Skip to content

Fix required dependency metadata and newcomer setup - #6

Merged
tbitcs merged 5 commits into
mainfrom
fix/dependency-metadata-and-onboarding
Sep 19, 2026
Merged

tbitcs merged 5 commits into
mainfrom
fix/dependency-metadata-and-onboarding

Conversation

@tbitcs

@tbitcs tbitcs commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

The AEE extension declared engine >=1.0.0 even though its gaps command needs 1.0.2, and its dependency metadata did not expose the separate Evaluator extension clearly. This patch prepares 1.0.1 with documented tool dependencies, links both required repositories, and explains the manual installation order and current Spec Kit enforcement limits.

New-user documentation now distinguishes shell and agent commands, published releases and this unreleased patch, actual CLI settings and the unused YAML reference, gap stdout/output behavior, and manual evidence review. The starter claim contains no fictional observed result. The README links the benchmark's immutable measurements and failures without claiming a demonstrated correctness or token-saving advantage.

Validation adds the real engine and Spec Kit parser to hash-locked dependencies, covers all six adapter operations, and runs a clean installation with the pinned published Evaluator. CI expands to Linux Python 3.11/3.13 and Windows Python 3.12 while preserving the protected validate check. CodeQL and dependency review remain enabled. Local results: 19 tests, Ruff, relative documentation links, and installation smoke pass. See final-commit checks and docs/dependency-audit.md for coverage and limitations.

Spec Kit's official guide requires an Extension Submission issue for catalog corrections, not a catalog PR. The metadata-only correction is submitted as github/spec-kit#4626 and retains the existing v1.0.0 archive; this source patch is unreleased until separately reviewed, merged and tagged. Do not move existing tags. No merge or release is performed by this PR.

Final validation at c7fe50c893b2173d0b72a8b499e69c129555e774: Linux Python 3.11/3.13 and Windows Python 3.12 tests/install smoke, required validate gate, CodeQL/analyze, and dependency-review all pass. Dependabot configuration validation passed on the preceding configuration commit. No open CodeQL alerts were returned. Latest main OpenSSF Scorecard succeeded; that scheduled/main workflow does not run against this PR head. Both exact public release URLs also passed installation and all six adapter operations locally. Benchmark PR #1 remains green; its 54 tests and 980 evidence objects/five manifests were rechecked. No merge or release performed.

@tbitcs
tbitcs marked this pull request as ready for review September 18, 2026 01:44
@tbitcs
tbitcs merged commit e44bfc7 into main Sep 19, 2026
7 checks passed
@tbitcs
tbitcs deleted the fix/dependency-metadata-and-onboarding branch September 19, 2026 13:51
tbitcs added a commit that referenced this pull request Sep 19, 2026
Resolve conflicts after PR #6 (dependency metadata, v1.0.1) merged:
- extension.yml: keep version 1.0.1 from main; keep the 99-char
  catalog-trimmed description from this branch
- CHANGELOG.md: combine both entry sets under 1.0.1 - Unreleased
- .gitignore: union of patterns (main's .venv-*/ subsumes .venv-hatch/)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant