Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
79 changes: 65 additions & 14 deletions ROADMAP.md
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
# CometAPI Python SDK Roadmap

Status: `0.1.0a1` in progress
Last updated: 2026-07-22
Last updated: 2026-07-23
Repository contract: this roadmap is self-contained.

## Product target
Expand DownExpand Up@@ -114,12 +114,12 @@ Pre-visibility dependency disposition:

| Item | Disposition | Evidence and required action |
| --- | --- | --- |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its initial code-bearing [CI run 29907523251](https://github.com/cometapi-dev/cometapi-python/actions/runs/29907523251) passed. Close PR #1 after PR #9 merges; do not merge both. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9); must not merge as-is | PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version and passed initial code-bearing CI run 29907523251. Close PR #2 after PR #9 merges; the failed PR #2 run remains negative evidence only. |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its final [CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839) passed, PR #9 squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`, and PR #1 was closed without merging. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9)| PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #2 was closed without merging, and its failed run remains negative evidence only. |
| Dependabot [PR #3](https://github.com/cometapi-dev/cometapi-python/pull/3): `pypa/gh-action-pypi-publish` 1.14.0 to 1.14.1 | Deferred; keep out of `main` | Pull-request CI does not execute the release-triggered OIDC publish action or prove PyPI publication, provenance, or registry installation. Revisit with an authorized release-path review and the separately required protected release evidence; credential-free CI success alone is insufficient. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, and passed initial code-bearing CI run 29907523251. Close PR #4 after PR #9 merges; do not merge both. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #4 was closed without merging. |
| Dependabot [PR #5](https://github.com/cometapi-dev/cometapi-python/pull/5): `googleapis/release-please-action` 4.4.1 to 5.0.0 | Deferred; keep out of `main` | `RELEASE_PLEASE_ENABLED` remains disabled, and pull-request CI does not execute the gated write-capable Release Please action. Revisit only after its real config, manifest, permissions, and release behavior can be reviewed without treating a skipped action as execution evidence. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows and passed initial code-bearing CI run 29907523251 on Python 3.10 through 3.14, the minimum OpenAI lane, package builds, and copied-checkout verification. Close PR #6 after PR #9 merges; do not merge both. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows, passed final CI run 29916685839 on every blocking lane, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #6 was closed without merging. |

Recorded pre-visibility replacement evidence on 2026-07-22:

Expand DownExpand Up@@ -198,24 +198,75 @@ Final workflow-inventory hardening evidence at commit
inspection, and independent clean installs of the wheel and source
distribution.

Final pre-visibility refresh evidence on 2026-07-23:

- `git diff --check`, `uv lock --check`, and `uv sync --locked` passed.
- `uv run ruff check src tests scripts`,
`uv run ruff format --check src tests scripts`, and `uv run pyright` passed.
- `uv run pytest -m "not live"` passed with 200 tests passed and one separately
marked live test deselected.
- `uv run python scripts/check_version.py --expected 0.1.0a1 --require-changelog`,
`uv run python scripts/check_version.py --require-public-preview-docs`,
`uv run python scripts/check_secrets.py`, and
`uv run python scripts/check_workflows.py` passed.
- `uv build --out-dir dist/previsibility-20260723` built exactly the
`0.1.0a1` wheel and source distribution in a newly created empty directory.
`uv run twine check dist/previsibility-20260723/*`,
`uv run python scripts/check_artifacts.py dist/previsibility-20260723/*`, and
`uv run python scripts/check_clean_install.py dist/previsibility-20260723/*`
passed for both exact artifacts.
- `uv run python scripts/check_repository_independence.py` passed the complete
copied-checkout gate, including its 200 offline tests, workflow validation,
package build, artifact inspection, and independent clean installs of both
artifacts.
- `uv run python scripts/run_actionlint.py` and
`uv run python scripts/run_actionlint.py --offline` passed with
checksum-pinned actionlint 1.7.12.

Failed or unavailable checks:

- None of the recorded final-candidate checks failed or were unavailable.
- None of the executed final-candidate validation checks failed or were
unavailable.
Dependabot PR #2's failed run remains separate negative evidence for that PR,
not replacement evidence for PR #9. An earlier intentional offline actionlint
probe in a fresh detached worktree failed closed before the verified cache was
populated; it is not final-candidate validation evidence.
- The execution environment rejected `rm -rf dist` before it ran, so no file was
removed. The final candidate instead used the newly created empty
`dist/previsibility-20260723` directory and completed the equivalent clean
build, inspection, and two-artifact install gates there.

Remote evidence:

- Private PR #9's credential-free initial code-bearing CI run 29907523251 passed
quality, Python 3.10 through 3.14, minimum OpenAI, package, exact-artifact
clean install, retained artifact digest, and copied-checkout jobs. The PR-only
latest-within-major canary skipped as designed; scheduled or Dependabot
execution remains unverified.
- The canonical repository was confirmed private after the successful
replacement run. No visibility, secret, environment, or
repository-protection change was made.
- Private PR #9's final-head
[CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839)
passed quality, Python 3.10 through 3.14, minimum OpenAI, package,
exact-artifact clean install, retained artifact digest, and copied-checkout
jobs for `5db7f012a1470564f4f60fe343b9a0799b58987d`; the PR-only
latest-within-major canary skipped as designed. PR #9 then squash-merged as
`72b212dd72e66bbde9c6714329f72071cc1ca129`, and its credential-free
[default-branch CI run 29916919999](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916919999)
passed. Superseded PRs #1, #2, #4, and #6 were closed without merging.
- Private PR #10's
[CI run 29978262916](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978262916)
passed the same blocking lanes for
`debd7c1d12c72219ee37de0baa58be119d135ae0`; its PR-only canary skipped as
designed. PR #10 squash-merged as
`7d9a3d70714b38b4815d8a8f82a7177d1bcea857`, and its
[default-branch CI run 29978384862](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384862)
passed. The corresponding
[Release Please run 29978384858](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384858)
skipped as required while `RELEASE_PLEASE_ENABLED` remains disabled.
- The final merged workflow's latest-within-major canary remains unverified
under its scheduled and Dependabot paths.
- The canonical repository was confirmed private after these runs.
Repository-level variables and Actions secrets, environments, tags, releases,
and publish runs were absent when checked; `main` reported
`protected: false`. Organization-level variables and secrets were unavailable
to the current credential; detailed protection and ruleset APIs were
unavailable under the current private-repository plan. They do not provide
additional evidence. No visibility, secret, environment, protection, live,
tag, release, registry, or publication change was made.

Live evidence:

Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
79 changes: 65 additions & 14 deletions ROADMAP.md
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
# CometAPI Python SDK Roadmap

Status: `0.1.0a1` in progress
Last updated: 2026-07-22
Last updated: 2026-07-23
Repository contract: this roadmap is self-contained.

## Product target
Expand DownExpand Up@@ -114,12 +114,12 @@ Pre-visibility dependency disposition:

| Item | Disposition | Evidence and required action |
| --- | --- | --- |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its initial code-bearing [CI run 29907523251](https://github.com/cometapi-dev/cometapi-python/actions/runs/29907523251) passed. Close PR #1 after PR #9 merges; do not merge both. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9); must not merge as-is | PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version and passed initial code-bearing CI run 29907523251. Close PR #2 after PR #9 merges; the failed PR #2 run remains negative evidence only. |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its final [CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839) passed, PR #9 squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`, and PR #1 was closed without merging. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9)| PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #2 was closed without merging, and its failed run remains negative evidence only. |
| Dependabot [PR #3](https://github.com/cometapi-dev/cometapi-python/pull/3): `pypa/gh-action-pypi-publish` 1.14.0 to 1.14.1 | Deferred; keep out of `main` | Pull-request CI does not execute the release-triggered OIDC publish action or prove PyPI publication, provenance, or registry installation. Revisit with an authorized release-path review and the separately required protected release evidence; credential-free CI success alone is insufficient. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, and passed initial code-bearing CI run 29907523251. Close PR #4 after PR #9 merges; do not merge both. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #4 was closed without merging. |
| Dependabot [PR #5](https://github.com/cometapi-dev/cometapi-python/pull/5): `googleapis/release-please-action` 4.4.1 to 5.0.0 | Deferred; keep out of `main` | `RELEASE_PLEASE_ENABLED` remains disabled, and pull-request CI does not execute the gated write-capable Release Please action. Revisit only after its real config, manifest, permissions, and release behavior can be reviewed without treating a skipped action as execution evidence. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows and passed initial code-bearing CI run 29907523251 on Python 3.10 through 3.14, the minimum OpenAI lane, package builds, and copied-checkout verification. Close PR #6 after PR #9 merges; do not merge both. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows, passed final CI run 29916685839 on every blocking lane, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #6 was closed without merging. |

Recorded pre-visibility replacement evidence on 2026-07-22:

Expand DownExpand Up@@ -198,24 +198,75 @@ Final workflow-inventory hardening evidence at commit
inspection, and independent clean installs of the wheel and source
distribution.

Final pre-visibility refresh evidence on 2026-07-23:

- `git diff --check`, `uv lock --check`, and `uv sync --locked` passed.
- `uv run ruff check src tests scripts`,
`uv run ruff format --check src tests scripts`, and `uv run pyright` passed.
- `uv run pytest -m "not live"` passed with 200 tests passed and one separately
marked live test deselected.
- `uv run python scripts/check_version.py --expected 0.1.0a1 --require-changelog`,
`uv run python scripts/check_version.py --require-public-preview-docs`,
`uv run python scripts/check_secrets.py`, and
`uv run python scripts/check_workflows.py` passed.
- `uv build --out-dir dist/previsibility-20260723` built exactly the
`0.1.0a1` wheel and source distribution in a newly created empty directory.
`uv run twine check dist/previsibility-20260723/*`,
`uv run python scripts/check_artifacts.py dist/previsibility-20260723/*`, and
`uv run python scripts/check_clean_install.py dist/previsibility-20260723/*`
passed for both exact artifacts.
- `uv run python scripts/check_repository_independence.py` passed the complete
copied-checkout gate, including its 200 offline tests, workflow validation,
package build, artifact inspection, and independent clean installs of both
artifacts.
- `uv run python scripts/run_actionlint.py` and
`uv run python scripts/run_actionlint.py --offline` passed with
checksum-pinned actionlint 1.7.12.

Failed or unavailable checks:

- None of the recorded final-candidate checks failed or were unavailable.
- None of the executed final-candidate validation checks failed or were
unavailable.
Dependabot PR #2's failed run remains separate negative evidence for that PR,
not replacement evidence for PR #9. An earlier intentional offline actionlint
probe in a fresh detached worktree failed closed before the verified cache was
populated; it is not final-candidate validation evidence.
- The execution environment rejected `rm -rf dist` before it ran, so no file was
removed. The final candidate instead used the newly created empty
`dist/previsibility-20260723` directory and completed the equivalent clean
build, inspection, and two-artifact install gates there.

Remote evidence:

- Private PR #9's credential-free initial code-bearing CI run 29907523251 passed
quality, Python 3.10 through 3.14, minimum OpenAI, package, exact-artifact
clean install, retained artifact digest, and copied-checkout jobs. The PR-only
latest-within-major canary skipped as designed; scheduled or Dependabot
execution remains unverified.
- The canonical repository was confirmed private after the successful
replacement run. No visibility, secret, environment, or
repository-protection change was made.
- Private PR #9's final-head
[CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839)
passed quality, Python 3.10 through 3.14, minimum OpenAI, package,
exact-artifact clean install, retained artifact digest, and copied-checkout
jobs for `5db7f012a1470564f4f60fe343b9a0799b58987d`; the PR-only
latest-within-major canary skipped as designed. PR #9 then squash-merged as
`72b212dd72e66bbde9c6714329f72071cc1ca129`, and its credential-free
[default-branch CI run 29916919999](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916919999)
passed. Superseded PRs #1, #2, #4, and #6 were closed without merging.
- Private PR #10's
[CI run 29978262916](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978262916)
passed the same blocking lanes for
`debd7c1d12c72219ee37de0baa58be119d135ae0`; its PR-only canary skipped as
designed. PR #10 squash-merged as
`7d9a3d70714b38b4815d8a8f82a7177d1bcea857`, and its
[default-branch CI run 29978384862](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384862)
passed. The corresponding
[Release Please run 29978384858](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384858)
skipped as required while `RELEASE_PLEASE_ENABLED` remains disabled.
- The final merged workflow's latest-within-major canary remains unverified
under its scheduled and Dependabot paths.
- The canonical repository was confirmed private after these runs.
Repository-level variables and Actions secrets, environments, tags, releases,
and publish runs were absent when checked; `main` reported
`protected: false`. Organization-level variables and secrets were unavailable
to the current credential; detailed protection and ruleset APIs were
unavailable under the current private-repository plan. They do not provide
additional evidence. No visibility, secret, environment, protection, live,
tag, release, registry, or publication change was made.

Live evidence:

Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
79 changes: 65 additions & 14 deletions ROADMAP.md
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
# CometAPI Python SDK Roadmap

Status: `0.1.0a1` in progress
Last updated: 2026-07-22
Last updated: 2026-07-23
Repository contract: this roadmap is self-contained.

