjMDJkZWRmZmYwN2VkOWEwMjFjNmYwZGMyNjE0NjYwMWZiMiIsInJlcGxheWVkQ2FuZGlkYXRlIjoiOGI2NWY1MTNjMWFhNjE1OGRhODNjYWRjNjYwOGI4OWFmMThjZjVlYiIsInJlcGxheWVkVHJlZSI6IjFkMGFjNzhjOTFkMWU1MjQ1NjNiNDQ0OWY0NjQwZTgzZTUyNmEyNDAiLCJxdWV1ZUF0dGVtcHQiOiIxODAxQDIyMzU5MmIxOTA1NzhlM2VkMTlkMTJmMmRmNGVmMzZiYzM4ODdiZjciLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6N2VlNzJiYmMzYTlhMDg3NjU4OTM3NDRlY2Y0YmJlOGRlNGUzMDk3N2Q5NjU5OTQxNTg0ZjM4MGRmNTJlZDI5MSIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjdlZTcyYmJjM2E5YTA4NzY1ODkzNzQ0ZWNmNGJiZThkZTRlMzA5NzdkOTY1OTk0MTU4NGYzODBkZjUyZWQyOTEiLCJzaGEyNTY6YTE1NjhlYzM0NzI4Y2YwMTA1ZWRjMWQ5NjRjYzljMTJiMzFhZDk1MjcxOGU4ZTI3NTU4ZWU0ZTBmNmQxYjk3MCIsInNoYTI1NjpkMjc2YjRlZmRiYmNhYThlNWIzNWIxNGY0ODQ5ODg0YzZmM2Y4ZDlmNDBiMWFhYWE4NGI1MTc0ZDVhYWZkNjE1Il0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZWNhYzY3YmNlYmZhZTNiZiIsImxlYXNlUm9vdCI6InNoYTI1NjoyYTAwNDk0MWUxNTVhZmZkMDZiNTQzMTE0MDUzODliMTEzZGM3ZGZhZmI3ODc2OWEzMjhmYjVjNTMzODQyNmU3In0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-28T23:36:37Z",
          "mergedAt": "2026-07-28T23:45:16Z",
          "additions": 24,
          "deletions": 13,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 230,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/230",
          "title": "fix(ci): collect governance receipt on production pushes",
          "body": "## Summary\n\n- classify `push` events on `refs/heads/main` as production governance requests\n- select the stable Buildchain runtime and stable contract lock for the same release path\n- enforce all three predicates in the infra contract check\n\n## Failure evidence\n\nProduction run https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/30408932685 failed closed before apply because `github-governance-receipt-json` was empty. The reviewed release PR had already merged, so rerunning the unchanged workflow could not repair the event-classification gap.\n\n## Validation\n\n- `node scripts/check-infra-outputs.mjs`\n- workflow YAML parse\n- `corepack pnpm run build`\n- `corepack pnpm run check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-28T23:52:11Z",
          "mergedAt": "2026-07-29T00:05:33Z",
          "additions": 19,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1799,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1799",
          "title": "perf(ci): classify SDK-neutral workflow changes",
          "body": "## Summary\n\nAvoid rebuilding the four-language SDK when an affected-native workflow edit changes only source-acceptance scheduling or unrelated jobs. Preserve fail-closed qualification for every execution, planner, runner, dependency, and SDK-boundary change.\n\n## Related issue\n\nDev required Gate latency SLO closure.\n\n## Changes\n\n- compare a build-free semantic projection of the affected-native workflow at base and head\n- exclude only the source-acceptance scheduling edge and unrelated jobs from SDK impact\n- retain all candidate planning and affected-native execution fields through SDK qualification\n- fail closed when the workflow or qualification boundary cannot be parsed\n- repair the delivery-attempt fixture so replay identity matches the merge-group head\n\n## Verification\n\n- `./shifu check`\n- `node --test scripts/run-core-affected-native.test.mjs scripts/candidate-timeline-events.test.mjs`\n- `./shifu core:affected -- --self-test`\n- historical replay of `bd5c1316e5`: SDK neutral while preserving 12 native closure components and the `embedded-sqlite` profile\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded CI planner optimization preserves the existing qualification authority and fail-closed SDK boundary.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T23:33:44Z",
          "mergedAt": "2026-07-29T00:16:08Z",
          "additions": 295,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2022,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2022",
          "title": "fix(signing): verify standalone Mach-O notarization",
          "body": "## Summary\n\n- retain exact Developer ID, Team ID, hardened runtime, and notarytool Accepted verification for standalone Mach-O artifacts\n- stop applying app-bundle spctl assessment semantics to a raw executable\n- record the online standalone notarization ticket honestly in provider evidence and generated docs\n\nApple documents that notarization tickets are created for standalone binaries but cannot currently be stapled to them: https://developer.apple.com/documentation/security/customizing-the-notarization-workflow\n\n## Verification\n\n- `corepack pnpm run check` (953 tests, workflow validation, generated site check, 6 action bundles)\n- `bash -n scripts/sign-macos-mach-o-request.sh`\n- `node --test tests/native-artifact-signing-authority.test.mjs`\n\n## Contract impact\n\nThe request and result schemas are unchanged. The macOS provider verification vocabulary replaces the false `gatekeeper-execute` claim with `standalone-notary-ticket-online`. App/package credential-island behavior is unchanged.\n\n## Residual risk\n\nA protected-authority dogfood rerun is still required to prove immutable signed-result import against the live Apple service.\n\n## Governance checklist\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] Provider CLI behavior is fail-closed and documented\n- [x] Release evidence remains source-, runtime-, and artifact-bound\n- [x] No hosted-service, package identity, or branding change",
          "author": "dongkeren",
          "createdAt": "2026-07-29T00:13:52Z",
          "mergedAt": "2026-07-29T00:19:03Z",
          "additions": 34,
          "deletions": 19,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2023,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2023",
          "title": "chore(signing): advance artifact signing authority",
          "body": "## Authority promotion\n\nAdvance the protected, channel-neutral artifact-signing authority from `ad4942fbf8130c0e7c28d6df28ece517a873859b` to the current reviewed `dev/v3/v3.0` head.\n\nThe immediate correction is PR #2022: standalone Mach-O notarization now retains strict codesign, Team ID, hardened runtime, and exact-submission `notarytool` Accepted verification without misapplying app-bundle `spctl` semantics. The promotion also carries the intervening reviewed same-line development commits through the established dev-to-authority path.\n\n## Evidence\n\n- PR #2022 merged through the protected dev merge queue at `558b5bed78f307796b94a5ad0784c38ea8381231`\n- local `corepack pnpm run check`: 953 tests, workflow validation, generated site integrity, and 6 action bundles passed\n- Agent Hub Demo run 30409715661 and authority run 30409817741 proved Apple Accepted submission `022a8664-4b41-43ee-9c03-5253c925d4b0`; the only failure was the obsolete app-only `spctl` assertion\n- native dogfood Finding `sha256:e250f6a502d08331158b5b2504e64796aa3f404355b634d6b9805c7fdbf6c796` and owned Issue `sha256:6b1d84c7c2396a556a1a1391cfc0d25b49500935a983b6de136fec68e649aeac` retain the product signal\n\n## Safety\n\n- no environment, secret, certificate, or consumer configuration changes\n- the formal authority still uses `buildchain-artifact-signing`\n- the authority branch remains protected against deletion and non-fast-forward updates\n- Agent Hub Demo must pass a fresh protected-authority dogfood before the temporary HK source environment can be retired",
          "author": "dongkeren",
          "createdAt": "2026-07-29T00:20:00Z",
          "mergedAt": "2026-07-29T00:21:47Z",
          "additions": 864,
          "deletions": 214,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 231,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/231",
          "title": "fix(ci): keep governance runtime out of event override",
          "body": "## Summary\n- keep the exact governance runtime SHA inside the fresh receipt evidence\n- select the official `v3` channel for normal main/release events\n- prevent a governance runtime SHA from becoming a forbidden non-dispatch Buildchain override\n\n## Evidence\n- failed main run: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/30410068703\n- fresh governance receipt succeeded before the runtime override was rejected\n- `node scripts/check-infra-outputs.mjs`\n- workflow YAML parse\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-29T00:09:34Z",
          "mergedAt": "2026-07-29T00:23:11Z",
          "additions": 9,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1798,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1798",
          "title": "feat(docs): govern evolution era candidates",
          "body": "## Summary\n\nAdd a governed Era Candidate lane to the Evolution Map so agents can capture a possible abstraction jump before a maintainer decides whether a canonical Era transition has occurred.\n\nCandidates are immutable, evidence-bearing, and intentionally non-authoritative. They cannot allocate an Era sequence, alter current authority, or promote themselves.\n\n## Related issue\n\nNative Assignment 2026-07-29-kungfu-evolution-era-candidates.\n\n## Changes\n\n- extend the Evolution Map contract and projections with a separate candidate ledger\n- add the dry-run-first `./shifu evolution:candidate -- --input FILE` authoring route\n- enforce content-addressed immutable revisions, bounded lifecycle transitions, evidence and counterevidence, and exact promotion authorization\n- keep candidates outside canonical Era and Stage authority until an authorized promotion links both records\n- document when agents should open, advance, fold back, reject, or propose promotion of a candidate\n- add contributor and pull-request guidance plus positive and fail-closed tests\n\n## Verification\n\n- `./shifu check:source` on `2be5e87165a62d40d55a9ecdf25288ab725f20c3`\n- source acceptance: 733 tests, 723 pass, 10 expected skips, 0 fail\n- documentation contract: 110 pass, 0 fail; 429 Markdown files checked\n- Python suites: 40 pass and 116 pass; desktop adapter: 69 pass\n- tooling type check and Biome passed\n- Evolution Map candidate suite includes authority isolation, path binding, duplicate evidence, revision continuity, promotion authorization, immutability, dry-run, exclusive write, and stale-root rejection\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019fa773-aae4-7f50-80a5-ce53b08490d2\"],\n  \"summary\": \"Extend the implemented first-party Evolution Map with a governed, non-authoritative Era Candidate lifecycle.\",\n  \"verification\": [\"./shifu check:source\", \"scripts/evolution-map.test.mjs\"]\n}\n-->\n\n## [Evolution Map](../docs/evolution/README.md) impact\n\nEvolution impact: extends\n\nThis extends the current Native Work Control and recursive dogfood Stage. It adds a governed observation lane for possible future Era transitions, but does not open, settle, or supersede an Era or Stage.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-28T23:30:14Z",
          "mergedAt": "2026-07-29T00:26:29Z",
          "additions": 1291,
          "deletions": 35,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2024,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2024",
          "title": "docs(runners): record Linux burst qualification",
          "body": "## Summary\n- retain the ten source-bound Linux CodeBuild qualification jobs\n- record queue p95, concurrency, conservative all-run spend, and zero-compute cleanup\n- add the deterministic Buildchain phase verification receipt\n\n## Verification\n- `node scripts/aws-runner-burst.mjs verify-linux --input evidence/aws-us-elastic-runner-burst-plane/linux-codebuild-qualification-input.json`\n- `node --test tests/aws-runner-burst.test.mjs`\n- `pnpm run test:unit`\n- `git diff --check`\n\n## Provider state\n- CodeBuild webhook deleted after the tenth qualifying job\n- no in-progress CodeBuild execution\n- no card-owned EC2 instance\n- AWS Billing ingestion still lagged; the receipt uses the conservative duration-derived USD 25.798 upper bound and requires final line-item reconciliation",
          "author": "dongkeren",
          "createdAt": "2026-07-29T00:20:44Z",
          "mergedAt": "2026-07-29T00:28:27Z",
          "additions": 217,
          "deletions": 9,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 61,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/61",
          "title": "fix(signing): verify standalone Mach-O notarization",
          "body": "## Summary\n\nVerify the final standalone macOS Mach-O with strict `codesign` validation and the immutable Buildchain result checks for Developer ID, hardened runtime, accepted notarization, and the online standalone ticket. A bare Mach-O is not an app bundle, so `spctl --assess --type execute` rejects it even when its code signature is valid.\n\nThis consumes the corrected generic Buildchain authority semantics delivered by kungfu-systems/buildchain#2022 and keeps provider credentials and orchestration out of the consumer repository.\n\n## Validation\n\n- [x] `npm test`\n- [x] `npm run runtime100`\n- [x] `npm run build`\n- [x] Commits are signed off (DCO)\n\nAlso passed `npm run check`, `node --test test/signing-dogfood.test.js`, and `git diff --check`.\n\n## Contract and provider governance\n\n- [x] No credentials, tokens, secrets, private logs, or production data\n- [x] Provider APIs, CLIs, telemetry, billing, quota, or usage attribution are unchanged or explained\n- [x] Official hosted or managed services are unchanged or explained\n- [x] Official branding, package names, release identity, or domains are unchanged or explained\n- [x] Release evidence, provenance, package publishing, or deployment surfaces are unchanged or explained\n- [x] Generic KFD or Buildchain friction is linked to an upstream issue rather than copied locally\n- [x] The public claim boundary remains accurate\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T00:29:46Z",
          "mergedAt": "2026-07-29T00:31:29Z",
          "additions": 20,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1806,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1806",
          "title": "chore(ledger): publish batch go-family-wave-1-successor-2",
          "body": "Kungfu-Settlement-Batch: sha256:f466df51e1259a944a0cd4e94a27b091ea4137d6c3b170dcfb5621ba9c48c9e9\nKungfu-Settlement-Manifest: sha256:824424f7f10fc4907ce537da2932459dc979f85ec681c37139a3734d78cb509f\nKungfu-Generated-By: kungfu-settlement-publication/v1\n\nThis protected projection does not decide Work Control completion or block runtime continuation.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Publish the already sealed Wave 1 Episode and settled Project Cuts as a bounded content-addressed Git projection without changing architecture contracts or Work Control authority.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWdvLWZhbWlseS1jb250aW51b3VzLWRlbGl2ZXJ5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtZ28tZmFtaWx5LWdpdC1zZXR0bGVtZW50LXB1YmxpY2F0aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiI2ZmQyZDU0NTVhZTA5OTAyMGI4MGRkMDcxZDBhMjcxMTJkMmZiYTIwIiwicHVsbFJlcXVlc3RIZWFkIjoiYzE2ZGZmYmQ1N2IwNDg2OWM5M2NiOThlNDNlOTEyNDVjMTk0Yjc4MSIsInJlcGxheWVkQ2FuZGlkYXRlIjoiY2E1MWM3Y2VjZjQwNDJhYjI4OWQyMGQzMzEzYmI0YjVjYTZhZTY4NyIsInJlcGxheWVkVHJlZSI6IjdiYjQ0YWY0Zjk2ZGEzYjU5NjU5MzhmNDNkYTEzMWU2Mjc4ZTZkMjEiLCJxdWV1ZUF0dGVtcHQiOiJjMTZkZmZiZDU3YjA0ODY5YzkzY2I5OGU0M2U5MTI0NWMxOTRiNzgxQDZmZDJkNTQ1NWFlMDk5MDIwYjgwZGQwNzFkMGEyNzExMmQyZmJhMjAiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6MjMwZDM2ZDQxZmNjNzY3MDVjNzcyMzgwNWJkNTdiY2MzYTJhNGM1NDU2MGNmMmE5MzIyZmVlY2IzYjllMzUxNiIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjIzMGQzNmQ0MWZjYzc2NzA1Yzc3MjM4MDViZDU3YmNjM2EyYTRjNTQ1NjBjZjJhOTMyMmZlZWNiM2I5ZTM1MTYiLCJzaGEyNTY6ZDI3NmI0ZWZkYmJjYWE4ZTViMzViMTRmNDg0OTg4NGM2ZjNmOGQ5ZjQwYjFhYWFhODRiNTE3NGQ1YWFmZDYxNSJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2VjYWM2N2JjZWJmYWUzYmYiLCJsZWFzZVJvb3QiOiJzaGEyNTY6OGEwYzdkZmY0ZTBiOGQ2Y2JkNTkxYjVkNjkzY2JkYjViNDQ4ZGJlOGQ5Mjc4ZTBiNDVhOWRlOTAwMWU3NmM5OSJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T00:31:39Z",
          "mergedAt": "2026-07-29T00:40:04Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2025,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2025",
          "title": "feat(runners): add Windows EC2 JIT burst provider",
          "body": "## Summary\n- add an explicit repository-scoped Windows EC2 one-job JIT runner preset and provenance verifier\n- add a zero-warm-capacity CloudFormation control plane with SSM one-read JIT handoff, no ingress, a five-minute reaper, and a USD 40 budget kill switch\n- pin GitHub Actions Runner and PortableGit archives, verify the Microsoft Build Tools bootstrap signature, and retain redacted lifecycle evidence\n\n## Safety boundaries\n- trusted workflow dispatch only; fork PRs never select the provider\n- no signing, publication, static AWS, SSH, or long-lived GitHub credential reaches an instance\n- IMDSv2, encrypted delete-on-termination root volume, instance-initiated terminate, and max three-hour lifetime\n- six accepted instances plus a two-instance race envelope is USD 34.80 at the live USD 1.45/hour rate\n\n## Verification\n- `pnpm run check`\n- `node --test tests/aws-windows-jit.test.mjs tests/build-surface.test.mjs`\n- `aws cloudformation validate-template --template-body file://infra/aws-us-elastic-runner-burst-plane/windows-jit.template.yml`\n- deterministic bootstrap render contains no unresolved placeholder or GitHub credential marker\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-29T00:42:07Z",
          "mergedAt": "2026-07-29T00:50:03Z",
          "additions": 1458,
          "deletions": 35,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 232,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/232",
          "title": "Release production from 3e0d7b433b84",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `3e0d7b433b84b48b73aa53c8447261752c1dac91`\n- Artifact hash: `f94593e8a763ced0ee590602b32c8d29bafe2c597a359df319657ec1ac4faf6c`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/30410989474)\n- Required label: `buildchain-release`\n- Release branch: `release/production-3e0d7b433b84`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-29T00:37:11Z",
          "mergedAt": "2026-07-29T00:53:36Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1808,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1808",
          "title": "feat(shifu): define qualified Core artifact contract",
          "body": "## Summary\n\nDefine a versioned, fail-closed Qualified Assignment Core artifact and qualification contract.\n\n## Changes\n\n- add strict v1 artifact and qualification receipt schemas\n- bind producer/target, native build, payload, contract, and promotion identities\n- verify canonical roots, safe payload paths/symlinks, clean targets, and one active protected authority\n- keep GitHub cache and workflow artifacts replaceable and non-authoritative\n- document KFD-1 version impact and the Shifu/Buildchain/Assignment/CAS boundaries\n\n## Verification\n\n- ./shifu check:shifu-cache-contract\n- ./shifu exec -- node --test scripts/check-shifu-cache-contract.test.mjs (36/36)\n- ./shifu check:source (741 Node tests; 731 pass, 10 environment skips; 40 Work Control; 116 upgrade; 69 desktop)\n- ./shifu build:core\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Complete the bounded qualified Assignment Core artifact contract and fail-closed verifier stage\",\n  \"verification\": [\"Shifu cache contract check\", \"36 focused conformance tests\", \"source acceptance\", \"Core build\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR defines pre-release provenance and qualification contracts only. It does not produce, upload, promote, or release a native payload.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LXF1YWxpZmllZC1hc3NpZ25tZW50LWNvcmUtY2FjaGUtZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtYXJ0aWZhY3QtY29udHJhY3QiLCJkZWxpdmVyeUNsYXNzIjoibm9uLW5hdGl2ZS1mYXN0IiwiZGV2SGVhZCI6ImQxZThkNTM2ODk1Mzg1ZTIxOTQxZTZiNGM2NjA5MzNkZDljNzljMjgiLCJwdWxsUmVxdWVzdEhlYWQiOiIxOTdmYjU2NjIwNjA5N2FlMmJhNjA1YWZkYTM2N2M5ZTQ5NGVjNTQ3IiwicmVwbGF5ZWRDYW5kaWRhdGUiOiI5NTg1NzE5NGZiYmRmNjYwNDA4Yzg4ZTFlYmQwNjljNjMzYjMxYTg5IiwicmVwbGF5ZWRUcmVlIjoiNmY3YTk5ZWY2M2JmNDIxMDFkOTkxMzk0NjllZTNmMDU2MjE3MDhlOCIsInF1ZXVlQXR0ZW1wdCI6IjE5N2ZiNTY2MjA2MDk3YWUyYmE2MDVhZmRhMzY3YzllNDk0ZWM1NDdAZDFlOGQ1MzY4OTUzODVlMjE5NDFlNmI0YzY2MDkzM2RkOWM3OWMyOCIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjphZjRiNjFiZTkxYmMxOGFjNzdmMTRlNWRhNDcxZTMxNzcxOWQ5ODhkOGU5M2NmYWRkM2RlNDI0NzI4ZGM4OTFjIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6M2ZmYmEzZjM0ODBiODBlMzA3MmNjOTFhZDdkZDBmNDE3YjU1OTI3ZDMwZmIwZmE5OGRlYjgwNDMxOWI2NzM3ZCIsInNoYTI1NjphZjRiNjFiZTkxYmMxOGFjNzdmMTRlNWRhNDcxZTMxNzcxOWQ5ODhkOGU5M2NmYWRkM2RlNDI0NzI4ZGM4OTFjIl0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvMjJjODRiMzE3MDEwNzllMiIsImxlYXNlUm9vdCI6InNoYTI1Njo5MTA5NzRhNzc0YzU2ODg0ODM3NzIzZjc0MzI0NmM0NGI5ZjgzOWRiNzE2M2U4ZmJhYTJlMmQzY2I5MGIwYTNiIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T00:48:43Z",
          "mergedAt": "2026-07-29T01:03:01Z",
          "additions": 1461,
          "deletions": 12,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1809,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1809",
          "title": "docs(shifu): close qualified Core artifact decision",
          "body": "## Summary\n\nClose the qualified Assignment Core artifact ADR after the protected implementation delivery merged in #1808.\n\n## Changes\n\n- mark the ADR implementation as implemented\n- bind implementation and closure evidence to merged PR #1808\n- record the independent maintainer review state\n- refresh generated ADR navigation projections\n\n## Verification\n\n- staged repository gate\n- deterministic documentation gate (118/118)\n- ADR authority audit (structural=0; stable-admitted=54)\n- implementation and closure evidence reachability fixtures\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Close the qualified Assignment Core artifact contract after protected implementation and qualification\",\n  \"verification\": [\"merged implementation PR #1808\", \"Shifu cache contract check\", \"36 focused conformance tests\", \"source acceptance\", \"Core build\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR records already-merged pre-release implementation evidence. It does not publish or promote payload bytes.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation projections regenerated\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LXF1YWxpZmllZC1hc3NpZ25tZW50LWNvcmUtY2FjaGUtZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtYXJ0aWZhY3QtY29udHJhY3QiLCJkZWxpdmVyeUNsYXNzIjoibm9uLW5hdGl2ZS1mYXN0IiwiZGV2SGVhZCI6IjU3NjI3OTgzZWQ2OTY0ZDFiNmE0YWNkOWFhODJmNTc2MzJmMjllYmUiLCJwdWxsUmVxdWVzdEhlYWQiOiIwMTEwYzNlNGI0N2Q3OGI5NWVjODNmMDI5MjBhZTkwNDIwMDg3YjhkIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiJiYTRmNDI0MWRlMDVhOGU0NWFlNDNkYzQwZGI1YjVmNzQxMjE4YmZiIiwicmVwbGF5ZWRUcmVlIjoiZTU0OGEwYjljMDU1YzJlN2MwYWExYTRkNjYyMTkyMzM4NjkzNWM2YiIsInF1ZXVlQXR0ZW1wdCI6IjAxMTBjM2U0YjQ3ZDc4Yjk1ZWM4M2YwMjkyMGFlOTA0MjAwODdiOGRANTc2Mjc5ODNlZDY5NjRkMWI2YTRhY2Q5YWE4MmY1NzYzMmYyOWViZSIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjozNDkxYmQyY2RmNDc1NzJhN2E5ZDMwZmI0OWZmZTVmNmQ3YjBlNTZlNGRjZDg3NjlkY2U3NGIxMTc4ZjUxYzlkIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6MzQ5MWJkMmNkZjQ3NTcyYTdhOWQzMGZiNDlmZmU1ZjZkN2IwZTU2ZTRkY2Q4NzY5ZGNlNzRiMTE3OGY1MWM5ZCIsInNoYTI1NjozZmZiYTNmMzQ4MGI4MGUzMDcyY2M5MWFkN2RkMGY0MTdiNTU5MjdkMzBmYjBmYTk4ZGViODA0MzE5YjY3MzdkIl0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvMjJjODRiMzE3MDEwNzllMiIsImxlYXNlUm9vdCI6InNoYTI1NjpkMTNhYmEwMGJhMWY5ZmY4OTg5ZDZiODU1MzI3MjRjYTBiZWUyNGI4ZTMwNDhhZWU4ZTU0OTEzZjExMDBkZTAwIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T01:08:36Z",
          "mergedAt": "2026-07-29T01:16:28Z",
          "additions": 6,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1811,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1811",
          "title": "fix(ci): preserve merged queue admission lease",
          "body": "Preserve the successful exact-head Queue admission lease after a normal merged dequeue, while retaining fail-closed revocation for every non-merged removal. Reuse one authoritative merge-queue removal observation across repair-marker, lease, and family settlement.\n\nValidation:\n- ./shifu exec node --test scripts/cancel-dequeued-merge-group-runs.test.mjs scripts/queue-admission-lease.test.mjs\n- ./shifu test:gate-latency\n- ./shifu check:gate-catalog\n- ./shifu check\n\nLive acceptance: the PR's post-merge dequeue run must report queueAdmissionLease.state=preserved and must not write a failure status to the exact PR head.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix preserves terminal merge-queue status semantics without changing an architecture contract\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T01:18:27Z",
          "mergedAt": "2026-07-29T01:36:31Z",
          "additions": 221,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1812,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1812",
          "title": "feat(ci): qualify Windows EC2 JIT burst runners",
          "body": "## Summary\n\nAdd the trusted-only consumer workflow and exact Windows runner-profile witness for the AWS US overflow plane. The workflow accepts six bounded operator slots (smoke, three full exact-source runs, cancellation cleanup, and timeout cleanup), requires a unique card-scoped JIT label, uses the reviewed Buildchain train, and carries no release, signing, publication, or deployment authority.\n\nThe new workflow is registered as a non-publication qualification surface in both closed-world authorities. The existing release-platform probe owns the Windows JIT profile witness so the source-tooling file budget remains closed.\n\n## Verification\n\n- staged repository gate: passed\n- `node --test scripts/buildchain-install.test.mjs scripts/check-kungfu-gate-catalog.test.mjs`: 33/33 passed\n- `node --test scripts/readonly-agent-bootstrap.test.mjs`: passed cold read-only discovery fixture\n- AWS CloudFormation stack: `CREATE_COMPLETE`\n- security group ingress: empty\n- reaper: enabled at `rate(5 minutes)` and dry invocation returned zero victims\n- repository self-hosted runners: 0 before qualification\n- Windows EC2 instances owned by this provider: 0 before qualification\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Implement the already-governed AWS US overflow qualification campaign without changing product architecture or release authority.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Regression tests added\n- [x] No release credentials or publication authority\n- [x] Exact-source and zero-idle cleanup boundaries retained\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T01:26:04Z",
          "mergedAt": "2026-07-29T01:41:16Z",
          "additions": 397,
          "deletions": 2,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2026,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2026",
          "title": "fix(runners): support modular AWS tools on Windows 2025",
          "body": "## Summary\n- import the modular AWS.Tools packages shipped by Windows Server 2025 AMIs\n- retain AWSPowerShell fallback for older Windows AMIs\n- lock the runtime contract in the Windows JIT provider test\n\n## Evidence\n- first bounded smoke instance exited before JIT consumption because Windows 2025 does not ship the legacy monolithic module\n- node --test tests/aws-windows-jit.test.mjs (8/8)\n- pnpm run test:unit (689/689)\n- pnpm run check:workflows\n- pnpm run check:site\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-29T01:53:44Z",
          "mergedAt": "2026-07-29T01:55:17Z",
          "additions": 13,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1807,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1807",
          "title": "fix(maintainability): close terminal review findings",
          "body": "## Summary\n\nClose the independent terminal-review findings against the maintainability closure with live exact-head evidence, native-state projection checks, bounded hotspot decomposition, and explicit protected-mainline budget semantics.\n\n## Changes\n\n- add terminal evidence v2 that compares retained delivery, review, Assignment, platform, artifact, and digest facts with live Git HEAD and the protected ref\n- fail closed when semantic-amplification projections disagree with sealed native Assignment closure\n- extract TUI control state, affected-native artifact lookup, and delivery evidence reconstruction into cohesive owners while preserving public exports and behavior\n- distinguish advisory code-length warnings from the protected-mainline hard budget and require independently signed exact exceptions for real crossings\n- expand negative coverage for stale or mixed source, review, Assignment, platform, artifact, waiver, and anti-gaming evidence\n\n## Verification\n\n- `node scripts/source-acceptance.mjs` at `a85f45a5e5448550fb44a1ab2fc0918857975de1`: pass\n- GitHub candidate CI run `30414929187` at the same exact head: success\n- source-acceptance contract suite: 728 passed, 10 declared skips, 0 failed\n- agent work state: 40 passed\n- runtime upgrade control plane: 116 passed\n- desktop update adapters: 69 passed\n- complexity report: pass, no blocking findings\n- semantic amplification: pass, 6 families, 77 surfaces, 0 issues\n- cold read-only discovery fixture: pass with zero writes\n- TypeScript tooling check, Biome, diff hygiene, and repository pre-commit gates: pass\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This remediates review findings in existing maintainability governance and evidence projection without changing architecture decisions, release intent, public APIs, or product semantics\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change strengthens exact-source evidence and protected-mainline governance. It does not alter credentials, publishing behavior, deployment, or public release policy.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T00:44:05Z",
          "mergedAt": "2026-07-29T02:02:15Z",
          "additions": 2509,
          "deletions": 1026,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2027,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2027",
          "title": "fix(runners): harden Windows JIT runtime contract",
          "body": "## Summary\n- require the complete GitHub JIT scheduling label set: self-hosted, Windows, X64, and the card label\n- install pinned PowerShell 7.6.4 before the one-job runner starts\n- verify SHA256 and Microsoft Authenticode, and retain the PowerShell identity in lifecycle evidence\n- refresh generated site projections\n\n## Runtime evidence\n- run 30415432378 proved one-job JIT registration, exact job selection after the complete label set, immediate SecureString deletion, S3 lifecycle/diagnostic upload, runner auto-removal, and instance termination\n- the job failed closed at pwsh: command not found, which this patch addresses\n\n## Verification\n- pnpm run test:unit (689/689)\n- pnpm run check:workflows\n- pnpm run generate:site && pnpm run check:site\n- node --test tests/aws-windows-jit.test.mjs (8/8)\n- Prettier check and git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-29T02:10:47Z",
          "mergedAt": "2026-07-29T02:12:32Z",
          "additions": 88,
          "deletions": 22,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2028,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2028",
          "title": "fix(runners): preserve Windows tools ahead of PortableGit",
          "body": "## Summary\n- expose only PortableGit cmd on the Windows JIT runner PATH\n- keep Windows system tar ahead of PortableGit POSIX compatibility tools\n- lock the non-shadowing contract in tests and refresh site projections\n\n## Runtime evidence\n- run 30416220380 reached pwsh, Rust, Buildchain checkout, source checkout, MSVC, CMake, and shifu doctor\n- install then failed because PortableGit /usr/bin/tar interpreted a Windows C: path as a remote host\n- JIT parameter deletion, one-job exit, S3 evidence, runner removal, and instance termination all succeeded\n\n## Verification\n- node --test tests/aws-windows-jit.test.mjs (8/8)\n- pnpm run generate:site && pnpm run check:site\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-29T02:24:05Z",
          "mergedAt": "2026-07-29T02:25:37Z",
          "additions": 11,
          "deletions": 9,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1813,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1813",
          "title": "fix(ci): execute dequeue from current protected base",
          "body": "## Summary\n\n- execute the dequeue controller from the current protected dev/v*/v* base ref\n- never execute pull-request head code\n- prevent stale pull_request.base.sha from reverting terminal queue-admission semantics\n\n## Live evidence\n\n- PR #1811 dequeue run 30414552175 checked out stale base 66f4318 after the terminal-preservation fix had merged\n- PR #1812 dequeue run 30414782541 repeated the same stale checkout even though its merge group was based on 4bf3344\n- both observations wrote a failure lease after a successful merged exit\n\n## Validation\n\n- targeted dequeue tests: 17/17\n- dev required Gate latency suite: 92/92\n- Gate catalog: passed\n- full ./shifu check: passed\n- pre-commit staged gate: passed\n- post-rebase targeted dequeue tests: 17/17\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This CI control-plane fix changes trusted controller source selection without altering an architecture contract\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T02:04:03Z",
          "mergedAt": "2026-07-29T02:32:18Z",
          "additions": 28,
          "deletions": 17,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2029,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2029",
          "title": "fix(gates): reserve control-plane timeout overhead",
          "body": "## Summary\n\n- reserve 30 minutes for Buildchain-owned checkout, setup, receipt validation, and upload around the sum of Shifu Gate action budgets\n- retain the existing 360-minute GitHub job cap and leave consumer Gate definitions/digests unchanged\n- document and test both the normal derived timeout and the cap\n\n## Dogfood evidence\n\nKungfu Dev Verify Patrol run 30407140194 attempt 2 planned 130 minutes from a 10-minute catalog Gate plus a 120-minute full verification Gate. Mandatory checkout/toolchain setup consumed about 14 minutes, so macOS full verification was cancelled at 116 minutes while its final C++ unit was still active; receipt upload then failed because execution had not finalized. The same matrix now resolves to 160 minutes.\n\n## Validation\n\n- node --test tests/gate-profile.test.mjs: 10/10 passed\n- prettier check: passed\n- site/workflow/inventory/action-bundle checks: passed\n- pnpm check: 952/954 unit tests passed; the two failures are the pre-existing macOS workspace-realpath artifact-signing-seal fixtures reproduced on the unchanged v3 baseline and do not touch this change\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-29T02:35:51Z",
          "mergedAt": "2026-07-29T02:42:10Z",
          "additions": 33,
          "deletions": 9,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1814,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1814",
          "title": "feat(project-cut): qualify native delivery loop",
          "body": "## Summary\n\n- add one rooted native delivery-loop qualification contract and closed JSON schema\n- bind an exact protected source PR, Buildchain/merge-group evidence, native Fact/Episode, settled Project Cut, protected ledger PR, and fresh-clone readback\n- qualify the eight required deterministic failure modes without replacing native or Git authorities\n- keep fewer than 30 samples as a default-policy promotion block only; advisory mode remains eligible\n\n## Verification\n\n- `./shifu test:native-loop-qualification`: 5/5 passed\n- `./shifu test:project-cut-publication`: 10/10 passed\n- `./shifu test:delivery-evidence`: 13/13 passed\n- `./shifu check:source`: build-free source gate passed; 741 Node contract tests (731 passed, 10 conditional skips), 40 Work-state Python tests, 116 upgrade tests, and 69 desktop adapter tests passed\n- staged pre-commit gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7d81-90a0-d144fc27fe03\"],\n  \"summary\": \"Qualify the exact protected delivery-to-native-to-ledger continuation path\",\n  \"verification\": [\"native-loop qualification 5/5\", \"settlement publication 10/10\", \"delivery evidence 13/13\", \"build-free source acceptance\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change adds a fail-closed qualification composition over existing evidence and settlement interfaces; it does not publish a product release or claim installed-product qualification.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWdvLWZhbWlseS1jb250aW51b3VzLWRlbGl2ZXJ5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtZ28tZmFtaWx5LW5hdGl2ZS1sb29wLXF1YWxpZmljYXRpb24iLCJkZWxpdmVyeUNsYXNzIjoibmF0aXZlLXByb29mLXJlcXVpcmVkIiwiZGV2SGVhZCI6ImQ0ZmQ2MjlmNzJiYTdiOWZiOTZiOGFlOTk3ZjM5YWM0MjgxMzM0ZDMiLCJwdWxsUmVxdWVzdEhlYWQiOiI4NzYxMzFhZTc0N2ZhOTI0MWVjMjE3MTI5Nzg5ODFjMTNiYTE0NGMzIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiI0MmJmNmI2ZmUzMzZhZmRmM2JlMmE2MWI0Y2YwODY1ODkxNzNkZTc4IiwicmVwbGF5ZWRUcmVlIjoiMTdmMzg0ZGZkYTY1YzE2NjEyMTg2NjE0MWZjYWY2ZWVjMTMxZmJmNyIsInF1ZXVlQXR0ZW1wdCI6IjE4MTRAZDRmZDYyOWY3MmJhN2I5ZmI5NmI4YWU5OTdmMzlhYzQyODEzMzRkMyIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjpkMzE0MjQxNTQyZGFjMDgxOGM0NjUwNjNjYTQ3NzU5OThmOThiOWRiZTM3ZWQ2OWI1OTkxMzhiZGI5ODc3OGFlIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6MDA3MDAyYjkzNjlkNDk1NmFjNzM3ZTEyMWQzNmIyMjVhODFmZDY5Mzg2Mzk5YmQ3MWFhNjJjNzZlMTMyMDdjYyIsInNoYTI1NjozZWEzZGZjNGRlYWE0MTQ2NWI2ZDRkZDI1NTkyMTc0Y2Y2MDczZWQxYzEyNTZhZTI5NzZlZTY0NGIzYzA0N2Y1Iiwic2hhMjU2OjYwNTliMWE4NWE4MmYxZDBmYjY1N2E1ODY1NzU3YTFlMDRkOTFlOWUzZDQ5MDc0YjZjYjk2OWExZTBhNWY4ZmQiLCJzaGEyNTY6ZDMxNDI0MTU0MmRhYzA4MThjNDY1MDYzY2E0Nzc1OTk4Zjk4YjlkYmUzN2VkNjliNTk5MTM4YmRiOTg3NzhhZSJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2VjYWM2N2JjZWJmYWUzYmYiLCJsZWFzZVJvb3QiOiJzaGEyNTY6ZDhjODkxYjY0MDlhODU2M2Y3YmJiODNlOWI4OGM2MTk4NGFiOGE1YWM4ZWViODhiM2RlNjdmYTcxNWQwOTYzNiJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T02:25:14Z",
          "mergedAt": "2026-07-29T02:55:00Z",
          "additions": 1672,
          "deletions": 7,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1816,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1816",
          "title": "fix(ci): verify Windows JIT smoke explicitly",
          "body": "## Summary\n\n- make the Windows JIT smoke use an explicit platform probe for both build and verify\n- prevent the optional default Kungfu lifecycle from demanding full native artifacts in the bounded smoke\n- refresh the closed-world workflow authority and release-surface roots\n\n## Verification\n\n- `node --test scripts/buildchain-install.test.mjs`\n- repository staged gate (pre-commit)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Correct the already-governed AWS US Windows qualification smoke lifecycle without changing product architecture or release authority.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Regression test added\n- [x] No release credentials or publication authority\n- [x] Exact-source and zero-idle cleanup boundaries retained",
          "author": "dongkeren",
          "createdAt": "2026-07-29T02:43:23Z",
          "mergedAt": "2026-07-29T03:07:02Z",
          "additions": 9,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1819,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1819",
          "title": "fix(work-control): align merge queue evidence chronology",
          "body": "## Summary\n\n- accept the real GitHub Merge Queue chronology: validation run completion, protected merge, then observation\n- measure freshness and native admission lag from the protected merge\n- bind the same ordering in the native adapter and final qualification verifier\n\n## Verification\n\n- `framework/core/tests/python/test_delivery_evidence.py`: 15 passed\n- `./shifu test:native-loop-qualification`: 5 passed\n- `./shifu check:staged`: passed\n- Ruff and Biome: passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7d81-90a0-d144fc27fe03\"],\n  \"summary\": \"Align exact Merge Queue evidence chronology with protected delivery\",\n  \"verification\": [\"delivery evidence 15/15\", \"native-loop qualification 5/5\", \"staged source gate\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis corrects fail-closed evidence chronology; it does not publish a release or claim installed-product qualification.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWdvLWZhbWlseS1jb250aW51b3VzLWRlbGl2ZXJ5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtZ28tZmFtaWx5LW5hdGl2ZS1sb29wLXF1YWxpZmljYXRpb24iLCJkZWxpdmVyeUNsYXNzIjoibmF0aXZlLXByb29mLXJlcXVpcmVkIiwiZGV2SGVhZCI6ImMxZmUwYWFmMTIwYmMxOWYyYTkxNTQxMmY4ZWZjNWFmMDBlNWRmNTUiLCJwdWxsUmVxdWVzdEhlYWQiOiIxOTEzNzU2NDUzMzJmNzNkYjM5YjI4NTY1MDVhMDhmY2RhOTY3MzY5IiwicmVwbGF5ZWRDYW5kaWRhdGUiOiI3YzUxOGRkMTZkZGE4YjE3NmRkMGVlNWUzY2IwODk4ZWI1YTcxYzAwIiwicmVwbGF5ZWRUcmVlIjoiYmUyNzM2N2Y4MjRkNDQxOTc5Yzc4Y2U1MTNkMGMzYTEzOWI0NGZmZCIsInF1ZXVlQXR0ZW1wdCI6IjE5MTM3NTY0NTMzMmY3M2RiMzliMjg1NjUwNWEwOGZjZGE5NjczNjlAYzFmZTBhYWYxMjBiYzE5ZjJhOTE1NDEyZjhlZmM1YWYwMGU1ZGY1NSIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjowY2FjYjg2Mzc1ZjhmNGEwZDc4MDNiNGZjY2JhOGI0MjE2NTY3OTExNTBkYTAzN2VjNDgyZjhiNGNkNWVjNWFhIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6MGNhY2I4NjM3NWY4ZjRhMGQ3ODAzYjRmY2NiYThiNDIxNjU2NzkxMTUwZGEwMzdlYzQ4MmY4YjRjZDVlYzVhYSIsInNoYTI1NjpkMzE0MjQxNTQyZGFjMDgxOGM0NjUwNjNjYTQ3NzU5OThmOThiOWRiZTM3ZWQ2OWI1OTkxMzhiZGI5ODc3OGFlIl0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZWNhYzY3YmNlYmZhZTNiZiIsImxlYXNlUm9vdCI6InNoYTI1NjpmNDU4ODM1YzA2NmIxYjc0MGJmZjUxNWM5YjdmYjQwOWI3NzJlNGQxNzk1ZjViYWM5ZjQ1ZjlmNTBjZmMzN2E2In0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T03:13:45Z",
          "mergedAt": "2026-07-29T03:28:42Z",
          "additions": 84,
          "deletions": 16,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 58,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/58",
          "title": "fix(hub): explain existing workspace registration",
          "body": "## Summary\n\n- map duplicate workspace registration to an explicit HTTP 409 conflict\n- tell returning creators to log in instead of showing a generic request failure\n- preserve generic handling for unrelated database errors\n\n## Verification\n\n- `npm run check` (53 tests)\n- `bash -n scripts/smoke-image.sh scripts/smoke-browser.sh scripts/publish-runtime-release.sh`\n- reproduced duplicate registration against the current LAN deployment before the fix\n\n## Version impact\n\nPatch: user-facing bug fix with no contract expansion.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T03:45:12Z",
          "mergedAt": "2026-07-29T03:46:27Z",
          "additions": 54,
          "deletions": 19,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1818,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1818",
          "title": "perf(ci): skip unused SDK module scans",
          "body": "## Summary\n\n- disable unused C++ module dependency scanning in the dev SDK build plan\n- keep the installed four-language SDK qualification and exact artifact closure unchanged\n- freeze the optimization in the SDK build-plan contract and gate documentation\n\n## Validation\n\n- `./shifu check`\n- `node --test framework/core/tests/sdk-core-build.test.js`\n- `node --test scripts/run-core-affected-native.test.mjs scripts/affected-native-proof.test.mjs`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This dev CI optimization skips dependency scanning only where the governed Core closure declares no C++ module sources; it preserves installed SDK qualification, artifact authority, and release semantics.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T03:09:00Z",
          "mergedAt": "2026-07-29T04:02:39Z",
          "additions": 30,
          "deletions": 4,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2031,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2031",
          "title": "feat(signing): support compound macOS archives",
          "body": "## Summary\n\nExtend the native Apple artifact-signing authority so a consumer can declaratively request signing for a generic compound archive. The authority safely extracts the archive, signs every Mach-O payload (including Mach-O code embedded in Python wheels), rebuilds wheel RECORD metadata, reconstructs the archive, and notarizes the complete extracted product tree under the protected Buildchain signing environment.\n\nNo credential material is added to the repository or exposed to consumers.\n\n## Related issue\n\nAssignment: `2026-07-26-buildchain-credential-island-self-dogfood`\n\n## Changes\n\n- admit `archive` for Apple Developer ID signing profiles\n- route the sealed artifact kind into the native signing authority\n- add safe tar/zip extraction, compound Mach-O signing, nested wheel RECORD repair, and deterministic reconstruction\n- derive result verification checks from provider evidence and fail closed when they are absent\n- document whole-product notarization and generic archive Gatekeeper/stapling semantics\n- regenerate checked-in action and public-site projections\n\n## Verification\n\n- `pnpm run check` (955 tests passed; workflow and action bundle integrity passed)\n- `python3 -m py_compile scripts/sign-macos-compound-archive.py`\n- `bash -n scripts/sign-macos-mach-o-request.sh`\n- `shellcheck scripts/sign-macos-mach-o-request.sh`\n- `git diff --check`\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [x] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes only the credential-island execution boundary and evidence contract. Existing protected environment secrets stay server-side; tests cover source binding, archive traversal rejection, nested wheel integrity, provider evidence, and notarization checks.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T04:25:59Z",
          "mergedAt": "2026-07-29T04:31:13Z",
          "additions": 890,
          "deletions": 223,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2032,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2032",
          "title": "chore(signing): advance compound artifact authority",
          "body": "## Summary\n\nAdvance the protected Buildchain artifact-signing authority to the reviewed `dev/v3/v3.0` merge that adds generic compound archive signing and whole-product notarization.\n\nThe formal `buildchain-artifact-signing` environment remains the sole credential authority. Its HK Developer ID and notary credentials are not copied into consumer repositories.\n\n## Related issue\n\n- Buildchain implementation: #2031\n- Assignment: `2026-07-26-buildchain-credential-island-self-dogfood`\n\n## Changes\n\n- move `authority/v3/v3.0/artifact-signing` forward to the reviewed dev merge\n- expose `archive` as a protected Apple Developer ID signing kind\n- retain source-bound request/result evidence and fail-closed provider verification\n\n## Verification\n\n- #2031 required PR checks passed\n- #2031 merge-queue `Verify` and governance audit passed\n- authority branch remains admitted by `buildchain-artifact-signing` deployment policies\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [x] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis advances only the protected authority ref. It does not modify or expose environment secrets.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T04:31:37Z",
          "mergedAt": "2026-07-29T04:33:09Z",
          "additions": 920,
          "deletions": 229,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 328,
          "url": "https://github.com/kungfu-systems/build-images/pull/328",
          "title": "feat(demo-renderer): replay qualified terminal captures",
          "body": "## Summary\n\n- replay an optional bounded PTY capture through pinned `@xterm/headless` instead of synthesizing terminal text\n- bind the capture root, installed terminal state-machine version, and inventory root in renderer evidence\n- keep raw capture bytes out of the public media bundle and reject implicit authority grants or incomplete non-authority declarations\n- retain deterministic transcript rendering for existing callers\n\n## Validation\n\n- `pnpm run check`\n- `node --check images/demo-renderer/render-demo.mjs`\n- `bash -n images/demo-renderer/tests/smoke.sh`\n- path-scoped Ubuntu qualification builds the exact image and executes deterministic plus negative smoke\n\n## Authority boundary\n\nTerminal bytes are volatile observations only. First-party/System identity, KFD compliance, Product System metadata, package metadata, registry history, scan output, and standalone generation grant no authority.\n\nSupersedes fork PR #327 with the identical head so the repository trust gate can evaluate a same-repository branch.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T04:31:19Z",
          "mergedAt": "2026-07-29T04:35:12Z",
          "additions": 465,
          "deletions": 101,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 59,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/59",
          "title": "fix(hub): expose registration rejection reasons",
          "body": "## Summary\n- return actionable registration validation and origin messages\n- add sanitized registration rejection logs without user input\n- preserve generic handling for unclassified failures\n\n## Verification\n- npm run check (55 tests)\n- bash -n scripts/smoke-image.sh scripts/smoke-browser.sh scripts/publish-runtime-release.sh\n- git diff --check\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-29T04:34:37Z",
          "mergedAt": "2026-07-29T04:35:13Z",
          "additions": 90,
          "deletions": 15,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2030,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2030",
          "title": "feat(auditable-demo): qualify terminal captures",
          "body": "## Summary\n\n- accept an additive, bounded `kungfu.terminal-capture/v1` adapter output while retaining compatibility with existing three-file adapters\n- seal the exact capture into the Gate bundle and require renderer input-root parity\n- reject implicit grants, incomplete identity/metadata non-authority declarations, malformed base64, unsafe timing, and unbounded captures\n- pass qualified capture bytes read-only to the immutable renderer without copying them into public media\n\n## Validation\n\n- `node --test tests/auditable-demo.test.mjs` (12 passed)\n- `pnpm run check:site`\n- `pnpm run check:workflows`\n- full local suite: 953 passed, 2 pre-existing macOS `/var` vs `/private/var` signing-fixture failures in untouched code; Linux CI is authoritative for those fixtures\n\n## Authority boundary\n\nTerminal bytes are observation only. First-party/System identity, KFD compliance, Product System metadata, package metadata, registry history, scan output, and standalone generation remain non-authoritative.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T04:21:20Z",
          "mergedAt": "2026-07-29T04:40:50Z",
          "additions": 265,
          "deletions": 18,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1824,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1824",
          "title": "chore(ledger): publish batch native-loop-qualification-pr-1814",
          "body": "Kungfu-Settlement-Batch: sha256:2073a8094acb224e4abe38cc53b3ffc27c6a5de5ea4bda799c35339ac8d11503\nKungfu-Settlement-Manifest: sha256:23dacd9f6a0889a9d588d7963837cc14be7e2902ec5b6f4effaef795ff06f855\nKungfu-Generated-By: kungfu-settlement-publication/v1\n\nThis protected projection does not decide Work Control completion or block runtime continuation.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Publish deterministic settlement evidence without changing architecture records or runtime behavior\"\n}\n-->\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWdvLWZhbWlseS1jb250aW51b3VzLWRlbGl2ZXJ5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtZ28tZmFtaWx5LW5hdGl2ZS1sb29wLXF1YWxpZmljYXRpb24iLCJkZWxpdmVyeUNsYXNzIjoibmF0aXZlLXByb29mLXJlcXVpcmVkIiwiZGV2SGVhZCI6IjFlMzNhMTY5Y2YyMmZiZWVjNGNlZDEyZDdmMjQ5ODUxM2M1M2YwOWIiLCJwdWxsUmVxdWVzdEhlYWQiOiJhMTQ3ZWJlM2FkM2MxYmY3YjA5N2QyOWM1MDI1MDRkMTRlNjJmNTZmIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiJhMTg0Njc0OWRiZTFiMDZlYmRmNjBmMzFmYTE5OTg1YTBlN2FlMTRjIiwicmVwbGF5ZWRUcmVlIjoiNGU5ZTk2MmQ5YWZkNWM2YjhiYTMwNWZmNGQ4NzFlOGYxYzVhZGY4NiIsInF1ZXVlQXR0ZW1wdCI6ImExNDdlYmUzYWQzYzFiZjdiMDk3ZDI5YzUwMjUwNGQxNGU2MmY1NmZAMWUzM2ExNjljZjIyZmJlZWM0Y2VkMTJkN2YyNDk4NTEzYzUzZjA5YiIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjpiY2M4M2U0MTY3MWY5ZDQyOTFmODhiMTk4NjZmNDkxNjczMDNhODY4N2FlNmRhMTY1OTE4NzliNTFhZTA0ZjJjIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6M2VhM2RmYzRkZWFhNDE0NjViNmQ0ZGQyNTU5MjE3NGNmNjA3M2VkMWMxMjU2YWUyOTc2ZWU2NDRiM2MwNDdmNSIsInNoYTI1NjpiY2M4M2U0MTY3MWY5ZDQyOTFmODhiMTk4NjZmNDkxNjczMDNhODY4N2FlNmRhMTY1OTE4NzliNTFhZTA0ZjJjIl0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZWNhYzY3YmNlYmZhZTNiZiIsImxlYXNlUm9vdCI6InNoYTI1Njo5NTdlYWI4YTZmMjNiMTYyNDM4YzE1OTljY2Q2ZDcyZDA3YjA5MGU1M2NmN2I3ZTZhMzk0YzkwN2RhYmQ5OGIxIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T04:19:05Z",
          "mergedAt": "2026-07-29T04:41:09Z",
          "additions": 19,
          "deletions": 0,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1825,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1825",
          "title": "fix(ci): recover non-family cache promotion",
          "body": "修复 post-merge cache promotion 对合法 non-family delivery attempt 的空指针，并提供仅限 dev channel 精确祖先 SHA 的证据恢复入口。\n\n验证：完整 ./shifu check 通过；真实回放 #1818 authority/delivery-attempt artifact 通过；targeted contract 23/23。\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This dev CI fix accepts the already-valid non-family delivery attempt shape and adds an exact ancestor-bound recovery path for immutable cache promotion evidence; it does not change product architecture or release semantics.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T04:23:03Z",
          "mergedAt": "2026-07-29T05:08:45Z",
          "additions": 134,
          "deletions": 48,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2034,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2034",
          "title": "feat(patrol): render exact-source candidate declarations",
          "body": "Merge feature/candidate-settlement-renderer into dev/v3/v3.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-29T05:19:30Z",
          "mergedAt": "2026-07-29T05:23:07Z",
          "additions": 443,
          "deletions": 23,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1827,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1827",
          "title": "fix(work-control): support Windows long assignment paths",
          "body": "## Summary\n\n- map Windows Assignment filesystem operations into the extended-length namespace\n- preserve logical paths in receipts and errors while using long-path-safe atomic I/O\n- cover local-drive and UNC namespace mappings with a regression test\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python:framework/core/build/Release uv run --project framework/core --frozen pytest -q framework/core/tests/python/test_assignment_orchestration.py` (60 passed)\n- `python3 -m py_compile framework/core/src/python/kungfu/assignment_orchestration.py framework/core/tests/python/test_assignment_orchestration.py`\n- repository staged gate (pre-commit)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Correct Windows filesystem compatibility for the existing Assignment atomic-write contract without changing product architecture or release authority.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Regression test added\n- [x] No release credentials or publication authority\n- [x] Logical Assignment identities and receipt paths are unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-29T04:40:37Z",
          "mergedAt": "2026-07-29T05:25:19Z",
          "additions": 85,
          "deletions": 50,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1831,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1831",
          "title": "fix(ci): bind recovery attempt artifact to target",
          "body": "修复历史 cache promotion 恢复时 delivery-attempt artifact 仍误绑当前 dev GITHUB_SHA，导致旧 target 永远匹配不到并轮询 10 分钟。现在该 artifact 与其余 authority 一样精确绑定 TARGET_SHA。\n\n验证：cache/proof、workflow authority、Gate catalog、actionlint、YAML、Biome、复杂度预算与 staged gate 通过。\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This CI recovery fix completes exact target binding for an immutable delivery-attempt artifact and does not change product architecture or release semantics.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T05:26:37Z",
          "mergedAt": "2026-07-29T05:37:22Z",
          "additions": 13,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1829,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1829",
          "title": "fix(work-control): clean up portfolio state projection",
          "body": "## Summary\n\n- normalize terminal compatibility status without conflating native Assignment phase\n- group authority-distinct Initiative labels while preserving every canonical root\n- keep disposable course probes test-only from first Catalog observation\n\n## Verification\n\n- `./shifu test:workspace-continuation` (121 passed)\n- `./shifu check:workspace-continuation`\n- `./shifu check:source`\n- Catalog maintenance exact plan `sha256:5b8b6cbf4d90b85d13ee04ee5dc9732e7abccca4fd11dfa36eb4e241ab6ae7cf`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded bugfix corrects Work Portfolio status projection and disposable Catalog lifecycle handling without changing an architecture contract.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T04:44:15Z",
          "mergedAt": "2026-07-29T05:49:45Z",
          "additions": 353,
          "deletions": 6,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1828,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1828",
          "title": "feat(release): consume Buildchain signing authority",
          "body": "## Summary\n\nMake Kungfu a complete consumer of the protected Buildchain artifact-signing authority. The macOS CLI archive is now declared for generic signing, product assembly rewrites internal symlinks to portable relative links, and alpha/release workflows pin the formal Buildchain artifact-signing authority SHA.\n\nThe existing desktop compatibility signing job now uses the HK environment. The Beijing environment remains unchanged as an inactive backup and is no longer referenced by the official build workflow.\n\n## Related issue\n\n- Assignment: `2026-07-26-buildchain-credential-island-self-dogfood`\n- Buildchain implementation: kungfu-systems/buildchain#2031\n- Protected authority promotion: kungfu-systems/buildchain#2032\n\n## Changes\n\n- declare the macOS CLI tarball as a required generic `archive` signing artifact\n- pin build and release workflows to protected authority `4716fc9d963f73c890f04cd3b91e59569de4fc38`\n- update the Alpha contract lock and release governance projections to the same exact runtime\n- route cross-repository authority dispatch through the existing promotion token without copying Apple credentials into Kungfu\n- migrate the desktop compatibility credential island from `alpha-macos-signing` to `alpha-macos-signing-hk`\n- normalize copied internal symlinks and preserve safe relative symlinks in tar products\n- reject absolute, escaping, and unsupported ZIP symlinks fail closed\n\n## Verification\n\n- `KUNGFU_DEV_BRANCH=dev/v4/v4.0 ./shifu check:source` (737 passed, 10 platform/tool skips, 0 failed; Python, runtime upgrade, desktop adapter, type, format, release publication, and workflow authority checks passed)\n- `./shifu test:release-admission` (5 passed)\n- `./shifu test:cli-surface-qualification` (39 passed)\n- `./shifu test:npm-core-platform-distribution` (82 passed, 3 Windows skips)\n- `./shifu test:upgrade-qualification` (43 passed)\n- `./shifu check:gate-catalog`\n- commit staged gate passed with `KUNGFU_DEV_BRANCH=dev/v4/v4.0`\n- live environment readback confirms the HK Team ID/fingerprint in both Buildchain formal authority and Kungfu compatibility environment; Beijing remains intact and unreferenced\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This consumes the already admitted Buildchain credential-island architecture and tightens product portability without changing a Kungfu architecture contract.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [x] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nApple credentials remain exclusively in protected GitHub environments. The change updates environment references, exact authority pins, and release evidence; no credential bytes or secret values enter the repository or logs.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T04:43:19Z",
          "mergedAt": "2026-07-29T06:01:39Z",
          "additions": 251,
          "deletions": 54,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 329,
          "url": "https://github.com/kungfu-systems/build-images/pull/329",
          "title": "chore(release): promote build-images v1.3 alpha",
          "body": "Promote the current verified dev/v1/v1.3 image family through the governed Buildchain Alpha publication transaction.\\n\\nThe target includes the reviewed OpenCode image baseline and the qualified demo-renderer update. Buildchain remains responsible for exact version selection, immutable OCI publication, anonymous pull verification, and Release Passport evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T05:59:05Z",
          "mergedAt": "2026-07-29T06:02:27Z",
          "additions": 597,
          "deletions": 206,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 330,
          "url": "https://github.com/kungfu-systems/build-images/pull/330",
          "title": "Prepare v1.3.0-alpha.17",
          "body": "Create the generated version-state commit for v1.3.0-alpha.17.\n\nBuildchain generated this PR because protected branch alpha/v1/v1.3 rejected direct generated bookkeeping.\n\nRejected update: 62fd0595a8187cb1cc4265b042dc5da98fd412cd -> dead4fa2403afcac6c11b3b320a644a4e5f7be3d\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T06:16:04Z",
          "mergedAt": "2026-07-29T06:20:09Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1832,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1832",
          "title": "fix(release): derive alpha settlement from exact candidate",
          "body": "## Summary\n\nDerive the dev-to-alpha ADR settlement from the exact selected candidate instead of carrying a static no-progress declaration.\n\n## Changes\n\n- Pin the candidate patrol to Buildchain 009c00d7c0145b5991f56aa97a98d5d1bbcc350f.\n- Render one deterministic alpha settlement from the exact target-to-candidate delta.\n- Fail closed on source drift, invalid target branches, malformed ADR projections, and oversized output.\n- Retain the generated workflow-authority and publication-surface projections.\n\n## Verification\n\n- node --test scripts/render-alpha-settlement.test.mjs scripts/dev-alpha-candidate-patrol.test.mjs scripts/release-publication-control-plane.test.mjs\n- KUNGFU_DEV_BRANCH=dev/v4/v4.0 ./shifu check:staged\n- KUNGFU_DEV_BRANCH=dev/v4/v4.0 ./shifu check:source\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair release-control settlement derivation without changing any accepted ADR record or architecture contract\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\nThis PR changes release evidence and candidate-control surfaces. It does not publish, create an alpha candidate, or widen release authority; exact-source and fail-closed behavior are covered by the listed regression suites.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation projections are current\n- [x] No secrets, credentials, or private logs are included\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI5LWJ1aWxkY2hhaW4tY2FuZGlkYXRlLXNldHRsZW1lbnQtcmVuZGVyZXIiLCJkZWxpdmVyeUNsYXNzIjoibm9uLW5hdGl2ZS1mYXN0IiwiZGV2SGVhZCI6IjUxY2EwNjZmMmJmNzEzYzJhZmJhNzE0NzJjY2I4NDEzMzRiNjc2NTEiLCJwdWxsUmVxdWVzdEhlYWQiOiJlNGI3MzgyMmFlYzcyNmEwNjhkNTljZGM5YTQxNmU0OGRhY2MwNDMyIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiI4MzE3YThkN2VlNzcxNGIxMTU0ZTZjODg5YmNmNmE1YjdlYzQ2NGUyIiwicmVwbGF5ZWRUcmVlIjoiMjQxMTUzMDEzYWY5ZjdjOWFmNzBhYTc5ODRmNGM5MzdmZDhmZmY1MCIsInF1ZXVlQXR0ZW1wdCI6ImU0YjczODIyYWVjNzI2YTA2OGQ1OWNkYzlhNDE2ZTQ4ZGFjYzA0MzJANTFjYTA2NmYyYmY3MTNjMmFmYmE3MTQ3MmNjYjg0MTMzNGI2NzY1MSIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1Njo0NDA5Y2M3OTBjMWU3NjBiZDUwNWUyMzNmNGJlNDE0NDA0MjU4OWNiMGVmZTRjMjI1ZmI3NDQ0ZTQyMzYxMjZhIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6NDQwOWNjNzkwYzFlNzYwYmQ1MDVlMjMzZjRiZTQxNDQwNDI1ODljYjBlZmU0YzIyNWZiNzQ0NGU0MjM2MTI2YSIsInNoYTI1Njo4M2JiMTY3MmM1MWU3NmM5MjQyYmU5OTJjYTA1MzAyZjgzMjYxMzllN2RjNDM3ZjZlMWMwZjIzODQwNzQzMjEzIl0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZDk5ZjNhOTE2NjczOWUwZCIsImxlYXNlUm9vdCI6InNoYTI1NjpkY2MxMTNjNjQ1ZWIzODczNjY5MmZmZDA5ODM0ODE4YzI0OWI2NjcwNDJhMjM4NjRmMjY4OWMxNDIxZjA4NGUzIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T05:38:16Z",
          "mergedAt": "2026-07-29T06:24:33Z",
          "additions": 317,
          "deletions": 20,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1836,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1836",
          "title": "feat(release): promote qualified Assignment Core",
          "body": "## Summary\n\nPromote a minimum relocatable macOS ARM64 Assignment Core only from exact merge-group qualification into an exact protected-dev artifact contract. Untrusted PR bytes and transport remain non-authoritative; source builds remain the fallback when no exact producer is available.\n\n## Related issue\n\nKungfu Assignment `2026-07-28-kungfu-qualified-core-producer-promotion`.\n\n## Changes\n\n- Seal only `kungfubuildinfo.json` and the matching `pykungfu` native payload with exact source, tree, toolchain, lock, Shifu, Buildchain, and affected-native plan roots.\n- Produce candidates only on GitHub-hosted macOS ARM64 merge-group runs after the required affected-native Gate succeeds.\n- Promote only one exact producer on the protected dev push and reject tamper, stale identity, unsafe paths or symlinks, ambiguous authority, and runner impersonation.\n- Keep transport replaceable, promotion outside the target checkout, and source build authoritative when the producer is unavailable.\n- Admit Initiative-family child Assignments in the native orchestration controller.\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu check:test-manifest`\n- `./shifu exec -- node --test scripts/qualified-assignment-core-artifact.test.mjs scripts/affected-native-cache-payload.test.mjs scripts/affected-native-proof.test.mjs`\n- `./shifu exec -- node scripts/code-complexity-budget.mjs`\n- Workflow YAML parse and commit-time staged Gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Implement the exact merge-group producer and protected-dev promotion path for qualified Assignment Core artifacts\",\n  \"verification\": [\"Full source acceptance\", \"Exact artifact contract tests\", \"Closed-world workflow authority\", \"Complexity budget\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change adds only qualifying artifact evidence and protected promotion authority. It adds no release credentials, package publication, or deployment action; closed-world workflow authority and exact-root contract tests cover this boundary.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LXF1YWxpZmllZC1hc3NpZ25tZW50LWNvcmUtY2FjaGUtZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtcHJvZHVjZXItcHJvbW90aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJhYzFjYmQ5ODZhY2RmYTk4NDI2NzQxOTkyZTU4MGFjZTAyMjVlMDMwIiwicHVsbFJlcXVlc3RIZWFkIjoiYzkzNDk1MWFjYzM4Y2U5NjlkZmJkZDM3YzRhOTlmMzA2ODMzMTQ1YiIsInJlcGxheWVkQ2FuZGlkYXRlIjoiN2FiNzczNDQ3NWZjZTI3NzI3MDBhYWVkYzc1ZDFlYjhkYjYyZTBiNCIsInJlcGxheWVkVHJlZSI6ImNlMjc5ZDIwYmM0ZTlmZGJiZjAwYTY4MzY3MDNkYzE1NGU2ZGVlMDQiLCJxdWV1ZUF0dGVtcHQiOiJjOTM0OTUxYWNjMzhjZTk2OWRmYmRkMzdjNGE5OWYzMDY4MzMxNDViQGFjMWNiZDk4NmFjZGZhOTg0MjY3NDE5OTJlNTgwYWNlMDIyNWUwMzAiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6N2VlNTc4MWY4OTFlMTRjYzNlNWQ0MTEyNGRlNjlhMGEzMzIyNjhlNzViZTk1MGFlNzc1YmNjZGU4NmUyZmJiOSIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjdlZTU3ODFmODkxZTE0Y2MzZTVkNDExMjRkZTY5YTBhMzMyMjY4ZTc1YmU5NTBhZTc3NWJjY2RlODZlMmZiYjkiLCJzaGEyNTY6ZDk3ZWI4MzI0ODQ4MjI1MDRkMmJiMGMyNTZlM2E4OThlZDYzOGFjNWNhNjRhZDIwNTgyMTc3NjdiNzllZDg2YyJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzIyYzg0YjMxNzAxMDc5ZTIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6ZmEyZWE3YzkwYWY0YTA3NTAwNTk5Y2EzZmMwOGE1OTZhNzU5ZWNlMTNiZTFlYjYyNTk1MjBhOTZlZjQyZTY0MCJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T06:32:30Z",
          "mergedAt": "2026-07-29T06:50:40Z",
          "additions": 1608,
          "deletions": 62,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1840,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1840",
          "title": "fix(ci): run qualified Core producer",
          "body": "## Summary\n\nEnsure the qualified Assignment Core path actually schedules its exact merge-group macOS ARM64 producer, while keeping an incomplete producer transport visible without turning the protected-dev source fallback into a failed promotion.\n\n## Related issue\n\nKungfu Assignment `2026-07-28-kungfu-qualified-core-producer-promotion`.\n\n## Changes\n\n- Resolve the hyphenated aggregate job through the expression-safe bracket form so the merge-group macOS producer is scheduled after an exact successful Gate.\n- Distinguish an incomplete completed producer transport from duplicate or ambiguous authority while retaining exact-root and exact-run rejection.\n- Refresh the closed-world workflow authority and publication-surface roots.\n\n## Verification\n\n- `actionlint .github/workflows/affected-native-pr.yml .github/workflows/affected-native-cache-promote.yml`\n- `node --test scripts/qualified-assignment-core-artifact.test.mjs`\n- `KUNGFU_READONLY_PYTEST=\"$PWD/framework/core/.venv/bin/pytest\" ./shifu check:source`\n- Commit-time staged Gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Activate the exact merge-group producer and preserve non-blocking source fallback for incomplete qualified Core transport\",\n  \"verification\": [\"Full source acceptance\", \"Exact artifact contract tests\", \"Closed-world workflow authority\", \"Commit-time staged Gate\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change corrects qualifying artifact evidence and protected promotion control flow. It adds no release credentials, package publication, or deployment action; closed-world workflow authority and exact-root contract tests cover this boundary.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LXF1YWxpZmllZC1hc3NpZ25tZW50LWNvcmUtY2FjaGUtZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtcHJvZHVjZXItcHJvbW90aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJmYTk3MDg4MWRiYTI0MWU5YzY0YWZhMzAyZjhmMjBmYTgwNDE1ODY3IiwicHVsbFJlcXVlc3RIZWFkIjoiNjgxYzQ3NTdiZTliZDQ2MWQ5NDgyMjQ4MTE0MmZlZTUxZGFjMjgwMyIsInJlcGxheWVkQ2FuZGlkYXRlIjoiMjkyZGI0ZjYwNmVhNWY4MWNlNmJhYjBlZWYzNzA0N2YyNDEwOWNlZiIsInJlcGxheWVkVHJlZSI6IjA4OGI4ZDk1ODRlNDAyYzMxZmZlMGE0YmY2MmY5MzAxNWIwZDgwYTgiLCJxdWV1ZUF0dGVtcHQiOiI2ODFjNDc1N2JlOWJkNDYxZDk0ODIyNDgxMTQyZmVlNTFkYWMyODAzQGZhOTcwODgxZGJhMjQxZTljNjRhZmEzMDJmOGYyMGZhODA0MTU4NjciLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6OGQ4MGYwOWMwMjI4ODcyN2MzZTkxMTlhYTdlNjZjMWNhMzk3OGQ1MDU2OGNmODVhY2Q3MjBmNmQzOGM5NjEwMCIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjhkODBmMDljMDIyODg3MjdjM2U5MTE5YWE3ZTY2YzFjYTM5NzhkNTA1NjhjZjg1YWNkNzIwZjZkMzhjOTYxMDAiLCJzaGEyNTY6ZDk3ZWI4MzI0ODQ4MjI1MDRkMmJiMGMyNTZlM2E4OThlZDYzOGFjNWNhNjRhZDIwNTgyMTc3NjdiNzllZDg2YyJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzIyYzg0YjMxNzAxMDc5ZTIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6ZGEwZTFhZmU3YTQ0ZWY3M2U0ZGE4YjZlZjlkYWRkMzNmZDZkZjRhOTg5ODZjMzJhNWIxMzI5YzMyODQxMDVlZiJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T07:22:05Z",
          "mergedAt": "2026-07-29T07:53:41Z",
          "additions": 38,
          "deletions": 11,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1838,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1838",
          "title": "feat(kfd): qualify Assignment adopter candidate",
          "body": "## Summary\n\nQualify Kungfu's bounded Assignment adopter profile for KFD-5 without widening it into shipped support, independent adoption, or Buildchain self-certification.\n\n## Related issue\n\nNative Assignment `2026-07-29-kungfu-kfd5-assignment-product-qualification` under the KFD support-governance program.\n\n## Changes\n\n- replace the provisional catalog-only KFD-5 input with the accepted upstream Assignment discovery cut;\n- bind the retained organization dogfood, minimum-closure, native lifecycle, and exact Assignment test source as product evidence;\n- fail closed unless product dogfood preserves cross-workspace closure, worktree deletion, tamper rejection, and the non-release boundary;\n- require every checked-in KFD product-gate evidence cut to pass while preserving `qualifying=false` and `selfCertified=false`;\n- project KFD-5 as a verified, Buildchain-gated, non-shipped candidate across the authority matrix, SDK, CLI documentation, and generated docs;\n- add a regression that rejects a KFD-5 candidate whose gate drifts away from `passed`.\n\n## Verification\n\n- `./shifu lint`\n- `./shifu kfd:buildchain:check -- --json`\n- `./shifu kfd:support-matrix:check --json`\n- `./shifu test:assignment-capture`\n- staged pre-commit gate, including 18 KFD matrix tests and Buildchain KFD evidence validation\n- `./shifu pack:spec` followed by the repository check converted all missing spec-artifact failures to passes; the full local checkout still reports the unrelated existing canonical-policy projection drift in the SDK suite\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f87cc-bd1f-786d-896d-07ea9245861e\"],\n  \"summary\": \"Bind the accepted portable Assignment profile to one bounded KFD-5 product qualification cut without activating release support.\",\n  \"verification\": [\"Buildchain KFD-5 gate passes with zero issues and remains non-qualifying\", \"KFD support matrix negative fixtures pass\", \"Assignment capture tests pass\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\nThis PR adds qualification evidence to an existing accepted architecture decision and does not change the Evolution Map corpus or current authority.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: this PR changes KFD product-gate inputs and support projections only. It does not publish a package, activate Alpha, change `releaseQualification.shippedSupport`, or grant release credentials. Buildchain continues to emit `qualifying=false` and `selfCertified=false`.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI5LWt1bmdmdS1rZmQ1LWFzc2lnbm1lbnQtcHJvZHVjdC1xdWFsaWZpY2F0aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5vbi1uYXRpdmUtZmFzdCIsImRldkhlYWQiOiI5ZTYyMDhjZDJhZTEwZGE3ZGQwZTYwNDc0ZTA4OTZhYWU1MGQ5MzQ0IiwicHVsbFJlcXVlc3RIZWFkIjoiZWUwMjEyMTQ4YTQ5ZDQ1MDMyMWUxNjJlMDk1YjdiNGViOTE5MmEyMSIsInJlcGxheWVkQ2FuZGlkYXRlIjoiOGE4NDc1MGFkZGM0ZDdiZTAzZWNhZWMyNjZhM2E0OTAyZjQ2NDc2NiIsInJlcGxheWVkVHJlZSI6IjQ5NWQ0MDBmY2RiZmJhZWNhZmZhNmQ2ZjkwZDQ4YjEzM2E1MTVlMTYiLCJxdWV1ZUF0dGVtcHQiOiJlZTAyMTIxNDhhNDlkNDUwMzIxZTE2MmUwOTViN2I0ZWI5MTkyYTIxQDllNjIwOGNkMmFlMTBkYTdkZDBlNjA0NzRlMDg5NmFhZTUwZDkzNDQiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6MmEwMTY5YWQwM2YwMjRkZDIzYjBhMWUwZWYxZjM3MzI3YzNlZTZkMDhlMTUzNGQ2NTkwYjI0NWE1MzEzYTI2NyIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjJhMDE2OWFkMDNmMDI0ZGQyM2IwYTFlMGVmMWYzNzMyN2MzZWU2ZDA4ZTE1MzRkNjU5MGIyNDVhNTMxM2EyNjciLCJzaGEyNTY6ZTZmZDJhODUzNTcxYTg5NzVlNjA1Yjc0NmEyMjdlZGQzMmQwODhlZGE5ZjdkYmI4MGUyYTA4NmI5OWRkNjUyNCJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6NGM5MWNmMTEwMmRjZDRlYjkxZjRkYTY4YTJlMGQ5NWQzM2RhYzA4N2U3MTQzMmZjMGVjYWM0MGZlMjNkZjZlMiJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T07:05:28Z",
          "mergedAt": "2026-07-29T08:04:22Z",
          "additions": 192,
          "deletions": 162,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1841,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1841",
          "title": "fix(ci): use identifier-safe producer dependency",
          "body": "## Summary\n\nMake the merge-group qualified Core producer depend on an identifier-safe aggregate job id, while preserving the existing human-visible required check name.\n\n## Related issue\n\nKungfu Assignment `2026-07-28-kungfu-qualified-core-producer-promotion`.\n\n## Changes\n\n- Rename only the aggregate workflow machine id from `affected-native` to `affected_native`.\n- Keep the protected check context `affected-native / linux` unchanged.\n- Bind the macOS producer through `needs.affected_native.result`.\n- Refresh closed-world workflow authority and publication-surface roots.\n- Record the hosted graph invariant in the accepted ADR.\n\n## Verification\n\n- `actionlint .github/workflows/affected-native-pr.yml`\n- `node --test scripts/qualified-assignment-core-artifact.test.mjs scripts/adr-release-gate.test.mjs`\n- `node scripts/kungfu-workflow-authority.mjs`\n- `node framework/release/publication-control-plane.mjs check`\n- Commit-time staged Gate\n- Runtime evidence: merge-group run `30433134539` showed the hyphenated dependency path still skipped the macOS producer\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Use an identifier-safe aggregate job dependency so the exact merge-group qualified Core producer is scheduled\",\n  \"verification\": [\"Hosted merge-group evidence\", \"Exact artifact contract tests\", \"Closed-world workflow authority\", \"Commit-time staged Gate\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects only internal workflow graph identity and evidence projections. It adds no credential or publication authority and preserves the required human-visible check context.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LXF1YWxpZmllZC1hc3NpZ25tZW50LWNvcmUtY2FjaGUtZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtcHJvZHVjZXItcHJvbW90aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiI4M2MxNWNkZWFjMmU3N2E4YjQzNTY4ZDc4OTA2NmI3ZjVlZmNhNzFkIiwicHVsbFJlcXVlc3RIZWFkIjoiNzk3MWI2MjYxODZjZWZmMThmNDBhYWI2NThlYjBiZTY3OWNhODQ0NiIsInJlcGxheWVkQ2FuZGlkYXRlIjoiMmUzNmY0MjYzMTA3YmVjNmQxNGIwMGI4MjUyZTJiZjVjN2YwYjEzOCIsInJlcGxheWVkVHJlZSI6ImM1N2NmZGQzYzM2OTBhMjgwZmE3YzMxM2NhNDNiMzEzYjI3OWNhMDIiLCJxdWV1ZUF0dGVtcHQiOiI3OTcxYjYyNjE4NmNlZmYxOGY0MGFhYjY1OGViMGJlNjc5Y2E4NDQ2QDgzYzE1Y2RlYWMyZTc3YThiNDM1NjhkNzg5MDY2YjdmNWVmY2E3MWQiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6MjQ2NDFhOTkyMmUxODJkNDZhNjgzNGNhMDgwMDQ0OWYyZTQzZGNkODQxYWMzMTYzYzRkOTE0ZTUyMTIyZWIwMiIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjI0NjQxYTk5MjJlMTgyZDQ2YTY4MzRjYTA4MDA0NDlmMmU0M2RjZDg0MWFjMzE2M2M0ZDkxNGU1MjEyMmViMDIiLCJzaGEyNTY6ZDk3ZWI4MzI0ODQ4MjI1MDRkMmJiMGMyNTZlM2E4OThlZDYzOGFjNWNhNjRhZDIwNTgyMTc3NjdiNzllZDg2YyJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzIyYzg0YjMxNzAxMDc5ZTIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6NTFiMDQzYTE1ODhmNjk4ZmFkNWRhNDcxNWI3MGJhNzJlZjhiMDYzMDg5YzNkZTA1Y2I0OTMwZjc1YjJiM2I1OSJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T08:02:51Z",
          "mergedAt": "2026-07-29T08:32:45Z",
          "additions": 101,
          "deletions": 102,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1844,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1844",
          "title": "fix(ci): evaluate producer after proof reuse",
          "body": "## Summary\n\nForce the merge-group qualified Core producer condition to be evaluated after exact PR-proof reuse skips heavy indirect prerequisite jobs.\n\n## Related issue\n\nKungfu Assignment `2026-07-28-kungfu-qualified-core-producer-promotion`.\n\n## Changes\n\n- Add `always()` to the producer job-level condition.\n- Preserve all exact direct-result, event, source, and affected-native gates.\n- Strengthen the artifact contract test to freeze the scheduling invariant.\n- Refresh closed-world workflow authority and publication-surface roots.\n- Record the hosted dependency-propagation invariant in the accepted ADR.\n\n## Verification\n\n- `actionlint .github/workflows/affected-native-pr.yml`\n- `node --test scripts/qualified-assignment-core-artifact.test.mjs scripts/check-kungfu-gate-catalog.test.mjs scripts/affected-native-proof.test.mjs scripts/adr-release-gate.test.mjs`\n- `node scripts/kungfu-workflow-authority.mjs`\n- `node framework/release/publication-control-plane.mjs check`\n- Commit-time staged Gate\n- Runtime evidence: merge-group run `30435705508` reused exact proof, skipped indirect heavy prerequisites, and GitHub skipped the producer before evaluating its otherwise true direct gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Evaluate the exact merge-group qualified Core producer after skipped indirect proof-reuse prerequisites\",\n  \"verification\": [\"Hosted merge-group evidence\", \"Exact artifact contract tests\", \"Closed-world workflow authority\", \"Commit-time staged Gate\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects only trusted workflow scheduling and evidence projections. It adds no credential or publication authority and preserves every exact producer gate.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LXF1YWxpZmllZC1hc3NpZ25tZW50LWNvcmUtY2FjaGUtZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtcHJvZHVjZXItcHJvbW90aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJlMGE5NzVkYjgxNTg4ZDI2NjczMjBkMDM1MmY1ZDUwYzFkNjhhZjdhIiwicHVsbFJlcXVlc3RIZWFkIjoiZTBkMjQ1M2YyZTY3N2RiM2U3NTM4NDg2NzJhOWY3NDA0NjA4ZDU0OSIsInJlcGxheWVkQ2FuZGlkYXRlIjoiN2FhODU5NTkzNzViM2I2ZTdmZmFmMTc4NWQ3MzYxZWUxMmE0YTZiMyIsInJlcGxheWVkVHJlZSI6ImU1YWY2OWYyZjJmZDFkZGQzYzAzNTM2MGUyZDFkOWVhNThmNjlhZmIiLCJxdWV1ZUF0dGVtcHQiOiJlMGQyNDUzZjJlNjc3ZGIzZTc1Mzg0ODY3MmE5Zjc0MDQ2MDhkNTQ5QGUwYTk3NWRiODE1ODhkMjY2NzMyMGQwMzUyZjVkNTBjMWQ2OGFmN2EiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6MTcyYTY3MGUyOTg5NmEwMTNkZGY3MjFjYzgwYzM2NmQ4YzE1NmUwNzhlYmEwYjg2OTUzMjg3ZDFkMWY1MGYyYyIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjE3MmE2NzBlMjk4OTZhMDEzZGRmNzIxY2M4MGMzNjZkOGMxNTZlMDc4ZWJhMGI4Njk1MzI4N2QxZDFmNTBmMmMiLCJzaGEyNTY6ZDk3ZWI4MzI0ODQ4MjI1MDRkMmJiMGMyNTZlM2E4OThlZDYzOGFjNWNhNjRhZDIwNTgyMTc3NjdiNzllZDg2YyJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzIyYzg0YjMxNzAxMDc5ZTIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6ZTkwZmQyODQ0ZDRjNWE3Mzc0MzAzMTU5ZTg2NmVmZDg1ODBmYWZjM2YyZDE5ZGNjNjcyMDUxYzQwNTI2MTcwZCJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T08:38:26Z",
          "mergedAt": "2026-07-29T08:52:32Z",
          "additions": 8,
          "deletions": 5,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 60,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/60",
          "title": "docs(hub): document in-place upgrades",
          "body": "Merge feature/hub-upgrade-guide into dev/v1/v1.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-29T08:53:35Z",
          "mergedAt": "2026-07-29T08:54:02Z",
          "additions": 111,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2035,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2035",
          "title": "fix(signing): dispatch through formal authority ref",
          "body": "## Summary\n- keep consumer/runtime evidence pinned to the exact Buildchain SHA\n- translate exact SHA workflow dispatches to the protected formal artifact-signing authority ref\n- cover exact-pin and formal-ref routing with a native authority regression test\n\n## Validation\n- node --test tests/native-artifact-signing-authority.test.mjs (6/6)\n- git diff --check\n\nThe consumer requires no new configuration. The authority workflow still validates expected-runtime-sha against the checked-out protected authority runtime.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-29T08:51:00Z",
          "mergedAt": "2026-07-29T08:55:01Z",
          "additions": 13,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 61,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/61",
          "title": "chore(release): promote registration recovery to alpha",
          "body": "## Summary\n- promote the actionable Hub registration recovery fixes from dev to alpha\n- include the checked-in in-place upgrade and rollback guide\n- let Buildchain select, qualify, and publish the next immutable Alpha transaction\n\n## Verification\n- PR #58 and PR #59 passed the protected runtime checks\n- PR #60 passed all 55 runtime tests and documentation invariants\n- this promotion must pass the protected alpha Verify check before merge\n\n## Release boundary\nBuildchain owns version selection, multi-architecture image and OCI Compose publication, fresh-install smoke, Release Passport evidence, and the final compose-preview move.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T08:54:58Z",
          "mergedAt": "2026-07-29T08:55:28Z",
          "additions": 248,
          "deletions": 29,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2036,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2036",
          "title": "chore(signing): promote formal dispatch routing",
          "body": "Promote merged Buildchain PR #2035 so exact runtime pins dispatch through the protected formal artifact-signing authority ref. Runtime evidence remains bound to ccce30fb8c8ff6934c0382afa0025eef3fb95f32.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T08:55:58Z",
          "mergedAt": "2026-07-29T08:57:28Z",
          "additions": 718,
          "deletions": 40,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 179,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/179",
          "title": "docs(site): add Hub Starter upgrade path",
          "body": "Merge feature/hub-upgrade-guide into main (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-29T09:00:25Z",
          "mergedAt": "2026-07-29T09:03:43Z",
          "additions": 82,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1842,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1842",
          "title": "feat(work): add verified history selector",
          "body": "## Summary\n\nAdd a build-free, deterministic Work History Selector that produces a content-addressed advisory evidence manifest without gaining Fact, Episode, Assignment, Work Control, Git, or repository authority.\n\n## Related issue\n\nNative Assignment: `2026-07-29-kungfu-work-history-selector`\n\n## Changes\n\n- add rooted request, policy, index snapshot, candidate, and selection-manifest contracts\n- apply authority, temporal, schema, source, supersession, invalidation, applicability, and ranking gates in a fixed order\n- retain explicit exclusions, coverage gaps, confidence, and deterministic tie handling\n- reject invalid roots and shapes without a manifest; return an incomplete zero-selection manifest for stale indexes\n- register source-acceptance, read-only cold-bootstrap, documentation, and versioning coverage\n\n## Verification\n\n- `./shifu check:work-history-selector`\n- `node --test scripts/check-work-history-selector.test.mjs scripts/source-acceptance.test.mjs`\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-77d5-a9ce-e7c798e3a623\",\n    \"KF-ADR-019f9771-4c20-7e2c-8e7c-3f3cb3f1b9bd\"\n  ],\n  \"summary\": \"Add a bounded read-only history selection projection that preserves Project Cut and native Work Control authority boundaries\",\n  \"verification\": [\n    \"./shifu check:work-history-selector\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\nThis additive pre-release selector does not open, settle, supersede, or extend an Evolution Map Stage.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T08:15:53Z",
          "mergedAt": "2026-07-29T09:03:46Z",
          "additions": 2145,
          "deletions": 9,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 62,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/62",
          "title": "Prepare v1.0.0-alpha.9",
          "body": "Create the generated version-state commit for v1.0.0-alpha.9.\n\nBuildchain generated this PR because protected branch alpha/v1/v1.0 rejected direct generated bookkeeping.\n\nRejected update: 795d8f50edb491d8f03d07512fca058b57cee3a6 -> 28787f2b772bf58addedb10c1cf08a2791fb4a4d\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T09:04:57Z",
          "mergedAt": "2026-07-29T09:07:11Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 180,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/180",
          "title": "Release production from 0ff68cd55c8e",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `0ff68cd55c8e9bf2735c05fb7b1b8f957f61c1ce`\n- Artifact hash: `daf4830adace25522e4139dd0508311a813bc329a6c66356e404229605adb6c6`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30438058777)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-0ff68cd55c8e`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-29T09:05:59Z",
          "mergedAt": "2026-07-29T09:13:15Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1843,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1843",
          "title": "feat(dogfood): reconcile queue lifecycle evidence",
          "body": "## Summary\n\nMake native Dogfood queue projections truthful across Issue lifecycle, recurrent Finding clusters, federated component cuts, and impact policy.\n\n## Related issue\n\nNative Assignment `2026-07-29-kungfu-dogfood-queue-lifecycle-reconciliation`.\n\n## Changes\n\n- Separate delivery-complete evidence from resolution-complete state and require the exact current Issue root plus governed resolution roots.\n- Cluster recurrent Findings through bounded semantic dimensions while preserving every immutable Finding root and recurrence.\n- Add federated starvation scope with component cuts, proof roots, explicit omissions, and non-atomic semantics.\n- Normalize canonical impact values, retain deterministic legacy aliases, reject unknown writes, and make blocker attention/release policy explicit.\n- Refresh the CLI catalog and its KFD evidence/support projections.\n\n## Verification\n\n- `pytest -q framework/core/tests/python/test_dogfood_profile.py` — 14 passed.\n- `./shifu test:kfx-profile-suite` — Node, GUI, and Python Profile Suite contracts passed.\n- Profile lifecycle C++/Python/Node suite — passed after rebinding the generated build tree to the persistent repository Ninja.\n- `./shifu check:cli-catalog-parity` — passed.\n- `node scripts/buildchain-kfd-evidence.mjs --check` — passed.\n- `node scripts/kfd-support-matrix.mjs --check` — passed.\n- Staged commit gate — passed, including format, lint, KFD, support matrix, documentation, and negative fixtures.\n\nKnown repository baseline: `./shifu check:domain-profile-authoring` reaches the global canonical-policy check and reports the pre-existing rendered-policy mismatch; the source and checked artifact hashes are identical, and this PR does not modify either policy file.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-71be-a2aa-c8744fa340d8\"],\n  \"summary\": \"Make the native Dogfood responsibility loop truthful across delivery, resolution, recurrence, federation, and impact policy.\",\n  \"verification\": [\n    \"Dogfood Profile tests: 14 passed\",\n    \"KFX Profile Suite contracts passed\",\n    \"Profile lifecycle C++/Python/Node suite passed\",\n    \"CLI catalog, KFD evidence, support matrix, and staged commit gates passed\"\n  ]\n}\n-->\n\n## [Evolution Map](../docs/evolution/README.md) impact\n\nEvolution impact: extends\n\nThis extends the current native responsibility and Dogfood feedback stage without changing authority.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release-evidence changes are deterministic KFD catalog and support-root projections caused by the added CLI scope; no publication or deployment is performed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Profile view, CLI catalog, and verification contracts reflect the behavior change\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T08:22:46Z",
          "mergedAt": "2026-07-29T09:16:26Z",
          "additions": 708,
          "deletions": 63,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 182,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/182",
          "title": "Release production from 0ff68cd55c8e via protected main",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nPublish the already-reviewed staging artifact from protected `main`. This fresh release-intent commit replaces #181, whose reused head SHA inherited the pull-request environment rejection from #180.\n\n### Staging URL\n- https://staging.kungfu.tech\n\n### Release evidence\n- Source SHA: `0ff68cd55c8e9bf2735c05fb7b1b8f957f61c1ce`\n- Artifact hash: `daf4830adace25522e4139dd0508311a813bc329a6c66356e404229605adb6c6`\n- Original Buildchain intent: #180\n- Staging passport: https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30438058777\n\nMerge with a merge commit so the production workflow runs from the protected `main` ref.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T09:17:08Z",
          "mergedAt": "2026-07-29T09:19:46Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1851,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1851",
          "title": "fix(ci): bootstrap producer conan profile",
          "body": "## Summary\n\nBind the hosted qualified Core producer to the existing bounded Buildchain source-build bootstrap so a fresh macOS runner receives a default Conan profile before rebuilding Core.\n\n## Related issue\n\nKungfu Assignment `2026-07-28-kungfu-qualified-core-producer-promotion`.\n\n## Changes\n\n- Declare `KUNGFU_BUILDCHAIN_SOURCE_BUILD=1` only on the trusted merge-group producer job.\n- Reuse `run-conan.js`'s existing profile-exists probe and missing-only `conan profile detect --force` path.\n- Strengthen the workflow artifact contract test.\n- Refresh closed-world workflow authority and publication-surface roots.\n- Record the fresh-runner bootstrap invariant in the accepted ADR.\n\n## Verification\n\n- `actionlint .github/workflows/affected-native-pr.yml`\n- `node --test scripts/qualified-assignment-core-artifact.test.mjs scripts/check-kungfu-gate-catalog.test.mjs scripts/affected-native-proof.test.mjs scripts/adr-release-gate.test.mjs`\n- `node scripts/kungfu-workflow-authority.mjs`\n- `node framework/release/publication-control-plane.mjs check`\n- Commit-time staged Gate\n- Runtime evidence: merge-group run `30436997924`, job `90527714348`, failed because the fresh hosted macOS ARM64 runner had no default Conan profile\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Bootstrap the trusted hosted producer through the existing missing-only Conan profile contract\",\n  \"verification\": [\"Hosted macOS ARM64 failure evidence\", \"Exact artifact contract tests\", \"Closed-world workflow authority\", \"Commit-time staged Gate\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change enables only the existing source-build bootstrap on the already trusted, read-only merge-group producer. It adds no credential or publication authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LXF1YWxpZmllZC1hc3NpZ25tZW50LWNvcmUtY2FjaGUtZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtcHJvZHVjZXItcHJvbW90aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJmMDUxNzQxYWNlZGRkYTQ0YTE5OTQyMDIzNjUwYWMxODkwNmJiOTYzIiwicHVsbFJlcXVlc3RIZWFkIjoiMWMwMzFkZDczZjkwMGViMjhhMjUwZjAyNjAyNTVlNGIyMzljN2IwNCIsInJlcGxheWVkQ2FuZGlkYXRlIjoiNjA2YjAwMmY0NzMxZGI3NGIxYzMwNmNiOGZjOWQ5NDY4NGQ5YjdmMSIsInJlcGxheWVkVHJlZSI6IjRhNDE1ZjY0ZTQyYjI3ZTdjYjQ5YjA5YTVkNGU1ZTAyODUxNWY3NGIiLCJxdWV1ZUF0dGVtcHQiOiIxYzAzMWRkNzNmOTAwZWIyOGEyNTBmMDI2MDI1NWU0YjIzOWM3YjA0QGYwNTE3NDFhY2VkZGRhNDRhMTk5NDIwMjM2NTBhYzE4OTA2YmI5NjMiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6MzE5NzAxODQxMjg0Y2E5N2Y5NzFlNWEyNzk3NWYwZTQwZTQyZDViZGI3YWY1NWQwNDk5NDY0ZTA4MzBiYjM0OCIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjMxOTcwMTg0MTI4NGNhOTdmOTcxZTVhMjc5NzVmMGU0MGU0MmQ1YmRiN2FmNTVkMDQ5OTQ2NGUwODMwYmIzNDgiLCJzaGEyNTY6ZDk3ZWI4MzI0ODQ4MjI1MDRkMmJiMGMyNTZlM2E4OThlZDYzOGFjNWNhNjRhZDIwNTgyMTc3NjdiNzllZDg2YyJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzIyYzg0YjMxNzAxMDc5ZTIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6OWFlNTFkMzIyNjI3YTJmN2ZmNjc2MTE0Mjk4NjdlOTUwYjNmZjQ5NzAzNWVkYzFiOGQwNzQ5N2JiZGExNjc3NiJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T09:18:49Z",
          "mergedAt": "2026-07-29T09:28:06Z",
          "additions": 9,
          "deletions": 5,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1855,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1855",
          "title": "feat(ci): expand local agent patrol cadence",
          "body": "## Summary\n\nRun the isolated agent-121 local-model Patrol as a daily light signal and a weekly deep rotating-fixture qualification, while keeping model outcomes advisory and infrastructure, evidence, privacy, and deduplication gates fail-closed.\n\nThis latest-base linear delivery supersedes #1845, #1846, and #1847.\n\n## Related issue\n\nKungfu Assignment `2026-07-29-kungfu-agent-patrol-cadence`.\n\n## Changes\n\n- schedule light Patrol runs Tuesday through Sunday and a deep Patrol run every Monday at 02:00 CST;\n- add manual light/deep dispatch and one shared non-cancelling concurrency group;\n- retain the exact agent-121 runner, local Qwen model, immutable OpenCode image, bounded timeouts, and sequential execution;\n- rotate the deep run through two of three repository-work fixtures while the light run executes one fixture;\n- keep model-oracle failures advisory while infrastructure, evidence, privacy, and Finding capture failures remain blocking;\n- capture privacy-safe deduplicated Dogfood Findings without automatically admitting Issues;\n- retain only bounded plan, report, classification, and receipt artifacts;\n- bind the recurring Patrol evidence into the staged Agent Work ADR and refresh ADR, KFD-2, support-matrix, workflow-authority, and publication projections.\n\n## Verification\n\n- `./shifu test:agent-patrol` (27 passing)\n- `./shifu kfd:buildchain:check`\n- `./shifu kfd:support-matrix:check`\n- `node framework/release/publication-control-plane.mjs check`\n- `./shifu check:source`\n- staged commit Gate on the latest-base linear commit\n- `./shifu project-cut:queue-admission -- --base origin/dev/v4/v4.0 --head HEAD` (`decision=qualified`, one replayed commit)\n- native Dogfood Finding capture returned `already-present` on the second identical capture\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-786d-aa24-a97705e13917\"],\n  \"summary\": \"Complete the bounded recurring agent-121 Patrol feedback stage with rotating repository-work fixtures and privacy-safe deduplicated Findings\",\n  \"verification\": [\"Full source acceptance\", \"Agent Patrol contract tests\", \"Closed-world workflow authority\", \"KFD evidence closure\", \"Independent PR review\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\nThis PR extends the current Agent Work stage with recurring operational evidence; it does not open or settle a new authority transition.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe Patrol invokes only the office-local Ollama endpoint through the exact pinned OpenCode image and Qwen model. It receives no credentials, retains no prompts or transcripts, grants no publishing authority, and uploads only bounded privacy-safe evidence.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-29T09:34:00Z",
          "mergedAt": "2026-07-29T09:46:00Z",
          "additions": 683,
          "deletions": 136,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1837,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1837",
          "title": "feat(auditable-demo): render Agent Work Lab autoplay",
          "body": "## Summary\n\nReplace the historical agent brief demo input with the exact installed `kungfu agent-work-lab autoplay` command, captured in a bounded real PTY and admitted by the reusable Buildchain Gate. The same Release Passport contract will drive the follow-up README and site projections after the merged-dev exact-source render.\n\n## Dependencies\n\n- build-images #328, released as v1.3.0-alpha.17\n- renderer digest: `sha256:8ba9a614f22e6cfe459d2dcc60bc82f0218e278c6a09ffeee5bda6bc3cbf33b9`\n- Buildchain #2030 at `de1a1cbb1176810ebee91d1e872b441d7113305a`\n- Assignment: `2026-07-29-kungfu-agent-work-lab-auditable-demo`\n\n## Changes\n\n- execute the exact installed autoplay command in a 120x36 PTY with duration, byte, event, archive, privacy, sentinel, and exit bounds\n- bind the terminal capture, transcript, public projection, and scene into the Gate\n- make first-party/System identity, KFD compliance, Product System metadata, package metadata, registry history, scans, and standalone generation explicitly non-authoritative\n- require exact Passport, Core policy, Work or Warrant, explicit capability grant, and runtime isolation for authorization\n- materialize README evidence only from the exact verified Passport and media bundle\n- preserve the prior content-addressed evidence as historical rollback material\n- pin the exact Buildchain Gate and public renderer digest\n- project this stage back to the accepted Agent Work auditable-demo ADR without claiming that final merged-dev media already exists\n\n## Verification\n\n- `./shifu test:auditable-demo`: 27 passed\n- `./shifu check:source`: passed on the final replayed source head\n- `./shifu project-cut:queue-admission`: qualified against `e0a975db81588d2667320d0352f5d50c1d68af7a`\n- `./shifu docs:check`: 118 passed, 0 failed\n- KFD source authority: 166 declared surfaces, 0 implicitly enforced\n- v1.3.0-alpha.17 release evidence and anonymous GHCR manifest both resolve the renderer digest above\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-786d-aa24-a97705e13917\"\n  ],\n  \"summary\": \"Advance the accepted Agent Work auditable-demo lane from the historical brief to the exact installed Agent Work Lab autoplay command without widening authorization authority.\",\n  \"verification\": [\n    \"./shifu test:auditable-demo\",\n    \"./shifu check:source\",\n    \"./shifu project-cut:queue-admission\",\n    \"./shifu docs:check\"\n  ]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo production deployment or publication authority is granted. Final README and site assets require a separate exact merged-source workflow run and the resulting Passport root.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-29T06:39:04Z",
          "mergedAt": "2026-07-29T10:07:41Z",
          "additions": 3642,
          "deletions": 347,
          "changedFiles": 63
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1860,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1860",
          "title": "fix(release): align GitHub attestation signer digest",
          "body": "## Summary\n\nAlign the Kungfu release-candidate attestation policy with the exact immutable Buildchain reusable signer workflow, replayed on the current protected dev head. This supersedes #1856 and #1859.\n\n## Changes\n\n- replace stale signer-bootstrap digest `ad57ae0f` with immutable workflow commit `375b2d4b`\n- refresh the promotion rehearsal contract, Gate workflow binding, and closed-world workflow authority digest\n- regenerate both source-bound semantic-amplification and release-publication projections on `7e0b6e5ee8`\n- preserve the distinct Buildchain runtime SHA and original Linux build-runner evidence\n\n## Verification\n\n- `node --test scripts/release-promotion-rehearsal.test.mjs scripts/alpha-promotion-preflight.test.mjs scripts/check-kungfu-gate-catalog.test.mjs` — 47/47 passed\n- `./shifu maintainability:amplification --check` — passed\n- `./shifu check:release-publication-control-plane` — qualifying, 29 workflows / 10 surfaces\n- `./shifu gate run governance.promotion-rehearsal` — passed with no tracked-file, ref, credential, or remote side effects\n- exact protected replay `7e0b6e5ee8..51d366cac7` — qualified; two commits; no composition change\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This repair aligns an existing GitHub attestation policy digest with the already protected immutable signer workflow and refreshes its generated source-bound projections; it does not change architecture, permissions, artifact bytes, or release authority.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo credential or permission is added. The change narrows verification to the exact GitHub-hosted reusable workflow commit already invoked by Buildchain.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Focused regression coverage and both generated authority projections updated\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI0LWJ1aWxkY2hhaW4tbGludXgtZ2l0aHViLWF0dGVzdGF0aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiI3ZTBiNmU1ZWU4ZTRlYjE2ZTM4ZjlkZGQxZDE5MTFjYWFhZDFhMjEyIiwicHVsbFJlcXVlc3RIZWFkIjoiNTFkMzY2Y2FjN2ExZmY0MTIwNGM3MzA0ZTU2Yjc4NjFhY2MyNzViNiIsInJlcGxheWVkQ2FuZGlkYXRlIjoiNjFlNDlkYmNlODI4MzNhM2ZmZTBjNWFlMWZjZDBmZWQxOThlZmE0ZiIsInJlcGxheWVkVHJlZSI6Ijc1NGUwYmNmNzQ4ZmY5MmIyZDNmMTZlZmY2MzAzYjRmOWY0NTU0ZDgiLCJxdWV1ZUF0dGVtcHQiOiI1MWQzNjZjYWM3YTFmZjQxMjA0YzczMDRlNTZiNzg2MWFjYzI3NWI2QDdlMGI2ZTVlZThlNGViMTZlMzhmOWRkZDFkMTkxMWNhYWFkMWEyMTIiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6NjMzMzFiZDE1N2RkODk0ZjI4MjM1Njk3Nzk0OGRhNjliYzRlOTQ1ZmE0ODJiYWIxYzkxZWM4YTk0YjUxZGQ4NiIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjM5NTJhNzBlNDkzMzM2Njg5ZTk4NTVjZjgzMjU3NDIzYjQxMTg3NWFhYzJhMWRiYjNmMjQ0MDliMTQ3NDIyYWUiLCJzaGEyNTY6NjMzMzFiZDE1N2RkODk0ZjI4MjM1Njk3Nzk0OGRhNjliYzRlOTQ1ZmE0ODJiYWIxYzkxZWM4YTk0YjUxZGQ4NiJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6NjY5M2YzYTI2YjhiNjliNWIwNzQxNmQwNmJjMmQwOTM2ZjUwMDZhNTQ3NTBlMGY1MDJkYzViYmMzMjZkZmM3MiJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T10:13:35Z",
          "mergedAt": "2026-07-29T10:24:22Z",
          "additions": 8,
          "deletions": 8,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1864,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1864",
          "title": "fix(signing): pin formal artifact signing authority",
          "body": "## Summary\n\nPin Kungfu alpha build and release workflows to the promoted Buildchain artifact-signing authority `2de64d5e216c8adaaaaeda12da7771b4814bf809` and refresh the exact contract and generated publication projections. Supersedes repair-required PR #1862 with a fresh linear Project Cut identity.\n\n## Verification\n\n- `KUNGFU_DEV_BRANCH=dev/v4/v4.0 ./shifu check:source`\n- exact Project Cut replay: qualified, one commit, no composition change\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This patch moves existing Kungfu alpha consumers to the already promoted Buildchain artifact-signing authority and refreshes exact generated projections; it does not introduce a new architecture decision or release.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo credential value or permission is added. The protected HK credential island remains the sole signing authority and Beijing remains an untouched backup.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Full source acceptance passed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI2LWJ1aWxkY2hhaW4tY3JlZGVudGlhbC1pc2xhbmQtc2VsZi1kb2dmb29kIiwiZGVsaXZlcnlDbGFzcyI6ImFydGlmYWN0LXNpZ25pbmctYXV0aG9yaXR5IiwiZGV2SGVhZCI6IjM1ZmQ2NjhjODFjZmY3MGUxNjA4NzM4ZTA2YTg5NTQ3N2ZmYWJhY2QiLCJwdWxsUmVxdWVzdEhlYWQiOiI3Njg5MmRiOTQ5Yzg2MTFlMGM3ZDc0ZTgxNTViNmM3MjExOWI2N2IxIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiI4NTk2ZjM5YzRhMDhlNDNkYTUwODgxZmZiMzE1ZjI4M2M5OTVjNDcwIiwicmVwbGF5ZWRUcmVlIjoiMTQ2OTlmZjlhNTU0NGEzMDNlYWI5ZTg5MjlmMTAzZWY4ZjA0MTQ2OCIsInF1ZXVlQXR0ZW1wdCI6Ijc2ODkyZGI5NDljODYxMWUwYzdkNzRlODE1NWI2YzcyMTE5YjY3YjFAMzVmZDY2OGM4MWNmZjcwZTE2MDg3MzhlMDZhODk1NDc3ZmZhYmFjZCIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjpmZjViOWE4MDU3YWU2YmQ3Y2EzOGI3MTU5MDI4NjZjZjkzN2QxYzQyMzUxNGY1ZmZjZDFlZjI3YjBjODEwZGQyIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6MjYwNjg0OWUyZTZiNjY2NzQ1NzZkNTEyNDcyZTVmOGVkZjMzMWY1MDk2MmFlMDVjNzUxOTA2NDgwYjFlZWEwZCIsInNoYTI1NjpmZjViOWE4MDU3YWU2YmQ3Y2EzOGI3MTU5MDI4NjZjZjkzN2QxYzQyMzUxNGY1ZmZjZDFlZjI3YjBjODEwZGQyIl0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZDk5ZjNhOTE2NjczOWUwZCIsImxlYXNlUm9vdCI6InNoYTI1NjplYTA0NzNhYzRkZWI1NWM2ODg2N2E3NWZhODg0MGE0ZWJmNTFiOTM3OWZiMzI2ZmNjNTNkMjk0OTk0NTk5ZmUxIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T10:31:33Z",
          "mergedAt": "2026-07-29T10:48:44Z",
          "additions": 29,
          "deletions": 29,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1866,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1866",
          "title": "fix(product): snapshot runtime pins before assembly",
          "body": "## Summary\n\n- capture the source-authoritative `.uv-version` and `runtime-pins.env` before product assembly mutates the checkout\n- stage the exact captured runtime pin bytes after Core freeze\n- retain fail-closed pin mismatch checks and add regression coverage\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix preserves the existing runtime pin authority and only snapshots its exact source bytes before mutable product assembly.\"\n}\n-->\n\n## Failure evidence\n\nBuild run 30442629961 failed on macOS ARM64 after Core freeze because `.uv-version` was no longer present when `stageTrunk` read it late.\n\n## Validation\n\n- focused runtime pin snapshot tests: 2 passed\n- Biome: passed\n- code complexity ratchet: passed (`dist.mjs` 2528 lines, below current 2530)\n- semantic amplification projection: current\n- source acceptance: 745 passed, 10 environment skips, with the sole local pytest-path failure rerun successfully after creating the pinned Core venv\n- pre-commit staged gate: passed",
          "author": "dongkeren",
          "createdAt": "2026-07-29T10:45:23Z",
          "mergedAt": "2026-07-29T11:03:34Z",
          "additions": 80,
          "deletions": 17,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 1,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/1",
          "title": "docs(paper): draft semantic autopoiesis roadmap",
          "body": "## Summary\n\n- publish the first draft of *Semantic Autopoiesis*\n- define a falsifiable machine proto-organism architecture around KFD, recursive dogfood, replaceable agents, KFX organs, and ordinary computing infrastructure\n- bind the paper to the Buildchain publication and paper-release presets\n- add the Kungfu public repository governance baseline\n\n## Evidence boundary\n\n- distinguishes observed Kungfu mechanisms from engineering inferences and testable hypotheses\n- records Product Release Cut as open in the 2026-07-29 evidence snapshot\n- makes no claim of consciousness, biological life, or completed autonomy\n\n## Checks\n\n- [x] `make check`\n- [x] `make pdf` (Tectonic, 20 pages)\n- [x] rendered PDF visual inspection\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T11:11:47Z",
          "mergedAt": "2026-07-29T11:20:09Z",
          "additions": 2174,
          "deletions": 0,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1870,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1870",
          "title": "feat(work): add work design advisor protocol",
          "body": "## Summary\n\nLatest-base linear successor to #1868. Add a build-free, deterministic Work Design Advisor that produces content-addressed, independently verified advisory topology without gaining Fact, Episode, Assignment, Work Control, Git, or repository authority.\n\n## Related issue\n\nNative Assignment: `2026-07-29-kungfu-work-design-advisor`\n\n## Changes\n\n- bind advice to exact objective/request, verified history selection, Xinfa, policy, and as-of roots\n- produce bounded topology, child slices, dependencies, budgets, delivery class, acceptance, evidence, continuation, confidence, gaps, and human override\n- verify schema, input binding, boundedness, dependency closure, acceptance/evidence coverage, and authority safety independently\n- preserve accepted, adapted, overridden, and insufficient-history dispositions without mutating the source advice\n- keep capture, claim, dispatch, execute, approve, merge, close, Assignment, and Work Control authority explicitly false\n- qualify advisory readiness with one verified sample; 30 samples remain a future default-policy promotion threshold only\n\n## Verification\n\n- `./shifu check:work-design-advisor`\n- `./shifu check:test-manifest`\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-77d5-a9ce-e7c798e3a623\",\n    \"KF-ADR-019f9771-4c20-7e2c-8e7c-3f3cb3f1b9bd\"\n  ],\n  \"summary\": \"Add a bounded advisory-only work design projection with independent verification and explicit non-authority semantics\",\n  \"verification\": [\n    \"./shifu check:work-design-advisor\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\nThis additive pre-release advisor does not open, settle, supersede, or extend an Evolution Map Stage.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T11:07:22Z",
          "mergedAt": "2026-07-29T11:20:39Z",
          "additions": 1889,
          "deletions": 8,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 3,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/3",
          "title": "fix(release): delegate Buildchain publication permissions",
          "body": "## Summary\n\nDelegate the least permissions required by the Buildchain v3 nested paper-release jobs:\n\n- `actions: read`\n- `checks: write`\n- `pull-requests: read`\n\nThe alpha run failed closed during workflow startup before any publication job ran.\n\n## Evidence\n\n- GitHub startup annotation: nested publication authority requested actions/checks/pull-request access not delegated by the caller\n- `make check`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T12:02:12Z",
          "mergedAt": "2026-07-29T12:03:29Z",
          "additions": 3,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 4,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/4",
          "title": "fix(release): use sealed paper publication preset",
          "body": "## Summary\n\n- switch the paper release lane to Buildchain sealed publication authority\n- bind the repository-local trusted publisher workflow\n- bind the declared PDF artifact explicitly\n\n## Verification\n\n- `make check`\n- `git diff --check`\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider billing, quota, or usage-attribution changes\n- [x] No official hosted-service behavior changes\n- [x] No branding, package-name, release-identity, or domain changes\n- [x] Release evidence/provenance changed: publication now uses the sealed Buildchain authority lane\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T12:12:03Z",
          "mergedAt": "2026-07-29T12:13:23Z",
          "additions": 3,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 5,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/5",
          "title": "fix(release): inherit sealed authority secret",
          "body": "## Summary\n\n- pass repository-accessible Actions secrets into the sealed Buildchain workflow\n- allow the nested publication authority job to receive the dedicated read-only governance auditor App key\n- keep registry publication bound to npm Trusted Publishing and OIDC\n\n## Verification\n\n- `make check`\n- `git diff --check`\n- sealed run `30450723359` built the candidate successfully and isolated the failure to an empty governance auditor private-key input\n\n## Governance\n\n- [x] No credential values are read, copied, logged, or committed\n- [x] No provider billing, quota, or usage-attribution changes\n- [x] No official hosted-service behavior changes\n- [x] No branding, package-name, release-identity, or domain changes\n- [x] Release authority secret routing changed; the authority remains fail-closed\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-29T12:17:31Z",
          "mergedAt": "2026-07-29T12:18:54Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1877,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1877",
          "title": "fix(ci): stabilize Agent Patrol checkout transport",
          "body": "## Summary\n\nStabilize the protected-source checkout used by the dedicated agent-121 Patrol after repeated HTTP/2 stream cancellation and early-EOF failures. The change is scoped to the checkout step and preserves the exact source, runner, credential, model, evidence, and concurrency boundaries.\n\n## Related issue\n\nKungfu Assignment 2026-07-29-kungfu-agent-patrol-cadence.\n\n## Changes\n\n- force Git HTTP/1.1 only for the pinned actions/checkout step through GIT_CONFIG_COUNT;\n- preserve github.sha, fetch-depth 1, and persist-credentials false;\n- add a workflow contract that rejects transport, ref, credential, or runner-global config drift;\n- document the bounded transport fallback;\n- refresh the closed-world workflow authority and release publication source roots.\n\n## Verification\n\n- node --test scripts/agent-patrol-workflow.test.mjs (6 passing)\n- Git configuration environment readback returned HTTP/1.1\n- git diff --check\n- staged commit Gate passed, including Gate catalog, documentation, KFD, and workflow authority checks\n- ./shifu check:source passed the changed workflow authority, Gate catalog, publication control, documentation, and 755 contract tests; the only local failure was the unrelated cold-fixture pytest executable prerequisite missing from PATH\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This reliability fix changes only the transport used by the existing exact protected-source checkout; it does not alter Patrol authority, architecture, evidence, or model contracts\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\nThis is a bounded CI transport reliability fix with no authority transition.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe workflow remains non-publication. Generated authority and publication-control roots are refreshed only to bind the modified workflow bytes.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-29T12:11:34Z",
          "mergedAt": "2026-07-29T12:21:31Z",
          "additions": 24,
          "deletions": 4,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2038,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2038",
          "title": "fix(governance): admit machine life paper targets",
          "body": "## Summary\n\n- admit `paper-kfd-machine-life-roadmap` into the closed-world GitHub governance authority\n- bind `main`, `dev/v0/v0.1`, and `alpha/v0/v0.1` to the paper check context\n- refresh generated public contract digests and add direct registry coverage\n\n## Verification\n\n- `node --test tests/github-governance-authority.test.mjs` (29/29 passed)\n- `pnpm run check` (958/961 passed; three pre-existing local macOS signing fixture failures outside the changed surfaces)\n- generated site bundle is current\n- the consumer alpha branch now has descriptor-matching native protection with frozen receipt root `sha256:6bd35c9089bd9249a3818e3283e73926080d465244f67fb9ce93100a20a82265`\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider billing, quota, or usage-attribution changes\n- [x] No official hosted-service behavior changes\n- [x] No branding, package-name, release-identity, or domain changes\n- [x] Release evidence/provenance changes are explicit and fail closed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T12:29:34Z",
          "mergedAt": "2026-07-29T12:45:11Z",
          "additions": 27,
          "deletions": 9,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 6,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/6",
          "title": "chore(release): admit v0.1.0-alpha.0",
          "body": "## Summary\n\nCreate the provider-enforced publication transaction for the first alpha release. This authorization commit intentionally leaves the paper tree unchanged.\n\n## Validation\n\n- source remains the reviewed `0.1.0-alpha.0` paper tree\n- required `check / check` runs on this exact PR head\n- merge into protected `alpha/v0/v0.1` requires an independent CODEOWNER approval\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-29T12:50:43Z",
          "mergedAt": "2026-07-29T12:51:51Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 7,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/7",
          "title": "chore(release): promote v0.1.0-alpha.0",
          "body": "## Summary\n\nPromote the first paper alpha through the canonical `dev/v0/v0.1 -> alpha/v0/v0.1` Buildchain channel transaction. The promotion commit intentionally leaves the reviewed paper tree unchanged.\n\n## Validation\n\n- both line branches use the admitted Buildchain governance policy\n- exact PR head must pass `check / check`\n- protected alpha merge requires a fresh independent CODEOWNER approval\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-29T12:56:04Z",
          "mergedAt": "2026-07-29T12:57:25Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2040,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2040",
          "title": "fix(release): allow zero-major alpha lines",
          "body": "## Summary\n\nTreat major `0` as a valid parsed release-line major when resolving alpha publication dist-tags. The previous truthiness check rejected legal `v0.x` paper channels after all governance and publication evidence had qualified.\n\n## Validation\n\n- `pnpm exec node --test tests/promote-buildchain-ref.test.mjs` (139/139)\n- `pnpm --filter @kungfu-systems/buildchain-promote-buildchain-ref build`\n- `node scripts/check-action-bundles.mjs`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:02:11Z",
          "mergedAt": "2026-07-29T13:05:57Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2039,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2039",
          "title": "fix(signing): replace stale request outputs",
          "body": "## Summary\n\n- validate the lifecycle manifest and declared subjects before replacing Buildchain-owned signing request output\n- reject output roots that could contain workspace/source material\n- make repeated sealing on reused self-hosted runner workspaces deterministic and stale-free\n- normalize macOS real-path containment for `/var` temporary workspaces\n\n## Verification\n\n- `node --test tests/artifact-signing-seal.test.mjs` (4/4)\n- `node --test tests/artifact-signing-seal.test.mjs tests/build-surface.test.mjs` (93/93)\n- `pnpm run check:workflows`\n- `pnpm run check` (962/963; the sole `BadZipFile` compound-archive fixture failure reproduces unchanged at formal authority `2de64d5e216c8adaaaaeda12da7771b4814bf809` on local Python 3.14)\n\n## Downstream failure closed\n\nKungfu candidate run 30451274495 failed on a reused macOS self-hosted workspace because `COPYFILE_EXCL` encountered a prior request payload. This change replaces only the validated Buildchain-owned request root before current materialization.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T12:59:06Z",
          "mergedAt": "2026-07-29T13:07:51Z",
          "additions": 165,
          "deletions": 18,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2041,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2041",
          "title": "chore(signing): promote reused-workspace sealing fix",
          "body": "Promote the reviewed v3 runtime after Buildchain PR #2039 closed stale signing-request output on reused self-hosted runner workspaces.\n\nThe authority candidate binds exact dev head `df74fe8fafd8a2f963c9a066fe2d1029e8e5593e`; the signing fix itself is `1bb91d7aad1e7cdb62723d0f9fc38c02427d7dd2`, with deterministic site refresh `8bac01e6853f3bc5c3b243a22a2fd5cab32b79e1`. PR #2039 passed protected review, `check`, governance, and the full Build Surface Fixture before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:08:49Z",
          "mergedAt": "2026-07-29T13:10:45Z",
          "additions": 198,
          "deletions": 28,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 8,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/8",
          "title": "fix(release): allow bookkeeping pull requests",
          "body": "## Summary\n\nGrant the sealed release job the narrowly required `pull_requests: write` permission so Buildchain can create its generated version-state PR when the protected dev line rejects direct bookkeeping.\n\nThe npm alpha was already published byte-for-byte; this change allows the durable transaction to resume and finish GitHub Release finalization.\n\n## Validation\n\n- workflow diff is limited to `pull-requests: read -> write`\n- `git diff --check`\n- protected dev and alpha PR gates remain in force\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:10:09Z",
          "mergedAt": "2026-07-29T13:11:31Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 11,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/11",
          "title": "chore(release): refresh alpha promotion authority",
          "body": "## Summary\n\nCreate an exact-head authorization transaction whose last pusher is the development identity. This allows the protected dev-to-alpha PR to receive a genuinely independent fresh approval under `require_last_push_approval`.\n\nThe commit is intentionally tree-neutral.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:15:20Z",
          "mergedAt": "2026-07-29T13:16:32Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 12,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/12",
          "title": "chore(release): bind development promotion identity",
          "body": "## Summary\n\nCreate a tree-neutral exact-head transaction explicitly merged by the development identity after independent review. This satisfies the protected alpha line requirement that the approving Code Owner differ from the last dev pusher.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:17:31Z",
          "mergedAt": "2026-07-29T13:18:48Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1879,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1879",
          "title": "feat(governance): add deprecation lifecycle authority",
          "body": "## Summary\n\n- establish the common versioned deprecation lifecycle authority and structured read-only audit\n- migrate Core ledger and Shifu release gates to the shared authority\n- document public surface promises, removal boundaries, Warrant handling, and migration evidence\n- replace #1861, #1867, #1869, #1873, and #1875 with one latest-base queue-replayable commit; no published history was rewritten\n\n## Verification\n\n- `./shifu check:deprecation-lifecycle` (28/28)\n- `./shifu adr:release:gate -- --contract-only`\n- `./shifu release:promotion:rehearse`\n- `./shifu docs:check`\n- `./shifu check:gate-catalog`\n- `./shifu check:source` (756 source-contract tests; all required suites passed, 10 platform-capability skips)\n- `./shifu project-cut:queue-admission -- --base origin/dev/v4/v4.0 --head HEAD`\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"implemented\",\"adrs\":[\"KF-ADR-019fad41-07fe-7f1e-a37a-a2572357700c\"],\"summary\":\"Common deprecation lifecycle authority, registry, audit, gates, fixtures, and public guidance are implemented and source-accepted.\",\"verification\":[\"./shifu check:deprecation-lifecycle\",\"./shifu release:promotion:rehearse\",\"./shifu check:source\"]}\n-->\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI5LWt1bmdmdS1kZXByZWNhdGlvbi1saWZlY3ljbGUtZ292ZXJuYW5jZSIsImRlbGl2ZXJ5Q2xhc3MiOiJjcm9zcy1sYXllci1nb3Zlcm5hbmNlLWFuZC1yZWxlYXNlLWdhdGUiLCJkZXZIZWFkIjoiNDdiYjdlN2Y1YWI0MTkyN2EzZjNjNTZhM2M2ZGRlMTgwN2M0NTk2NSIsInB1bGxSZXF1ZXN0SGVhZCI6ImQ0ZmY5OWY2MzkzYTA1NjJiNWI4YmY1NjE0MmFmOGM2N2Q2NWQyMjQiLCJyZXBsYXllZENhbmRpZGF0ZSI6Ijg1ZTIyNTQ4NmQ5OTgwODJkZjBlMzdkZGFjMmVlZGJhMDg1NjA2MGEiLCJyZXBsYXllZFRyZWUiOiJiNTQyMzQ3MzE4YTY4NDEyYjIxMGM2OTM4NDExMTVmNzYyNmI1ZDEwIiwicXVldWVBdHRlbXB0IjoiZDRmZjk5ZjYzOTNhMDU2MmI1YjhiZjU2MTQyYWY4YzY3ZDY1ZDIyNEA0N2JiN2U3ZjVhYjQxOTI3YTNmM2M1NmEzYzZkZGUxODA3YzQ1OTY1IiwiYWRtaXNzaW9uUHJvb2ZSb290Ijoic2hhMjU2OmY3NjkwNDBlZDNjYjM4N2UwNWYyM2RhZDBiOTI0OGNkOTUzYTg4ZmQzMDA1YmYzZjJkOGFhNWQ3ODg4YjkxMjYiLCJhZG1pc3Npb25Qcm9vZlJvb3RzIjpbInNoYTI1Njo0MGVhODAxZDdmZDFjZmQxZWYwNmY3ZDBmODE2NjY5MjkzZThhMTQ0OTc1ZmMyMmMzM2M1NWU1OWMyOGFmZTM5Iiwic2hhMjU2OmY3NjkwNDBlZDNjYjM4N2UwNWYyM2RhZDBiOTI0OGNkOTUzYTg4ZmQzMDA1YmYzZjJkOGFhNWQ3ODg4YjkxMjYiXSwic3RhdHVzQ29udGV4dCI6IlF1ZXVlIGZhbWlseSBsZWFzZS9kOTlmM2E5MTY2NzM5ZTBkIiwibGVhc2VSb290Ijoic2hhMjU2OjlhNWZhZWJkZGY0NzNmNzJiYWIxZTAwMzdiY2NlZTg4YTEzNmY5ZDAzMzIwYTk3Yjg4MDhmNzU0NWViYWU4NTQifQ -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T12:23:47Z",
          "mergedAt": "2026-07-29T13:20:18Z",
          "additions": 2143,
          "deletions": 63,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 13,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/13",
          "title": "chore(release): sync alpha lineage into dev",
          "body": "## Summary\n\nBring the already-reviewed alpha merge history back into the protected dev line through a normal PR. The resulting tree preserves the dev workflow permission change and removes the behind-base condition from the dev-to-alpha promotion.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:20:11Z",
          "mergedAt": "2026-07-29T13:21:23Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 14,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/14",
          "title": "fix(release): promote resumable paper publication",
          "body": "## Summary\n\nPromote the reviewed release-bookkeeping permission from the synchronized protected dev line to alpha. This allows the already-published npm alpha transaction to resume, create its generated version-state PR, and finish the GitHub Release.\n\n## Validation\n\n- dev and alpha histories are synchronized through PR #13\n- the paper tree is unchanged except `pull-requests: write` in the sealed release caller\n- fresh exact-head checks and independent CODEOWNER approval are required\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:25:14Z",
          "mergedAt": "2026-07-29T13:26:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1883,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1883",
          "title": "fix(ci): accept prefixed runtime recovery command",
          "body": "## Summary\n\n- keep the runtime surface qualification bound to the GUI recovery path through the shared public CLI\n- admit the existing optional `argsPrefix` before the literal `runtime stop` command\n- preserve the prohibition on ordinary lifecycle ownership in GUI recovery\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This qualification bugfix updates a stale source assertion to the existing prefixed public CLI invocation without changing runtime authority or behavior.\"\n}\n-->\n\n## Failure evidence\n\nFinal Build run 30446260284 attempt 2, Linux x64 job 90566601803, passed the native build and 72/72 build-chain verification before `runtime-surface-parity` rejected `[...(options.argsPrefix ?? []), 'runtime', 'stop']` with the obsolete exact-array regex.\n\n## Validation\n\n- `node scripts/check-runtime-surface-integration.mjs`: passed, 7 surfaces and 14 KFX actions\n- `node --check scripts/check-runtime-surface-integration.mjs`: passed\n- `git diff --check`: passed\n- pre-commit staged gate: passed, including 53 dev-required latency tests, 17 invariant tests, 118 documentation tests, deterministic docs gate, and Biome",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:07:55Z",
          "mergedAt": "2026-07-29T13:30:40Z",
          "additions": 4,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 15,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/15",
          "title": "chore(release): prepare v0.1.0-alpha.1",
          "body": "## Summary\n\n- advance the paper publication version to `0.1.0-alpha.1`\n- preserve the published `alpha.0` transaction and create a fresh immutable release identity\n\n## Validation\n\n- `make check`\n- `git diff --check`\n\n## Version impact\n\nPrerelease patch increment on the existing v0.1 line.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:45:06Z",
          "mergedAt": "2026-07-29T13:46:31Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2042,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2042",
          "title": "fix(paper-release): allow generated bookkeeping pull requests",
          "body": "## Summary\n\n- grant the sealed paper publication job pull-request write authority\n- lock the permission contract with a regression test\n\n## Validation\n\n- `pnpm exec node --test tests/paper-sealed-release.test.mjs`\n- `pnpm exec node --test --test-name-pattern=\"paper release workflow publishes\" tests/build-surface.test.mjs`\n- `pnpm run check:workflows`\n- `git diff --check`\n\n## Release impact\n\nPatch. This restores the existing generated version-state PR path without changing package or artifact semantics.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:39:18Z",
          "mergedAt": "2026-07-29T13:47:20Z",
          "additions": 5,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 17,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/17",
          "title": "chore(release): bind alpha.1 promotion identity",
          "body": "## Summary\n\nCreate a tree-neutral release identity commit so the protected alpha promotion can satisfy fresh-review and last-push separation after the alpha.1 version cut.\n\n## Validation\n\n- empty commit; tree is identical to `4c90e3d0e4221f34efa905d6c6c5af5f7cebe979`\n- DCO sign-off present\n\nNo paper, package, or workflow bytes change.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:47:58Z",
          "mergedAt": "2026-07-29T13:49:49Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 233,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/233",
          "title": "feat(papers): publish machine life roadmap",
          "body": "## Summary\n\n- consume `@kungfu-tech/paper-kfd-machine-life-roadmap@0.1.0-alpha.0`\n- render the package-owned paper, latest, and immutable archive routes\n- extend the publication package-set and lockfile checks to five papers\n\n## Verification\n\n- `pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `pnpm run build`\n- `pnpm run check`\n\n## Release surface\n\nMerging to `main` updates the protected staging web surface through the existing Buildchain workflow. Production is unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:32:40Z",
          "mergedAt": "2026-07-29T13:50:40Z",
          "additions": 17,
          "deletions": 1,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 18,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/18",
          "title": "chore(release): sync alpha lineage before alpha.1",
          "body": "## Summary\n\nMerge the current protected alpha lineage into the development channel before promoting alpha.1.\n\n## Validation\n\n- first parent: `7a93501a8f0ab12a7cc6893a18a83810d85477eb`\n- alpha parent: `2a7f0f4a418284fc0982cac05bbd50473df59313`\n- tree diff against the first parent: empty\n- DCO sign-off present\n\nThis is graph synchronization only; paper, package, and workflow bytes are unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:51:42Z",
          "mergedAt": "2026-07-29T13:53:27Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1839,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1839",
          "title": "fix(work-control): read Windows long-path capture receipts",
          "body": "## Summary\n\n- route captured Assignment request and receipt reads through the same Windows extended-length filesystem namespace as atomic writes\n- preserve logical paths and receipt identity while enumerating long receipt directories safely\n- cover request, directory, and receipt read paths with a regression test\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python:framework/core/build/Release uv run --project framework/core --frozen pytest -q framework/core/tests/python/test_assignment_orchestration.py` (62 passed)\n- `node --test product/scripts/dist.test.mjs` (Assignment admission smoke passed; 26/27 overall, one unrelated macOS `/var` symlink-alias fixture failure)\n- `./shifu check:source` (passed; 750 contract tests, Python suites, desktop tests, mypy, ruff, Biome, clang-format)\n- repository staged gate and pre-commit gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Complete Windows filesystem compatibility for the existing Assignment capture contract without changing product architecture or release authority.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Regression test added\n- [x] No release credentials or publication authority\n- [x] Logical Assignment identities and receipt paths are unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-29T07:18:42Z",
          "mergedAt": "2026-07-29T13:53:43Z",
          "additions": 94,
          "deletions": 46,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 19,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/19",
          "title": "chore(release): promote v0.1.0-alpha.1",
          "body": "## Summary\n\nPromote the final reviewed `v0.1.0-alpha.1` development cut to the protected alpha channel.\n\n## Evidence\n\n- version PR: #15\n- release identity PR: #17\n- alpha-lineage sync PR: #18\n- exact dev head: `b7ea01570515cfd341e3081c5e7580b57226c58b`\n- current alpha is an ancestor of the exact dev head\n\nThe release workflow will be dispatched manually with exact Buildchain runtime `4282534accd4344ded43b10cae021fc2e709b7f9` after this promotion merges.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:55:46Z",
          "mergedAt": "2026-07-29T13:57:20Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 63,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/63",
          "title": "fix(hub): retry transient database startup",
          "body": "## Summary\n\n- retry only transient Docker DNS, network, and PostgreSQL startup failures before the Hub exits\n- preserve fail-fast behavior for authentication, migration, and permission errors\n- qualify each Buildchain publication by upgrading the previous Compose preview in place and proving account/course persistence on the same PostgreSQL container\n- retry short-lived OCI pull/start failures during release qualification\n\n## Validation\n\n- `npm run check` (59 tests passed)\n- `bash -n scripts/publish-runtime-release.sh`\n- `shellcheck scripts/publish-runtime-release.sh` (only pre-existing SC2016 informational finding)\n- exact `compose-preview@sha256:...` application config resolution verified with Docker Compose\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:58:01Z",
          "mergedAt": "2026-07-29T13:58:49Z",
          "additions": 248,
          "deletions": 17,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 64,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/64",
          "title": "fix(release): promote Hub database startup recovery",
          "body": "## Alpha promotion\n\nPromote the verified Hub database startup recovery and preserved-volume application upgrade qualification from `dev/v1/v1.0`.\n\n- source PR: #63\n- expected impact: patch-level Alpha prerelease\n- publication remains owned by the successful Verify `workflow_run` and Buildchain transaction\n- rollback coordinate remains the exact `compose-v1.0.0-alpha.9` application\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:59:28Z",
          "mergedAt": "2026-07-29T14:00:09Z",
          "additions": 248,
          "deletions": 17,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 65,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/65",
          "title": "Prepare v1.0.0-alpha.10",
          "body": "Create the generated version-state commit for v1.0.0-alpha.10.\n\nBuildchain generated this PR because protected branch alpha/v1/v1.0 rejected direct generated bookkeeping.\n\nRejected update: 8ea4291a78eda9a6185ebce22e544823506d60b3 -> a1cf574f3338c5ef522d49ae8575d4f88ed9bb00\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T14:09:03Z",
          "mergedAt": "2026-07-29T14:10:28Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1874,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1874",
          "title": "refactor(work-control): close canonical naming debt",
          "body": "## Summary\n\nMake Work Control the sole current and discoverable product identity while preserving Mission Control v3 only as an explicit, read-only compatibility boundary. This closes naming debt across KFX packages, Python modules, CLI, GUI, TUI, Agent surfaces, documentation, generated projections, and packaged output without introducing a second writer or rewriting retained facts.\n\nRelated Native Assignment: `2026-07-29-kungfu-work-control-naming-debt-closure`.\n\n## Related issue\n\nNative Initiative `2026-07-21-kungfu-initiative-assignment-control-plane` / Assignment `2026-07-29-kungfu-work-control-naming-debt-closure`.\n\n## Changes\n\n- Rename active Profile, member, module, dashboard, and contribution paths to Work Control.\n- Isolate retained v3 readers and protocol literals under explicit compatibility boundaries.\n- Keep legacy CLI entrypoints hidden and replacement-directed without creating a peer action identity.\n- Add classified reverse scanning for source and packaged output, plus bounded maintainability policy coverage.\n- Preserve the five Work Control npm identities and the closed 29-package publication inventory.\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu test:mission-authority-cutover`\n- `./shifu freeze` followed by packaged vocabulary scanning\n- installed-product CLI and Python compatibility qualification\n- five Work Control npm package dry-runs\n- exact affected-native plan: full profile, 36 targets, 22 tests, SDK qualification required\n\nNo package publication, registry mutation, release, or deployment was executed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-719a-866a-28afd48c21dc\",\n    \"KF-ADR-019f86da-4f90-732e-826c-e994acc20716\",\n    \"KF-ADR-019f8759-ab29-7627-bc04-6aba547ea45f\",\n    \"KF-ADR-019f87cc-bd45-7a5c-9b37-1d6b5917928a\",\n    \"KF-ADR-019f9771-4c20-7e2c-8e7c-3f3cb3f1b9bd\"\n  ],\n  \"summary\": \"Close current Work Control naming debt while retaining sealed Mission Control v3 compatibility evidence under one writer.\",\n  \"verification\": [\n    \"source acceptance and focused Work Control suites\",\n    \"packaged and installed-product qualification\",\n    \"npm package dry-runs and affected-native Gate\"\n  ]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: opens\n\nThis PR opens Stage 09 for canonical Work Control identity closure and records the load-bearing transition from mixed current naming to one current product identity plus a bounded compatibility boundary.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change updates current branding and package identity projections and validates publication inventory and packability. It does not publish or deploy anything.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjEta3VuZ2Z1LWluaXRpYXRpdmUtYXNzaWdubWVudC1jb250cm9sLXBsYW5lIiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOS1rdW5nZnUtd29yay1jb250cm9sLW5hbWluZy1kZWJ0LWNsb3N1cmUiLCJkZWxpdmVyeUNsYXNzIjoiY3Jvc3Mtc3VyZmFjZS1taWdyYXRpb24tcHJvb2YtcmVxdWlyZWQiLCJkZXZIZWFkIjoiOTlkYjdmZmEwMjJiMTBiYWM0MjVjZjE2MzEyZTI5MmY3ZGY2ZDRjZSIsInB1bGxSZXF1ZXN0SGVhZCI6IjZkODhjOWIxNDk4ZDU1ODdiZWIzZDM3NzQxMDA3OTUzOTY0ODg1NWIiLCJyZXBsYXllZENhbmRpZGF0ZSI6IjY0MGE5Y2Q5ZTcyMDUzZTVmMjI5MTdiZDM1ZWJjM2UyNGJiNmQ1OWYiLCJyZXBsYXllZFRyZWUiOiIzMjhhMjdkYzFkMDQ3ZWM0ODg5MWM2NTYxNDQ1OWIxYjk1MmZhZjE0IiwicXVldWVBdHRlbXB0IjoiNmQ4OGM5YjE0OThkNTU4N2JlYjNkMzc3NDEwMDc5NTM5NjQ4ODU1YkA5OWRiN2ZmYTAyMmIxMGJhYzQyNWNmMTYzMTJlMjkyZjdkZjZkNGNlIiwiYWRtaXNzaW9uUHJvb2ZSb290Ijoic2hhMjU2OmMzNTkwZmU3Y2Y3MDliNTJjMWI0MTQ5NDM2OGRjNzMwYzJmOWYxNDUyYjc3MjEyOTE1YTQxMDBjNTUyNzJmMzgiLCJhZG1pc3Npb25Qcm9vZlJvb3RzIjpbInNoYTI1NjpjMzU5MGZlN2NmNzA5YjUyYzFiNDE0OTQzNjhkYzczMGMyZjlmMTQ1MmI3NzIxMjkxNWE0MTAwYzU1MjcyZjM4Iiwic2hhMjU2OmY3ZjE3OWM4OTg3ZDlkMjMxN2EzZTIyZDZmYzQ4ZWVhYmI2MDQ0ZDE5OTUzNWY2ZjdmNWQ0MTZjMWM0NDIzOTYiXSwic3RhdHVzQ29udGV4dCI6IlF1ZXVlIGZhbWlseSBsZWFzZS9kOTM4ODgwMjFkNWI0NzlmIiwibGVhc2VSb290Ijoic2hhMjU2OmYxNDUxNmM4YTE0NTc2MDM5ZTQ1NWExNTMzMzc4MDJlYmUzN2U1OWI4YTU2ZmFlZjJjN2VhMTg1MTc1ZjFiOTcifQ -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T11:29:39Z",
          "mergedAt": "2026-07-29T14:43:57Z",
          "additions": 3590,
          "deletions": 3988,
          "changedFiles": 185
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1885,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1885",
          "title": "fix(signing): advance Buildchain artifact authority",
          "body": "## Summary\n\nAdvance the Kungfu Alpha build and release consumers to protected Buildchain v3 artifact-signing authority `8ec8ef36421fc363ebfb24146ca1d0a2fee4ae7b`. This authority contains the idempotent artifact-signing request output fix required by reused macOS runner workspaces while preserving the existing Linux GitHub-native keyless attestation contract.\n\n## Related issue\n\nAtlas Assignment: `2026-07-24-buildchain-linux-github-attestation`\n\n## Changes\n\n- pin both reusable Buildchain workflows and the Alpha contract lock to the promoted v3 authority;\n- refresh workflow authority, release admission, publication, and semantic amplification projections;\n- retain the exact GitHub attestation signer workflow and stable release authority unchanged.\n\n## Verification\n\n- `KUNGFU_DEV_BRANCH=dev/v4/v4.0 uv run --no-project --with pytest --with ruff -- ./shifu check:source`: all repository and release/signing checks passed; the only local bootstrap probe required the remaining declared Core runtime dependencies.\n- `uv run --no-project --with pytest --with ruff --with click --with jsonschema --with psutil --with tabulate --with flatbuffers node --test scripts/readonly-agent-bootstrap.test.mjs`: 1/1 passed.\n- exact Project Cut replay against `f4c7559b4b6edbe9c53d2a9d395b4cff0dd93d0f`: qualified, one commit, no composition change.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This patch advances existing Kungfu Alpha consumers to the already promoted Buildchain v3 artifact-signing authority and refreshes exact generated projections; it does not introduce a new architecture decision or release.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo credential value or signing material is added. Existing protected GitHub OIDC and credential-island boundaries remain unchanged.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Source and release authority checks passed\n- [x] Exact family queue replay is qualified\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI0LWJ1aWxkY2hhaW4tbGludXgtZ2l0aHViLWF0dGVzdGF0aW9uIiwiZGVsaXZlcnlDbGFzcyI6ImFydGlmYWN0LXNpZ25pbmctYXV0aG9yaXR5IiwiZGV2SGVhZCI6ImY0Yzc1NTliNGI2ZWRiZTljNTNkMmE5ZDM5NWI0Y2ZmMGRkOTNkMGYiLCJwdWxsUmVxdWVzdEhlYWQiOiJlNzU1OThhOTQzZjcwZThiYzY0MjU0YWRjNDlhOTIzNjBiMTRiMmRjIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiIwMjE1ZTUxYTJhN2Y2NjM2Mjc3YzIxZWEyMDYxNTk1ZjhkMGZhM2MyIiwicmVwbGF5ZWRUcmVlIjoiNDczYmM3YzQ1ZDU3MjVhYTcwOGFmZjgyMjFjOTBiODNiZmYwODE1NyIsInF1ZXVlQXR0ZW1wdCI6ImU3NTU5OGE5NDNmNzBlOGJjNjQyNTRhZGM0OWE5MjM2MGIxNGIyZGNAZjRjNzU1OWI0YjZlZGJlOWM1M2QyYTlkMzk1YjRjZmYwZGQ5M2QwZiIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1Njo1ZWJiZGRmNGZmMGE1ZGY1Y2IyZmRkYjI0YmIyYjFlOWMxMzk2NTZjZTk4YTEzMjgwMTA1NmQ0MzBhZGMzNTIxIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6Mzk1MmE3MGU0OTMzMzY2ODllOTg1NWNmODMyNTc0MjNiNDExODc1YWFjMmExZGJiM2YyNDQwOWIxNDc0MjJhZSIsInNoYTI1Njo1ZWJiZGRmNGZmMGE1ZGY1Y2IyZmRkYjI0YmIyYjFlOWMxMzk2NTZjZTk4YTEzMjgwMTA1NmQ0MzBhZGMzNTIxIl0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZDk5ZjNhOTE2NjczOWUwZCIsImxlYXNlUm9vdCI6InNoYTI1NjpiNTcyMmM5ODhjMzdmNzNlNGE5ZDJlMDljMTdiOGNkY2UzNGFlMzVmYTQzYTdmYzEyZWZhZDIwNTdiNzA3ODIzIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T13:42:47Z",
          "mergedAt": "2026-07-29T14:55:40Z",
          "additions": 29,
          "deletions": 29,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 20,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/20",
          "title": "docs(paper): sharpen machine-life thesis and prepare alpha.2",
          "body": "## Summary\n\n- sharpen the paper around **Semantic Autopoiesis** and **machine life**\n- add the Agent Patrol heartbeat and Deprecation Lifecycle metabolism mechanisms\n- add a homeostatic control-loop architecture figure and distinguish Kungfu's proposal from adjacent work\n- synchronize the current alpha lineage, pin the sealed publication workflow, and advance the immutable prerelease identity to `0.1.0-alpha.2`\n- align the PDF, README, and Buildchain publication title to `Semantic Autopoiesis: An Engineering Roadmap for Machine Life`\n\n## Validation\n\n- `make check`\n- `make pdf` (24 pages)\n- `git diff --check`\n- local PDF SHA-256: `aeaf4058e62c1655e6b0e723b3691f377ec0e27a392bbe17453f182347c934b9` before the release-label-only rebuild; CI artifact is authoritative\n- PR Build workflow validates the pinned Buildchain toolchain\n\n## Version impact\n\nPublishes `0.1.0-alpha.2`. The already-published alpha.0 and alpha.1 transactions remain immutable.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T14:02:57Z",
          "mergedAt": "2026-07-29T15:11:22Z",
          "additions": 330,
          "deletions": 77,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 22,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/22",
          "title": "chore(release): bind alpha.2 promotion identity",
          "body": "## Summary\n\nBind the alpha.2 promotion to a last push from the development identity so the distinct `kungfu-origin` CODEOWNER can satisfy the protected alpha branch's last-push approval rule.\n\nThis is an intentional empty DCO-signed commit and does not change paper content or release metadata.\n\n## Evidence\n\n- follows the alpha.1 promotion pattern from PR #17\n- source/release content is already merged in PR #20\n- alpha promotion PR #21 remains the publication boundary\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T15:16:20Z",
          "mergedAt": "2026-07-29T15:17:44Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 23,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/23",
          "title": "chore(release): promote v0.1.0-alpha.2",
          "body": "## Release\n\nPromote exact reviewed development head `5cc285e8b6ce382cb50d11e344b462c610e4359f` to the alpha channel as `0.1.0-alpha.2`.\n\n## Included\n\n- focused title: **Semantic Autopoiesis: An Engineering Roadmap for Machine Life**\n- sharpened machine-life thesis and differentiation\n- Agent Patrol heartbeat and Dogfood Queue feedback\n- Deprecation Lifecycle as governed metabolism\n- homeostatic control-loop architecture figure\n- pinned sealed Buildchain workflow and synchronized alpha lineage\n\n## Evidence\n\n- content PR #20 approved, checked, and merged\n- promotion-identity PR #22 approved, checked, and merged\n- current dev head checks passed\n- `0.1.0-alpha.2` is not yet published\n\nThis supersedes PR #21 solely to obtain a clean protected-review ledger after its head changed.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T15:21:13Z",
          "mergedAt": "2026-07-29T15:22:48Z",
          "additions": 330,
          "deletions": 77,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 24,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/24",
          "title": "chore(release): prepare v0.1.0-alpha.2",
          "body": "Create the generated version-state reconciliation for `v0.1.0-alpha.2`.\n\nBuildchain generated the exact branch after protected `dev/v0/v0.1` rejected direct bookkeeping.\n\nRejected update: `5cc285e8b6ce382cb50d11e344b462c610e4359f` → `b1e13c291443c4319f233941b58b7e34b43952ae`.\n\nThe npm package is already published immutably; this PR synchronizes the admitted alpha lineage back into dev so the sealed workflow can resume idempotently and finish GitHub Release/bookkeeping.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T15:31:32Z",
          "mergedAt": "2026-07-29T15:33:01Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1888,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1888",
          "title": "fix(action): refresh package manifest digest",
          "body": "## Summary\n\n- refresh the Action package manifest digest for the renamed work-control contract bytes\n- add a direct source-package verification regression so tracked byte drift fails locally\n- preserve the existing Action authority and installed package verification behavior\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix restores the existing Action package integrity invariant after a contract vocabulary rename without changing Action authority, authorization, or runtime behavior.\"\n}\n-->\n\n## Failure evidence\n\nFinal auditable-demo Build run 30462994266 failed on Linux x64 job 90614161860 and macOS ARM64 job 90614161886 with package-tampered because action-loop.contract.json had digest sha256:f4327c98ee30b4f04ad65ef1939069dc10580c180b908de1aceaa7aaf2dde506 while framework/action/manifest.json retained the pre-rename digest.\n\n## Validation\n\n- node --test framework/action/action.test.mjs: 9 passed\n- ./shifu test:action-kernel: 36 passed, 2 native-binding skips; Python 5 passed\n- staged pre-commit gate: passed, including test manifest, 53 latency tests, 17 invariant tests, 131 documentation tests, deterministic docs gate, and Biome\n- git diff --check: passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T15:18:11Z",
          "mergedAt": "2026-07-29T15:36:49Z",
          "additions": 10,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 183,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/183",
          "title": "feat(papers): frame Kungfu now and future",
          "body": "## Summary\n\n- present the White Paper as Kungfu now and Machine Life as its future\n- limit the human-facing paper page to the two defining papers\n- direct readers to papers.libkungfu.dev for the complete publication library\n- retain the full exact-version package catalog and machine-readable LLMS contract\n\n## Verification\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `git diff --check`\n\n## Boundary\n\nPreview review only. Do not merge or promote to staging/production yet.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T14:43:07Z",
          "mergedAt": "2026-07-29T15:45:50Z",
          "additions": 207,
          "deletions": 136,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 235,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/235",
          "title": "feat(papers): prioritize defining papers",
          "body": "## Summary\n\n- place the White Paper and Machine Life together in a two-card featured row\n- frame them as Kungfu now and Kungfu next with stronger visual treatment\n- move the remaining research papers into a distinct supporting row\n- preserve package-owned publication facts, archive routes, and machine registries\n\n## Verification\n\n- pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/\n- pnpm run build\n- pnpm run check\n- git diff --check\n- node --check scripts/render-site.mjs\n- bash -n scripts/check-site.sh\n\n## Release boundary\n\nPreview review only. Do not merge or promote to staging or production until the layout is approved.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T14:17:16Z",
          "mergedAt": "2026-07-29T15:50:18Z",
          "additions": 225,
          "deletions": 36,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 184,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/184",
          "title": "Release production from 8ff9da135f3f",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `8ff9da135f3faed99ffc89cf88dfa0b83faf1ae7`\n- Artifact hash: `ed2752468abb4a38d14d97d8bd2a2c368cc9b9a206d5425b98903ab617b41ac3`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30467488227)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-8ff9da135f3f`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-29T15:50:59Z",
          "mergedAt": "2026-07-29T15:54:11Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1889,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1889",
          "title": "feat(shifu): materialize qualified Assignment Core",
          "body": "## Summary\n\nMaterialize an exact protected Qualified Assignment Core artifact into fresh macOS ARM64 source worktrees so native Work commands can start without compiling Core, while preserving source-build fallback and the installed product boundary.\n\n## Related issue\n\nKungfu Assignment `2026-07-29-kungfu-qualified-core-consumer-materialization`.\n\n## Changes\n\n- Add a built-in-only consumer for exact GitHub promotion discovery, bounded ZIP extraction, full artifact and authority verification, and immutable local CAS storage.\n- Publish the four-file CPython 3.13 runtime closure atomically into `framework/core/dist/kungfu` only for an exact clean Darwin ARM64 checkout.\n- Invoke the consumer from the source `./shifu work` path only when the current checkout has no native binding.\n- Reject tamper, expiry, ambiguity, unsafe archive members, identity drift, dirty or linked targets, and provider failures with one machine-actionable source-build diagnosis.\n- Extend the producer contract to seal the complete runtime closure and bind the consumer source into the Shifu contract root.\n- Update the accepted ADR and generated architecture projections.\n\n## Verification\n\n- `./shifu check:source` on `091cd45dd0f02346527fd432622ec62aeb572b3b`: 762 passed, 10 platform skips, 0 failed in the unified Node contract matrix; 40 Agent Work Python tests, 116 runtime-upgrade tests, 69 desktop-update tests, documentation, type checking, Biome, complexity, and all build-free source gates passed.\n- `./shifu docs:check` on `7afddbe621a3f02b9b2b12525cedf0d0c90fede9`: 131 passed, 0 failed.\n- `node --test scripts/qualified-assignment-core-artifact.test.mjs`: exact hit, repeat hit, concurrency, atomic publication, tamper, identity drift, expiry, ambiguity, dirty target, fallback, and four-file producer closure.\n- Native Assignment stage-ready proof `sha256:d057b3cdd8c4a1fa0f2b42e41be3c285d6f452e65fb405b7e33ae932d02b0e6d`.\n- Latest protected-dev replay qualified with candidate tree `5d4e9a281886c5b6aa5d68ffcb7e7e624d4abad6`.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Consume exact protected Qualified Assignment Core artifacts through an immutable local CAS and atomic source-runtime view\",\n  \"verification\": [\"Full source acceptance\", \"Exact consumer and producer contract tests\", \"Native Assignment stage-ready proof\", \"Latest protected-dev replay\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe consumer uses the authenticated GitHub CLI only as a transport adapter. It never reads or logs credentials, never promotes transport into qualification authority, does not broaden workflow permissions, and cannot mutate the installed Kungfu product.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LXF1YWxpZmllZC1hc3NpZ25tZW50LWNvcmUtY2FjaGUtZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOS1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtY29uc3VtZXItbWF0ZXJpYWxpemF0aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiI4OGY4YjAwOTk4NDljN2QyY2VmNmIzMWM4OTQ1MGNiOGRiNTdlMmM4IiwicHVsbFJlcXVlc3RIZWFkIjoiN2FmZGRiZTYyMWEzZjAyYjliMmIxMjUyNWNlZGYwZDBjOTBmZWRlOSIsInJlcGxheWVkQ2FuZGlkYXRlIjoiN2VlYjNhZGIwMGY3NGRhN2IxZjViNzljZjMyYzhhNzZhZjYwNzY5NCIsInJlcGxheWVkVHJlZSI6IjVkNGU5YTI4MTg4NmM1YjZhYTVkNjhmZmNiN2U3ZTYyNGQ0YWJhZDYiLCJxdWV1ZUF0dGVtcHQiOiI3YWZkZGJlNjIxYTNmMDJiOWIyYjEyNTI1Y2VkZjBkMGM5MGZlZGU5QDg4ZjhiMDA5OTg0OWM3ZDJjZWY2YjMxYzg5NDUwY2I4ZGI1N2UyYzgiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6ZGRmZTY2ZmIwNmNiNWE0Yjg2YTEyMTFmMDk1ZjcxMjU3OTg2MTYzOTUwYzI2MjhmMmUwODgyYjBkYWM1M2E5MSIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjQwNTRhYWU5OTQxNWEyYjM0N2I4NjZkNzIzNTRmYzUxZjQyNjQ0NWNjZjgxYjE1ZTQxYWZkZmU2NzJmNzNhZmQiLCJzaGEyNTY6ZGRmZTY2ZmIwNmNiNWE0Yjg2YTEyMTFmMDk1ZjcxMjU3OTg2MTYzOTUwYzI2MjhmMmUwODgyYjBkYWM1M2E5MSJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzIyYzg0YjMxNzAxMDc5ZTIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6MDZlYTVkNmVhZmQ1NTVlMTZkZGRiOTk3MzY3OWYyYTZmMjAxNTVlMDc1ZWM1YzlkNmJjNzkzMDFlZjkzNTUxZCJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T15:22:31Z",
          "mergedAt": "2026-07-29T16:00:27Z",
          "additions": 1463,
          "deletions": 56,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 185,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/185",
          "title": "Release Machine Life alpha.2 from protected main",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nPublish the reviewed Machine Life `0.1.0-alpha.2` site artifact from protected `main`. The prior release PR #184 was rebased and therefore attempted production from `refs/pull/184/merge`, which the production environment correctly rejected. This fresh release-intent commit follows the proven protected-main merge path.\n\n### Staging URL\n- https://staging.kungfu.tech/whitepaper/\n\n### Release evidence\n- Reviewed source SHA: `8ff9da135f3faed99ffc89cf88dfa0b83faf1ae7`\n- Artifact hash: `ed2752468abb4a38d14d97d8bd2a2c368cc9b9a206d5425b98903ab617b41ac3`\n- Staging run: https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30467488227\n- Prior release intent: #184\n\nMerge with a merge commit so the production workflow runs from the protected `main` ref.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T16:01:12Z",
          "mergedAt": "2026-07-29T16:06:51Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1893,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1893",
          "title": "fix(work-control): accept legacy import admission key",
          "body": "## Summary\n\n- keep the canonical `work-control` CLI wording while accepting the existing internal `mission_control` admission key\n- fail closed with a clear diagnostic if neither admission evidence key is present\n\n## Evidence\n\n- Dev Verify Patrol attempt 2 run 30463414400 failed only on macOS fixture `atlas-demo-import` with `KeyError: work_control`\n- full pre-commit staged gate passed, including 53 Gate latency tests, 17 invariant tests, 131 documentation/release tests, Ruff format, and Ruff lint\n- `python3 -m py_compile framework/core/src/python/kungfu/cli/commands/atlas.py`\n\nThe existing `atlas-demo-import` fixture is the direct behavioral regression test and will rerun in protected CI.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded bug fix preserves the canonical Work Control CLI surface while accepting the existing compatibility receipt key; it introduces no architecture decision or release behavior.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Full staged pre-commit gate passed\n- [x] Existing product fixture is the direct regression proof\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI0LWJ1aWxkY2hhaW4tbGludXgtZ2l0aHViLWF0dGVzdGF0aW9uIiwiZGVsaXZlcnlDbGFzcyI6ImFydGlmYWN0LXNpZ25pbmctYXV0aG9yaXR5IiwiZGV2SGVhZCI6IjdlYjE3ZDJjMTI5ODQ3MjVkMmExMmEwMTc3ZDM4NGIxN2E1YzhiOWMiLCJwdWxsUmVxdWVzdEhlYWQiOiIzMjEzNWQ0MDFkZDJhMzY5MzY0OWU4NDlmOTZjOGM1NzRhOWJkYWZlIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiJhZjE1MDBiYmU2NTM0OGEyOWJlN2NhMTViMmI1NzliOTdlOTA1YWY3IiwicmVwbGF5ZWRUcmVlIjoiMmYxMmE5Y2FmODY3OTEyY2U0NDdhMzM2YWZlNTMzNGQ3MzVhZDhlYiIsInF1ZXVlQXR0ZW1wdCI6IjMyMTM1ZDQwMWRkMmEzNjkzNjQ5ZTg0OWY5NmM4YzU3NGE5YmRhZmVAN2ViMTdkMmMxMjk4NDcyNWQyYTEyYTAxNzdkMzg0YjE3YTVjOGI5YyIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjpkN2U1Y2ZmN2RhZmJjZWVjNzYwYTliMDgzMmJlMzg5NWM1NTM3OTcyNmQ4MGEyYzcyNDVmNWI4MTQxM2ZjOTUyIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6Mzk1MmE3MGU0OTMzMzY2ODllOTg1NWNmODMyNTc0MjNiNDExODc1YWFjMmExZGJiM2YyNDQwOWIxNDc0MjJhZSIsInNoYTI1NjpkN2U1Y2ZmN2RhZmJjZWVjNzYwYTliMDgzMmJlMzg5NWM1NTM3OTcyNmQ4MGEyYzcyNDVmNWI4MTQxM2ZjOTUyIl0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZDk5ZjNhOTE2NjczOWUwZCIsImxlYXNlUm9vdCI6InNoYTI1Njo2ZWZkYTYxYmU5OTM3OTQ1ODQyZGYxYWE4NzcyNzg5NmM2ZTdmN2EwNTI2MjBmZTVhZjMyODkyNjk1ZmEyOTg1In0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T15:45:48Z",
          "mergedAt": "2026-07-29T16:11:04Z",
          "additions": 8,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 237,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/237",
          "title": "fix(papers): preserve immutable archive pages",
          "body": "## Summary\n\n- keep the new featured Papers index layout on mutable pages\n- exclude featured-layout CSS from immutable publication version pages\n- add a regression check that immutable version pages contain no mutable featured-layout styles\n\n## Evidence\n\n- `npm run build`\n- `npm run check`\n- `SITE_SURFACE_CHANNEL=staging npm run build`\n- `SITE_SURFACE_CHANNEL=staging npm run check`\n- existing staging object restored byte-for-byte: `episodes-to-primitives@0.1.0-alpha.2/index.html` SHA-256 `20057177f2072c2ad1f394225a8b782dfe69d58d82df1f0e6f3b01fc7fcb1a23`\n- Machine Life alpha.2 PDF SHA-256 `829bfa463bbcbdfc68712bd8b03c3d4e0dd832f5c8ab876221d3ed45ed67af91`\n\n## Scope\n\nStaging recovery only. No production deployment.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T16:01:05Z",
          "mergedAt": "2026-07-29T16:16:10Z",
          "additions": 18,
          "deletions": 13,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1898,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1898",
          "title": "fix(ci): bind latency evidence to proof producer",
          "body": "## Summary\n\n- resolve merge-group cache evidence to the exact pull-request proof producer\n- require the producer's complete immutable artifact partition set before accepting cache receipts\n- bind measured cache, native attribution, validation, and delivery evidence back to the verified proof authority\n\n## Verification\n\n- `./shifu test:gate-latency` — 96 passed\n- `./shifu check:source` — build-free source acceptance passed\n- `./shifu exec -- node scripts/code-complexity-budget.mjs` — passed\n- live PR #1839 collector canary — `verified-proof-producer`, `verified-proof-authority`, delivery evidence proved\n- Project Cut successor `sha256:1dca846fb74f829d685cce6a74159a8b524488d45b0c046b0c6a8731633978f1` verified and commit-observed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded collector correctness fix preserves the existing gate and proof authority while making its evidence join exact; it introduces no architecture decision or release behavior.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n\nThe change reads existing immutable CI evidence and verifies exact producer authority. It adds no credentials, publication, or deployment action.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Focused and full source gates passed\n- [x] Live collector canary passed",
          "author": "dongkeren",
          "createdAt": "2026-07-29T16:20:19Z",
          "mergedAt": "2026-07-29T16:35:24Z",
          "additions": 317,
          "deletions": 30,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 239,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/239",
          "title": "Release production from c884452c2527",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `c884452c2527f1da4e5c9cdc2758914f35fab80d`\n- Artifact hash: `12b8d78e6d5fa277f441b7a86a2152914956a3fcdbaacd3b0e80d350242e70c1`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/30469940671)\n- Required label: `buildchain-release`\n- Release branch: `release/production-c884452c2527`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-29T16:28:56Z",
          "mergedAt": "2026-07-29T16:42:04Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1897,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1897",
          "title": "fix(core): qualify Core artifact authority changes",
          "body": "## Summary\n\nMake every Qualified Assignment Core producer, consumer, contract, and qualification-authority change schedule the complete native Core qualification closure. This closes the post-merge gap where a successful source-only merge produced no protected macOS ARM64 artifact.\n\n## Related issue\n\nKungfu Assignment `2026-07-29-kungfu-qualified-core-consumer-materialization`.\n\n## Changes\n\n- Classify the Qualified Core producer, consumer, cache contract, artifact contract, and both schemas as global native-impact authority paths.\n- Require every authority path fixture to select all 12 Core components and a native build profile.\n- Preserve the existing affected-native planner, branch policy, and artifact contract.\n\n## Verification\n\n- `./shifu core:affected -- --self-test`: 31 negative and determinism fixtures passed.\n- Direct planner readback for `framework/release/qualified-assignment-core-artifact.mjs`: all 12 components, `embedded-sqlite`, `architecture-or-gate-authority`.\n- `node --test scripts/qualified-assignment-core-artifact.test.mjs`: 7 passed.\n- `./shifu check:source`: 761 passed, 10 platform skips, 0 failed; Agent Work Python 40, runtime upgrade 116, desktop update 69, docs 131.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Restore the existing Qualified Assignment Core artifact qualification path without changing its architecture contract\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe patch changes only the source-bound native-impact planner. It does not broaden workflow permissions, change transport authority, or mutate installed product state.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LXF1YWxpZmllZC1hc3NpZ25tZW50LWNvcmUtY2FjaGUtZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOS1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtY29uc3VtZXItbWF0ZXJpYWxpemF0aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiI5MTQ4OWU4MDE1YTg4ZmQyZThiYjcwYTkwNDkyOGY5NmE3OGJiM2U0IiwicHVsbFJlcXVlc3RIZWFkIjoiM2M0MmZmNGYzMzJjNGE2YzhhMDI2Mjc4OWYwYzJmNmZjMmQ2MmJjYSIsInJlcGxheWVkQ2FuZGlkYXRlIjoiNmY5NWU5MWYzZDY5NzdjYTg5ZmI4ZmZjODNkNzczMTI3Mzc1YmVhZiIsInJlcGxheWVkVHJlZSI6IjgxNGNkMGFlZGRlZjNiMDJhYjJlOGE0M2Y4N2NhMjc4YzA0M2FlNTIiLCJxdWV1ZUF0dGVtcHQiOiIzYzQyZmY0ZjMzMmM0YTZjOGEwMjYyNzg5ZjBjMmY2ZmMyZDYyYmNhQDkxNDg5ZTgwMTVhODhmZDJlOGJiNzBhOTA0OTI4Zjk2YTc4YmIzZTQiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6YzViODJjMTUzNDMxMWU3ZjkzNDc5YWEzMGVlNmE1YWIwZjYzNzY1ZDZmMDZiMzFlNDRjNzMyNGU4MDBmZDUxMiIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjQwNTRhYWU5OTQxNWEyYjM0N2I4NjZkNzIzNTRmYzUxZjQyNjQ0NWNjZjgxYjE1ZTQxYWZkZmU2NzJmNzNhZmQiLCJzaGEyNTY6YzViODJjMTUzNDMxMWU3ZjkzNDc5YWEzMGVlNmE1YWIwZjYzNzY1ZDZmMDZiMzFlNDRjNzMyNGU4MDBmZDUxMiJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzIyYzg0YjMxNzAxMDc5ZTIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6ZjVmNDA4MjJkYjBjM2IyNTEwZjA2MjMyM2RiMTNlNjgxNDE3YWZjNzEwMGQwMTdmY2I5OTJlMGZhYzBlNDQxZSJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T16:19:18Z",
          "mergedAt": "2026-07-29T17:05:15Z",
          "additions": 28,
          "deletions": 9,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1900,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1900",
          "title": "feat(deprecation): enforce surface enrollment",
          "body": "## Summary\n\nMake every machine-recognizable deprecation surface discoverable and exactly enrolled in the common lifecycle authority.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add a versioned discovery contract for C++, Python, JavaScript/TypeScript, persisted schemas, CLI registries, KFX contributions, documents, and release artifacts\n- backfill the 11 live yijinjing deprecation markers under four stable lifecycle entries without resetting their historical dates\n- reject orphan, duplicate, mismatched, missing, and entry-without-live-surface states in full-tree and changed-file source acceptance\n- publish a read-only inventory that separates live debt, settled history, generated vocabulary, and historical evidence\n- retain cold read-only bootstrap coverage and document the enrollment workflow\n\n## Verification\n\n- `./shifu check:deprecation-lifecycle`\n- `./shifu build:core`\n- `node --test scripts/readonly-agent-bootstrap.test.mjs`\n- `./shifu check:source`\n- staged commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019fad41-07fe-7f1e-a37a-a2572357700c\"],\n  \"summary\": \"Close the bounded deprecation surface enrollment stage and establish the current legacy baseline\",\n  \"verification\": [\"deprecation lifecycle audit\", \"Core build\", \"cold read-only bootstrap\", \"full source acceptance\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI5LWt1bmdmdS1kZXByZWNhdGlvbi1zdXJmYWNlLWVucm9sbG1lbnQtYW5kLWxlZ2FjeS1iYXNlbGluZSIsImRlbGl2ZXJ5Q2xhc3MiOiJjcm9zcy1sYW5ndWFnZS1zb3VyY2UtZ292ZXJuYW5jZSIsImRldkhlYWQiOiIxOWNlMGZjNzQ3YTJlZGRhN2MyYWQzMzQ5MTJiMDg2OGI5NjViNjJlIiwicHVsbFJlcXVlc3RIZWFkIjoiYTczNzVhMTc1MmI5YzAwZjY0YjBhZGQ0ZWU4ODdiMTc2OGUyOGUxZiIsInJlcGxheWVkQ2FuZGlkYXRlIjoiN2JlOGQzMDdjMTQxMjM3ZGFiZTRiY2U1M2M4NzFhNTExNjBkNWY5NCIsInJlcGxheWVkVHJlZSI6ImNhNGIyNWFhZDVhMGVlYzIzMWZlYTg0ZmQ0NjM5NmJlMGVhYmNkOWIiLCJxdWV1ZUF0dGVtcHQiOiJhNzM3NWExNzUyYjljMDBmNjRiMGFkZDRlZTg4N2IxNzY4ZTI4ZTFmQDE5Y2UwZmM3NDdhMmVkZGE3YzJhZDMzNDkxMmIwODY4Yjk2NWI2MmUiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6NDEzNzkzZTMwNzdjODc3ZGRlMzRiNTBhYmY1MTkwMmRkZGRjYjM1NjYxZTZjZjc3MTU4MzAwMzliY2E2Y2ExNSIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjAyMWViZWJmZjUzOTU0OGM4ZTBmMjk2MWZjOTg3OGE3MjU5N2EwYTI4Y2Y2YTA5MjdkMDIwMjUwYzZiYjM2OGYiLCJzaGEyNTY6NDEzNzkzZTMwNzdjODc3ZGRlMzRiNTBhYmY1MTkwMmRkZGRjYjM1NjYxZTZjZjc3MTU4MzAwMzliY2E2Y2ExNSJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6MzFkM2NjZDdiOGU2Mjg3ODBkN2YzMDVhZGE1MTcwYWUyZjA0ZTU2YWEyMDMxZTgwMzdjZjYwMzg4MDZmMzNkNyJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T16:22:48Z",
          "mergedAt": "2026-07-29T17:38:26Z",
          "additions": 1449,
          "deletions": 25,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1905,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1905",
          "title": "fix(assignment): retry qualified core transport",
          "body": "## Summary\n\n- stream Qualified Core GitHub artifact downloads into bounded mode-0600 temporary files\n- retry transient transport failures three times without retaining partial bytes\n- discard transport stderr so signed artifact URLs are never retained or surfaced\n- preserve exact commit, tree, authority, and digest verification before publication\n\n## Motivation\n\nA real empty-cache source-thread materialization test reached the promoted exact artifact but failed during a transient TLS handshake after a partial download. The consumer correctly fell back without publishing bytes, but a single transport interruption made an otherwise valid promoted artifact unusable.\n\n## Validation\n\n- `node --check framework/assignment-capture/qualified-assignment-core-consumer.mjs`\n- `node --test scripts/qualified-assignment-core-artifact.test.mjs scripts/run-core-affected-native.test.mjs` (16 passed)\n- commit hook staged validation passed\n- local source acceptance: 768 passed, 10 skipped; the sole failure was the host environment lacking `ruff` on PATH\n- protected source acceptance: passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Harden the existing Qualified Assignment Core transport without changing its architecture or authority contract\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe patch changes only the authenticated artifact transport implementation. It does not read or log credentials, broaden workflow permissions, alter qualification authority, or mutate installed product state.\n\n## Version impact\n\nPatch: this hardens transport behavior without changing the artifact contract or public command surface.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LXF1YWxpZmllZC1hc3NpZ25tZW50LWNvcmUtY2FjaGUtZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOS1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtY29uc3VtZXItbWF0ZXJpYWxpemF0aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJlNmYzNmU5NDQxMWQ0MjA0ZjZkY2EyZmQ0YWU1M2IyNTc0MzAyZWY3IiwicHVsbFJlcXVlc3RIZWFkIjoiZTQyNWU4OGU3YzJlZGQyZWUzZWFiYzJkZTdiNjA0M2M4ZDAwM2Y0MyIsInJlcGxheWVkQ2FuZGlkYXRlIjoiOTZlMmM4YjYxN2RmYjk3MjcxNzk3MDExZWM2ZDZjOTEwM2E5MmYyNSIsInJlcGxheWVkVHJlZSI6IjRjY2MwNzUxN2E0MWE0NmY4ZTVmMjhjNmNkMGIwODQ1ZDFhMmIwMDAiLCJxdWV1ZUF0dGVtcHQiOiJlNDI1ZTg4ZTdjMmVkZDJlZTNlYWJjMmRlN2I2MDQzYzhkMDAzZjQzQGU2ZjM2ZTk0NDExZDQyMDRmNmRjYTJmZDRhZTUzYjI1NzQzMDJlZjciLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6MzI2ZjI3ZTE1Zjk1NTg0ZTVmOGMzMmZlYmE5N2VjOGRmZjAxMjkzMzhiYTcwNzA3ZDgwYzJmNTEyZjNiYmY1ZSIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjMyNmYyN2UxNWY5NTU4NGU1ZjhjMzJmZWJhOTdlYzhkZmYwMTI5MzM4YmE3MDcwN2Q4MGMyZjUxMmYzYmJmNWUiLCJzaGEyNTY6YzViODJjMTUzNDMxMWU3ZjkzNDc5YWEzMGVlNmE1YWIwZjYzNzY1ZDZmMDZiMzFlNDRjNzMyNGU4MDBmZDUxMiJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzIyYzg0YjMxNzAxMDc5ZTIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6MzRlMDJjMjQ1YTY1ZmIyMDI3MjkwZGZkMDRkYzJmOWM0MGYzMDkwMWUxODM5MzZmNmUzYTAwMjVhY2Q2MDMzNiJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T18:05:13Z",
          "mergedAt": "2026-07-29T18:24:49Z",
          "additions": 149,
          "deletions": 16,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1906,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1906",
          "title": "fix(ci): bind latency history to emitted plans",
          "body": "## Summary\n\n- classify every full-evidence sample from the exact `dev-candidate-plan` emitted by its merge-group workflow\n- verify the plan digest, source SHA, base ancestry, and planner-equivalent changed-path set before accepting historical native evidence\n- preserve fail-closed behavior for missing, ambiguous, stale, or inconsistent plan artifacts\n\n## Verification\n\n- `./shifu test:gate-latency` — 99 passed\n- `./shifu check:source` — build-free source acceptance passed; 762 source contract tests passed with 10 declared skips\n- `node scripts/code-complexity-budget.mjs` — passed\n- live PR #1827 canary — historical native classification restored; cache, native, and delivery evidence proved\n- live PR #1889 canary — historical non-native classification preserved\n- full 30-sample report — qualified; 24 native / 6 non-native; unknown 0; required P50/P95 228/261 seconds; delivery P50/P90 232/283 seconds; dequeue, repeat validation, and wasted runner time all 0\n- report SHA256 — `80c718293b860fe8ae204e87151656e9abbbdd984fb659a830c8f7b9e731d34d`\n- Project Cut successor `sha256:58210f8315a503daea65a384912e428a372b6534998fe0a929adf9f642a49072` verified and commit-observed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded collector correctness fix reads and validates an already emitted source-bound plan; it introduces no architecture decision or release behavior.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n\nThe change reads existing immutable CI evidence and performs read-only GitHub ancestry comparison. It adds no credentials, publication, or deployment action.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Focused and full source gates passed\n- [x] Historical native and non-native canaries passed\n- [x] Full 30-sample qualification report passed",
          "author": "dongkeren",
          "createdAt": "2026-07-29T18:32:35Z",
          "mergedAt": "2026-07-29T18:41:48Z",
          "additions": 281,
          "deletions": 30,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1908,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1908",
          "title": "fix(qualification): follow work control test rename",
          "body": "## Summary\n\n- update the profile-action admission runner to invoke the tracked Work Control test after its canonical rename\n- preserve the existing profile SDK and runtime qualification contract\n\n## Failure evidence\n\n- Alpha build run 30476485711 attempt 3, Windows job 90673558601\n- 72/72 core verification and all other runtime-activation suites passed\n- profile-action-admission failed only because test_mission_control_profile.py no longer exists\n\n## Verification\n\n- 64 profile SDK/composition/Work Control tests passed\n- Biome passed\n- full staged pre-commit repository gates passed\n- Project Cut admission qualified with one replayed commit and no composition change\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded qualification repair follows an existing canonical test-file rename and does not change architecture, runtime behavior, or release authority.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Focused tests and staged gates passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T19:34:16Z",
          "mergedAt": "2026-07-29T19:46:35Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1909,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1909",
          "title": "fix(assignment): retain qualified core extraction",
          "body": "## Summary\n\n- await Qualified Assignment Core materialization before removing the extracted promotion bundle\n- retain the existing exact-identity, verification, and atomic-publication contract\n- add an archive-backed regression test that exercises the asynchronous retention boundary\n\n## Motivation\n\nA real empty-cache consumption of the promoted macOS ARM64 artifact verified the transport and bundle, then failed while retaining the extracted payload because the extraction directory was removed by `finally` before asynchronous materialization completed.\n\n## Validation\n\n- `node --test scripts/qualified-assignment-core-artifact.test.mjs scripts/run-core-affected-native.test.mjs` (17 passed)\n- `PATH=/Users/dkr/.cache/uv/archive-v0/_T8kv5tTmZ5O_RLL/bin:$PATH KUNGFU_READONLY_PYTEST=/Users/dkr/.cache/uv/archive-v0/_T8kv5tTmZ5O_RLL/bin/pytest ./shifu check:source` (passed; 770 passed, 10 skipped)\n- staged repository gates (passed)\n\n## Evolution Map\n\nNo Evolution Map change. This is an ADR-neutral correction to the existing Qualified Assignment Core consumer lifecycle.\n\n## Governance risk\n\n- [x] No authority widening\n- [x] No schema or CLI compatibility change\n- [x] No secret or credential handling change\n- [x] No installed-product mutation\n\n## Versioning\n\nPatch.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Preserve the existing Qualified Assignment Core artifact contract while fixing asynchronous extraction lifetime\"\n}\n-->\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LXF1YWxpZmllZC1hc3NpZ25tZW50LWNvcmUtY2FjaGUtZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOS1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtY29uc3VtZXItbWF0ZXJpYWxpemF0aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiIzMmJlN2YzN2QzZDgyMjZjZTc0OGNmNGVmOTY1MjNlYzkzYWRhOWRmIiwicHVsbFJlcXVlc3RIZWFkIjoiYTk2MzA3MzcwZDU1NWIwMzYwYzkzM2IyZDgyYTM0N2ZlYWM4Y2JmZCIsInJlcGxheWVkQ2FuZGlkYXRlIjoiNTAxNDEwMzg0MWQ0M2IwMzlhNTBhYWI0MTI0ZjA3ZmZhN2E0OTBmMSIsInJlcGxheWVkVHJlZSI6IjE2MmQ5YTUyOGQxNmViMzM0YjkwNzA4NzYyZTJhNjFmYjdmODQ5NGIiLCJxdWV1ZUF0dGVtcHQiOiJhOTYzMDczNzBkNTU1YjAzNjBjOTMzYjJkODJhMzQ3ZmVhYzhjYmZkQDMyYmU3ZjM3ZDNkODIyNmNlNzQ4Y2Y0ZWY5NjUyM2VjOTNhZGE5ZGYiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6Yjc2ODQxY2M1MzhmMGMwZTQxMzg5MjZkNmJlMjgzYjUwYjU5ZDdiMDM2OTlmNzdhZmI2ZTIyZjk1M2NhYjJkZCIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OmI3Njg0MWNjNTM4ZjBjMGU0MTM4OTI2ZDZiZTI4M2I1MGI1OWQ3YjAzNjk5Zjc3YWZiNmUyMmY5NTNjYWIyZGQiLCJzaGEyNTY6YzViODJjMTUzNDMxMWU3ZjkzNDc5YWEzMGVlNmE1YWIwZjYzNzY1ZDZmMDZiMzFlNDRjNzMyNGU4MDBmZDUxMiJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzIyYzg0YjMxNzAxMDc5ZTIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6NTYyZThjNjk5NDVkMDZjMGNmNDllMDBjMzJhNzJiMDM4NDY5MDU2YjYzZTdhZTNjNzU0OTFiYjVkZmEwODliZiJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T20:13:42Z",
          "mergedAt": "2026-07-29T20:28:12Z",
          "additions": 49,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1914,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1914",
          "title": "fix(ci): keep scheduled dev verify on workflow runtime",
          "body": "## Summary\n\n- leave `buildchain-ref` empty for scheduled Dev Verify runs so Buildchain resolves the exact reusable-workflow runtime without treating it as an event override\n- retain the trusted `workflow_dispatch` override path\n- refresh the closed-world workflow authority and binding projection\n\n## Verification\n\n- focused Dev Patrol and workflow catalog tests passed\n- complete staged pre-commit repository gate passed\n- 58 Gate latency, 27 workflow authority/catalog, 17 invariant, 131 docs/ADR, and 18 KFD support tests passed in the commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded CI scheduling repair preserves the existing Buildchain runtime authority and changes no architecture, product behavior, or release contract.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Focused tests and staged gates passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-29T20:40:45Z",
          "mergedAt": "2026-07-29T21:01:15Z",
          "additions": 16,
          "deletions": 8,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1916,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1916",
          "title": "fix(work): discover native profile source",
          "body": "## Summary\n\n- discover the native `extensions/work-control` source Profile before the bounded compatibility layout\n- retain packaged Profile precedence and the existing compatibility fallback\n- bind the source-layout regression test into the KFD-5 evidence authority and generated SDK projection\n\n## Motivation\n\nAfter the source Profile moved from `extensions/mission-control` to `extensions/work-control`, the Assignment CLI source fallback still searched only the compatibility directory. A new source workspace therefore failed before Work Control activation with `Work Control Profile is absent from this Kungfu product`.\n\n## Validation\n\n- `pytest framework/core/tests/python/test_assignment_orchestration.py` (63 passed)\n- `node scripts/kfd-support-matrix.mjs --check` (passed)\n- `node scripts/buildchain-kfd-evidence.mjs --check` (passed)\n- `PATH=/Users/dkr/.cache/uv/archive-v0/_T8kv5tTmZ5O_RLL/bin:$PATH KUNGFU_READONLY_PYTEST=/Users/dkr/.cache/uv/archive-v0/_T8kv5tTmZ5O_RLL/bin/pytest KUNGFU_NATIVE_PATH=/Users/dkr/Worktrees/kungfu/review/codex/qualified-core-consumer-lifetime-e2e/framework/core/dist/kungfu ./shifu check:source` (passed; 770 passed, 10 skipped)\n- staged repository gates (passed)\n\n## Evolution Map\n\nNo Evolution Map change. This is an ADR-neutral correction to native Work Control Profile discovery.\n\n## Governance risk\n\n- [x] No authority widening\n- [x] No schema or CLI compatibility change\n- [x] No secret or credential handling change\n- [x] No installed-product mutation\n\n## Versioning\n\nPatch.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Restore native Work Control Profile discovery after the source-layout rename without widening compatibility\"\n}\n-->\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LXF1YWxpZmllZC1hc3NpZ25tZW50LWNvcmUtY2FjaGUtZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOS1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtY29uc3VtZXItbWF0ZXJpYWxpemF0aW9uIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJjOTgzZGE2YThhMzllN2NlYmFmZDRhZWIyZDgzYWIxN2MwZDg3NzJmIiwicHVsbFJlcXVlc3RIZWFkIjoiNzJmYTU2ZTAwMTZiODExZThiYjhhYzA3NTMwZGVkY2JhYWVjZWEyZSIsInJlcGxheWVkQ2FuZGlkYXRlIjoiYjNjYWM0MjViZWE0MTJiNzMyOTY4Y2JmYThiMDA2MGFiY2VhNzkwNSIsInJlcGxheWVkVHJlZSI6ImU0NTlhYTZhNGMwOTFiN2RmMDZiMWM2NzgwYjE5YjU5OGQyMWQ0ODEiLCJxdWV1ZUF0dGVtcHQiOiI3MmZhNTZlMDAxNmI4MTFlOGJiOGFjMDc1MzBkZWRjYmFhZWNlYTJlQGM5ODNkYTZhOGEzOWU3Y2ViYWZkNGFlYjJkODNhYjE3YzBkODc3MmYiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6Nzg3ZDljMTZhOGIzODM1MTliYjU3MGQxODgyMzNmMjc0ZDkyODgxZDc5NjhjNDk2NzQyM2E0OWI3ZTk1ZTM2YSIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2Ojc4N2Q5YzE2YThiMzgzNTE5YmI1NzBkMTg4MjMzZjI3NGQ5Mjg4MWQ3OTY4YzQ5Njc0MjNhNDliN2U5NWUzNmEiLCJzaGEyNTY6YzViODJjMTUzNDMxMWU3ZjkzNDc5YWEzMGVlNmE1YWIwZjYzNzY1ZDZmMDZiMzFlNDRjNzMyNGU4MDBmZDUxMiJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzIyYzg0YjMxNzAxMDc5ZTIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6Mzc1Yjk1YTUxMDg0YzNmZmM3ZDliODlmN2I5ZWJkYjdhNjc1MzJjNzFhOTE2OTAzZTk1YmE1NzQ4OWZhOTMyMiJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T21:38:55Z",
          "mergedAt": "2026-07-29T21:47:41Z",
          "additions": 22,
          "deletions": 8,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 186,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/186",
          "title": "fix(papers): fingerprint the white paper stylesheet",
          "body": "## Summary\n\n- fingerprint the white paper stylesheet alongside the shared site stylesheet\n- require generated paper pages to resolve the content-addressed CSS asset\n- update rollback guidance for the fingerprinted path\n\n## Why\n\nThe publication HTML was cache-busted while `/assets/whitepaper.css` remained browser-cacheable for 24 hours. Returning visitors could therefore receive the new two-card markup with the old stylesheet, which removed the paired layout and colored borders.\n\n## Verification\n\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- negative regression: replacing the fingerprinted href with `/assets/whitepaper.css` makes the asset check fail\n\n## Version impact\n\nPatch: deployment correctness only; no public content or contract change.",
          "author": "dongkeren",
          "createdAt": "2026-07-29T22:29:19Z",
          "mergedAt": "2026-07-29T22:34:23Z",
          "additions": 49,
          "deletions": 38,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 187,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/187",
          "title": "Release production from 988542df6f1a",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `988542df6f1a5cd5736ba5f03fb728758f2d94ab`\n- Artifact hash: `57233564919e6aaec371cba680421eda8879c761e4177153c5dd2c286af79c13`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30496614048)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-988542df6f1a`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-29T22:36:41Z",
          "mergedAt": "2026-07-29T22:40:41Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1918,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1918",
          "title": "fix(qualification): admit safe CLI archive symlinks",
          "body": "## Summary\n\n- admit relative CLI archive symlinks only when their normalized and resolved targets remain inside the extracted product\n- keep hard links, absolute targets, traversal, broken links, cycles, and non-file targets fail-closed\n- cover the real Python launcher shape plus absolute and escaping negatives\n\n## Evidence\n\n- Alpha candidate Build run 30491711634 built all four platforms successfully but required auditable-demo Gate rejected `runtime/python/bin/python` as an unsupported member type\n- `node --test scripts/auditable-demo-adapter.test.mjs`: 10/10 pass\n- staged repository pre-commit/source checks pass\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded qualification adapter repair admits only archive-internal symlinks and changes no architecture, product payload, or release authority.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Focused tests and staged gates passed",
          "author": "dongkeren",
          "createdAt": "2026-07-29T22:54:08Z",
          "mergedAt": "2026-07-29T23:14:36Z",
          "additions": 61,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1919,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1919",
          "title": "fix(work): defer Windows long-path admission validation",
          "body": "## Summary\n\n- defer captured Assignment request path existence validation from Click to the orchestration filesystem boundary\n- allow Windows extended-length path handling to occur before the request is opened\n- preserve fail-closed request, receipt, content, and semantic validation in `load_captured_request`\n- refresh the governed KFD-5 evidence root and SDK projection\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python:<ancestor-native> uv run --project framework/core --frozen pytest -q framework/core/tests/python/test_assignment_orchestration.py` (64 passed)\n- `./shifu check:source` (passed; source contracts, KFD gates, docs, type checks, Ruff and Biome)\n- repository staged/pre-commit gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fix Windows MAX_PATH handling at the existing Assignment admission boundary without changing product architecture or release authority.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Regression test added\n- [x] No release credentials or publication authority\n- [x] Assignment request semantics and receipt identity are unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-29T23:05:06Z",
          "mergedAt": "2026-07-29T23:25:35Z",
          "additions": 19,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1924,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1924",
          "title": "fix(product): qualify packaged TUI autoplay",
          "body": "## Summary\n\n- resolve the packaged TUI from `KUNGFU_DIR` without requiring the source-only `@kungfu-tech/core` package\n- export the CLI product's bundled `extensions/` root before entering embedded Node\n- align the auditable-demo completion gate with the Agent Work Lab's authoritative `qualified` verdict\n\n## Evidence\n\n- Alpha candidate Build run `30501250218` built all four platforms; the Linux auditable-demo Gate exposed the missing packaged Core module\n- exact retained artifact `kungfu-linux-x64-946789145d68d913eb837cb1c99cc23eea2bb7f3` (`sha256:9d78a4de934889f4f145866e3af5c24ba8f80f6dce6578875c305f0c3817043a`) reproduced the failure on agent-120\n- the newly bundled TUI drove that same installed artifact to one `qualified` completion sentinel with exit status zero and no module/catalog error\n- TUI tests: 73/73 pass\n- auditable-demo tests: 28/28 pass\n- packaged-environment Python regression: 1/1 pass\n- `./shifu check:source`: pass\n- repository pre-commit gate: pass\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded product-packaging repair restores already-declared bundled runtime and Agent Work Lab verdict semantics; it changes no architecture or release authority.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Focused tests and staged/source gates passed\n- [x] Exact retained Linux product artifact reproduced and passed after the bounded fixes\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T02:10:50Z",
          "mergedAt": "2026-07-30T02:20:00Z",
          "additions": 103,
          "deletions": 11,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2044,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2044",
          "title": "fix: resolve Buildchain issue backlog",
          "body": "## Summary\n\n- avoid recompressing deterministic release artifacts on the GitHub Artifacts path\n- publish observed-evidence projections as a bounded transactional set with read-back verification and rollback\n- admit the exact workflow-shell runtime for a closed release PR while reserving production apply for protected main\n- align the Kungfu development merge-queue governance authority and bound remote passport reads\n\n## Verification\n\n- pnpm run test:unit (969 passed)\n- pnpm run check:site\n- pnpm run check:workflows\n- node scripts/check-internal-architecture.mjs\n- node scripts/check-inventory.mjs\n- node scripts/check-action-bundles.mjs\n- git diff --check\n\nCloses #1932\nCloses #2006\nCloses #2011\nCloses #2043\n\nPartially addresses #1614; provider-plan and repository-admission findings remain external governance work.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T02:25:34Z",
          "mergedAt": "2026-07-30T02:31:04Z",
          "additions": 652,
          "deletions": 170,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1926,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1926",
          "title": "test(shifu): harden direct entry correction assertion",
          "body": "## Summary\n\nMake the direct package-manager guard regression deterministic across both a synchronized checkout and a first-run dependency synchronization.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- accept only the two canonical Shifu corrections emitted by the guarded root lifecycle: `./shifu install` during dependency synchronization or `./shifu check:entry-contract` after synchronization\n- reject correction text that recommends direct `corepack`, `node`, or `pnpm` invocation\n- reuse one captured process output for all assertions\n\n## Verification\n\n- `./shifu test:shifu-xinfa-source` (28 passed)\n- `./shifu test:shifu-kfd-readonly` with the Buildchain-equivalent source-tool projection (40 passed, including the cold read-only nested source gate)\n- `./shifu check:entry-contract`\n- `./shifu check:source` against protected base `be1023eb60638b4c94c0543d6203e50774fe55df` (770 passed, 10 skipped, 0 failed)\n- commit-time staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This test-only fix preserves the existing Shifu entry contract and narrows accepted correction text without changing architecture or release semantics.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; test-only contract hardening)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T02:48:59Z",
          "mergedAt": "2026-07-30T02:59:27Z",
          "additions": 6,
          "deletions": 7,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1896,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1896",
          "title": "feat(kfd): qualify perspective replay candidate",
          "body": "## Summary\n\nQualify Kungfu's bounded KFD-4 perspective-replay candidate on the current `dev/v4/v4.0` channel without widening it into shipped support, independent adoption, or Buildchain self-certification.\n\nThis is the sole active delivery intent for native Assignment `2026-07-29-kungfu-kfd4-perspective-product-qualification`. Closed predecessors #1850, #1852, #1853, #1857, #1865, #1872, #1881, #1884, #1886, #1887, #1890, and #1892 are historical exact-base attempts retired before merge; none is release evidence. #1887 passed fresh CI but was closed before enqueue after concurrent mainline advancement. #1890 exposed and repaired its auto-created body's missing ADR manifest, then was closed before a queue attempt when dev advanced again. #1892 was deliberately stopped before its long native closure after #1889 and #1893 obtained exact position-1 queue authority; both predecessors then merged. This head preserves those concurrent deliveries, resolves the generated ADR map through its canonical generator, and remains bounded to the same KFD-4 claim.\n\n## Changes\n\n- add a bounded first-party perspective projection and replay implementation over accepted native source ranges and admitted Facts;\n- retain two observer-relative views, perspective-preserving and contrastive replay, explicit loss, causal ordering, and evidence roots;\n- fail closed on causal inversion, undeclared source cuts, missing evidence, observer flattening, unknown policy versions, and undeclared replay loss;\n- preserve implementation revision `d73cab0d69b77a14c546d063bf89760d846d49a9` while reconstructing its evidence on current dev;\n- bind the implementation to pristine native build `83c15cdeac2e77a8b43568d789066b7f5efca71d` and six negative qualification cases;\n- retain qualification root `sha256:c3d363844e58b55ab8eb677dfd3d579364580c701dbe385957b38fc6b06efdf2`;\n- replace provisional Buildchain KFD-4 inputs while preserving `qualifying=false`, `selfCertified=false`, and `shippedSupport=false`;\n- update KFD support, SDK, ADR, architecture, Buildchain evidence, and source/staged regression gates.\n\n## Verification\n\n- `node scripts/kfd4-perspective-qualification.test.mjs` — 6 passed;\n- `node scripts/kfd-support-matrix.test.mjs` — 19 passed;\n- `node framework/core/tests/qualification/kfd4-perspective.mjs` — two perspectives, six negative cases, all release non-claims preserved;\n- `./shifu kfd:query KFD-4` — candidate, implementation/verification/Buildchain passed, shipped=no;\n- predecessor run `30463108154` passed all source, governance, KFD, Shifu, both native shards, and aggregate checks for the same resulting tree before its dev head became stale;\n- protected latest-base replay from `9e208bd7ed5d82808f69338ca60e0a73ad9f9a34` to `81dd87c48484f46e06215333956cb336f059d73b` qualified with candidate `e4c6aae8a6dea3389a8c1cf07dbbe1a30cb340ca`, tree `731cf22683e7468e45a7f26d69858abc8639a93e`, and `compositionChanged=false`;\n- this PR receives its own fresh required checks and independent CODEOWNER approval.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-704e-9488-a793b1c4bf48\"],\n  \"summary\": \"Bind one bounded native-backed KFD-4 perspective replay candidate to retained product evidence without activating release support.\",\n  \"verification\": [\"KFD-4 retained qualification passes with two perspectives and six fail-closed cases\", \"Buildchain KFD-4 gate passes while remaining non-qualifying\", \"KFD support matrix, consumer query, and complete source acceptance pass\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\nThis PR advances qualification evidence for an existing accepted architecture decision and does not change the Evolution Map corpus or current authority.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: this PR implements and qualifies a bounded candidate only. It does not publish a package, activate Alpha, claim independent adoption, change `releaseQualification.shippedSupport`, or grant release credentials. Buildchain continues to emit `qualifying=false` and `selfCertified=false`.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI5LWt1bmdmdS1rZmQ0LXBlcnNwZWN0aXZlLXByb2R1Y3QtcXVhbGlmaWNhdGlvbiIsImRlbGl2ZXJ5Q2xhc3MiOiJub24tbmF0aXZlLWZhc3QiLCJkZXZIZWFkIjoiMjM0OWZkNzY5ZGU2NjdiZDdjNzU0ODkxOGVmMzgzODhhYjk4NTM0YyIsInB1bGxSZXF1ZXN0SGVhZCI6IjI4OTViNjJkZWVjYjZhZWE0NzQ2YzcwOTk4YTFjNWZhZGQzMjlhMTMiLCJyZXBsYXllZENhbmRpZGF0ZSI6IjJkYmVjMmU3MDA5NTU0NzU1MGI3YjA4ZDEwOWZjMTdkNmI5ZDBhYmQiLCJyZXBsYXllZFRyZWUiOiI2NTA4NzdlM2NiZDNmNzgwZWQyZTBlODZhOGIxMDFmZmQ5MjgyZjFmIiwicXVldWVBdHRlbXB0IjoiMjg5NWI2MmRlZWNiNmFlYTQ3NDZjNzA5OThhMWM1ZmFkZDMyOWExM0AyMzQ5ZmQ3NjlkZTY2N2JkN2M3NTQ4OTE4ZWYzODM4OGFiOTg1MzRjIiwiYWRtaXNzaW9uUHJvb2ZSb290Ijoic2hhMjU2OjIzOWU4MWYzMDNmNjM4MmQxYjc2NTQ0ZTE5Y2EzMjUzNjM3Y2YwZmY3ZWZkMzNiNjJhNzYxMmI5ZTQ3NmE5YmEiLCJhZG1pc3Npb25Qcm9vZlJvb3RzIjpbInNoYTI1NjoyMzllODFmMzAzZjYzODJkMWI3NjU0NGUxOWNhMzI1MzYzN2NmMGZmN2VmZDMzYjYyYTc2MTJiOWU0NzZhOWJhIiwic2hhMjU2OjlkNjY1N2NiMjYwNDNmOWZkMWQ0YTAwY2JhZGU3OGY0NGFlOWFhZmY2MjZhYzIxOTA3ZDNlMjgzZDc1NzlhNTAiXSwic3RhdHVzQ29udGV4dCI6IlF1ZXVlIGZhbWlseSBsZWFzZS9kOTlmM2E5MTY2NzM5ZTBkIiwibGVhc2VSb290Ijoic2hhMjU2OjViYzNiZDc0ZGIxNjVjZmY1NzhhODU0ZTEwZWRlODkzZjVjM2VmYWQxYjFjOWE5MDIxM2JiMzA2NGIzMzRkOWIifQ -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T16:12:48Z",
          "mergedAt": "2026-07-30T04:05:12Z",
          "additions": 2372,
          "deletions": 189,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 240,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/240",
          "title": "fix: grant stable canary check read access",
          "body": "## Summary\n\n- grant the stable canary caller the read-only checks permission requested by the current Buildchain v3 reusable workflow graph\n- keep preview, staging, and production apply disabled\n- recover the exact v3.0.2-alpha.10 qualification path after startup failure run 30513715067\n\n## Verification\n\n- actionlint .github/workflows/buildchain-stable-canary.yml\n- node scripts/check-infra-outputs.mjs\n- git diff --check\n\nRelated: kungfu-systems/buildchain#1883",
          "author": "dongkeren",
          "createdAt": "2026-07-30T04:54:57Z",
          "mergedAt": "2026-07-30T05:11:38Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1923,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1923",
          "title": "fix(qualification): let NSIS self-copy before uninstall",
          "body": "## Summary\n\nFix GitHub-hosted Windows surface qualification by preserving the standard NSIS temporary-copy uninstall behavior. The previous `_?=` override kept the uninstaller inside the install root, where electron-builder 26.15.3 process detection could terminate the uninstaller itself.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- invoke the NSIS uninstaller with `/S` without the no-copy override\n- wait boundedly for a detached temporary uninstaller to remove the install root\n- make the surface qualification await real uninstall completion\n- add regression coverage for the command boundary and asynchronous removal\n\n## Verification\n\n- `./shifu check`\n- GitHub-hosted Windows alpha qualification will provide the exact installer/uninstaller regression proof\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fix corrects the existing Windows installer qualification harness without changing an architecture contract.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects release qualification evidence only; it does not publish artifacts or change release identity.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed — not applicable; product behavior is unchanged\n\n## GitHub-hosted Windows proof\n\n- Exact source: `51941f9db831b938ff022e61475de7faf2a3269a`\n- Alpha preflight: https://github.com/kungfu-systems/kungfu/actions/runs/30501796822 (success)\n- Windows-only full lifecycle: https://github.com/kungfu-systems/kungfu/actions/runs/30501919863 (success)\n- Windows job: 2h21m57s total; build 59m08s; verify 50m20s. The NSIS uninstall qualification completed successfully.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T00:07:23Z",
          "mergedAt": "2026-07-30T05:12:15Z",
          "additions": 46,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2045,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2045",
          "title": "fix(release): bind qualification to dispatched canary run",
          "body": "## Summary\n\n- bind replacement workflow polling to the previous run timestamp and ID\n- ignore the stale completed run that caused the replacement dispatch\n- cover delayed GitHub Actions run visibility and same-second run creation\n\n## Verification\n\n- node --test tests/stable-candidate-qualification.test.mjs\n- pnpm run check\n- git diff --check\n\nDogfood finding: sha256:b4830c5159e099ff0fce7374629232a400978869f8db400401c12cdfbd37f7e2",
          "author": "dongkeren",
          "createdAt": "2026-07-30T05:20:55Z",
          "mergedAt": "2026-07-30T05:26:12Z",
          "additions": 78,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1929,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1929",
          "title": "feat(agent-patrol): qualify a real Kungfu module snapshot",
          "body": "## Summary\n\nReplace #1928 with a Project Cut linearly replayable delivery of the same bounded real-module Agent Patrol qualification. Add a protected manual lane that repairs one deterministic regression in a content-rooted snapshot of real Kungfu Agent Patrol modules. The weekly real-snapshot schedule remains disabled until the protected agent-121 qualification passes.\n\n## Related issue\n\nAtlas goal `2026-07-30-kungfu-agent-patrol-real-module-snapshot`.\n\n## Changes\n\n- commit an eight-file, 3,102-line exact-commit manifest with per-file mode, byte, line, and SHA256 roots plus one canonical tree root\n- materialize only tracked regular files, copy no Git metadata, and apply one reversible stable-fingerprint regression\n- keep Agent A read-only and restrict Agent B to `framework/agent-patrol/classify.mjs`\n- verify the visible regression, a hidden external variant, exact changed paths, and the pristine reference root outside the model workspace\n- add a manual `real-snapshot` Patrol mode while leaving existing daily-light and weekly-deep synthetic schedules unchanged\n- replay the three logical commits linearly from current `dev/v4/v4.0`; local Project Cut queue-admission reports `qualified`\n\n## Verification\n\n- `./shifu test:agent-patrol` (32/32)\n- exact commit `057eeae026babb4618708e24d31ad55537a6857e` seeded/reference qualification through `git show`\n- seeded defect present; reference repair passes visible + hidden external checks with only `framework/agent-patrol/classify.mjs` changed\n- `./shifu project-cut:queue-admission -- --base 35f7e8fdec548a3385382afd7799d79d370acb3c --head 4876d884350ce5db5cfecb6968d68abc1d4e4fc2` (`qualified`, composition unchanged)\n- full staged pre-commit gate, including documentation, invariants, KFD, Biome, and DCO\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-786d-aa24-a97705e13917\"],\n  \"summary\": \"Add the manual content-rooted real-module Agent Patrol qualification lane without enabling its weekly schedule.\",\n  \"verification\": [\"./shifu test:agent-patrol\", \"exact-commit real snapshot seeded/reference oracle\", \"./shifu project-cut:queue-admission\", \"staged pre-commit gate\"]\n}\n-->\n\n## [Evolution Map](../docs/evolution/README.md) impact\n\nEvolution impact: extends\n\nThis adds bounded real-module qualification evidence to the current Agent continuity stage; it does not open or settle a new authority transition.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: OpenCode remains digest-pinned, unauthenticated against the explicit local-model endpoint, sandboxed, and advisory. No provider transcript, prompt, source bytes, or credentials are retained.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T04:48:18Z",
          "mergedAt": "2026-07-30T05:37:27Z",
          "additions": 907,
          "deletions": 107,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2046,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2046",
          "title": "fix(signing): split artifact upload proxy route",
          "body": "## Summary\n- add an optional upload-only `NO_PROXY` route for Buildchain-owned signing requests\n- preserve the runner route for immutable signed-result downloads\n- document and publish the additive v3 workflow contract\n\n## Evidence\n- macOS candidate run 30509709219 attempt 3: proxied upload advanced only to 16 MiB before `write EPIPE`\n- prior direct upload completed while direct signed-result download repeatedly reset\n- `pnpm run check` (974 tests, workflow lint, generated site contract, action bundle integrity)\n- focused upload-route and reusable build-surface tests\n\n## Downstream validation\nKungfu Alpha will pin the exact merged runtime and set `.blob.core.windows.net` only for the signing-request upload before candidate rerun.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T06:20:19Z",
          "mergedAt": "2026-07-30T06:30:39Z",
          "additions": 210,
          "deletions": 39,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1930,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1930",
          "title": "feat(shifu): add Qualified Core usage observability",
          "body": "## Summary\n\nAdd a bounded, local, content-addressed Qualified Core usage ledger and a\nread-only `./shifu qualified-core status --json` surface.\n\nThe consumer now records deterministic terminal hit, miss, rejection,\nunsupported-host, and source-build fallback outcomes with bounded platform,\nduration, source, compatibility, and artifact identities. The ledger remains\noptimization evidence only: it cannot qualify, promote, admit, or authorize an\nartifact, and it does not retain provider bodies, URLs, credentials, paths, or\nenvironment dumps.\n\n## Related issue\n\nQualified Core developer acceleration family child:\n`2026-07-30-kungfu-qualified-core-usage-observability`.\n\n## Changes\n\n- publish immutable observations under the Qualified Core cache root;\n- summarize at most 10,000 regular-file observations without following\n  symlinks outside the cache;\n- record local CAS, trusted remote, explicit bundle, cache miss, verification\n  rejection, unsupported-host, and fallback results;\n- preserve observations across artifact-object eviction and worktree removal;\n- route the read-only status command through the build-free Shifu L2 surface;\n- bind the consumer and observation implementation into the Qualified Core\n  Shifu contract identity.\n\n## Verification\n\n- `PATH=<isolated-py313-tools> ./shifu check:source`\n- `SHIFU_NATIVE=0 ./shifu exec node --test scripts/qualified-assignment-core-artifact.test.mjs scripts/check-shifu-cache-contract.test.mjs` (53 passed)\n- `SHIFU_NATIVE=0 ./shifu exec node scripts/code-complexity-budget.mjs`\n- `node node_modules/typescript/bin/tsc -p tsconfig.tools.json`\n- pre-commit staged gate (passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Add bounded local Qualified Core usage observability without changing artifact authority.\",\n  \"verification\": [\"build-free source acceptance\", \"53 Qualified Core and cache contract tests\", \"tooling type check\", \"complexity budget\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe GitHub artifact provider remains read-only and existing. The new local\nledger stores only selected bounded metadata and explicitly excludes signed\nURLs, provider bodies, credentials, and raw environment state.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LXF1YWxpZmllZC1jb3JlLWRldmVsb3Blci1hY2NlbGVyYXRpb24tZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtdXNhZ2Utb2JzZXJ2YWJpbGl0eSIsImRlbGl2ZXJ5Q2xhc3MiOiJuYXRpdmUtcHJvb2YtcmVxdWlyZWQiLCJkZXZIZWFkIjoiM2UxZDAzYmMxNmEyYTZmYWUxMzhjMjY1YzU0MWIyMzIzODFhZDI0NSIsInB1bGxSZXF1ZXN0SGVhZCI6IjYwZDdmMjA2NzJmOTQ0OGM2NmQ2Yjc1ODkzNGQ0NDAzMGYyYjNiZjkiLCJyZXBsYXllZENhbmRpZGF0ZSI6IjA3ZWJmZTdlYWI5YzgwMTcxNDM3NWM3ZThhMjUxMGU4OWU4ZjNmZjgiLCJyZXBsYXllZFRyZWUiOiI2MGIwZjllMWJiN2Y5OWI3MmFjYTQxNzJhYzZkMGMxZTk5M2M2YzI1IiwicXVldWVBdHRlbXB0IjoiNjBkN2YyMDY3MmY5NDQ4YzY2ZDZiNzU4OTM0ZDQ0MDMwZjJiM2JmOUAzZTFkMDNiYzE2YTJhNmZhZTEzOGMyNjVjNTQxYjIzMjM4MWFkMjQ1IiwiYWRtaXNzaW9uUHJvb2ZSb290Ijoic2hhMjU2OjhkMDk3MDJjYTQwYTRlZWM0ZjAwYmM0MjAwMDY1MmI3ODQyMjNmMjAxYzk2NWViZjBkMzRlYzIyYzQ5MDMyOGUiLCJhZG1pc3Npb25Qcm9vZlJvb3RzIjpbInNoYTI1Njo4ZDA5NzAyY2E0MGE0ZWVjNGYwMGJjNDIwMDA2NTJiNzg0MjIzZjIwMWM5NjVlYmYwZDM0ZWMyMmM0OTAzMjhlIiwic2hhMjU2Ojk5YjcwMTExODYyMGUwYTRhMWZlNzFiY2QxZjZmYTI5ZWQyNTc5MGVkMDA3OTk1YWE5YmM2MjAwODExNjlmNzQiXSwic3RhdHVzQ29udGV4dCI6IlF1ZXVlIGZhbWlseSBsZWFzZS85NmQzYmZmNTcxYjA0YmIyIiwibGVhc2VSb290Ijoic2hhMjU2OmQzMmIzYWUwOGYwMzZlNWJlMTAzZGU2NGQyNGVlODNiMzAwZWY4MzgyZDkyNzVkOTVhZDlkNGNjYTgxOTRhYzQifQ -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T06:04:19Z",
          "mergedAt": "2026-07-30T06:35:43Z",
          "additions": 1027,
          "deletions": 69,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 188,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/188",
          "title": "feat(site): standardize copyable code surfaces",
          "body": "## Summary\n\nStandardize every actionable code or Agent-prompt surface on kungfu.tech with one shared copy control, while preserving the compact Install/Update switcher on Hub Starter. Add a site-wide gate so future command surfaces cannot ship without the same structure, behavior, accessibility labels, and fingerprinted asset.\n\n## Changes\n\n- keep Hub Starter Install and Update as keyboard-operable tabs within one command card\n- add shared one-click copy behavior and global styling to Get Kungfu, Verify Agent Hub, Hub Starter, and both bootstrapping pages\n- cover all 11 currently rendered command and Agent-prompt surfaces, including generated installer and Agent Hub output\n- fingerprint the shared clipboard JavaScript alongside site CSS\n- add a source-and-dist gate that rejects uncovered actionable code, missing copy controls, missing accessibility labels, or missing shared behavior\n- add negative fixtures proving the gate rejects each omission class\n\n## Verification\n\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `bash -n scripts/check-site.sh`\n- `shellcheck scripts/check-site.sh`\n- `git diff --check`\n- headless Chrome rendering across all five affected routes\n- headless Chrome interaction check: all 11 controls produced exact clipboard contents and visible copied state\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces (presentation and asset fingerprinting only; no authority or publication facts changed)\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed (the pages and executable site checks are the behavior source)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T04:00:09Z",
          "mergedAt": "2026-07-30T06:48:39Z",
          "additions": 538,
          "deletions": 79,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2047,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2047",
          "title": "Release v3.0.2 from qualified v3.0.2-alpha.10",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v3.0.2-alpha.10`\n- Candidate SHA: `44242696401d4456d23413501517735787db247d`\n- Selection: `latest-qualified`\n- Ledger ref: `buildchain/candidate-ledger/v3/v3.0`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T06:48:51Z",
          "mergedAt": "2026-07-30T06:50:16Z",
          "additions": 18838,
          "deletions": 2443,
          "changedFiles": 176
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 189,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/189",
          "title": "Release production from adf3a3c42ff1",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `adf3a3c42ff1cf0e51338d10b78bff3a253456cd`\n- Artifact hash: `6f362994dbf58fd50898e80b31dcc1655856689eb267bfce97e6ff4b7755e6a9`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30520771364)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-adf3a3c42ff1`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-30T06:50:54Z",
          "mergedAt": "2026-07-30T06:53:53Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 190,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/190",
          "title": "Release production from adf3a3c42ff1 (merge retry)",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed and byte-verified from the current main commit. This retry exists because rebase-merging the prior empty release-intent commit produced no `main` push, so the protected production environment correctly rejected the pull-request ref. Merge this PR with a merge commit to create the required protected `main` push.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release evidence\n\n- Source SHA: `adf3a3c42ff1cf0e51338d10b78bff3a253456cd`\n- Artifact hash: `6f362994dbf58fd50898e80b31dcc1655856689eb267bfce97e6ff4b7755e6a9`\n- Staging release passport: https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30520771364\n- Prior rejected PR-ref production run: https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30521061728\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-adf3a3c42ff1-retry`\n\nThis PR intentionally contains one empty release-intent commit and must be merged with a merge commit.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T06:57:00Z",
          "mergedAt": "2026-07-30T07:00:29Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2049,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2049",
          "title": "fix(release): accept pre-publication release candidate evidence",
          "body": "## Summary\n\n- make stable canary completion timing source-aware\n- accept exact successful release-candidate evidence produced before alpha publication\n- retain post-publication timing for consumer commit-status evidence\n- expose the timing decision in the stable gate report\n\n## Verification\n\n- `node --test tests/stable-release-gate.test.mjs tests/stable-release-gate-cli.test.mjs`\n- live evidence replay for `v3.0.2-alpha.10`: `stable-release-gate=allow`\n- `pnpm run check` (975 tests)\n- `git diff --check`\n\nFixes #2048\n\nKungfu dogfood issue root: `sha256:46c9c7d855f6541fd2efed906a01c5797254d9a7d4d2e9c970bff8b8b571fa82`",
          "author": "dongkeren",
          "createdAt": "2026-07-30T07:04:11Z",
          "mergedAt": "2026-07-30T07:07:31Z",
          "additions": 19,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 241,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/241",
          "title": "Release production from 31afe2128c51",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `31afe2128c51e83ab01968cb086f0818e9ecff96`\n- Artifact hash: `852cabb9f7ce65abe2d49235e2442ff992f6169fa41665bd98c3135e9b89d9f1`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/30515939374)\n- Required label: `buildchain-release`\n- Release branch: `release/production-31afe2128c51`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-30T05:23:53Z",
          "mergedAt": "2026-07-30T07:08:08Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1932,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1932",
          "title": "fix(signing): split artifact transport route",
          "body": "## Summary\n\n- advance the protected Buildchain v3 artifact-signing authority to `67bf0346474ec4d5ccba04747fe52df9019819a8`\n- route the large signing-request upload directly to Azure Blob while preserving the runner proxy for signed-result download\n- refresh the Alpha contract lock and all release/workflow authority projections\n\n## Related issue\n\n- Atlas goal `2026-07-24-buildchain-linux-github-attestation`\n\n## Changes\n\n- bind `BUILDCHAIN_ARTIFACT_SIGNING_REQUEST_UPLOAD_NO_PROXY` through the reusable build input\n- retain stable `v3` release authority unchanged while advancing only the Alpha exact-SHA authority\n- add a consumer regression assertion for the split transport route\n\n## Verification\n\n- `./shifu test:auditable-demo` — 28/28 pass\n- `./shifu test:release-admission` — 5/5 pass\n- `./shifu release:promotion:rehearse` — pass, zero side effects\n- `./shifu check:gate-catalog` — pass\n- `./shifu check:source` — pass on latest `dev/v4/v4.0`; 777/777 source contract tests pass, 10 platform-only skips\n- pre-commit staged gate — pass\n- repository variable readback: `.blob.core.windows.net`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded transport repair preserves the accepted artifact-signing and release authority; it changes only how the existing signing request and signed result traverse the runner network boundary.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change advances an independently reviewed exact Buildchain workflow SHA and contract digest; no credential material is added or exposed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and generated authority projections are current\n- [x] Focused, source, and staged gates passed",
          "author": "dongkeren",
          "createdAt": "2026-07-30T07:01:35Z",
          "mergedAt": "2026-07-30T07:13:46Z",
          "additions": 36,
          "deletions": 30,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/.github",
          "number": 1,
          "url": "https://github.com/kungfu-systems/.github/pull/1",
          "title": "ci: establish organization governance gate",
          "body": "## Summary\n\n- assign all organization community-health files to the independent governance identity\n- add a read-only governance check for required public policy sources\n- prepare `main` for descriptor-bound native branch protection\n\n## Verification\n\n- `git diff --check`\n- workflow uses read-only repository permissions and pinned major actions",
          "author": "dongkeren",
          "createdAt": "2026-07-30T07:19:30Z",
          "mergedAt": "2026-07-30T07:19:54Z",
          "additions": 28,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2052,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2052",
          "title": "fix(release): separate recovery runtime from source",
          "body": "## Summary\n\n- keep durable recovery product source pinned to the exact protected channel SHA\n- execute recovery with the reviewed workflow runtime that owns the dispatch\n- preserve normal workflow-run and manual dry-run runtime behavior\n\n## Verification\n\n- `node --test tests/build-surface.test.mjs` (90 tests)\n- `pnpm run check:workflows`\n- `git diff --check`\n\nFollow-up to #2048 and #2049. The first durable recovery run proved that the prior wrapper still checked out the old release source as its runtime, so the repaired stable gate could not be reached.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T07:18:46Z",
          "mergedAt": "2026-07-30T07:21:54Z",
          "additions": 13,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 66,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/66",
          "title": "chore(governance): assign independent code ownership",
          "body": "## Summary\n\n- assign the repository to the independent `kungfu-origin` Code Owner\n- prepare the active dev and alpha branches for strict descriptor-bound review enforcement\n\n## Verification\n\n- `npm ci --ignore-scripts --registry=https://registry.npmjs.org/`\n- `npm run check` (59 tests)\n- `bash -n scripts/smoke-image.sh scripts/smoke-browser.sh`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-30T07:20:19Z",
          "mergedAt": "2026-07-30T07:22:57Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 242,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/242",
          "title": "Accept current Buildchain v3 contracts",
          "body": "## Summary\n\n- accept the current stable `v3` runtime contract at `f541fd28556a`\n- accept the current `v3-alpha` runtime contract at `44242696401d`\n- retain the `major-compatible` policy and exact surface digests\n\n## Review\n\nStable changes cover the v3.0.1 release/governance updates and the additive auditable-demo surface. Alpha changes cover stable signing compatibility and DCO-signed generated release commits. Existing web-surface breaking digests remain unchanged.\n\n## Verification\n\n- generated both locks with the matching tagged Buildchain runtime\n- exact stable lock check: `unchanged`, compatible, no drift\n- exact alpha lock check: `unchanged`, compatible, no drift\n- `jq empty`\n- `git diff --check`\n\nCloses #218\nCloses #212",
          "author": "dongkeren",
          "createdAt": "2026-07-30T07:12:06Z",
          "mergedAt": "2026-07-30T07:25:17Z",
          "additions": 12,
          "deletions": 7,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2053,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2053",
          "title": "Release v3.0.2",
          "body": "Create the generated version-state commit for v3.0.2.\n\nBuildchain generated this PR because protected branch release/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: 1aeb9191f607a7223f8ab63c96427b605ecda9be -> 2eee38ecd8f6b6dff1815bb8cdf28936c1ca321d\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T07:25:29Z",
          "mergedAt": "2026-07-30T07:36:43Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2054,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2054",
          "title": "fix(governance): admit complete public managed zone",
          "body": "## Summary\n- admit the public organization profile and runtime image repositories into the authoritative managed zone\n- bind their exact protected refs and required checks\n- refresh the 19-repository / 41-public-target governance baseline and generated site facts\n\n## Verification\n- `pnpm run check` (975 passed)\n- `node --test tests/github-governance-authority.test.mjs tests/build-surface.test.mjs` (120 passed after merging latest dev)\n- `pnpm run check:workflows`\n- `git diff --check origin/dev/v3/v3.0...HEAD`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-30T07:42:40Z",
          "mergedAt": "2026-07-30T07:57:38Z",
          "additions": 46,
          "deletions": 21,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/runtime-images",
          "number": 67,
          "url": "https://github.com/kungfu-systems/runtime-images/pull/67",
          "title": "fix(governance): protect alpha ownership",
          "body": "## Summary\n- add the same independent CODEOWNERS authority already present on dev to the protected alpha line\n- keep the patch alpha-only; no dev payload is promoted\n\n## Verification\n- `npm run check` (59 passed)\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-30T08:02:46Z",
          "mergedAt": "2026-07-30T08:04:31Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 245,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/245",
          "title": "Accept Buildchain v3.0.2 contract",
          "body": "## Summary\n\nAccept the current floating `v3` contract at `ca36670853ac` (`v3.0.2`).\n\nThe stable release adds opt-in auditable-demo media profiles and advances that surface digest. This site does not call the auditable-demo workflow; its `web-surface` breaking digest remains unchanged. The new media profile defaults preserve `archive-v1`, and Buildchain marks the release impact as non-breaking with no migration required.\n\n## Verification\n\n- generated the lock with the exact `v3` tagged runtime\n- exact stable lock check: `unchanged`, compatible, no drift\n- `jq empty`\n- `git diff --check`\n\nCloses #244",
          "author": "dongkeren",
          "createdAt": "2026-07-30T07:50:00Z",
          "mergedAt": "2026-07-30T08:05:49Z",
          "additions": 5,
          "deletions": 5,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2056,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2056",
          "title": "fix(release): admit Environment tag policies",
          "body": "## Summary\n- bind publication Environment authorization to the actual deployment ref and ref kind\n- support GitHub custom branch/tag policies with slash-safe `*` and recursive `**` matching\n- make sealed binary assets audit the exact `v<version>` tag instead of incorrectly requiring the channel branch itself\n\n## Incident evidence\n- failed sealed asset run: https://github.com/kungfu-systems/buildchain/actions/runs/30523940117\n- dogfood Finding: `sha256:c9eab094f64aff803e02a081d74a439f442e29c7a589da86674386cdb56d9ba5`\n- dogfood Issue: `sha256:39b751bfb81980f601f03807c9d6278624177f33518bcfed40f337badb7b0003`\n\n## Verification\n- live v3.0.2 control-plane replay: all six facts pass, including `environment-policy`\n- `pnpm run check` (976 passed)\n- combined post-merge targeted suite (145 passed)\n- `pnpm run check:site`\n- `pnpm run check:workflows`\n- `git diff --check origin/dev/v3/v3.0...HEAD`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-30T08:03:36Z",
          "mergedAt": "2026-07-30T08:09:42Z",
          "additions": 72,
          "deletions": 11,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1931,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1931",
          "title": "feat(ci): add queue-aware macOS overflow",
          "body": "## Summary\n\nAdd a minimal macOS-only queue-aware overflow route for Alpha build diagnostics. Healthy self-hosted execution remains primary; GitHub-hosted `macos-15` starts only after the retained-workspace health guard fails, a source-proven queue prediction crosses the boundary, or observed queue time reaches 25 minutes.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- extend the existing `build.yml` entry with one `macos-overflow-request-json` control envelope; no extra workflow is added\n- bind control and both candidate runs to one exact source SHA and successful Alpha preflight run\n- run the existing Buildchain lane as independent self-hosted and GitHub-hosted macOS candidates with `publish-channel: none`\n- inspect the known retained signing-result destination before the non-idempotent import path\n- cancel a queued self-hosted candidate only after the hosted platform job has acquired a runner; never cancel a started self-hosted platform job\n- emit a machine-readable receipt for route reason, queue duration, runner identity and labels, cancellation, result, winner, source, and preflight\n- retain the existing Alpha promotion workflow as the sole publication authority\n- bind the controller into workflow authority, preflight, publication-surface, and semantic-amplification roots\n\n## Verification\n\nFinal head `8ae0eb5e67197e8a8569bf61982f5befe45a74c7`:\n\n- `./shifu test:alpha-macos-overflow` — 8/8 passed\n- `./shifu test:alpha-promotion-preflight` — 55/55 passed\n- `actionlint .github/workflows/build.yml` — passed\n- `./shifu check:source` — passed after merging current `dev/v4/v4.0`\n- DCO staged gates — passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7b6b-ae6d-76cea57487f2\"],\n  \"summary\": \"Complete a bounded queue-aware macOS candidate-routing stage while preserving Buildchain promotion as the sole publication boundary.\",\n  \"verification\": [\"alpha macOS overflow contract tests\", \"Alpha promotion preflight contract tests\", \"actionlint build workflow\", \"full Shifu source acceptance\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe controller uses the existing Actions token and existing Buildchain caller boundary without changing credentials, runner labels, services, or repository settings. Both candidate routes force `publish-channel: none`; the existing Alpha promotion workflow remains the sole publication authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation covers the queue threshold, health boundary, cancellation ordering, and receipt contract",
          "author": "dongkeren",
          "createdAt": "2026-07-30T06:12:12Z",
          "mergedAt": "2026-07-30T08:16:36Z",
          "additions": 1043,
          "deletions": 51,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2058,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2058",
          "title": "fix(signing): finalize signed artifacts on hosted runners",
          "body": "## Summary\n\n- keep self-hosted native runners out of authority-result downloads\n- bind a credential-free signing delegation to the exact source run, runtime, and platform\n- verify/import signed bytes and replace deterministic artifacts on GitHub-hosted infrastructure\n- fail closed before aggregate and release evidence until finalization succeeds\n- verify the complete provider result set before authority delivery\n\n## Validation\n\n- `pnpm run check` (965 tests, workflow checks, site contract, and six action bundles)\n- focused artifact-signing delegation, sealing, and native authority tests\n- `git diff --check`\n\n## Operational boundary\n\nThis changes Buildchain orchestration only. It does not modify self-hosted runner configuration.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T08:10:14Z",
          "mergedAt": "2026-07-30T08:18:18Z",
          "additions": 764,
          "deletions": 89,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2059,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2059",
          "title": "fix(demo): accept qualified autoplay sentinel",
          "body": "## Summary\n\nAlign the Buildchain auditable-demo terminal-capture validator with the canonical Kungfu `kungfu.agent-work-lab.tui-autoplay/v1` completion vocabulary. The validator now accepts `status: \"qualified\"` and rejects the legacy `\"passed\"` spelling without weakening report-root, event-count, exit-code, authority, or terminal bounds.\n\n## Related issue\n\nCloses #2057\n\n## Changes\n\n- require the canonical `qualified` autoplay completion status;\n- update the positive fixture;\n- add a negative assertion that rejects `passed`.\n\n## Verification\n\n- `node --test tests/auditable-demo.test.mjs` (12 passed)\n- `pnpm run check` (975 passed; workflow, site, architecture, and 6 action bundle checks passed)\n- downstream validation is running from exact commit `3272608ba28ef714fe710dd8da99d00fdeb4c619` in kungfu run `30525890727`\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change is limited to qualification evidence vocabulary and remains fail-closed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (the canonical status is owned by Kungfu; the Buildchain fixture and validator are aligned here)",
          "author": "dongkeren",
          "createdAt": "2026-07-30T08:14:51Z",
          "mergedAt": "2026-07-30T08:20:11Z",
          "additions": 8,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2060,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2060",
          "title": "chore(signing): promote hosted finalization authority",
          "body": "Promote the reviewed v3 runtime after Buildchain PR #2058 moved artifact-signing result import and final manifest sealing onto GitHub-hosted infrastructure.\n\nThe authority candidate binds exact dev head `fe80aa8912779004417c027223c5cbe2fb865803`, which contains the protected #2058 merge plus the subsequent qualified demo sentinel merge #2059. PR #2058 passed independent Code Owner review, Verify run `30525746027`, governance run `30525746037`, full Build Surface Fixture run `30525746418`, and merge-group verification before merge. The fixture proved all three hosted finalization lanes plus the qualifying build-controller and channel-router receipts.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T08:19:40Z",
          "mergedAt": "2026-07-30T08:21:59Z",
          "additions": 1784,
          "deletions": 256,
          "changedFiles": 55
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 15,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/15",
          "title": "fix(tap): publish Buildchain v3 formula",
          "body": "## Summary\n\n- project the governed Buildchain v3.0.2 release passport into the Homebrew formula and manifest\n- bind darwin-arm64 and linux-x64 archives to the published SHA256 values\n- accept the reviewed additive `auditable-demo` v3 contract surface and regenerate KFD witnesses\n\n## Verification\n\n- `node scripts/update-managed-products.mjs --package buildchain --type formula --release-passport https://github.com/kungfu-systems/buildchain/releases/download/v3.0.2/buildchain.release.json --check --update-lock --json`\n- `node --test scripts/update-managed-products.test.mjs`\n- `node scripts/check-tap.mjs`\n- `ruby -c Formula/buildchain.rb`\n- `git diff --check`\n\nNo credentials, provider APIs, hosted-service configuration, or package names are changed. Release evidence is the public Buildchain v3.0.2 passport.\n\nCloses kungfu-systems/buildchain#1883",
          "author": "dongkeren",
          "createdAt": "2026-07-30T08:24:11Z",
          "mergedAt": "2026-07-30T08:30:39Z",
          "additions": 38,
          "deletions": 33,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1934,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1934",
          "title": "feat(shifu): add Qualified Core compatibility identity",
          "body": "## Summary\n\nAdd a versioned compatibility identity for Qualified Core artifacts so native outputs can be reused across non-native commits when the full native input closure is unchanged, while preserving exact producer provenance and source fallback.\n\n## Related issue\n\n- `2026-07-30-kungfu-qualified-core-compatibility-identity`\n\n## Changes\n\n- introduce v2 candidate, manifest, qualification, equivalence, and materialization contracts keyed by an immutable compatibility root\n- bind the root to the tracked `framework/core` closure, target identity, CPython ABI, toolchain, lockfiles, profile, Shifu/Buildchain contracts, policy implementation, and artifact root\n- retain exact producer and consuming commits separately from compatibility identity\n- allow explicit target-equivalence reuse only after recomputing and validating both roots\n- keep v1 exact-commit artifacts readable through 2026-10-31 without admitting them to compatibility-index reuse\n- deduplicate transport copies in local CAS while rejecting distinct qualified authorities for the same compatibility root\n- promote an existing qualified artifact in the protected workflow when the current commit has no exact candidate\n\n## Verification\n\n- 59 focused Qualified Core/cache contract tests passed\n- AJV validation: 3 valid fixtures accepted and 2 invalid fixtures rejected\n- `actionlint .github/workflows/affected-native-cache-promote.yml`\n- Biome checks for changed JavaScript and JSON\n- workflow authority refresh and ADR map refresh\n- Shifu light gate with Rust capability\n- full staged pre-commit gate\n\n## ADR release manifest\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Add versioned Qualified Core native compatibility identity and protected non-native reuse without weakening source fallback.\",\n  \"verification\": [\"59 Qualified Core and cache contract tests\", \"AJV schema validation\", \"workflow authority and actionlint\", \"Shifu workspace gate\", \"pre-commit staged gate\"]\n}\n-->\n\n## Evolution impact\n\n- updated `docs/architecture/adr-map.json` and `docs/architecture/adr-map.md`\n\n## Governance and risk\n\n- compatibility and qualification roots remain immutable and independently verifiable\n- protected promotion remains workflow-owned; remote transport is not authority\n- no credentials or secret material are introduced\n- any incompatibility, ambiguity, missing proof, or expired v1 input degrades to source build\n\n## Checklist\n\n- [x] contracts and schemas versioned\n- [x] producer, verifier, consumer, and protected workflow aligned\n- [x] positive, negative, tamper, migration-window, and transport-deduplication tests added\n- [x] workflow authority and ADR projections refreshed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LXF1YWxpZmllZC1jb3JlLWRldmVsb3Blci1hY2NlbGVyYXRpb24tZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtY29tcGF0aWJpbGl0eS1pZGVudGl0eSIsImRlbGl2ZXJ5Q2xhc3MiOiJuYXRpdmUtcHJvb2YtcmVxdWlyZWQiLCJkZXZIZWFkIjoiZTRiNmRiYzdjYTdkNWFkNjFmODFhOGRjMWZmMGJlNGQ1MjViNDY3OCIsInB1bGxSZXF1ZXN0SGVhZCI6ImUzMWM2Mjc3ZDdmZTFhZjdhNWI0NzdmZmRmZjNhNzY5NjAwOTIzYjIiLCJyZXBsYXllZENhbmRpZGF0ZSI6ImViOWY5YTQ2MWFlZDk3MjQ0OGIxMDZiYzY4Mjk1NWMwMzcyYzE2NDMiLCJyZXBsYXllZFRyZWUiOiI0MjIwOTA2NTM3Njg1MzU0N2ExMDE0Y2RmNzE2YjI4NjE0YmM1ZDM1IiwicXVldWVBdHRlbXB0IjoiZTMxYzYyNzdkN2ZlMWFmN2E1YjQ3N2ZmZGZmM2E3Njk2MDA5MjNiMkBlNGI2ZGJjN2NhN2Q1YWQ2MWY4MWE4ZGMxZmYwYmU0ZDUyNWI0Njc4IiwiYWRtaXNzaW9uUHJvb2ZSb290Ijoic2hhMjU2OjRmZmQ2ZWYxODgxZjM5YTI3ZTQyYzM2ODc3NDE2OWFjZTYzZDUyNTVjMjY0MmVjMWNmZjIwYjQxY2FiMGJjOTMiLCJhZG1pc3Npb25Qcm9vZlJvb3RzIjpbInNoYTI1Njo0ZmZkNmVmMTg4MWYzOWEyN2U0MmMzNjg3NzQxNjlhY2U2M2Q1MjU1YzI2NDJlYzFjZmYyMGI0MWNhYjBiYzkzIiwic2hhMjU2OjhlYjg5NmZkM2Q0Y2M5ZmQwNjJiZDAyMTJmZTNkZDFiNmQ4NGNjNDhiZWM0ZjA1Yzk0MjE0NTYzZDQxNGQ2NDEiXSwic3RhdHVzQ29udGV4dCI6IlF1ZXVlIGZhbWlseSBsZWFzZS85NmQzYmZmNTcxYjA0YmIyIiwibGVhc2VSb290Ijoic2hhMjU2OjZkZDRiMjY5OGRmNDQzZGVkNTAzMmZiMjFjNzk3OWM0MmMwNTU0NzA1MjI2YjdkNDZjZjA1NzlkODlkZDhjZmUifQ -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T07:53:21Z",
          "mergedAt": "2026-07-30T08:39:33Z",
          "additions": 1984,
          "deletions": 215,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 246,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/246",
          "title": "Release production from 863fe5771803",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `863fe5771803240f5adf6a083154e02582b72e2c`\n- Artifact hash: `b64f61639d6a662e8cf4f1a91770a4e886e7a2afa2d71926acbe7fe2e6fd4317`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/30525329819)\n- Required label: `buildchain-release`\n- Release branch: `release/production-863fe5771803`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-30T08:23:53Z",
          "mergedAt": "2026-07-30T08:41:14Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1936,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1936",
          "title": "fix(release): consume hosted signing finalization",
          "body": "## Summary\n\nAdvance Kungfu Alpha to the protected Buildchain artifact-signing authority that finalizes exact signed binary bytes on GitHub-hosted infrastructure. The macOS credential island keeps signing and notarization authority, while consumers receive a declarative, repository-independent signing capability for requested binary artifacts.\n\n## Related issue\n\n- Atlas goal `2026-07-24-kungfu-public-alpha-release-closure`\n\n## Changes\n\n- pin reusable build and release-promotion workflows to Buildchain `bb55d20799d23c78b61a8a46765b2edd8c192aa9`\n- move the credential island to the formal `buildchain-artifact-signing` environment\n- refresh the Alpha contract lock, workflow authority, publication roots, and semantic-amplification report\n- assert hosted signing finalization and arbitrary requested-binary coverage in consumer regressions\n- keep the stable channel pinned to its existing Buildchain v3 authority\n\n## Verification\n\n- `./shifu check:source` on current `dev/v4/v4.0`: passed; 793 main tests (783 passed, 10 platform-only skips), plus 40 Python, 116 runtime-upgrade, and 69 desktop-update tests\n- `./shifu test:auditable-demo`: 28/28 passed\n- `./shifu test:alpha-promotion-preflight`: 55/55 passed\n- `./shifu test:npm-core-platform-distribution`: 82 passed, 3 Windows-only skips\n- `./shifu release:promotion:rehearse`: passed with zero side effects\n- `./shifu check:gate-catalog`: passed\n- `./shifu docs final-ready --since origin/dev/v4/v4.0 --budget 66560 --json`: Human/Agent parity matched, no omissions or violations; authored documentation requires independent review\n- full DCO staged gate passed\n- exact legacy environment identifier absent from the current repository\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This release-infrastructure fix advances the accepted Buildchain artifact-signing authority and verification route without changing Kungfu architecture contracts or adding a second signing authority.\"\n}\n-->\n\n## [Evolution Map](../docs/evolution/README.md) impact\n\nEvolution impact: none\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes only protected workflow references, the formal environment selector, and derived authority evidence. It does not add, expose, or modify credential bytes. The final signed artifact set is independently digested on GitHub-hosted infrastructure before release admission.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T08:49:18Z",
          "mergedAt": "2026-07-30T09:01:23Z",
          "additions": 40,
          "deletions": 40,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2061,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2061",
          "title": "fix(runtime): move ungoverned defaults to v3",
          "body": "## Summary\n\n- move active Buildchain runtime fallbacks and patrol defaults from v2 to v3\n- keep scheduled dogfood patrols on the governed v3-alpha channel\n- add a machine-verifiable inventory for every remaining workflow v2 token, including caller status, ownership, and sunset conditions\n- preserve the public contract fallback and legacy compatibility or fail-closed tombstone surfaces\n\n## Validation\n\n- `pnpm run check`\n- 981 unit tests passed\n- workflow, site-generation, inventory, architecture, and action-bundle checks passed\n\n## Compatibility\n\nThe public reusable build and web-surface fallback remains v2 only when the workflow shell ref is unavailable, as required by the existing v3 contract lock. Normal `@v3` calls resolve the workflow shell ref and do not execute that fallback.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T09:07:07Z",
          "mergedAt": "2026-07-30T09:13:15Z",
          "additions": 335,
          "deletions": 90,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1935,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1935",
          "title": "feat(agent-patrol): add capability observation cadence",
          "body": "## Summary\n\nEvolve Agent Patrol from a single pass/fail repository task into a bounded capability-observation system on the dedicated agent-121 runner. Deterministic infrastructure and evidence-integrity failures remain blocking; model-quality outcomes remain advisory and feed deduplicated Dogfood Findings only.\n\n## Related issue\n\n- Atlas goal `2026-07-30-kungfu-agent-patrol-capability-observation-cadence`\n- Native Assignment `2026-07-30-kungfu-agent-patrol-capability-observation-cadence`\n\n## Changes\n\n- add daily light, weekly deep, weekly real-snapshot, and monthly qualification schedule selection;\n- retain exact protected-branch, pinned runner/image/model, bounded-trial, and serialized-model execution constraints;\n- emit content-addressed capability receipts binding source, fixture, runtime, report, classification, warrant, continuity, verifier, and Dogfood evidence;\n- store receipts append-only under the existing Patrol state root and derive bounded 14-day and 30-day trends;\n- produce strict qualification decisions without turning model quality into a blocking PR gate;\n- audit a JSON-only retained-artifact allowlist and reject symlinks, oversize files, raw model content, private paths, credentials, and environment dumps;\n- keep automatic Dogfood handling Finding-only with deduplication and explicit `issueAdmitted: false`.\n\n## Verification\n\n- `./shifu test:agent-patrol` — 40/40 pass\n- `actionlint .github/workflows/kungfu-agent-patrol.yml` — pass\n- `./shifu check:gate-catalog` — pass; 38 gates and 29 workflows aligned\n- `./shifu check:release-publication-control-plane` — pass\n- `./shifu check:source` — pass; 777 Node source contract tests pass with 10 expected platform skips, plus documentation, Python, runtime-upgrade, desktop, type, and formatting gates\n- pre-commit staged gate — pass\n- `./shifu docs final-ready --since 4107a587fd04a2460bbd1f8270ecf2f87b2df12a --json` — zero violations; independent review required for two authored qualification documents\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-786d-aa24-a97705e13917\"],\n  \"summary\": \"Add bounded Agent Patrol capability receipts, trends, privacy audit, and multi-cadence observation while preserving deterministic blocking gates and advisory model outcomes.\",\n  \"verification\": [\"40 Agent Patrol contract tests\", \"actionlint\", \"Gate catalog\", \"release publication control plane\", \"full Shifu source acceptance\", \"independent protected review\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe workflow invokes only the existing local OpenCode/Ollama path on agent-121, never passes repository credentials into the model container, retains no raw model content, and cannot admit a Dogfood Issue. Capability and qualification receipts are advisory evidence; deterministic infrastructure and evidence-integrity gates remain blocking.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for cadence, evidence, privacy, and qualification behavior\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LWFnZW50LXBhdHJvbC1jYXBhYmlsaXR5LW9ic2VydmF0aW9uLWNhZGVuY2UtaW5pdGlhdGl2ZSIsImFzc2lnbm1lbnRJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LWFnZW50LXBhdHJvbC1jYXBhYmlsaXR5LW9ic2VydmF0aW9uLWNhZGVuY2UiLCJkZWxpdmVyeUNsYXNzIjoibmF0aXZlLXByb29mLXJlcXVpcmVkIiwiZGV2SGVhZCI6IjU0N2IxYTFmOTkzZTc2YTI1MWUwNjEwMzljNjE2YThhYjZhOTE1YzAiLCJwdWxsUmVxdWVzdEhlYWQiOiIwY2MxNDkwZDY5MWMwNDllYTU3YWI1OWZkMDQ5OTQ1YzljNTBjYzczIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiI4ZGFhZGEzNDUyYTdmZjU5N2FiYTFjZDRlY2NkOTIwMzM5M2JkYWMzIiwicmVwbGF5ZWRUcmVlIjoiNjM5MjRhOTA1NGY1NWIyNmFmYzQwYTQwZDI2YmY5MmExMDk0ZmRlYyIsInF1ZXVlQXR0ZW1wdCI6IjBjYzE0OTBkNjkxYzA0OWVhNTdhYjU5ZmQwNDk5NDVjOWM1MGNjNzNANTQ3YjFhMWY5OTNlNzZhMjUxZTA2MTAzOWM2MTZhOGFiNmE5MTVjMCIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjozNTAxMDQ5OWUzYjIwMzA1ODZjZWJiMjQzYzdlZjU2MDkxM2NjOTc0YTQxMDUwY2YxYWE5ZWY4NGJiN2U2ODYyIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6MmY4YTE0ZmEyZTAyMmVmZDUyNzhjNjFhMGM4OWE1ODFiYmJjOWU0MjFiODc1OTQ4M2Q2ZmE3MTQ1OWM2ODRmMCIsInNoYTI1NjozNTAxMDQ5OWUzYjIwMzA1ODZjZWJiMjQzYzdlZjU2MDkxM2NjOTc0YTQxMDUwY2YxYWE5ZWY4NGJiN2U2ODYyIl0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvYjA2ZmI0MTE1ZmNkNDU5YSIsImxlYXNlUm9vdCI6InNoYTI1NjphMmFhNmI5MjNjYjIwZjkzNGRkN2U5N2Q1NDgxZGRhNzc4NTA5MzYxZWFjY2IzY2M5Zjk2ZDQxOWYwZDVkYWU0In0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T08:34:13Z",
          "mergedAt": "2026-07-30T09:23:59Z",
          "additions": 1664,
          "deletions": 142,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2063,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2063",
          "title": "fix(governance): exclude private repositories",
          "body": "## Summary\n\n- declare the managed GitHub governance zone as public-only\n- exclude private repositories before receipt and diagnostic generation\n- preserve fail-closed admission for newly discovered public repositories\n- remove retained private identity roots and regenerate the public site bundle\n\n## Verification\n\n- `pnpm run check` (981 tests; 6 action bundles)\n- `node --test tests/github-governance-authority.test.mjs` (31 tests)\n- `pnpm run check:site`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-30T09:19:37Z",
          "mergedAt": "2026-07-30T09:24:39Z",
          "additions": 113,
          "deletions": 81,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2065,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2065",
          "title": "fix(release): include signing finalization in candidate receipt",
          "body": "## Problem\n\nAlpha promotion PR #2064 exposed a fail-closed release-candidate bug: the candidate passport receipt omitted the required `signing-finalization` stage even after all platform finalization jobs succeeded. The receipt therefore became `partial` and the passport rejected it.\n\n## Fix\n\n- Emit `needs.finalize-artifact-signing.result` in the release-candidate controller receipt.\n- Add a regression test requiring both build controller receipt stage sets to exactly match the declared build-lifecycle descriptor.\n- Regenerate the public contract bundle.\n\n## Evidence\n\n- `node --test tests/controller-evidence.test.mjs`: 14/14 passed.\n- `bash scripts/check-workflows.sh`: passed.\n- `pnpm run check`: 983 tests passed; architecture, inventory, site, workflow and 6 action bundle checks passed.\n- Root-cause run: https://github.com/kungfu-systems/buildchain/actions/runs/30530387234",
          "author": "dongkeren",
          "createdAt": "2026-07-30T09:33:39Z",
          "mergedAt": "2026-07-30T09:39:19Z",
          "additions": 25,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1938,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1938",
          "title": "fix(qualification): keep durable host out of installer smoke",
          "body": "## Summary\n\nKeep the detached Agent Session host out of one-shot installer qualification so its worker cannot retain an executable under the temporary Windows install root while NSIS proves uninstall removal. Normal product launches retain the durable host.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- do not start or expose the durable Agent Session host in `KF_QUALIFICATION_MODE`\n- preserve the existing host for every normal product launch\n- retain the bounded 60-second uninstall deadline\n- report bounded remaining-entry and process-path diagnostics if removal times out\n- add regression coverage for the qualification boundary and timeout evidence\n\n## Verification\n\n- `./shifu check:source`\n- installer surface tests: 7/7 passed\n- changed GUI TypeScript check: 2 files passed\n- GitHub-hosted Windows full lifecycle will provide the exact installer/uninstaller proof\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fix enforces the existing one-shot installer qualification boundary without changing the Agent Session product architecture.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects release qualification evidence only. Diagnostics omit command lines and remain bounded; no artifacts are published and release identity is unchanged.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed — not applicable; normal product behavior is unchanged\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T09:22:37Z",
          "mergedAt": "2026-07-30T09:44:19Z",
          "additions": 137,
          "deletions": 10,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2064,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2064",
          "title": "chore(release): promote v3 runtime defaults to alpha",
          "body": "This replaces the conflicting direct promotion PR #2062 with the canonical publish-gate integration pattern.\n\n## Evidence\n\n- Integrates protected dev merge `bd9844314c07a1e05cd7e7d7419e3d330c84f379` into the current `alpha/v3/v3.0` head.\n- The only merge conflict was generated `dist/site/buildchain-contract.json`; it was regenerated from the merged sources with `pnpm run generate:site`.\n- `pnpm run check` passed: architecture, inventory, site and workflow checks; 981 tests; 6 action bundle integrity checks.\n- Hosted weekly patrol run 30529956812 succeeded and resolved `buildchain-ref: v3-alpha` to `44242696401d4456d23413501517735787db247d`.\n\n## Delivery\n\n- Author: dongkeren\n- Review and merge: kungfu-origin\n- DCO sign-off present on the integration commit.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T09:21:49Z",
          "mergedAt": "2026-07-30T09:45:56Z",
          "additions": 4096,
          "deletions": 665,
          "changedFiles": 105
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2066,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2066",
          "title": "Prepare v3.0.3-alpha.0",
          "body": "Create the generated version-state commit for v3.0.3-alpha.0.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: 5770bd104905c6a7ac9fe6b0513ca9e24e5814b4 -> 9d74fb4557e71992db3516b5ba750d57cb9f3521\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T09:50:34Z",
          "mergedAt": "2026-07-30T09:54:38Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 25,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/25",
          "title": "feat(site): publish Machine Life brand reader bundle",
          "body": "## Summary\n\n- publish a deterministic `site/brand-site.json` consumer bundle for `kungfu.tech`\n- preserve `papers.libkungfu.dev` as the publication evidence and immutable archive authority\n- expose all eleven paper sections with source paths, claim boundaries, and a drift-checking generator\n- prepare immutable publication version `0.1.0-alpha.3`\n\n## Validation\n\n- `make check`\n- `git diff --check`\n- generated bundle/source-order comparison\n- public-surface maintenance and private-path scan\n\n## Release impact\n\nAdditive publication surface for a new site consumer; no paper thesis, PDF argument, archive route, or existing evidence contract is removed.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T09:54:06Z",
          "mergedAt": "2026-07-30T09:55:32Z",
          "additions": 568,
          "deletions": 6,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 27,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/27",
          "title": "chore(release): bind alpha.3 promotion identity",
          "body": "## Summary\n\nCreate the reviewed no-content promotion identity for `v0.1.0-alpha.3`.\n\nThe protected alpha branch requires its final development push to be approved by a different account. This empty commit preserves the exact alpha.3 source tree while allowing the established developer/reviewer split to satisfy `require_last_push_approval`.\n\n## Validation\n\n- tree is byte-identical to the current `dev/v0/v0.1` head\n- implementation PR #25 remains the content authority\n- alpha promotion PR #26 remains the release authority",
          "author": "dongkeren",
          "createdAt": "2026-07-30T09:58:34Z",
          "mergedAt": "2026-07-30T10:00:09Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 332,
          "url": "https://github.com/kungfu-systems/build-images/pull/332",
          "title": "fix(demo-renderer): align qualified autoplay sentinel",
          "body": "## Summary\n\n- accept only the canonical `qualified` Agent Work Lab autoplay completion sentinel\n- update the retained capture fixture to the canonical status\n- reject the legacy `passed` sentinel in the container smoke suite\n\n## Verification\n\n- `git diff --check`\n- `node --check images/demo-renderer/render-demo.mjs`\n- `bash -n images/demo-renderer/tests/smoke.sh`\n- `pnpm run check` (114 qualification tests plus repository/KFD/workflow gates)\n- exact consumer Gate passed and selective render reproduced the stale renderer check in Kungfu run 30525890727\n\nCloses #331",
          "author": "dongkeren",
          "createdAt": "2026-07-30T09:57:32Z",
          "mergedAt": "2026-07-30T10:01:15Z",
          "additions": 22,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 333,
          "url": "https://github.com/kungfu-systems/build-images/pull/333",
          "title": "chore(release): promote qualified demo renderer alpha",
          "body": "Promote the current verified `dev/v1/v1.3` image family through the governed Buildchain Alpha publication transaction.\n\nThis cut contains only the reviewed demo-renderer sentinel correction from PR #332 relative to the current Alpha material: canonical `qualified` is accepted, legacy `passed` is rejected, and terminal identity/metadata remains non-authoritative. Buildchain remains responsible for exact version selection, selective OCI publication, anonymous digest verification, and Release Passport evidence.\n\nConsumer evidence: Kungfu run 30525890727 passed the exact Gate and reproduced the stale renderer boundary before this correction.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:01:47Z",
          "mergedAt": "2026-07-30T10:05:20Z",
          "additions": 22,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 29,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/29",
          "title": "chore(release): bind alpha.3 pusher identity",
          "body": "Identity-only release governance change. No publication content changes. This makes the protected alpha promotion last-pusher approval requirement satisfiable without bypassing branch protection.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:05:10Z",
          "mergedAt": "2026-07-30T10:06:22Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 30,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/30",
          "title": "chore(release): finalize alpha.3 identity binding",
          "body": "Final identity-only governance change. No publication content changes. Pushed by dongkeren; it will be independently reviewed by kungfu-origin and merged by dongkeren so protected alpha promotion can satisfy last-pusher approval without bypass.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:08:06Z",
          "mergedAt": "2026-07-30T10:09:16Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2067,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2067",
          "title": "fix(release): bind qualification to alpha evidence",
          "body": "## Summary\n\n- bind automatic stable-candidate qualification to the exact `v3-alpha` SHA proven by the triggering self-dogfood artifact\n- reject missing, failed, wrong-ref, or SHA-divergent self-dogfood evidence\n- keep manual dispatch bound to its explicit immutable candidate SHA\n\n## Evidence\n\n- `node --test tests/stable-candidate-qualification.test.mjs tests/build-surface.test.mjs` (105 passed)\n- `pnpm run check` (985 tests passed; workflow, site, inventory, architecture, and 6 action bundle checks passed)\n- production failure reproduced in run 30533114922: the old workflow supplied dev SHA `04ca9f0d...` and returned `exact-alpha-release-not-found` while the job stayed green\n\n## Delivery context\n\nRoot fix for Assignment `2026-07-30-buildchain-v3-runtime-default-hardening` under parent `2026-07-30-buildchain-v3-zone-v2-elimination`.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:08:49Z",
          "mergedAt": "2026-07-30T10:12:57Z",
          "additions": 94,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 31,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/31",
          "title": "chore(release): bind alpha.3 API pusher identity",
          "body": "Identity-only governance commit with the same tree as dev. Created directly by the dongkeren GitHub API identity so protected alpha promotion can unambiguously satisfy last-pusher approval. No publication content changes.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:12:16Z",
          "mergedAt": "2026-07-30T10:13:37Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 26,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/26",
          "title": "chore(release): promote v0.1.0-alpha.3",
          "body": "## Release\n\nPromote the exact reviewed development head to the alpha channel as `0.1.0-alpha.3`.\n\n## Included\n\n- package-owned `kungfu.tech` Machine Life brand reader bundle\n- complete eleven-section deterministic reader projection\n- explicit future-facing and non-consciousness claim boundary\n- `papers.libkungfu.dev` retained as publication evidence and immutable archive authority\n\n## Evidence\n\n- implementation PR #25 approved, checked, and merged\n- `make check` passed\n- publication artifact build passed\n- `0.1.0-alpha.3` is not yet published\n\nMerging this protected promotion PR activates the existing Buildchain Trusted Publishing transaction.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T09:55:57Z",
          "mergedAt": "2026-07-30T10:17:50Z",
          "additions": 568,
          "deletions": 6,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2068,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2068",
          "title": "fix(release): keep qualification shell on dev",
          "body": "## Summary\n\n- execute the stable-candidate qualification controller from the current protected dev shell\n- keep the candidate identity independently pinned to the explicit alpha SHA or self-dogfood evidence\n- prevent manual qualification from checking out a prerelease tree that predates the qualification fix\n\n## Evidence\n\n- `node --test tests/stable-candidate-qualification.test.mjs tests/build-surface.test.mjs` (105 passed)\n- `pnpm run check:workflows`\n- production reproduction run 30533822239 proved the old checkout selected candidate `9d74fb4` and therefore executed the prerelease copy of the controller instead of protected dev `36fd5f2c`\n\nFollow-up root fix for Assignment `2026-07-30-buildchain-v3-runtime-default-hardening`.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:14:48Z",
          "mergedAt": "2026-07-30T10:17:55Z",
          "additions": 3,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1940,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1940",
          "title": "fix(xinfa): refresh release route authority",
          "body": "<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded Xinfa authority-root repair restores the already-declared Buildchain release route after its machine-proved probe revision changed; it does not change architecture, route selection policy, or release authority.\"\n}\n-->\n\n## Summary\n\n- refresh the declared `probe.kfd-evidence` revision used by the Buildchain release documentation route\n- regenerate the retained 31-case Xinfa context-quality qualification receipt\n- restore all three release scenarios to the exact `kungfu-buildchain-release-agent` route\n\n## Evidence\n\n- `./shifu xinfa:quality --write`\n- `./shifu xinfa:quality --check`\n- `node --test scripts/qualify-xinfa-context-quality.test.mjs`\n- full pre-commit staged gate, including 58 dev latency/cache tests, 131 documentation/promotion tests, Rust workspace tests, Xinfa WASM/native equivalence\n\nThe regression was observed on Alpha candidate PR #1937: the prior expected probe revision `0876e144...` no longer matched the actual machine-proved revision `349d6746...`, making the entire Buildchain release route stale and producing a 3/31 human-correction rate.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:04:20Z",
          "mergedAt": "2026-07-30T10:20:55Z",
          "additions": 94,
          "deletions": 94,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 32,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/32",
          "title": "Prepare v0.1.0-alpha.3",
          "body": "Create the generated version-state commit for v0.1.0-alpha.3.\n\nBuildchain generated this branch because protected branch dev/v0/v0.1 rejected direct generated bookkeeping. This manually opens the exact fallback PR that GitHub Actions was not permitted to create.\n\nRejected update: c3ca958f1407ff6bd5009236daefc30103499e73 -> 5ba911612144bccb010c5363b226bc4cda1388da.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:22:33Z",
          "mergedAt": "2026-07-30T10:23:45Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 334,
          "url": "https://github.com/kungfu-systems/build-images/pull/334",
          "title": "Prepare v1.3.0-alpha.18",
          "body": "Create the generated version-state commit for v1.3.0-alpha.18.\n\nBuildchain generated this PR because protected branch alpha/v1/v1.3 rejected direct generated bookkeeping.\n\nRejected update: 24aff5eb17a07ce13b1a3b518ee94557f7f94074 -> 8605faf2651252a427679757c5667de027481ace\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:24:03Z",
          "mergedAt": "2026-07-30T10:32:22Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/agent-hub-demo",
          "number": 63,
          "url": "https://github.com/kungfu-systems/agent-hub-demo/pull/63",
          "title": "fix(ci): pin Verify to reviewed Buildchain v3",
          "body": "## Summary\n- pass the exact reviewed Buildchain v3 runtime SHA to Verify\n- add a regression contract preventing a v2 runtime selection\n- preserve the existing Build and release expressions unchanged\n\n## Evidence\n- exact Buildchain v3 authority: `9d74fb4557e71992db3516b5ba750d57cb9f3521` (`v3.0.3-alpha.0`)\n- `npm run check`\n- 15 tests pass, Runtime 100 admits 100/100, standalone build succeeds\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:29:39Z",
          "mergedAt": "2026-07-30T10:32:49Z",
          "additions": 14,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2069,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2069",
          "title": "feat(runners): route offline native lanes to GitHub",
          "body": "## Summary\n- add an opt-in `self-hosted-offline-fallback` reusable-build setting\n- observe exact-label runner inventory only from the trusted workflow shell\n- route offline Kungfu Linux x64, macOS ARM64, and Windows x64 lanes independently to GitHub-hosted runners\n- keep online-but-busy lanes self-hosted and preserve the original matrix when inventory is unavailable\n- publish only de-identified routing evidence\n\n## Validation\n- `pnpm run check` (987 tests passed; workflow, site bundle, and action bundle checks passed)\n- `node --test tests/runner-offline-fallback.test.mjs` (4 passed)\n\n## Security boundary\nThe existing `BUILDCHAIN_PROMOTION_TOKEN` is projected only into code checked out at `buildchain-workflow-shell-sha`; consumer source and runtime overrides do not receive the token.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:38:59Z",
          "mergedAt": "2026-07-30T10:45:35Z",
          "additions": 466,
          "deletions": 56,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 33,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/33",
          "title": "fix(ci): pin Verify to reviewed Buildchain v3",
          "body": "## Summary\n- pass the exact reviewed Buildchain v3 runtime SHA to Verify\n- enforce the Verify pin while preserving the existing Build and Paper Release channel expressions\n- leave all paper source and publication behavior unchanged\n\n## Evidence\n- exact Buildchain v3 authority: `9d74fb4557e71992db3516b5ba750d57cb9f3521` (`v3.0.3-alpha.0`)\n- `make check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:46:32Z",
          "mergedAt": "2026-07-30T10:47:52Z",
          "additions": 4,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1944,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1944",
          "title": "feat(core): accelerate qualified cache cold path",
          "body": "## Summary\n\nReduce Qualified Core first-use latency with a replaceable office HTTP byte transport while preserving GitHub workflow discovery and all existing manifest, receipt, compatibility, and promotion authority checks. The reference Darwin arm64 evidence records a 4.31-second cold median and a 1.039-second retained-CAS maximum.\n\n## Related issue\n\n- Atlas goal `2026-07-30-kungfu-qualified-core-cold-path-performance`\n- Native Assignment `2026-07-30-kungfu-qualified-core-cold-path-performance`\n- Parent Initiative `2026-07-30-kungfu-qualified-core-developer-acceleration-family`\n\n## Changes\n\n- separate trusted GitHub artifact discovery from replaceable office HTTP and GitHub byte transport;\n- stream HTTP artifacts with exact-size bounds, identity-bound partial state, safe Range resume, and verified restart when Range is ignored;\n- remove completed transfer staging after successful verification or archive/verification rejection while retaining interrupted partial bytes only for exact identity-bound retry;\n- attribute discovery, transfer, verification, retention, and publication phases independently;\n- add a repeatable three-cold/three-retained-CAS benchmark and current Darwin arm64 evidence;\n- document the transport-only authority boundary and source-build fallback.\n\n## Verification\n\n- `./shifu check:source` — pass; 796 tests, 786 pass, 10 expected platform skips, 0 failures, plus TypeScript and Biome gates\n- `node --test scripts/qualified-assignment-core-artifact.test.mjs scripts/check-shifu-cache-contract.test.mjs` — 63/63 pass\n- `node scripts/code-complexity-budget.mjs --json` — pass\n- pre-commit staged gate — pass\n- benchmark evidence root `sha256:362737f6ca7617ef89b7d163d2e1855ff1bc6f8af071ef8226bd3c4cbc941057`\n- native Assignment phase `stage-ready`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Add bounded replaceable cold-path transport and phase-attributed benchmark evidence without widening Qualified Assignment Core artifact authority.\",\n  \"verification\": [\"full Shifu source acceptance\", \"63 Qualified Core cache contract tests\", \"complexity budget\", \"Darwin arm64 cold-path evidence\", \"independent protected review\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe office endpoint supplies bytes only after GitHub has established the unique protected workflow artifact identity. No endpoint, URL, credential, or private response body is retained in evidence. Every candidate still passes the existing manifest, receipt, payload, compatibility, and promotion verification before publication.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for transport, resume, phase attribution, and benchmark behavior\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LXF1YWxpZmllZC1jb3JlLWRldmVsb3Blci1hY2NlbGVyYXRpb24tZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtY29sZC1wYXRoLXBlcmZvcm1hbmNlIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiIwMzllM2I1OWZkN2QzOGQ1ZjM1OTY0Y2M1NGQ1ZmU1MDYxNGQzNGE2IiwicHVsbFJlcXVlc3RIZWFkIjoiZGEwMjJmMDA1ODc5OGU2NTQyMzE1NWQ3MTVjZTc4MzgwMTZmOWQxYiIsInJlcGxheWVkQ2FuZGlkYXRlIjoiNTVlYzIzNTc1OWIzYjY3OGIwZjQzYzBjNTM0YTdmMzFiN2RiNDBjNSIsInJlcGxheWVkVHJlZSI6IjRjODQ1MzBlMjZhNjlkZTRmZjhkM2VhMjYzNzFlNmNiMDVmZGRmZTciLCJxdWV1ZUF0dGVtcHQiOiJkYTAyMmYwMDU4Nzk4ZTY1NDIzMTU1ZDcxNWNlNzgzODAxNmY5ZDFiQDAzOWUzYjU5ZmQ3ZDM4ZDVmMzU5NjRjYzU0ZDVmZTUwNjE0ZDM0YTYiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6MTIxZjY0ODgzZGQ5NjMxNmE4OTdjMjY5MTNiNDA0ZDIwYWQ3YjhkMWUxOGMzYTUyMGE4NTM0YjRhODI4OGY0YiIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjEyMWY2NDg4M2RkOTYzMTZhODk3YzI2OTEzYjQwNGQyMGFkN2I4ZDFlMThjM2E1MjBhODUzNGI0YTgyODhmNGIiLCJzaGEyNTY6ZmZkODFjNzlkMGYxZDUzNGRjMmE5ZmY1MzA1YmU3MmU2YzljNWEyNDU2NTdlOTc4ZDk4YzVmNjVhZWNlN2MzNyJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzk2ZDNiZmY1NzFiMDRiYjIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6MWU1NTk3MmQyNTFjNTBlMTdhNThmN2U5Zjc2NWUwMDk2Y2NkMjkxNGU2ZTE1NjJiNGEyMzg1MTBmZmIyZDZjOSJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:35:53Z",
          "mergedAt": "2026-07-30T10:49:10Z",
          "additions": 1010,
          "deletions": 29,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 191,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/191",
          "title": "feat(papers): add local Machine Life reader",
          "body": "## Summary\n\n- pin `@kungfu-tech/paper-kfd-machine-life-roadmap@0.1.0-alpha.3`\n- render Machine Life on `kungfu.tech` with the same package-owned reader model as the White Paper\n- publish the local PDF, manifest, and agent entrypoint while preserving `papers.libkungfu.dev` as the evidence/archive surface\n- add gates for exact package version, local routes, all eleven sections, source PDF digest, evidence link, and shared layout\n\n## Validation\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- local HTTP checks returned 200 for the paper index, both readers, Machine Life PDF, manifest, and llms entrypoint\n\nThis PR is intentionally left open for Buildchain preview review; it does not request production publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:29:57Z",
          "mergedAt": "2026-07-30T10:52:26Z",
          "additions": 195,
          "deletions": 71,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2071,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2071",
          "title": "chore(signing): promote native runner offline fallback",
          "body": "## Summary\n\nPromote the current v3 development line into the artifact-signing authority through the release-line mandated `dev/v3/v3.0` route.\n\nThe promoted delta includes the independently routed native self-hosted offline fallback from #2069:\n\n- Linux x64 offline -> `ubuntu-24.04`\n- macOS arm64 offline -> `macos-15`\n- Windows x64 offline -> `windows-2022`\n- online-but-busy self-hosted runners remain preferred\n- runner-inventory API failure preserves the original self-hosted matrix\n\nThe authority candidate was also verified locally from exact authority base `bb55d20799d23c78b61a8a46765b2edd8c192aa9` with the fallback patch (`pnpm run check`: 984 tests passed), while the development merge was verified by the merge-group checks for #2069.\n\nSupersedes #2070, whose feature-branch head intentionally failed the authority release-line ref policy.\n\n## Source\n\n- development head: `53923edcff7bbadba9f2320f704ad1a36be7b33d`\n- fallback commit: `bf48d85d3ddb2121018947a16d3271d80525dde5`\n- authority base: `bb55d20799d23c78b61a8a46765b2edd8c192aa9`\n\n## Validation\n\n- #2069 merge-group Verify: passed\n- #2069 Governance audit: passed\n- authority-base candidate `pnpm run check`: 984/984 passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:52:41Z",
          "mergedAt": "2026-07-30T10:54:19Z",
          "additions": 1023,
          "deletions": 221,
          "changedFiles": 51
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 192,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/192",
          "title": "Release production from 90589c687ef9",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `90589c687ef9bc24f36fbc2980f2793b4175e5d7`\n- Artifact hash: `ecfe169fca97844be447e9e7255b69805e825b679b7af95b7667b5471dc92a9f`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30536359046)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-90589c687ef9`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-30T10:55:00Z",
          "mergedAt": "2026-07-30T10:57:53Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1947,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1947",
          "title": "fix(ci): retire Buildchain v2 AWS burst campaigns",
          "body": "## Summary\n\nRetire the two bounded AWS burst qualification campaigns because their runner contracts exist only on the historical Buildchain v2 train and are not supported by the reviewed Buildchain v3 authority.\n\nThe retained manual workflows now fail closed on a GitHub-hosted runner before any burst runner allocation or cloud work. Historical v2 runs remain immutable evidence, and reactivation requires a new protected Assignment plus an exact reviewed v3 implementation.\n\n## Related issue\n\nNative Assignment `2026-07-30-kungfu-aws-burst-buildchain-v3-cutover`.\n\n## Changes\n\n- replace the Linux CodeBuild and Windows EC2 JIT callers with least-privilege dispatchable tombstones\n- add a machine-readable retirement, history, safety, and reactivation contract\n- refresh workflow authority and publication-surface projections\n- replace runnable-v2 assertions with fail-closed retirement tests\n\n## Verification\n\n- `KUNGFU_DEV_BRANCH=origin/dev/v4/v4.0 ./shifu check:source`\n- staged pre-commit gate\n- `./shifu check:gate-catalog`\n- `git diff --check`\n- reviewed Buildchain v3 source `9d74fb4557e71992db3516b5ba750d57cb9f3521` exposes none of the retired AWS inputs or runner presets\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded CI retirement removes obsolete v2 execution authority without changing a product architecture contract.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: this PR removes AWS-capable jobs and their write permissions. It does not call or change AWS, IAM, runner registration, secrets, billing, quota, or infrastructure. No new campaign was dispatched.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTMwLWt1bmdmdS1hd3MtYnVyc3QtYnVpbGRjaGFpbi12My1jdXRvdmVyIiwiZGVsaXZlcnlDbGFzcyI6ImluaXRpYXRpdmUtY2hpbGQiLCJkZXZIZWFkIjoiZDNhN2Q2YmRjZjQyNDJjMTc3MWQ5YWQxMjljN2RlNmU4ZjBmMDZjZSIsInB1bGxSZXF1ZXN0SGVhZCI6IjZkYWJjYTVlN2Y5YmMyOGI4MTgwNDkzNjMxMGMxNjdmZTY0YjcyYjYiLCJyZXBsYXllZENhbmRpZGF0ZSI6Ijc2MDAyOWVlNTY2ZDk3YjhlZmZkMmVmZGU2ZWU4NmE0MjgwYjljMDAiLCJyZXBsYXllZFRyZWUiOiJjNjk2MWI2OTAwYWFmMWJhMjAzZGE3Zjg2MTEzOGI1YjgxNTAwNTJlIiwicXVldWVBdHRlbXB0IjoiNmRhYmNhNWU3ZjliYzI4YjgxODA0OTM2MzEwYzE2N2ZlNjRiNzJiNkBkM2E3ZDZiZGNmNDI0MmMxNzcxZDlhZDEyOWM3ZGU2ZThmMGYwNmNlIiwiYWRtaXNzaW9uUHJvb2ZSb290Ijoic2hhMjU2OmY3OTYwNmZjOWQyNTJjYjJmNWVmMmNlZTI5ZDljYTBjZWEwNzgxODlhYjUyMmQxYzE0NGJmM2Q5ZTU5ZDNjZWEiLCJhZG1pc3Npb25Qcm9vZlJvb3RzIjpbInNoYTI1Njo0MWU3MTgwNDU0ZWIxNDJiOWZjOWFjMGM2NzBlMTk3MjcwZDFiODVlMWE3YTZlYjkwMDAwYmUzODUyYzc2NjdjIiwic2hhMjU2OmY3OTYwNmZjOWQyNTJjYjJmNWVmMmNlZTI5ZDljYTBjZWEwNzgxODlhYjUyMmQxYzE0NGJmM2Q5ZTU5ZDNjZWEiXSwic3RhdHVzQ29udGV4dCI6IlF1ZXVlIGZhbWlseSBsZWFzZS9kOTlmM2E5MTY2NzM5ZTBkIiwibGVhc2VSb290Ijoic2hhMjU2OjZlNTFlNjk3NzJjNGVhZDMwN2JiOGNkODFlOTdlMWVmYzNmMmE2YjdiNWEwZGMyY2M0YjQ1NTY1OThkNDYyMTkifQ -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T11:09:41Z",
          "mergedAt": "2026-07-30T11:22:49Z",
          "additions": 158,
          "deletions": 370,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1948,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1948",
          "title": "fix(agent-patrol): classify invalid model JSON as advisory",
          "body": "## Summary\n\nClassify malformed model investigation JSON as model-tool-runtime advisory evidence, preserving deterministic runner gates.\n\n## Changes\n\n- attach an explicit model-tool-runtime category to invalid Agent A investigation JSON;\n- keep deterministic runner, scope, evidence, and verifier failures blocking;\n- add a regression test for the exact agent-121 failure path.\n\n## Verification\n\n- ./shifu test:agent-patrol — 40/40 pass\n- ./shifu check:source — pass\n- staged repository gate — pass\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded bug fix corrects failure classification without altering an architecture contract or widening Patrol authority.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change retains no raw model content and affects only bounded error classification.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation behavior is already covered by the Patrol contract and regression test\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LWFnZW50LXBhdHJvbC1jYXBhYmlsaXR5LW9ic2VydmF0aW9uLWNhZGVuY2UtaW5pdGlhdGl2ZSIsImFzc2lnbm1lbnRJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LWFnZW50LXBhdHJvbC1jYXBhYmlsaXR5LW9ic2VydmF0aW9uLWNhZGVuY2UiLCJkZWxpdmVyeUNsYXNzIjoibmF0aXZlLXByb29mLXJlcXVpcmVkIiwiZGV2SGVhZCI6ImIwY2NkY2YyNmVhZWM3OTkxZDhiODgxMjU4ZWExNDMyNjMzMjhkOTUiLCJwdWxsUmVxdWVzdEhlYWQiOiIyZTZjMzE0NDgwMDMwOTRiNmRiODk2YmM0NmFhZGYzMGZhZmZhNWFlIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiI2MTY3ZTc4ZWM5ZWJmYzMxMTY5ZDQ4ZjA4MTQwOTkyNDlhNmRiYTg4IiwicmVwbGF5ZWRUcmVlIjoiNDNmOTZlOGI3ZjExMmI3ODk4YjI3MDA5ZDBlODJlZWQyOTA2N2NlNCIsInF1ZXVlQXR0ZW1wdCI6IjJlNmMzMTQ0ODAwMzA5NGI2ZGI4OTZiYzQ2YWFkZjMwZmFmZmE1YWVAYjBjY2RjZjI2ZWFlYzc5OTFkOGI4ODEyNThlYTE0MzI2MzMyOGQ5NSIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjpjMDVlMjA3NWQ1M2MxNWYwZGI3OTViY2MyNjhmZmQ0ZDRhZTAwZWM2ODM3ZDkyZTk2NTJlMjY5ZTEwN2I0MGU0IiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6MmY4YTE0ZmEyZTAyMmVmZDUyNzhjNjFhMGM4OWE1ODFiYmJjOWU0MjFiODc1OTQ4M2Q2ZmE3MTQ1OWM2ODRmMCIsInNoYTI1NjpjMDVlMjA3NWQ1M2MxNWYwZGI3OTViY2MyNjhmZmQ0ZDRhZTAwZWM2ODM3ZDkyZTk2NTJlMjY5ZTEwN2I0MGU0Il0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvYjA2ZmI0MTE1ZmNkNDU5YSIsImxlYXNlUm9vdCI6InNoYTI1NjpiNWU0NWRiNmZlYjM2NThjODEzNDc1MWM5ZmExNmRkZGE3ZjcwMDQ2YjQ2M2ZmNjJmOWQzZTIwYjU4ZjQ4YWMzIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T11:29:56Z",
          "mergedAt": "2026-07-30T11:47:50Z",
          "additions": 26,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1941,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1941",
          "title": "feat(ci): route offline native self-hosted lanes to GitHub",
          "body": "## Summary\n\n- route each normal native self-hosted lane independently when its exact-label runner fleet is offline: `linux-x64` to `ubuntu-24.04`, `macos-arm64` to `macos-15`, and `windows-x64` to `windows-2022`\n- preserve self-hosted hot-cache priority whenever a matching runner is online, including when it is busy; inventory/API uncertainty fails closed to the original self-hosted queue\n- keep Linux ARM64 on its existing GitHub-hosted lane and preserve the specialized macOS 25-minute queue-aware overflow experiment for explicit self-hosted/GitHub-hosted candidates\n- consume the reviewed Buildchain authority cut `2522e79e4c00233a5d15f887360547ed1034c39e` from build and promotion workflows, with publication still owned by the existing caller authority\n- record the cross-repository implementation and authority promotions in Buildchain PRs #2069 and #2071\n\n## Verification\n\n- Buildchain dev: `pnpm run check` (987/987)\n- Buildchain authority candidate: `pnpm run check` (984/984)\n- Kungfu focused overflow/preflight tests (22/22)\n- Kungfu release/promotion/auditable/overflow suite (49/49)\n- `actionlint .github/workflows/build.yml .github/workflows/release-new-version.yml`\n- `./shifu check:source` (passed; source-acceptance 797 tests: 794 passed, 3 platform skips)\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"implemented\",\"adrs\":[\"KF-ADR-019f86da-4f90-7b6b-ae6d-76cea57487f2\"],\"summary\":\"Route every offline native self-hosted lane through the reviewed GitHub-hosted fallback while preserving online self-hosted priority and caller-owned publication\",\"verification\":[\"Buildchain runner routing contract tests\",\"alpha macOS overflow controller tests\",\"Alpha promotion preflight contract tests\",\"source acceptance\"]}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T10:09:22Z",
          "mergedAt": "2026-07-30T12:07:03Z",
          "additions": 558,
          "deletions": 46,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1952,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1952",
          "title": "fix(qualification): remove empty NSIS shells",
          "body": "## Summary\n\nTreat a Windows NSIS uninstall as complete only when all remaining install-root entries are empty directory shells, then remove those shells without ever deleting files or links. Recursively report bounded residual paths when a real artifact remains.\n\nThis preserves the zero-file uninstall invariant observed after the packaged GUI and Agent Session processes fully exited. It is independent of the retired AWS v2 caller and remains part of the cross-platform release qualification harness.\n\nSupersedes #1951 solely to restore the required contributor/reviewer identity split.\n\n## Verification\n\n- `node --test tests/qualification/layers/surfaces/installer.test.mjs` (9/9)\n- `biome check` on both changed files\n- full source acceptance reached 797 contract tests plus cold read-only bootstrap; after source-tool binding, all passed and the only final failure was a formatter delta corrected before commit\n- staged pre-commit gate passed\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This is a fail-closed qualification cleanup fix and does not change product architecture authority.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: qualification evidence only; no publication, deployment, cloud mutation, or credential path.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Tests cover empty shells and retained files",
          "author": "dongkeren",
          "createdAt": "2026-07-30T12:09:12Z",
          "mergedAt": "2026-07-30T12:30:49Z",
          "additions": 80,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2072,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2072",
          "title": "feat(runners): restore bounded AWS burst providers",
          "body": "## Summary\n\n- port the proven Linux CodeBuild and Windows EC2 one-job JIT providers from the retired v2 train into Buildchain v3\n- add a bounded macOS ARM64 one-host campaign preset with three sequential one-job JIT runs, a 24-hour minimum, and a 30-hour fail-closed ceiling\n- preserve the trust gate ahead of all dynamic cloud runner labels and bind every runner artifact to the exact resolved consumer source\n- add fail-closed cost, lifecycle, zero-residue, and secret-exclusion contracts plus generated public contract surfaces\n\n## Validation\n\n- `pnpm run check` (1020/1020 tests; workflow, site, inventory, architecture, and 6 action bundle checks passed)\n- focused AWS provider tests (28/28)\n- `bash -n infra/aws-us-elastic-runner-burst-plane/macos-jit-bootstrap.sh`\n- AWS CloudFormation `validate-template` passed for the Windows and macOS stacks\n- `git diff --check`\n\n## Provider and security boundary\n\nThis PR defines provider contracts and infrastructure templates only; it does not allocate a Mac host or mutate a deployed stack. JIT material is accepted only through card-scoped SSM SecureString paths, deleted immediately after read, and forbidden from user data, tags, logs, and artifacts. Signing, notarization, publication, static AWS, SSH, and long-lived GitHub credentials remain excluded.\n\nThe macOS cost envelope is one `mac2.metal` host at USD 0.6498/hour: USD 15.60 minimum commitment and USD 19.49 at the 30-hour fail-closed ceiling, below a dedicated USD 25 budget.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T12:15:54Z",
          "mergedAt": "2026-07-30T12:33:31Z",
          "additions": 4823,
          "deletions": 72,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 193,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/193",
          "title": "feat(site): publish auditable Agent Work Lab autoplay",
          "body": "## Summary\n\n- import the exact Kungfu Release Passport and all verified media members\n- update /how-tested/auditable-demo/ and the machine-readable public projection\n- keep first-party/System identity, KFD compliance, and Product System metadata explicitly non-authoritative\n- fix autoplay attribute detection so accessible command labels do not create false positives\n\n## Exact evidence\n\n- Kungfu source: b48d30166e26dfceb873d1057e1db3c3e00c3385\n- workflow run: 30536659808\n- Gate root: sha256:31a259eccd3a4f093eaad2be01bc6def399b1653a010a6949c0bf8fa903bd54b\n- media root: sha256:7fafb048c7133291602643beeb702bea58763863e533d696d6bc962f66e5981b\n- Passport root: sha256:0ff4cc1ef018544ad752eb08cf2fec205fe8d1bbedeb41b0111566732919b5e7\n\n## Verification\n\n- node --test scripts/import-auditable-demo.test.mjs\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n\nNo production deployment is performed by this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T12:56:07Z",
          "mergedAt": "2026-07-30T13:02:51Z",
          "additions": 928,
          "deletions": 782,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2073,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2073",
          "title": "feat(publication): verify reproducible paper artifacts",
          "body": "## Summary\n\n- add a public `publication-artifact reproducibility` CLI and Node API\n- build twice from independent clean clones with isolated caches and a digest-pinned, network-disabled LaTeX toolchain\n- compare exact PDF, normalized source archive, publication evidence, synthesized package files, and real npm tarball bytes\n- bind the qualifying receipt and npm integrity into the reusable publication workflow before admission\n- expose the new surface through generated Buildchain contracts and documentation\n\n## Verification\n\n- `node --test tests/publication-reproducibility.test.mjs tests/publication-artifact.test.mjs tests/build-surface.test.mjs` — 94 passed\n- `pnpm run test:unit` — 683 passed\n- Prettier, `git diff --check`, inventory, workflow, and generated site checks passed\n\nReal paper qualification against this exact Buildchain commit (`430368a617de04453605aea2eb551bd439088c0d`):\n\n- Machine Life: https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/actions/runs/30545204752\n- KFD Foundation: https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/actions/runs/30545208679\n- Observer-Declared Timelines: https://github.com/kungfu-systems/paper-observer-declared-timelines/actions/runs/30545211880\n\nAll three receipts are machine-verifiable and qualifying, with two identical output-set roots, normalized archives, identical PDF SHA-256, identical npm integrity/SHA-256, and no first difference.\n\nNo package publication, tag movement, or Alpha release is performed by this PR.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T13:06:00Z",
          "mergedAt": "2026-07-30T13:09:24Z",
          "additions": 1572,
          "deletions": 122,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1955,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1955",
          "title": "feat(demo): publish auditable Agent Work Lab autoplay",
          "body": "## Summary\n\n- execute the installed kungfu agent-work-lab autoplay command in a bounded PTY\n- gate the exact capture before selective immutable rendering\n- publish one Release Passport projection to the README without granting identity-derived authority\n\n## Verification\n\n- exact-source preflight run 30536447336\n- full Build run 30536659808\n- ./shifu test:auditable-demo\n- ./shifu check:gate-catalog\n- ./shifu check:release-publication-control-plane\n- ./shifu qualify:kfx-identity-neutral-terminal (sha256:2ea3c1e7e3008ae61f4addaf08c732188576dacb122f910e638b465e41982dd0)\n\nEvolution impact: none\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7b6b-ae6d-76cea57487f2\"],\n  \"summary\": \"Bind the auditable demo path to the existing Buildchain publication boundary and one exact Release Passport\",\n  \"verification\": [\n    \"exact-source preflight run 30536447336\",\n    \"full Build and Gate run 30536659808\",\n    \"identity-neutral terminal sha256:2ea3c1e7e3008ae61f4addaf08c732188576dacb122f910e638b465e41982dd0\"\n  ]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T12:59:42Z",
          "mergedAt": "2026-07-30T13:13:14Z",
          "additions": 540,
          "deletions": 99,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1954,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1954",
          "title": "feat(shifu): add qualified core producer matrix",
          "body": "## Summary\n\n- bind Qualified Core production to an exact four-row macOS/Linux/Windows platform matrix\n- seal and promote row-qualified immutable artifacts without cross-row substitution\n- publish one matrix index and retain fail-closed unsupported-host consumer outcomes\n- bind matrix, workflows, actions, schema, and runtime to the compatibility identity\n\n## Verification\n\n- `node --test scripts/qualified-assignment-core-artifact.test.mjs scripts/check-shifu-cache-contract.test.mjs` (64/64)\n- `node --test --test-name-pattern=\"declared discovery routes\" scripts/readonly-agent-bootstrap.test.mjs` (1/1; nested source acceptance)\n- staged repository gate via signed DCO commit\n- Biome, YAML parse, code complexity, Gate catalog, release publication control plane, and `git diff --check`\n\n## Assignment\n\n- `2026-07-30-kungfu-qualified-core-cross-platform-producer-matrix`\n- stage-ready before PR; completion remains gated on protected merge and exact proof roots\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Qualify the exact four-row producer matrix and fail-closed promotion boundary without widening consumer support\",\n  \"verification\": [\"64 Qualified Core contract tests\", \"cold read-only nested source acceptance\", \"project-cut queue admission\", \"protected four-platform merge-group workflow\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] none of the above\n\nThe change is limited to candidate and protected promotion evidence; it does not publish from untrusted PR authority or widen supported consumer hosts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LXF1YWxpZmllZC1jb3JlLWRldmVsb3Blci1hY2NlbGVyYXRpb24tZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtY3Jvc3MtcGxhdGZvcm0tcHJvZHVjZXItbWF0cml4IiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiIwNWM3ZjU4NzU5NzA1MjE4YmIyYmM4ZTk4Y2JmOGRhMTIyMGIyMjBiIiwicHVsbFJlcXVlc3RIZWFkIjoiMzA3NmE1NzQyYTE1MTY1NTYzZDNiMzhkOTNkMDJiYWE0Mjc0OTA2ZCIsInJlcGxheWVkQ2FuZGlkYXRlIjoiNjdlNTQ3YWQxNDMwMmRiMzg0NmUyNDJiODRhN2UxNTk0ZDBmMGQ3MCIsInJlcGxheWVkVHJlZSI6ImYyZGY2NjhjZWViYTNlY2QyMzkzNjQ4MjlhZGVlZTkxNmY1YTRjNGIiLCJxdWV1ZUF0dGVtcHQiOiIzMDc2YTU3NDJhMTUxNjU1NjNkM2IzOGQ5M2QwMmJhYTQyNzQ5MDZkQDA1YzdmNTg3NTk3MDUyMThiYjJiYzhlOThjYmY4ZGExMjIwYjIyMGIiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6NTMwODZhNTM4ZTIwODVlZWYxNmE4ODZhM2I4NjNlNjg4MDlhYmE3ZDA0ZTZlM2QxNmM1YmJlZTZlNjQyN2ZjZCIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjUzMDg2YTUzOGUyMDg1ZWVmMTZhODg2YTNiODYzZTY4ODA5YWJhN2QwNGU2ZTNkMTZjNWJiZWU2ZTY0MjdmY2QiLCJzaGEyNTY6OTU4NGYwOTVmZjEwM2RlY2M2Mjc4YThmYWJkMWI1NWRjZjlkZmE4YWI1NTJiYmQyNGYxMjc1ZmI0ZWZiNTBlNiJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzk2ZDNiZmY1NzFiMDRiYjIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6MDZhY2RmYWI0MTljYTEyMjc2YTIzOWE3NDgzNTVjOTNiZWFiZmVmZWQ1MTg2N2VmN2MyNzMxMzAyNTcxZDQ1MiJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T12:54:59Z",
          "mergedAt": "2026-07-30T13:36:33Z",
          "additions": 1535,
          "deletions": 289,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2074,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2074",
          "title": "feat(paper): seal resumable publication bytes",
          "body": "## Summary\n\n- preserve the first qualified npm tarball and bind it with release assets in a typed, content-addressed sealed bundle\n- persist exact binary bundle bytes to the durable release transaction before publish and restore/verify them on a fresh runner\n- publish the restored tarball without repacking, expose stable publication milestones, and resume settled Alpha GitHub Release completion\n- publish the new Node API and generated site contract metadata\n\n## Verification\n\n- `pnpm run check`\n- 688/688 unit tests passed\n- workflow validation and generated site strict readback passed\n- all four action bundles built successfully\n- targeted sealed-resume suite: 131/131 passed\n\n## Safety\n\n- no real npm package or GitHub Release was published\n- `.kungfu/workspace-identity.json` remains untracked and is not part of this PR\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T14:07:47Z",
          "mergedAt": "2026-07-30T14:11:50Z",
          "additions": 2018,
          "deletions": 364,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 335,
          "url": "https://github.com/kungfu-systems/build-images/pull/335",
          "title": "feat(demo-renderer): preserve ANSI terminal styles",
          "body": "## Outcome\n\nPreserve terminal color and cell styles when replaying qualified PTY captures, while keeping raw ANSI bytes out of DOM markup.\n\n## Contract\n\n- replay ANSI 16-color, xterm 256-color, RGB foreground/background, inverse, bold, dim, italic, underline, strikethrough, overline, and invisible state\n- bind the fixed ansi16-xterm256-rgb/v1 style model in the render manifest\n- bump the renderer contract to 1.2.0 and tighten capture line spacing for 36-row material\n- keep identity-neutral authority boundaries unchanged\n\n## Verification\n\n- node --check images/demo-renderer/render-demo.mjs\n- bash -n images/demo-renderer/tests/smoke.sh\n- python3 scripts/verify-image-manifests.py\n- git diff --check\n- exact @xterm/headless@5.5.0 type-surface audit\n- CI fixture renders twice byte-identically and asserts xterm-256 background plus RGB foreground pixels\n\nThe authoritative Linux/amd64 container build and deterministic media smoke remain required PR checks.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T14:08:36Z",
          "mergedAt": "2026-07-30T14:15:23Z",
          "additions": 165,
          "deletions": 17,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1957,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1957",
          "title": "ci: add rolling dev gate latency patrol",
          "body": "## Summary\n\n- monitor the latest 30 merged PRs across every protected admitted dev branch\n- classify required-gate, merge-queue delivery, evidence, and patrol-infrastructure anomalies independently\n- capture deduplicated native Dogfood Findings without admitting Issues or becoming a required gate\n\n## Validation\n\n- `./shifu test:dev-gate-latency-patrol`\n- staged source gate and DCO hook\n- exact Project Cut queue replay against the current dev base\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This CI observability patrol adds no architecture contract and remains diagnostic, read-only, and non-required.\"\n}\n-->\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTMwLWt1bmdmdS1kZXYtZ2F0ZS1sYXRlbmN5LXJvbGxpbmctbW9uaXRvciIsImRlbGl2ZXJ5Q2xhc3MiOiJjcm9zcy1yZXBvLW5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJkYWMwMTY3ZjhhZjRiMWQxODYyZGI5OGY0MmUyYTMxZjIzOGIwYzY5IiwicHVsbFJlcXVlc3RIZWFkIjoiYmY5NDFjMDZkNjU2MmJhZjQ3ODQ3ZjY0ZDdkMjMzNjJhNWU1YzViOSIsInJlcGxheWVkQ2FuZGlkYXRlIjoiYzE2NTBiZWU1MDE2ZTk2ZjA1YTMwZWEyZDQ0YzU0YjBhNGY2NGI5MCIsInJlcGxheWVkVHJlZSI6IjgxMzg3ZmRlMjZkZjRkMmQwMzdkYzhlOWZiNTg2ZDgwZjgzZjg4MmIiLCJxdWV1ZUF0dGVtcHQiOiJiZjk0MWMwNmQ2NTYyYmFmNDc4NDdmNjRkN2QyMzM2MmE1ZTVjNWI5QGRhYzAxNjdmOGFmNGIxZDE4NjJkYjk4ZjQyZTJhMzFmMjM4YjBjNjkiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6OTUzMTgwMTBjZDRmYjI2ODI1YjZjYTk2Nzk2NzkwOTVkNDgzYmZhZTY3ZjVkMDgxMWViMjM5MTc1YjczMTNkNiIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjQwNDI0Y2JmNmM1OGZhMTdmZDJlNjY4MGRiMGUxZjg0Y2UwZGViNmZlY2MwZjljNjIzNjUzYjc4MDc2MGYxN2MiLCJzaGEyNTY6OTUzMTgwMTBjZDRmYjI2ODI1YjZjYTk2Nzk2NzkwOTVkNDgzYmZhZTY3ZjVkMDgxMWViMjM5MTc1YjczMTNkNiJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6MjE5ZDJlZjYzNmNjYjg4YzIyOWVmYWQ5ZDJhZmIzN2JjNDNiMzM5MjdmODI3YzkxN2QzY2NkOGJlOGQxZWVjZCJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T14:13:15Z",
          "mergedAt": "2026-07-30T14:21:48Z",
          "additions": 1417,
          "deletions": 1696,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 336,
          "url": "https://github.com/kungfu-systems/build-images/pull/336",
          "title": "chore(release): promote ANSI-faithful demo renderer alpha",
          "body": "Promote the verified dev/v1/v1.3 image family through the governed Buildchain Alpha publication transaction.\n\nThis cut contains only the reviewed ANSI terminal-style replay from PR #335 relative to the current Alpha material: the renderer preserves ANSI 16-color, xterm 256-color, RGB foreground/background and bounded cell styles, binds style model ansi16-xterm256-rgb/v1, and keeps captured bytes and identity metadata non-authoritative.\n\nSource: dev/v1/v1.3@8258ec24fb397010dd472eb7e5f30587c14f1f2c\nRenderer qualification: run 30550811284\nBuildchain Verify: run 30550812518\n\nBuildchain remains responsible for exact version selection, selective OCI publication, anonymous digest verification, and Release Passport evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T14:19:22Z",
          "mergedAt": "2026-07-30T14:22:09Z",
          "additions": 165,
          "deletions": 17,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1958,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1958",
          "title": "docs(readme): lead with agent work continuity",
          "body": "## Summary\n\nMake Kungfu's first GitHub screen explain the user-visible continuity result before exposing its evidence and system architecture.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Lead the auditable demo with one Work continuing across two fresh Agent processes without copied chat.\n- Keep the exact artifact, Gate, hash, Release Passport, and non-claim boundary in a disclosure directly below the animation.\n- Reorder the README around preserved value, existing Agent compatibility, source evaluation, and optional system depth.\n- Update the demo block generator and tests so future evidence refreshes preserve the product-first presentation.\n\n## Verification\n\n- `./shifu test:auditable-demo`\n- `./shifu docs:check`\n- `./shifu docs:prose:required`\n- `./shifu exec node scripts/update-auditable-demo-readme.mjs --readme README.md --evidence docs/qualification/evidence/auditable-demo/0ff4cc1ef018544ad752eb08cf2fec205fe8d1bbedeb41b0111566732919b5e7/public-evidence.json --write false`\n- Repository pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This documentation presentation change preserves the existing Agent Work and auditable-demo architecture contracts, evidence bytes, qualification status, and non-claims.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\nThis change does not open, settle, supersede, or extend an Evolution Map stage. It only improves the first-contact projection of already retained evidence.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe README presentation changes, but the product name, artifact identity, retained evidence, hashes, provenance links, and explicit non-claims remain unchanged. Generator tests and documentation gates bind that boundary.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-30T14:13:25Z",
          "mergedAt": "2026-07-30T14:35:59Z",
          "additions": 134,
          "deletions": 108,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 337,
          "url": "https://github.com/kungfu-systems/build-images/pull/337",
          "title": "Prepare v1.3.0-alpha.19",
          "body": "Create the generated version-state commit for v1.3.0-alpha.19.\n\nBuildchain generated this PR because protected branch alpha/v1/v1.3 rejected direct generated bookkeeping.\n\nRejected update: f6bccf6ecb5753386a502a335748c6a0b1ecb7a9 -> 0dc471bfdec50e06afd12493a279d3c0056dae1f\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T14:36:32Z",
          "mergedAt": "2026-07-30T14:40:05Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1964,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1964",
          "title": "fix(ci): scope patrol runner context to capture step",
          "body": "## Summary\n\n- move `runner.temp` out of job-level `env` into the capture step where the runner context is available\n- add a regression contract that rejects job-level runner context\n- refresh workflow authority and publication roots\n\n## Validation\n\n- `/opt/homebrew/bin/actionlint -ignore SC2016 .github/workflows/dev-gate-latency-patrol.yml`\n- `./shifu test:dev-gate-latency-patrol`\n- staged source gate and exact Project Cut queue replay\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fixes GitHub Actions context scope for an existing diagnostic workflow and changes no architecture contract.\"\n}\n-->\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTMwLWt1bmdmdS1kZXYtZ2F0ZS1sYXRlbmN5LXJvbGxpbmctbW9uaXRvciIsImRlbGl2ZXJ5Q2xhc3MiOiJjcm9zcy1yZXBvLW5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJlOGNmZWU3M2QyNTY5ZWQ2MzIxYzc0MjJkYWU3MjAzOGJhMDI3NTk2IiwicHVsbFJlcXVlc3RIZWFkIjoiZDA1YzI1NjdhMTVjNWI0NzcyODM2ZDE0YzQwNDRkYTdmNDliYWY5MCIsInJlcGxheWVkQ2FuZGlkYXRlIjoiZjc5MGVjOGQzMDZmYWRlMThhNjEyYTc5ZTYxNzNkMTQ5MWMyZGI5NyIsInJlcGxheWVkVHJlZSI6ImM4MGQ0ZDJlODdmYmNkOWVkMjdiOWFhNmU5NDlkMWI1NjUzNzdlMmYiLCJxdWV1ZUF0dGVtcHQiOiJkMDVjMjU2N2ExNWM1YjQ3NzI4MzZkMTRjNDA0NGRhN2Y0OWJhZjkwQGU4Y2ZlZTczZDI1NjllZDYzMjFjNzQyMmRhZTcyMDM4YmEwMjc1OTYiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6ZTZhZjE1OWVhNGFkZWJjN2U3ZjI1ZTU5YWQ4MWEzMDViM2M4MjA1ZGI3Y2YyZDJmYjBjMGJlMTU0MzU4ZGQxZiIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjQwNDI0Y2JmNmM1OGZhMTdmZDJlNjY4MGRiMGUxZjg0Y2UwZGViNmZlY2MwZjljNjIzNjUzYjc4MDc2MGYxN2MiLCJzaGEyNTY6ZTZhZjE1OWVhNGFkZWJjN2U3ZjI1ZTU5YWQ4MWEzMDViM2M4MjA1ZGI3Y2YyZDJmYjBjMGJlMTU0MzU4ZGQxZiJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6MWI1OTJlZGI4M2Q1YzFjZTIyMzU2ZGU5NTZjMjYwZTQ2MzYxMTJjNjIyNWJiNjU5MmYxODYwZjU0MWM2NGNjOCJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T14:42:19Z",
          "mergedAt": "2026-07-30T14:52:12Z",
          "additions": 17,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1966,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1966",
          "title": "feat(work): add policy replay governance",
          "body": "## Summary\n\nLinear successor to #1962 after the protected exact-base gate observed that dev/v4/v4.0 advanced during its check window. Add deterministic, offline Work Design policy replay over an exact as-of cohort. One qualified sample permits advisory replay, while default-policy promotion fails closed below 30 qualified samples and all replay, candidate, and promotion artifacts remain non-authoritative.\n\n## Related issue\n\nNative Assignment: `2026-07-29-kungfu-work-design-policy-replay`\n\n## Changes\n\n- compare immutable active and candidate policy roots over an exact cohort and as-of boundary\n- root selection, advice, disposition, outcome, coverage, drift, regression, and rollback evidence\n- permit advisory-mode replay with one qualified sample but enforce a hard 30-sample default-promotion floor\n- independently verify report and promotion artifact structure, counters, rates, roots, and authority constraints\n- keep Assignment, Work Control, repositories, protected branches, and the active default policy outside artifact authority\n- require any activation to occur through a separate authorized native decision\n- exclude Open Card Integration\n\n## Verification\n\n- `./shifu check:work-design-policy-replay`\n- `./shifu test:work-design-policy-replay`\n- `./shifu test:work-history-selector`\n- `./shifu test:work-design-advisor`\n- `./shifu check:source`\n- `./shifu docs final-ready --since origin/dev/v4/v4.0 --budget 66560 --json`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"KF-ADR-019f86da-4f90-77d5-a9ce-e7c798e3a623\",\n    \"KF-ADR-019f9771-4c20-7e2c-8e7c-3f3cb3f1b9bd\"\n  ],\n  \"summary\": \"Add deterministic advisory-only Work Design policy replay with a hard 30-sample promotion floor and explicit non-authority semantics\",\n  \"verification\": [\n    \"./shifu test:work-design-policy-replay\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\nThis additive pre-release replay governance does not open, settle, supersede, or extend an Evolution Map Stage.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWdvLWZhbWlseS1jb250aW51b3VzLWRlbGl2ZXJ5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOS1rdW5nZnUtd29yay1kZXNpZ24tcG9saWN5LXJlcGxheSIsImRlbGl2ZXJ5Q2xhc3MiOiJuYXRpdmUtcHJvb2YtcmVxdWlyZWQiLCJkZXZIZWFkIjoiM2VkMTk4ZmY4MDhlMjQ4ODQ1ZGJhYWVmMWZmNzNjZGJiNjZkY2VhNiIsInB1bGxSZXF1ZXN0SGVhZCI6Ijk2N2Q1NDAyZjdlZTI2ZmM3YzI2MjgwMDA5NDIwODkyOTYwNTliODUiLCJyZXBsYXllZENhbmRpZGF0ZSI6IjU4Zjg4YjE4NDNhN2RiN2IwMmVhNjQ0M2UwZThhNWQyZmM3OTYxOTciLCJyZXBsYXllZFRyZWUiOiIyMjdmMjljNTJmZmEzYjkwMjFlODllMTFlZmM5ZDUyODg3MDg2ZWE2IiwicXVldWVBdHRlbXB0IjoiOTY3ZDU0MDJmN2VlMjZmYzdjMjYyODAwMDk0MjA4OTI5NjA1OWI4NUAzZWQxOThmZjgwOGUyNDg4NDVkYmFhZWYxZmY3M2NkYmI2NmRjZWE2IiwiYWRtaXNzaW9uUHJvb2ZSb290Ijoic2hhMjU2OjgyYjMwZmM4MmVmNDc4YjMyMzZlNmUwMmIyNjI1MDNhODNiYmQ2ZTUwZmFmNDQ1MDVkYTU3MWU0MzcyZDA3ZmUiLCJhZG1pc3Npb25Qcm9vZlJvb3RzIjpbInNoYTI1Njo4MmIzMGZjODJlZjQ3OGIzMjM2ZTZlMDJiMjYyNTAzYTgzYmJkNmU1MGZhZjQ0NTA1ZGE1NzFlNDM3MmQwN2ZlIiwic2hhMjU2OjkzYmI1MThhZWJjM2E4MjFhZDM1OGY4ZDIwNTg3ODk3NzI3ZDk3N2FiMjQyYzQ4MmU0MjNmMWM4ODc1ZjZiZjEiXSwic3RhdHVzQ29udGV4dCI6IlF1ZXVlIGZhbWlseSBsZWFzZS9lY2FjNjdiY2ViZmFlM2JmIiwibGVhc2VSb290Ijoic2hhMjU2OjBlYjVmOWZmNWY5Yzg1YjY0Y2U4YTI2YTc2MzQwYmUzN2Y3OTgyZDhlYTFiNTEzNGU3ODQ5N2VmNjMxMTkxNDcifQ -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T14:55:01Z",
          "mergedAt": "2026-07-30T15:06:25Z",
          "additions": 1886,
          "deletions": 10,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1963,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1963",
          "title": "fix(ci): select qualified core linux compiler",
          "body": "## Summary\n\n- select the repository-required GCC 14 toolchain for the Linux Qualified Core producer row\n- keep compiler selection row-local so macOS and Windows retain their native hosted toolchains\n- verify both compiler commands before producing an exact Linux candidate\n- refresh the governed workflow authority after the matrix definition changes\n\n## Verification\n\n- `node --test scripts/qualified-assignment-core-artifact.test.mjs` (27/27)\n- `node --test --test-name-pattern='workflows keep candidate' scripts/qualified-assignment-core-artifact.test.mjs` (1/1)\n- `actionlint .github/workflows/affected-native-pr.yml`\n- full staged repository gate (58 dev Gate tests, Gate catalog, invariant, documentation, Biome, KFD, and release checks)\n- `git diff --check`\n\n## Assignment\n\n- `2026-07-30-kungfu-qualified-core-cross-platform-producer-matrix`\n- follow-up to the protected real-runner observation from PR #1954\n- completion remains gated on the next protected merge-group run and exact per-row matrix status\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair the hosted Linux compiler selection and refresh derived workflow roots without changing the qualified artifact architecture contract\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] none of the above\n\nThe change only selects already-installed hosted-runner compiler commands and does not widen support claims or publish from untrusted PR authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LXF1YWxpZmllZC1jb3JlLWRldmVsb3Blci1hY2NlbGVyYXRpb24tZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtY3Jvc3MtcGxhdGZvcm0tcHJvZHVjZXItbWF0cml4IiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJkMTg0ZDliN2E2OWEwMTE4MDVkY2ExZTU0NzhiMzMzYTc2N2VmOWU5IiwicHVsbFJlcXVlc3RIZWFkIjoiMzAxNWU5OWFlYWE0MTBmODc4NDBmYmNkNGQ1MjQ1OWUxNjc0M2U3ZiIsInJlcGxheWVkQ2FuZGlkYXRlIjoiYjkzMjI1NzU1MDk5MTBlNTY4NzZkZDgwMzEyNmNkMDc2ZjAxYWZhMSIsInJlcGxheWVkVHJlZSI6IjAyZmRmZDk0YTRmM2MzNTI0YWIyNjE1NDVhZGM5ZWEzNjdlZGRjNDgiLCJxdWV1ZUF0dGVtcHQiOiIzMDE1ZTk5YWVhYTQxMGY4Nzg0MGZiY2Q0ZDUyNDU5ZTE2NzQzZTdmQGQxODRkOWI3YTY5YTAxMTgwNWRjYTFlNTQ3OGIzMzNhNzY3ZWY5ZTkiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6Y2RlYzY2Y2E4ZjY4OWFlMWMzYjU2ZDZhM2NjN2MwMGY3OWNiZGMzZmI3ODc2ZTRmNjZlY2NhMTI3N2JlMzQ5ZiIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2Ojk1ODRmMDk1ZmYxMDNkZWNjNjI3OGE4ZmFiZDFiNTVkY2Y5ZGZhOGFiNTUyYmJkMjRmMTI3NWZiNGVmYjUwZTYiLCJzaGEyNTY6Y2RlYzY2Y2E4ZjY4OWFlMWMzYjU2ZDZhM2NjN2MwMGY3OWNiZGMzZmI3ODc2ZTRmNjZlY2NhMTI3N2JlMzQ5ZiJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzk2ZDNiZmY1NzFiMDRiYjIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6MTIwMmUzZDY0Nzc3Yzg4MDIzZjA3ZWE2NzlhYTQ5ZjkyNjU0MjdlOGQxMTNjNDc2ZDQ3ZWIzZDEwNDJhY2ZmZiJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T14:38:15Z",
          "mergedAt": "2026-07-30T15:18:07Z",
          "additions": 27,
          "deletions": 7,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2075,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2075",
          "title": "feat(paper): add unified publication CLI",
          "body": "## Summary\n\n- add the unified buildchain paper scaffold, preflight, bootstrap npm, build, alpha, status, and resume command families\n- add typed Node API contracts, exact evidence states, no-overwrite scaffolding, and explicit external mutation gates\n- publish the CLI and Node API in generated registries and document operator ownership boundaries\n\n## Safety\n\n- all external mutations remain dry-run unless execute is explicit\n- npm bootstrap is restricted to the official registry and exact package confirmation\n- status never infers publication or visibility from earlier states\n- consumer workflows remain thin and protected release authority stays in Buildchain\n\n## Verification\n\n- pnpm run check\n- 693 tests passed\n- inventory, generated site, workflow checks, and all four Action builds passed\n- node --test tests/paper.test.mjs: 5 passed\n\n## Version impact\n\nMinor: additive public CLI and Node API surfaces; no existing command or contract is removed.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T15:06:57Z",
          "mergedAt": "2026-07-30T15:20:22Z",
          "additions": 4055,
          "deletions": 43,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2076,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2076",
          "title": "fix(patrol): enforce Alpha candidate single flight",
          "body": "## Summary\n\nMake the Dev-to-Alpha candidate patrol a single controller-owned flight with compare-and-swap transitions, durable supersession evidence, and exact-source pull-request reuse.\n\n## Changes\n\n- fence active/next transitions with the exact prior state root\n- retain durable supersede and rejection tombstones, including explicit reactivation authority\n- reuse one known pull request per exact source SHA and fail visibly on duplicate historical identities\n- preserve the last qualified next candidate when a newer observation is not qualified\n- serialize patrol triggers without cancelling the active controller\n\n## Verification\n\n- `node --test tests/dev-alpha-candidate-patrol.test.mjs` (25 passed)\n- `corepack pnpm run check` (1023 tests passed; workflow, generated projection, and action bundle gates passed)\n\nNo release, package publication, signing, notarization, or artifact upload is performed by this change.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T15:07:33Z",
          "mergedAt": "2026-07-30T15:22:01Z",
          "additions": 462,
          "deletions": 51,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1967,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1967",
          "title": "feat(qualification): reactivate AWS burst on Buildchain v3",
          "body": "## Summary\n\nReactivate the bounded AWS Linux CodeBuild and Windows EC2 one-job JIT qualification callers on reviewed Buildchain v3 commit `407445c43df4888bb4464e91aef0debdc62aa0e6`, with both the reusable workflow shell and runtime `buildchain-ref` pinned to the same immutable source.\n\nAdd the manual-only macOS EC2 Dedicated Host caller for two smoke slots and one full native slot, plus a source-bound macOS JIT runner profile probe. The change preserves the GitHub-hosted trust gate, exact label mapping, non-publication boundary, and Windows cancellation and timeout cleanup exercises.\n\nAlso canonicalize symlink targets before product staging containment checks so macOS `/var` and `/private/var` aliases cannot reject an internal absolute link; an escaping-link negative fixture remains fail closed.\n\n## Verification\n\n- `actionlint` on all three AWS workflows\n- `node --test scripts/buildchain-install.test.mjs scripts/run-release-qualification.test.mjs` (38/38)\n- `node --test product/scripts/dist.test.mjs` (30/30)\n- `pnpm --filter @kungfu-tech/spec run build && node --test framework/spec/index.test.js` (12/12)\n- workflow authority closed-world check\n- release publication control-plane check\n- full `./shifu check` passed\n- staged pre-commit gate passed\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This reactivates an already-admitted bounded qualification campaign on reviewed Buildchain v3 authority and fixes a platform path-normalization defect without changing product architecture authority.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: manual qualification callers and non-publication evidence only. This PR does not mutate AWS, IAM, secrets, budgets, runners, release channels, or deployment state.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Trust, exact pin, label, non-publication, cancellation, timeout, cleanup, and symlink escape contracts are covered by tests\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T15:00:28Z",
          "mergedAt": "2026-07-30T15:33:19Z",
          "additions": 539,
          "deletions": 88,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1970,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1970",
          "title": "fix(ci): make latency patrol executable and lightweight",
          "body": "## Summary\n\n- pass collector arguments through Shifu exactly once\n- use the existing latency-only collector mode so latest-30 monitoring skips large native artifact downloads while preserving native/non-native source attribution\n- classify latency-only windows without treating intentionally skipped cache artifacts as unknown attribution\n- build the native Dogfood runtime on agent-121 only when an anomaly requires capture\n\n## Validation\n\n- `./shifu test:dev-gate-latency-patrol` (15 passed)\n- `/opt/homebrew/bin/actionlint -ignore SC2016 .github/workflows/dev-gate-latency-patrol.yml`\n- `./shifu check:release-publication-control-plane`\n- staged source gate (73 latency-contract tests plus repository gates)\n- live latest-30 latency-only probe completed in 225 seconds and retained 30 required/delivery samples\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This repairs and bounds an existing non-required diagnostic patrol without changing product architecture or required gate authority.\"\n}\n-->\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTMwLWt1bmdmdS1kZXYtZ2F0ZS1sYXRlbmN5LXJvbGxpbmctbW9uaXRvciIsImRlbGl2ZXJ5Q2xhc3MiOiJjcm9zcy1yZXBvLW5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiIzNzc5ZTFjNjJkNzBmNjc1MWNhYjViMjQ1YmFhMjExNzQ4YjQyNWFhIiwicHVsbFJlcXVlc3RIZWFkIjoiYjg0MzZlMGY1OTgwYWRlOGQwYTM2ODI0MzdjMDVkMWU3MjY1MjM0YiIsInJlcGxheWVkQ2FuZGlkYXRlIjoiMmQ2ZTRlYmI1ZjgxZjliNzZkMmVkOTU4OTBkMjJmY2ExNWJlNGQ1YyIsInJlcGxheWVkVHJlZSI6IjI0OTMzN2RhMmNhMDI2ZmFjZTRhZjRkMDZkNzhkODUxN2M2YmUwOGYiLCJxdWV1ZUF0dGVtcHQiOiJiODQzNmUwZjU5ODBhZGU4ZDBhMzY4MjQzN2MwNWQxZTcyNjUyMzRiQDM3NzllMWM2MmQ3MGY2NzUxY2FiNWIyNDViYWEyMTE3NDhiNDI1YWEiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6ZmU5NzZlMDY4NmZmNzM4MTFlNDg0YzkzZTdjZmViNTFmNjUwMTczMzNhMTUzN2RmNzFlYzc3NTMyYjU4YjRmNSIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjQwNDI0Y2JmNmM1OGZhMTdmZDJlNjY4MGRiMGUxZjg0Y2UwZGViNmZlY2MwZjljNjIzNjUzYjc4MDc2MGYxN2MiLCJzaGEyNTY6ZmU5NzZlMDY4NmZmNzM4MTFlNDg0YzkzZTdjZmViNTFmNjUwMTczMzNhMTUzN2RmNzFlYzc3NTMyYjU4YjRmNSJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6YWEwZTg4MGY0YzBiOTU2MTg4ZmI1NGJhZjI5NTA5ZWM0M2I4NGNhYzhmOTBjMWI4NjZlOWU4YzJkNDdhM2ExNCJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T15:37:39Z",
          "mergedAt": "2026-07-30T15:46:14Z",
          "additions": 75,
          "deletions": 23,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1971,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1971",
          "title": "fix(runtime): isolate frozen supervisor process",
          "body": "<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded runtime bugfix detaches the already-declared long-lived supervisor from its parent PyInstaller instance; it does not change runtime architecture, process ownership, product authority, or release policy.\"\n}\n-->\n\n## Summary\n\n- reset PyInstaller state only when a frozen Kungfu runtime launches its long-lived supervisor\n- preserve ordinary Python, coordinator, worker, and non-frozen process behavior\n- prove the frozen launch boundary passes `PYINSTALLER_RESET_ENVIRONMENT=1` without mutating the source environment\n\n## Root cause\n\nAlpha Build run `30539085997` reproduced the Windows Product runtime smoke failure on attempts 3 and 4 after 72/72 build-chain verification passed. The frozen `kungfu.exe` launched the supervisor as an independent process, but PyInstaller continued to treat it as a child worker of the expiring parent application instance; the supervisor then stopped by signal before the coordinator became available.\n\n## Evidence\n\n- `PYTHONPATH=framework/core/src/python ./shifu exec uv run --project framework/core --frozen pytest -q framework/core/tests/python/test_runtime_service.py` — 37 passed\n- `./shifu check:source` — passed, including 798 passed / 10 conditional skips in the source-acceptance contract suite\n- `TMPDIR=/private/var/folders/lh/63dh4_t12tl7smhvvcr9wwlr0000gn/T ./shifu check` — passed\n- targeted macOS temp-path normalization fixture — passed\n\nThis PR intentionally leaves installed Product state untouched. The decisive qualification is the protected Windows Alpha Product runtime smoke after this exact head reaches the dev candidate pipeline.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T15:42:55Z",
          "mergedAt": "2026-07-30T16:01:53Z",
          "additions": 47,
          "deletions": 7,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1965,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1965",
          "title": "fix(demo): retain full-width ANSI autoplay",
          "body": "## Summary\n\nRetain the installed Kungfu Agent Work Lab autoplay at full-width and with its ANSI styling, then bind the auditable-demo Gate and Passport to the independently released ANSI-faithful renderer.\n\n## Related issue\n\n#1624\n\n## Changes\n\n- Capture the exact installed kungfu agent-work-lab autoplay command in a 150x36 PTY.\n- Remove NO_COLOR and set FORCE_COLOR=3 while retaining xterm-256color and truecolor declarations.\n- Pin demo-renderer v1.3.0-alpha.19 by immutable OCI digest in both the Gate and Passport.\n- Refresh the governed workflow-authority and release-publication source-root projections.\n- Document the frozen capture boundary.\n\n## Verification\n\n- ./shifu test:auditable-demo (34 passed after rebasing onto the latest dev/v4/v4.0).\n- ./shifu check:release-publication-control-plane passed with registry root sha256:6107dfccf9fc441764b44a4f45129797533d774a9ffc68142010078f510e0a3b.\n- Pre-commit staged gate passed for both signed-off commits, including documentation, workflow-authority, and release-publication checks.\n- Anonymous GHCR manifest verification matched sha256:06141e3d01a13e6d44766d3acc115ca07c58443f59840f313ecd938b2b0c138c.\n- Build Images v1.3.0-alpha.19 Release Passport and protected promotion runs completed successfully.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix changes only terminal capture dimensions, color environment, and the immutable demo renderer input; it does not alter a product architecture contract or grant authority.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change updates only evidence-generation inputs. The demo path retains read-only permissions and explicitly grants no publication or deployment authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T14:52:54Z",
          "mergedAt": "2026-07-30T16:13:38Z",
          "additions": 29,
          "deletions": 17,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2077,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2077",
          "title": "feat(paper): bind provisioning and trust authority",
          "body": "Bind paper repository callers, runtime, contract lock, npm trusted-publisher target, repository policy, and generated-write authority to one exact Buildchain coordinate. Add the thin Atlas provisioning adapter separately in Atlas.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T16:15:52Z",
          "mergedAt": "2026-07-30T16:17:17Z",
          "additions": 931,
          "deletions": 142,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1973,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1973",
          "title": "fix(ci): await qualified core producer completion",
          "body": "## Summary\n\n- select the repository-required GCC 14 toolchain for the Linux Qualified Core producer row\n- keep compiler selection row-local so macOS and Windows retain their native hosted toolchains\n- verify both compiler commands before producing an exact Linux candidate\n- refresh the governed workflow authority after the matrix definition changes\n\n## Verification\n\n- `node --test scripts/qualified-assignment-core-artifact.test.mjs` (27/27)\n- `node --test --test-name-pattern='workflows keep candidate' scripts/qualified-assignment-core-artifact.test.mjs` (1/1)\n- `actionlint .github/workflows/affected-native-pr.yml`\n- full staged repository gate (58 dev Gate tests, Gate catalog, invariant, documentation, Biome, KFD, and release checks)\n- `git diff --check`\n\n## Assignment\n\n- `2026-07-30-kungfu-qualified-core-cross-platform-producer-matrix`\n- follow-up to the protected real-runner observation from PR #1954\n- completion remains gated on the next protected merge-group run and exact per-row matrix status\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair the hosted Linux compiler selection and refresh derived workflow roots without changing the qualified artifact architecture contract\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] none of the above\n\nThe change only selects already-installed hosted-runner compiler commands and does not widen support claims or publish from untrusted PR authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LXF1YWxpZmllZC1jb3JlLWRldmVsb3Blci1hY2NlbGVyYXRpb24tZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtY3Jvc3MtcGxhdGZvcm0tcHJvZHVjZXItbWF0cml4IiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiIxMjdhNGJjMWYwNjE4MTczZGQ4MGNlMGNmZDdmNDNhMWRlMTc5ZWY4IiwicHVsbFJlcXVlc3RIZWFkIjoiZjk2OTM2NzVlZDI0NjlhNzI5N2YyOTM3MTk5ZDFlZmNmNzhkODNiYyIsInJlcGxheWVkQ2FuZGlkYXRlIjoiNDU4Yzc5MTk3NDhmNGY0YmU3YmU0MDgxNWQ1NTRjYjUxZjk3YmVjNCIsInJlcGxheWVkVHJlZSI6ImRiYTNmMTEyNmFjNzY1ZDZhNDk5NTc4YTQ4OTIxYTU1NjRhYmU0YjgiLCJxdWV1ZUF0dGVtcHQiOiJmOTY5MzY3NWVkMjQ2OWE3Mjk3ZjI5MzcxOTlkMWVmY2Y3OGQ4M2JjQDEyN2E0YmMxZjA2MTgxNzNkZDgwY2UwY2ZkN2Y0M2ExZGUxNzllZjgiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6ZDhhMTIyZTA1MjhhYmJkOGNhYzZmZjFlZWZmOGU1NzEwZWM4NWU3MGEyMGMxNzlkNmIwZGU2NDBjMTM2NjI1NyIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2Ojk1ODRmMDk1ZmYxMDNkZWNjNjI3OGE4ZmFiZDFiNTVkY2Y5ZGZhOGFiNTUyYmJkMjRmMTI3NWZiNGVmYjUwZTYiLCJzaGEyNTY6ZDhhMTIyZTA1MjhhYmJkOGNhYzZmZjFlZWZmOGU1NzEwZWM4NWU3MGEyMGMxNzlkNmIwZGU2NDBjMTM2NjI1NyJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzk2ZDNiZmY1NzFiMDRiYjIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6ZDI0ZDFiYTUzYzAxZGU4MTgwMDIwZTNkYzlkYTU5YmI0NDQ0MDI5MWY3NDNmYzkzYzA0NTk3MjhiZGMwNWEzYiJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T16:15:49Z",
          "mergedAt": "2026-07-30T16:26:58Z",
          "additions": 9,
          "deletions": 6,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1972,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1972",
          "title": "fix(ci): bind Windows burst inputs through trust outputs",
          "body": "## Summary\n\nRepair the AWS Windows burst reusable-workflow caller after dispatch `30557755510` failed during workflow startup before any job or AWS resource existed.\n\nThe trusted Linux job now validates the manual inputs and projects one typed mode contract through job outputs. The Buildchain reusable caller consumes only `needs.trust.outputs`, including explicit `fromJSON` conversion for boolean and numeric inputs, instead of evaluating `inputs` expressions inside `jobs.<job_id>.with`.\n\n## Related issue\n\nFollow-up to #1967 and the bounded AWS burst qualification campaign.\n\n## Changes\n\n- Project exact runner, artifact, command, timeout, parallelism, and cache-profile values from the trust job.\n- Keep smoke and full qualification behavior, immutable Buildchain v3 pin, and non-publication boundary unchanged.\n- Add regression assertions for the compiler-safe reusable-caller contract.\n- Refresh workflow authority and release publication roots.\n\n## Verification\n\n- `actionlint .github/workflows/aws-us-windows-burst-qualification.yml`\n- `./shifu check:release-publication-control-plane`\n- `./shifu check:source`: all directly related checks passed; 808/809 aggregate tests passed, with the sole unrelated local cold-read fixture failure reporting `pytest is not available on PATH`\n- staged pre-commit checks passed\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This repairs the expression transport for an already-admitted manual qualification workflow without changing product or release architecture authority.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: this PR only repairs a manual, exact-source, publish-none qualification caller. It does not allocate AWS resources, create credentials, or change release channels.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T15:53:53Z",
          "mergedAt": "2026-07-30T16:38:44Z",
          "additions": 75,
          "deletions": 16,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1975,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1975",
          "title": "fix(ci): checkout qualified core recovery target",
          "body": "## Summary\n\n- select the repository-required GCC 14 toolchain for the Linux Qualified Core producer row\n- keep compiler selection row-local so macOS and Windows retain their native hosted toolchains\n- verify both compiler commands before producing an exact Linux candidate\n- refresh the governed workflow authority after the matrix definition changes\n\n## Verification\n\n- `node --test scripts/qualified-assignment-core-artifact.test.mjs` (27/27)\n- `node --test --test-name-pattern='workflows keep candidate' scripts/qualified-assignment-core-artifact.test.mjs` (1/1)\n- `actionlint .github/workflows/affected-native-pr.yml`\n- full staged repository gate (58 dev Gate tests, Gate catalog, invariant, documentation, Biome, KFD, and release checks)\n- `git diff --check`\n\n## Assignment\n\n- `2026-07-30-kungfu-qualified-core-cross-platform-producer-matrix`\n- follow-up to the protected real-runner observation from PR #1954\n- completion remains gated on the next protected merge-group run and exact per-row matrix status\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair the hosted Linux compiler selection and refresh derived workflow roots without changing the qualified artifact architecture contract\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] none of the above\n\nThe change only selects already-installed hosted-runner compiler commands and does not widen support claims or publish from untrusted PR authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LXF1YWxpZmllZC1jb3JlLWRldmVsb3Blci1hY2NlbGVyYXRpb24tZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtY3Jvc3MtcGxhdGZvcm0tcHJvZHVjZXItbWF0cml4IiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiI1MDRlM2FiMjE1ZTAyMTRjYjRhZTJmMmUzZTY5NDQ0ODEyZTRhM2Q3IiwicHVsbFJlcXVlc3RIZWFkIjoiYWNmODA4OWU4NmM3OGM4MjAwNjA5YmE3MWFlYjcxZjFiMDdmNTA5MSIsInJlcGxheWVkQ2FuZGlkYXRlIjoiN2Y4NDk4MGJmZWU0NjE0YjcyNzYzYzA3NzhmZGZhOTg5MTlhMTRhOCIsInJlcGxheWVkVHJlZSI6IjQ2NDNkZDQ0MGMzYmU2YmJiZDM5YzZiNmU0NWJkOGE5NTMyMjFkZmMiLCJxdWV1ZUF0dGVtcHQiOiJhY2Y4MDg5ZTg2Yzc4YzgyMDA2MDliYTcxYWViNzFmMWIwN2Y1MDkxQDUwNGUzYWIyMTVlMDIxNGNiNGFlMmYyZTNlNjk0NDQ4MTJlNGEzZDciLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6Yjk2MGYzMzZjYWIxN2RhZWY3ZTQ1NTUzY2NmMmZmYmIxMGEzZGJhZDg0YjU3ZDA0MDYwMmQ1NjBiYzdkMGVjOSIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2Ojk1ODRmMDk1ZmYxMDNkZWNjNjI3OGE4ZmFiZDFiNTVkY2Y5ZGZhOGFiNTUyYmJkMjRmMTI3NWZiNGVmYjUwZTYiLCJzaGEyNTY6Yjk2MGYzMzZjYWIxN2RhZWY3ZTQ1NTUzY2NmMmZmYmIxMGEzZGJhZDg0YjU3ZDA0MDYwMmQ1NjBiYzdkMGVjOSJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzk2ZDNiZmY1NzFiMDRiYjIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6NTUwYTZjODQwMTIzMDA1ZDQ1OTFmMDZhN2FiZjg4YjNlOTUzYzhjYzdjMmM2NzA2NjcwM2E3NTczZjljNWVhMSJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T16:40:44Z",
          "mergedAt": "2026-07-30T17:00:16Z",
          "additions": 20,
          "deletions": 5,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2078,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2078",
          "title": "feat(propagation): add exact paper package fast path",
          "body": "## Summary\n\n- derive release-specific propagation keys and branches, with idempotent lock writes and exact receipts\n- let downstream consumers apply package/config pins through a bounded update command\n- add a qualified publication fast path that uploads one declared immutable prefix and bounded mutable files only\n- keep package publication, alpha completion, staging visibility, and production visibility as separate machine states\n\n## Verification\n\n- corepack pnpm run check (696 tests passed)\n- corepack pnpm run check:workflows\n- node --test tests/release-propagation.test.mjs tests/web-surface.test.mjs\n\n## Boundaries\n\n- no package publication or production deployment is performed by this change\n- malformed or absent qualification keeps the full web-surface deployment path\n- existing immutable objects are verified before and after no-overwrite upload",
          "author": "dongkeren",
          "createdAt": "2026-07-30T17:16:05Z",
          "mergedAt": "2026-07-30T17:21:49Z",
          "additions": 969,
          "deletions": 120,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1974,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1974",
          "title": "feat: integrate advisory work design into open-card capture",
          "body": "## Summary\n\nIntegrate verified Work History Selector and Work Design Advisor guidance into Atlas open-card capture without transferring final work-definition authority away from the human.\n\n## Related issue\n\nNone. Native Assignment: 2026-07-29-kungfu-work-design-open-card-integration.\n\n## Changes\n\n- Add a capture-only open-card preflight protocol that composes selector and advisor evidence.\n- Preserve exact advice roots and explicit accepted, adapted, overridden, or insufficient-history human dispositions.\n- Fail explicitly back to the existing manual capture path on unavailable, stale, timed-out, or root-mismatched advice.\n- Weld the protocol checks and fixtures into source acceptance.\n\n## Verification\n\n- ./shifu check:source\n- ./shifu test:shifu-kfd-readonly\n- ./shifu check:work-design-open-card\n- ./shifu test:work-design-open-card\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-77d5-a9ce-e7c798e3a623\"],\n  \"summary\": \"Add the bounded open-card advisory composition stage while preserving human authorization and capture-only authority.\",\n  \"verification\": [\"./shifu check:source\", \"./shifu test:shifu-kfd-readonly\", \"./shifu test:work-design-open-card\"]\n}\n-->\n\n## [Evolution Map](../docs/evolution/README.md) impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [ ] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWdvLWZhbWlseS1jb250aW51b3VzLWRlbGl2ZXJ5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0yOS1rdW5nZnUtd29yay1kZXNpZ24tb3Blbi1jYXJkLWludGVncmF0aW9uIiwiZGVsaXZlcnlDbGFzcyI6ImNyb3NzLXJlcG8tbmF0aXZlLXByb29mLXJlcXVpcmVkIiwiZGV2SGVhZCI6IjYyY2Q5ZTRhNTIzZTE3YjI0Y2UyZjU0NDMxZTIyNzQzNTA4NjNmYTAiLCJwdWxsUmVxdWVzdEhlYWQiOiJhOGM0ZTdjZmM1MmY1NjMzNmEzM2FjYjc5ODg3ZGUwYmRiMmY3ZTc4IiwicmVwbGF5ZWRDYW5kaWRhdGUiOiJhOTk0ZGExNGRhZTczYTdiYzcxOTY1MDcwZTI1ZjFmZDMxYjQwMDI4IiwicmVwbGF5ZWRUcmVlIjoiYjM0MzVlOWRlNDg2YTIzYTRlODk5YTIzNDk4ZTJjODhmNzM4OWMxNSIsInF1ZXVlQXR0ZW1wdCI6ImE4YzRlN2NmYzUyZjU2MzM2YTMzYWNiNzk4ODdkZTBiZGIyZjdlNzhANjJjZDllNGE1MjNlMTdiMjRjZTJmNTQ0MzFlMjI3NDM1MDg2M2ZhMCIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1Njo2N2Y2NGI0MjA4OGI5MTBiZGU5ZGYyOTNlMGQ0ZmIwOWU4YjI3ZTM3Zjg1YmIxZmY1NGZlZjE5YjA4MGQwN2Y4IiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6NGJiYzk0Njg4NDMzMWEwNzA1OWMyNmMzZmNiMzIwZTVjN2RhMDNmZDU5YzM4MGYzYjM0NTYxYTk0ZDNkMDQ4NyIsInNoYTI1Njo2N2Y2NGI0MjA4OGI5MTBiZGU5ZGYyOTNlMGQ0ZmIwOWU4YjI3ZTM3Zjg1YmIxZmY1NGZlZjE5YjA4MGQwN2Y4Il0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvZWNhYzY3YmNlYmZhZTNiZiIsImxlYXNlUm9vdCI6InNoYTI1NjpiZTU1MzVhOGFmOTRmYTA5N2RmOGFkZTRkOGQ0Yzg2MmM2ODg3NTkzNDJkNTc3YzczNjFkY2VlNGFmM2E4MTI2In0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T16:29:05Z",
          "mergedAt": "2026-07-30T17:25:01Z",
          "additions": 827,
          "deletions": 4,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1969,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1969",
          "title": "fix(runtime): detach Windows resident supervisor",
          "body": "<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bounded Windows resident-process repair restores the declared runtime lifecycle on the qualified product artifact; it does not change runtime architecture, public commands, or release authority.\"\n}\n-->\n\n## Summary\n\n- detach the Windows resident supervisor from kill-on-close parent jobs while retaining a controlled fallback for hosts that forbid breakaway\n- preserve the existing detached process group semantics on every Windows host\n- include bounded supervisor and coordinator log tails when product runtime qualification times out\n\n## Evidence\n\n- `PYTHONPATH=framework/core/src/python uv run --project framework/core --frozen pytest -q framework/core/tests/python/test_runtime_service.py` (37 passed)\n- `./shifu exec node --test framework/core/tests/qualification/runtime-activation/run.test.mjs` (16 passed)\n- Ruff format and lint passed\n- full staged pre-commit gate passed\n\nThis fixes the reproducible Windows product smoke failure seen after `runtime restart`: cold activation and warm reuse passed, then the replacement supervisor exited at the spawning command boundary.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T15:20:04Z",
          "mergedAt": "2026-07-30T17:38:55Z",
          "additions": 107,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 247,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/247",
          "title": "feat(papers): qualify package pin propagation",
          "body": "## Summary\n\n- consume exact paper release locks into package and publication-set pins\n- verify package integrity and package-local publication facts before enabling a Papers-only fast path\n- preserve the four already-published immutable HTML pages byte-for-byte from canonical snapshots\n- render future immutable version pages with a frozen v1 shell and bind every version index by SHA-256\n\n## Verification\n\n- corepack pnpm run build\n- corepack pnpm run check\n- all four historical version-page SHA-256 values match papers.libkungfu.dev\n\n## Boundaries\n\n- this pull request does not qualify as package-pin-only and therefore keeps the full Site deployment path\n- no package publication or production deployment is performed by the implementation\n- production approval remains owned by the existing reviewed release path",
          "author": "dongkeren",
          "createdAt": "2026-07-30T17:16:17Z",
          "mergedAt": "2026-07-30T17:45:09Z",
          "additions": 5632,
          "deletions": 28,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1968,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1968",
          "title": "fix(ci): serialize Alpha candidates and add fast sentinels",
          "body": "## Summary\n\nRestore one Alpha candidate flight across the Kungfu caller and Buildchain controller, and reject two recent known-invalid source classes before expensive four-platform qualification.\n\n## Changes\n\n- serialize Dev-to-Alpha patrol triggers without cancelling the active controller\n- serialize normal Alpha builds across pull-request numbers while preserving separate experiment identities\n- add bounded Windows and auditable-demo exact-source sentinels ahead of the expensive build\n- expose explicit tombstone reactivation only for an authorized manual create-PR request\n- pin the consumer to Buildchain remediation train commit `f6b0cddea283495414ac3481364c1c27ae5c6485` after protected Buildchain merge\n\n## Verification\n\n- `./shifu node --test scripts/alpha-promotion-preflight.test.mjs scripts/release-promotion-rehearsal.test.mjs`\n- `./shifu check:source` (790 passed, 10 explicitly skipped, 0 failed)\n- generated workflow-authority and publication-control-plane projections are current\n\nNo release, package publication, signing, notarization, or artifact upload is performed by this change.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix narrows CI scheduling and source rejection behavior without changing an accepted architecture contract.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects pre-publication CI evidence only. It adds no publication authority and preserves the existing single publisher boundary.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation projections updated for workflow behavior\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTMwLWt1bmdmdS1hbHBoYS1jYW5kaWRhdGUtc2luZ2xlLWZsaWdodC1yZW1lZGlhdGlvbiIsImRlbGl2ZXJ5Q2xhc3MiOiJuYXRpdmUtcHJvb2YtcmVxdWlyZWQiLCJkZXZIZWFkIjoiZDFmMWYzODI3NTNiOTYxODU0Y2ZjOWYxNmRhZjhhNzQ0MjhjYTdiOCIsInB1bGxSZXF1ZXN0SGVhZCI6IjRkYTA2ZjAxNmIzNTU1YzEyNzc4ZTMyNzk5NDdhOTVkZjdkODMxMzYiLCJyZXBsYXllZENhbmRpZGF0ZSI6IjIxMzE2NWIxMzgyM2RiNGE0MDcwNGMyM2YzMmJkZDI1NWM2YzdmZTAiLCJyZXBsYXllZFRyZWUiOiJjZWViODg4OGYxMjcyNTY2OWMxYjBlNzFhNTBmY2U1YjMyOGQ3NWNiIiwicXVldWVBdHRlbXB0IjoiNGRhMDZmMDE2YjM1NTVjMTI3NzhlMzI3OTk0N2E5NWRmN2Q4MzEzNkBkMWYxZjM4Mjc1M2I5NjE4NTRjZmM5ZjE2ZGFmOGE3NDQyOGNhN2I4IiwiYWRtaXNzaW9uUHJvb2ZSb290Ijoic2hhMjU2OmFlYTdlOTUzNjBkZmQ4NjhiZmZiYTljNjdlYTg3ZWEyNTkwYmRmMWFkMzMwNDlkMjgwYzZmNTk5ODJlNGZjYTYiLCJhZG1pc3Npb25Qcm9vZlJvb3RzIjpbInNoYTI1Njo0YTdjNzkzZjAzNGUyMTE1YWU2ZDdlODBlZmYxNmNmNmM5MjUxNWY4NDg4M2E3YmM5ZTA2OTQ0OTJlYzkxZThmIiwic2hhMjU2OmFlYTdlOTUzNjBkZmQ4NjhiZmZiYTljNjdlYTg3ZWEyNTkwYmRmMWFkMzMwNDlkMjgwYzZmNTk5ODJlNGZjYTYiXSwic3RhdHVzQ29udGV4dCI6IlF1ZXVlIGZhbWlseSBsZWFzZS9kOTlmM2E5MTY2NzM5ZTBkIiwibGVhc2VSb290Ijoic2hhMjU2OjcwODc4NmU0ZDFhNjc4MTg0NWQ3ZTI0NGQyNzA2MWVjOTRlYjkzOGFiODQ5NTUyZTRkNTFkZWU1Yzc4YWU4MTAifQ -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T15:07:49Z",
          "mergedAt": "2026-07-30T17:56:53Z",
          "additions": 324,
          "deletions": 20,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1977,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1977",
          "title": "fix(ci): restore static Windows burst caller jobs",
          "body": "## Summary\n\n- restore separate static smoke and full reusable-workflow jobs for the Windows JIT qualification caller\n- keep the immutable Buildchain v3 workflow and contract lock\n- retain trust validation and bounded cleanup exercises\n\n## Why\n\nThe dynamic caller and the trust-output repair both failed during workflow startup before any job could be created. The prior static two-job shape is proven by run 30533043881 to compile and reach the Windows runner. This patch restores that caller structure while retaining the current immutable Buildchain v3 revision.\n\n## Verification\n\n- actionlint\n- workflow authority refresh\n- release publication write-roots and control-plane check\n- directly related Buildchain install/AWS workflow contract tests\n- staged pre-commit gate\n- full local source check: 798 passed, 10 skipped; one environment-only failure because pytest is unavailable on this Mac PATH\n\n## Governance\n\n- [x] ADR-neutral CI bug fix\n- [x] No release publication or credential widening\n- [x] DCO signed-off commit\n- [x] Generated workflow authority and publication roots refreshed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Restore the previously proven static Windows JIT reusable-workflow caller shape without changing product architecture, support claims, or publication authority.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T16:50:08Z",
          "mergedAt": "2026-07-30T18:39:52Z",
          "additions": 75,
          "deletions": 77,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2079,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2079",
          "title": "feat(paper): qualify existing repository migration",
          "body": "## Summary\n\n- add a dry-run-first `buildchain paper migrate` path for existing governed paper repositories\n- limit writes to the exact Buildchain-owned lock, version pin, thin workflows, and provisioning authority\n- accept digest-pinned publication toolchains without requiring a duplicate lifecycle build command\n- publish the migration route through Buildchain public surface facts\n\n## Qualification\n\n- `corepack pnpm run check`\n- relevant paper, reproducibility, sealed-bundle, transaction, propagation, and immutable-site tests: 56/56\n- dry-run migration against three existing paper repositories, including Machine Life roadmap: 3/3 conflict-free, 0.281-0.356s each\n\n## Safety\n\n- no paper content or publication configuration is rewritten\n- no npm publish, GitHub Release, staging apply, or production apply was executed\n- each planned change exposes exact current and replacement SHA-256 digests\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T18:57:48Z",
          "mergedAt": "2026-07-30T19:00:22Z",
          "additions": 466,
          "deletions": 53,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1981,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1981",
          "title": "feat(shifu): activate Linux Qualified Core consumer",
          "body": "## Summary\n\n- activate automatic Qualified Core materialization for Linux x86_64 CPython 3.13 source worktrees\n- preserve the shared manifest, compatibility, qualification, promotion, and immutable CAS authority contracts\n- qualify a fresh remote bundle hit and a second fresh checkout local-CAS hit on the protected Linux runner\n- verify ELF payload identity, executable modes, receipt roots, and Work Control activation\n\n## Related issue\n\n- Native Assignment `2026-07-30-kungfu-qualified-core-linux-x86-64-consumer`\n- Parent Initiative `2026-07-30-kungfu-qualified-core-developer-acceleration-family`\n\n## Verification\n\n- `./shifu check:source` — pass; 810 tests, 800 pass, 10 expected platform skips, 0 failures, plus Python, TypeScript, desktop-update, and Biome gates\n- `node --test scripts/qualified-assignment-core-artifact.test.mjs` — 28/28 pass\n- pre-commit staged gate — pass\n- native Assignment phase `stage-ready`\n- protected post-push qualification owns the real Linux remote-hit and second-checkout local-CAS evidence\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Activate the governed Linux x86_64 Qualified Core consumer row while preserving exact artifact identity, qualification, promotion, and fallback authority.\",\n  \"verification\": [\"full Shifu source acceptance\", \"28 Qualified Core artifact contract tests\", \"protected Linux remote-hit and local-CAS qualification\", \"independent protected review\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] none of the above\n\nThe workflow uses only protected candidate and promotion artifacts. GitHub transport and local observations do not become qualification authority, and no installed product or global environment is mutated.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and governed workflow roots updated\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LXF1YWxpZmllZC1jb3JlLWRldmVsb3Blci1hY2NlbGVyYXRpb24tZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtbGludXgteDg2LTY0LWNvbnN1bWVyIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJhMmNhY2M5OWU4YmQ3OTJmZjkwNzFjMWEyMDljYjAwNTU3ZDNmMmI4IiwicHVsbFJlcXVlc3RIZWFkIjoiODk3MWE3NDc4NWYyOGQ1NWY4NDRhODQ2YTRiZDJjMWEyY2JmM2M3MyIsInJlcGxheWVkQ2FuZGlkYXRlIjoiYTQ1ZWNhOWNkNDhjYzExOGQyNWJhNWM3NTgxNzRmMjE2NTc3ODYzOSIsInJlcGxheWVkVHJlZSI6ImM0MmM1MTVmN2YzNTdiMjk2NWQxOGE0NWVmZGYxMGYzYzhhNDkwYzQiLCJxdWV1ZUF0dGVtcHQiOiI4OTcxYTc0Nzg1ZjI4ZDU1Zjg0NGE4NDZhNGJkMmMxYTJjYmYzYzczQGEyY2FjYzk5ZThiZDc5MmZmOTA3MWMxYTIwOWNiMDA1NTdkM2YyYjgiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6MWU2ZTk3MzVmM2EwMTdiYmEwYWY5ZDMyMzM2NWU2Mzk2YzEyMjIyYmFmNmMwZDE2NTI4ZmFmODM0MzE4N2I0NCIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjFlNmU5NzM1ZjNhMDE3YmJhMGFmOWQzMjMzNjVlNjM5NmMxMjIyMmJhZjZjMGQxNjUyOGZhZjgzNDMxODdiNDQiLCJzaGEyNTY6NmRhODE1OWQ1ZjMyMWFhMTlhOTE3NDI2ODU3YWUwZGY5OGEzOWE2NzdjNjA1MDZjNWIyMDY2NzQyYTkzZGFhMyJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzk2ZDNiZmY1NzFiMDRiYjIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6Y2M5NDk1ZmM4ZmY1ZDBjODU0M2U5MWYzZGE1OGFlYTRmMTkzZjUxOWNkNTFlZTYzYWQ2ZmFhNTljYTY2ODAwNiJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T18:43:15Z",
          "mergedAt": "2026-07-30T19:22:05Z",
          "additions": 178,
          "deletions": 21,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2080,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2080",
          "title": "feat(paper): qualify unified paper publication for v3",
          "body": "Port the unified Buildchain Paper surface to v3, preserve controller v1 compatibility, seal resumable publication bytes, add exact-package propagation, and close migration/qualification contracts. Local corepack pnpm run check: 1039 tests passed, 0 failed; 6 action bundles verified.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T19:30:45Z",
          "mergedAt": "2026-07-30T19:36:35Z",
          "additions": 9488,
          "deletions": 592,
          "changedFiles": 59
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1982,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1982",
          "title": "fix(ci): grant Windows burst reusable permissions",
          "body": "## Summary\n\n- grant the exact token permissions declared by the pinned Buildchain v3 reusable workflow\n- keep local trust and cleanup jobs restricted to contents read\n- add a regression assertion for the caller permission contract\n\n## Root cause\n\nRun 30571491548 resolved the pinned Buildchain workflow but failed at startup with zero jobs. The Buildchain v3 reusable workflow declares actions read, contents read, issues write, and id-token write; the Windows caller exposed only contents read. GitHub reusable workflows cannot elevate permissions beyond the caller. Branch compile probe 30572196733 creates the trust job after this patch.\n\n## Verification\n\n- actionlint .github/workflows/aws-us-windows-burst-qualification.yml\n- targeted AWS Windows workflow contract test\n- workflow authority refresh\n- release publication roots and control-plane check\n- full staged repository gate\n- live branch compile probe: 30572196733\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair the existing Windows burst reusable-workflow permission contract without changing product architecture, publication authority, or support claims.\"\n}\n-->\n\n## Governance risk check\n\n- [x] GitHub token permissions: exact called-workflow contract, with local jobs reduced to contents read\n- [ ] release publication or credential exposure\n- [ ] product architecture or support claim change\n\n## Checklist\n\n- [x] Commit signed off (DCO)\n- [x] Generated workflow authority and publication roots refreshed",
          "author": "dongkeren",
          "createdAt": "2026-07-30T18:51:34Z",
          "mergedAt": "2026-07-30T19:41:46Z",
          "additions": 57,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2081,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2081",
          "title": "fix(paper): bind alpha plans to remote refs",
          "body": "Prefer origin-tracking refs over stale local branches in paper Alpha plans, resolve exact source and target branch OIDs from GitHub before execute, and add a regression for stale local dev state. Local corepack pnpm run check: 1040 tests passed, 0 failed; 6 action bundles verified.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T20:06:43Z",
          "mergedAt": "2026-07-30T20:10:34Z",
          "additions": 145,
          "deletions": 12,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2082,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2082",
          "title": "Release v3.0.3 from qualified v3.0.3-alpha.0",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v3.0.3-alpha.0`\n- Candidate SHA: `9d74fb4557e71992db3516b5ba750d57cb9f3521`\n- Selection: `latest-qualified`\n- Ledger ref: `buildchain/candidate-ledger/v3/v3.0`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T20:12:43Z",
          "mergedAt": "2026-07-30T20:14:04Z",
          "additions": 4112,
          "deletions": 681,
          "changedFiles": 109
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 34,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/34",
          "title": "chore(paper): qualify Buildchain alpha.4 publication",
          "body": "Migrate the paper repository to the protected Buildchain v3 contract, bind the alpha.4 publication package, and add byte-identical two-build qualification evidence. Buildchain runtime: 60ac9ca28dc0cc7a06945b45b06f22507c510145. Local reproducibility receipt: sha256:0ee67983efeaa8d6cee1a7cbac9dfd875362c3e38c0f2c532bf62c75aa89b33e.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T20:16:59Z",
          "mergedAt": "2026-07-30T20:17:58Z",
          "additions": 107,
          "deletions": 43,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2083,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2083",
          "title": "fix(runners): expose PortableGit bash to Windows JIT",
          "body": "## Summary\n\n- expose PortableGit `bin` as well as `cmd` in the Windows EC2 JIT runner PATH\n- preserve `git` discovery while making Buildchain `shell: bash` steps executable\n- pin the bootstrap PATH contract in the Windows JIT test\n\n## Failure evidence\n\nKungfu exact-source Windows qualification run `30576011490` completed the native product build, then failed at `Seal declared artifact signing requests` with `bash: command not found`. The one-job runner terminated cleanly afterward; EC2, volume, SSM, and GitHub runner residue were all zero.\n\n## Verification\n\n- `node --test tests/aws-windows-jit.test.mjs` — 8/8 passed\n- `pnpm run check:workflows` — passed\n- `pnpm run check` — 1040/1040 unit tests passed; action bundle integrity passed\n- `git diff --check` — passed\n\n## Risk\n\nThe change affects only the disposable Windows JIT bootstrap PATH. It adds the reviewed PortableGit Bash executable directory and introduces no credential, publication, or inbound network authority.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T20:35:13Z",
          "mergedAt": "2026-07-30T20:39:01Z",
          "additions": 2,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1985,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1985",
          "title": "fix(ci): pin repaired Windows burst runtime",
          "body": "## Summary\n\n- pin all three bounded AWS burst callers to reviewed Buildchain repair commit `376fb92fa014102366111b9aaef4856486c1e499`\n- record Buildchain PR #2083 as the Windows JIT runtime repair authority\n- refresh workflow authority and publication roots\n\n## Root cause and evidence\n\nExact-source Windows run `30576011490` completed the native product build, then failed at `Seal declared artifact signing requests` with `bash: command not found`. Buildchain PR #2083 adds PortableGit `bin` to the disposable Windows JIT PATH while preserving `cmd`; its merge commit is the exact runtime pinned here.\n\nThe failed one-job runner terminated cleanly: EC2 instance terminated, disposable volume deleted, SSM parameters zero, registered GitHub runners zero. Lifecycle and runner diagnostics were retained in the bounded evidence bucket.\n\n## Verification\n\n- repaired Buildchain commit contains the exact PortableGit PATH fix\n- actionlint on Linux, Windows, and macOS AWS burst callers\n- `node --test scripts/buildchain-install.test.mjs` — 11/11 passed\n- workflow authority closed-world check — passed\n- publication control-plane check — passed\n- full staged repository gate — passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Advance the existing bounded AWS burst callers to the reviewed Buildchain Windows bootstrap repair without changing product architecture, publication authority, or support claims.\"\n}\n-->\n\n## Governance risk check\n\n- [x] exact third-party reusable workflow SHA changes to an independently reviewed same-organization commit\n- [ ] release publication or credential exposure\n- [ ] product architecture or support claim change\n\n## Checklist\n\n- [x] Commit signed off (DCO)\n- [x] Generated workflow authority and publication roots refreshed",
          "author": "dongkeren",
          "createdAt": "2026-07-30T20:43:11Z",
          "mergedAt": "2026-07-30T20:52:04Z",
          "additions": 29,
          "deletions": 22,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1984,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1984",
          "title": "fix(shifu): activate Work from pinned uv cache",
          "body": "## Summary\n\n- resolve the repository-pinned uv binary from the native Shifu tool cache when uv is absent from PATH\n- activate Work immediately after a Qualified Core bundle is materialized in a fresh Linux checkout\n- reject unsafe pin segments, non-files, and non-executable cached tools without widening network or artifact authority\n\n## Related issue\n\n- Native Assignment `2026-07-30-kungfu-qualified-core-linux-x86-64-consumer`\n- Parent Initiative `2026-07-30-kungfu-qualified-core-developer-acceleration-family`\n\n## Verification\n\n- `node --test scripts/check-shifu-entry-contract.test.mjs scripts/qualified-assignment-core-artifact.test.mjs` — 51/51 pass\n- `node --test scripts/readonly-agent-bootstrap.test.mjs` — pass in the existing pinned Core test environment\n- Biome — pass\n- pre-commit staged gate — pass\n- protected post-push Linux qualification will prove the real remote-hit and second-checkout local-CAS Work activation\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Repair Linux Qualified Core Work activation by binding Shifu to the repository-pinned uv binary already provisioned in its native tool cache.\",\n  \"verification\": [\"51 focused Shifu and Qualified Core tests\", \"cold read-only source route fixture\", \"protected Linux remote-hit and local-CAS qualification\", \"independent protected review\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] none of the above\n\nThe repair consumes only an already provisioned repository-pinned uv binary. It does not add downloads, credentials, global configuration, or alternate qualification authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] ADR implementation evidence updated with this PR\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LXF1YWxpZmllZC1jb3JlLWRldmVsb3Blci1hY2NlbGVyYXRpb24tZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtbGludXgteDg2LTY0LWNvbnN1bWVyIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJjNjYxMGE5ZDQzZTkzMTYzODRhOTU4OTJmNTVhZWZlMjExODYwY2UxIiwicHVsbFJlcXVlc3RIZWFkIjoiNGFmMTMyZjA2NzQ4ZjAyZmJmMjJmYWViMDU4M2NhYTI4MjFkMzc4OSIsInJlcGxheWVkQ2FuZGlkYXRlIjoiNjM0MGQwZjQ1ZDI0MDA5YTcyNWNmZWFlYTkyOWU1NmY2ZDkzZDJiOCIsInJlcGxheWVkVHJlZSI6IjQxMWViYmQ0MDU0ZmUzOWZiY2E5M2JkNmJmNDllNTMzZTI5YmIwODMiLCJxdWV1ZUF0dGVtcHQiOiI0YWYxMzJmMDY3NDhmMDJmYmYyMmZhZWIwNTgzY2FhMjgyMWQzNzg5QGM2NjEwYTlkNDNlOTMxNjM4NGE5NTg5MmY1NWFlZmUyMTE4NjBjZTEiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6N2YzMDExOGE4ZWYyNzY1ZDQ5M2Y0NGE4MTk2M2FlMzM3MWRmYjYzNjcyNzhmODFlNDY5YzM4ZjNjYWVhYjYwOCIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjZkYTgxNTlkNWYzMjFhYTE5YTkxNzQyNjg1N2FlMGRmOThhMzlhNjc3YzYwNTA2YzViMjA2Njc0MmE5M2RhYTMiLCJzaGEyNTY6N2YzMDExOGE4ZWYyNzY1ZDQ5M2Y0NGE4MTk2M2FlMzM3MWRmYjYzNjcyNzhmODFlNDY5YzM4ZjNjYWVhYjYwOCJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlLzk2ZDNiZmY1NzFiMDRiYjIiLCJsZWFzZVJvb3QiOiJzaGEyNTY6OTExZThlYzgxZjJjNDE2MjI1MTY1NzhiNDM4ZDgxNWFhOGIzOTliYTkzODJhMTI3MjZjOGJhYTViYzExMWRlOCJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T20:41:07Z",
          "mergedAt": "2026-07-30T21:03:35Z",
          "additions": 204,
          "deletions": 5,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2084,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2084",
          "title": "fix(signing): derive app identity from sealed input",
          "body": "## Summary\n\n- derive the expected macOS application bundle identifier from the exact source- and tree-bound sealed credential input\n- remove the per-consumer `BUILDCHAIN_MACOS_EXPECTED_BUNDLE_ID` environment requirement\n- retain fail-closed repository, source, tree, archive digest, and bundle-identifier verification\n\n## Verification\n\n- `pnpm run check`\n- 989 unit tests passed\n- workflow validation and 6 action bundle integrity checks passed\n\n## Release evidence\n\nThis fixes the final credential-island failure observed after all four Kungfu Alpha product lanes, the generic CLI signing authority run, notarization, relay verification, and signed-artifact finalization had already succeeded.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T21:34:57Z",
          "mergedAt": "2026-07-30T21:43:53Z",
          "additions": 46,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2085,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2085",
          "title": "chore(signing): promote source-bound application identity",
          "body": "## Summary\n\nPromote the exact reviewed v3 development head into the protected artifact-signing authority.\n\nThe promoted delta makes macOS application signing zero-config for consumers: Buildchain resolves the expected bundle identifier from the sealed, source-bound application manifest and passes it to the credential-island action without a consumer repository variable. Arbitrary-binary signing remains unchanged.\n\n## Source\n\n- development head: `f12d5d707cecff24a32fac8d3c8c0c53167bc70d`\n- authority base: `2522e79e4c00233a5d15f887360547ed1034c39e`\n- implementation PR: #2084\n\n## Validation\n\n- #2084 hosted checks: passed\n- #2084 merge-group Verify: passed\n- #2084 merge-group Governance audit: passed\n- `pnpm run check`: 1040/1040 tests passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T21:44:51Z",
          "mergedAt": "2026-07-30T21:47:25Z",
          "additions": 14930,
          "deletions": 696,
          "changedFiles": 84
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2086,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2086",
          "title": "fix(signing): derive bundle identity in native action",
          "body": "## Summary\n\nMake `expected-bundle-id` optional in the native macOS credential-island action. For source-bound sealed application inputs, Buildchain now derives and validates the application identity from the sealed manifest. Generic artifact requests without an embedded application identity retain the explicit fail-closed input path.\n\nThis removes the final consumer repository variable from caller-owned credential-island jobs while preserving source, tree, archive, and application identity binding.\n\n## Validation\n\n- `pnpm run check`\n- 1041/1041 tests passed\n- action bundle integrity: 6/6 passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T21:54:05Z",
          "mergedAt": "2026-07-30T22:00:04Z",
          "additions": 127,
          "deletions": 81,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2087,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2087",
          "title": "chore(signing): promote native derived application identity",
          "body": "## Summary\n\nPromote the exact reviewed v3 development head into the protected artifact-signing authority.\n\nThe native macOS credential-island action now derives an omitted application bundle identifier from the source-bound sealed manifest. Caller-owned consumer jobs therefore require no product identity repository variable, while explicit identifiers remain supported as fail-closed consistency assertions.\n\n## Source\n\n- development head: `7fed4f952790a4474717a98bf6374db8d366faaa`\n- authority base: `bfa7e9add00f5db11344a0e9a62a6af4ba90e132`\n- implementation PR: #2086\n\n## Validation\n\n- #2086 hosted checks: passed\n- #2086 merge-group checks: passed\n- `pnpm run check`: 1041/1041 tests passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T22:00:28Z",
          "mergedAt": "2026-07-30T22:05:06Z",
          "additions": 127,
          "deletions": 81,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1989,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1989",
          "title": "fix(qualification): shorten Windows installer temp path",
          "body": "## Summary\n\n- run Windows surface installer qualification under the preserved short host temp\n- keep Linux and macOS temp routing unchanged\n- cover Windows host-temp selection and fallback behavior\n\n## Failure evidence\n\nAWS Windows qualification run 30581097394 built the product and reached the verify lifecycle, then NSIS uninstall left files under a 273-character path even though no process remained under the install root. The release driver already preserves RUNNER_TEMP as KUNGFU_QUALIFICATION_HOST_TEMP before redirecting general temp files into the checkout.\n\n## Verification\n\n- 14 focused surface installer tests passed\n- Biome check passed for both changed files\n- repository staged gate passed, including 73 merge/latency tests, 17 invariant tests, 436-document validation, and 132 documentation/promotion tests\n- DCO sign-off present\n\n## Boundary\n\nThis changes only the Windows qualification scratch location. Product installation paths and shipped installer behavior are unchanged.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fix Windows qualification scratch path without changing architecture or product contracts\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T22:17:58Z",
          "mergedAt": "2026-07-30T22:33:30Z",
          "additions": 44,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1988,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1988",
          "title": "fix(signing): consume source-bound native identity",
          "body": "## Summary\n\n- pin the formal protected Buildchain signing authority at `ea0d13ac2ccfbb3dc3a11a94e8eb83ab04b936b8`\n- remove the consumer-owned macOS bundle identifier input so Buildchain derives identity from the sealed source\n- refresh the release admission contract, workflow authority, publication roots, and semantic amplification evidence\n\n## Validation\n\n- `KUNGFU_DEV_BRANCH=origin/dev/v4/v4.0 ./shifu check:staged`\n- 47 targeted release/signing tests\n- release promotion rehearsal completed with no side effects\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Consume the existing Buildchain signing contract without changing a Kungfu architecture contract\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T22:17:36Z",
          "mergedAt": "2026-07-30T22:43:39Z",
          "additions": 39,
          "deletions": 35,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2090,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2090",
          "title": "feat(cache): add auditable sccache preparation",
          "body": "## Summary\n\n- add opt-in, platform-scoped sccache preparation between install and build\n- bind current-run stats to an exact source/runtime/profile preparation receipt\n- retain the receipt in diagnostics and reject cumulative sccache stats without it\n- expose the new inputs through the generated channel workflow and public contract\n\n## Validation\n\n- `pnpm run check`\n- 1,044 unit tests passed\n- action bundle integrity check passed (6 bundles)\n- targeted compiler-cache evidence tests passed\n\nGoal: `2026-07-31-kungfu-windows-alpha-build-performance`",
          "author": "dongkeren",
          "createdAt": "2026-07-30T23:27:29Z",
          "mergedAt": "2026-07-30T23:35:34Z",
          "additions": 871,
          "deletions": 108,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1994,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1994",
          "title": "docs(demo): publish qualified colored agent work replay",
          "body": "## Summary\n\nPublish the exact qualified full-width colored Agent Work Lab replay in the README without granting publication, deployment, or identity-derived authority.\n\n## Related issue\n\nPart of the KFX identity-neutral terminal qualification sequence.\n\n## Changes\n\n- materialize the content-addressed 1280x720 GIF from workflow run 30583219789\n- bind README copy to Gate, media, and Release Passport roots\n- retain explicit non-authority boundaries for identity, KFD, Product System metadata, package metadata, registry history, scans, and standalone generation\n\n## Verification\n\n- `./shifu test:auditable-demo` (34/34)\n- `./shifu check:release-publication-control-plane` (qualifying)\n- `./shifu docs:check` (132/132 negative and contract tests)\n- committed README media digest verified against public evidence\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This PR materializes already-qualified exact demo evidence and does not alter an architecture contract\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe exact Passport states `productionDeployment=false` and publication `github-artifacts-only`; this PR only projects its verified evidence into repository documentation.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-30T23:25:01Z",
          "mergedAt": "2026-07-30T23:43:49Z",
          "additions": 85,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 195,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/195",
          "title": "feat(demo): stage qualified colored agent work replay",
          "body": "## Summary\n\nStage the exact qualified full-width colored Kungfu Agent Work Lab replay on `/how-tested/auditable-demo/`. This updates only the site staging branch; it does not merge or approve the separate production release PR.\n\n## Changes\n\n- import the exact Release Passport and verified media from Kungfu workflow run 30583219789\n- retain the immutable content-addressed public evidence path rooted at `bca0cebc...88b8`\n- update the public auditable-demo projection and page links to the new Gate, media, source, and renderer coordinates\n- preserve the identity-neutral authority boundary and `productionDeployment=false`\n\n## Verification\n\n- `node scripts/import-auditable-demo.mjs --check`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- media types verified: GIF/MP4/WebM and 1280x720 poster\n\n## Deployment boundary\n\nThis PR targets `main` staging only. Production remains approval-gated through Buildchain and the existing production release PR is intentionally left open.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe exact Passport states `productionDeployment=false`; this PR only stages its verified public evidence.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-30T23:25:39Z",
          "mergedAt": "2026-07-30T23:45:34Z",
          "additions": 651,
          "deletions": 138,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1995,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1995",
          "title": "fix(qualification): retain failed suite diagnostics",
          "body": "## Summary\n\n- emit a bounded raw-log tail for every failed live Peer qualification suite\n- preserve the existing native campaign diagnostics\n- keep successful suite logs out of the console\n\n## Failure evidence\n\nAWS Windows qualification run 30587669164 failed `peer-lifecycle-control-plane`, but the controller log retained only the suite status because its raw pytest log lived on the terminated ephemeral instance. The missing tail prevented root-cause diagnosis even though infrastructure cleanup completed correctly.\n\n## Verification\n\n- 13 focused live Peer qualification harness tests passed\n- Biome check passed for both changed files\n- repository staged gate passed, including 73 merge/latency tests, 17 invariant tests, 436-document validation, and 132 documentation/promotion tests\n- DCO sign-off present\n\n## Boundary\n\nThis changes failure observability only. Passing qualification behavior, evidence bundles, and runtime semantics are unchanged.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Retain bounded failed-suite diagnostics without changing architecture or product contracts\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T23:36:08Z",
          "mergedAt": "2026-07-30T23:55:34Z",
          "additions": 11,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1998,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1998",
          "title": "perf(ci): add auditable Windows compiler cache",
          "body": "## Summary\n\n- install pinned sccache 0.16.0 on the Windows Alpha lane with archive and executable SHA256 verification\n- bind the local compiler cache through a public Shifu profile and retain tool/preparation evidence\n- expose same-source `sccache` / `off` workflow dispatch modes for cold/warm qualification\n- advance the coherent Buildchain Alpha authority to merged Buildchain PR #2090 (`472bc2efc987dd8baab310f0d510e2e165875b19`)\n\n## Verification\n\n- `./shifu check:source` exercised the complete repository source-acceptance chain; the final discovered formatting-only failure was corrected and its exact Biome gate passed\n- pre-commit staged gate passed, including 314/314 test manifest registration, 73 dev-latency tests, 17 invariant tests, docs, KFD, Gate catalog, and staged Biome\n- `actionlint .github/workflows/build.yml .github/workflows/release-new-version.yml`\n- sccache official release archive SHA256 `b8514ed7552e148b0a032114f745118dcb801791adafafeaf9935e4bfb0edf1b`\n- extracted `sccache.exe` SHA256 `9209ba7cc02278065b6795484228d8dda7125dd72f4a682a215fde0c195a4e0b`\n- publication control plane qualifying: 31 workflows, 10 surfaces, registry root `sha256:f76f480c4a29cf6967d45ff365ab3b0cf3f5fb760547bb3b9ab08b90d077e3f7`\n\n## Scope boundary\n\nLive Ubuntu mirror changes and DARKHERO Defender/power-plan A/B remain separate explicitly confirmed real-system operations after this code path merges.\n\nGoal: `2026-07-31-kungfu-windows-alpha-build-performance`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Windows Alpha compiler-cache qualification and workflow authority change without accepted ADR record changes\"\n}\n-->\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTMxLWt1bmdmdS13aW5kb3dzLWFscGhhLWJ1aWxkLXBlcmZvcm1hbmNlIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiIxYjc3ZGJlOGEwZTY2OWYzZWMwODZmNzZjNjNlYWMwN2VjNmUyYTBkIiwicHVsbFJlcXVlc3RIZWFkIjoiYTkyM2YzZjdjMDY1NDFlNzI5MzUxYzA2MmExZmViYTRmODhlY2Y0NiIsInJlcGxheWVkQ2FuZGlkYXRlIjoiNjUwNzRlNDdjYWVjMzFiMzVhYzhjNjE0MjZhMGY1ZDcyYTEzMGRjNSIsInJlcGxheWVkVHJlZSI6ImUxZTFlZGVjNDgwZmE5YjE5OTIwOWY1YWI4MWM1MjQ4NzhhOWUyN2UiLCJxdWV1ZUF0dGVtcHQiOiJhOTIzZjNmN2MwNjU0MWU3MjkzNTFjMDYyYTFmZWJhNGY4OGVjZjQ2QDFiNzdkYmU4YTBlNjY5ZjNlYzA4NmY3NmM2M2VhYzA3ZWM2ZTJhMGQiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6MDg4MzYxOWVlNzcyZjA0NmU1MzIyZDIyNTkzZWJiNWEzMjZkZDZhYjJmOGZiZTMzMmQ3OWMyMTYyYjNjNzBhOSIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjA4ODM2MTllZTc3MmYwNDZlNTMyMmQyMjU5M2ViYjVhMzI2ZGQ2YWIyZjhmYmUzMzJkNzljMjE2MmIzYzcwYTkiLCJzaGEyNTY6NDM2Yjg3YTYxZDQ4MjI3YWNjNjAzMjU4NzIyYjVlN2EwYTI1N2Q2Y2UxYzA1ODMwODczMzJkMDM0NWVlOTg2OSJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6YjhlODViZGNmMTViM2M2ZjRjYTAzZDk0YTYwYzA1MzEwNmQ5OTQ4NWRkMzQ0MWYyMjE1ZTY5ZWJkZThjNWVkMSJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T00:14:15Z",
          "mergedAt": "2026-07-31T00:54:45Z",
          "additions": 593,
          "deletions": 46,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2092,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2092",
          "title": "feat(demo): support bounded adapter arguments",
          "body": "## Summary\n\nAdd a bounded literal argv extension point for consumer-owned auditable-demo adapters. The accepted vector is parsed as JSON, cannot override Buildchain coordinate flags, is never evaluated by a shell, and is bound into the Gate receipt.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add the optional adapter-arguments-json reusable workflow input\n- validate and append at most 32 bounded literal arguments\n- retain the accepted vector and bind its content root into Gate evidence\n- document the authority boundary and refresh the generated site contract bundle\n\n## Verification\n\n- pnpm run check\n- git diff --check\n\nKFD-1 impact: additive reusable-workflow capability; backward compatible for existing callers.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change extends release-evidence adapter selection only. It grants no publication or runtime authority, reserves all source coordinate flags, and binds the exact argument vector into Gate evidence.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-31T00:59:30Z",
          "mergedAt": "2026-07-31T01:06:01Z",
          "additions": 114,
          "deletions": 23,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1999,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1999",
          "title": "fix(deprecation): enforce lifecycle classification integrity",
          "body": "## Summary\n\nEnforce deprecation class minima and classification provenance, and preserve the sole historical zero-window CLI settlement as an exact non-copyable grandfather.\n\n## Related issue\n\nAtlas Assignment 2026-07-29-kungfu-deprecation-minimum-window-and-classification-integrity\n\n## Changes\n\n- enforce calendar and qualified-release class minima with stable diagnostics\n- bind Core and CLI classification authorities and cross-check marker dialects\n- reject future dates, later product versions, invalid removal order, and unsupported protocol evidence\n- add positive and adversarial fixtures plus contributor and release documentation\n\n## Verification\n\n- `./shifu check:deprecation-lifecycle`\n- `./shifu check:source`\n- `./shifu adr:release:gate -- --contract-only`\n- `./shifu release:promotion:rehearse`\n- pre-commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019fad41-07fe-7f1e-a37a-a2572357700c\"],\n  \"summary\": \"Make deprecation minima, classification provenance, and the exact historical grandfather machine-enforced\",\n  \"verification\": [\"deprecation lifecycle fixtures\", \"source acceptance\", \"protected release gate\", \"promotion rehearsal\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes protected release admission only; source acceptance and promotion rehearsal exercise the same authority without publishing.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI5LWt1bmdmdS1kZXByZWNhdGlvbi1taW5pbXVtLXdpbmRvdy1hbmQtY2xhc3NpZmljYXRpb24taW50ZWdyaXR5IiwiZGVsaXZlcnlDbGFzcyI6ImNvbXBhdGliaWxpdHktcG9saWN5LWludGVncml0eSIsImRldkhlYWQiOiJlODg1M2UzYTM2NGY3ZDZmNzYyOTZkNTEzMzAwYzg2OTE5MTBiMWQxIiwicHVsbFJlcXVlc3RIZWFkIjoiNDg4NWQ3NTFkM2IwYzczZGJkODA1ZWZiZTQ3ZTQ4NmFkNDc3MDY5ZSIsInJlcGxheWVkQ2FuZGlkYXRlIjoiODQ2NDA4N2M1NTAzNTBlMmU0MjgwMGFmZmIzZWUxMzg4MTRjN2U2MCIsInJlcGxheWVkVHJlZSI6IjIyZWY3NzY0MDM2YWU1ODg5ZTQ0MTQ0M2M1ZDgxYjk0MGMzYzhiZjUiLCJxdWV1ZUF0dGVtcHQiOiI0ODg1ZDc1MWQzYjBjNzNkYmQ4MDVlZmJlNDdlNDg2YWQ0NzcwNjllQGU4ODUzZTNhMzY0ZjdkNmY3NjI5NmQ1MTMzMDBjODY5MTkxMGIxZDEiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6Yzc3NDFkMjkzMGY3MTJkY2I2ZWQyZGM5YWMxOTMxMjBlOWQ2NTc3NGY0Mzg2ZDQyZDkwZmQ3NjRmZjFlOTU2ZCIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjM1NzFkODQxMTEwMWZlMzM5MTU4MTQxMTM1NGE0ZjhlOTg1YTJiNTAxMmVkNzJkNzQ2ZjA1NDdhOTViODBiYjkiLCJzaGEyNTY6Yzc3NDFkMjkzMGY3MTJkY2I2ZWQyZGM5YWMxOTMxMjBlOWQ2NTc3NGY0Mzg2ZDQyZDkwZmQ3NjRmZjFlOTU2ZCJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6MTQzMGJmOTZjYTcyNTMzNDdmOTA4NzdiZmYwNWIxNzk0YjA1ZDQ3YTI0YjlkNjIwOTliODU2MzQ3MjBkYzFkNyJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T01:15:18Z",
          "mergedAt": "2026-07-31T01:23:38Z",
          "additions": 870,
          "deletions": 20,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2000,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2000",
          "title": "feat(maintainability): govern abstraction integrity",
          "body": "## Summary\n- extend the existing semantic-amplification projection with versioned abstraction-integrity topology governance\n- model legal runner, product, packaging, and durability variants without introducing a second business authority\n- add build-free findings, baseline ratchet, adversarial fixtures, query recovery, and product assembly lifecycle ownership\n- bind the delivery to the accepted maintainability-governance ADR and its deterministic navigation projections\n\n## Verification\n- exact-head ./shifu check:source\n- ./shifu node --test framework/maintainability/semantic-amplification.test.mjs product/scripts/dist.test.mjs\n- ./shifu maintainability:complexity\n- cold read-only bootstrap test\n- deterministic documentation gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f9f04-f8bd-7002-a702-1b9f66827ec0\"],\n  \"summary\": \"Complete build-free abstraction-integrity topology governance as an additive projection over existing authorities\",\n  \"verification\": [\"exact-head source acceptance\", \"cold read-only discovery\", \"adversarial topology fixtures\", \"complexity and weighted-debt ratchets\"]\n}\n-->\n\nAssignment: 2026-07-31-kungfu-abstraction-integrity-fragmentation-governance",
          "author": "dongkeren",
          "createdAt": "2026-07-31T01:33:53Z",
          "mergedAt": "2026-07-31T01:56:10Z",
          "additions": 2250,
          "deletions": 192,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1996,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1996",
          "title": "Promote qualified dev/v4/v4.0 candidate b2d71e03f13e to alpha/v4/v4.0",
          "body": "<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"alpha-settlement\",\n  \"progress\": [\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7008-b154-d488eb39d844\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-704e-9488-a793b1c4bf48\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7089-b9b1-e070edf7d540\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-709e-8116-1c8ddf385fdf\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-70b8-a4e7-fb053a54f164\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-70c5-b572-89ec183b37de\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-70f3-9a0e-d502826fbc81\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7105-b400-fa2be0ed2132\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-710c-a3b6-5e0cb5a28ad0\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7111-9165-691b834edbab\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-712d-b871-24090476e338\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-713b-a44c-0677d2446cc1\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-713d-8626-d70bca82cb76\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7153-a6c1-ab7a0a3cf481\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-716a-b49f-3ffe646d3c88\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7171-9dde-411f02f55950\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7178-b0b5-ff507589cc70\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7179-a900-c40bdb498910\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-719a-866a-28afd48c21dc\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-71ac-bb91-32456981141a\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-71be-a2aa-c8744fa340d8\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-71eb-81b1-f75c7382ba57\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-71eb-b4c0-376ca7bc7ad3\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7220-9a21-bdcbedc82715\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-726e-b31f-ed180aa2e7a8\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7272-b883-cb90fc4613b1\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-72df-add3-948f3ae38c3a\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-72e8-8000-db544fb35a56\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-72ff-a471-26c952d200e0\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-732e-826c-e994acc20716\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7332-a4cd-c9c9b549a5fb\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-737e-893f-c095b9a05cae\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-738c-b372-e509976f69ff\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7394-9953-5dbb467859fa\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-73f3-b027-c343b2bc8bcc\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-73ff-9543-f0a4f0beef05\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7410-a3fc-f9cdeb55d2be\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-741b-8f16-b27fcd99d0df\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7463-89b2-78cb94de9a0b\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7499-9152-520599d089ae\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-74c2-9cbb-24f1c34303bf\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-74d7-9ddd-84adc0f38f82\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-74fb-9f80-970c3db586d0\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7513-9c95-f19e0c7faa80\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7585-ab0e-eea95d65b0d5\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-760e-9945-f737049d905f\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7626-861e-3fdee887abd2\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-762d-a677-5e8984cc6692\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-764b-a1f8-90375260328c\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7650-bb2d-932dce8ae16a\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-765c-9723-069718911491\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-76a1-8eda-6e49fa70e7d5\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-76b5-847e-1b56562d15cf\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-76ce-8957-f95affe9341a\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7718-8d1f-6402a87408a7\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7739-aa31-52af27bc4470\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7740-812b-32762d430059\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7749-b14e-9c0626c03f9f\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7789-8b48-620aa694acf9\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-77b2-863d-f04dbb185e00\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-77ba-8f80-470856cedce4\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-77c0-827b-fe1a3aa43e2b\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-77d5-a9ce-e7c798e3a623\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7809-898a-ccc0f52bd390\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7828-9142-46f9bca4b0f5\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7834-a788-5b65c6a4bba2\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-786d-9fd5-468c3f3d231b\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-786d-aa24-a97705e13917\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-78ca-b356-4d5d425263a8\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-791c-9b90-4888cca36327\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7977-9cfc-85d26d41780b\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-79d7-a4b7-044fcf998708\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-79e3-8411-bbd133d55fff\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7a1f-a527-7bb8db2ceb1c\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7a3d-9578-42b1c711759f\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7a4b-b1a3-256ce6fa3f06\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7a57-a680-9739f5e67173\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7a58-80ea-4666cc94397f\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7a66-b427-f4bcd638d8bc\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7a7d-99ba-c5c18088d450\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7acc-b6dc-d560f0fab367\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7af4-883f-3eb7f05d75b5\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7b1a-8633-b9153e586424\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7b3f-9ef3-84f5a878f302\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7b50-9cb5-715a82f9e7c4\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7b52-a878-2326be81c03b\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7b6b-ae6d-76cea57487f2\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7b77-a360-0725f23aad30\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7b89-895f-21b4008bc732\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7b96-bc7d-4555833303eb\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7bc8-a3ed-a7b0a6363d6c\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7bf2-9789-1b88bf3ed265\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7c45-8d95-3745dcbbff1c\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7c76-bf49-3e804d3ba63f\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7c8c-b8ef-5b46308541bf\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7c91-9cc2-6dbd18d68dff\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7ca2-8757-52f713bd3df8\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7cb5-b65c-b463768e7ae8\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7cef-a31b-bf3c50bd7cf7\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7d2c-aaa5-974ca5e38654\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7d41-a4a0-e6b01d4b31c6\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7d53-b594-952ae035eb04\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7d58-b5b3-b6d5041dcab6\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7d6c-926a-ddd27dbde8ab\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7d72-bf9f-1d5913bbb0d5\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7d75-949b-4b5de42226ba\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7d81-90a0-d144fc27fe03\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7e38-b72f-ef8829e14104\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7e58-bb03-bee0f101dc01\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7e5e-ae22-2a8fc24086f1\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7ec5-a83c-99cfaee56aca\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7ecd-9660-81f9f74dc416\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7ef4-b28b-ee1fbaf9e62e\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7f1b-87cd-06e3787a116a\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7f46-b195-3af6228d17b1\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7f7b-90be-c002b024d412\",\n      \"to\": \"not-applicable\",\n      \"summary\": \"Exact candidate projects not-applicable\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7f7f-b5cc-b4553aac9194\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7f8a-9bff-e4f7683da35f\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7fa3-8045-32c1220ecd72\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f86da-4f90-7fbf-9949-b7ed353dfaef\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f8759-ab29-7627-bc04-6aba547ea45f\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f878c-5480-7890-bc64-9b2aab7e9aa5\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f87cb-b4e7-7cda-80ec-be5aceb7b500\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f87cc-bd1f-786d-896d-07ea9245861e\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f87cc-bd45-7a5c-9b37-1d6b5917928a\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f87e8-6b8b-735c-b036-fa42d7cee8cf\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f8822-1d7a-7594-adea-65ad12c47733\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f8c53-6105-71e5-8f34-53f2a81ee61c\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f8cc4-e796-7b0e-9a16-50c08614e848\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f8e99-9354-7ab6-a9ba-b166f83f25a3\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f8fb8-579b-78d5-9ebb-da03bb9aa40c\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f917f-d116-70e8-b4a1-2e0209598aec\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f9388-a139-7355-b9f2-f6dd9aa91042\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f9659-5560-7d9d-a143-78766f19ec85\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f96a2-c686-76e1-9261-f6106aa50429\",\n      \"to\": \"staged\",\n      \"summary\": \"Exact candidate projects staged\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f9771-4c20-7e2c-8e7c-3f3cb3f1b9bd\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f9ec5-fa5d-76a3-9adb-71611ee67005\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019f9f04-f8bd-7002-a702-1b9f66827ec0\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019fa773-aae4-7f50-80a5-ce53b08490d2\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"KF-ADR-019fad41-07fe-7f1e-a37a-a2572357700c\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"SHIFU-ADR-019f86da-4f90-7015-bdde-ae4cc649ed82\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"SHIFU-ADR-019f86da-4f90-7222-b238-9683f61e7288\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"SHIFU-ADR-019f86da-4f90-73bd-a6a9-5d39752151d6\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"SHIFU-ADR-019f86da-4f90-7885-9597-bfdcb4fd4453\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"SHIFU-ADR-019f86da-4f90-78f2-9256-43ef0fe3c58b\",\n      \"to\": \"partial\",\n      \"summary\": \"Exact candidate projects partial\"\n    },\n    {\n      \"adr\": \"SHIFU-ADR-019f86da-4f90-79a1-bc85-4b542fecf011\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"SHIFU-ADR-019f86da-4f90-7b07-b137-378fb5533b13\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"SHIFU-ADR-019f86da-4f90-7eac-ad5f-db132ae04d50\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"SHIFU-ADR-019f86ff-a8d6-7431-ae05-0ec95fdb7ace\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    },\n    {\n      \"adr\": \"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\",\n      \"to\": \"implemented\",\n      \"summary\": \"Exact candidate projects implemented\"\n    }\n  ]\n}\n-->\n\nBuildchain exact-source channel candidate.\n\n- Source branch: `dev/v4/v4.0`\n- Observed source HEAD: `1b77dbe8a0e669f3ec086f76c63eac07ec6e2a0d`\n- Source SHA: `b2d71e03f13e804f717182c0fd4cf8f72a2c771f`\n- Skipped newer unqualified commits: `2`\n- Target branch/head: `alpha/v4/v4.0` / `b9632daebcc1071ad7bc29b882c1c0fa54a2a292`\n- Decision root: `sha256:56a114bd26f10eb3c304efd87192581b359972279129a11858665471bcbfd500`\n- Dev Verify Patrol: [run 30588226971 attempt 3](https://github.com/kungfu-systems/kungfu/actions/runs/30588226971)\n- Alpha promotion preflight: [run 30588146705 attempt 1](https://github.com/kungfu-systems/kungfu/actions/runs/30588146705)\n\nThe source-lock branch must continue to point at the exact source SHA. This patrol never merges the PR, publishes a package, creates a tag, or creates a release.\n\n<!-- buildchain-dev-alpha-candidate-state\n{\"schema\":\"kungfu-buildchain-dev-alpha-candidate-state/v1\",\"repository\":\"kungfu-systems/kungfu\",\"sourceBranch\":\"dev/v4/v4.0\",\"targetBranch\":\"alpha/v4/v4.0\",\"targetSha\":\"b9632daebcc1071ad7bc29b882c1c0fa54a2a292\",\"generation\":1,\"priorStateRoot\":\"absent\",\"activeCandidate\":{\"sourceSha\":\"b2d71e03f13e804f717182c0fd4cf8f72a2c771f\",\"sourceLockRef\":\"buildchain/candidate/alpha-v4-v4.0/b2d71e03f13e\",\"decisionRoot\":\"sha256:56a114bd26f10eb3c304efd87192581b359972279129a11858665471bcbfd500\",\"workflowEvidence\":[{\"workflowPath\":\".github/workflows/dev-verify-patrol.yml\",\"workflowName\":\"Dev Verify Patrol\",\"runId\":30588226971,\"runAttempt\":3,\"headSha\":\"b2d71e03f13e804f717182c0fd4cf8f72a2c771f\",\"status\":\"completed\",\"conclusion\":\"success\",\"completedAt\":\"2026-07-30T23:59:23Z\",\"url\":\"https://github.com/kungfu-systems/kungfu/actions/runs/30588226971\"},{\"workflowPath\":\".github/workflows/alpha-promotion-preflight.yml\",\"workflowName\":\"Alpha promotion preflight\",\"runId\":30588146705,\"runAttempt\":1,\"headSha\":\"b2d71e03f13e804f717182c0fd4cf8f72a2c771f\",\"status\":\"completed\",\"conclusion\":\"success\",\"completedAt\":\"2026-07-30T22:45:45Z\",\"url\":\"https://github.com/kungfu-systems/kungfu/actions/runs/30588146705\"}],\"qualificationRoot\":\"sha256:6084adc05ff2e57b4555181bd48b5104e7768be4effc00f6789fd386affae254\"},\"nextCandidate\":null,\"tombstones\":[],\"observationDecisionRoot\":\"sha256:56a114bd26f10eb3c304efd87192581b359972279129a11858665471bcbfd500\",\"observedAt\":\"2026-07-31T00:04:00.999Z\",\"stateRoot\":\"sha256:53a9bf59d9438480a3f5bd44bb4c6f573666b4cdba1bfb659b37ab8fd64fce88\"}\n-->\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-31T00:04:15Z",
          "mergedAt": "2026-07-31T02:29:05Z",
          "additions": 783128,
          "deletions": 37594,
          "changedFiles": 4765
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2093,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2093",
          "title": "feat(signing): finalize native app bundles in authority",
          "body": "## Summary\\n\\n- route declarative app-bundle requests through the protected Buildchain signing authority\\n- bind notarized and stapled ZIP/DMG bytes into the generic signing result\\n- project verified macOS release payloads from GitHub-hosted finalization without consumer credentials\\n\\n## Verification\\n\\n- corepack pnpm@11.7.0 run check (1046 tests, workflow lint, generated site, 6 action bundles)\\n- node --test tests/native-artifact-signing-authority.test.mjs tests/macos-credential-island.test.mjs\\n\\nGoal: 2026-07-24-kungfu-public-alpha-release-closure",
          "author": "dongkeren",
          "createdAt": "2026-07-31T02:29:50Z",
          "mergedAt": "2026-07-31T02:36:01Z",
          "additions": 448,
          "deletions": 100,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2094,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2094",
          "title": "chore(signing): promote native app bundle authority",
          "body": "## Summary\n\nPromote the exact reviewed v3 development head into the protected artifact-signing authority.\n\nThe Buildchain authority now materializes declarative app-bundle signing requests through its own credential island, returns signed ZIP/DMG and notarization evidence as source-bound result bytes, and projects those outputs into consumer artifacts without consumer repository credentials or jobs.\n\n## Source\n\n- development head: `a56673f6d05390e125c9cae1addb8f349df81541`\n- authority base: `ea0d13ac2ccfbb3dc3a11a94e8eb83ab04b936b8`\n- implementation PR: #2093\n\n## Validation\n\n- #2093 hosted checks: passed\n- #2093 merge-group checks: passed\n- `corepack pnpm@11.7.0 run check`: 1046/1046 tests passed\n- native signing tests: 26/26 passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T02:36:23Z",
          "mergedAt": "2026-07-31T02:38:03Z",
          "additions": 1412,
          "deletions": 210,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1990,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1990",
          "title": "feat(shifu): qualify Windows x64 Core consumer",
          "body": "## Summary\n\n- emit normalized operating-system and architecture identity in Core build metadata and verify it independently from the native OS version string\n- activate the Windows x86_64 CPython 3.13 Qualified Core consumer, including fresh promoted-bundle materialization and second-worktree local CAS reuse\n- let `shifu.cmd work ...` materialize Qualified Core before source fallback and reuse the repository-pinned cached `uv`\n- require a protected `windows-2022` consumer job after promotion to verify PE bytes, receipt roots, actual Work activation, and GitHub-disabled local CAS reuse\n\n## Related issue\n\n- Native Assignment `2026-07-30-kungfu-qualified-core-windows-x86-64-consumer`\n- Parent Initiative `2026-07-30-kungfu-qualified-core-developer-acceleration-family`\n\n## Verification\n\n- Qualified Core artifact contract suite — 30/30 pass\n- Shifu entry contract suite — 22/22 pass\n- Windows identity tamper, protected bundle materialization, second-checkout local CAS, and Windows source-entry tests — pass\n- `actionlint` — no errors after excluding the workflow's pre-existing SC2016 informational finding\n- full source acceptance — pass, including 820 main contract tests\n- full pre-commit staged gate, documentation/ADR audit, DCO, Gate catalog, and publication-control roots — pass\n- protected merge-group and post-push Windows qualification will prove the real Windows PYD/DLL producer, promotion, independent reverification, and fresh Work activation\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Qualify the Windows x86_64 Core consumer with normalized build identity, verified materialization, local CAS reuse, and automatic Work activation.\",\n  \"verification\": [\"30 Qualified Core artifact contract tests\", \"Windows identity tamper rejection\", \"protected Windows remote-hit and second-checkout local-CAS qualification\", \"actual shifu.cmd Work activation\", \"independent protected review\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] none of the above\n\nThe change adds no credentials, registry writes, services, scheduled tasks, firewall changes, global Python mutation, or alternate qualification authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] ADR implementation evidence updated with this PR\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LXF1YWxpZmllZC1jb3JlLWRldmVsb3Blci1hY2NlbGVyYXRpb24tZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtd2luZG93cy14ODYtNjQtY29uc3VtZXIiLCJkZWxpdmVyeUNsYXNzIjoibmF0aXZlLXByb29mLXJlcXVpcmVkIiwiZGV2SGVhZCI6ImRkNzI1MDcyY2FkZDk0MGY1NDhiYjM4ZWJhOWUyMzEwNzZlZDFjYmIiLCJwdWxsUmVxdWVzdEhlYWQiOiI2NTQ3NDk1NGI4OWEwZTk0OTdkODFhOTZhNjU3OWU1ZmI4OTMzOWNmIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiI2ZDJkYzMxNmY1OGQ3NTdkNDE0MTIwMTgzZDEwMDcxNTc3NGJlMzBmIiwicmVwbGF5ZWRUcmVlIjoiYWI2MzIwN2YzMThiNWQ2ZmFmMGU2YzUyNDk2MzBkZDE4NjFkNzcwYyIsInF1ZXVlQXR0ZW1wdCI6IjY1NDc0OTU0Yjg5YTBlOTQ5N2Q4MWE5NmE2NTc5ZTVmYjg5MzM5Y2ZAZGQ3MjUwNzJjYWRkOTQwZjU0OGJiMzhlYmE5ZTIzMTA3NmVkMWNiYiIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1Njo3NzNlMWI4ODgyNTAyYTJlM2M5OGVmZjE4ZWM0ZjgyYjhiYzRiZDNmOTg0NGEwNjIzOTc5NzkyOGE4ZDA0YjlmIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6NzczZTFiODg4MjUwMmEyZTNjOThlZmYxOGVjNGY4MmI4YmM0YmQzZjk4NDRhMDYyMzk3OTc5MjhhOGQwNGI5ZiIsInNoYTI1NjplYzFhOTVlN2Y4MDdhNWQ2ZTBkOGVkMTc1MjRiMTEwZTFjZTgyYzc4ZmJlMWQ2NzZhMWUzNjlkMzBiMmJiN2M1Il0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvOTZkM2JmZjU3MWIwNGJiMiIsImxlYXNlUm9vdCI6InNoYTI1NjoyNTdlYTQ3ZmUwNDEzZjYzMDU1MzNhZTZiOTgzYzc0NDMyMTczY2QxNmI0ZjY0ZTFiMTViYjI3MDViZGVjZGJlIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-30T22:57:15Z",
          "mergedAt": "2026-07-31T02:40:33Z",
          "additions": 271,
          "deletions": 27,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2095,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2095",
          "title": "fix(promotion): trust reusable workflow runtime pin",
          "body": "## Summary\n\n- pass the immutable reusable-workflow `job.workflow_sha` into the promotion router\n- treat an exact runtime SHA matching that trusted SHA as a source pin, not an operator override\n- retain the trusted `workflow_dispatch` authorization gate for mismatched SHA, train, and authority overrides\n- regenerate the public workflow and site contract digest\n\n## Incident proof\n\nKungfu Alpha release run `30599090779` called the Buildchain reusable workflow and runtime at the same immutable SHA `ea0d13ac2ccfbb3dc3a11a94e8eb83ab04b936b8`, but the router marked it as `overrideUsed=true` and rejected the legitimate merged-PR event. The exact coordinates now resolve to `overrideUsed=false` with `selectionSource=trusted-router-sha`.\n\n## Verification\n\n- `node --test tests/promotion-channel-router.test.mjs`\n- `node scripts/generate-channel-promotion-workflow.mjs --check`\n- `bash scripts/check-workflows.sh`\n- `pnpm run check` (1047 tests; inventory, site bundle, workflows, and 6 action bundles passed)\n\nAgent: Codex\nGoal: 2026-07-24-buildchain-linux-github-attestation",
          "author": "dongkeren",
          "createdAt": "2026-07-31T02:37:20Z",
          "mergedAt": "2026-07-31T02:47:52Z",
          "additions": 54,
          "deletions": 6,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2003,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2003",
          "title": "fix(ci): quote Windows cache-off dispatch option",
          "body": "## Summary\n\n- quote the Windows compiler-cache `off` workflow-dispatch choice so GitHub accepts the intended string value\n- add a raw workflow regression assertion that rejects an unquoted YAML token\n\n## Verification\n\n- `node --test scripts/check-shifu-cache-contract.test.mjs` — 39/39 passed before dependency sync\n- `./shifu sync` — frozen lockfile, 994 packages reused from the local store\n- repository pre-commit staged gate — passed, including 73 dev-latency tests, 17 invariant tests, 137 documentation/release tests, KFD gates, and staged Biome\n\n## Failure evidence\n\nThe first same-source A/B dispatch failed before creating a workflow run with HTTP 422 because GitHub did not admit `off` as a string choice. No DARKHERO Defender or power-plan state changed, and the temporary experiment branch was removed.\n\nGoal: `2026-07-31-kungfu-windows-alpha-build-performance`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Workflow-dispatch string parsing bugfix without accepted ADR record changes\"\n}\n-->\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTMxLWt1bmdmdS13aW5kb3dzLWFscGhhLWJ1aWxkLXBlcmZvcm1hbmNlIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJhZDk3ZTQyOTlkNTZiOTIwZmJkODRmNTQyMWM3MDkxMGU3YjQwZTc2IiwicHVsbFJlcXVlc3RIZWFkIjoiMmRmN2M4ZmZkMTJmODMwYmJmZTZjMWUyZDY5MTdmYTM1MGRkZjk0MyIsInJlcGxheWVkQ2FuZGlkYXRlIjoiNWYxNmQ4ZWNjOThiMzQ1NTI0ZDQ1NWY1MWFkOWY2NjVkNjI2NjY2YiIsInJlcGxheWVkVHJlZSI6IjQzNzMwYTlkNWI0NjUyZGYzYTBjNDFlMTUzNzMyOWZkNWJkMDVmOGYiLCJxdWV1ZUF0dGVtcHQiOiIyZGY3YzhmZmQxMmY4MzBiYmZlNmMxZTJkNjkxN2ZhMzUwZGRmOTQzQGFkOTdlNDI5OWQ1NmI5MjBmYmQ4NGY1NDIxYzcwOTEwZTdiNDBlNzYiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6ZjZkMmI4ZGQ5MDk3MzQ0OWZlMzcyODA2NzM2MTM3YjFmNWVhN2NhYzQ0ZjJmZmI0MjBmZTlhZTdmZTU5MzEwMCIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjA4ODM2MTllZTc3MmYwNDZlNTMyMmQyMjU5M2ViYjVhMzI2ZGQ2YWIyZjhmYmUzMzJkNzljMjE2MmIzYzcwYTkiLCJzaGEyNTY6ZjZkMmI4ZGQ5MDk3MzQ0OWZlMzcyODA2NzM2MTM3YjFmNWVhN2NhYzQ0ZjJmZmI0MjBmZTlhZTdmZTU5MzEwMCJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6MDhjNjIzZTk1N2QwYmUwMDIxNGYxZjQwYzRlNzEwMjgxODBkZjRlNzQzMDZmOTMyMTg5MzdmNmNmZmMzODYxMyJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T02:05:57Z",
          "mergedAt": "2026-07-31T02:51:39Z",
          "additions": 7,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2001,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2001",
          "title": "feat(demo): add multi-animation capture catalog",
          "body": "## Summary\n\nAdd a governed multi-animation capture catalog to the existing auditable-demo lane. Capture selection is explicit and identity-neutral: a demo entry supplies deterministic argv, bounded completion evidence, publication metadata, and exact Release Passport binding without treating first-party or System identity as authorization.\n\nKFD-1 impact: additive pre-release qualification and capture selection only. This PR does not open a new release line or change a stable/welded compatibility surface.\n\n## Related issue\n\nSupports the current auditable-demo qualification and publication work.\n\n## Changes\n\n- Add the `framework/auditable-demo` catalog authority with one README-featured default demo and room for additional deterministic demos.\n- Pass the selected demo ID through the Buildchain auditable Gate and bind catalog/descriptor roots into Release Passport v2.\n- Execute catalog argv directly through the bounded PTY adapter, preserving ANSI color and exact completion evidence.\n- Extend README publication logic so secondary qualified demos remain additive and cannot replace the featured hero implicitly.\n- Refresh workflow-authority and publication-surface projections.\n\n## Verification\n\n- `./shifu test:auditable-demo` (39/39)\n- `./shifu node scripts/code-complexity-budget.mjs`\n- `./shifu node scripts/check-kungfu-gate-catalog.mjs`\n- `./shifu release:publication:status`\n- `./shifu check:source` (all gates passed after provisioning the locked pytest toolchain; isolated `node --test scripts/readonly-agent-bootstrap.test.mjs` passed)\n- pre-commit staged gate, including Ruff, Biome, documentation, ADR, KFD, and DCO checks\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7b6b-ae6d-76cea57487f2\"],\n  \"summary\": \"Add identity-neutral multi-animation selection and exact Passport binding to the existing auditable-demo consumer lane\",\n  \"verification\": [\"Auditable-demo suite 39/39\", \"Staged source, documentation, workflow-authority, KFD, Ruff, and Biome gates passed\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\nThis extends the current auditable-demo implementation stage; it does not allocate or settle a new Era or Stage.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release-evidence boundary is fail-closed: demo selection, catalog root, descriptor root, source SHA, artifact digest, and publication surface are bound before publication. The workflow remains `publish-none` outside the qualified lane and this PR performs no production deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T01:36:06Z",
          "mergedAt": "2026-07-31T03:04:04Z",
          "additions": 990,
          "deletions": 126,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 198,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/198",
          "title": "feat(demo): import multiple qualified animations",
          "body": "## Summary\n\nExtend the public auditable-demo importer from one qualified animation to a bounded collection while preserving the existing Agent Work Lab hero and v1 compatibility route. Every animation remains independently bound to its exact Release Passport, media root, Gate root, and identity-neutral authorization non-claims.\n\nThis PR depends on kungfu-systems/kungfu#2001 for the upstream Passport v2 and catalog producer contract. It may be reviewed and tested now, but should merge only after that dependency reaches `dev/v4/v4.0`.\n\n## Changes\n\n- Accept the legacy `kungfu.site.auditable-demo-source/v1` descriptor without output drift and add the bounded v2 collection form.\n- Verify one to eight exact demo ID, Passport, and media-directory bindings with exactly one featured entry.\n- Preserve `/auditable-demo.json` as the featured compatibility projection and add `/auditable-demos.json` plus per-demo machine projections.\n- Materialize secondary evidence under demo-specific paths and append additional videos to `/how-tested/auditable-demo/` without replacing the current hero.\n- Document the importer and authority boundary.\n\n## Verification\n\n- `node --test scripts/import-auditable-demo.test.mjs` (7/7)\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `git diff --check`\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe importer consumes only exact qualified upstream Passports and media. Demo identity, first-party/System identity, KFD compliance, and Product System metadata grant no publication or runtime authority. This PR does not deploy production and does not approve or merge a `buildchain-release` production PR.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T02:33:02Z",
          "mergedAt": "2026-07-31T03:05:06Z",
          "additions": 373,
          "deletions": 35,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2089,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2089",
          "title": "fix(runtime): close all-ref v2 to v3 parity",
          "body": "## Summary\n\n- make v3 the implicit runtime baseline across reusable build, web-surface, contract-lock, and Paper entrypoints\n- forward every material v2 capability absent from v3, including the AWS CodeConnections name fix\n- restore train-only Initiative-family release evidence and all-ref typed product-owned release evidence attachments\n- retain v2 JSON/CLI/direct-Action compatibility while keeping the distinct v3 post-activation evidence stage\n- preserve explicit legacy/history/multi-major evidence without restoring stale authority\n- incorporate the current native app signing authority and rebuild generated site/Action artifacts from the combined v3 tree\n- bind Release Passport attachments by exact id/path coordinates and reject duplicate ids, duplicate paths, or non-sibling paths\n\n## Parity boundary\n\nThe audit covered all 992 fetched remote refs and tags whose names select the v2 product line, representing 869 unique tips. It included authority refs, train refs, work branches, version-state refs, immutable tags, and other remote v2 coordinates.\n\nThe historical v2 tree union has 35 paths absent from v3. The retrospective classifies them as retired orchestration, immutable historical `.kungfu`/`.xinfa` projections, namespaced config replacements, or superseded product-specific KFD gates. No stale release state or generated historical authority is copied into v3.\n\nTwo real all-ref omissions were found and closed:\n\n1. `train/v2/v2.3/go-family-release-handoff@c4f3ad6fcc84a131f40e97773975e6b4a81a5dd3`: optional fail-closed Initiative-family release evidence, restored as the Buildchain adapter envelope while Kungfu Work Control remains authoritative for native Family State v1/v2.\n2. `801813dfb933bf8f092e2059fae51a2c421435ed`: typed product-owned release evidence attachments, restored with exact source/tag/channel validation, canonical digest binding, sibling retention, and independent verification.\n\nThe direct Action retains the v2 `release-passport-evidence-command` alias. Reusable v3 workflows use `release-passport-attachment-command` because the old workflow input name now belongs to the distinct post-activation released-evidence stage.\n\nThis branch contains #2088 and the current protected `dev/v3/v3.0@adbcbdef01668890d8de9354bdb6e32a84bb52ad` baseline, including #2090, #2092, #2093, and #2095. The bounded auditable-demo adapter arguments, Release Passport attachment surface, and native signing authority all coexist.\n\n## Verification\n\n- `pnpm run check`: passed on the combined protected-v3/parity tree\n- inventory, site bundle, and workflow checks passed\n- Action bundle integrity: 6 passed\n- targeted parity, Release Passport, Build Surface, CLI, promotion, and native signing tests: 417 passed\n- `git diff --check`\n- remote exact head readback: `5f2b4847b942c183c39fec3ed0cb978acc261462`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T23:05:49Z",
          "mergedAt": "2026-07-31T03:09:25Z",
          "additions": 2354,
          "deletions": 510,
          "changedFiles": 67
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2088,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2088",
          "title": "fix(workflows): trust exact pinned self runtime",
          "body": "## Summary\n- admit an exact Buildchain SHA only when it equals the reusable workflow shell SHA\n- record the non-override decision as `pinned-self` in publication and sealed paper workflows\n- retain fail-closed behavior for different SHA and train overrides\n\n## Regression\n- `node --test --test-name-pattern=\"runtime selection|runtime-aware workflows\" tests/build-surface.test.mjs`\n- `pnpm run check:workflows`\n- `git diff --check`\n\n## Live evidence\nPaper publication PR #35 invoked `publication-artifact.yml@60ac9ca28dc0cc7a06945b45b06f22507c510145` with the identical `buildchain-ref`, but the current v3 workflow rejected it as a manual-only override before build. This patch treats that identical self-pin as the already-running authority, without allowing any independent override.",
          "author": "dongkeren",
          "createdAt": "2026-07-30T22:23:41Z",
          "mergedAt": "2026-07-31T03:09:26Z",
          "additions": 108,
          "deletions": 22,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 36,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/36",
          "title": "fix(ci): pin paper release to qualified v3 cut",
