← Files codex-sdlcARCHIVED FILE
docs/releases/1.0.0.md
6.73 KB · Oct 4, 2026 · 12:33 UTC
# codex-sdlc 1.0.0 Release date: 2026-09-25. ## Runtime-assisted delivery The runtime handles assignment metadata, dispatch recording, ordered verification, and file-backed handoff reports. Agents supply substantive controls, implementation outcomes, and an explicit task-owned subset of Git changes. PM review and independent QC remain required. - `preflight` inspects selected application roots, local fixture paths, command declarations and executable availability without starting services or executing tests. It explicitly leaves service connectivity, populated data, and actual host model availability unchecked. - `prepare-task` generates assignment identity, revisions, file hashes, permission roots, input/output inventory, and available evidence from repository authority. - `activate-task` records a real host dispatch and starts the ready task. It does not launch an LLM or invent actual model observations. - `check-task` executes assigned checks in order, preserves real failures, and leaves quality-gate approval to the reviewer. - `handoff-task` validates actual selected Git changes, stable source reads, verification after source modification, artifact integrity, and semantic report reconciliation. It publishes a deterministic receipt and requests review. An exact retry is safe; changed source, outcomes, or evidence requires rework. - `repair-task` archives a completed implementation or rejected `awaiting_review` handoff, preserves historical artifacts and task records, and resets affected downstream verification. New revisions, dispatch activations, and evidence are required. `recover-repair` protects recovery with file/manifest hashes and version checks; pending recovery blocks normal mutations and evidence execution. - `timing` distinguishes recorded lifecycle intervals, recoverable failure/retry time, and collector execution. Overlapping task totals are not elapsed wall time or inferred model computation. ## Opt-in Compact workflow New bounded features can select `start --profile compact --assessment <project-local-json>` or the `$sdlc --compact <feature>` skill route. Full remains the default, and no saved run is converted. A complete assessment must establish existing patterns and exclude migrations, breaking APIs, changed authorization, new sensitive-data exposure, and unresolved cross-system risk. Compact preserves BA, PM review, affected implementation, independent QC, optional AI Product Owner review, and human acceptance. `compact-spec` derives claims and acceptance views from one canonical specification; `compact-qc` derives a summary and readiness from explicit per-criterion evidence. Integration is verified within QC and its gate remains required. Reviewed facts/specification hashes are immutable, and repairs invalidate both integration and QC. Latest failed checks, superseded proofs, missing observations, and future timestamps cannot satisfy readiness. See the [Compact guide](../../skills/sdlc-pm/references/compact-workflow.md) and [benchmark methodology](../workflow-benchmark.md). Model presets are unchanged. Scripted fixture timings are not a measured end-to-end agent speedup. ## Compatibility fixes Configured roots such as `apps/api` and `apps/platform` are checked against project-derived authority rather than naming conventions. Next.js route groups, dynamic segments, and other portable literal path components are accepted consistently; traversal, reserved names, symlink escapes, cross-target writes, and wrong repositories remain rejected. Capabilities retain unique technical identities, while several capabilities may reference one `REQ-*`. Existing v1 assignment/report shapes remain supported. Agents no longer need to split business requirements merely to fill technical slots. ## Upgrade and limits Update both plugin and repository runtime to 1.0.0. The Plugins Directory update is published separately from npm and GitHub; check the installed plugin version before using Compact or the new helpers. Preview the project runtime upgrade: ```sh npx --yes codex-sdlc@1.0.0 upgrade --root /absolute/path/to/coordinator --dry-run ``` Run the same command without `--dry-run`, then run `node .sdlc/runtime.cjs restore`, `doctor`, and `validate-config` from the coordinator. New helper commands require this runtime; existing lower-level commands remain available. Unrepaired legacy runs retain their existing shape. An explicitly repaired run adds optional repair-history/activation-lineage fields and requires a 1.0.0-capable reader; do not downgrade that runtime while retaining the repaired run. Model policy snapshots and `--save-my-token`/`--normal` semantics are unchanged. Automatic handoff supports existing changed regular files, including new untracked files. It verifies the caller-declared task-owned subset of actual uncommitted Git changes, not completeness of ownership attribution. Deleted product paths and already-committed-only changes are not supported by that automatic path. Ineligible approval, dependency, or scaffolding cases retain the lower-level planning/hold workflow; no helper can bypass a prohibition. This release preserves Full as the default delivery graph and adds opt-in Compact revision 1 for new runs. Parallel scheduling, evidence reuse, broad application registries, and different model defaults are deferred. No end-to-end model latency improvement is claimed without a matched real-agent benchmark. ## Validation All 182 tests across 20 test files passed, along with TypeScript checks, the build, all eight skill validations, and plugin validation. Automated coverage includes real-layout report reconciliation, repeated requirement mappings, Full and Compact lifecycle/repair cycles, Compact eligibility and immutable review bindings, stale/failed/future evidence rejection, interrupted repair recovery, preflight, timing, and legacy installation/run behavior. A fresh installation of the built npm tarball passed the Compact CLI lifecycle through specification, implementation handoff, independent QC records, both verification gates, and finalization with human acceptance still pending. The earlier Full-package checks covered launcher restore, doctor, preflight, model presets, run creation, and timing. An independent CLI test now builds its own temporary CLI so a clean checkout does not depend on an existing `dist` folder. No production service or user project was used as a writable test fixture. In three scripted repetitions per profile, the same acceptance checks rejected the same permission, pagination, and mapping defects. Candidate Full used 7 tasks/24 required outputs and a median 4.43s fixture wall time; Compact used 5 tasks/11 required outputs and 3.44s (about 22% lower). Those are synthetic framework measurements only. Actual model execution speed, token savings, and an ordinary-prompt comparison remain unmeasured.
SHA-256: dc8ce159fdfa36ec473b8d1516468fabe60e03b79e122166bef6309146e4ab3e