## Product target
Expand DownExpand Up@@ -114,12 +114,12 @@ Pre-visibility dependency disposition:

| Item | Disposition | Evidence and required action |
| --- | --- | --- |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its initial code-bearing [CI run 29907523251](https://github.com/cometapi-dev/cometapi-python/actions/runs/29907523251) passed. Close PR #1 after PR #9 merges; do not merge both. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9); must not merge as-is | PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version and passed initial code-bearing CI run 29907523251. Close PR #2 after PR #9 merges; the failed PR #2 run remains negative evidence only. |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its final [CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839) passed, PR #9 squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`, and PR #1 was closed without merging. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9)| PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #2 was closed without merging, and its failed run remains negative evidence only. |
| Dependabot [PR #3](https://github.com/cometapi-dev/cometapi-python/pull/3): `pypa/gh-action-pypi-publish` 1.14.0 to 1.14.1 | Deferred; keep out of `main` | Pull-request CI does not execute the release-triggered OIDC publish action or prove PyPI publication, provenance, or registry installation. Revisit with an authorized release-path review and the separately required protected release evidence; credential-free CI success alone is insufficient. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, and passed initial code-bearing CI run 29907523251. Close PR #4 after PR #9 merges; do not merge both. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #4 was closed without merging. |
| Dependabot [PR #5](https://github.com/cometapi-dev/cometapi-python/pull/5): `googleapis/release-please-action` 4.4.1 to 5.0.0 | Deferred; keep out of `main` | `RELEASE_PLEASE_ENABLED` remains disabled, and pull-request CI does not execute the gated write-capable Release Please action. Revisit only after its real config, manifest, permissions, and release behavior can be reviewed without treating a skipped action as execution evidence. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows and passed initial code-bearing CI run 29907523251 on Python 3.10 through 3.14, the minimum OpenAI lane, package builds, and copied-checkout verification. Close PR #6 after PR #9 merges; do not merge both. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows, passed final CI run 29916685839 on every blocking lane, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #6 was closed without merging. |

Recorded pre-visibility replacement evidence on 2026-07-22:

Expand DownExpand Up@@ -198,24 +198,75 @@ Final workflow-inventory hardening evidence at commit
inspection, and independent clean installs of the wheel and source
distribution.

Final pre-visibility refresh evidence on 2026-07-23:

- `git diff --check`, `uv lock --check`, and `uv sync --locked` passed.
- `uv run ruff check src tests scripts`,
`uv run ruff format --check src tests scripts`, and `uv run pyright` passed.
- `uv run pytest -m "not live"` passed with 200 tests passed and one separately
marked live test deselected.
- `uv run python scripts/check_version.py --expected 0.1.0a1 --require-changelog`,
`uv run python scripts/check_version.py --require-public-preview-docs`,
`uv run python scripts/check_secrets.py`, and
`uv run python scripts/check_workflows.py` passed.
- `uv build --out-dir dist/previsibility-20260723` built exactly the
`0.1.0a1` wheel and source distribution in a newly created empty directory.
`uv run twine check dist/previsibility-20260723/*`,
`uv run python scripts/check_artifacts.py dist/previsibility-20260723/*`, and
`uv run python scripts/check_clean_install.py dist/previsibility-20260723/*`
passed for both exact artifacts.
- `uv run python scripts/check_repository_independence.py` passed the complete
copied-checkout gate, including its 200 offline tests, workflow validation,
package build, artifact inspection, and independent clean installs of both
artifacts.
- `uv run python scripts/run_actionlint.py` and
`uv run python scripts/run_actionlint.py --offline` passed with
checksum-pinned actionlint 1.7.12.

Failed or unavailable checks:

- None of the recorded final-candidate checks failed or were unavailable.
- None of the executed final-candidate validation checks failed or were
unavailable.
Dependabot PR #2's failed run remains separate negative evidence for that PR,
not replacement evidence for PR #9. An earlier intentional offline actionlint
probe in a fresh detached worktree failed closed before the verified cache was
populated; it is not final-candidate validation evidence.
- The execution environment rejected `rm -rf dist` before it ran, so no file was
removed. The final candidate instead used the newly created empty
`dist/previsibility-20260723` directory and completed the equivalent clean
build, inspection, and two-artifact install gates there.

Remote evidence:

- Private PR #9's credential-free initial code-bearing CI run 29907523251 passed
quality, Python 3.10 through 3.14, minimum OpenAI, package, exact-artifact
clean install, retained artifact digest, and copied-checkout jobs. The PR-only
latest-within-major canary skipped as designed; scheduled or Dependabot
execution remains unverified.
- The canonical repository was confirmed private after the successful
replacement run. No visibility, secret, environment, or
repository-protection change was made.
- Private PR #9's final-head
[CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839)
passed quality, Python 3.10 through 3.14, minimum OpenAI, package,
exact-artifact clean install, retained artifact digest, and copied-checkout
jobs for `5db7f012a1470564f4f60fe343b9a0799b58987d`; the PR-only
latest-within-major canary skipped as designed. PR #9 then squash-merged as
`72b212dd72e66bbde9c6714329f72071cc1ca129`, and its credential-free
[default-branch CI run 29916919999](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916919999)
passed. Superseded PRs #1, #2, #4, and #6 were closed without merging.
- Private PR #10's
[CI run 29978262916](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978262916)
passed the same blocking lanes for
`debd7c1d12c72219ee37de0baa58be119d135ae0`; its PR-only canary skipped as
designed. PR #10 squash-merged as
`7d9a3d70714b38b4815d8a8f82a7177d1bcea857`, and its
[default-branch CI run 29978384862](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384862)
passed. The corresponding
[Release Please run 29978384858](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384858)
skipped as required while `RELEASE_PLEASE_ENABLED` remains disabled.
- The final merged workflow's latest-within-major canary remains unverified
under its scheduled and Dependabot paths.
- The canonical repository was confirmed private after these runs.
Repository-level variables and Actions secrets, environments, tags, releases,
and publish runs were absent when checked; `main` reported
`protected: false`. Organization-level variables and secrets were unavailable
to the current credential; detailed protection and ruleset APIs were
unavailable under the current private-repository plan. They do not provide
additional evidence. No visibility, secret, environment, protection, live,
tag, release, registry, or publication change was made.

Live evidence:

Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
79 changes: 65 additions & 14 deletions ROADMAP.md
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
# CometAPI Python SDK Roadmap

Status: `0.1.0a1` in progress
Last updated: 2026-07-22
Last updated: 2026-07-23
Repository contract: this roadmap is self-contained.