          "body": "## Summary\n\n- pin both Paper workflows and runtime inputs to the protected Buildchain v3 cut `71a75f21159b994241ec7cb2c50f7a150c5d440b`\n- refresh the admitted Buildchain contract lock with zero runtime drift\n- rebind the Paper provisioning authority to the exact workflow bytes and protected runtime SHA\n- preserve paper content and the existing `0.1.0-alpha.4` candidate\n\n## Root cause\n\nThe previous `60ac9ca28dc0cc7a06945b45b06f22507c510145` runtime classified its own exact reusable-workflow SHA as a manual override on pull-request events. The protected v3 cut includes the pinned-self runtime fix, the complete v2-to-v3 parity closure, and the Release Passport attachment verifier hardening.\n\n## Verification\n\n- managed Paper migration: 5 unchanged files after regeneration; 0 drift, 0 conflicts\n- live preflight: exact runtime and contract lock unchanged; provisioning authority valid; repository Actions policy and GitHub App generated-write authority observed\n- `make check`\n- `make pdf` with Tectonic\n- two independent clean Docker builds: qualifying and byte-identical\n- reproducibility receipt: `sha256:63607c49c97b2d6de356f225fb79cf46f36d8536ac222fbd05c327e5a44ed422`\n- promoted npm tarball SHA-256: `213b21e1f228ca12624f977d4d8474af23edd4b4d2f40012fd7e3adeb5ea607b`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T03:16:00Z",
          "mergedAt": "2026-07-31T03:17:43Z",
          "additions": 21,
          "deletions": 21,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2096,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2096",
          "title": "fix(runners): inspect organization runner inventory",
          "body": "## Summary\n\n- resolve the repository owner before runner availability routing\n- inspect organization runner inventory for organization-owned repositories\n- preserve fail-closed self-hosted routing when inventory access is unavailable\n- expose only the de-identified inventory scope in routing evidence\n\n## Why\n\n`trusted-build-runners` is an organization-level runner group shared with selected repositories. The repository runner endpoint returns an empty inventory for this topology even while DARKHERO is online, causing false GitHub-hosted fallback.\n\n## Verification\n\n- `node --test tests/runner-offline-fallback.test.mjs` (5 passed)\n- `pnpm run test:unit`\n- live read-only resolution against `kungfu-systems/kungfu`: `inventoryScope=organization`, Windows matching/online count `1/1`, fallback count `0`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T03:15:21Z",
          "mergedAt": "2026-07-31T03:26:07Z",
          "additions": 131,
          "deletions": 43,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2007,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2007",
          "title": "fix(release): pin trusted Buildchain promotion runtime",
          "body": "## Summary\n\n- pin Kungfu release and build workflows to Buildchain `adbcbdef01668890d8de9354bdb6e32a84bb52ad`\n- refresh the accepted Alpha contract lock and workflow-authority projections\n- consume the trusted-router-sha fix from buildchain#2095 so an immutable reusable-workflow source pin is not misclassified as an operator override\n\n## Failure evidence\n\nRelease run `30599090779` failed before publication because the router rejected the exact reusable-workflow SHA as an untrusted runtime override. No tag or release asset was published.\n\n## Validation\n\n- `./shifu check:staged`\n- `./shifu check:source`\n- 27 targeted release/signing/workflow tests\n- Buildchain contract check: compatible, unchanged, no drift\n- workflow authority: closed world verified\n\n## Evolution impact\n\nNone. This is a source-pin correction within the established Buildchain release authority and does not alter a Kungfu architecture contract.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This source-pin correction consumes the established Buildchain release authority without altering a Kungfu architecture contract\"\n}\n-->\n\nGoal: `2026-07-24-buildchain-linux-github-attestation`",
          "author": "dongkeren",
          "createdAt": "2026-07-31T02:58:35Z",
          "mergedAt": "2026-07-31T03:26:09Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2013,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2013",
          "title": "fix(ci): use organization runner inventory runtime",
          "body": "## Summary\n\n- advance the exact Buildchain runtime to the organization runner-inventory fix\n- keep selected-repository organization runners visible to offline fallback routing\n- refresh the coherent Alpha contract lock, workflow authority, release admission, and publication roots\n\n## Verification\n\n- live read-only resolution: DARKHERO `online`, exact-label matching/online count `1/1`, fallback count `0`\n- `./shifu check:source`\n- `./shifu check:gate-catalog`\n- `./shifu test:release-admission`\n- `./shifu check:release-publication-control-plane`\n- repository pre-commit staged gate: 73 latency, 17 invariant, 137 documentation/release tests plus KFD and Biome gates passed\n\n## Failure evidence\n\nThe previous Buildchain runtime queried repository-level runner inventory, which returns an empty list for the `trusted-build-runners` organization group even when DARKHERO is online and shared with this repository. The corrected runtime queries organization inventory for organization-owned repositories and preserves fail-closed self-hosted routing when inventory access is unavailable.\n\nGoal: `2026-07-31-kungfu-windows-alpha-build-performance`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"CI runner inventory scope bugfix without accepted ADR record changes\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T03:36:51Z",
          "mergedAt": "2026-07-31T03:37:37Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 200,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/200",
          "title": "feat(home): feature auditable Agent Work replay",
          "body": "## Summary\n\nRedesign the homepage hero as a full-width, evidence-bound demonstration reel that leads with the Kungfu continuity claim and then shows the exact Agent Work Lab replay.\n\n## Changes\n\n- render the core continuity claim as slide 1 in the same 16:9 frame as the replay\n- cross-fade once to the exact Agent Work Lab replay after five seconds\n- cancel automatic advance after any user click, arrow-key action, or touch swipe\n- disable automatic advance and playback for reduced-motion visitors\n- place the carousel directly below the shared header with no intervening blank row\n- keep one full page-content-width showcase while centering only the height-constrained inner reel\n- use a cool gray-blue light-theme stage and a corresponding dark-theme stage; keep black limited to the video media field\n- let the showcase own the single border and shadow so slides do not look like nested cards\n- overlay the temporary Coming Soon label, visible counter, and previous/next controls in the card's bottom-right corner\n- keep the full slide title in an accessible live status while presenting a compact visible counter\n- reserve caption space and share the overlay's vertical center so links remain clearly separated from the controls\n- keep Get Kungfu as the single shared-header install action and remove its duplicate from the supporting row\n- center the left-aligned execution-surface copy block, replace untested Copilot wording with OpenCode, and stack the two neutral exploration links as right-aligned rows\n- render the brand principle as three explicit rows and match the stewardship heading to the builder-card title scale and content inset\n- make Alpha activation a label-only removal that cannot change reel geometry\n- generate Agent Work Lab media coordinates and duration from the retained auditable-demo Passport\n- gate slide order, unified stage styling, supporting-row hierarchy, overlay placement, evidence paths, transition behavior, viewport-height sizing, and the retired static continuity card\n\n## Verification\n\n- node --test scripts/import-auditable-demo.test.mjs\n- node --check scripts/import-auditable-demo.mjs\n- bash -n scripts/build-site.sh\n- bash -n scripts/check-site.sh\n- shellcheck scripts/build-site.sh scripts/check-site.sh\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- 1920x900 Chrome: 1180px showcase and complete reel remain visible; overlay stays inside without content overlap\n- 1920x820 Chrome: 1180px showcase aligns with the header, the 1077.77px reel is centered, and the complete stage remains visible\n- desktop caption check: 43.7px link-to-control gap and exact shared vertical center on both slides\n- 1920x1200 and 1280x1000 supporting-row checks: centered left-aligned copy block, two stacked right-aligned exploration links, and no overflow\n- stewardship check: 44px desktop and 28px mobile heading parity with builder cards, with desktop vertical centers within 2.5px and title left edges exactly aligned\n- 900x1000 and 390x844 responsive checks: supporting content stacks cleanly with no horizontal overflow\n- action hierarchy check: one header Get Kungfu action, no supporting-row install action, no Copilot copy, and one OpenCode reference\n- light/dark theme check: claim title, tagline, stage, caption, and controls use theme-appropriate contrast\n- browser interaction check: visible counter and accessible full-title status update together\n- timed browser check: core idea cross-fades to Agent Work Lab and the replay starts only after activation\n- interaction browser check: manual next/previous cancels the timed handoff\n- reduced-motion browser check: core slide remains active and media remains paused\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR renders an existing qualified public evidence bundle on the homepage. It does not alter the Passport, evidence claims, production status, infrastructure, or production approval path. The importer and site gate bind every Agent Work Lab media route to the current verified public evidence path.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-31T03:33:26Z",
          "mergedAt": "2026-07-31T03:39:36Z",
          "additions": 658,
          "deletions": 215,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2012,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2012",
          "title": "refactor(architecture): converge packaging and durability variants",
          "body": "## Summary\n\n- materialize framework and product Electron Builder projections from one canonical base plus a product-only overlay\n- converge strict native file and directory durability mechanics behind one internal cross-platform adapter while preserving strict, best-effort, and provider-owned semantics\n- reduce the abstraction-integrity ratchet from three findings / weighted debt 18 to zero without adding an exception\n- bind the delivery to the accepted maintainability-governance ADR and deterministic navigation projections\n\n## Verification\n\n- `./shifu check:source`\n- `node --test framework/maintainability/semantic-amplification.test.mjs framework/gui/scripts/electron-builder-config.test.mjs product/scripts/dist.test.mjs product/scripts/upgrade-manifest.test.mjs framework/gui/scripts/sign-macos.test.mjs`\n- `./shifu maintainability:complexity`\n- full Core CMake compile for `yijinjing`, `kungfu_ledger_services`, and `kungfu_storage_services`\n- `yijinjing_durability_tests`\n- deterministic documentation and ADR gates\n\n## Boundaries\n\n- no installed GUI product was launched, replaced, promoted, or qualified\n- this delivery does not claim physical power-loss, installed-product, public-release, or unobserved-platform qualification\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f9f04-f8bd-7002-a702-1b9f66827ec0\"],\n  \"summary\": \"Converge representative desktop packaging and native durability variants under explicit authorities and qualified projections\",\n  \"verification\": [\"exact-head source acceptance\", \"deterministic packaging projections\", \"native adapter compilation and tests\", \"zero-finding abstraction-integrity ratchet\"]\n}\n-->\n\nAssignment: 2026-07-31-kungfu-abstraction-integrity-fragmentation-governance\n\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T03:30:59Z",
          "mergedAt": "2026-07-31T03:45:49Z",
          "additions": 1227,
          "deletions": 773,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 201,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/201",
          "title": "Release production from 27e1f302e54c",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `27e1f302e54cc8cb38a3ec63d7a9c6b4d8bca56c`\n- Artifact hash: `69de9083385fd1435deca053fec40f969b60da13c8c85c323402beafe7745828`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30602130519)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-27e1f302e54c`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-31T03:42:05Z",
          "mergedAt": "2026-07-31T03:47:00Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2014,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2014",
          "title": "fix(release): align Alpha sentinel with demo catalog",
          "body": "## Summary\n\n- validate the catalog-declared qualified completion sentinel for the default auditable demo\n- prove the adapter consumes the catalog sentinel and verdict instead of requiring retired literal constants\n- bind the fast sentinel to an exact Buildchain SHA and one bounded catalog demo id\n\n## Failure evidence\n\nAlpha promotion preflight run `30601568824` rejected exact dev source `306a289dd3bac20131c2397e954b275f744b30ff` because its legacy text probe did not understand the catalog-driven adapter introduced by the multi-demo delivery.\n\n## Validation\n\n- `node --test scripts/alpha-promotion-preflight.test.mjs product/scripts/cli-surface-qualification.test.mjs`\n- `./shifu check:staged`\n- `./shifu check:source`\n- Biome check for both changed files\n\n## Evolution impact\n\nNone. This repairs a qualification probe to follow the already-established auditable-demo catalog authority; it does not alter the product or architecture contract.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This qualification repair follows the established auditable-demo catalog authority without altering a Kungfu architecture contract\"\n}\n-->\n\nGoal: `2026-07-24-buildchain-linux-github-attestation`",
          "author": "dongkeren",
          "createdAt": "2026-07-31T03:39:23Z",
          "mergedAt": "2026-07-31T03:56:51Z",
          "additions": 49,
          "deletions": 10,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2018,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2018",
          "title": "chore(release): reconcile Alpha history for attestation",
          "body": "## Summary\n\nReconcile the current Alpha branch as an ancestry-only parent of exact protected dev before the GitHub-attested Linux Alpha publication. The merge uses the ours strategy, so the resulting tree remains byte-identical to protected dev.\n\n## Verification\n\n- merge commit: `9305c725f3073d00a8e0a296ac63a388ae2a7d51`\n- first parent (current dev): `b0eccac6a95e22ca5b5c1462451c3039ab6ca42c`\n- second parent (current Alpha): `9058fc5d07f1035093c0f53bfd1c535f25e39daa`\n- merge tree equals first-parent tree: `34a9c9bd2fa2824729ebcf1a151c3a786164ed35`\n- no files changed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Ancestry-only Alpha history reconciliation with a tree identical to protected dev\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Tree identity and both parents verified",
          "author": "dongkeren",
          "createdAt": "2026-07-31T04:06:04Z",
          "mergedAt": "2026-07-31T04:17:01Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2006,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2006",
          "title": "fix(signing): delegate application notarization to Buildchain",
          "body": "## Summary\n\nDelegate macOS application signing and notarization to Buildchain's native protected artifact authority.\n\n## Changes\n\n- declare the Kungfu desktop app as a required `app-bundle` signing artifact\n- remove the consumer-owned signing job, environment, certificate inputs, and notary inputs\n- lock Alpha build and promotion workflows to the protected Buildchain implementation\n- refresh workflow authority, publication roots, and contract tests\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu release:promotion:rehearse`\n- targeted signing and release tests: 69 passed\n- staged repository gate: passed\n\n## Evolution impact\n\nNone. This delegates an existing release concern to its established Buildchain authority and does not alter a Kungfu architecture contract.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This release integration change delegates existing signing authority without altering a Kungfu architecture contract\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T02:57:10Z",
          "mergedAt": "2026-07-31T04:36:20Z",
          "additions": 45,
          "deletions": 132,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 35,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/35",
          "title": "release(paper): publish 0.1.0-alpha.4 alpha",
          "body": "## Summary\n\nPromote `dev/v0/v0.1@d3512863be1449e1b17d278d056ba0b39fbac468` to `alpha/v0/v0.1@5ba911612144bccb010c5363b226bc4cda1388da` through the protected Buildchain paper release flow.\n\n## Exact publication candidate\n\n- package: `@kungfu-tech/paper-kfd-machine-life-roadmap`\n- version: `0.1.0-alpha.4`\n- npm dist-tag: `alpha` (currently `0.1.0-alpha.3`)\n- expected immutable tag / GitHub prerelease: `v0.1.0-alpha.4` (currently absent)\n- Buildchain runtime: `71a75f21159b994241ec7cb2c50f7a150c5d440b`\n- provisioning authority: `sha256:1cfb1e181476fc63a86a1423564ff96581dfaa72f1e0652477cb6b3bce715b1c`\n- local reproducibility receipt: `sha256:63607c49c97b2d6de356f225fb79cf46f36d8536ac222fbd05c327e5a44ed422`\n- promoted npm tarball SHA-256: `213b21e1f228ca12624f977d4d8474af23edd4b4d2f40012fd7e3adeb5ea607b`\n\n## Safety and verification\n\n- Build and verification remain credential-free; publication authority is only available after sealed candidate admission.\n- Exact artifact bytes are sealed before npm OIDC is available.\n- Two independent local clean builds were byte-identical and qualifying.\n- Push and pull-request Build/Verify checks all passed on the exact source head.\n- `kungfu-origin` independently approved the exact candidate.\n- Merging this PR is the explicit public publication gate; it will trigger the protected Paper Release workflow. npm versions and immutable GitHub release/tag objects cannot be overwritten in place after publication.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-30T22:14:35Z",
          "mergedAt": "2026-07-31T04:39:33Z",
          "additions": 109,
          "deletions": 45,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2097,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2097",
          "title": "fix(paper): grant sealed release permission floor",
          "body": "## Summary\n\n- grant generated Paper release callers the `pull-requests: write` permission required by the nested sealed publish job\n- lock the caller permission floor in Paper scaffold regression coverage\n- refresh the generated Node API contract digests\n\n## Failure evidence\n\nPaper Alpha 4 run 30604720498 failed during workflow startup with zero jobs after the generated caller invoked the sealed workflow without the nested publish job permission floor. No npm version, tag, or GitHub Release was created.\n\n## Verification\n\n- `node --test tests/paper.test.mjs` (8/8)\n- `pnpm run check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T04:43:46Z",
          "mergedAt": "2026-07-31T04:52:30Z",
          "additions": 8,
          "deletions": 3,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 202,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/202",
          "title": "fix(home): prefer mp4 for auditable demos",
          "body": "Merge fix/prefer-mp4-source into main (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-31T04:50:53Z",
          "mergedAt": "2026-07-31T04:54:18Z",
          "additions": 39,
          "deletions": 8,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 37,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/37",
          "title": "fix(ci): grant sealed paper release permission floor",
          "body": "## Summary\n\n- pin Paper workflows, contract lock, and provisioning authority to protected Buildchain v3 `d61d194d0676cb0f53510ce6b082419d3368e699`\n- grant the generated sealed release caller the nested `pull-requests: write` permission floor\n- preserve Paper content, publication version, and package identity unchanged\n\n## Failure recovery\n\nThe first Alpha 4 release run (`30604720498`) failed during workflow startup with zero jobs because the generated caller could not grant the nested publish job permission. No npm version, Git tag, or GitHub Release was created.\n\n## Qualification\n\n- `make check`\n- `make pdf`\n- live Paper preflight: valid authority, exact runtime/contract lock, generated-write GitHub App configured\n- two clean network-disabled Docker builds: byte-identical\n- reproducibility receipt: `sha256:f3ec56725ccab0fa0321b18428082c9982f134b9eac2f4a038ffd30baeb2558f`\n- npm tarball SHA-256: `31001f521840bf5a52eecad336205b77ea8d6dcd941cc8a67b3d81e1ba1b2a95`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T04:56:13Z",
          "mergedAt": "2026-07-31T04:57:48Z",
          "additions": 19,
          "deletions": 18,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 203,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/203",
          "title": "Release production from c88837d7ed6c",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `c88837d7ed6ca31dd5cf3843eef6d4bffb4e32e4`\n- Artifact hash: `c5d3384ecbfba356f81d653bff68425ac6b0897bc53374bdb05c9c4048126637`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30605355429)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-c88837d7ed6c`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-31T04:56:42Z",
          "mergedAt": "2026-07-31T04:59:27Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 39,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/39",
          "title": "chore(release): reconcile failed Alpha publication ancestry",
          "body": "## Summary\n\n- merge the already-protected `alpha/v0/v0.1@0a1f04174e2a5a0447a24bf83cc3fc5730b7144f` ancestry back into dev\n- preserve the exact dev tree `5f71f0d3d6636e9daf6b7fe6682925edb9ee70fe` byte-for-byte\n- unblock the retried protected dev-to-alpha publication PR after the first release workflow failed before any job started\n\n## Proof\n\n- first parent: `0765619a31db9b2696064a45393ae393e4a24315`\n- second parent: `0a1f04174e2a5a0447a24bf83cc3fc5730b7144f`\n- pre-merge dev tree: `5f71f0d3d6636e9daf6b7fe6682925edb9ee70fe`\n- merged tree: `5f71f0d3d6636e9daf6b7fe6682925edb9ee70fe`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T04:59:19Z",
          "mergedAt": "2026-07-31T05:00:38Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 38,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/38",
          "title": "release(paper): publish 0.1.0-alpha.4 alpha",
          "body": "## Summary\n\nPromote `dev/v0/v0.1` to `alpha/v0/v0.1` through the protected Buildchain paper release flow.\n\n## Safety\n\n- Build and verification remain credential-free.\n- Exact artifact bytes are sealed before npm OIDC is available.\n- This PR does not bypass review or publish directly.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T04:58:20Z",
          "mergedAt": "2026-07-31T05:02:08Z",
          "additions": 19,
          "deletions": 18,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2098,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2098",
          "title": "fix(publication): union authenticated registry snapshots",
          "body": "## Summary\n- union independently authenticated immutable publication registry snapshots\n- preserve publication id, registry digest, and same-version immutability checks\n- surface structured reproducibility failures in workflow logs\n\n## Validation\n- `node --test tests/publication-artifact.test.mjs tests/publication-reproducibility.test.mjs tests/build-surface.test.mjs` (109 passed)\n- `CI=true pnpm run check` (1063 passed; workflow/site/action bundle checks passed)\n- reproduced Paper Alpha 4 against the patched runtime: `publication-reproducibility=passed`, `qualifying=true`",
          "author": "dongkeren",
          "createdAt": "2026-07-31T05:17:33Z",
          "mergedAt": "2026-07-31T05:21:56Z",
          "additions": 54,
          "deletions": 17,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1991,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1991",
          "title": "feat(product): unify Project files and Work across GUI and TUI",
          "body": "## Summary\n\n- make Project, Work, and Agent the shared first-layer model across GUI, TUI, and CLI\n- give GUI Projects the same Files/Work navigation, bounded loading state, one-level expandable tree, path copy, Work creation, and exact Agent run flow as TUI\n- retain All Work as the machine-wide projection while Project surfaces keep project-local Files and Work context\n- establish qualified public component entrypoints for the shared Project, navigation, window, and installed-runtime capabilities\n\n## Changes\n\n- add machine-local Project discovery and exact Core project authority paths\n- align GUI Projects cards and opened Project behavior with the TUI golden path\n- preserve direct Codex, Claude, and OpenCode actions with explicit verification diagnostics\n- refresh primitive, maintainability, KFD, and support-matrix evidence\n\n## Verification\n\n- `./shifu check` passed before the final mainline synchronization\n- API: 48 tests passed\n- TUI: 123 tests passed\n- GUI focused shell and Project/Lab contracts: 44 tests passed\n- Work Dashboard: 30 tests passed\n- Python Project and Assignment orchestration: 90 tests passed\n- product distribution and CLI qualification: 36 tests passed\n- code complexity budget: passed with zero blocking findings\n- staged repository gates, KFD evidence, KFD support matrix, and documentation contracts passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019fb2de-4a59-7bf4-8231-b32b62aa7e9b\"],\n  \"summary\": \"Deliver the Project, Work, and Agent first-layer golden path across GUI, TUI, and CLI.\",\n  \"verification\": [\"Project Work Agent product contract\", \"API, GUI, TUI, Work Dashboard, Python, and distribution test suites\", \"source acceptance and KFD evidence gates\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR refreshes checked-in KFD and qualification roots only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-30T23:12:43Z",
          "mergedAt": "2026-07-31T05:27:18Z",
          "additions": 19862,
          "deletions": 1322,
          "changedFiles": 130
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 40,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/40",
          "title": "fix(ci): finalize Alpha 4 publication runtime",
          "body": "## Summary\n- reconcile the failed Alpha publication merge back into development ancestry without changing the tree\n- pin Paper workflows and authority to protected Buildchain v3 runtime `2cd4e117742ca39fddd43e4244d01581cae75556`\n- preserve the Alpha 4 content and package version unchanged\n\n## Validation\n- pre/post ancestry reconciliation tree: `5f71f0d3d6636e9daf6b7fe6682925edb9ee70fe`\n- `make check`\n- `make pdf`\n- offline and live `buildchain paper preflight`\n- two independent clean Docker builds for `4d0cc04adaa70964fc622c416b72d16cbde04410`: qualifying, receipt `sha256:9e5abb43c69e7c731e639a0e94d84743d0be29e939000ae4ba737358b0140afd`",
          "author": "dongkeren",
          "createdAt": "2026-07-31T05:26:03Z",
          "mergedAt": "2026-07-31T05:27:37Z",
          "additions": 18,
          "deletions": 18,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 41,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/41",
          "title": "release(paper): publish 0.1.0-alpha.4 alpha",
          "body": "## Summary\n\nPromote `dev/v0/v0.1` to `alpha/v0/v0.1` through the protected Buildchain paper release flow.\n\n## Safety\n\n- Build and verification remain credential-free.\n- Exact artifact bytes are sealed before npm OIDC is available.\n- This PR does not bypass review or publish directly.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T05:28:05Z",
          "mergedAt": "2026-07-31T05:30:37Z",
          "additions": 18,
          "deletions": 18,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2020,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2020",
          "title": "feat(release): unify auditable demo refresh triggers",
          "body": "## Summary\n\n- Compile manual, Alpha, and Release events into one retained auditable-demo trigger plan.\n- Preserve manual Gate-only validation and manual full-media refresh, while forcing Alpha and Release candidates through the same full-media path.\n- Keep final promotion on the same `build.yml` execution contract and grant no publication or production-deployment authority.\n- Reuse the existing auditable-demo Passport tooling and refresh both workflow-authority and release-publication roots.\n\n## Verification\n\n- `./shifu test:auditable-demo` (42/42)\n- `./shifu check:gate-catalog`\n- `./shifu check`\n- `./shifu docs:check`\n- `./shifu check:source` (all product/source checks passed; the cold read-only pytest route was also rerun in the locked Shifu uv environment)\n\n## Evolution impact\n\nExtends the existing auditable-demo artifact pipeline. It does not introduce a second media generator, publisher, deployer, or release authority.\n\n## Governance risk\n\nThis changes release evidence/provenance workflow inputs. The new plan is read-only, source-bound, retained as an artifact, and explicitly carries `publicationAuthority: false`; README/site materialization and production deployment remain separately reviewed boundaries.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7b6b-ae6d-76cea57487f2\"],\n  \"summary\": \"Unify manual, Alpha, and Release auditable-demo media refresh planning behind one source-bound contract.\",\n  \"verification\": [\"./shifu test:auditable-demo\", \"./shifu check:source\"]\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T04:19:49Z",
          "mergedAt": "2026-07-31T05:43:40Z",
          "additions": 352,
          "deletions": 29,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2099,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2099",
          "title": "fix(paper): forward governance auditor authority",
          "body": "## Summary\n- declare the dedicated read-only Governance Auditor private-key secret on the sealed Paper release workflow\n- forward the same organization-visible secret from generated Paper callers\n- add workflow-surface and scaffold regressions without changing any App permission or token fallback\n\n## Incident evidence\nPaper Alpha 4 run `30606999420` completed reproducibility, then failed before publication because the nested authority workflow received an empty private-key input. Organization readback confirms the existing secret is `visibility=all`; the missing boundary was caller forwarding.\n\n## Validation\n- focused Paper workflow/scaffold regressions: 2 passed\n- `CI=true pnpm run check`: 1063 passed; site/workflow/action bundle checks passed",
          "author": "dongkeren",
          "createdAt": "2026-07-31T05:54:03Z",
          "mergedAt": "2026-07-31T05:59:54Z",
          "additions": 32,
          "deletions": 10,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2016,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2016",
          "title": "feat(release): generalize version-line authority",
          "body": "## Summary\n\n- establish one machine-readable version-line authority and reproducible exact projections\n- migrate branch, ruleset, runner, publication, KFD, candidate-ledger, and latency consumers to that authority\n- add a fail-closed tracked-source gate with synthetic v5/v6 and negative narrow-binding tests\n- remove the stale concrete runner-preset entry newly introduced in the maintainability manifest\n- bind the completed delivery to the existing Buildchain release-governance ADR\n\n## Validation\n\n- `./shifu check:version-line-authority`\n- `./shifu project-cut:queue-admission -- --base 3fc42839c38c6a0c63f4cc96c01f7609bcc4c614 --head HEAD`\n- `PATH=\"/Users/dkr/Code/kungfu-systems/kungfu/framework/core/.venv/bin:$PATH\" ./shifu check:source`\n- `./shifu build:core` (qualified on the original exact implementation tree; this linear replacement changes delivery history, the tracked-source scan fix, and its ADR evidence projection)\n- `git diff --check`\n\n## Assignment\n\n`2026-07-31-kungfu-version-line-authority-generalization`\n\nThis PR replaces #2011 with a fresh linear replay against the current protected base while the proof-window lock prevents another local delivery from invalidating the candidate. It preserves the exact implementation and source-gate fix and regenerates workflow, maintainability, publication, and ADR projections against the new base.\n\nNo live ruleset, runner, release, signing, notarization, or publication state is changed by this PR.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-7b6b-ae6d-76cea57487f2\"],\n  \"summary\": \"Generalize version-line authority and derive every operational projection from one data source\",\n  \"verification\": [\"version-line authority gate with synthetic v5/v6\", \"tracked-source negative fixtures\", \"full source acceptance\", \"qualified Core build\", \"merge-queue replay\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T03:54:50Z",
          "mergedAt": "2026-07-31T06:00:26Z",
          "additions": 1425,
          "deletions": 116,
          "changedFiles": 54
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 42,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/42",
          "title": "fix(ci): forward Alpha 4 governance authority",
          "body": "## Summary\n- reconcile the authority-gated Alpha merge back into development ancestry without changing the tree\n- pin Paper to protected Buildchain v3 runtime `4147226415630a0cba6bb3be56f32410fb56c2b1`\n- forward the existing organization-wide read-only Governance Auditor secret through the generated caller\n\n## Validation\n- pre/post ancestry tree: `2651da7a989dd733987e8f48111a13794d322535`\n- `make check` and `make pdf`\n- offline and live Paper preflight\n- two independent clean Docker builds for `8b8d14ce7cfb2b021510d66d707dbfa3f6745d6f`: qualifying, receipt `sha256:643ecb2662ccedf04296549c82ebc66d02f0debc38f07cef201c62388a2f5b5d`",
          "author": "dongkeren",
          "createdAt": "2026-07-31T06:04:21Z",
          "mergedAt": "2026-07-31T06:05:44Z",
          "additions": 19,
          "deletions": 18,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 43,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/43",
          "title": "release(paper): publish 0.1.0-alpha.4 alpha",
          "body": "## Summary\n\nPromote `dev/v0/v0.1` to `alpha/v0/v0.1` through the protected Buildchain paper release flow.\n\n## Safety\n\n- Build and verification remain credential-free.\n- Exact artifact bytes are sealed before npm OIDC is available.\n- This PR does not bypass review or publish directly.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T06:06:08Z",
          "mergedAt": "2026-07-31T06:07:37Z",
          "additions": 19,
          "deletions": 18,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2100,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2100",
          "title": "fix(signing): bind declared artifacts independently",
          "body": "## Summary\n- let declarative signing artifacts carry their own exact inventory without duplicating paths in workflow artifact uploads\n- retain byte-for-byte lifecycle manifest verification when the subject is covered there\n- fail closed when lifecycle evidence covers only part of a declared directory\n\n## Validation\n- `pnpm run check`\n- 1065 unit tests passed\n- 6 action bundles verified\n\n## Failure evidence\nKungfu Alpha Build run 30606449034 built the macOS product successfully, then failed while sealing the declared app bundle because its nested framework was outside the independent `artifact-paths` upload inventory.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T06:03:45Z",
          "mergedAt": "2026-07-31T06:10:09Z",
          "additions": 126,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2102,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2102",
          "title": "fix(signing): promote independent artifact binding",
          "body": "## Summary\n\nPromote the reviewed Buildchain development head into the protected artifact-signing authority so consumers can sign declared artifacts without repeating those paths in workflow artifact uploads.\n\nThe authority still verifies byte-for-byte lifecycle evidence when it covers a signing subject and fails closed on partial directory coverage.\n\n## Source\n\n- development head: `ffb99ba117bbf70476735231ff66ed1185aa90f0`\n- implementation PR: #2100\n- failing downstream evidence: kungfu-systems/kungfu Actions run `30606449034`\n\n## Validation\n\n- #2100 hosted checks: passed\n- #2100 merge-group checks: passed\n- `pnpm run check`: 1065/1065 tests passed\n- action bundle integrity: 6/6 passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T06:10:59Z",
          "mergedAt": "2026-07-31T06:12:24Z",
          "additions": 2733,
          "deletions": 569,
          "changedFiles": 78
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2101,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2101",
          "title": "fix(signing): bind declared subjects to lifecycle manifest",
          "body": "## Summary\n- include current-platform signing declarations in the build lifecycle manifest even when they are outside ordinary artifact upload paths\n- preserve fail-closed signing-request lifecycle binding for nested app-bundle files\n- document the evidence boundary and regenerate the committed Action/site projections\n\n## Regression\n- reproduces the Kungfu Alpha failure for `product/dist/desktop/mac-arm64/Kungfu Episodes.app/Contents/Frameworks/Electron Framework.framework/Versions/A/Electron Framework`\n- proves macOS declarations enter the manifest while Linux excludes them\n\n## Validation\n- `pnpm run check`\n- 1064 tests passed; action bundle integrity passed\n\nFollow-up for kungfu-systems/kungfu#2023 candidate Build run 30606449034.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T06:08:33Z",
          "mergedAt": "2026-07-31T06:14:57Z",
          "additions": 144,
          "deletions": 36,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2103,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2103",
          "title": "fix(paper): drop unused sealed package result",
          "body": "## Summary\n\n- stop the sealed publish job from requiring a legacy `package-result.json` that the publication-candidate workflow never produces\n- keep verification bound to the admitted npm package, tarball, publication manifest, reproducibility receipt, and sealed capability\n- add a workflow regression assertion for the absent legacy dependency\n\n## Failure evidence\n\nPaper Alpha 4 run `30608734268` passed candidate reproducibility and independent authority, then failed before public mutation because the publish job expected `.buildchain/paper-release/package-result.json`. The value was never used beyond a dead `void` reference.\n\n## Verification\n\n- `node --test tests/paper-sealed-release.test.mjs tests/build-surface.test.mjs` (95/95)\n- `CI=true corepack pnpm@11.7.0 run check` (1065/1065; workflows, site bundle, and 6 action bundles passed)",
          "author": "dongkeren",
          "createdAt": "2026-07-31T06:20:56Z",
          "mergedAt": "2026-07-31T06:29:27Z",
          "additions": 1,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 44,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/44",
          "title": "fix(ci): pin sealed Alpha 4 publication runtime",
          "body": "## Summary\n\n- reconcile the failed Alpha publication commit into dev with a tree-neutral merge\n- pin paper build and sealed release workflows to Buildchain `7c61f08514bfc29a8653c4efb4768cbca13da742`\n- refresh the exact contract lock and provisioning authority\n\n## Evidence\n\n- ancestry merge: `17b540cc9241f7901c56edb4a4c001c179b2ef48`\n- tree before/after ancestry merge: `a2b838ed06ebcef755ae4ff345e88e3807a80f1d`\n- exact source: `bed15ecf52d70d8a70bd658d5cb6be9eaa5e01f2`\n- online and offline paper preflight: local gates passed, exact runtime unchanged\n- `make check`: passed\n- qualifying two-clean build: passed, receipt `sha256:3a1e00808f4065e8d264402b8e65c7ca307373b4572b920695d7d3a387bba896`\n- npm tarball integrity: `sha512-GkNDm72AygMeOLnVPIr0HgBpajVKTITsDZ4nytt/0wXSzeacfxFiqve/99pYz3a4hN0dPk18L/JFsF8R8gUo8Q==`",
          "author": "dongkeren",
          "createdAt": "2026-07-31T06:33:58Z",
          "mergedAt": "2026-07-31T06:35:10Z",
          "additions": 18,
          "deletions": 18,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 45,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/45",
          "title": "release(alpha): publish 0.1.0-alpha.4",
          "body": "## Alpha publication intent\n\nPromote the protected dev source to Alpha after Buildchain sealed-paper runtime repairs.\n\n- source: `4690491712681327adefd188e7f6fdcde31bb4ab`\n- target baseline: `db72d26f1b4cb33baa99e84f2dd5392096f48685`\n- Buildchain runtime: `7c61f08514bfc29a8653c4efb4768cbca13da742`\n- local qualifying receipt: `sha256:3a1e00808f4065e8d264402b8e65c7ca307373b4572b920695d7d3a387bba896`\n- dev PR: #44 (independently approved and merged)\n\nThe prior failed Alpha merge is an ancestor through the tree-neutral dev reconciliation, so this promotion is fast-forward ancestry safe.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T06:35:33Z",
          "mergedAt": "2026-07-31T06:36:52Z",
          "additions": 18,
          "deletions": 18,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2028,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2028",
          "title": "fix(release): refresh declarative signing runtime",
          "body": "## Summary\n\nRefresh Kungfu Alpha build and promotion onto the protected Buildchain artifact-signing authority that supports independently declared binary artifacts.\n\n## Changes\n\n- pin Alpha build and promotion to the repaired immutable Buildchain runtime\n- regenerate the Alpha contract lock and release admission policy\n- refresh workflow authority, Gate bindings, publication roots, and semantic projections\n- keep consumer configuration declarative and credential-free\n\n## Verification\n\n- `KUNGFU_DEV_BRANCH=dev/v4/v4.0 ./shifu check:source`\n- targeted signing, promotion, Gate, and publication suites: 80 passed\n- full source suite: 827 Node tests, 116 runtime-upgrade tests, 69 desktop-update tests, and 40 Python tests passed\n- staged repository gate: passed\n\n## Evolution impact\n\nNone. This refreshes an existing protected runtime binding and does not alter a Kungfu architecture contract.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This release runtime refresh preserves the established declarative signing authority boundary\"\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T06:24:16Z",
          "mergedAt": "2026-07-31T06:38:00Z",
          "additions": 35,
          "deletions": 35,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 46,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/46",
          "title": "Prepare v0.1.0-alpha.4",
          "body": "Create the generated version-state commit for v0.1.0-alpha.4.\n\nBuildchain generated this PR because protected branch dev/v0/v0.1 rejected direct generated bookkeeping.\n\nRejected update: 4690491712681327adefd188e7f6fdcde31bb4ab -> 3442cb932b4f7c6637ce830c2da04ffa839cf9ec\n\nGitHub response: Changes must be made through a pull request.",
          "author": "app/kungfu-paper-release-bot",
          "createdAt": "2026-07-31T06:40:09Z",
          "mergedAt": "2026-07-31T06:41:31Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 339,
          "url": "https://github.com/kungfu-systems/build-images/pull/339",
          "title": "feat(demo-renderer): add responsive media renditions",
          "body": "## Summary\\n\\n- emit source-resolution MP4/WebM/poster assets plus deterministic 1280x720 MP4/WebM/GIF renditions from one frame set\\n- bind the shared derivation policy and dimensions in the renderer manifest\\n- qualify the 1920x1080 source fixture, ANSI color preservation, and byte-identical reruns\\n\\n## Validation\\n\\n- {\n  \"schema\": 1,\n  \"images\": [\n    {\n      \"name\": \"aeron-native-kit\",\n      \"contract_major\": 1,\n      \"platform\": \"linux-x64\",\n      \"base\": null,\n      \"publish\": true,\n      \"lock_status\": null,\n      \"test_commands\": [\n        \"/opt/aeron-native-kit/tests/smoke.sh\"\n      ]\n    },\n    {\n      \"name\": \"base-linux\",\n      \"contract_major\": 1,\n      \"platform\": \"linux-x64\",\n      \"base\": null,\n      \"publish\": true,\n      \"lock_status\": null,\n      \"test_commands\": [\n        \"cat /etc/os-release\",\n        \"git --version\",\n        \"id kungfu\"\n      ]\n    },\n    {\n      \"name\": \"clickhouse-server\",\n      \"contract_major\": 1,\n      \"platform\": \"linux-x64\",\n      \"base\": null,\n      \"publish\": true,\n      \"lock_status\": null,\n      \"test_commands\": [\n        \"clickhouse-server --version\",\n        \"clickhouse-client --version\"\n      ]\n    },\n    {\n      \"name\": \"comparator-formal-runner\",\n      \"contract_major\": 1,\n      \"platform\": \"linux-x64\",\n      \"base\": \"kungfu-verify\",\n      \"publish\": true,\n      \"lock_status\": null,\n      \"test_commands\": [\n        \"/opt/formal-performance/tests/smoke.sh\"\n      ]\n    },\n    {\n      \"name\": \"demo-renderer\",\n      \"contract_major\": 1,\n      \"platform\": \"linux-x64\",\n      \"base\": null,\n      \"publish\": true,\n      \"lock_status\": \"pending-first-publish\",\n      \"test_commands\": [\n        \"test \\\"$(node --version)\\\" = \\\"v24.0.0\\\"\",\n        \"test \\\"$(demo-renderer --version)\\\" = \\\"1.3.0\\\"\",\n        \"test \\\"$(node -p 'require(\\\"/opt/kungfu/demo-renderer/node_modules/@xterm/headless/package.json\\\").version')\\\" = \\\"5.5.0\\\"\",\n        \"ffmpeg -hide_banner -version | grep -F 'ffmpeg version'\",\n        \"ffprobe -hide_banner -version | grep -F 'ffprobe version'\",\n        \"test \\\"$(id -u)\\\" -ne 0\",\n        \"fc-match 'DejaVu Sans Mono' | grep -F 'DejaVuSansMono.ttf'\",\n        \"test -s /opt/kungfu/demo-renderer/licenses/DejaVu-fonts.copyright\",\n        \"test -s /opt/kungfu/demo-renderer/terminal-runtime-inventory.json\",\n        \"bash /opt/kungfu/demo-renderer/tests/smoke.sh\"\n      ]\n    },\n    {\n      \"name\": \"kungfu-native-linux-x64\",\n      \"contract_major\": 1,\n      \"platform\": \"linux-x64\",\n      \"base\": \"kungfu-verify\",\n      \"publish\": true,\n      \"lock_status\": null,\n      \"test_commands\": [\n        \"/opt/kungfu-native-source-build/tests/smoke.sh\"\n      ]\n    },\n    {\n      \"name\": \"kungfu-verify\",\n      \"contract_major\": 1,\n      \"platform\": \"linux-x64\",\n      \"base\": \"base-linux\",\n      \"publish\": true,\n      \"lock_status\": null,\n      \"test_commands\": [\n        \"git --version\",\n        \"fnm --version\",\n        \"uv --version\",\n        \"python3 --version\",\n        \"jq --version\"\n      ]\n    },\n    {\n      \"name\": \"latex-pdf-builder\",\n      \"contract_major\": 1,\n      \"platform\": \"linux-x64\",\n      \"base\": \"node24-pnpm\",\n      \"publish\": true,\n      \"lock_status\": null,\n      \"test_commands\": [\n        \"latexmk -version\",\n        \"biber --version\",\n        \"test \\\"$(pnpm --version)\\\" = \\\"11.7.0\\\"\",\n        \"test -n \\\"$(kpsewhich sfrm1000.pfb)\\\"\",\n        \"cp -R /opt/kungfu/latex-pdf-builder-smoke /tmp/latex-smoke && cd /tmp/latex-smoke && pnpm run pdf && test -s _build/main.pdf && sha256sum _build/main.pdf\"\n      ]\n    },\n    {\n      \"name\": \"native-linux-x64\",\n      \"contract_major\": 1,\n      \"platform\": \"linux-x64\",\n      \"base\": \"base-linux\",\n      \"publish\": true,\n      \"lock_status\": null,\n      \"test_commands\": [\n        \"cmake --version\",\n        \"ninja --version\",\n        \"python3 --version\",\n        \"ccache --version\"\n      ]\n    },\n    {\n      \"name\": \"node24-pnpm\",\n      \"contract_major\": 1,\n      \"platform\": \"linux-x64\",\n      \"base\": \"base-linux\",\n      \"publish\": true,\n      \"lock_status\": null,\n      \"test_commands\": [\n        \"node --version\",\n        \"corepack --version\",\n        \"test \\\"$(pnpm --version)\\\" = \\\"11.7.0\\\"\"\n      ]\n    },\n    {\n      \"name\": \"opencode-ci\",\n      \"contract_major\": 1,\n      \"platform\": \"linux-x64\",\n      \"base\": \"kungfu-verify\",\n      \"publish\": true,\n      \"lock_status\": null,\n      \"test_commands\": [\n        \"test \\\"$(opencode --version)\\\" = \\\"1.18.5\\\"\",\n        \"node --version\",\n        \"python3 --version\",\n        \"git --version\",\n        \"jq --version\",\n        \"test \\\"$(id -u)\\\" -ne 0\",\n        \"opencode-ci-run --help\",\n        \"opencode-ci-verify --help\"\n      ]\n    }\n  ]\n}\naeron-native-kit\nbase-linux\nclickhouse-server\nkungfu-verify <- base-linux\ncomparator-formal-runner <- kungfu-verify\ndemo-renderer\nkungfu-native-linux-x64 <- kungfu-verify\nnode24-pnpm <- base-linux\nlatex-pdf-builder <- node24-pnpm\nnative-linux-x64 <- base-linux\nopencode-ci <- kungfu-verify\nselective publish planner fixtures passed: 16\npublish provenance fixtures passed: 9\n{\n  \"schema\": 1,\n  \"tag\": \"v1.3.0-alpha.15\",\n  \"source\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n  \"publish_run\": \"https://github.com/kungfu-systems/build-images/actions/runs/30157192214\",\n  \"images\": [\n    {\n      \"name\": \"aeron-native-kit\",\n      \"image\": \"ghcr.io/kungfu-systems/build-images/aeron-native-kit\",\n      \"digest\": \"sha256:37c372b6207a129d752a5c43f25b0534e7ffde0c5f2d0c66476f767471488923\",\n      \"platform\": \"linux/amd64\",\n      \"contract_major\": 1,\n      \"parent_digest\": null,\n      \"content\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"release\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"target_ref\": \"alpha/v1/v1.3\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"test_commands\": [\n        \"/opt/aeron-native-kit/tests/smoke.sh\"\n      ]\n    },\n    {\n      \"name\": \"base-linux\",\n      \"image\": \"ghcr.io/kungfu-systems/build-images/base-linux\",\n      \"digest\": \"sha256:345ae09465844af6dd586edd36546a9d6a5b0f05678ad93a5cdf87222c4728c7\",\n      \"platform\": \"linux/amd64\",\n      \"contract_major\": 1,\n      \"parent_digest\": null,\n      \"content\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"release\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"target_ref\": \"alpha/v1/v1.3\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"test_commands\": [\n        \"cat /etc/os-release\",\n        \"git --version\",\n        \"id kungfu\"\n      ]\n    },\n    {\n      \"name\": \"clickhouse-server\",\n      \"image\": \"ghcr.io/kungfu-systems/build-images/clickhouse-server\",\n      \"digest\": \"sha256:d91e7dfae4d21c37a8e385c72a57965be9e24e86665e203d88247dcef333367f\",\n      \"platform\": \"linux/amd64\",\n      \"contract_major\": 1,\n      \"parent_digest\": null,\n      \"content\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"release\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"target_ref\": \"alpha/v1/v1.3\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"test_commands\": [\n        \"clickhouse-server --version\",\n        \"clickhouse-client --version\"\n      ]\n    },\n    {\n      \"name\": \"comparator-formal-runner\",\n      \"image\": \"ghcr.io/kungfu-systems/build-images/comparator-formal-runner\",\n      \"digest\": \"sha256:280cf0c70f50b611ec3b9466326d3058326c48a56c05a88061161ec25124491f\",\n      \"platform\": \"linux/amd64\",\n      \"contract_major\": 1,\n      \"parent_digest\": \"sha256:bf1f9c6736b6d17dc045147df4ce440d5d3b8e281fc17c26dc57fc32aea7f652\",\n      \"content\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"release\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"target_ref\": \"alpha/v1/v1.3\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"test_commands\": [\n        \"/opt/formal-performance/tests/smoke.sh\"\n      ]\n    },\n    {\n      \"name\": \"kungfu-native-linux-x64\",\n      \"image\": \"ghcr.io/kungfu-systems/build-images/kungfu-native-linux-x64\",\n      \"digest\": \"sha256:7d97728d6333159ef488d381838694ed3447fe66aca7641fb01d32e95bafc8d7\",\n      \"platform\": \"linux/amd64\",\n      \"contract_major\": 1,\n      \"parent_digest\": \"sha256:bf1f9c6736b6d17dc045147df4ce440d5d3b8e281fc17c26dc57fc32aea7f652\",\n      \"content\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"release\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"target_ref\": \"alpha/v1/v1.3\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"test_commands\": [\n        \"/opt/kungfu-native-source-build/tests/smoke.sh\"\n      ]\n    },\n    {\n      \"name\": \"kungfu-verify\",\n      \"image\": \"ghcr.io/kungfu-systems/build-images/kungfu-verify\",\n      \"digest\": \"sha256:bf1f9c6736b6d17dc045147df4ce440d5d3b8e281fc17c26dc57fc32aea7f652\",\n      \"platform\": \"linux/amd64\",\n      \"contract_major\": 1,\n      \"parent_digest\": \"sha256:345ae09465844af6dd586edd36546a9d6a5b0f05678ad93a5cdf87222c4728c7\",\n      \"content\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"release\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"target_ref\": \"alpha/v1/v1.3\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"test_commands\": [\n        \"git --version\",\n        \"fnm --version\",\n        \"uv --version\",\n        \"python3 --version\",\n        \"jq --version\"\n      ]\n    },\n    {\n      \"name\": \"latex-pdf-builder\",\n      \"image\": \"ghcr.io/kungfu-systems/build-images/latex-pdf-builder\",\n      \"digest\": \"sha256:bb6c88bf64561cffb2a16bb48550645355f792dda4ed82741d804b90911fe27d\",\n      \"platform\": \"linux/amd64\",\n      \"contract_major\": 1,\n      \"parent_digest\": \"sha256:c2b6a68ab21142117329f995d78e5e0d02b4647fc28f615c2a25011b83a09014\",\n      \"content\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"release\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"target_ref\": \"alpha/v1/v1.3\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"test_commands\": [\n        \"latexmk -version\",\n        \"biber --version\",\n        \"test \\\"$(pnpm --version)\\\" = \\\"11.7.0\\\"\",\n        \"test -n \\\"$(kpsewhich sfrm1000.pfb)\\\"\",\n        \"cp -R /opt/kungfu/latex-pdf-builder-smoke /tmp/latex-smoke && cd /tmp/latex-smoke && pnpm run pdf && test -s _build/main.pdf && sha256sum _build/main.pdf\"\n      ]\n    },\n    {\n      \"name\": \"native-linux-x64\",\n      \"image\": \"ghcr.io/kungfu-systems/build-images/native-linux-x64\",\n      \"digest\": \"sha256:030a6fb5d79976fe707904c4f791683586a5d618b6dcca8d7c42d613f52742dc\",\n      \"platform\": \"linux/amd64\",\n      \"contract_major\": 1,\n      \"parent_digest\": \"sha256:345ae09465844af6dd586edd36546a9d6a5b0f05678ad93a5cdf87222c4728c7\",\n      \"content\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"release\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"target_ref\": \"alpha/v1/v1.3\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"test_commands\": [\n        \"cmake --version\",\n        \"ninja --version\",\n        \"python3 --version\",\n        \"ccache --version\"\n      ]\n    },\n    {\n      \"name\": \"node24-pnpm\",\n      \"image\": \"ghcr.io/kungfu-systems/build-images/node24-pnpm\",\n      \"digest\": \"sha256:c2b6a68ab21142117329f995d78e5e0d02b4647fc28f615c2a25011b83a09014\",\n      \"platform\": \"linux/amd64\",\n      \"contract_major\": 1,\n      \"parent_digest\": \"sha256:345ae09465844af6dd586edd36546a9d6a5b0f05678ad93a5cdf87222c4728c7\",\n      \"content\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"release\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"target_ref\": \"alpha/v1/v1.3\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"test_commands\": [\n        \"node --version\",\n        \"corepack --version\",\n        \"test \\\"$(pnpm --version)\\\" = \\\"11.7.0\\\"\"\n      ]\n    },\n    {\n      \"name\": \"opencode-ci\",\n      \"image\": \"ghcr.io/kungfu-systems/build-images/opencode-ci\",\n      \"digest\": \"sha256:4083ee089fa9a419f4915505094a6c1bcce433ff77455605ce8993af3b684ed3\",\n      \"platform\": \"linux/amd64\",\n      \"contract_major\": 1,\n      \"parent_digest\": \"sha256:bf1f9c6736b6d17dc045147df4ce440d5d3b8e281fc17c26dc57fc32aea7f652\",\n      \"content\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"release\": {\n        \"material_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"ref\": \"v1.3.0-alpha.15\",\n        \"source_sha\": \"7bc9d076ce85558703dd24313ace7103c68ff045\",\n        \"target_ref\": \"alpha/v1/v1.3\",\n        \"version\": \"1.3.0-alpha.15\"\n      },\n      \"test_commands\": [\n        \"test \\\"$(opencode --version)\\\" = \\\"1.18.5\\\"\",\n        \"node --version\",\n        \"python3 --version\",\n        \"git --version\",\n        \"jq --version\",\n        \"test \\\"$(id -u)\\\" -ne 0\",\n        \"opencode-ci-run --help\",\n        \"opencode-ci-verify --help\"\n      ]\n    }\n  ],\n  \"pending_first_publish\": [\n    \"demo-renderer\"\n  ]\n}\ncomparator pilot locks: ok\n{\n  \"schemaVersion\": 1,\n  \"contract\": \"kungfu-build-images-kfd123-check\",\n  \"status\": \"passed\",\n  \"buildchain\": {\n    \"configPath\": \".buildchain/buildchain.toml\",\n    \"alphaContractLockRef\": \"v2-alpha\",\n    \"alphaContractLockStatus\": \"unchanged\",\n    \"alphaContractDrift\": false,\n    \"alphaContractDigest\": \"sha256:9d5bef7245674767352cc2746d507d556a11d685502120c00176f1a15bade2ba\",\n    \"stableContractLockRef\": \"v2\",\n    \"stableContractLockStatus\": \"unchanged\",\n    \"stableContractDrift\": false,\n    \"stableContractDigest\": \"sha256:81c0ed79269d4b0c2f94c11cc316069db7b4264814f3170b3877a9f960ac0320\"\n  },\n  \"kfd1\": {\n    \"witness\": \".buildchain/kfd/kfd-1/build-images-contract-world.witness.json\",\n    \"surfaceCount\": 6\n  },\n  \"kfd2\": {\n    \"claim\": \".buildchain/kfd/kfd-2/release-claims.json\",\n    \"upstreamCount\": 2,\n    \"claimStatus\": \"passed\"\n  },\n  \"kfd3\": {\n    \"registry\": \".buildchain/kfd/kfd-3/surfaces.json\",\n    \"auditStatus\": \"passed\",\n    \"declared\": 4,\n    \"prebuildWitness\": \".buildchain/kfd/kfd-3/collaboration-interface.prebuild.json\",\n    \"artifactWitness\": \".buildchain/kfd/kfd-3/collaboration-interface.artifact.json\"\n  },\n  \"releasePassportSmoke\": {\n    \"ok\": true\n  }\n}\\n- \\n- \\n\\n## Release impact\\n\\nAdditive image-contract change on the v1.3 line. The renderer contract becomes 1.3.0; downstream adoption remains digest-pinned and requires the matching Buildchain responsive media profile.\\n\\nSigned-off-by: Keren Dong <[email-redacted]>\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T06:44:18Z",
          "mergedAt": "2026-07-31T06:48:30Z",
          "additions": 166,
          "deletions": 76,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 340,
          "url": "https://github.com/kungfu-systems/build-images/pull/340",
          "title": "chore(release): promote responsive demo renderer alpha",
          "body": "Promote the verified responsive Auditable Demo renderer through the governed Buildchain Alpha publication transaction.\n\nThis cut adds deterministic 1920x1080 source-resolution MP4/WebM/poster plus exact 1280x720 MP4/WebM/GIF renditions from one captured frame set. The renderer manifest binds the derivation policy and every output dimension; the smoke suite rejects smaller or non-16:9 source scenes.\n\nSource: dev/v1/v1.3@e0e8f7afd1f032deb2898dd1f8bd0cac833aab29\nImplementation PR: #339\nBuildchain Verify: run 30610551833\nDemo Renderer Qualification: run 30610551275\n\nBuildchain remains responsible for exact version selection, selective OCI publication, anonymous digest verification, and Release Passport evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T06:49:12Z",
          "mergedAt": "2026-07-31T06:52:23Z",
          "additions": 166,
          "deletions": 76,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2029,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2029",
          "title": "fix(release): pin signing lifecycle manifest authority",
          "body": "## Summary\n- pin Kungfu Alpha build and promotion to Buildchain v3 merge 0f2b2b0134b3fe071e7b57924f3d5fb1f5d241ec\n- bind declared current-platform signing artifacts into the build lifecycle manifest before hosted signing\n- refresh exact contract locks, workflow authority, publication roots, and regression expectations\n\n## Verification\n- 30 focused release/signing contract tests pass\n- release promotion rehearsal passes with no side effects\n- readonly agent bootstrap test passes with the framework Python environment on PATH\n- generated workflow/semantic/publication projections are clean\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Pins the existing accepted release-signing architecture to a later Buildchain v3 defect fix without changing an architecture contract or ADR record\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] none of the above\n\nThe exact Buildchain SHA and regenerated authority projections bind this release-evidence change; no credential material is introduced.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\nGoal: 2026-07-24-buildchain-linux-github-attestation",
          "author": "dongkeren",
          "createdAt": "2026-07-31T06:43:35Z",
          "mergedAt": "2026-07-31T07:08:14Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 249,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/249",
          "title": "fix(papers): materialize only pinned release artifacts",
          "body": "## Summary\n- retain all package registry versions as metadata\n- materialize bytes only for the exact pinned package version\n- preserve frozen legacy immutable index snapshots without re-reading historical bytes from the current package\n- fail if historical registry entries are accidentally rematerialized\n\n## Validation\n- `corepack pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/ --config.minimumReleaseAge=0`\n- `pnpm --config.minimumReleaseAge=0 run build`\n- `pnpm --config.minimumReleaseAge=0 run check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T06:55:06Z",
          "mergedAt": "2026-07-31T07:11:59Z",
          "additions": 132,
          "deletions": 105,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 341,
          "url": "https://github.com/kungfu-systems/build-images/pull/341",
          "title": "Prepare v1.3.0-alpha.20",
          "body": "Create the generated version-state commit for v1.3.0-alpha.20.\n\nBuildchain generated this PR because protected branch alpha/v1/v1.3 rejected direct generated bookkeeping.\n\nRejected update: 5accb093605447913c8e8ced4ceaa9e65c8ea18f -> b3cebc2deb5f140af74db24b1b45233ac6733ef1\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T07:07:46Z",
          "mergedAt": "2026-07-31T07:13:54Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2022,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2022",
          "title": "refactor(node): isolate watcher runtime thread",
          "body": "## Summary\n\nMove the long-lived Node watcher journal/reactor loop from a lifetime `uv_queue_work` job to one dedicated native thread. Preserve the current-state snapshot model through a one-slot coalescing N-API bridge, add explicit lifecycle and runtime metrics, and keep product snapshot meaning in System KFX and Domain Profiles.\n\n## Related issue\n\nAtlas goal: `2026-07-31-kungfu-node-kfx-watcher-runtime-boundary`\n\n## Changes\n\n- run watcher consumption on a dedicated native thread with stop/join cleanup\n- bound native-to-Node snapshot wakeups to one coalesced entry\n- expose versioned step, lock, bridge, and custom queue runtime statistics\n- qualify libuv-pool isolation, quit, addon cleanup, and a 512-frame slow-consumer native transport burst\n- run the focused watcher and native transport suites in qualified Core candidate builds\n- open the successor ADR required by the withdrawn historical watcher proposal\n\n## Verification\n\n- `./shifu build:core`\n- `./shifu test:node-watcher-runtime-boundary`\n- `./shifu test:agent-session-peer-transport:native`\n- `./shifu test:agent-session-peer-transport`\n- `./shifu test:native-loop-qualification`\n- `./shifu core:architecture:health`\n- `./shifu --filter @kungfu-tech/api build`\n- `./shifu check`\n- `./shifu docs:check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019fb66f-1186-7739-9bfa-6418f9d33278\"],\n  \"summary\": \"Stage the measured Node watcher lifecycle boundary without changing journal, RxCpp, replay, or product snapshot authority\",\n  \"verification\": [\"focused watcher lifecycle and libuv-pool probe\", \"real 512-frame native transport slow-consumer qualification\", \"qualified Core cross-platform candidate action\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\nThis extends the current Core/runtime Stage with a measured lifecycle boundary and does not allocate a new Era or transfer product authority into Core.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe qualified Core candidate action gains two exact-source runtime qualification commands; it does not publish or deploy.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated for the runtime behavior and known limits\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMTUta3VuZ2Z1LWNvcmUtbmF0aXZlLWtmeC1ydW50aW1lIiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMS1rdW5nZnUtbm9kZS1rZngtd2F0Y2hlci1ydW50aW1lLWJvdW5kYXJ5IiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiIwZTMzYmIwZGQyYjRhOTI0NmQwZWFmNDkzZWM3M2VhMzJmYTFiNmQxIiwicHVsbFJlcXVlc3RIZWFkIjoiYjU0OTJkMmE0MDFmZGNjY2NiZmZjYjZiOTI1ZWI4OTljOGVhZWUyYyIsInJlcGxheWVkQ2FuZGlkYXRlIjoiZTkzMjVlOGExMzMxMzJmYWNkMDMzZDFmYWJiYTM0NDQ5ZTQ0YTU4YSIsInJlcGxheWVkVHJlZSI6IjQ0YjFmMDM5NGU5MTM1ODEwNTJhYzExNDUwY2ViMzI5YzE0MWI2NmQiLCJxdWV1ZUF0dGVtcHQiOiJiNTQ5MmQyYTQwMWZkY2NjY2JmZmNiNmI5MjVlYjg5OWM4ZWFlZTJjQDBlMzNiYjBkZDJiNGE5MjQ2ZDBlYWY0OTNlYzczZWEzMmZhMWI2ZDEiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6M2Q4OTc4ZjU0ZTFlMjQyZjM1Y2ViZDZmNGMxYWYyZGRkYzkwZGJjNzE4NDdjMDI1NmJjM2MzYjkxZDlmMzA1OCIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjIxMzdhZWIxYTI4YjhmYTg0MzgzNTVmODhiMTlhMjRjZmNmMmFlZTVkNGZmNzJjNTc3YzA0NTY4YTQzNTU0NzAiLCJzaGEyNTY6M2Q4OTc4ZjU0ZTFlMjQyZjM1Y2ViZDZmNGMxYWYyZGRkYzkwZGJjNzE4NDdjMDI1NmJjM2MzYjkxZDlmMzA1OCJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Y2MTM4NWVhYTM4NzcxN2MiLCJsZWFzZVJvb3QiOiJzaGEyNTY6ZWRhNDhkYWI0MzA0MTgwMzM4NzRhZDkyMDc4ODViN2FiZTkzYzNjY2FkMDQxY2MzNGQwOTRlZDA5NjVmZWZhOCJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T04:31:55Z",
          "mergedAt": "2026-07-31T07:24:46Z",
          "additions": 861,
          "deletions": 137,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 250,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/250",
          "title": "fix(papers): validate materialized publication routes",
          "body": "## Summary\n- validate rendered paper outputs against manifest routes\n- require current package artifacts while allowing metadata-only historical versions\n- preserve canonical/latest and immutable-index checks\n\n## Verification\n- `pnpm --config.minimumReleaseAge=0 run build`\n- `pnpm --config.minimumReleaseAge=0 run check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T07:15:30Z",
          "mergedAt": "2026-07-31T07:28:09Z",
          "additions": 14,
          "deletions": 5,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2104,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2104",
          "title": "feat(auditable-demo): qualify responsive media renditions",
          "body": "## Summary\n\n- add the `responsive-web-delivery-v1` media profile for one source frame set with qualified 1080p and 720p MP4/WebM renditions\n- bind role, MIME, dimensions, byte budgets, derivation policy, and media qualification root into Gate receipts and reusable workflow outputs\n- preserve the existing web-delivery qualification and add an exact 1920x1080 responsive qualification baseline\n\n## Verification\n\n- `corepack pnpm run check` (1066 tests, 1066 passed)\n- responsive and legacy qualification workflow: https://github.com/kungfu-systems/buildchain/actions/runs/30612064858\n- responsive qualification root: `sha256:1c588662db5abcc6776a43b3210f43555161b55ddf8aa4aa4530371bc1d26ec8`\n- qualification evidence root: `sha256:5bebb7ca41b7b509d63293c3c363fbff917d188fe1d6ae19a73d33424ea623ed`",
          "author": "dongkeren",
          "createdAt": "2026-07-31T07:18:48Z",
          "mergedAt": "2026-07-31T07:32:55Z",
          "additions": 729,
          "deletions": 72,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2026,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2026",
          "title": "fix(work-design): bind open-card history to installed Work",
          "body": "## Summary\n\nBind Atlas open-card planning to verified installed Kungfu Work history before Work History Selector and Work Design Advisor run.\n\n## Changes\n\n- Compile selector candidates from verified, settled, sealed global Work coordinates.\n- Deduplicate replicas by immutable state root and expose exact proof, projection, count, state, and coverage bindings.\n- Keep the Shifu open-card preflight build-free on POSIX and Windows.\n- Fail closed in Atlas unless a human explicitly requests manual fallback.\n\n## Verification\n\n- ./shifu check:source\n- ./shifu check:work-design-open-card\n- ./shifu test:work-design-open-card (11 passed)\n- node --test scripts/check-shifu-entry-contract.test.mjs (23 passed)\n- Atlas open-card and skill policy tests (48 passed)\n- Live read-only canary against installed global Work (200 candidates; partial coverage disclosed; 0 writes)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-77d5-a9ce-e7c798e3a623\"],\n  \"summary\": \"Bind open-card Selector and Advisor input to verified installed global Work history without moving capture authority.\",\n  \"verification\": [\"source acceptance\", \"work-design open-card contract and tests\", \"build-free Shifu entry tests\", \"Atlas fail-closed policy tests\", \"read-only installed Work canary\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\nThis extends the current Project Cut / Work Design stage with a verified installed-history producer and preserves all existing authority boundaries.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T06:03:27Z",
          "mergedAt": "2026-07-31T07:35:26Z",
          "additions": 471,
          "deletions": 7,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2105,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2105",
          "title": "fix(web-surface): preserve metadata-only paper history",
          "body": "## Summary\n- distinguish declared historical paper prefixes from locally materialized prefixes\n- preserve every declared prefix from deletion while uploading only versions carrying the additive `immutableIndex` envelope\n- retain legacy all-prefix materialization when no envelope exists\n- add the exact metadata-only history regression and refresh generated site documentation\n\n## Incident replay\nSite PR #251 failed closed during `Plan pull request preview` because alpha.0/1/3 remain registry history but are intentionally not rematerialized from old packages. With this change, exact artifact planning preserves all nine paper prefixes and uploads only alpha.4 for the qualified fast path.\n\n## Verification\n- `node --test tests/web-surface.test.mjs` -> 52 passed\n- `pnpm run check` -> 1070 passed, 0 failed; 6 action bundles consistent\n- exact site artifact `deploy-plan` -> fast path `sha256:8aa518280b04eedef0af8e3e2f248adcb28b0022e0bbc95e36f3b1331d21341d`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T07:40:55Z",
          "mergedAt": "2026-07-31T07:47:12Z",
          "additions": 114,
          "deletions": 21,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2034,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2034",
          "title": "fix(kfx): align bundled capabilities with core policy",
          "body": "## Summary\n\n- admit the bundled `projects` capability in the embedded Core KFX ceiling\n- validate every shipped extension manifest against that ceiling\n- align Work Dashboard fixtures with the current All Work surface\n- refresh generated KFD and maintainability evidence\n\n## Validation\n\n- `./shifu test:kfx-profile-suite`\n- `./shifu check:kfx-identity-neutral-authority --identity-neutral-only`\n- `node --test scripts/readonly-agent-bootstrap.test.mjs`\n- staged repository gate (commit hook)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Aligns an already shipped bundled capability with the existing embedded Core KFX policy without changing an architecture contract or ADR record\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Generated evidence is current",
          "author": "dongkeren",
          "createdAt": "2026-07-31T08:02:32Z",
          "mergedAt": "2026-07-31T08:15:56Z",
          "additions": 74,
          "deletions": 42,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 252,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/252",
          "title": "ci(web-surface): pin paper history validation runtime",
          "body": "## Summary\n- pin non-production web-surface validation to protected Buildchain v3 merge `5d18e3c40fe58ea7010971cf655fc273dc9e3575`\n- leave main/production selection on official stable `v3`\n- avoid moving unpublished `v3-alpha` while allowing required PR checks to exercise the protected metadata-only history fix\n\n## Evidence\n- Buildchain PR #2105 independently approved and merge-queued at the exact source\n- trusted dispatch run 30614137757 resolved that SHA and passed the exact site alpha.4 deployment plan\n- site PR #251 previously failed closed on the older `v3-alpha` planner\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T07:53:21Z",
          "mergedAt": "2026-07-31T08:18:55Z",
          "additions": 10,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 253,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/253",
          "title": "chore(papers): pin machine life alpha.4",
          "body": "## Summary\n- pin `@kungfu-tech/paper-kfd-machine-life-roadmap@0.1.0-alpha.4`\n- bind exact npm integrity, upstream tag/source, Release Passport, artifact digests, and deterministic propagation key\n- qualify the four-file package-pin-only Papers fast path on the protected history-aware Buildchain shell\n\n## Exact evidence\n- source: `3442cb932b4f7c6637ce830c2da04ffa839cf9ec`\n- release passport: `sha256:2eb288fab240fd895862a51d6bace3f5a833517327067eec98d58b7bc84a437f`\n- lock: `sha256:ddb2b0090c8578f46b5d5883e6b97517192a88bf56eea18ecb1b08468e3b58de`\n- qualification: `sha256:8aa518280b04eedef0af8e3e2f248adcb28b0022e0bbc95e36f3b1331d21341d`\n\n## Verification\n- exact rebase on site main `412b734d3e98c17cb7a78de7456e29c98f8f0930`\n- `pnpm --config.minimumReleaseAge=0 run build`\n- `pnpm --config.minimumReleaseAge=0 run check`\n- `git diff --check`\n\nProduction remains not requested.\n\nSupersedes #251 solely to restore independent author/CODEOWNER review separation.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T08:21:02Z",
          "mergedAt": "2026-07-31T08:34:20Z",
          "additions": 85,
          "deletions": 7,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2036,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2036",
          "title": "fix(windows): preload sibling libnode for TUI bootstrap",
          "body": "## Summary\n\n- preload the packaged sibling `libnode.dll` by exact path before loading `kungfu_node_host.dll` on Windows\n- preserve the Python fallback for incomplete product layouts while releasing native handles on failed admission\n- remove the deterministic `No module named kungfu` fallback seen in Windows Alpha installed-TUI qualification\n\n## Evidence\n\n- failed Alpha A/B control run `30613558251`, Windows job `91102078593`: full package build reached installed TUI bootstrap, then fell through to Python with `No module named kungfu`\n- DARKHERO `dumpbin /dependents` and `/exports`: host depends on sibling `libnode.dll` and exports `kungfu_node_run`\n- direct Windows loader reproduction: host load succeeds after exact-path `libnode.dll` preload\n- pre-commit staged gate passed, including 73 dev-latency tests, 137 docs tests, Rust format/clippy, and complete Rust workspace tests\n- `cargo test --manifest-path crates/Cargo.toml -p kungfu-trunk`: 53/53 passed\n\n## Scope boundary\n\nThis PR fixes the product bootstrap prerequisite. The five-group same-SHA sccache/Defender/power-plan A/B resumes only after the fix is merged and has an exact successful dev Alpha preflight.\n\nGoal: `2026-07-31-kungfu-windows-alpha-build-performance`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Windows packaged runtime loader bugfix without accepted ADR record changes\"\n}\n-->\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTMxLWt1bmdmdS13aW5kb3dzLWFscGhhLWJ1aWxkLXBlcmZvcm1hbmNlIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiIzYzVjM2Q3NTg1MDVhY2UwZWU4ZDhhYWVlODQzMDcxMzBlNGRiZmRhIiwicHVsbFJlcXVlc3RIZWFkIjoiZTQyN2RjMzViMTNjNWI0OGVhMzQwMjZmNjgwNTA2YjVhNDFiYWU4YyIsInJlcGxheWVkQ2FuZGlkYXRlIjoiMjA2ZWQ3MWQ3YmY3ZTc2MmYxYjM5ZTU3MTYyOTdlNGM5MDI2NDlmZCIsInJlcGxheWVkVHJlZSI6ImNlOTUyOTczZGM0MzZmNTNhMGY5ZDc1MWYzYTM5MzY5NmE4MmI4OWEiLCJxdWV1ZUF0dGVtcHQiOiJlNDI3ZGMzNWIxM2M1YjQ4ZWEzNDAyNmY2ODA1MDZiNWE0MWJhZThjQDNjNWMzZDc1ODUwNWFjZTBlZThkOGFhZWU4NDMwNzEzMGU0ZGJmZGEiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6NWQzYzg2ZDVkZDhiZWY0ZDdhOWM0ODg3ZjE3ZWJkMmNmZjQ0Mzg2ZGZiYjU3YmVmNzFkY2JlNmQ2MGJkNjA5ZSIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjA4ODM2MTllZTc3MmYwNDZlNTMyMmQyMjU5M2ViYjVhMzI2ZGQ2YWIyZjhmYmUzMzJkNzljMjE2MmIzYzcwYTkiLCJzaGEyNTY6NWQzYzg2ZDVkZDhiZWY0ZDdhOWM0ODg3ZjE3ZWJkMmNmZjQ0Mzg2ZGZiYjU3YmVmNzFkY2JlNmQ2MGJkNjA5ZSJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6YjAyNDJhMTRmYTI0NWVjNjZjN2ZhZDQ0ZGUzNGQ2MDI4ZDExYTgxNWQ4ZmI3N2Q3YzA4Zjg0ZTQ5MDMwNDlkNCJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T08:22:36Z",
          "mergedAt": "2026-07-31T08:38:13Z",
          "additions": 25,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2035,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2035",
          "title": "fix(kfx): admit Projects capability in Core policy",
          "body": "## Summary\n- admit the existing Projects application service through the Core-owned KFX capability ceiling\n- advance the governed KFX contract to v13 and refresh exact cross-language roots and canonical policy projections\n- update the work-dashboard qualification fixtures from the retired Portfolio wording to the current All Work surface\n\n## Verification\n- `./shifu build`\n- `node scripts/run-native-kfx-admission-tests.mjs`\n- install plus both work-dashboard fixtures pass\n- `./shifu qualify:embedding-membranes` passes, followed by two further three-trial dual-engine passes\n- release promotion rehearsal passes 16/16 with no side effects\n- commit hooks pass apart from one explained concurrent-ref observation; the isolated rerun passes\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Corrects capability and qualification projections for the already governed Projects application service and current All Work UI; no new architectural decision is introduced\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Governed projections and fixtures updated with the behavior\n\nGoal: 2026-07-24-buildchain-linux-github-attestation\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T08:19:00Z",
          "mergedAt": "2026-07-31T08:53:30Z",
          "additions": 61,
          "deletions": 53,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 254,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/254",
          "title": "fix(papers): derive propagation diff from event bounds",
          "body": "## Summary\n- derive push changed files from the authoritative `before..GITHUB_SHA` event bounds\n- derive PR changed files from the authoritative base/head trees\n- fetch the exact bounded commits before diffing, with the existing full-tree fallback for unsupported events\n\nThis closes the shallow-checkout false full-site classification observed on main run `30616779218`. It does not weaken immutable S3 verification.\n\n## Verification\n- `pnpm --config.minimumReleaseAge=0 run build`\n- `pnpm --config.minimumReleaseAge=0 run check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T08:39:23Z",
          "mergedAt": "2026-07-31T08:56:16Z",
          "additions": 17,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2038,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2038",
          "title": "fix(verify): expose bounded fixture diagnostics",
          "body": "## Summary\n\n- preserve bounded multi-line verifier diagnostics for native fixture failures\n- expose the actionable assertion from the cross-platform storage binding failure on the next exact-source Dev Verify run\n\nThe packaged KFX capability expectation is now provided by merged PR #2035; this rebased delta contains only the diagnostic correction.\n\n## Validation\n\n- `node --check scripts/verify.mjs`\n- `pnpm exec biome check --no-errors-on-unmatched scripts/verify.mjs`\n- staged repository gate (commit hook)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Improves bounded verifier diagnostics without changing an architecture contract or ADR record\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Diagnostic output remains bounded and redacted by the existing verifier path",
          "author": "dongkeren",
          "createdAt": "2026-07-31T08:50:54Z",
          "mergedAt": "2026-07-31T09:03:18Z",
          "additions": 5,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2106,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2106",
          "title": "fix(web-surface): accept fast-path health evidence",
          "body": "## Summary\n- require `sync-publication-fast-path` instead of full static sync for managed-network health when a bounded publication fast path is active\n- retain deployment-manifest and S3 object verification requirements\n- regress the package-pin-only managed-network health path\n\n## Validation\n- `node --test --test-name-pattern=\"publication package-pin fast path touches one surface\" tests/web-surface.test.mjs`\n- `pnpm run check` (1070 tests passed)\n\nDownstream evidence: site-libkungfu-dev PR #255 applied the bounded fast path successfully but health rejected it only because `sync-static-artifact` was hard-coded.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T09:06:59Z",
          "mergedAt": "2026-07-31T09:13:10Z",
          "additions": 16,
          "deletions": 7,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2037,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2037",
          "title": "fix(product): bind installed TUI to assembled runtime",