## Product target
Expand DownExpand Up@@ -114,12 +114,12 @@ Pre-visibility dependency disposition:

| Item | Disposition | Evidence and required action |
| --- | --- | --- |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its initial code-bearing [CI run 29907523251](https://github.com/cometapi-dev/cometapi-python/actions/runs/29907523251) passed. Close PR #1 after PR #9 merges; do not merge both. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9); must not merge as-is | PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version and passed initial code-bearing CI run 29907523251. Close PR #2 after PR #9 merges; the failed PR #2 run remains negative evidence only. |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its final [CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839) passed, PR #9 squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`, and PR #1 was closed without merging. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9)| PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #2 was closed without merging, and its failed run remains negative evidence only. |
| Dependabot [PR #3](https://github.com/cometapi-dev/cometapi-python/pull/3): `pypa/gh-action-pypi-publish` 1.14.0 to 1.14.1 | Deferred; keep out of `main` | Pull-request CI does not execute the release-triggered OIDC publish action or prove PyPI publication, provenance, or registry installation. Revisit with an authorized release-path review and the separately required protected release evidence; credential-free CI success alone is insufficient. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, and passed initial code-bearing CI run 29907523251. Close PR #4 after PR #9 merges; do not merge both. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #4 was closed without merging. |
| Dependabot [PR #5](https://github.com/cometapi-dev/cometapi-python/pull/5): `googleapis/release-please-action` 4.4.1 to 5.0.0 | Deferred; keep out of `main` | `RELEASE_PLEASE_ENABLED` remains disabled, and pull-request CI does not execute the gated write-capable Release Please action. Revisit only after its real config, manifest, permissions, and release behavior can be reviewed without treating a skipped action as execution evidence. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows and passed initial code-bearing CI run 29907523251 on Python 3.10 through 3.14, the minimum OpenAI lane, package builds, and copied-checkout verification. Close PR #6 after PR #9 merges; do not merge both. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows, passed final CI run 29916685839 on every blocking lane, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #6 was closed without merging. |

Recorded pre-visibility replacement evidence on 2026-07-22:

Expand DownExpand Up@@ -198,24 +198,75 @@ Final workflow-inventory hardening evidence at commit
inspection, and independent clean installs of the wheel and source
distribution.

Final pre-visibility refresh evidence on 2026-07-23:

- `git diff --check`, `uv lock --check`, and `uv sync --locked` passed.
- `uv run ruff check src tests scripts`,
`uv run ruff format --check src tests scripts`, and `uv run pyright` passed.
- `uv run pytest -m "not live"` passed with 200 tests passed and one separately
marked live test deselected.
- `uv run python scripts/check_version.py --expected 0.1.0a1 --require-changelog`,
`uv run python scripts/check_version.py --require-public-preview-docs`,
`uv run python scripts/check_secrets.py`, and
`uv run python scripts/check_workflows.py` passed.
- `uv build --out-dir dist/previsibility-20260723` built exactly the
`0.1.0a1` wheel and source distribution in a newly created empty directory.
`uv run twine check dist/previsibility-20260723/*`,
`uv run python scripts/check_artifacts.py dist/previsibility-20260723/*`, and
`uv run python scripts/check_clean_install.py dist/previsibility-20260723/*`
passed for both exact artifacts.
- `uv run python scripts/check_repository_independence.py` passed the complete
copied-checkout gate, including its 200 offline tests, workflow validation,
package build, artifact inspection, and independent clean installs of both
artifacts.
- `uv run python scripts/run_actionlint.py` and
`uv run python scripts/run_actionlint.py --offline` passed with
checksum-pinned actionlint 1.7.12.

Failed or unavailable checks:

- None of the recorded final-candidate checks failed or were unavailable.
- None of the executed final-candidate validation checks failed or were
unavailable.
Dependabot PR #2's failed run remains separate negative evidence for that PR,
not replacement evidence for PR #9. An earlier intentional offline actionlint
probe in a fresh detached worktree failed closed before the verified cache was
populated; it is not final-candidate validation evidence.
- The execution environment rejected `rm -rf dist` before it ran, so no file was
removed. The final candidate instead used the newly created empty
`dist/previsibility-20260723` directory and completed the equivalent clean
build, inspection, and two-artifact install gates there.

Remote evidence:

- Private PR #9's credential-free initial code-bearing CI run 29907523251 passed
quality, Python 3.10 through 3.14, minimum OpenAI, package, exact-artifact
clean install, retained artifact digest, and copied-checkout jobs. The PR-only
latest-within-major canary skipped as designed; scheduled or Dependabot
execution remains unverified.
- The canonical repository was confirmed private after the successful
replacement run. No visibility, secret, environment, or
repository-protection change was made.
- Private PR #9's final-head
[CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839)
passed quality, Python 3.10 through 3.14, minimum OpenAI, package,
exact-artifact clean install, retained artifact digest, and copied-checkout
jobs for `5db7f012a1470564f4f60fe343b9a0799b58987d`; the PR-only
latest-within-major canary skipped as designed. PR #9 then squash-merged as
`72b212dd72e66bbde9c6714329f72071cc1ca129`, and its credential-free
[default-branch CI run 29916919999](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916919999)
passed. Superseded PRs #1, #2, #4, and #6 were closed without merging.
- Private PR #10's
[CI run 29978262916](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978262916)
passed the same blocking lanes for
`debd7c1d12c72219ee37de0baa58be119d135ae0`; its PR-only canary skipped as
designed. PR #10 squash-merged as
`7d9a3d70714b38b4815d8a8f82a7177d1bcea857`, and its
[default-branch CI run 29978384862](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384862)
passed. The corresponding
[Release Please run 29978384858](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384858)
skipped as required while `RELEASE_PLEASE_ENABLED` remains disabled.
- The final merged workflow's latest-within-major canary remains unverified
under its scheduled and Dependabot paths.
- The canonical repository was confirmed private after these runs.
Repository-level variables and Actions secrets, environments, tags, releases,
and publish runs were absent when checked; `main` reported
`protected: false`. Organization-level variables and secrets were unavailable
to the current credential; detailed protection and ruleset APIs were
unavailable under the current private-repository plan. They do not provide
additional evidence. No visibility, secret, environment, protection, live,
tag, release, registry, or publication change was made.

Live evidence:

Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
79 changes: 65 additions & 14 deletions ROADMAP.md
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
# CometAPI Python SDK Roadmap

Status: `0.1.0a1` in progress
Last updated: 2026-07-22
Last updated: 2026-07-23
Repository contract: this roadmap is self-contained.

## Product target
Expand DownExpand Up@@ -114,12 +114,12 @@ Pre-visibility dependency disposition:

| Item | Disposition | Evidence and required action |
| --- | --- | --- |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its initial code-bearing [CI run 29907523251](https://github.com/cometapi-dev/cometapi-python/actions/runs/29907523251) passed. Close PR #1 after PR #9 merges; do not merge both. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9); must not merge as-is | PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version and passed initial code-bearing CI run 29907523251. Close PR #2 after PR #9 merges; the failed PR #2 run remains negative evidence only. |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its final [CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839) passed, PR #9 squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`, and PR #1 was closed without merging. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9)| PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #2 was closed without merging, and its failed run remains negative evidence only. |
| Dependabot [PR #3](https://github.com/cometapi-dev/cometapi-python/pull/3): `pypa/gh-action-pypi-publish` 1.14.0 to 1.14.1 | Deferred; keep out of `main` | Pull-request CI does not execute the release-triggered OIDC publish action or prove PyPI publication, provenance, or registry installation. Revisit with an authorized release-path review and the separately required protected release evidence; credential-free CI success alone is insufficient. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, and passed initial code-bearing CI run 29907523251. Close PR #4 after PR #9 merges; do not merge both. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #4 was closed without merging. |
| Dependabot [PR #5](https://github.com/cometapi-dev/cometapi-python/pull/5): `googleapis/release-please-action` 4.4.1 to 5.0.0 | Deferred; keep out of `main` | `RELEASE_PLEASE_ENABLED` remains disabled, and pull-request CI does not execute the gated write-capable Release Please action. Revisit only after its real config, manifest, permissions, and release behavior can be reviewed without treating a skipped action as execution evidence. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows and passed initial code-bearing CI run 29907523251 on Python 3.10 through 3.14, the minimum OpenAI lane, package builds, and copied-checkout verification. Close PR #6 after PR #9 merges; do not merge both. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows, passed final CI run 29916685839 on every blocking lane, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #6 was closed without merging. |

Recorded pre-visibility replacement evidence on 2026-07-22:

Expand DownExpand Up@@ -198,24 +198,75 @@ Final workflow-inventory hardening evidence at commit
inspection, and independent clean installs of the wheel and source
distribution.

Final pre-visibility refresh evidence on 2026-07-23:

- `git diff --check`, `uv lock --check`, and `uv sync --locked` passed.
- `uv run ruff check src tests scripts`,
`uv run ruff format --check src tests scripts`, and `uv run pyright` passed.
- `uv run pytest -m "not live"` passed with 200 tests passed and one separately
marked live test deselected.
- `uv run python scripts/check_version.py --expected 0.1.0a1 --require-changelog`,
`uv run python scripts/check_version.py --require-public-preview-docs`,
`uv run python scripts/check_secrets.py`, and
`uv run python scripts/check_workflows.py` passed.
- `uv build --out-dir dist/previsibility-20260723` built exactly the
`0.1.0a1` wheel and source distribution in a newly created empty directory.
`uv run twine check dist/previsibility-20260723/*`,
`uv run python scripts/check_artifacts.py dist/previsibility-20260723/*`, and
`uv run python scripts/check_clean_install.py dist/previsibility-20260723/*`
passed for both exact artifacts.
- `uv run python scripts/check_repository_independence.py` passed the complete
copied-checkout gate, including its 200 offline tests, workflow validation,
package build, artifact inspection, and independent clean installs of both
artifacts.
- `uv run python scripts/run_actionlint.py` and
`uv run python scripts/run_actionlint.py --offline` passed with
checksum-pinned actionlint 1.7.12.

Failed or unavailable checks:

- None of the recorded final-candidate checks failed or were unavailable.
- None of the executed final-candidate validation checks failed or were
unavailable.
Dependabot PR #2's failed run remains separate negative evidence for that PR,
not replacement evidence for PR #9. An earlier intentional offline actionlint
probe in a fresh detached worktree failed closed before the verified cache was
populated; it is not final-candidate validation evidence.
- The execution environment rejected `rm -rf dist` before it ran, so no file was
removed. The final candidate instead used the newly created empty
`dist/previsibility-20260723` directory and completed the equivalent clean
build, inspection, and two-artifact install gates there.

Remote evidence:

- Private PR #9's credential-free initial code-bearing CI run 29907523251 passed
quality, Python 3.10 through 3.14, minimum OpenAI, package, exact-artifact
clean install, retained artifact digest, and copied-checkout jobs. The PR-only
latest-within-major canary skipped as designed; scheduled or Dependabot
execution remains unverified.
- The canonical repository was confirmed private after the successful
replacement run. No visibility, secret, environment, or
repository-protection change was made.
- Private PR #9's final-head
[CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839)
passed quality, Python 3.10 through 3.14, minimum OpenAI, package,
exact-artifact clean install, retained artifact digest, and copied-checkout
jobs for `5db7f012a1470564f4f60fe343b9a0799b58987d`; the PR-only
latest-within-major canary skipped as designed. PR #9 then squash-merged as
`72b212dd72e66bbde9c6714329f72071cc1ca129`, and its credential-free
[default-branch CI run 29916919999](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916919999)
passed. Superseded PRs #1, #2, #4, and #6 were closed without merging.
- Private PR #10's
[CI run 29978262916](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978262916)
passed the same blocking lanes for
`debd7c1d12c72219ee37de0baa58be119d135ae0`; its PR-only canary skipped as
designed. PR #10 squash-merged as
`7d9a3d70714b38b4815d8a8f82a7177d1bcea857`, and its
[default-branch CI run 29978384862](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384862)
passed. The corresponding
[Release Please run 29978384858](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384858)
skipped as required while `RELEASE_PLEASE_ENABLED` remains disabled.
- The final merged workflow's latest-within-major canary remains unverified
under its scheduled and Dependabot paths.
- The canonical repository was confirmed private after these runs.
Repository-level variables and Actions secrets, environments, tags, releases,
and publish runs were absent when checked; `main` reported
`protected: false`. Organization-level variables and secrets were unavailable
to the current credential; detailed protection and ruleset APIs were
unavailable under the current private-repository plan. They do not provide
additional evidence. No visibility, secret, environment, protection, live,
tag, release, registry, or publication change was made.

Live evidence:

Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
79 changes: 65 additions & 14 deletions ROADMAP.md
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
# CometAPI Python SDK Roadmap

Status: `0.1.0a1` in progress
Last updated: 2026-07-22
Last updated: 2026-07-23
Repository contract: this roadmap is self-contained.