          "body": "## Summary\n\n- resolve the assembled runtime entry from the installed manifest\n- bind child CLI calls from the installed TUI smoke to that runtime\n- cover the launcher/runtime separation with a focused regression test\n\n## Failure evidence\n\nAWS Windows qualification run 30611818245 assembled and sealed the product, then failed the installed TUI bootstrap because the child CLI inherited the launcher directory as KUNGFU_DIR and fell back to the standalone uv Python, which had no kungfu module.\n\n## Verification\n\n- focused installed TUI runtime-binding test passed\n- Biome check passed for all three changed files\n- repository staged gate passed twice, including the commit hook\n- DCO sign-off present\n\n## Boundary\n\nThis changes only installed-product smoke binding. The shipped manifest and runtime layout remain unchanged.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fix installed TUI runtime selection without changing architecture or product contracts\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T08:44:02Z",
          "mergedAt": "2026-07-31T09:14:07Z",
          "additions": 67,
          "deletions": 25,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2032,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2032",
          "title": "feat(auditable-demo): qualify responsive media renditions",
          "body": "## Summary\n\n- run the auditable demo through Buildchain `responsive-web-delivery-v1` with one exact 1080p source scene and deterministic 720p renditions\n- bind the media profile and qualification root into the Kungfu release Passport\n- verify and materialize README evidence by declared media roles, roots, dimensions, and derivation policy\n- pin Buildchain PR #2104 and the Build Images alpha.20 renderer by immutable SHA/digest\n\n## Verification\n\n- `node --test scripts/auditable-demo-passport.test.mjs scripts/auditable-demo-workflow.test.mjs scripts/update-auditable-demo-readme.test.mjs` (24 passed)\n- staged repository gate and source acceptance passed during commit\n- Buildchain qualification: https://github.com/kungfu-systems/buildchain/actions/runs/30612064858\n- Buildchain merged source: `0e4ac58013ff3e09abb18da9896fad5f5b823ef7`\n- renderer: `ghcr.io/kungfu-systems/build-images/demo-renderer@sha256:b70a2f5631665f685280bc9d7434c5ed5cf48b760b728873734d0c47bff72b25`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-786d-aa24-a97705e13917\"],\n  \"summary\": \"Qualify exact responsive auditable-demo media renditions from one authoritative capture.\",\n  \"verification\": [\n    \"24 targeted auditable-demo tests passed\",\n    \"Kungfu source acceptance and exact queue admission passed\",\n    \"Buildchain responsive-web-delivery-v1 qualification run 30612064858 passed\"\n  ]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T07:44:34Z",
          "mergedAt": "2026-07-31T09:25:36Z",
          "additions": 216,
          "deletions": 42,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 256,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/256",
          "title": "ci(web-surface): pin fast-path health runtime",
          "body": "## Summary\n- pin the web-surface reusable workflow to Buildchain PR #2106 merge `969e6ec1315fc7395bce198e3e5252181bf4eb93`\n- accept that exact protected shell in the site contract check\n- add the exact alpha.4 paper package to pnpm minimum-release-age exclusions without weakening the global age policy\n\n## Validation\n- `pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `npm run build`\n- `npm run check`\n\nThis runtime fixes the managed-network health evidence mismatch observed by paper propagation replay PR #255.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T09:15:54Z",
          "mergedAt": "2026-07-31T09:33:04Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2040,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2040",
          "title": "feat(work-design): auto-adopt bounded open-card advice",
          "body": "## Summary\n\nUse verified historical Work guidance to improve open-card splitting without adding a default human approval gate.\n\n## Changes\n\n- Add a rooted native auto-adoption policy for complete, non-empty, verified medium/high-confidence advice.\n- Permit only the disclosed `global-work-partial` gap on the automatic path.\n- Return `human-decision-required` for insufficient history, low confidence, or unapproved gaps.\n- Preserve explicit human accepted/adapted/overridden/insufficient-history dispositions and manual fallback as exceptional paths.\n- Keep the original human-authorized work definition and capture-only authority unchanged.\n\n## Verification\n\n- `./shifu check:work-design-open-card`\n- `./shifu test:work-design-open-card` (16 passed)\n- staged pre-commit gate (passed)\n- `./shifu check:source` reached 846/847 tests; the sole local failure was the cold bootstrap fixture because bare `pytest` was absent from PATH, unrelated to changed surfaces\n- Atlas open-card, inbox sync, and skill policy tests (56 passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-77d5-a9ce-e7c798e3a623\"],\n  \"summary\": \"Auto-adopt bounded verified open-card advice while escalating only exceptions that require human judgment.\",\n  \"verification\": [\"work-design open-card contract and tests\", \"staged source and documentation gates\", \"Atlas client and skill policy tests\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\nThis extends the current Project Cut and Work Design open-card stage with a rooted bounded auto-adoption policy while preserving all Assignment, Work Control, and capture authority boundaries.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T09:04:02Z",
          "mergedAt": "2026-07-31T09:35:47Z",
          "additions": 320,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 255,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/255",
          "title": "chore(papers): replay machine life alpha.4 propagation",
          "body": "## Summary\n- replay the already sealed alpha.4 package propagation after event-bounded changed-file detection landed\n- use a temporary dev-only npm alias to produce a pnpm-authored lockfile delta without changing package bytes or integrity\n- keep the release lock root and qualification root unchanged\n\n## Exact boundary\n- changed paths: package.json, pnpm-lock.yaml, src/publication-packages.json, and the alpha.4 release lock\n- qualification: exact-package-pin-only\n- qualification root: `sha256:8aa518280b04eedef0af8e3e2f248adcb28b0022e0bbc95e36f3b1331d21341d`\n- immutable upload prefix: `archive/kfd-machine-life-roadmap/v0.1.0-alpha.4`\n\nA follow-up four-file fast-path cleanup will remove the temporary alias after staging succeeds.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T08:57:06Z",
          "mergedAt": "2026-07-31T09:37:03Z",
          "additions": 10,
          "deletions": 3,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 258,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/258",
          "title": "chore(papers): remove alpha.4 propagation replay alias",
          "body": "## Summary\n- remove the temporary exact-package replay alias after alpha.4 staging qualification succeeded\n- restore stable JSON key ordering in the propagation lock and publication package list\n- retain the real alpha.4 package pin, release lock, Buildchain runtime pin, and package-scoped age exclusion\n\n## Validation\n- `pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `npm run build`\n- `npm run check`\n\nStaging qualification evidence: run `30620592402`, source `1f429822f559281efeb13efbd644a2ea517932c2`.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T09:41:05Z",
          "mergedAt": "2026-07-31T09:43:36Z",
          "additions": 3,
          "deletions": 10,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2019,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2019",
          "title": "fix(shifu): bind Windows consumer to exact closure",
          "body": "## Summary\n\n- replace the Windows consumer native-file count heuristic with the exact qualified closure: `pykungfu.cp313-win_amd64.pyd` and `libnode.dll`\n- keep independent PE magic verification for both named files\n- bind the exact closure into the workflow contract test, ADR, Gate authority, and publication-control projection\n\n## Related issue\n\n- Native Assignment `2026-07-30-kungfu-qualified-core-windows-x86-64-consumer`\n- Parent Initiative `2026-07-30-kungfu-qualified-core-developer-acceleration-family`\n- Repairs the post-merge consumer failure from PR #1990\n\n## Production evidence\n\n- merge-group candidate job `91059188766` produced the valid two-file native closure plus separately verified build metadata\n- exact Windows candidate artifact root: `sha256:bec363f29d51bc499ed3325465ba9b28d9880201af37afdf55a1259eba654232`\n- post-promotion consumer job `91065710072` materialized the bundle, then failed only on the invalid `nativeFiles.Count -lt 3` heuristic\n\n## Verification\n\n- focused artifact and workflow-authority tests: pass\n- Gate catalog, publication control plane, ADR map, actionlint, and diff hygiene: pass\n- cold read-only source bootstrap with the governed pytest 9.1.1 tool: pass, including nested full `shifu check:source`\n- full staged pre-commit gate: pass\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-019fab1a-2853-737e-8c67-a9b1aa9035aa\"],\n  \"summary\": \"Bind Windows Qualified Core consumer verification to the exact two-file native closure instead of an invalid file-count heuristic.\",\n  \"verification\": [\"exact Windows closure contract\", \"PE magic verification\", \"cold read-only nested source acceptance\", \"independent protected review\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [x] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] none of the above\n\nThe repair adds no credentials, registry writes, services, scheduled tasks, firewall changes, installed-product changes, or global Python mutation.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] ADR implementation evidence is bound to the protected delivery\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LXF1YWxpZmllZC1jb3JlLWRldmVsb3Blci1hY2NlbGVyYXRpb24tZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtd2luZG93cy14ODYtNjQtY29uc3VtZXIiLCJkZWxpdmVyeUNsYXNzIjoibmF0aXZlLXByb29mLXJlcXVpcmVkIiwiZGV2SGVhZCI6ImJlMjYwM2NjYmQ1NDNjZTVhNWM2NjMzNjcxMTc1MDQ3ZTYxNzg4MWMiLCJwdWxsUmVxdWVzdEhlYWQiOiI0NzVhZTJlZGVhMGUwYThkOGFlNGFhMGFiMjZlZWZhMzQ1NTNmMjdlIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiJlMDdhZTE1ZDI1NzBjOGI5MDE3MmJjYzBhNWY1MGQ0ZTZjODBlYzg5IiwicmVwbGF5ZWRUcmVlIjoiY2JhZDkxZTAxOTY5ZWY5MzA4NTJjYTMxOWZmMWRiYzRmZTJkYmNiZSIsInF1ZXVlQXR0ZW1wdCI6IjQ3NWFlMmVkZWEwZTBhOGQ4YWU0YWEwYWIyNmVlZmEzNDU1M2YyN2VAYmUyNjAzY2NiZDU0M2NlNWE1YzY2MzM2NzExNzUwNDdlNjE3ODgxYyIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjpiYTUxZjI5ZmNhOWNlMWJmZWQ2NWY5YTI3ZDU3ZTgyMzBlYzZiMjEzM2MxNWNkNjQxOTkwM2Y0MDJlY2ExNjJhIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6YmE1MWYyOWZjYTljZTFiZmVkNjVmOWEyN2Q1N2U4MjMwZWM2YjIxMzNjMTVjZDY0MTk5MDNmNDAyZWNhMTYyYSIsInNoYTI1NjplYzFhOTVlN2Y4MDdhNWQ2ZTBkOGVkMTc1MjRiMTEwZTFjZTgyYzc4ZmJlMWQ2NzZhMWUzNjlkMzBiMmJiN2M1Il0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvOTZkM2JmZjU3MWIwNGJiMiIsImxlYXNlUm9vdCI6InNoYTI1Njo1MjhjODI4ODJhN2U1ZThlMGRmYjFjZjdkZDhmMzJhZGNjMjgwNzU5NWVkNzNmOWMwOTUxNzVhNjIxNDc2OGFkIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T04:06:57Z",
          "mergedAt": "2026-07-31T09:56:59Z",
          "additions": 20,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 78,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/78",
          "title": "docs(paper): publish continuity white paper alpha.11",
          "body": "## Summary\n\n- Reposition the White Paper around continuity for long-running agent work.\n- Introduce the Project / Work / Agent product model, Agent Work Lab, the Foundation Triad, and the evidence ladder without overloading first-time readers.\n- Add a clear bridge from present-day work continuity to the Machine Life research direction.\n- Refresh the publication with a commercial editorial system and a real Kungfu CLI evidence view.\n- Prepare `0.1.0-alpha.11` under the Buildchain v3 publication contract.\n\n## Checks\n\n- [x] `make check`\n- [x] `make pdf`\n- [x] `npm run build`\n- [x] `npm pack --dry-run --json`\n- [x] Rendered and visually reviewed all 16 PDF pages\n- [x] Buildchain release manifest and passport generated by the pinned Docker toolchain\n\n## Governance\n\n- [x] The change is scoped to the White Paper publication.\n- [x] The Alpha channel remains pre-release only; no stable release is requested.\n- [x] Public copy and release metadata contain no internal control-plane details.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T10:27:11Z",
          "mergedAt": "2026-07-31T10:28:05Z",
          "additions": 2234,
          "deletions": 1595,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 80,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/80",
          "title": "chore(release): describe alpha.11 impact",
          "body": "## Summary\n\n- Correct the release impact contract for `0.1.0-alpha.11`.\n- Point the declared channel and target ref to Alpha rather than stable release.\n- Describe the actual continuity narrative, Project / Work / Agent model, Foundation Triad and Machine Life bridge, and publication design impact.\n\n## Checks\n\n- [x] `jq empty release-impact.json`\n- [x] `npm run check`\n- [x] `git diff --check`\n\n## Governance\n\n- [x] Metadata-only correction; the reviewed PDF candidate is unchanged.\n- [x] No stable release is requested.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T10:32:41Z",
          "mergedAt": "2026-07-31T10:33:36Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 81,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/81",
          "title": "chore(release): sync alpha promotion base",
          "body": "## Summary\n\n- Merge the current `alpha/v0/v0.1` history into `dev/v0/v0.1` before the Alpha 11 promotion.\n- Preserve forward-only channel ancestry required by the protected promotion PR.\n- Keep the candidate tree byte-identical to the already reviewed dev candidate.\n\n## Checks\n\n- [x] `git diff --exit-code origin/dev/v0/v0.1..HEAD`\n- [x] No publication source, metadata, or artifact content changed\n- [x] Merge commit includes DCO sign-off\n\n## Governance\n\n- [x] History synchronization only\n- [x] No direct protected-branch update\n- [x] No stable release\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T10:34:52Z",
          "mergedAt": "2026-07-31T10:35:46Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 79,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/79",
          "title": "chore(release): promote white paper alpha.11",
          "body": "## Summary\n\n- Promote the reviewed White Paper candidate from `dev/v0/v0.1` to `alpha/v0/v0.1`.\n- Publish pre-release version `0.1.0-alpha.11` through the Buildchain v3 channel workflow.\n- Keep the stable channel unchanged.\n\n## Qualification\n\n- [x] Feature-to-dev PR approved and merged\n- [x] Source verification passed on the exact candidate\n- [x] Pinned Docker publication build passed\n- [x] Final 16-page PDF rendered and visually reviewed\n- [x] npm package dry-run reports `0.1.0-alpha.11`\n\n## Release intent\n\n- [x] Alpha npm dist-tag only\n- [x] Alpha GitHub Release and Release Passport\n- [x] No stable release\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T10:28:33Z",
          "mergedAt": "2026-07-31T10:36:43Z",
          "additions": 2237,
          "deletions": 1598,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 82,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/82",
          "title": "fix(ci): grant Buildchain v3 workflow permissions",
          "body": "## Summary\n\n- Grant the caller permissions required by the Buildchain v3 reusable Build workflow.\n- Grant the exact promotion permissions required for ref promotion, artifact metadata, attestations, checks, and protected pull-request coordination.\n- Accept the current reviewed `v3-alpha` contract after confirming the only incompatible surface, `auditable-demo`, is not consumed by this repository.\n- Restore workflow startup without changing publication content or artifacts.\n\n## Root cause\n\nGitHub rejected both reusable workflow calls before job startup because the called Buildchain v3 workflows requested permissions that the consumer workflow had reduced to `none` or `read`.\n\nAfter startup was restored, the Trust Gate correctly reported the stale Alpha contract lock in issue #83. The current contract adds required media qualification outputs to `auditable-demo`; this repository does not call that workflow. The Build lifecycle change explicitly lists the previously accepted digest as compatible.\n\n## Checks\n\n- [x] `actionlint -verbose .github/workflows/build.yml .github/workflows/buildchain-ref-promotion.yml`\n- [x] `npm run check`\n- [x] `buildchain validate --cwd . --json`\n- [x] Alpha lock surface set and breaking digests match Buildchain `v3-alpha` at `9d74fb4`\n- [x] Confirmed no repository use of the `auditable-demo` workflow\n- [x] `git diff --check`\n\n## Governance\n\n- [x] Permissions match the called Buildchain v3 workflow contract exactly.\n- [x] No publication source, metadata, package version, or PDF artifact changed.\n- [x] Alpha release only; stable remains unchanged.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T10:54:46Z",
          "mergedAt": "2026-07-31T11:03:13Z",
          "additions": 11,
          "deletions": 7,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2043,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2043",
          "title": "fix(spec): refresh generated KFX authority root",
          "body": "## Summary\n\n- refresh the committed portable-format registry projection after the KFX contract changed\n- restore release qualification and package verification on every platform\n\n## Validation\n\n- `node framework/spec/scripts/generate.js --check`\n- `node framework/spec/scripts/aggregate.js`\n- `node framework/spec/scripts/verify.js`\n- `node --test framework/spec/index.test.js`\n- repository pre-commit checks with `KUNGFU_DEV_BRANCH=dev/v4/v4.0`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Refreshes a deterministic generated source root after an already-governed KFX contract change; no architecture contract or ADR record changes\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T10:44:15Z",
          "mergedAt": "2026-07-31T11:06:20Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 84,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/84",
          "title": "chore(release): sync alpha ci promotion base",
          "body": "## Summary\n\n- Merge the current Alpha history back into dev after the Buildchain v3 repair.\n- Preserve forward-only ancestry for the protected Alpha promotion.\n- Keep the dev candidate tree unchanged.\n\n## Checks\n\n- [x] `git diff --exit-code origin/dev/v0/v0.1..HEAD`\n- [x] No source, metadata, workflow, or artifact bytes changed by this merge\n- [x] Merge commit includes DCO sign-off\n\n## Governance\n\n- [x] History synchronization only\n- [x] No direct protected-branch update\n- [x] No stable release\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T11:04:05Z",
          "mergedAt": "2026-07-31T11:07:52Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 85,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/85",
          "title": "chore(release): publish white paper alpha.11",
          "body": "## Summary\n\n- Promote the fully qualified White Paper `0.1.0-alpha.11` candidate from dev to Alpha.\n- Carry the Buildchain v3 workflow permission repair and reviewed Alpha contract lock.\n- Trigger the Buildchain-managed npm Alpha publication, GitHub pre-release, and Release Passport.\n\n## Qualification\n\n- [x] White Paper content and 16-page PDF reviewed\n- [x] Source verification passed\n- [x] Buildchain Trust Gate passed\n- [x] Pinned Linux x64 publication build passed\n- [x] Build controller plan and receipt passed\n- [x] Channel router plan and receipt passed\n- [x] Alpha contract lock matches `v3-alpha` at `9d74fb4`\n\n## Release intent\n\n- [x] Publish `0.1.0-alpha.11` to npm dist-tag `alpha`\n- [x] Create the Alpha GitHub Release and Release Passport\n- [x] Keep stable unchanged\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T11:08:22Z",
          "mergedAt": "2026-07-31T11:12:26Z",
          "additions": 11,
          "deletions": 7,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 86,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/86",
          "title": "fix(ci): grant main promotion workflow permissions",
          "body": "## Summary\n\n- grant the default-branch `workflow_run` caller the exact write permissions required by Buildchain v3\n- keep the change limited to publication control-plane permissions\n- leave stable paper content and the npm `latest` channel unchanged\n\n## Evidence\n\nBuildchain Ref Promotion run 30626244313 failed before job startup because the default-branch caller allowed only `actions: read` and denied `artifact-metadata`, `attestations`, and `pull-requests`, while the v3 reusable workflow requires write access.\n\n## Validation\n\n- `git diff --check`\n- exact one-file permission diff reviewed\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T11:14:33Z",
          "mergedAt": "2026-07-31T11:15:32Z",
          "additions": 4,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2045,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2045",
          "title": "test(agent): honor native registration window",
          "body": "## Summary\n\n- align the native AgentSession peer fixture with Core’s 60-second production registration window\n- retain a bounded five-second child-reporting margin and a bounded two-peer roundtrip timeout\n- prevent cold Windows native rebuilds from being rejected by the former 15-second fixture-only deadline\n\n## Related work\n\n- Native Assignment: 2026-07-30-kungfu-qualified-core-windows-x86-64-consumer\n- Parent Initiative: 2026-07-30-kungfu-qualified-core-developer-acceleration-family\n- Follow-up to the merge-group Windows failure on run 30621530629\n\n## Verification\n\n- full staged pre-commit gate: passed\n- AgentSession non-native runtime-port tests: 3/3 passed\n- AgentSession source contract: passed\n- exact Windows native proof: required from protected merge-group execution\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Change is isolated to the native qualification fixture\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Align the native AgentSession qualification timeout with the existing Core registration contract without changing runtime behavior.\"\n}\n-->\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LXF1YWxpZmllZC1jb3JlLWRldmVsb3Blci1hY2NlbGVyYXRpb24tZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtd2luZG93cy14ODYtNjQtY29uc3VtZXIiLCJkZWxpdmVyeUNsYXNzIjoibmF0aXZlLXByb29mLXJlcXVpcmVkIiwiZGV2SGVhZCI6ImZiOTZmYzgyMDYyZWQyMmRiZDAxZjY2ZmU3OWI3NjhlYmYwZWM2NDYiLCJwdWxsUmVxdWVzdEhlYWQiOiI0MThlNzNlN2E1ZGQ5YmJjYWQxNjI4ZWQ4NzYwNzRhYTVkMTBhNDM5IiwicmVwbGF5ZWRDYW5kaWRhdGUiOiI1NTNiZGQ4Yzg3MjRhNjE2NWY0MjUxNWVmNDU1ODUyMjVhN2U0MmVjIiwicmVwbGF5ZWRUcmVlIjoiYjQ3MDQ2NzIzZTlkMmI2NTQ3NjdiOGNjZWNmMWZmMmRkODNhYWQ5NSIsInF1ZXVlQXR0ZW1wdCI6IjQxOGU3M2U3YTVkZDliYmNhZDE2MjhlZDg3NjA3NGFhNWQxMGE0MzlAZmI5NmZjODIwNjJlZDIyZGJkMDFmNjZmZTc5Yjc2OGViZjBlYzY0NiIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1Njo2MTRlZDU5Y2ZmNzQ1NGNmZDZiOGRhM2E4NzdkMWE0NWE1ZTNlMTA5MDNhOTE4Nzk4ODQ3OWE0Y2Q0ODU5MTAxIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6NjE0ZWQ1OWNmZjc0NTRjZmQ2YjhkYTNhODc3ZDFhNDVhNWUzZTEwOTAzYTkxODc5ODg0NzlhNGNkNDg1OTEwMSIsInNoYTI1NjplYzFhOTVlN2Y4MDdhNWQ2ZTBkOGVkMTc1MjRiMTEwZTFjZTgyYzc4ZmJlMWQ2NzZhMWUzNjlkMzBiMmJiN2M1Il0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvOTZkM2JmZjU3MWIwNGJiMiIsImxlYXNlUm9vdCI6InNoYTI1NjowMmRjZGEyNGQ5Y2VhNmU4MDA1Yjg0NTE2MjEwMGNmMWY5YmZjYWU5ZjI3M2FlYjRiOGRkZjk4NzUxYzNlMDVhIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T11:01:50Z",
          "mergedAt": "2026-07-31T11:20:10Z",
          "additions": 16,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 88,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/88",
          "title": "fix(ci): seal automatic paper publication admission",
          "body": "## Summary\n\n- enable Buildchain v3 automatic sealed evidence assembly for the managed paper release candidate\n- bind publication authority to this workflow, product, npm target, and package\n- grant the default-branch Build caller the read permission required by Buildchain v3\n- accept the same current Alpha contract lock already qualified on Dev/Alpha\n- leave paper content, versions, and npm `latest` unchanged\n\n## Evidence\n\nPromotion run 30626444634 reached publication authority but denied publication because all five sealed admission inputs were empty. Buildchain v3 exposes automatic evidence assembly through `publication-auto-admission`; this repository had not enabled it.\n\nThe first PR run also exposed the already-known Alpha contract drift on the default branch. The accepted lock is byte-identical to the lock that passed the Dev/Alpha Buildchain checks.\n\n## Validation\n\n- full Verify and Build passed on the exact head in superseded PR #87\n- current Alpha contract lock blob identity verified\n- `git diff --check`\n\nSupersedes #87 solely to restore the required author/reviewer identity separation.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T11:27:33Z",
          "mergedAt": "2026-07-31T11:31:08Z",
          "additions": 13,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 89,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/89",
          "title": "fix(ci): pass governance auditor credential",
          "body": "## Summary\n\n- pass the existing organization-level read-only governance auditor App private-key secret into the Buildchain v3 reusable promotion workflow\n- keep the secret value opaque; this change references only its logical name\n- leave paper content, versions, and publication channels unchanged\n\n## Evidence\n\nPromotion run 30627351197 enabled automatic evidence assembly and then failed at `Mint bounded governance auditor token`: the App ID was present, while the `private-key` input was empty. The organization secret `KUNGFU_GOVERNANCE_AUDITOR_APP_PRIVATE_KEY` exists with all-repository visibility, but the caller did not forward it.\n\n## Validation\n\n- secret inventory checked by name only\n- reusable workflow secret contract inspected at exact Buildchain v3 Alpha SHA\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T11:35:23Z",
          "mergedAt": "2026-07-31T11:39:08Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2047,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2047",
          "title": "feat(kfx): add standard Python asyncio runtime bridge",
          "body": "<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019fb64f-ba63-7620-a384-063adec7af2f\"],\n  \"summary\": \"Replace the custom Python coloop half-event-loop with a standards-compatible asyncio bridge while preserving deterministic journal and reactor semantics.\",\n  \"verification\": [\"./shifu build:core\", \"./shifu test:native-kfx-admission\", \"./shifu docs:check\"]\n}\n-->\n\n## Summary\n\n- delegate scheduling to the CPython 3.13 standard asyncio loop while pumping Kungfu journal/reactor work through an explicit bridge\n- add async capability sessions with cancellation, failure, lifecycle, sandbox, and graceful-shutdown handling\n- keep deterministic journal/replay semantics in Core and Python adaptation in the host/binding layer\n- document the machine contract, compatibility removal gate, known limits, and ADR\n\n## Verification\n\n- [x] `./shifu build:core`\n- [x] `./shifu test:native-kfx-admission`\n- [x] `./shifu docs:check`\n- [x] exact candidate qualification started on agent-120 Linux\n- [ ] protected PR Windows/Linux/macOS checks on final head\n\n## Evolution impact\n\n- [x] none\n- [ ] extends\n- [ ] opens\n\nThe change implements an accepted architecture decision without changing an Evolution Map stage.\n\n## Governance risk\n\n- [ ] rewrites history or evidence\n- [ ] weakens capability or isolation boundaries\n- [ ] bypasses protected review or merge policy\n- [ ] changes release/channel semantics\n- [x] none\n\n## Review focus\n\nPlease verify that generic journal/reactor ordering remains in Core, Python-specific scheduling stays in the runtime/host boundary, capability grants fail closed, and no private asyncio scheduler fields or partial `AbstractEventLoop` implementation remain in production code.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T11:25:03Z",
          "mergedAt": "2026-07-31T11:41:56Z",
          "additions": 1941,
          "deletions": 706,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 90,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/90",
          "title": "fix(release): ignore promotion shell checkout",
          "body": "## Summary\n\n- ignore the provider-owned `.buildchain/promotion-shell/` checkout created inside the promotion job\n- keep version-state verification focused on consumer source changes\n- leave paper content and version unchanged\n\n## Evidence\n\nPromotion run 30627826962 passed sealed governance admission, then failed before npm publishing because version verification saw `?? .buildchain/promotion-shell/`. Buildchain v3 itself creates that checkout path before invoking the promotion action.\n\n## Validation\n\n- verified the exact checkout path in Buildchain v3 Alpha workflow source\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T11:45:00Z",
          "mergedAt": "2026-07-31T11:48:44Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2048,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2048",
          "title": "fix(ci): route native AgentSession changes through platform matrix",
          "body": "## Summary\n\n- classify the Qualified Core candidate action and AgentSession native consumer boundary as full native matrix authority\n- ensure runtime-port native source, fixture, and roundtrip changes require all four protected platform rows\n- close the proof-routing gap observed after PR #2045 merged without a Windows candidate job\n\n## Related work\n\n- Native Assignment: 2026-07-30-kungfu-qualified-core-windows-x86-64-consumer\n- Parent Initiative: 2026-07-30-kungfu-qualified-core-developer-acceleration-family\n\n## Verification\n\n- core affected-native self-test: 32/32 passed\n- planner unit tests: 7/7 passed\n- exact-file Biome check: passed\n- full staged pre-commit gate: passed\n- protected four-platform Qualified Core matrix: required from merge queue\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Change is isolated to native qualification routing\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair qualification routing for the existing Qualified Core native consumer contract without changing runtime architecture.\"\n}\n-->\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LXF1YWxpZmllZC1jb3JlLWRldmVsb3Blci1hY2NlbGVyYXRpb24tZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtd2luZG93cy14ODYtNjQtY29uc3VtZXIiLCJkZWxpdmVyeUNsYXNzIjoibmF0aXZlLXByb29mLXJlcXVpcmVkIiwiZGV2SGVhZCI6ImI5ZmQ0M2NlZDZlNmE2YTU1YTRlZDc1NzZjNWY2MTRiM2Y3MDgxMzAiLCJwdWxsUmVxdWVzdEhlYWQiOiIxMGZiNzYyZGRlY2RjYzUwNGExNDBlYzk2NzUxYzI1ZmYzMmMxYzVlIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiJiZDZjYzYxMDE5NzExMTM1MjUzZGVkOTk3NDIzZjVkYzAwMWNkZTdkIiwicmVwbGF5ZWRUcmVlIjoiMWYyNmM4YjMyN2NhNDI4MmFlZWU4MjcxOWUwYmRkNzZiNzFiMzFjMCIsInF1ZXVlQXR0ZW1wdCI6IjEwZmI3NjJkZGVjZGNjNTA0YTE0MGVjOTY3NTFjMjVmZjMyYzFjNWVAYjlmZDQzY2VkNmU2YTZhNTVhNGVkNzU3NmM1ZjYxNGIzZjcwODEzMCIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1NjpjOTY0ZmU5NTRiODkyMjMwMjg4ZjViYWQ5NzA1YTg1NDg4Yzc3ZGU4YWYwZThhNDJhY2Y5ZGUyYzFhMzYzYTg3IiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6Yzk2NGZlOTU0Yjg5MjIzMDI4OGY1YmFkOTcwNWE4NTQ4OGM3N2RlOGFmMGU4YTQyYWNmOWRlMmMxYTM2M2E4NyIsInNoYTI1NjplYzFhOTVlN2Y4MDdhNWQ2ZTBkOGVkMTc1MjRiMTEwZTFjZTgyYzc4ZmJlMWQ2NzZhMWUzNjlkMzBiMmJiN2M1Il0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvOTZkM2JmZjU3MWIwNGJiMiIsImxlYXNlUm9vdCI6InNoYTI1NjphMTg4OTU0ZTBmMDk0MzQ3YjI4YTdjYWRhN2RiNDFjYWFkZmY5NjJiYjhjNDY1NDg3MzUzZmE1MTYwMmRhOGE2In0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T11:33:08Z",
          "mergedAt": "2026-07-31T11:55:02Z",
          "additions": 40,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 92,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/92",
          "title": "docs(release): explain promotion shell ignore",
          "body": "## Summary\n\n- document why the Buildchain promotion shell directory is ignored\n- preserve the already-qualified paper and PDF unchanged\n- make the Dev head merge attributable to the product author for Alpha last-push approval separation\n\n## Scope\n\nOne `.gitignore` comment only.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T11:54:43Z",
          "mergedAt": "2026-07-31T11:58:46Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 94,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/94",
          "title": "fix(release): qualify alpha.11 promotion workspace",
          "body": "## Summary\n\n- integrate the current Dev promotion-workspace fix on top of the current Alpha baseline\n- ignore and document Buildchain's isolated promotion shell checkout\n- preserve White Paper content, generated PDF, and version `0.1.0-alpha.11` unchanged\n\n## Evidence\n\n- source fix passed full Buildchain Build and Verify suites in #90 and #92\n- resolves the clean-tree version-verification failure tracked by buildchain#2107\n- Alpha-rooted integration avoids reciprocal protected-branch drift\n\n## Scope\n\nTwo `.gitignore` lines only; no paper or artifact changes.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T12:04:22Z",
          "mergedAt": "2026-07-31T12:07:48Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2050,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2050",
          "title": "fix(ci): anchor Windows sccache cache to workspace",
          "body": "## Summary\n\n- resolve the Windows sccache directory against the repository workspace before exporting it to the compiler process\n- retain the portable relative cache binding while recording the workspace-resolution rule in the auditable tool receipt\n- prevent cache bytes from being nested under the sccache executable cache and make cold/warm qualification inspect the intended directory\n\n## Failure evidence\n\nA live DARKHERO build exported the relative `.buildchain/cache/compiler/windows-sccache-v1` value. The sccache server resolved that value from its executable directory, not the checked-out repository, and wrote 233 files (270,956,024 bytes) beneath the tool cache. The existing A/B operator therefore inspected the wrong path and could falsely call the run cold.\n\n## Verification\n\n- `./shifu check:shifu-cache-contract` passed, including 2/2 focused Windows sccache tests\n- repository commit hook and staged gate passed\n- `./shifu check:source` passed 846/847 tests; the sole local-environment failure was the cold read-only fixture reporting `pytest is not available on PATH`\n- `./shifu check` reached the unrelated layer harness and failed because a clean worktree lacked prebuilt `framework/spec/dist/reader-matrix.json`\n- DCO sign-off present\n\n## Boundary\n\nThis changes only cache path resolution and its receipt binding. It does not change the sccache version or digest, cache profile identity, compiler-cache provider, release publication authority, Defender state, or runner power plan.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fix Windows compiler-cache path resolution without changing architecture or publication authority\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects a source-bound compiler-cache tool receipt, but grants no release or publication authority. Focused receipt tests and the repository staged gate passed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (no user-facing documentation change required)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T11:48:41Z",
          "mergedAt": "2026-07-31T12:20:07Z",
          "additions": 22,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 96,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/96",
          "title": "chore(release): retry alpha.11 promotion",
          "body": "## Summary\n\n- re-enter Alpha 11 through the machine-recognized `publish-gate/alpha/*` recovery lineage\n- retain the already-qualified source tree exactly\n- retry protected publication after resolving the workspace and provenance gates\n\n## Scope\n\nEmpty-tree recovery commit only; no files, paper content, PDF, or version changed.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T12:19:23Z",
          "mergedAt": "2026-07-31T12:24:09Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2108,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2108",
          "title": "refactor: harden maintainability boundaries",
          "body": "## Summary\n\n- add an exact-head maintainability audit plus deterministic new-only and extracted-debt budgets\n- decompose promotion, Release Passport, CLI dispatch, and workflow authorization while preserving public contracts\n- add lifecycle ownership metadata and documentation/registry parity checks across CLI, Node APIs, actions, and workflows\n- remove unused root Vitest and @types/node dependencies and wire syntax/format/architecture checks into `pnpm run check`\n\n## Compatibility and authority\n\n- no CLI command, flag, Node export, action input/output, workflow input/secret/output, or compatibility alias removed\n- protected promotion and runtime-override authority remains fail closed\n- no alpha, stable, npm, release, AWS, or provider configuration mutation is part of this PR\n\n## Evidence\n\n- audit baseline: `53923edcff7bbadba9f2320f704ad1a36be7b33d`\n- integration base: `969e6ec1315fc7395bce198e3e5252181bf4eb93`\n- semantic candidate: `e82afc975df2c89dd48b1b2efc9304302fc903c7`\n- reviewed head: `f3ae9df04b935b16939eb835f62af918b84c73ee`\n- train: `train/v3/v3.0/maintainability-hardening` at `f3ae9df04b935b16939eb835f62af918b84c73ee`\n- `pnpm run check`: 1081 passed, 0 failed, 0 skipped\n- `pnpm run pack:check`: passed\n- action bundles, site facts, and generated promotion workflow: reproducible\n- promotion orchestration: 341 lines / complexity 26 (budget 600 / 50)\n- Release Passport report constructor: 65 lines / complexity 5 (budget 180 / 25)\n- internal architecture: 11 capabilities, 18 implementations, 0 dependency cycles\n- exact-head PR fixture: https://github.com/kungfu-systems/buildchain/actions/runs/30629976647\n- exact-train downstream publication build: https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/actions/runs/30630218178\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T12:12:35Z",
          "mergedAt": "2026-07-31T12:25:53Z",
          "additions": 4989,
          "deletions": 1849,
          "changedFiles": 38
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 97,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/97",
          "title": "chore(release): admit alpha.11 publication",
          "body": "## Summary\n\n- enter Alpha 11 through the exact Buildchain publish-gate ref grammar\n- bind channel `alpha`, line `v0/v0.1`, and consumer version `0.1.0-alpha.11`\n- retain the qualified source tree exactly\n\n## Scope\n\nEmpty-tree publication-admission commit only; no files, paper content, PDF, or version changed.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T12:29:31Z",
          "mergedAt": "2026-07-31T12:33:27Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2054,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2054",
          "title": "fix(shifu): align Qualified Core platform support",
          "body": "## Summary\n\n- remove the unsupported Darwin x86_64 Qualified Core producer row that failed after PR #1990 because the public libnode release has no `darwin-x64` package\n- align the platform matrix, schema, artifact contract, candidate workflow, protected promotion controller, and upload action with the actual supported surface: macOS ARM64, Linux x86_64, and Windows x86_64\n- make consumer activation reuse the matrix `REQUIRED_ROWS` authority so producer and consumer platform support cannot drift independently\n- retain fail-closed behavior for unsupported hosts and add an explicit Darwin x86_64 fallback test\n\n## Related issue\n\n- Native Assignment `2026-07-29-kungfu-terminal-review-remediation`\n\n## Changes\n\n- Qualified Core now has exactly three supported platform rows\n- Intel macOS remains unsupported instead of entering a guaranteed-failing producer lane\n- closed-world workflow authority digests are refreshed for the changed jobs and steps\n\n## Verification\n\n- `./shifu check:source` — pass for the nine source/contract changes before workflow-authority refresh\n- `./shifu check:gate-catalog` — 38 gates, 6 profiles, 27 structured invocations, and 31 closed-world workflows aligned\n- full staged pre-commit gate — pass, including documentation contracts, 73 dev latency contract tests, 17 invariant tests, KFD evidence, schema authority, formatting, and workflow authority\n- Qualified Core tests explicitly reject Darwin x86_64 and Linux ARM64 as unsupported hosts\n- protected merge-group execution will prove the remaining three producer rows against the exact candidate source\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix narrows a development-stage qualification matrix to the already authoritative public libnode and active consumer platform surface; it does not alter an architecture contract or release channel topology.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change narrows only the development-stage Qualified Core evidence surface to platforms that are actually supported; it grants no publication authority and weakens no required supported-platform gate.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI5LWt1bmdmdS10ZXJtaW5hbC1yZXZpZXctcmVtZWRpYXRpb24iLCJkZWxpdmVyeUNsYXNzIjoiY3Jvc3MtcGxhdGZvcm0iLCJkZXZIZWFkIjoiMjc5YjNiZDYyYWIwZDI4NzYwOWI2NDA5ODQyNTA3NjFkN2Q1ZTAzNCIsInB1bGxSZXF1ZXN0SGVhZCI6ImZjNjcwNmUyYmI2YTNiODg4N2E2NWFjYjJkYzM0NmU5ODdkOGNiMDIiLCJyZXBsYXllZENhbmRpZGF0ZSI6Ijk0ZDFlYzg0ODU2ODMxNTkwMDQ0NzllYWUyMTBjYWM3NmIxOTdlMmYiLCJyZXBsYXllZFRyZWUiOiIzYjM4NTM4NGUzYzQzMzMwZTJmYWE5MzMyMTFmOTNmNzJlZjk3MDM0IiwicXVldWVBdHRlbXB0IjoiZmM2NzA2ZTJiYjZhM2I4ODg3YTY1YWNiMmRjMzQ2ZTk4N2Q4Y2IwMkAyNzliM2JkNjJhYjBkMjg3NjA5YjY0MDk4NDI1MDc2MWQ3ZDVlMDM0IiwiYWRtaXNzaW9uUHJvb2ZSb290Ijoic2hhMjU2OjZlZDkzNTlhZmU5YTRjMjMwZjVkMTIwOTI0ZjE5ZTM4ODFiN2VmYTMyMGU0NTNhMDFjOTdjMjhjN2Y2NDFmNzEiLCJhZG1pc3Npb25Qcm9vZlJvb3RzIjpbInNoYTI1Njo1YjJiYjllNjdlZDgyMmQ4ZTBlMmIzNzZkMzlkYTcwNWM3Mjk2OGQwNThjOWIxZGYyNTM0MzEyMTcwYzk2OGYwIiwic2hhMjU2OjZlZDkzNTlhZmU5YTRjMjMwZjVkMTIwOTI0ZjE5ZTM4ODFiN2VmYTMyMGU0NTNhMDFjOTdjMjhjN2Y2NDFmNzEiXSwic3RhdHVzQ29udGV4dCI6IlF1ZXVlIGZhbWlseSBsZWFzZS9kOTlmM2E5MTY2NzM5ZTBkIiwibGVhc2VSb290Ijoic2hhMjU2OmI2ODAyY2JiNDFmMmYxNTdlYjRiNTFmNmZlNzIyNThhNDMwM2Q1YjM1NjRlY2M5OGYwOWJkY2UxMjQ2MGM1OWEifQ -->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T12:27:57Z",
          "mergedAt": "2026-07-31T12:38:38Z",
          "additions": 44,
          "deletions": 119,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2109,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2109",
          "title": "chore(release): promote maintainability hardening to alpha",
          "body": "## Summary\n\n- integrates protected dev merge c5dfdd6d90f3f75ca33df008c616e4e050ef952f into alpha/v3/v3.0\n- preserves the alpha package version at 3.0.3-alpha.0\n- resolves the generated Buildchain contract conflict by regenerating dist/site\n- carries the maintainability budgets, architecture boundaries, CLI registry, workflow helpers, and compatibility fixes reviewed in #2108\n\n## Verification\n\n- pnpm run check: 1081 passed, 0 failed\n- maintainability: 197 files checked against 969e6ec; audit baseline 53923ed\n- architecture: 11 capabilities, 18 implementations, 0 cycles\n- site generation, workflow contracts, and 6 action bundles passed\n- exact-train downstream canary passed at f3ae9df04b93\n\n## Provenance\n\n- dev PR: #2108\n- merge parents: alpha 683bba847bc254ba872c4af99ab0bb4308789bea + dev c5dfdd6d90f3f75ca33df008c616e4e050ef952f\n- merge commit: 25e1ea258eceeeaad7fc6df16cd1d098d9f07da1\n\nThis PR uses the protected alpha promotion path; no direct branch or tag movement.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T12:34:59Z",
          "mergedAt": "2026-07-31T12:41:17Z",
          "additions": 25166,
          "deletions": 3011,
          "changedFiles": 179
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 98,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/98",
          "title": "Prepare v0.1.0-alpha.11",
          "body": "Create the generated version-state commit for v0.1.0-alpha.11.\n\nBuildchain generated this PR because protected branch dev/v0/v0.1 rejected direct generated bookkeeping.\n\nRejected update: 9f612396b0cd785a63c81eeff381e1ce134989b5 -> 695b849203b5879f6169f1806f31c1b1e860fdf6\n\nGitHub response: Changes must be made through a pull request.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-31T12:39:09Z",
          "mergedAt": "2026-07-31T12:43:02Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2056,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2056",
          "title": "feat(work-design): close outcome feedback loop",
          "body": "## Summary\n\nClose the rooted Work Design outcome feedback loop without adding a second Work authority or a routine human approval checkpoint.\n\n## Related issue\n\nAtlas Assignment `2026-07-31-kungfu-work-design-outcome-feedback-loop`.\n\n## Changes\n\n- compile verified settled Work into deterministic, privacy-bounded outcome records;\n- feed qualified outcomes into the existing comparable-cohort policy replay path;\n- enforce the exact 9/10/29/30 shadow and promotion boundaries;\n- add bounded automatic canary, promotion, monitoring, and exact previous-policy rollback;\n- expose build-free machine-readable compile, shadow, activation, monitoring, transition, and status routes.\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu check:work-design-policy-replay`\n- `./shifu test:work-design-policy-replay` (18/18)\n- `./shifu build:core`\n- DCO sign-off and Kungfu commit identity guard\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f9771-4c20-7e2c-8e7c-3f3cb3f1b9bd\"],\n  \"summary\": \"Deliver rooted Work outcome feedback, replay, bounded activation, monitoring, and exact rollback through the existing Work Control authority.\",\n  \"verification\": [\"Exact-head source acceptance\", \"18 Work Design replay and feedback tests\", \"Core build qualification\"]\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: extends\n\nThis extends the current Work Control stage with outcome-derived feedback and bounded policy lifecycle evidence; it does not open or settle an Era.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMjgta3VuZ2Z1LWdvLWZhbWlseS1jb250aW51b3VzLWRlbGl2ZXJ5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMS1rdW5nZnUtd29yay1kZXNpZ24tb3V0Y29tZS1mZWVkYmFjay1sb29wIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiJjMTdlMGQwYjgyZDM4YTNiZWFmNTBhMWFiMDM3YWIzNGZhNzkwOTY2IiwicHVsbFJlcXVlc3RIZWFkIjoiMjE4ZTJmZDQ4OGY4YWYwZGI1ZjVjNzk3YWEzNWU2MmE1OTIwNDY5YyIsInJlcGxheWVkQ2FuZGlkYXRlIjoiMGQ4MjJlNGVmOWUxNWY5MTA5NzBkNzFhNmIzMGFlMWIwMzJhYTAzZiIsInJlcGxheWVkVHJlZSI6IjY0OGFjZDFhNGQ0ZjNiYjAzOTFlZjI0ZGYwZDc5M2JmODMxZjhhY2EiLCJxdWV1ZUF0dGVtcHQiOiIyMThlMmZkNDg4ZjhhZjBkYjVmNWM3OTdhYTM1ZTYyYTU5MjA0NjljQGMxN2UwZDBiODJkMzhhM2JlYWY1MGExYWIwMzdhYjM0ZmE3OTA5NjYiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6MjBjOWZiZTM4ZGQ0ZjEyZWEyNWQ3YzZjZTIwM2I3YTE3NDIzNmFmOGQ1NDUyNzkzODM4MWMxOGM5ZGM0NTA5NyIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OjIwYzlmYmUzOGRkNGYxMmVhMjVkN2M2Y2UyMDNiN2ExNzQyMzZhZjhkNTQ1Mjc5MzgzODFjMThjOWRjNDUwOTciLCJzaGEyNTY6YjVhMTIzMTYzMmEyNmRjYThkMDMxMGE2ZjJiM2VkYTBjNzRiNzlmM2QxMWFlNjgyZWE2ZjA2YjY1ODY2ODczZiJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2VjYWM2N2JjZWJmYWUzYmYiLCJsZWFzZVJvb3QiOiJzaGEyNTY6MzljODIzODkwZGMxY2Y2Yzk1MGRiMGVjM2M1NTA0NWJiODNiY2RkNTIyY2M0MGRiNWU4Y2YzNjNmZjY5YTQ0ZSJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T12:40:12Z",
          "mergedAt": "2026-07-31T12:54:10Z",
          "additions": 2057,
          "deletions": 20,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2111,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2111",
          "title": "fix(maintainability): hydrate shallow baseline revision",
          "body": "## Summary\n\n- hydrates the exact maintainability enforcement commit only when a shallow checkout lacks it\n- uses a bounded no-tags depth-1 fetch from origin and verifies the fetched object is a commit\n- fails closed with a precise error if the object cannot be fetched or remains unavailable\n- adds a local file-remote shallow-clone regression test\n\n## Root cause\n\nBuildchain Ref Promotion run 30631622162 reached Promote-only publish, then version-state verification failed because the depth-1 checkout did not contain enforcement revision 969e6ec1315fc7395bce198e3e5252181bf4eb93.\n\n## Verification\n\n- pnpm run check: 1082 passed, 0 failed\n- real depth-1 clone: baseline absent before check, exact SHA hydrated, maintainability check passed\n- local source remains governed against the same exact revision; no budget was relaxed\n\nFollow-up for #2108 and alpha promotion PR #2109.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T12:53:18Z",
          "mergedAt": "2026-07-31T13:01:16Z",
          "additions": 81,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 204,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/204",
          "title": "feat(site): align brand palette and white paper",
          "body": "## Summary\n\n- apply the confirmed warm commercial palette across kungfu.tech\n- consume @kungfu-tech/paper-kungfu-product-white-paper 0.1.0-alpha.11\n- follow the new /whitepaper/kungfu-real-world-agent-work/ canonical reader and PDF routes while preserving legacy aliases\n- keep the standalone Agent Supply Chain page on the exact alpha.10 structured snapshot removed from alpha.11\n- render the new paper reading prompt with the shared one-click copy control\n\n## Verification\n\n- corepack pnpm@11.7.0 run build\n- corepack pnpm@11.7.0 run check\n- git diff --check\n\n## Claim boundary\n\nWhite Paper pages, PDF, metadata, evidence, and immutable publication coordinates use alpha.11. Only the pre-existing standalone Agent Supply Chain presentation remains pinned to its last exported structured contract, alpha.10.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T12:54:52Z",
          "mergedAt": "2026-07-31T13:05:36Z",
          "additions": 186,
          "deletions": 111,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 260,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/260",
          "title": "feat(site): align developer palette and white paper",
          "body": "## Summary\n\n- apply the confirmed cool developer-platform palette across libkungfu.dev\n- consume @kungfu-tech/paper-kungfu-product-white-paper 0.1.0-alpha.11\n- publish the alpha.11 current page, artifacts, manifest, registry, and immutable archive routes\n- preserve the alpha.10 immutable archive and retain the removed Agent Supply Chain presentation as an exact alpha.10 snapshot\n- add palette and publication-contract gates\n\n## Verification\n\n- corepack pnpm@11.9.0 run build\n- corepack pnpm@11.9.0 run check\n- git diff --check\n\n## Claim boundary\n\nCurrent White Paper publication surfaces use alpha.11. Only the pre-existing Agent Supply Chain overview remains sourced from the last package version that exported that structured presentation contract.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T12:54:52Z",
          "mergedAt": "2026-07-31T13:10:44Z",
          "additions": 98,
          "deletions": 48,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2112,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2112",
          "title": "chore(release): sync shallow-baseline fix to alpha",
          "body": "## Summary\n\n- integrates protected dev hotfix #2111 into alpha/v3/v3.0\n- preserves alpha version 3.0.3-alpha.0\n- ensures the publish target tree contains the shallow-checkout baseline hydration fix\n\n## Verification\n\n- pnpm run check on the alpha merge tree: 1082 passed, 0 failed\n- merge parents: alpha 69d82c83addec9c6e2e569621eb71c7bb5f4138a and dev 7ea1a0cf262fe5aca287681642f070560dc34a39\n- prior promotion failure: run 30631622162 / issue #2110\n\nNo manual ref or tag movement.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T13:06:11Z",
          "mergedAt": "2026-07-31T13:12:11Z",
          "additions": 81,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 205,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/205",
          "title": "Release production from 5aecb2b083d9",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `5aecb2b083d9f164ee5af4cf2b73d616a5c1994e`\n- Artifact hash: `8635947ed41a5e047643215b2a70b20876275efd1dd591b7b3e681e1763fcb36`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30633092760)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-5aecb2b083d9`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-31T13:09:46Z",
          "mergedAt": "2026-07-31T13:12:33Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2058,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2058",
          "title": "fix(gui): retry Windows runtime uninstall cleanup",
          "body": "## Summary\n\n- retry removal of the owned Windows runtime subtree before the default NSIS uninstall pass\n- keep the retry bounded to 30 seconds and leave the default installer cleanup semantics intact\n- bind the same NSIS include into framework and product projections with focused contract coverage\n\n## Failure evidence\n\nKungfu Build run 30626449970 reached release qualification on Windows and failed because uninstall left only resources\\\\kungfu profile files under the installed desktop root. The qualification diagnostics reported no process under the install root. Linux x64, Linux ARM64, and macOS ARM64 passed; macOS signing and notarization also passed.\n\n## Verification\n\n- node --test framework/gui/scripts/electron-builder-config.test.mjs tests/qualification/layers/surfaces/installer.test.mjs: 11 passed, 1 platform skip, 0 failed\n- git diff origin/dev/v4/v4.0...HEAD --check: passed\n\n## Boundary\n\nThe custom uninstall macro removes only $INSTDIR\\\\resources\\\\kungfu, retries for at most 30 seconds, and then returns control to the default uninstall pass. It does not change signing, notarization, publication authority, runner routing, or release topology.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Bounded Windows installer cleanup repair without architecture or release topology change\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change repairs a release qualification failure but grants no publication authority and changes no protected signing boundary.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Focused tests passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T13:13:41Z",
          "mergedAt": "2026-07-31T13:23:38Z",
          "additions": 48,
          "deletions": 0,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 261,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/261",
          "title": "chore(papers): replay white paper alpha.11 propagation",
          "body": "## Summary\n- record the exact white paper alpha.11 propagation lock\n- pin a replay alias so staging takes the package-pin-only path\n- preserve every existing immutable publication prefix\n\n## Validation\n- `pnpm run check:paper-propagation`\n- `pnpm run check`\n- exact propagation qualification: `package-pin-only` for `archive/kungfu-product-white-paper/v0.1.0-alpha.11`",
          "author": "dongkeren",
          "createdAt": "2026-07-31T13:23:45Z",
          "mergedAt": "2026-07-31T13:29:16Z",
          "additions": 87,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2113,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2113",
          "title": "fix(maintainability): hydrate all audit revisions",
          "body": "Closes the remaining shallow-checkout failure in the v3-alpha publication transaction.\n\n- hydrates both the audit baseline and enforcement revision by exact SHA\n- preserves fail-closed behavior when either revision cannot be fetched\n- restores the Linux x64 esbuild lockfile closure removed during dependency cleanup\n- adds regression coverage for two-revision shallow clones and the Linux standalone dependency\n\nVerification:\n- fresh depth=1 clone + `corepack pnpm@11.7.0 install --frozen-lockfile`\n- `pnpm run check`: 1083/1083 tests, 6 action bundles\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T13:30:16Z",
          "mergedAt": "2026-07-31T13:34:25Z",
          "additions": 68,
          "deletions": 8,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2114,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2114",
          "title": "fix(alpha): hydrate all maintainability revisions",
          "body": "Carries the reviewed dev/v3/v3.0 shallow-checkout hardening into alpha without changing the configured version.\n\n- source dev merge: 3e63a39cfa44ff4a923ec97baa3fe778eda212ec\n- alpha merge commit: 0112957d267dc64a5ffdb305d20bedb8401ab924\n- package version remains 3.0.3-alpha.0\n- `pnpm run check`: 1083/1083 tests and 6 action bundles\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T13:36:37Z",
          "mergedAt": "2026-07-31T13:38:12Z",
          "additions": 68,
          "deletions": 8,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 263,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/263",
          "title": "chore(papers): clean up white paper propagation replay",
          "body": "## Summary\n- remove the temporary alpha.11 replay alias after successful staging propagation\n- retain the exact alpha.11 propagation lock\n- preserve package-pin-only qualification for the cleanup staging pass\n\n## Validation\n- `pnpm run check`\n- exact propagation qualification: `package-pin-only`",
          "author": "dongkeren",
          "createdAt": "2026-07-31T13:35:32Z",
          "mergedAt": "2026-07-31T13:38:25Z",
          "additions": 4,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 47,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/47",
          "title": "feat(paper): redesign the Machine Life edition",
          "body": "Redesigns the Machine Life paper as a distinct public-facing edition, clarifies the KFD-to-machine-life argument, adds reader orientation and visual structure, and refreshes the website bundle.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T13:41:26Z",
          "mergedAt": "2026-07-31T13:42:15Z",
          "additions": 574,
          "deletions": 123,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2115,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2115",
          "title": "Prepare v3.0.3-alpha.1",
          "body": "Create the generated version-state commit for v3.0.3-alpha.1.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: b8e84bcb51e131207896c426fb8e79fd0f46b5ac -> 15bf4369927d2c23beaf6ff531d52d5e1f6494fa\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T13:43:43Z",
          "mergedAt": "2026-07-31T13:47:47Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2060,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2060",
          "title": "fix(qualification): keep NSIS paths below MAX_PATH",
          "body": "## Summary\n\n- shorten the surface qualification workspace prefix and remove one test-only desktop nesting layer\n- preserve the fail-closed NSIS uninstall check; no residual files are deleted by the harness\n- derive a Windows path-budget regression from the exact Python and profile sources assembled into the desktop package\n\n## Evidence\n\n- failed run: https://github.com/kungfu-systems/kungfu/actions/runs/30626449970\n- legacy longest assembled path: 264 characters\n- qualified layout longest assembled path: 218 characters\n- ./shifu node --test tests/qualification/layers/surfaces/installer.test.mjs tests/qualification/layers/surfaces/run.test.mjs (15/15)\n- pnpm exec biome check (passed)\n- pre-commit gate (137/137 plus repository gates)\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Shorten test-only Windows qualification paths so the existing fail-closed NSIS uninstall contract can evaluate packaged files below legacy MAX_PATH; no architecture contract is introduced or altered.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T13:35:46Z",
          "mergedAt": "2026-07-31T13:48:08Z",
          "additions": 88,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 264,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/264",
          "title": "Release production from 20682afdf182",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `20682afdf182cd9234867bc8a2397021999303b8`\n- Artifact hash: `512c43ca17250eff2437fb17efb9eb2245f061382762b8a8a63ccc704039d867`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/30635272331)\n- Required label: `buildchain-release`\n- Release branch: `release/production-20682afdf182`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-31T13:41:15Z",
          "mergedAt": "2026-07-31T13:55:04Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2062,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2062",
          "title": "fix(core): preserve watcher benchmark carrier continuity",
          "body": "## Summary\n\n- make the watcher dispatch benchmark follow the load peer's journal before requesting carrier reads\n- prove requested frames come from the target carrier and report target-carrier latency instead of mixing control traffic\n- fail closed when the coordinator command writer is not ready, avoiding a native `unordered_map::at` termination during startup races\n- supersedes #2061 with the same two verified patches replayed onto the latest `dev/v4/v4.0`\n\n## Verification\n\n- `git range-diff dbe6ee17f6..4281614ab5 7777de45e3..34b6cff2e4` — both patches equivalent\n- `./shifu build:core` — pass\n- `./shifu test:node-watcher-runtime-boundary` — 5/5 pass\n- `./shifu test:agent-session-peer-transport:native` — 4/4 pass\n- `./shifu exec node framework/core/tests/bench/dispatch_bench_watcher.mjs 200000 601` — 93,025 frames/s writer throughput; target-carrier mean 1,758 ns; 202,000 target frames observed for 200,000 requested\n- `./shifu check:staged` — pass\n- `git diff --check` — pass\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repair benchmark carrier continuity and harden the existing watcher startup boundary without changing an architecture contract\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T13:49:59Z",
          "mergedAt": "2026-07-31T14:00:54Z",
          "additions": 88,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 343,
          "url": "https://github.com/kungfu-systems/build-images/pull/343",
          "title": "fix(latex): install TeX Gyre publication fonts",
          "body": "Installs the TeX Gyre Type 1 and OpenType packages required by publication themes, documents the explicit dependency, and extends the LaTeX smoke fixture to compile Pagella, Heros, and Cursor.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T14:05:01Z",
          "mergedAt": "2026-07-31T14:08:10Z",
          "additions": 11,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 342,
          "url": "https://github.com/kungfu-systems/build-images/pull/342",
          "title": "Prepare v1.3.0-alpha.21",
          "body": "Create the generated version-state commit for v1.3.0-alpha.21.\n\nBuildchain generated this PR because protected branch alpha/v1/v1.3 rejected direct generated bookkeeping.\n\nRejected update: f7caa720e43980889c24b6ddc30d5bcfbe98ee9f -> 894ed377ebfdc7e7ba52e84dcf14f3ad1d5aba6d\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T07:28:07Z",
          "mergedAt": "2026-07-31T14:11:55Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 159,
          "url": "https://github.com/kungfu-systems/libnode/pull/159",
          "title": "feat(packages): publish macOS x64 libnode",
          "body": "## Summary\n\n- add @kungfu-tech/libnode-darwin-x64 as the fifth native platform package\n- build the package on GitHub-hosted macos-15-intel and require it in release promotion\n- extend entrypoint, tarball, KFD-1/2/3, cache, documentation, and alpha.4 version contracts\n\n## Related work\n\n- Kungfu Assignment: 2026-07-30-kungfu-qualified-core-macos-x86-64-consumer\n- Parent Initiative: 2026-07-30-kungfu-qualified-core-developer-acceleration-family\n- Required by Kungfu merge-group run 30628488259, job 91149824593\n\n## Verification\n\n- entrypoint and KFD evidence tests: 5/5 passed\n- release manifest, KFD witnesses, package source, formatting, and diff checks: passed\n- official npm registry confirms alpha.4 and darwin-x64 package names are unused\n- protected five-platform Buildchain matrix: required from this PR",
          "author": "dongkeren",
          "createdAt": "2026-07-31T12:06:46Z",
          "mergedAt": "2026-07-31T14:15:33Z",
          "additions": 112,
          "deletions": 41,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2063,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2063",
          "title": "Expose Windows native peer coordinator diagnostics",
          "body": "## Summary\n- preserve the existing 60-second native peer registration boundary\n- on writer registration failure, report whether the coordinator exited\n- include the bounded coordinator stdout/stderr so repeated Windows runner failures become actionable\n\n## Evidence\n- Windows Qualified Core candidate attempts 1 and 2 both failed after the full registration window\n- watcher runtime boundary passed before the failure\n- targeted syntax, Biome, and diff checks passed\n- no production code or timeout semantics changed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This test-only diagnostic change exposes existing coordinator output without changing architecture, runtime behavior, or qualification thresholds.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [x] none of the above",
          "author": "dongkeren",
          "createdAt": "2026-07-31T14:03:48Z",
          "mergedAt": "2026-07-31T14:24:42Z",
          "additions": 13,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 345,
          "url": "https://github.com/kungfu-systems/build-images/pull/345",
          "title": "Prepare v1.3.0-alpha.22",
          "body": "Create the generated version-state commit for v1.3.0-alpha.22.\n\nBuildchain generated this PR because protected branch alpha/v1/v1.3 rejected direct generated bookkeeping.\n\nRejected update: 5468641598668d1bf3920be3ff88ea5eb66ad5d1 -> e5c9bbd997405637b020d18e5681ca5ad82c462e\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T14:26:19Z",
          "mergedAt": "2026-07-31T14:29:52Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 344,
          "url": "https://github.com/kungfu-systems/build-images/pull/344",
          "title": "chore(release): promote TeX Gyre publication fonts alpha",
          "body": "Promote the reviewed TeX Gyre publication-font support from the active development line into the protected Alpha channel. The resulting Buildchain release must publish a latex-pdf-builder image containing tgpagella, tgheros, and tgcursor support.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T14:19:26Z",
          "mergedAt": "2026-07-31T14:35:25Z",
          "additions": 177,
          "deletions": 78,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 346,
          "url": "https://github.com/kungfu-systems/build-images/pull/346",
          "title": "Prepare v1.3.0-alpha.23",
          "body": "Create the generated version-state commit for v1.3.0-alpha.23.\n\nBuildchain generated this PR because protected branch alpha/v1/v1.3 rejected direct generated bookkeeping.\n\nRejected update: 4af152ec6945c61c54832b4a750f2a3232b05211 -> 8505d5bb7e3939540b5bc5b0cbff5ad02880459a\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T14:47:55Z",
          "mergedAt": "2026-07-31T14:51:16Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2116,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2116",
          "title": "feat(paper): add fleet-safe v3 work controls",
          "body": "## Summary\n\n- add typed Paper work start/submit plans with canonical remote, exact dev SHA, clean-tree, safe-branch, non-force, and correct PR target gates\n- add data-driven Paper fleet audit/update with exact v3 dependency, pnpm lock, managed workflow, authority, and live GitHub governance observations\n- scaffold and migrate repository-pinned pnpm scripts while preserving fast local make pdf and protected reproducibility/release gates\n- update the closed-world CLI/Node registries and KFD-2 typed residual-risk evidence\n\n## Validation\n\n- pnpm run check: full architecture, inventory, workflow, 1047/1047 unit tests passed; generated action bundle refreshed and integrity-checked\n- focused Paper/public-surface/release-impact tests passed after rebase to the latest dev/v3/v3.0\n- train canary: train/v3/v3.0/paper-fleet-golden-path\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T14:14:52Z",
          "mergedAt": "2026-07-31T14:55:54Z",
          "additions": 2680,
          "deletions": 862,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 48,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/48",
          "title": "build(paper): pin TeX Gyre Alpha image",
          "body": "Pin the Machine Life publication toolchain to the public build-images v1.3.0-alpha.23 latex-pdf-builder digest so the redesigned edition builds with the qualified TeX Gyre font set.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T15:00:45Z",
          "mergedAt": "2026-07-31T15:01:34Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 49,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/49",
          "title": "release(alpha): publish redesigned Machine Life edition",
          "body": "Promote the redesigned Machine Life edition and its pinned TeX Gyre-capable latex-pdf-builder image into the protected Alpha publication channel.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T15:02:01Z",
          "mergedAt": "2026-07-31T15:03:05Z",
          "additions": 575,
          "deletions": 124,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 50,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/50",
          "title": "chore(release): prepare Machine Life alpha.5",
          "body": "Advance the publication version, visible paper date, and generated site bundle coordinates to v0.1.0-alpha.5 before retrying the sealed Alpha publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T15:11:04Z",
          "mergedAt": "2026-07-31T15:11:57Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2117,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2117",
          "title": "fix(paper): audit exact branch protection",
          "body": "## Summary\n\n- aggregate classic branch protection and repository rulesets for Paper fleet governance\n- audit exact descriptor-admitted dev, alpha, and release refs with exact GitHub Actions check bindings\n- admit the five Paper release/v0/v0.1 targets and regenerate public contract metadata\n\n## Validation\n\n- pnpm run check\n- 1086 tests passed\n- maintainability, architecture, site, workflows, and six action bundles passed\n\n## Safety\n\n- read-only audit path only\n- no branch or repository setting mutation from the CLI\n- missing release protection fails closed",
          "author": "dongkeren",
          "createdAt": "2026-07-31T15:08:29Z",
          "mergedAt": "2026-07-31T15:12:38Z",
          "additions": 200,
          "deletions": 90,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 51,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/51",
          "title": "release(alpha): publish Machine Life v0.1.0-alpha.5",
          "body": "Promote the explicit v0.1.0-alpha.5 publication state, redesigned paper, regenerated site bundles, and TeX Gyre-capable pinned build image into the protected Alpha channel.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T15:12:28Z",
          "mergedAt": "2026-07-31T15:13:26Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 52,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/52",
          "title": "Prepare v0.1.0-alpha.5",
          "body": "Create the generated version-state commit for v0.1.0-alpha.5.\n\nBuildchain generated this PR because protected branch dev/v0/v0.1 rejected direct generated bookkeeping.\n\nRejected update: d6fb0d12c82ed9d92384307244c9e64736bbfc26 -> 6d5d32b7df62603716c3728a077607ab1f24154b\n\nGitHub response: Changes must be made through a pull request.",
          "author": "app/kungfu-paper-release-bot",
          "createdAt": "2026-07-31T15:15:36Z",
          "mergedAt": "2026-07-31T15:19:46Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2118,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2118",
          "title": "chore(release): promote paper fleet golden path to alpha",
          "body": "## Summary\n\nPromote the reviewed Buildchain v3 Paper fleet golden path from `dev/v3/v3.0` into the protected Alpha channel.\n\n- includes dev merge `67cbf454b065a9a6bf9cd63dd941dea5dc960f9b`\n- includes #2116 Paper work/fleet controls and #2117 exact governance audit\n- preserves the current Alpha version state until the release controller prepares the next prerelease\n- generated contract digest was rebuilt from the merged Alpha tree\n\n## Validation\n\n- `pnpm run check`\n- 1086/1086 tests\n- maintainability, architecture, site, workflows, and six action bundles passed\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T15:19:37Z",
          "mergedAt": "2026-07-31T15:21:19Z",
          "additions": 2817,
          "deletions": 889,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2119,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2119",
          "title": "Prepare v3.0.3-alpha.2",
          "body": "Create the generated version-state commit for v3.0.3-alpha.2.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: 00a07a9a2eb0e4839727cf455fa209066166abbf -> 130f9826cdf064aa2bcecd4325812af8c93947ec\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T15:27:13Z",
          "mergedAt": "2026-07-31T15:28:58Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 1817,
          "url": "https://github.com/kungfu-systems/kungfu/pull/1817",
          "title": "feat(release): bind updates to product release cuts",
          "body": "## Summary\n\n- introduce Product Release Cut as the exact immutable identity for public and Shifu-local product builds\n- bind native CLI selection, side-by-side inventory, rollback, signed channel supersession, bootstrap receipts, and Shifu desktop promotion to exact Cut and platform-slice roots\n- preserve SemVer as a weak human label while allowing authorized same-SemVer Cut successors and rejecting absent, diverged, or unknown transitions\n- open Evolution Stage 10 and document the updater authority split; this PR does not publish a release or mutate an installed product\n\n## Related issue\n\nAtlas Assignment `2026-07-29-kungfu-release-cut-updater-convergence`\n\n## Changes\n\n- add the Release Cut contract, transition validation, and Cut-aware distribution/runtime/channel handling\n- add hidden native Shifu apply/rollback adapters and retained-image rollback independent of source archives\n- make KFD-3 register desktop, CLI archive, and final upgrade manifest in one provenance slot\n- bind bootstrap/channel/manifests/receipts and KFD evidence projections to the exact Cut\n- make registrar and promotion revalidate exact local artifact kind, format, digest, and size through one shared authority\n- publish the cross-process promotion lock only after its private owner record is fully written and synced\n- add disposable native handoff coverage for same-SemVer distinct Cuts, side-by-side install, deleted source archives, rollback, and interrupted promotion recovery\n- reject publication-ineligible local Cuts at public discovery and signed-channel consumption boundaries\n- give deferred Cut successors an exact `active-work-must-be-idle` result and machine-readable idle-wait impact\n- preserve KFD source binding across protected rebase-queue replay only when the source is a commit and an exact full-tree equivalent remains on the bounded first-parent history\n\n## Verification\n\n- final exact head `c55b7b47c18bccbc6f840cb461ce2bfa2f4e93b4`, tree `b3658f4b9871a54713a9bc56aa2cc0ef21046bc9`, protected base `9b421de23d43ddb4c704635ab53e374b131733df`\n- local `./shifu check:source` passed at the final exact head, including the bounded tree-equivalent queue-replay regression\n- GitHub Actions run `30642269350` completed successfully at the final exact head\n- runtime upgrade control plane: 134 passed; desktop updater adapter: 72 passed\n- source contract suite: 862 tests, 852 passed, 10 conditional skips, 0 failed\n- Python type baseline: no issues in 206 source files\n- KFD evidence: KFD-1 witness, 5 KFD-2 claims, 161 KFD-3 surfaces\n- KFD support matrix: 19 positive/fail-closed fixtures, 4 shipped-support rows, root `sha256:4ec38019c02a5a414add93e088e3551aafff1c179b60160ded758bd0eece3841`\n- canonical policy root: `sha256:cc42aa6432a09432bb31bb8ca69d7134b3413e36e39d5e77cef296472e2d0f38`\n- publication registry root: `sha256:852c7aa3118920d66acdf876a5c52f2facf85c871bc8e196a5860a5a503dcd50`\n- packaged manifest convergence root: `sha256:a22ea3c042430a5206ce5979681caa67a2da61caf3dfc04d4af46241e6074f30`\n- physical successor Cut: `sha256:5a4fc0eec67ef463e0a4eb5e126b68753fd5bc548dcacc3a7fd5e22450c27bd1`, parent `sha256:c3543bddcb10faf4eb28bb509b16645f46cf10ee1e58b5db8319c3b22a8032f1`\n- physical campaign at pre-replay head `d00c36c541505655d1b5f1127bfe0d47669106f6` retained generation 1/2 receipts, pruned the successor source slot, and completed generation 3 rollback\n- scoped Project Cut composition qualified with no omissions or conflicts at `sha256:37e2424de1ad03678f18d1ddd941cc1219a34f54e3d13c1e2709c0744ff28ccd`\n- fresh-context independent review at the final exact head: FIT, P0=0, P1=0, P2=0\n- no public release, channel, tag, `/Applications`, or installed dogfood state was mutated\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"KF-ADR-019fabb5-62a0-7b8d-8f8d-6505efdbc239\"],\n  \"summary\": \"Bind product update, rollback, channel, bootstrap, and Shifu promotion authority to exact Product Release Cuts\",\n  \"verification\": [\"exact-head GitHub Actions run 30642269350 passed for c55b7b47c18b tree b3658f4b9871 against 9b421de23d\", \"local source acceptance passed on the immediately preceding queue-replay repair head\", \"commit-bound bounded exact-tree queue-rebase KFD source binding regressions passed\", \"runtime upgrade 134 passed\", \"desktop updater 72 passed\", \"KFD matrix 19 passed\", \"fresh-context independent review FIT with P0 P1 P2 all zero\", \"qualified scoped Project Cut composition\", \"source-pruned native rollback campaign\", \"shared digest and size identity validation\", \"public channel rejects publication-ineligible local Cuts at both consumer boundaries\"]\n}\n-->\n\n## [Evolution Map](../docs/evolution/README.md) impact\n\nEvolution impact: opens\n\nStage 10 records the Product Release Cut and native updater convergence boundary.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change governs release identity and evidence, but performs no channel publication, package publishing, credential use, or mutation of a real installed product. Public Cut movement remains signed-channel-authorized and fail-closed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6Imt1bmdmdS10ZWNobmljYWwtc3Rld2FyZHNoaXAiLCJhc3NpZ25tZW50SWQiOiIyMDI2LTA3LTI5LWt1bmdmdS1yZWxlYXNlLWN1dC11cGRhdGVyLWNvbnZlcmdlbmNlIiwiZGVsaXZlcnlDbGFzcyI6Im5hdGl2ZS1wcm9vZi1yZXF1aXJlZCIsImRldkhlYWQiOiI5YjQyMWRlMjNkNDNkZGI0YzcwNDYzNWFiNTNlMzc0YjEzMTczM2RmIiwicHVsbFJlcXVlc3RIZWFkIjoiYzU1YjdiNDdjMThiY2NiYzZmODQwY2I0NjFjZTJiZmEyZjRlOTNiNCIsInJlcGxheWVkQ2FuZGlkYXRlIjoiYzEyNDg2NjgyOTYzODdjOTk2MDIwNDZkZTU4NWU0YzE1NWJlNWYwYSIsInJlcGxheWVkVHJlZSI6ImIzNjU4ZjRiOTg3MWE1NDcxM2E5YmM1NmFhMmNjMGVmMjEwNDZiYzkiLCJxdWV1ZUF0dGVtcHQiOiJjNTViN2I0N2MxOGJjY2JjNmY4NDBjYjQ2MWNlMmJmYTJmNGU5M2I0QDliNDIxZGUyM2Q0M2RkYjRjNzA0NjM1YWI1M2UzNzRiMTMxNzMzZGYiLCJhZG1pc3Npb25Qcm9vZlJvb3QiOiJzaGEyNTY6Y2I2YjIzNzYxMWExMDIzNDkxYzc1NTRkYzllYTE2MzBiMDBiMDdhYmUzZDkyOGJjYTQwNTFlMTU3MTZjNzRkNyIsImFkbWlzc2lvblByb29mUm9vdHMiOlsic2hhMjU2OmI2MWZlZTQ5OGQyZjdiNzUwMDFhNWQ3MTkwYzVlNzY2OTM4YjMwMzQxMTZmODE3ZmEyNzAyMDIwZDk5YzYzYWYiLCJzaGEyNTY6Y2I2YjIzNzYxMWExMDIzNDkxYzc1NTRkYzllYTE2MzBiMDBiMDdhYmUzZDkyOGJjYTQwNTFlMTU3MTZjNzRkNyJdLCJzdGF0dXNDb250ZXh0IjoiUXVldWUgZmFtaWx5IGxlYXNlL2Q5OWYzYTkxNjY3MzllMGQiLCJsZWFzZVJvb3QiOiJzaGEyNTY6MTNmNDk4N2ZmNzc3MmNkMjNkYzc1YmViMzdmYmQzMjI2MDNiNTRmZjBlMDRhN2Y1MmEzZjBkMDExYjIwYjRmMSJ9 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-29T03:03:31Z",
          "mergedAt": "2026-07-31T15:33:49Z",
          "additions": 9142,
          "deletions": 1048,
          "changedFiles": 79
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2120,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2120",
          "title": "fix(paper): converge legacy v2 workflows",
          "body": "## Summary\n\n- migrate the standard Paper verify workflow to the exact released Buildchain source\n- fail fleet audit when any Paper workflow still calls a v2 Buildchain reusable surface\n- keep contract-lock intent on the declared v3 channel while binding the exact resolved SHA\n- derive acceptedAt from npm publication time when the CLI runs through npx without a Git checkout\n\n## Validation\n\n- pnpm run check\n- 1086/1086 tests\n- maintainability, architecture, site, workflows, and six action bundles passed\n\n## Compatibility\n\n- paper content and publication config remain untouched\n- only the recognized Buildchain check.yml uses line is rewritten in an existing verify.yml\n- existing custom scripts and package fields are preserved",
          "author": "dongkeren",
          "createdAt": "2026-07-31T15:46:21Z",
          "mergedAt": "2026-07-31T15:50:33Z",
          "additions": 124,
          "deletions": 12,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2121,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2121",
          "title": "chore(release): promote paper v3 convergence to alpha",
          "body": "Promotes the reviewed Paper v3 convergence fix from dev/v3/v3.0 to alpha/v3/v3.0.\\n\\nValidation: pnpm run check (1086/1086).",
          "author": "dongkeren",
          "createdAt": "2026-07-31T15:56:27Z",
          "mergedAt": "2026-07-31T15:57:59Z",
          "additions": 124,
          "deletions": 12,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2064,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2064",
          "title": "fix(qualification): register path-loaded Python guests",
          "body": "## Summary\n\n- register path-loaded guest modules in `sys.modules` before `exec_module`\n- preserve Python import machinery semantics required by `dataclasses` on Python 3.14\n- repair both sandbox-launch and subprocess-capability qualification fixtures\n- rebind the KFD prebuild witness to the exact protected-main replay commit after the preceding release-cut delivery tightened commit-object validation\n\n## Evidence\n\nThe exact-runtime Dev Verify run 30636673838 completed the Gate profile but produced non-qualifying receipts on macOS and Linux. The macOS log showed `dataclasses` resolving `cls.__module__` through `sys.modules` and failing because the path-loaded guest module had not been registered.\n\nAfter protected dev advanced, source acceptance correctly exposed that the KFD witness still named the original work-branch commit even though the exact tree-equivalent replay commit is `2a29edb1f2b2b7d79ad8244ac91aef26f5a0775e` on main. The witness now names that reachable protected commit without changing KFD content.\n\nValidated locally:\n\n- Python 3.14.6 fixture runs for sandbox-launch and subprocess-caps\n- `node scripts/buildchain-kfd-evidence.mjs --check`\n- `./shifu check:source`: 852 passed, 10 conditional skips; the sole initial local failure was missing bare pytest\n- locked uv pytest rerun of `scripts/readonly-agent-bootstrap.test.mjs`: 1/1 passed\n- full repository pre-commit qualification hook\n- `git diff --check`\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Restore standard import machinery semantics in two qualification fixtures and bind the existing KFD witness to its exact protected replay commit; no architecture or runtime product contract changes.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T15:18:33Z",