## Product target
Expand DownExpand Up@@ -114,12 +114,12 @@ Pre-visibility dependency disposition:

| Item | Disposition | Evidence and required action |
| --- | --- | --- |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its initial code-bearing [CI run 29907523251](https://github.com/cometapi-dev/cometapi-python/actions/runs/29907523251) passed. Close PR #1 after PR #9 merges; do not merge both. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9); must not merge as-is | PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version and passed initial code-bearing CI run 29907523251. Close PR #2 after PR #9 merges; the failed PR #2 run remains negative evidence only. |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its final [CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839) passed, PR #9 squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`, and PR #1 was closed without merging. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9)| PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #2 was closed without merging, and its failed run remains negative evidence only. |
| Dependabot [PR #3](https://github.com/cometapi-dev/cometapi-python/pull/3): `pypa/gh-action-pypi-publish` 1.14.0 to 1.14.1 | Deferred; keep out of `main` | Pull-request CI does not execute the release-triggered OIDC publish action or prove PyPI publication, provenance, or registry installation. Revisit with an authorized release-path review and the separately required protected release evidence; credential-free CI success alone is insufficient. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, and passed initial code-bearing CI run 29907523251. Close PR #4 after PR #9 merges; do not merge both. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #4 was closed without merging. |
| Dependabot [PR #5](https://github.com/cometapi-dev/cometapi-python/pull/5): `googleapis/release-please-action` 4.4.1 to 5.0.0 | Deferred; keep out of `main` | `RELEASE_PLEASE_ENABLED` remains disabled, and pull-request CI does not execute the gated write-capable Release Please action. Revisit only after its real config, manifest, permissions, and release behavior can be reviewed without treating a skipped action as execution evidence. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows and passed initial code-bearing CI run 29907523251 on Python 3.10 through 3.14, the minimum OpenAI lane, package builds, and copied-checkout verification. Close PR #6 after PR #9 merges; do not merge both. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows, passed final CI run 29916685839 on every blocking lane, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #6 was closed without merging. |

Recorded pre-visibility replacement evidence on 2026-07-22:

Expand DownExpand Up@@ -198,24 +198,75 @@ Final workflow-inventory hardening evidence at commit
inspection, and independent clean installs of the wheel and source
distribution.

Final pre-visibility refresh evidence on 2026-07-23:

- `git diff --check`, `uv lock --check`, and `uv sync --locked` passed.
- `uv run ruff check src tests scripts`,
`uv run ruff format --check src tests scripts`, and `uv run pyright` passed.
- `uv run pytest -m "not live"` passed with 200 tests passed and one separately
marked live test deselected.
- `uv run python scripts/check_version.py --expected 0.1.0a1 --require-changelog`,
`uv run python scripts/check_version.py --require-public-preview-docs`,
`uv run python scripts/check_secrets.py`, and
`uv run python scripts/check_workflows.py` passed.
- `uv build --out-dir dist/previsibility-20260723` built exactly the
`0.1.0a1` wheel and source distribution in a newly created empty directory.
`uv run twine check dist/previsibility-20260723/*`,
`uv run python scripts/check_artifacts.py dist/previsibility-20260723/*`, and
`uv run python scripts/check_clean_install.py dist/previsibility-20260723/*`
passed for both exact artifacts.
- `uv run python scripts/check_repository_independence.py` passed the complete
copied-checkout gate, including its 200 offline tests, workflow validation,
package build, artifact inspection, and independent clean installs of both
artifacts.
- `uv run python scripts/run_actionlint.py` and
`uv run python scripts/run_actionlint.py --offline` passed with
checksum-pinned actionlint 1.7.12.

Failed or unavailable checks:

- None of the recorded final-candidate checks failed or were unavailable.
- None of the executed final-candidate validation checks failed or were
unavailable.
Dependabot PR #2's failed run remains separate negative evidence for that PR,
not replacement evidence for PR #9. An earlier intentional offline actionlint
probe in a fresh detached worktree failed closed before the verified cache was
populated; it is not final-candidate validation evidence.
- The execution environment rejected `rm -rf dist` before it ran, so no file was
removed. The final candidate instead used the newly created empty
`dist/previsibility-20260723` directory and completed the equivalent clean
build, inspection, and two-artifact install gates there.

Remote evidence:

- Private PR #9's credential-free initial code-bearing CI run 29907523251 passed
quality, Python 3.10 through 3.14, minimum OpenAI, package, exact-artifact
clean install, retained artifact digest, and copied-checkout jobs. The PR-only
latest-within-major canary skipped as designed; scheduled or Dependabot
execution remains unverified.
- The canonical repository was confirmed private after the successful
replacement run. No visibility, secret, environment, or
repository-protection change was made.
- Private PR #9's final-head
[CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839)
passed quality, Python 3.10 through 3.14, minimum OpenAI, package,
exact-artifact clean install, retained artifact digest, and copied-checkout
jobs for `5db7f012a1470564f4f60fe343b9a0799b58987d`; the PR-only
latest-within-major canary skipped as designed. PR #9 then squash-merged as
`72b212dd72e66bbde9c6714329f72071cc1ca129`, and its credential-free
[default-branch CI run 29916919999](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916919999)
passed. Superseded PRs #1, #2, #4, and #6 were closed without merging.
- Private PR #10's
[CI run 29978262916](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978262916)
passed the same blocking lanes for
`debd7c1d12c72219ee37de0baa58be119d135ae0`; its PR-only canary skipped as
designed. PR #10 squash-merged as
`7d9a3d70714b38b4815d8a8f82a7177d1bcea857`, and its
[default-branch CI run 29978384862](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384862)
passed. The corresponding
[Release Please run 29978384858](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384858)
skipped as required while `RELEASE_PLEASE_ENABLED` remains disabled.
- The final merged workflow's latest-within-major canary remains unverified
under its scheduled and Dependabot paths.
- The canonical repository was confirmed private after these runs.
Repository-level variables and Actions secrets, environments, tags, releases,
and publish runs were absent when checked; `main` reported
`protected: false`. Organization-level variables and secrets were unavailable
to the current credential; detailed protection and ruleset APIs were
unavailable under the current private-repository plan. They do not provide
additional evidence. No visibility, secret, environment, protection, live,
tag, release, registry, or publication change was made.

Live evidence:

Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
79 changes: 65 additions & 14 deletions ROADMAP.md
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
# CometAPI Python SDK Roadmap

Status: `0.1.0a1` in progress
Last updated: 2026-07-22
Last updated: 2026-07-23
Repository contract: this roadmap is self-contained.

## Product target
Expand DownExpand Up@@ -114,12 +114,12 @@ Pre-visibility dependency disposition:

| Item | Disposition | Evidence and required action |
| --- | --- | --- |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its initial code-bearing [CI run 29907523251](https://github.com/cometapi-dev/cometapi-python/actions/runs/29907523251) passed. Close PR #1 after PR #9 merges; do not merge both. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9); must not merge as-is | PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version and passed initial code-bearing CI run 29907523251. Close PR #2 after PR #9 merges; the failed PR #2 run remains negative evidence only. |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its final [CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839) passed, PR #9 squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`, and PR #1 was closed without merging. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9)| PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #2 was closed without merging, and its failed run remains negative evidence only. |
| Dependabot [PR #3](https://github.com/cometapi-dev/cometapi-python/pull/3): `pypa/gh-action-pypi-publish` 1.14.0 to 1.14.1 | Deferred; keep out of `main` | Pull-request CI does not execute the release-triggered OIDC publish action or prove PyPI publication, provenance, or registry installation. Revisit with an authorized release-path review and the separately required protected release evidence; credential-free CI success alone is insufficient. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, and passed initial code-bearing CI run 29907523251. Close PR #4 after PR #9 merges; do not merge both. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #4 was closed without merging. |
| Dependabot [PR #5](https://github.com/cometapi-dev/cometapi-python/pull/5): `googleapis/release-please-action` 4.4.1 to 5.0.0 | Deferred; keep out of `main` | `RELEASE_PLEASE_ENABLED` remains disabled, and pull-request CI does not execute the gated write-capable Release Please action. Revisit only after its real config, manifest, permissions, and release behavior can be reviewed without treating a skipped action as execution evidence. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows and passed initial code-bearing CI run 29907523251 on Python 3.10 through 3.14, the minimum OpenAI lane, package builds, and copied-checkout verification. Close PR #6 after PR #9 merges; do not merge both. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows, passed final CI run 29916685839 on every blocking lane, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #6 was closed without merging. |

Recorded pre-visibility replacement evidence on 2026-07-22:

Expand DownExpand Up@@ -198,24 +198,75 @@ Final workflow-inventory hardening evidence at commit
inspection, and independent clean installs of the wheel and source
distribution.

Final pre-visibility refresh evidence on 2026-07-23:

- `git diff --check`, `uv lock --check`, and `uv sync --locked` passed.
- `uv run ruff check src tests scripts`,
`uv run ruff format --check src tests scripts`, and `uv run pyright` passed.
- `uv run pytest -m "not live"` passed with 200 tests passed and one separately
marked live test deselected.
- `uv run python scripts/check_version.py --expected 0.1.0a1 --require-changelog`,
`uv run python scripts/check_version.py --require-public-preview-docs`,
`uv run python scripts/check_secrets.py`, and
`uv run python scripts/check_workflows.py` passed.
- `uv build --out-dir dist/previsibility-20260723` built exactly the
`0.1.0a1` wheel and source distribution in a newly created empty directory.
`uv run twine check dist/previsibility-20260723/*`,
`uv run python scripts/check_artifacts.py dist/previsibility-20260723/*`, and
`uv run python scripts/check_clean_install.py dist/previsibility-20260723/*`
passed for both exact artifacts.
- `uv run python scripts/check_repository_independence.py` passed the complete
copied-checkout gate, including its 200 offline tests, workflow validation,
package build, artifact inspection, and independent clean installs of both
artifacts.
- `uv run python scripts/run_actionlint.py` and
`uv run python scripts/run_actionlint.py --offline` passed with
checksum-pinned actionlint 1.7.12.

Failed or unavailable checks:

- None of the recorded final-candidate checks failed or were unavailable.
- None of the executed final-candidate validation checks failed or were
unavailable.
Dependabot PR #2's failed run remains separate negative evidence for that PR,
not replacement evidence for PR #9. An earlier intentional offline actionlint
probe in a fresh detached worktree failed closed before the verified cache was
populated; it is not final-candidate validation evidence.
- The execution environment rejected `rm -rf dist` before it ran, so no file was
removed. The final candidate instead used the newly created empty
`dist/previsibility-20260723` directory and completed the equivalent clean
build, inspection, and two-artifact install gates there.

Remote evidence:

- Private PR #9's credential-free initial code-bearing CI run 29907523251 passed
quality, Python 3.10 through 3.14, minimum OpenAI, package, exact-artifact
clean install, retained artifact digest, and copied-checkout jobs. The PR-only
latest-within-major canary skipped as designed; scheduled or Dependabot
execution remains unverified.
- The canonical repository was confirmed private after the successful
replacement run. No visibility, secret, environment, or
repository-protection change was made.
- Private PR #9's final-head
[CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839)
passed quality, Python 3.10 through 3.14, minimum OpenAI, package,
exact-artifact clean install, retained artifact digest, and copied-checkout
jobs for `5db7f012a1470564f4f60fe343b9a0799b58987d`; the PR-only
latest-within-major canary skipped as designed. PR #9 then squash-merged as
`72b212dd72e66bbde9c6714329f72071cc1ca129`, and its credential-free
[default-branch CI run 29916919999](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916919999)
passed. Superseded PRs #1, #2, #4, and #6 were closed without merging.
- Private PR #10's
[CI run 29978262916](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978262916)
passed the same blocking lanes for
`debd7c1d12c72219ee37de0baa58be119d135ae0`; its PR-only canary skipped as
designed. PR #10 squash-merged as
`7d9a3d70714b38b4815d8a8f82a7177d1bcea857`, and its
[default-branch CI run 29978384862](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384862)
passed. The corresponding
[Release Please run 29978384858](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384858)
skipped as required while `RELEASE_PLEASE_ENABLED` remains disabled.
- The final merged workflow's latest-within-major canary remains unverified
under its scheduled and Dependabot paths.
- The canonical repository was confirmed private after these runs.
Repository-level variables and Actions secrets, environments, tags, releases,
and publish runs were absent when checked; `main` reported
`protected: false`. Organization-level variables and secrets were unavailable
to the current credential; detailed protection and ruleset APIs were
unavailable under the current private-repository plan. They do not provide
additional evidence. No visibility, secret, environment, protection, live,
tag, release, registry, or publication change was made.

Live evidence:

Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
79 changes: 65 additions & 14 deletions ROADMAP.md
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
# CometAPI Python SDK Roadmap

Status: `0.1.0a1` in progress
Last updated: 2026-07-22
Last updated: 2026-07-23
Repository contract: this roadmap is self-contained.