          "mergedAt": "2026-07-31T16:01:08Z",
          "additions": 7,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2122,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2122",
          "title": "Prepare v3.0.3-alpha.3",
          "body": "Create the generated version-state commit for v3.0.3-alpha.3.\n\nBuildchain generated this PR because protected branch alpha/v3/v3.0 rejected direct generated bookkeeping.\n\nRejected update: f30bb2678cacbae947eb46411c13eda75e9e35b0 -> 4f6782d985c32ae8761edc3ee4dc06cbbda4c8eb\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T16:03:52Z",
          "mergedAt": "2026-07-31T16:05:59Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2065,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2065",
          "title": "fix(agent-session): canonicalize native runtime roots",
          "body": "## Summary\n- canonicalize the native Agent Session runtime root before constructing the C++ locator\n- resolve existing path aliases with the OS-native realpath while preserving missing suffixes\n- cover POSIX aliases and Windows case normalization without changing registration timeouts\n\n## Evidence\n- exact-checkout `./shifu build:core` completed\n- native coordinator-to-two-peer mmap+nng roundtrip passed\n- Agent Session control-plane suite passed 98/98\n- repository staged gate passed\n- full installed-provider suite had 96/99 pass; the three unrelated failures are local Codex/Claude adapter version drift\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix makes the existing shared data-root identity deterministic across path aliases without changing runtime architecture, protocols, or qualification thresholds.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [x] none of the above\n\n<!-- kungfu-family-queue-lease:v1 eyJzY2hlbWEiOiJwcm9qZWN0LmN1dC5mYW1pbHktcXVldWUtbGVhc2UvdjEiLCJzdGF0ZSI6ImFjdGl2ZSIsImluaXRpYXRpdmVJZCI6IjIwMjYtMDctMzAta3VuZ2Z1LXF1YWxpZmllZC1jb3JlLWRldmVsb3Blci1hY2NlbGVyYXRpb24tZmFtaWx5IiwiYXNzaWdubWVudElkIjoiMjAyNi0wNy0zMC1rdW5nZnUtcXVhbGlmaWVkLWNvcmUtd2luZG93cy14ODYtNjQtY29uc3VtZXIiLCJkZWxpdmVyeUNsYXNzIjoibmF0aXZlLXByb29mLXJlcXVpcmVkIiwiZGV2SGVhZCI6ImNhOGFiMGZjNmFjNzJkODVlOTgwZDEzYTNmOTdjNTIyMDQ1M2I0NGEiLCJwdWxsUmVxdWVzdEhlYWQiOiJiZjFkNDI4NTU1NTcxMDE4NGZhNmE1OTEwNDkwMDZlYjY4ZmQ1YmRkIiwicmVwbGF5ZWRDYW5kaWRhdGUiOiJkZmRiZTAyOThhYmVjMmVlOTJlZTBlMGExNmY1MWE2Mzk4ZWNkZWQyIiwicmVwbGF5ZWRUcmVlIjoiYTUyZGEyNjJiNWEwMzQxOWVkMzQ2ODgzNjFiMWRhNjk0YzFmNjEzNyIsInF1ZXVlQXR0ZW1wdCI6ImJmMWQ0Mjg1NTU1NzEwMTg0ZmE2YTU5MTA0OTAwNmViNjhmZDViZGRAY2E4YWIwZmM2YWM3MmQ4NWU5ODBkMTNhM2Y5N2M1MjIwNDUzYjQ0YSIsImFkbWlzc2lvblByb29mUm9vdCI6InNoYTI1Njo2YTEwNjNkNTkzZmVjNTkzN2NhNWFmNDE1NTI4OGVhYTI1NGQ3ZDk0NjIyODEyOGNhYWM4NTQ3MDQ4NWUxZGZlIiwiYWRtaXNzaW9uUHJvb2ZSb290cyI6WyJzaGEyNTY6MDAxZDQxMGFjOTYyZTFmNmQ0NDhiYzNkY2NmY2VhMjlkOTY2MmEyMDRlYmI1M2RiZjczNTBlZWJkY2Y2ZjQ1MCIsInNoYTI1Njo2YTEwNjNkNTkzZmVjNTkzN2NhNWFmNDE1NTI4OGVhYTI1NGQ3ZDk0NjIyODEyOGNhYWM4NTQ3MDQ4NWUxZGZlIl0sInN0YXR1c0NvbnRleHQiOiJRdWV1ZSBmYW1pbHkgbGVhc2UvOTZkM2JmZjU3MWIwNGJiMiIsImxlYXNlUm9vdCI6InNoYTI1Njo4YWZjMjMwOWE5ODJiYTI1NTIwZDMyYjMwYzYzODg2ZWQ1Yzg2NTc0MmM0ZGY0MTNhZTYzNzgyOWVmZjQ5ZGZjIn0 -->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T15:40:20Z",
          "mergedAt": "2026-07-31T16:13:47Z",
          "additions": 51,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-episodes-to-primitives",
          "number": 13,
          "url": "https://github.com/kungfu-systems/paper-episodes-to-primitives/pull/13",
          "title": "chore(paper): buildchain v3 golden path final",
          "body": "## Summary\n\nSubmit this Paper work branch through the protected Buildchain development path.\n\n## Safety\n\n- No direct push to a protected channel.\n- No force push.\n- Publication remains behind the accepted PR and release gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T16:17:33Z",
          "mergedAt": "2026-07-31T16:19:43Z",
          "additions": 173,
          "deletions": 43,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 73,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/73",
          "title": "chore(paper): buildchain v3 golden path final",
          "body": "## Summary\n\nSubmit this Paper work branch through the protected Buildchain development path.\n\n## Safety\n\n- No direct push to a protected channel.\n- No force push.\n- Publication remains behind the accepted PR and release gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T16:18:03Z",
          "mergedAt": "2026-07-31T16:19:49Z",
          "additions": 167,
          "deletions": 42,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-kfd-machine-life-roadmap",
          "number": 53,
          "url": "https://github.com/kungfu-systems/paper-kfd-machine-life-roadmap/pull/53",
          "title": "chore(paper): buildchain v3 golden path final",
          "body": "## Summary\n\nSubmit this Paper work branch through the protected Buildchain development path.\n\n## Safety\n\n- No direct push to a protected channel.\n- No force push.\n- Publication remains behind the accepted PR and release gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T16:18:22Z",
          "mergedAt": "2026-07-31T16:19:55Z",
          "additions": 71,
          "deletions": 23,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 99,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/99",
          "title": "chore(paper): buildchain v3 golden path final",
          "body": "## Summary\n\nSubmit this Paper work branch through the protected Buildchain development path.\n\n## Safety\n\n- No direct push to a protected channel.\n- No force push.\n- Publication remains behind the accepted PR and release gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T16:18:42Z",
          "mergedAt": "2026-07-31T16:20:02Z",
          "additions": 177,
          "deletions": 60,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 78,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/78",
          "title": "chore(paper): buildchain v3 golden path final",
          "body": "## Summary\n\nSubmit this Paper work branch through the protected Buildchain development path.\n\n## Safety\n\n- No direct push to a protected channel.\n- No force push.\n- Publication remains behind the accepted PR and release gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T16:19:02Z",
          "mergedAt": "2026-07-31T16:20:09Z",
          "additions": 167,
          "deletions": 42,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2066,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2066",
          "title": "chore(kfd): refresh Alpha release evidence",
          "body": "## Summary\n\nRefresh the checked-in Buildchain KFD collaboration evidence so Alpha qualification is bound to the current admitted dev ancestry.\n\n## Related issue\n\nAlpha release closure.\n\n## Changes\n\n- Regenerate the Buildchain KFD evidence through the official Shifu generator.\n- Bind the prebuild collaboration interface evidence to source commit 3cacb8586e11680915daec7abea7d57b6edf0f77.\n\n## Verification\n\n- KUNGFU_DEV_BRANCH=dev/v4/v4.0 ./shifu check\n- KUNGFU_DEV_BRANCH=dev/v4/v4.0 ./shifu kfd:buildchain:check\n- git diff --check\n- Signed commit hook staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This maintenance refreshes generated release evidence provenance without changing an architecture contract\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change updates generated release evidence only; its exact source ancestry and deterministic regeneration were verified locally.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; behavior is unchanged)",
          "author": "dongkeren",
          "createdAt": "2026-07-31T16:59:36Z",
          "mergedAt": "2026-07-31T17:10:24Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2059,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2059",
          "title": "fix(qualification): quiesce Windows runtime before uninstall",
          "body": "## Summary\n\n- wait for packaged Windows runtime children to exit before starting the one-shot NSIS uninstaller\n- reuse the bounded process-under-install-root diagnostics for uninstall failures\n- fail closed after a bounded timeout; do not force-kill processes or post-delete installed files\n\n## Failure evidence\n\nWindows burst qualification run 30629454081 passed build, sealing, AgentSession, control-plane, presentation, catalog, contract, format, and SDK checks. `layers.surfaces` alone failed because NSIS started while a short-lived installed runtime child still held packaged DLLs, skipped those files, and did not retry them.\n\n## Verification\n\n- `./shifu exec node --test tests/qualification/layers/surfaces/installer.test.mjs` (11/11)\n- `./shifu exec biome check tests/qualification/layers/surfaces/installer.mjs tests/qualification/layers/surfaces/installer.test.mjs`\n- `./shifu check:staged`\n\n## Boundary\n\nThis changes qualification harness behavior only. It does not change shipped installer/uninstaller behavior.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This repair changes only the Windows qualification harness timing and does not alter an architecture contract or shipped product behavior\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T13:34:37Z",
          "mergedAt": "2026-07-31T17:26:38Z",
          "additions": 111,
          "deletions": 43,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2067,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2067",
          "title": "fix(release): converge local artifact identity",
          "body": "## Summary\n\n- exclude release-only local desktop artifact bytes from the shared product manifest identity\n- keep those bytes bound by the platform slice and Product Release Cut\n- cover the real desktop-finalized base plus CLI-embedded identity path\n\n## Evidence\n\nThe exact Build run 30647417124 completed macOS packaging through wheel, GUI, DMG/ZIP, and CLI installed-layout smoke, then failed with \"CLI archive and desktop release base have divergent upgrade identities\". The two manifests shared source, runtime, and frontend identities; only the finalized desktop manifest carried localArtifact, which was already bound separately into the platform slice.\n\nValidated locally:\n\n- node --test product/scripts/upgrade-manifest.test.mjs product/scripts/dist.test.mjs: 42/42 passed\n- full repository pre-commit qualification hook\n- staged Biome check\n- git diff --check\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Correct the projection of an existing product upgrade identity contract so release-only local artifact evidence remains in the Product Release Cut without splitting the shared CLI and desktop manifest identity.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-31T17:10:46Z",
          "mergedAt": "2026-07-31T17:45:09Z",
          "additions": 11,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2069,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2069",
          "title": "chore(kfd): anchor Alpha evidence to dev",
          "body": "## Summary\n\nAnchor the checked-in Buildchain KFD release evidence to the current protected dev commit so post-rebase Alpha verification can prove ancestry from the ordinary checkout.\n\n## Related issue\n\nAlpha release closure.\n\n## Changes\n\n- Regenerate the Buildchain KFD evidence through the official Shifu generator.\n- Replace the unreachable pre-rebase PR source with protected dev commit 266694ddc52c61b110a1c81ee0dd36caf069bae2.\n\n## Verification\n\n- KUNGFU_DEV_BRANCH=dev/v4/v4.0 ./shifu check\n- KUNGFU_DEV_BRANCH=dev/v4/v4.0 ./shifu kfd:buildchain:check\n- git diff --check\n- Signed commit staged gate\n- CI failure reproduction: the prior source d49b115b1c8bbdf38d6719d2fdd17cf8ecc85085 was unavailable and not an ancestor after rebase merge.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This maintenance refreshes generated release evidence provenance without changing an architecture contract\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe exact source ancestry and deterministic regeneration were verified locally.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; behavior is unchanged)",
          "author": "dongkeren",
          "createdAt": "2026-07-31T18:10:39Z",
          "mergedAt": "2026-07-31T18:20:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 162,
          "url": "https://github.com/kungfu-systems/libnode/pull/162",
          "title": "Refresh libnode v3 alpha contract lock",
          "body": "## Summary\n- accept exact `v3-alpha@15bf4369927d2c23beaf6ff531d52d5e1f6494fa`\n- refresh the runtime contract and compatibility digests\n- explicitly accept the changed `reusable-build` and `web-surface` breaking digests\n\n## Verification\n- generated with the Buildchain `v3-alpha` contract-lock writer\n- generated lock matches the committed JSON exactly\n- contract check reports `unchanged`, `compatible=true`, and no drift\n- libnode existing inputs remain valid; new Buildchain inputs are optional",
          "author": "dongkeren",
          "createdAt": "2026-07-31T14:21:33Z",
          "mergedAt": "2026-07-31T18:25:52Z",
          "additions": 6,
          "deletions": 6,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 206,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/206",
          "title": "feat(site): publish responsive audited demo renditions",
          "body": "## Summary\n\n- upgrade the auditable-demo importer to a collection descriptor with a featured demo and stable per-demo projection\n- select qualified media by declared role instead of fixed filenames\n- publish 1920x1080 and 1280x720 MP4/WebM renditions from one exact Release Passport, plus the 1280x720 README GIF and 1920x1080 poster\n- render responsive homepage and `/how-tested/auditable-demo/` media while retaining content-addressed evidence and exact authorization non-claims\n- keep manual validation and release-triggered refreshes on the same importer/check/build path\n\n## Verification\n\n- `corepack pnpm@11.7.0 run test:auditable-demo-import` (7 passed)\n- importer check against the exact Passport/media bundle (passed)\n- `corepack pnpm@11.7.0 run build` (passed)\n- `corepack pnpm@11.7.0 run check` (passed)\n- `git diff --check` (passed)\n- formal Kungfu qualification/render: https://github.com/kungfu-systems/kungfu/actions/runs/30646944258\n\n## Claim boundary\n\nThe site projects only the exact installed-artifact autoplay, Gate, responsive render, and Release Passport. First-party/System identity, KFD compliance, Product System metadata, package metadata, registry history, scan output, and standalone generation grant no authority.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T18:25:16Z",
          "mergedAt": "2026-07-31T18:32:12Z",
          "additions": 1771,
          "deletions": 177,
          "changedFiles": 43
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 207,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/207",
          "title": "Release production from 74e2900cdcc5",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `74e2900cdcc512e708e0bc2b9e1c65b8227903f7`\n- Artifact hash: `5adc74c59665285b8a2a39b4eee26af970a3eb607d2b8c7b2802114188e1b206`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/30655542240)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-74e2900cdcc5`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-31T18:35:48Z",
          "mergedAt": "2026-07-31T18:39:35Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2070,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2070",
          "title": "docs(demo): publish responsive audited media",
          "body": "## Summary\n\n- materialize the qualified `responsive-web-delivery-v1` README animation from Release Passport root `sha256:835bde89ae8cee57661dfc2f4ba96bbf6d2be1546d89f42fd0c18a331a7308da`\n- retain the content-addressed 1280x720 GIF and public evidence envelope in the repository\n- update the README proof block to the exact source, Gate, media bundle, and Release Passport from formal run 30646944258\n- preserve the explicit authorization non-claims: first-party/System identity, KFD compliance, Product System metadata, package metadata, scans, and standalone generation grant no authority\n\n## Verification\n\n- `./shifu test:auditable-demo` (42 passed)\n- `node scripts/update-auditable-demo-readme.mjs --check true ...` (passed)\n- `npm --prefix framework/spec run build && node --test framework/spec/index.test.js` (12 passed)\n- `uv run --project framework/core --frozen node --test scripts/readonly-agent-bootstrap.test.mjs` (1 passed)\n- staged repository gate passed during commit\n- formal qualification and render: https://github.com/kungfu-systems/kungfu/actions/runs/30646944258\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"KF-ADR-019f86da-4f90-786d-aa24-a97705e13917\"],\n  \"summary\": \"Materialize the exact qualified responsive auditable-demo evidence into README public evidence.\",\n  \"verification\": [\n    \"42 targeted auditable-demo tests passed\",\n    \"staged repository gate passed\",\n    \"formal responsive media qualification run 30646944258 passed\"\n  ]\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T18:23:54Z",
          "mergedAt": "2026-07-31T18:52:54Z",
          "additions": 113,
          "deletions": 17,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2071,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2071",
          "title": "fix(kfd): recover shallow history before evidence checks",
          "body": "## Summary\n\nRecover complete Git ancestry before read-only Buildchain KFD evidence validation so shallow CI checkouts can prove the protected source ancestry deterministically.\n\n## Changes\n\n- Reuse the existing gate-history preparation helper before read-only KFD evidence validation.\n- Preserve the historical evidence checker line budget.\n\n## Verification\n\n- node --test scripts/prepare-gate-measurement-history.test.mjs scripts/source-acceptance.test.mjs\n- KUNGFU_DEV_BRANCH=dev/v4/v4.0 ./shifu check\n- KUNGFU_DEV_BRANCH=dev/v4/v4.0 ./shifu kfd:buildchain:check\n- KUNGFU_DEV_BRANCH=dev/v4/v4.0 node scripts/code-complexity-budget.mjs\n- Biome and commit hooks\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This maintenance restores complete source ancestry for release evidence validation without changing an architecture contract\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe history hydration is filter-limited, read-only, and covered by shallow-clone tests.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not applicable; the release contract is unchanged)",
          "author": "dongkeren",
          "createdAt": "2026-07-31T18:45:51Z",
          "mergedAt": "2026-07-31T19:20:13Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 100,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/100",
          "title": "fix(paper): restore TeX Gyre typography",
          "body": "## Summary\n\n- restore TeX Gyre Pagella, Heros, and Cursor across the white paper and visual proof\n- pin the TeX Gyre-capable latex builder image\n- advance the publication surface to 0.1.0-alpha.12\n\n## Validation\n\n- npm run check\n- local PDF build with the TeX Gyre-enabled latex builder\n- embedded-font inspection with pdffonts\n- visual inspection of representative pages\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, billing, quota, or usage-attribution changes\n- [x] Release identity changes are limited to the Alpha version and pinned builder digest",
          "author": "dongkeren",
          "createdAt": "2026-07-31T19:46:08Z",
          "mergedAt": "2026-07-31T19:46:56Z",
          "additions": 15,
          "deletions": 15,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 102,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/102",
          "title": "chore(release): describe alpha.12 impact",
          "body": "## Summary\n\nUpdate the release impact declaration for the Alpha 12 TeX Gyre typography restoration.\n\n## Validation\n\n- npm run check\n- jq release-impact.json\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, billing, quota, or usage-attribution changes\n- [x] Release metadata now matches the declared Alpha version and typography change",
          "author": "dongkeren",
          "createdAt": "2026-07-31T19:52:14Z",
          "mergedAt": "2026-07-31T19:52:53Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 101,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/101",
          "title": "chore(release): promote white paper alpha.12",
          "body": "## Summary\n\nPromote the TeX Gyre typography restoration and pinned latex builder to the Alpha channel.\n\n## Release\n\n- target version: `0.1.0-alpha.12`\n- target tag: `v0.1.0-alpha.12`\n- preserves the long-lived `dev/v0/v0.1` and `alpha/v0/v0.1` channel branches\n\n## Validation\n\n- required checks passed on the development PR\n- local PDF build succeeded with TeX Gyre packages\n- embedded fonts and representative pages were inspected\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, billing, quota, or usage-attribution changes\n- [x] Release identity changes are limited to the Alpha version and pinned builder digest",
          "author": "dongkeren",
          "createdAt": "2026-07-31T19:47:34Z",
          "mergedAt": "2026-07-31T19:53:41Z",
          "additions": 196,
          "deletions": 79,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 103,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/103",
          "title": "fix(release): reuse narrow generated-write token",
          "body": "## Summary\n\nPass the repository's existing narrow promotion token into the Buildchain v3 generated-write input when GitHub App credentials are not configured. The reusable workflow still forbids `github.token` fallback.\n\n## Validation\n\n- npm run check\n- git diff --check\n- tracked secret-file scan\n\n## Governance\n\n- [x] No secret value is read, copied, printed, or committed\n- [x] The existing repository secret remains the only credential source\n- [x] No provider API, billing, quota, or usage-attribution changes",
          "author": "dongkeren",
          "createdAt": "2026-07-31T20:00:09Z",
          "mergedAt": "2026-07-31T20:00:47Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 104,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/104",
          "title": "fix(release): restore alpha.12 generated-write authority",
          "body": "## Summary\n\nPromote the Buildchain v3 generated-write authority compatibility fix for the Alpha 12 publication transaction.\n\n## Release\n\n- resumes target version `0.1.0-alpha.12`\n- reuses the existing narrow repository token\n- does not fall back to `github.token`\n- preserves the long-lived channel branches\n\n## Validation\n\n- required checks passed on PR #103\n- no secret value was read, copied, printed, or committed\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs are present in the diff\n- [x] Release identity remains `v0.1.0-alpha.12`\n- [x] The change is limited to secret routing for the sealed publisher",
          "author": "dongkeren",
          "createdAt": "2026-07-31T20:01:12Z",
          "mergedAt": "2026-07-31T20:01:51Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2123,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2123",
          "title": "Release v3.0.3 from qualified v3.0.3-alpha.3",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v3.0.3-alpha.3`\n- Candidate SHA: `4f6782d985c32ae8761edc3ee4dc06cbbda4c8eb`\n- Selection: `latest-qualified`\n- Ledger ref: `buildchain/candidate-ledger/v3/v3.0`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T20:16:31Z",
          "mergedAt": "2026-07-31T20:18:19Z",
          "additions": 27872,
          "deletions": 3536,
          "changedFiles": 191
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2074,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2074",
          "title": "fix(kfd): preserve committed prebuild source binding",
          "body": "## Summary\n\nKeep read-only KFD release-evidence checks bound to the source SHA recorded in the committed KFD-3 prebuild witness, even when the exact release controller projects BUILDCHAIN_SOURCE_SHA for the checkout. This linear follow-up composes with the newly merged shallow-history recovery.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- select the committed witness source in check mode and validate its ancestry or protected-rebase tree equivalence\n- retain configured/current source selection in write mode\n- add regression coverage and document the fail-closed boundary\n\n## Verification\n\n- BUILDCHAIN_SOURCE_SHA=$(git rev-parse HEAD) ./shifu kfd:buildchain:check\n- ./shifu check:source\n- ./shifu check\n- git diff --check\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix restores the documented KFD witness source-binding contract without changing architecture authority or release semantics\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: read-only validation of the committed KFD-3 prebuild witness during exact-source release qualification. The regression command reproduces the controller environment and remains fail-closed for malformed, unrelated, or non-equivalent source bindings.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-31T20:20:40Z",
          "mergedAt": "2026-07-31T20:47:59Z",
          "additions": 124,
          "deletions": 12,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 2075,
          "url": "https://github.com/kungfu-systems/kungfu/pull/2075",
          "title": "fix(kfd): recover witnesses from cached checkouts",
          "body": "## Summary\n\nRecover committed KFD prebuild witness commits when Buildchain restores a locked consumer checkout from the trusted local/reference cache and therefore has no `origin` remote.\n\n## Related issue\n\nFollow-up from final Buildchain Linux GitHub Artifact Attestation qualification.\n\n## Changes\n\n- derive a sanitized HTTP(S) source repository URL from the GitHub Actions repository context\n- try the existing origin, rewritten bundle, and declared source repository without weakening exact-commit verification\n- preserve fail-closed behavior when the witness or every trusted fetch source is unavailable\n- cover no-origin cache checkouts, URL validation, and the no-source negative case\n\n## Verification\n\n- `./shifu check`: changed files, KFD evidence, and target tests pass; the broader local run reaches only the known missing `framework/spec/dist` build-artifact prerequisite\n- `./shifu check:source`: 854 tests pass; the sole local environment failure is the known bare `pytest` PATH prerequisite\n- pre-commit staged gate: pass\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix restores the existing exact-source KFD verification contract for Buildchain cache-hit checkouts; it does not alter architecture authority or release claims.\"\n}\n-->\n\n## Evolution Map impact\n\nEvolution impact: none\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects only recovery of the exact historical commit object needed to verify already-committed KFD release evidence. SHA identity remains mandatory and missing history remains non-qualifying.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not required; external behavior and authority are unchanged)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-31T21:20:40Z",
          "mergedAt": "2026-07-31T21:29:13Z",
          "additions": 162,
          "deletions": 34,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 106,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/106",
          "title": "chore(release): reconcile alpha.12 publication state",
          "body": "Reconcile the reviewed Alpha channel history back into the development line after npm publication completed but protected generated-write finalization was interrupted.\\n\\nThe head is the exact admitted Alpha SHA 7b0c951699836afb300c16ed14d70970f29b0b92. This PR advances history only: the compared trees have no file changes. Merging it lets the sealed publication transaction resume idempotently and create the public GitHub Release assets.\\n\\nSupersedes #105 to satisfy the latest-push approval rule with distinct push and review identities.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T23:09:01Z",
          "mergedAt": "2026-07-31T23:10:38Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 347,
          "url": "https://github.com/kungfu-systems/build-images/pull/347",
          "title": "fix(demo-renderer): scale terminal to source frames",
          "body": "## Summary\n- scale terminal chrome and PTY cells with the source scene dimensions\n- keep native 1080p rendering and deterministic 720p downsampling aligned\n- add a 150x36 lower-right pixel sentinel regression for terminal occupancy\n\n## Verification\n- `pnpm run check`\n- `git diff --check`\n- `node --check images/demo-renderer/render-demo.mjs`\n- `bash -n images/demo-renderer/tests/smoke.sh`",
          "author": "dongkeren",
          "createdAt": "2026-07-31T23:09:28Z",
          "mergedAt": "2026-07-31T23:12:54Z",
          "additions": 35,
          "deletions": 15,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 348,
          "url": "https://github.com/kungfu-systems/build-images/pull/348",
          "title": "chore(release): promote full-frame demo renderer alpha",
          "body": "## Summary\n- promote the source-scaled demo renderer to the v1.3 alpha channel\n- publish a renderer whose native 1080p composition fills the terminal frame\n- retain deterministic 720p renditions from the same source frame set\n\n## Qualification\n- feature PR #347 approved and merged\n- Linux/amd64 renderer qualification passed\n- 150x36 PTY lower-right occupancy regression passed",
          "author": "dongkeren",
          "createdAt": "2026-07-31T23:13:22Z",
          "mergedAt": "2026-07-31T23:16:41Z",
          "additions": 35,
          "deletions": 15,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 349,
          "url": "https://github.com/kungfu-systems/build-images/pull/349",
          "title": "Prepare v1.3.0-alpha.24",
          "body": "Create the generated version-state commit for v1.3.0-alpha.24.\n\nBuildchain generated this PR because protected branch alpha/v1/v1.3 rejected direct generated bookkeeping.\n\nRejected update: 618ef44bdd9488a9a7aedf545aee0de0bbf0fc84 -> 355a92eb95fa57df687a7fe8f304bff1c3c95b5b\n\nGitHub response: Changes must be made through a pull request.",
          "author": "dongkeren",
          "createdAt": "2026-07-31T23:29:45Z",
          "mergedAt": "2026-07-31T23:32:48Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2125,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2125",
          "title": "feat(paper): enforce agent entry contract",
          "body": "## Summary\n\n- add a digest-bound Paper agent-entry contract and managed AGENTS.md section\n- make work start/submit require the exact contract and runtime SHA\n- enforce feature-to-dev lineage inside the existing required Buildchain check\n- scaffold and migrate the agent entry, verification workflow, scripts, and provisioning authority\n\n## Verification\n\n- `pnpm run check` (1086/1087 unit tests passed; one existing concurrent npm dry-run assertion was transient)\n- isolated npm bootstrap dry-run passed immediately afterward\n- Paper tests: 12/12 passed, including CLI local entry and adversarial CI/script/marker cases\n- public-surface audit and standalone binary tests passed\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-31T23:45:44Z",
          "mergedAt": "2026-07-31T23:58:49Z",
          "additions": 1024,
          "deletions": 214,
          "changedFiles": 26
        }
      ],
      "developmentAttribution": {
        "repository": "kungfu-systems/kungfu",
        "branch": "dev/v4/v4.0",
        "window": {
          "id": "kungfu-v4-through-operating-cutoff",
          "label": "Kungfu v4 public branch through the operating cutoff",
          "startInclusive": "2026-06-16T00:00:00.000Z",
          "endExclusive": "2026-08-01T00:00:00.000Z",
          "duration": "P46D"
        },
        "windowRelation": "overlaps-bootstrap-and-operating-observations",
        "totalCommitsScanned": 2908,
        "explicitlyAttributedCommits": 135,
        "byAgent": [
          {
            "agent": "Codex",
            "commits": 78,
            "markerTypes": [
              {
                "name": "agent-field",
                "count": 78
              }
            ]
          },
          {
            "agent": "Claude",
            "commits": 34,
            "markerTypes": [
              {
                "name": "agent-field",
                "count": 34
              }
            ]
          },
          {
            "agent": "Cursor",
            "commits": 21,
            "markerTypes": [
              {
                "name": "co-author-trailer",
                "count": 21
              }
            ]
          },
          {
            "agent": "Amp",
            "commits": 2,
            "markerTypes": [
              {
                "name": "co-author-trailer",
                "count": 2
              }
            ]
          }
        ],
        "records": [
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "a20748de6117b627d8ad9e41551f53fe7fa9f5f2",
            "url": "https://github.com/kungfu-systems/kungfu/commit/a20748de6117b627d8ad9e41551f53fe7fa9f5f2",
            "title": "build(v4): arm64 点亮 C++ 内核，conan2 + fmt10 现代化",
            "observedAt": "2026-06-16T10:01:10Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "01cf26faab988082b65bb0b37a8c35d87df50a6c",
            "url": "https://github.com/kungfu-systems/kungfu/commit/01cf26faab988082b65bb0b37a8c35d87df50a6c",
            "title": "build(v4): Step 2 点亮 Python 绑定 pykungfu，journal 写读往返通过",
            "observedAt": "2026-06-16T10:51:20Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "1599ab1cc50a2eeef0f7f4dfd54b8d2030f674b8",
            "url": "https://github.com/kungfu-systems/kungfu/commit/1599ab1cc50a2eeef0f7f4dfd54b8d2030f674b8",
            "title": "build(v4): Step 3 点亮 Node 绑定 kungfu_node，三语言共享同一条 journal",
            "observedAt": "2026-06-16T11:29:29Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "5f3ab0786cba51bde94b6a075c8720c913bf6143",
            "url": "https://github.com/kungfu-systems/kungfu/commit/5f3ab0786cba51bde94b6a075c8720c913bf6143",
            "title": "build(v4): Step 4 点亮单进程三语言联动，技术终点达成",
            "observedAt": "2026-06-16T12:15:12Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "d07fe5a894b55a4600c360e194b27206ac40ff69",
            "url": "https://github.com/kungfu-systems/kungfu/commit/d07fe5a894b55a4600c360e194b27206ac40ff69",
            "title": "build(v4): .v4 跨平台适配 Linux(rpath/linker/测试脚本)",
            "observedAt": "2026-06-16T15:05:18Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "fa4feb44e7cc39bc71c6f53b44545e1c6a88bac7",
            "url": "https://github.com/kungfu-systems/kungfu/commit/fa4feb44e7cc39bc71c6f53b44545e1c6a88bac7",
            "title": "fix(yijinjing): time.h 显式 #include <cstdint> 修 gcc13 编译",
            "observedAt": "2026-06-16T15:17:33Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "77ee308fb5f66a6a7f57fb095da5f4d4a0dba4c5",
            "url": "https://github.com/kungfu-systems/kungfu/commit/77ee308fb5f66a6a7f57fb095da5f4d4a0dba4c5",
            "title": "fix(v4): Linux 单进程内嵌设 RTLD_GLOBAL，修 napi_* undefined symbol",
            "observedAt": "2026-06-16T16:01:07Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "0e41c8e0257ed5c199f18de93be43bc925a54780",
            "url": "https://github.com/kungfu-systems/kungfu/commit/0e41c8e0257ed5c199f18de93be43bc925a54780",
            "title": "build(v4): 去掉 FMT_USE_CONSTEVAL=0 workaround，恢复 fmt 编译期检查",
            "observedAt": "2026-06-16T22:40:50Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "1775eb2378da27255bdb77916fe0453e0308ef22",
            "url": "https://github.com/kungfu-systems/kungfu/commit/1775eb2378da27255bdb77916fe0453e0308ef22",
            "title": "docs(v4): 建 conan2 迁移理解与决策日志",
            "observedAt": "2026-06-17T02:38:14Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "326179cac308f91469e1fea8723ee555095bf269",
            "url": "https://github.com/kungfu-systems/kungfu/commit/326179cac308f91469e1fea8723ee555095bf269",
            "title": "refactor(core): conanfile.py 端口到 conan2 (Stage A-1)",
            "observedAt": "2026-06-17T02:54:15Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "77d126a3bc3abbbafa2c984921f100f5ab49bb49",
            "url": "https://github.com/kungfu-systems/kungfu/commit/77d126a3bc3abbbafa2c984921f100f5ab49bb49",
            "title": "refactor(core): 主 CMakeLists 适配 conan2 桥接 (Stage A-2a)",
            "observedAt": "2026-06-17T03:04:38Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "6831fb222d47bb183752ff30560767bf251e2f01",
            "url": "https://github.com/kungfu-systems/kungfu/commit/6831fb222d47bb183752ff30560767bf251e2f01",
            "title": "docs(v4): 摸清欠债② libnode→dist 真实形态并落档(排序调整)",
            "observedAt": "2026-06-17T03:15:30Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "7f57c318d78aed8686f0b9642cd0a5e80eb0a6e0",
            "url": "https://github.com/kungfu-systems/kungfu/commit/7f57c318d78aed8686f0b9642cd0a5e80eb0a6e0",
            "title": "docs(v4): 记录欠债② libnode→dist 双平台落位完成",
            "observedAt": "2026-06-17T03:25:08Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "103b66851dcaa647f1ca9a5abeb151e4a0828128",
            "url": "https://github.com/kungfu-systems/kungfu/commit/103b66851dcaa647f1ca9a5abeb151e4a0828128",
            "title": "docs(v4): 立 v4 产品长期目标与分阶段实施计划(恢复点)",
            "observedAt": "2026-06-17T03:53:41Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ad0f812e14e54e0f40ed1db5faa10112657347e6",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ad0f812e14e54e0f40ed1db5faa10112657347e6",
            "title": "build(core): kungfu-core devDep 升级 + 真实绑定首编 (A-2b 进行中)",
            "observedAt": "2026-06-17T04:18:08Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "0d5db708abbcf0fbb2c9fda9541a55d8d888e47b",
            "url": "https://github.com/kungfu-systems/kungfu/commit/0d5db708abbcf0fbb2c9fda9541a55d8d888e47b",
            "title": "docs(v4): A-2b cmake-js+conan2 集成打通(node+electron，Mac)",
            "observedAt": "2026-06-17T05:09:03Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "f2a0bd93c4ab12363ad3bfab302f52daaff62609",
            "url": "https://github.com/kungfu-systems/kungfu/commit/f2a0bd93c4ab12363ad3bfab302f52daaff62609",
            "title": "build(core): A-2b Mac 侧收尾(Python pin/run-conan conan2/electron) ①②③",
            "observedAt": "2026-06-17T06:38:24Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "c859683a262e3912106e52140c4e7a4bb1e17a8c",
            "url": "https://github.com/kungfu-systems/kungfu/commit/c859683a262e3912106e52140c4e7a4bb1e17a8c",
            "title": "chore(core): gitignore conan2/cmake 构建工件",
            "observedAt": "2026-06-17T07:11:19Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "2149a187862b65f92d7e62d80e12580beb8bb0ee",
            "url": "https://github.com/kungfu-systems/kungfu/commit/2149a187862b65f92d7e62d80e12580beb8bb0ee",
            "title": "docs(v4): A-2b 双平台闭环完成(node+electron 真实绑定)",
            "observedAt": "2026-06-17T07:22:17Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ae8b29a0b96c90f10d8442b5de4502001b65363a",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ae8b29a0b96c90f10d8442b5de4502001b65363a",
            "title": "docs(v4): Stage C(freeze+kfc)分析与前置决策",
            "observedAt": "2026-06-17T08:29:58Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "2600b382b8ae2287d0c845023ddf41dadbe2b2c6",
            "url": "https://github.com/kungfu-systems/kungfu/commit/2600b382b8ae2287d0c845023ddf41dadbe2b2c6",
            "title": "build(core): Stage C 基础 — Python 栈现代化到 3.13(pyproject+Pipfile)",
            "observedAt": "2026-06-17T08:52:24Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "44c02919758ed7aaeb516106131e151ed6f4be18",
            "url": "https://github.com/kungfu-systems/kungfu/commit/44c02919758ed7aaeb516106131e151ed6f4be18",
            "title": "build(core): Stage C env bootstrap 通过 — Python 3.13 数据栈解析+安装成功",
            "observedAt": "2026-06-17T09:19:52Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "6b95fe388cd83ccc531391613b627f6e8dded528",
            "url": "https://github.com/kungfu-systems/kungfu/commit/6b95fe388cd83ccc531391613b627f6e8dded528",
            "title": "fix(python): kfc 适配 click 8.1.7+ (F→本地 TypeVar)",
            "observedAt": "2026-06-17T09:37:33Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "29f6685d18995d45a70bc96c1b4e2ab370ba0093",
            "url": "https://github.com/kungfu-systems/kungfu/commit/29f6685d18995d45a70bc96c1b4e2ab370ba0093",
            "title": "docs(v4): Stage C env bootstrap + kfc 运行验证完成(记录+下一步 Nuitka freeze)",
            "observedAt": "2026-06-17T09:41:43Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "d0e969649e570a78a5e39d08fd2ab7c5d66d2db6",
            "url": "https://github.com/kungfu-systems/kungfu/commit/d0e969649e570a78a5e39d08fd2ab7c5d66d2db6",
            "title": "docs(v4): Nuitka freeze 进展与卡点(bundle 出+卡 certifi/stdlib)",
            "observedAt": "2026-06-17T12:43:27Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "f0c2886a5fd8e2483b36c6575f093e9ffe02a04b",
            "url": "https://github.com/kungfu-systems/kungfu/commit/f0c2886a5fd8e2483b36c6575f093e9ffe02a04b",
            "title": "build(core): 数据栈加 plotly 6.8(kfc freeze include-package=plotly 需要)",
            "observedAt": "2026-06-17T12:48:37Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "28f4f9cadbc8219d2f66eaebee7948022bf335a1",
            "url": "https://github.com/kungfu-systems/kungfu/commit/28f4f9cadbc8219d2f66eaebee7948022bf335a1",
            "title": "build(core): kfc Nuitka freeze 调通(升 4.1.2 修 certifi)，kfc.bin 独立运行",
            "observedAt": "2026-06-17T14:45:01Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "4e4127d888d58228c0a1a085a0e64edabfb57d0e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/4e4127d888d58228c0a1a085a0e64edabfb57d0e",
            "title": "chore(core): poetry.lock 重锁匹配 nuitka ~4.1(Linux freeze 用 4.1.2)",
            "observedAt": "2026-06-17T23:17:05Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "4e85bf22a7c008b2c2e5d8e7268be0037b358109",
            "url": "https://github.com/kungfu-systems/kungfu/commit/4e85bf22a7c008b2c2e5d8e7268be0037b358109",
            "title": "docs(core): 记录 Stage C Linux freeze 调通，双平台 kfc 独立运行完成",
            "observedAt": "2026-06-18T00:18:37Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "3ab57f1cdd170498ece61113a46a673f88338a1a",
            "url": "https://github.com/kungfu-systems/kungfu/commit/3ab57f1cdd170498ece61113a46a673f88338a1a",
            "title": "build(core): Stage C 收尾 — freeze 入口脚本化 + kungfubuildinfo 自动化",
            "observedAt": "2026-06-18T01:20:53Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ddbaf32b2cddc266349641c544dee2e03cacc9bd",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ddbaf32b2cddc266349641c544dee2e03cacc9bd",
            "title": "build(core): Windows 端口 — libkungfu 改 STATIC 解 LNK1189，Stage D GUI 路径跑通",
            "observedAt": "2026-06-18T05:52:08Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "4c26196e7826311273cbee0684cfc492a0eadc00",
            "url": "https://github.com/kungfu-systems/kungfu/commit/4c26196e7826311273cbee0684cfc492a0eadc00",
            "title": "chore(core): .v4 退役 — bootstrap 删除，文档迁 framework/core/docs",
            "observedAt": "2026-06-18T11:17:43Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "faea6ad26076269f2608408924c382c6c3936595",
            "url": "https://github.com/kungfu-systems/kungfu/commit/faea6ad26076269f2608408924c382c6c3936595",
            "title": "chore(core): P0 收尾 — Windows cppstd=17 固化进 run-conan + ⑤⑦ 落档",
            "observedAt": "2026-06-18T14:23:05Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "7f7aab5fa4c2d52a283e6b6e5192d79bf8e3c2c2",
            "url": "https://github.com/kungfu-systems/kungfu/commit/7f7aab5fa4c2d52a283e6b6e5192d79bf8e3c2c2",
            "title": "feat(longfist,ledger): born-FB Asset(第四类型) + Position/Asset ledger 写侧 dual-write(默认 OFF)",
            "observedAt": "2026-06-22T11:02:39Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "8c51591dd3c0c834fa16d946752c51890cd7233e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/8c51591dd3c0c834fa16d946752c51890cd7233e",
            "title": "feat(config): make Kungfu config contract-first",
            "observedAt": "2026-07-06T03:12:14Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "2132071b0c6efe8651026334fb789b009145be40",
            "url": "https://github.com/kungfu-systems/kungfu/commit/2132071b0c6efe8651026334fb789b009145be40",
            "title": "feat(storage): move atlas integrity checks into core",
            "observedAt": "2026-07-08T15:37:01Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "f93c90c726e13a15d2d82fc925fd5a9d4e0a8e66",
            "url": "https://github.com/kungfu-systems/kungfu/commit/f93c90c726e13a15d2d82fc925fd5a9d4e0a8e66",
            "title": "docs(mission-control): design workspace product flow",
            "observedAt": "2026-07-11T15:46:26Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "42c0107dff94ad56485cd39a93cbd2172306b206",
            "url": "https://github.com/kungfu-systems/kungfu/commit/42c0107dff94ad56485cd39a93cbd2172306b206",
            "title": "perf(yijinjing): avoid transaction frame refcounts",
            "observedAt": "2026-07-12T08:04:32Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "eceb82e66481e5d8ea42e2ba112ee389c46233de",
            "url": "https://github.com/kungfu-systems/kungfu/commit/eceb82e66481e5d8ea42e2ba112ee389c46233de",
            "title": "fix(yijinjing): contain compatibility deprecation warnings",
            "observedAt": "2026-07-12T08:04:32Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "a8393059cb18bf6ec3cf25ea23301b1da2697254",
            "url": "https://github.com/kungfu-systems/kungfu/commit/a8393059cb18bf6ec3cf25ea23301b1da2697254",
            "title": "test(yijinjing): stabilize transaction qualification",
            "observedAt": "2026-07-12T08:04:32Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "26b97c3b9af68c808d5d0da89c0e3c50c1c5f080",
            "url": "https://github.com/kungfu-systems/kungfu/commit/26b97c3b9af68c808d5d0da89c0e3c50c1c5f080",
            "title": "perf(yijinjing): qualify lifetime ownership costs",
            "observedAt": "2026-07-12T08:04:32Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "527d8c1f954ba6bd540451e3b9f526be5ed5a28a",
            "url": "https://github.com/kungfu-systems/kungfu/commit/527d8c1f954ba6bd540451e3b9f526be5ed5a28a",
            "title": "fix(yijinjing): isolate reader management snapshots",
            "observedAt": "2026-07-12T08:04:32Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "e8d1d6d26d6199e39bccfb34118a595bb9ae5471",
            "url": "https://github.com/kungfu-systems/kungfu/commit/e8d1d6d26d6199e39bccfb34118a595bb9ae5471",
            "title": "feat(yijinjing): add exception-safe writer transactions",
            "observedAt": "2026-07-12T08:04:32Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "a296e6dfdf3a43340093accafbee646ef97ea821",
            "url": "https://github.com/kungfu-systems/kungfu/commit/a296e6dfdf3a43340093accafbee646ef97ea821",
            "title": "fix(runtime): make error stop ownership local",
            "observedAt": "2026-07-12T08:55:18Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "3fd04734143d4ffb252aab33b3838fb8276c3eba",
            "url": "https://github.com/kungfu-systems/kungfu/commit/3fd04734143d4ffb252aab33b3838fb8276c3eba",
            "title": "docs(core): define strong durability and recovery path",
            "observedAt": "2026-07-12T09:46:09Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "6ecd48e6b1a89097430c907122df88b27eabb848",
            "url": "https://github.com/kungfu-systems/kungfu/commit/6ecd48e6b1a89097430c907122df88b27eabb848",
            "title": "feat(profile): add generic composition manager",
            "observedAt": "2026-07-12T18:40:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "0cc689769fd74326856ec19bf63a8811ce72dfd4",
            "url": "https://github.com/kungfu-systems/kungfu/commit/0cc689769fd74326856ec19bf63a8811ce72dfd4",
            "title": "feat(profile): bind assessments to exact query cuts",
            "observedAt": "2026-07-12T18:40:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "45ff4dfa94f0ee1d288cf8213f9f6d7529336a07",
            "url": "https://github.com/kungfu-systems/kungfu/commit/45ff4dfa94f0ee1d288cf8213f9f6d7529336a07",
            "title": "fix(profile): require installed composition schemas",
            "observedAt": "2026-07-12T18:40:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "7353682b28e99229eb7b1e1ee531b854e2714e17",
            "url": "https://github.com/kungfu-systems/kungfu/commit/7353682b28e99229eb7b1e1ee531b854e2714e17",
            "title": "feat(profile): expose composition query plans",
            "observedAt": "2026-07-12T18:40:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "e554acf2ef58236af6b9c2c84fdf103352191bab",
            "url": "https://github.com/kungfu-systems/kungfu/commit/e554acf2ef58236af6b9c2c84fdf103352191bab",
            "title": "feat(profile): start generic composition catalog",
            "observedAt": "2026-07-12T18:40:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "0aa72aedc310b8b42d8fbc323406fcd034f63b32",
            "url": "https://github.com/kungfu-systems/kungfu/commit/0aa72aedc310b8b42d8fbc323406fcd034f63b32",
            "title": "fix(gui): inject complete KFX shared-module contract",
            "observedAt": "2026-07-14T01:16:07Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "b9862da2a0187316037b2f7774d20ca339c089a8",
            "url": "https://github.com/kungfu-systems/kungfu/commit/b9862da2a0187316037b2f7774d20ca339c089a8",
            "title": "feat(project-cut): admit live completion episode",
            "observedAt": "2026-07-17T14:38:04Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "aa3cdede12708b95d3859e71361e06955dff0218",
            "url": "https://github.com/kungfu-systems/kungfu/commit/aa3cdede12708b95d3859e71361e06955dff0218",
            "title": "test(project-cut): seal live go completion episode",
            "observedAt": "2026-07-17T14:38:04Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/019f7402-9d55-70f1-b562-1d2dfd86036b",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "c1ab522675d653261962c5d66f016bd5e690ecb0",
            "url": "https://github.com/kungfu-systems/kungfu/commit/c1ab522675d653261962c5d66f016bd5e690ecb0",
            "title": "fix(fact): harden portable protocol validation",
            "observedAt": "2026-07-20T14:20:14Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "9daacb38a91e406e07654ec6b1fdf4a9e833b0df",
            "url": "https://github.com/kungfu-systems/kungfu/commit/9daacb38a91e406e07654ec6b1fdf4a9e833b0df",
            "title": "chore(project-cut): bind linear invariant qualification",
            "observedAt": "2026-07-20T18:41:25Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "a2762d18251f8630fdd0c9791ea4a5be2c13e5a8",
            "url": "https://github.com/kungfu-systems/kungfu/commit/a2762d18251f8630fdd0c9791ea4a5be2c13e5a8",
            "title": "fix(invariant): qualify Fact native harness cross-platform",
            "observedAt": "2026-07-20T18:41:25Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "8aa1f9ab9a9eee6129be3e43ac6e0acb971da135",
            "url": "https://github.com/kungfu-systems/kungfu/commit/8aa1f9ab9a9eee6129be3e43ac6e0acb971da135",
            "title": "chore(project-cut): publish Agent Hub trunk successor",
            "observedAt": "2026-07-20T22:39:04Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/019f7d00-2611-7603-bfa5-716304dfc6cc",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ffe68d7ff52d71cb99cd486053cf298547811e17",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ffe68d7ff52d71cb99cd486053cf298547811e17",
            "title": "docs(core): bind queue-linear KFD-7 ABI cut",
            "observedAt": "2026-07-20T22:42:22Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/019f7d00-2611-7603-bfa5-716304dfc6cc",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "b95b1f459d6ebf02fc5395fe5c05be3a1dfbd7ce",
            "url": "https://github.com/kungfu-systems/kungfu/commit/b95b1f459d6ebf02fc5395fe5c05be3a1dfbd7ce",
            "title": "chore(project-cut): collapse superseded KFD-7 cuts",
            "observedAt": "2026-07-20T22:42:22Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/019f7d00-2611-7603-bfa5-716304dfc6cc",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "c7df73a2bcf724709df552120e0ff2957f58fdca",
            "url": "https://github.com/kungfu-systems/kungfu/commit/c7df73a2bcf724709df552120e0ff2957f58fdca",
            "title": "docs(core): bind rebased KFD-7 ABI successor cut",
            "observedAt": "2026-07-20T22:42:22Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/019f7d00-2611-7603-bfa5-716304dfc6cc",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "465c3b27dff85fe229b1f8cabb04bda92d703fd7",
            "url": "https://github.com/kungfu-systems/kungfu/commit/465c3b27dff85fe229b1f8cabb04bda92d703fd7",
            "title": "test(fact): preserve typed ledger boundary assertions",
            "observedAt": "2026-07-20T22:42:22Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "054148cbb45ff607d7cc5d282649485928814390",
            "url": "https://github.com/kungfu-systems/kungfu/commit/054148cbb45ff607d7cc5d282649485928814390",
            "title": "chore(project-cut): republish empty-delta cut on current merge base tip",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "4cfceb9392d90cb9cfb80b75afd45feb98579460",
            "url": "https://github.com/kungfu-systems/kungfu/commit/4cfceb9392d90cb9cfb80b75afd45feb98579460",
            "title": "chore(project-cut): drop cut drifted by intervening merge-queue tip",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "218a6cb16552950ae58699c8994a62d6d23f083a",
            "url": "https://github.com/kungfu-systems/kungfu/commit/218a6cb16552950ae58699c8994a62d6d23f083a",
            "title": "chore(project-cut): republish empty-delta cut on merge-queue tip",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "dbad3bdfe7b08c42bc70486f082961b846c8c640",
            "url": "https://github.com/kungfu-systems/kungfu/commit/dbad3bdfe7b08c42bc70486f082961b846c8c640",
            "title": "chore(project-cut): drop rebase-drifted empty-delta cut before republish",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "657a6131eb42f0e311c198b97de115d257b97a90",
            "url": "https://github.com/kungfu-systems/kungfu/commit/657a6131eb42f0e311c198b97de115d257b97a90",
            "title": "chore(project-cut): publish final empty-delta cut for native action authority",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "6a411bd6bf428ec34531959f36de9c61033cf224",
            "url": "https://github.com/kungfu-systems/kungfu/commit/6a411bd6bf428ec34531959f36de9c61033cf224",
            "title": "chore(project-cut): drop overlapping pre/post-rebase cut publications",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "64aa1f437e34dad40ae45de1695ef4740e405224",
            "url": "https://github.com/kungfu-systems/kungfu/commit/64aa1f437e34dad40ae45de1695ef4740e405224",
            "title": "fix(core): sync ADR-0123 delivery evidence and architecture health projections",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ff4232a65f43541bff65e2caca02602a2384e946",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ff4232a65f43541bff65e2caca02602a2384e946",
            "title": "fix(core): repair architecture projections after rebase",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "2c59c4cf1ccd4351663d080e39565199eae324ca",
            "url": "https://github.com/kungfu-systems/kungfu/commit/2c59c4cf1ccd4351663d080e39565199eae324ca",
            "title": "chore(project-cut): republish empty-delta cut after rebase onto dev/v4/v4.0",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "0357cb17bb406af7e3846c13eb53c28eb0fab83d",
            "url": "https://github.com/kungfu-systems/kungfu/commit/0357cb17bb406af7e3846c13eb53c28eb0fab83d",
            "title": "chore(project-cut): stage empty-delta cut for action-geometry native authority",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ff9dc497a8eb96cf99690c735497a3b41a24780e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ff9dc497a8eb96cf99690c735497a3b41a24780e",
            "title": "test(core): shadow-compare action_runtime and confirm authority flip",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "7691fff485bca47c03baad870bcd8374e6f49ec1",
            "url": "https://github.com/kungfu-systems/kungfu/commit/7691fff485bca47c03baad870bcd8374e6f49ec1",
            "title": "feat(core): wire action_runtime edge and Python shims",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "a3795a79b7419167022b4d2505b0caf5b84ec136",
            "url": "https://github.com/kungfu-systems/kungfu/commit/a3795a79b7419167022b4d2505b0caf5b84ec136",
            "title": "feat(core): port Profile action orchestration to libkungfu",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "a2339161d158130190cbc86cc6ae674bd473f463",
            "url": "https://github.com/kungfu-systems/kungfu/commit/a2339161d158130190cbc86cc6ae674bd473f463",
            "title": "feat(core): port Domain Profile engine to libkungfu",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "9b1bec9965c20d64fc1ae776aa1718261762368b",
            "url": "https://github.com/kungfu-systems/kungfu/commit/9b1bec9965c20d64fc1ae776aa1718261762368b",
            "title": "feat(core): port Action Geometry evaluator to libkungfu",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "610ef7c9bb61953e85a8b8cd0972a49a0b32b9bb",
            "url": "https://github.com/kungfu-systems/kungfu/commit/610ef7c9bb61953e85a8b8cd0972a49a0b32b9bb",
            "title": "chore(xinfa): record portable shim cut",
            "observedAt": "2026-07-21T06:57:59Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ce3e846c10b07d1239bc5742e210aaf72a112815",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ce3e846c10b07d1239bc5742e210aaf72a112815",
            "title": "fix(xinfa): let Node invoke Windows shim",
            "observedAt": "2026-07-21T06:57:59Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "fadac5121d0b36b5a89b0c25d860447ff4ab5b36",
            "url": "https://github.com/kungfu-systems/kungfu/commit/fadac5121d0b36b5a89b0c25d860447ff4ab5b36",
            "title": "chore(xinfa): record Windows qualification cut",
            "observedAt": "2026-07-21T06:57:59Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "693a44d4927c1401b28f9e5bf079c4c3b04dd02f",
            "url": "https://github.com/kungfu-systems/kungfu/commit/693a44d4927c1401b28f9e5bf079c4c3b04dd02f",
            "title": "fix(xinfa): qualify wasm shim on Windows",
            "observedAt": "2026-07-21T06:57:59Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "1a9e6355b4b162e37a1b9ef01c06b7cc91724038",
            "url": "https://github.com/kungfu-systems/kungfu/commit/1a9e6355b4b162e37a1b9ef01c06b7cc91724038",
            "title": "chore(project-cut): bind refreshed Xinfa context",
            "observedAt": "2026-07-21T10:50:44Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "5e303f2c464b8ebe2d77f87c0a08be231afc212d",
            "url": "https://github.com/kungfu-systems/kungfu/commit/5e303f2c464b8ebe2d77f87c0a08be231afc212d",
            "title": "chore(project-cut): rebind workspace migration to current dev",
            "observedAt": "2026-07-21T10:50:44Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "f4adf4c5dbd6c2a7781b8dc58182734585a0185c",
            "url": "https://github.com/kungfu-systems/kungfu/commit/f4adf4c5dbd6c2a7781b8dc58182734585a0185c",
            "title": "fix(storage): close workspace layout coverage gaps",
            "observedAt": "2026-07-21T20:24:42Z"
          },
          {
            "agent": "Amp",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Amp",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "8857b44ff5ced6328524508639f30353238f63ed",
            "url": "https://github.com/kungfu-systems/kungfu/commit/8857b44ff5ced6328524508639f30353238f63ed",
            "title": "chore(project-cut): publish composition-replay settlement witness for cut 551ba04b",
            "observedAt": "2026-07-21T22:44:42Z"
          },
          {
            "agent": "Amp",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Amp",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "152eaea082d506e0f24fc559707e9a538615e69e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/152eaea082d506e0f24fc559707e9a538615e69e",
            "title": "fix(project-cut): replay squash-published cut chains order-independently",
            "observedAt": "2026-07-21T22:44:42Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "2901313005f7c9f7cfc31ac67cc4787bc979a74e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/2901313005f7c9f7cfc31ac67cc4787bc979a74e",
            "title": "style(work): format facade contract test",
            "observedAt": "2026-07-22T04:22:11Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "c09d3be1cf4a586ee1b15a4d56fdffd042f1693e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/c09d3be1cf4a586ee1b15a4d56fdffd042f1693e",
            "title": "fix(work): preserve runtime and Cut authority boundaries",
            "observedAt": "2026-07-22T04:22:11Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "46df537e1b3c2868fb5eb1a70ed11281eafb59ff",
            "url": "https://github.com/kungfu-systems/kungfu/commit/46df537e1b3c2868fb5eb1a70ed11281eafb59ff",
            "title": "docs(adr): bind Project Cut facade delivery",
            "observedAt": "2026-07-22T04:22:11Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "f5a9025a605feb4d57e2a386031a0da22d4499b5",
            "url": "https://github.com/kungfu-systems/kungfu/commit/f5a9025a605feb4d57e2a386031a0da22d4499b5",
            "title": "docs(adr): define Project Cut Work facade",
            "observedAt": "2026-07-22T04:22:11Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "969f6148881f99da6a81b559efd69b8ad6bb4f04",
            "url": "https://github.com/kungfu-systems/kungfu/commit/969f6148881f99da6a81b559efd69b8ad6bb4f04",
            "title": "feat(work): bind managed runs and settlement plans",
            "observedAt": "2026-07-22T04:22:11Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "f24b67efd285858d7c85c128cc37c844b35390e2",
            "url": "https://github.com/kungfu-systems/kungfu/commit/f24b67efd285858d7c85c128cc37c844b35390e2",
            "title": "feat(work): add Project Cut facade read model",
            "observedAt": "2026-07-22T04:22:11Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "06fb9eb5465e14bfc3344e224a2f5e10baaca924",
            "url": "https://github.com/kungfu-systems/kungfu/commit/06fb9eb5465e14bfc3344e224a2f5e10baaca924",
            "title": "chore(project-cut): bind 088 queue baseline",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "6b753fa3633a75876da1b2e691c779f51f4fd186",
            "url": "https://github.com/kungfu-systems/kungfu/commit/6b753fa3633a75876da1b2e691c779f51f4fd186",
            "title": "chore(project-cut): bind 0bee queue baseline",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "445127935ff72c24a0e9e095ee718ffa507bb92e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/445127935ff72c24a0e9e095ee718ffa507bb92e",
            "title": "chore(project-cut): bind a297 queue baseline",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "dcf11a4afdcd6d02e4f16f7985a46afca6551c43",
            "url": "https://github.com/kungfu-systems/kungfu/commit/dcf11a4afdcd6d02e4f16f7985a46afca6551c43",
            "title": "chore(project-cut): bind final rebased baseline",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "bec10e401e7a404844f1f9802a75604ae14e3c7e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/bec10e401e7a404844f1f9802a75604ae14e3c7e",
            "title": "chore(project-cut): bind final queue baseline",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "e9fce77cef2b462bea2743edff00ef4500543445",
            "url": "https://github.com/kungfu-systems/kungfu/commit/e9fce77cef2b462bea2743edff00ef4500543445",
            "title": "chore(project-cut): bind verified completion evidence",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "98c99300d0eff4e5cf1bd9391a3b59009d849207",
            "url": "https://github.com/kungfu-systems/kungfu/commit/98c99300d0eff4e5cf1bd9391a3b59009d849207",
            "title": "chore(project-cut): seal verified integration episode",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "b5f3508b5a61e63c83e3442648d98739b48b2b3d",
            "url": "https://github.com/kungfu-systems/kungfu/commit/b5f3508b5a61e63c83e3442648d98739b48b2b3d",
            "title": "chore(project-cut): admit queue integration",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "20dd3cc0b04b18bd621ce50bac7108cdb1987e6e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/20dd3cc0b04b18bd621ce50bac7108cdb1987e6e",
            "title": "chore(project-cut): seal queue integration evidence",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "25a0d13f081324101ecfcebed7fd1b4c6cf341cc",
            "url": "https://github.com/kungfu-systems/kungfu/commit/25a0d13f081324101ecfcebed7fd1b4c6cf341cc",
            "title": "chore(project-cut): bind protected queue baseline",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "55d2ab229611dae8b18b76d5247f148024f4c73b",
            "url": "https://github.com/kungfu-systems/kungfu/commit/55d2ab229611dae8b18b76d5247f148024f4c73b",
            "title": "chore(project-cut): bind latest dev baseline",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "4516a55d3f0ba8a4e2e1d9d7d4cd1fbcf768ef68",
            "url": "https://github.com/kungfu-systems/kungfu/commit/4516a55d3f0ba8a4e2e1d9d7d4cd1fbcf768ef68",
            "title": "chore(project-cut): bind Windows fixture qualification",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "148a179d4b94a51641d733eafac9d9ca58367eb6",
            "url": "https://github.com/kungfu-systems/kungfu/commit/148a179d4b94a51641d733eafac9d9ca58367eb6",
            "title": "test(core): make API fixture cleanup non-throwing",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "b9b91128007cd92ea1717543849402175545244a",
            "url": "https://github.com/kungfu-systems/kungfu/commit/b9b91128007cd92ea1717543849402175545244a",
            "title": "chore(project-cut): bind locked source transport",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "026a0724115316faa28e3a2de26c344b8f02022c",
            "url": "https://github.com/kungfu-systems/kungfu/commit/026a0724115316faa28e3a2de26c344b8f02022c",
            "title": "ci(gate): persist locked source transport policy",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex\\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference\\nMission: kungfu-technical-stewardship",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "b82786544e4474aecd6095b78c641ea2868dfb22",
            "url": "https://github.com/kungfu-systems/kungfu/commit/b82786544e4474aecd6095b78c641ea2868dfb22",
            "title": "fix(assignment): bind admitted work to native source",
            "observedAt": "2026-07-23T06:26:29Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "00bc84e9bc51aff1fc2bc1703853a323d3a9da44",
            "url": "https://github.com/kungfu-systems/kungfu/commit/00bc84e9bc51aff1fc2bc1703853a323d3a9da44",
            "title": "fix(assignment): reject partial source assemblies",
            "observedAt": "2026-07-24T00:23:19Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "f6e6e3e74d64279bb50097decbb63636001522ca",
            "url": "https://github.com/kungfu-systems/kungfu/commit/f6e6e3e74d64279bb50097decbb63636001522ca",
            "title": "fix(assignment): refresh initialized workspace identity",
            "observedAt": "2026-07-24T00:23:19Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "e054d96a7b36fe9aa149108b2a007cc46f8cead9",
            "url": "https://github.com/kungfu-systems/kungfu/commit/e054d96a7b36fe9aa149108b2a007cc46f8cead9",
            "title": "fix(assignment): preserve source admission diagnostics",
            "observedAt": "2026-07-24T00:23:19Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "50d169751e092b34955c4e42c696ca87bf09d3cc",
            "url": "https://github.com/kungfu-systems/kungfu/commit/50d169751e092b34955c4e42c696ca87bf09d3cc",
            "title": "fix(mission-control): authenticate native completion evidence",
            "observedAt": "2026-07-24T03:02:51Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "54ed3edce763f156d41991d55c83337abb3780cd",
            "url": "https://github.com/kungfu-systems/kungfu/commit/54ed3edce763f156d41991d55c83337abb3780cd",
            "title": "feat(core): admit native Work journal ownership",
            "observedAt": "2026-07-25T01:59:58Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "589bdf1fd2f794f67414549cf1c85dac2816ddda",
            "url": "https://github.com/kungfu-systems/kungfu/commit/589bdf1fd2f794f67414549cf1c85dac2816ddda",
            "title": "docs(primitive): record authority closure delivery",
            "observedAt": "2026-07-25T03:17:07Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "74d2f5f1894f26d33346ab26b6d2a3ef85a6596a",
            "url": "https://github.com/kungfu-systems/kungfu/commit/74d2f5f1894f26d33346ab26b6d2a3ef85a6596a",
            "title": "feat(primitive): close authority consumption paths",
            "observedAt": "2026-07-25T03:17:07Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/pro-2088/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "cbcce6c49b20a6a14da7535ac0fbae9604cda485",
            "url": "https://github.com/kungfu-systems/kungfu/commit/cbcce6c49b20a6a14da7535ac0fbae9604cda485",
            "title": "feat(agent): add repository work experiment",
            "observedAt": "2026-07-27T14:37:40Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "0ebf87ebdb5be31996b2ddb0dc0abf62b1bdafeb",
            "url": "https://github.com/kungfu-systems/kungfu/commit/0ebf87ebdb5be31996b2ddb0dc0abf62b1bdafeb",
            "title": "fix(core): adopt Linux ARM64 libnode package",
            "observedAt": "2026-07-27T19:28:56Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "55c406c91c9ad37b55136a14426d7b31e28140ee",
            "url": "https://github.com/kungfu-systems/kungfu/commit/55c406c91c9ad37b55136a14426d7b31e28140ee",
            "title": "chore(release): refresh qualification projections",
            "observedAt": "2026-07-27T22:06:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "d404ada50a2aeaee213436fa97ea95cd27d9cff3",
            "url": "https://github.com/kungfu-systems/kungfu/commit/d404ada50a2aeaee213436fa97ea95cd27d9cff3",
            "title": "fix(release): scope ARM64 Hub qualification to CLI",
            "observedAt": "2026-07-27T22:06:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "d22606161449e7c6c84fcbf890506594e55b1b62",
            "url": "https://github.com/kungfu-systems/kungfu/commit/d22606161449e7c6c84fcbf890506594e55b1b62",
            "title": "fix(release): preserve execution context compatibility",
            "observedAt": "2026-07-27T23:06:13Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "e097ed411cceb03a9a390f7b7428c145dc53b30b",
            "url": "https://github.com/kungfu-systems/kungfu/commit/e097ed411cceb03a9a390f7b7428c145dc53b30b",
            "title": "fix(deps): remove stale Buildchain KFD override",
            "observedAt": "2026-07-28T00:28:21Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "eb6e53284f7462208bf65b80e1c25e1b2cbcddf1",
            "url": "https://github.com/kungfu-systems/kungfu/commit/eb6e53284f7462208bf65b80e1c25e1b2cbcddf1",
            "title": "fix(core): consume qualified libnode alpha.3",
            "observedAt": "2026-07-28T00:28:21Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "d68fe84a5935780a933df4e19e6d094ee5fb06ab",
            "url": "https://github.com/kungfu-systems/kungfu/commit/d68fe84a5935780a933df4e19e6d094ee5fb06ab",
            "title": "feat(ci): add dedicated local agent patrol",
            "observedAt": "2026-07-28T09:02:39Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ce9d80f9bec73813c230cc214c334716b7bc5ca7",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ce9d80f9bec73813c230cc214c334716b7bc5ca7",
            "title": "fix(ci): support rootless Patrol bind mounts",
            "observedAt": "2026-07-28T10:40:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "e8cfee73d2569ed6321c7422dae72038ba027596",
            "url": "https://github.com/kungfu-systems/kungfu/commit/e8cfee73d2569ed6321c7422dae72038ba027596",
            "title": "fix(readme): preserve public source signature",
            "observedAt": "2026-07-30T14:31:56Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "c08720588a64c5f597e04bb620dbbbe11f81c488",
            "url": "https://github.com/kungfu-systems/kungfu/commit/c08720588a64c5f597e04bb620dbbbe11f81c488",
            "title": "docs(readme): lead with agent work continuity",
            "observedAt": "2026-07-30T14:31:56Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "b2d71e03f13e804f717182c0fd4cf8f72a2c771f",
            "url": "https://github.com/kungfu-systems/kungfu/commit/b2d71e03f13e804f717182c0fd4cf8f72a2c771f",
            "title": "fix(signing): consume source-bound native identity",
            "observedAt": "2026-07-30T22:39:45Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "e8853e3a364f7d6f76296d513300c8691910b1d1",
            "url": "https://github.com/kungfu-systems/kungfu/commit/e8853e3a364f7d6f76296d513300c8691910b1d1",
            "title": "perf(ci): add auditable Windows compiler cache",
            "observedAt": "2026-07-31T00:50:39Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "b0eccac6a95e22ca5b5c1462451c3039ab6ca42c",
            "url": "https://github.com/kungfu-systems/kungfu/commit/b0eccac6a95e22ca5b5c1462451c3039ab6ca42c",
            "title": "fix(release): align Alpha sentinel with demo catalog",
            "observedAt": "2026-07-31T03:52:09Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "7536ebf8a0157e1e09f92a0dc8bbdea69fae2608",
            "url": "https://github.com/kungfu-systems/kungfu/commit/7536ebf8a0157e1e09f92a0dc8bbdea69fae2608",
            "title": "fix(signing): delegate notarization to Buildchain",
            "observedAt": "2026-07-31T04:32:17Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "0e33bb0dd2b4a9246d0eaf493ec73ea32fa1b6d1",
            "url": "https://github.com/kungfu-systems/kungfu/commit/0e33bb0dd2b4a9246d0eaf493ec73ea32fa1b6d1",
            "title": "fix(release): pin signing lifecycle manifest authority",
            "observedAt": "2026-07-31T07:04:10Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "d423cf756aa3668a0ee48e8e3215bd1740adf629",
            "url": "https://github.com/kungfu-systems/kungfu/commit/d423cf756aa3668a0ee48e8e3215bd1740adf629",
            "title": "fix(kfx): admit Projects capability in Core policy",
            "observedAt": "2026-07-31T08:49:24Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "a5e19ac2287ab0628553d31f81080ffd183429c3",
            "url": "https://github.com/kungfu-systems/kungfu/commit/a5e19ac2287ab0628553d31f81080ffd183429c3",
            "title": "docs(shifu): bind Windows repair PR evidence",
            "observedAt": "2026-07-31T09:52:26Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "1f46a9d43b675e83ac02909d35166b03848ae346",
            "url": "https://github.com/kungfu-systems/kungfu/commit/1f46a9d43b675e83ac02909d35166b03848ae346",
            "title": "fix(shifu): bind Windows consumer to exact closure",
            "observedAt": "2026-07-31T09:52:26Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "99d4e2f2023e3c7b09ec68fc98757f4da0aca89b",
            "url": "https://github.com/kungfu-systems/kungfu/commit/99d4e2f2023e3c7b09ec68fc98757f4da0aca89b",
            "title": "test(shifu): reject registrar artifact size drift",
            "observedAt": "2026-07-31T15:28:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "3ffa6a78bcccf56ec7a92d094858df0ab1359807",
            "url": "https://github.com/kungfu-systems/kungfu/commit/3ffa6a78bcccf56ec7a92d094858df0ab1359807",
            "title": "refactor(shifu): share local artifact identity validation",
            "observedAt": "2026-07-31T15:28:27Z"
          }
        ]
      }
    }
  },
  "comparison": {
    "pullRequestRatio": 78.17,
    "changedLinesRatio": 441.12,
    "changedFilesRatio": 273.46,
    "kungfuPrimaryAuthor": {
      "account": "dongkeren",
      "mergedPullRequests": 3913,
      "share": 0.9626
    },
    "publicAuthorLeverage": {
      "unit": "public output per accountable GitHub author identity over the fixed calendar window",
      "kungfuPrimary": {
        "account": "dongkeren",
        "mergedPullRequests": 3913,
        "activeMergeDays": 30,
        "totalAdditions": 2327162,
        "totalDeletions": 524869,
        "grossChangedLines": 2852031,
        "totalChangedFiles": 47662,
        "medianChangedLinesPerPullRequest": 119,
        "central90": {
          "pullRequests": 3523,
          "grossChangedLines": 1326994,
          "meanChangedLinesPerPullRequest": 376.67
        },
        "topTenGrossChangedLinesShare": 0.1604
      },
      "axTopAuthor": {
        "account": "joycel-github",
        "mergedPullRequests": 19,
        "activeMergeDays": 10,
        "totalAdditions": 1040,
        "totalDeletions": 615,
        "grossChangedLines": 1655,
        "totalChangedFiles": 44,
        "medianChangedLinesPerPullRequest": 67,
        "central90": {
          "pullRequests": 19,
          "grossChangedLines": 1655,
          "meanChangedLinesPerPullRequest": 87.11
        },
        "topTenGrossChangedLinesShare": 0.8767
      },
      "axTopThree": {
        "accounts": [
          "joycel-github",
          "rakyll",
          "wjjclaud"
        ],
        "combined": {
          "mergedPullRequests": 45,
          "activeMergeDays": 13,
          "totalAdditions": 3400,
          "totalDeletions": 1461,
          "grossChangedLines": 4861,
          "totalChangedFiles": 159,
          "medianChangedLinesPerPullRequest": 67,
          "central90": {
            "pullRequests": 41,
            "grossChangedLines": 4019,
            "meanChangedLinesPerPullRequest": 98.02
          },
          "topTenGrossChangedLinesShare": 0.5785
        },
        "average": {
          "mergedPullRequests": 15,
          "grossChangedLines": 1620.33,
          "totalChangedFiles": 53
        }
      },
      "axAllAuthors": {
        "accounts": [
          "joycel-github",
          "rakyll",
          "wjjclaud",
          "zbl94"
        ],
        "combined": {
          "mergedPullRequests": 52,
          "activeMergeDays": 15,
          "totalAdditions": 6821,
          "totalDeletions": 1563,
          "grossChangedLines": 8384,
          "totalChangedFiles": 194,
          "medianChangedLinesPerPullRequest": 92,
          "central90": {
            "pullRequests": 48,
            "grossChangedLines": 6127,
            "meanChangedLinesPerPullRequest": 127.65
          },
          "topTenGrossChangedLinesShare": 0.6156
        },
        "average": {
          "mergedPullRequests": 13,
          "grossChangedLines": 2096,
          "totalChangedFiles": 48.5
        }
      },
      "ratios": {
        "kungfuPrimaryToAxTopAuthor": {
          "mergedPullRequests": 205.95,
          "grossChangedLines": 1723.28,
          "totalChangedFiles": 1083.23
        },
        "kungfuPrimaryToAxTopThreeCombined": {
          "mergedPullRequests": 86.96,
          "grossChangedLines": 586.72,
          "totalChangedFiles": 299.76
        },
        "kungfuPrimaryToAxTopThreeAverage": {
          "mergedPullRequests": 260.87,
          "grossChangedLines": 1760.15,
          "totalChangedFiles": 899.28
        },
        "kungfuPrimaryToAxAllAuthorsCombined": {
          "mergedPullRequests": 75.25,
          "grossChangedLines": 340.18,
          "totalChangedFiles": 245.68
        },
        "kungfuPrimaryToAxAllAuthorsAverage": {
          "mergedPullRequests": 301,
          "grossChangedLines": 1360.7,
          "totalChangedFiles": 982.72
        }
      }
    }
  },
  "bootstrapCommitPhase": null,
  "collection": {
    "repository": "https://github.com/kungfu-systems/site-libkungfu-dev",
    "script": "scripts/collect-agent-output-comparison.mjs",
    "command": "node scripts/collect-agent-output-comparison.mjs --window operating",
    "api": "GitHub CLI over public GitHub GraphQL and REST APIs",
    "normalization": "Public PR fields are retained; email addresses in titles and bodies are replaced with [email-redacted].",
    "independentSearchCounts": {
      "ax": 52,
      "kungfu": 4065
    },
    "recordDigest": {
      "ax": "69f432c946cfc11bf31167b44cffe543e5c62174054ce1f617b1e788c02de96f",
      "kungfu": "4a47e9c604aa23a414081068b8418dd7887ed9f91ebf744e730d5ce99498ab49"
    }
  },
  "boundaries": [
    "A merged pull request is a public work item, not a feature, quality, maturity, or value unit.",
    "The comparison observes public GitHub delivery only. Google internal work and all other private work are outside the dataset.",
    "The scopes intentionally reflect the two real organization forms: AX is one product repository; Kungfu is a multi-repository product and release system.",
    "Author accounts are public GitHub identities. They do not by themselves identify whether a human or an Agent produced the underlying change.",
    "Per-author comparisons observe public responsibility identities, not verified team headcount, labor hours, employment roles, or individual authorship of every line.",
    "Kungfu pull requests operate as settlement objects while AX pull requests follow a conventional contribution workflow; their counts are visible responsibility throughput, not interchangeable feature units.",
    "Additions, deletions, and changed-file totals are gross PR statistics and may include generated files, vendored material, formatting, or repeated edits.",
    "Explicit attribution markers establish some Agent participation in both repositories. AX's Gemini co-author history predates the measured windows; Kungfu's census spans the v4 bootstrap through the operating cutoff.",
    "Attribution examples do not prove AI authorship of every change or isolate Agent use as the sole cause of the output difference.",
    "Different review, merge, and PR-splitting disciplines remain a confounder; the raw records are published so readers can test alternative measures."
  ]
}