## Product target
Expand DownExpand Up@@ -114,12 +114,12 @@ Pre-visibility dependency disposition:

| Item | Disposition | Evidence and required action |
| --- | --- | --- |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its initial code-bearing [CI run 29907523251](https://github.com/cometapi-dev/cometapi-python/actions/runs/29907523251) passed. Close PR #1 after PR #9 merges; do not merge both. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9); must not merge as-is | PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version and passed initial code-bearing CI run 29907523251. Close PR #2 after PR #9 merges; the failed PR #2 run remains negative evidence only. |
| Dependabot [PR #1](https://github.com/cometapi-dev/cometapi-python/pull/1): `actions/download-artifact` 4.3.0 to 8.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin throughout the release workflow and adds a credential-free CI artifact download plus SHA256 round trip. Its final [CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839) passed, PR #9 squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`, and PR #1 was closed without merging. |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9)| PR #2's [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed because its regression test hard-coded the previous checkout SHA. PR #9 instead validates parsed action references independently of version, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #2 was closed without merging, and its failed run remains negative evidence only. |
| Dependabot [PR #3](https://github.com/cometapi-dev/cometapi-python/pull/3): `pypa/gh-action-pypi-publish` 1.14.0 to 1.14.1 | Deferred; keep out of `main` | Pull-request CI does not execute the release-triggered OIDC publish action or prove PyPI publication, provenance, or registry installation. Revisit with an authorized release-path review and the separately required protected release evidence; credential-free CI success alone is insufficient. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, and passed initial code-bearing CI run 29907523251. Close PR #4 after PR #9 merges; do not merge both. |
| Dependabot [PR #4](https://github.com/cometapi-dev/cometapi-python/pull/4): `actions/upload-artifact` 4.6.2 to 7.0.1 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin in CI and release builds, requires missing artifacts to fail, retains digest evidence, passed final CI run 29916685839, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #4 was closed without merging. |
| Dependabot [PR #5](https://github.com/cometapi-dev/cometapi-python/pull/5): `googleapis/release-please-action` 4.4.1 to 5.0.0 | Deferred; keep out of `main` | `RELEASE_PLEASE_ENABLED` remains disabled, and pull-request CI does not execute the gated write-capable Release Please action. Revisit only after its real config, manifest, permissions, and release behavior can be reviewed without treating a skipped action as execution evidence. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Superseded by private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows and passed initial code-bearing CI run 29907523251 on Python 3.10 through 3.14, the minimum OpenAI lane, package builds, and copied-checkout verification. Close PR #6 after PR #9 merges; do not merge both. |
| Dependabot [PR #6](https://github.com/cometapi-dev/cometapi-python/pull/6): `actions/setup-python` 5.6.0 to 7.0.0 | Closed unmerged; superseded by merged private [PR #9](https://github.com/cometapi-dev/cometapi-python/pull/9) | PR #9 applies the reviewed SHA pin across CI, monitoring, and release workflows, passed final CI run 29916685839 on every blocking lane, and squash-merged as `72b212dd72e66bbde9c6714329f72071cc1ca129`; PR #6 was closed without merging. |

Recorded pre-visibility replacement evidence on 2026-07-22:

Expand DownExpand Up@@ -198,24 +198,75 @@ Final workflow-inventory hardening evidence at commit
inspection, and independent clean installs of the wheel and source
distribution.

Final pre-visibility refresh evidence on 2026-07-23:

- `git diff --check`, `uv lock --check`, and `uv sync --locked` passed.
- `uv run ruff check src tests scripts`,
`uv run ruff format --check src tests scripts`, and `uv run pyright` passed.
- `uv run pytest -m "not live"` passed with 200 tests passed and one separately
marked live test deselected.
- `uv run python scripts/check_version.py --expected 0.1.0a1 --require-changelog`,
`uv run python scripts/check_version.py --require-public-preview-docs`,
`uv run python scripts/check_secrets.py`, and
`uv run python scripts/check_workflows.py` passed.
- `uv build --out-dir dist/previsibility-20260723` built exactly the
`0.1.0a1` wheel and source distribution in a newly created empty directory.
`uv run twine check dist/previsibility-20260723/*`,
`uv run python scripts/check_artifacts.py dist/previsibility-20260723/*`, and
`uv run python scripts/check_clean_install.py dist/previsibility-20260723/*`
passed for both exact artifacts.
- `uv run python scripts/check_repository_independence.py` passed the complete
copied-checkout gate, including its 200 offline tests, workflow validation,
package build, artifact inspection, and independent clean installs of both
artifacts.
- `uv run python scripts/run_actionlint.py` and
`uv run python scripts/run_actionlint.py --offline` passed with
checksum-pinned actionlint 1.7.12.

Failed or unavailable checks:

- None of the recorded final-candidate checks failed or were unavailable.
- None of the executed final-candidate validation checks failed or were
unavailable.
Dependabot PR #2's failed run remains separate negative evidence for that PR,
not replacement evidence for PR #9. An earlier intentional offline actionlint
probe in a fresh detached worktree failed closed before the verified cache was
populated; it is not final-candidate validation evidence.
- The execution environment rejected `rm -rf dist` before it ran, so no file was
removed. The final candidate instead used the newly created empty
`dist/previsibility-20260723` directory and completed the equivalent clean
build, inspection, and two-artifact install gates there.

Remote evidence:

- Private PR #9's credential-free initial code-bearing CI run 29907523251 passed
quality, Python 3.10 through 3.14, minimum OpenAI, package, exact-artifact
clean install, retained artifact digest, and copied-checkout jobs. The PR-only
latest-within-major canary skipped as designed; scheduled or Dependabot
execution remains unverified.
- The canonical repository was confirmed private after the successful
replacement run. No visibility, secret, environment, or
repository-protection change was made.
- Private PR #9's final-head
[CI run 29916685839](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916685839)
passed quality, Python 3.10 through 3.14, minimum OpenAI, package,
exact-artifact clean install, retained artifact digest, and copied-checkout
jobs for `5db7f012a1470564f4f60fe343b9a0799b58987d`; the PR-only
latest-within-major canary skipped as designed. PR #9 then squash-merged as
`72b212dd72e66bbde9c6714329f72071cc1ca129`, and its credential-free
[default-branch CI run 29916919999](https://github.com/cometapi-dev/cometapi-python/actions/runs/29916919999)
passed. Superseded PRs #1, #2, #4, and #6 were closed without merging.
- Private PR #10's
[CI run 29978262916](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978262916)
passed the same blocking lanes for
`debd7c1d12c72219ee37de0baa58be119d135ae0`; its PR-only canary skipped as
designed. PR #10 squash-merged as
`7d9a3d70714b38b4815d8a8f82a7177d1bcea857`, and its
[default-branch CI run 29978384862](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384862)
passed. The corresponding
[Release Please run 29978384858](https://github.com/cometapi-dev/cometapi-python/actions/runs/29978384858)
skipped as required while `RELEASE_PLEASE_ENABLED` remains disabled.
- The final merged workflow's latest-within-major canary remains unverified
under its scheduled and Dependabot paths.
- The canonical repository was confirmed private after these runs.
Repository-level variables and Actions secrets, environments, tags, releases,
and publish runs were absent when checked; `main` reported
`protected: false`. Organization-level variables and secrets were unavailable
to the current credential; detailed protection and ruleset APIs were
unavailable under the current private-repository plan. They do not provide
additional evidence. No visibility, secret, environment, protection, live,
tag, release, registry, or publication change was made.

Live evidence:

Expand Down