Skip to content

Record Flow 9.1.0 qualification and canary evidence - #133

Merged
vriesd merged 2 commits into
mainfrom
release/9.1.0-qualification-evidence
Sep 27, 2026
Merged

vriesd merged 2 commits into
mainfrom
release/9.1.0-qualification-evidence

Conversation

@vriesd

@vriesd vriesd commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

The Flow 9.1.0 release now has a passed exact-artifact canary and a sealed OpenAI-only qualification bundle. The bundle independently regrades 38 of 38 fixed-target attempts as passing and binds the packed artifact SHA-256 0b7f7a66bf1910b5d0da3a235f891d532b4aa352a2dbd25e398325c18e051b24.

Four original campaign transcripts contained the recording host's home path in diagnostic tool output. The source report is preserved byte-for-byte as an extensionless snapshot. A redaction receipt lists each original and derived transcript hash and the 12 output fields changed. The sealed bundle contains the privacy-safe derived report and transcripts. Recorded decisions, attempt outcomes, and the 38/38 score did not change. The original transcripts remain local and are not published.

Validation: bun run check passed with 1,591 tests, 20 skips, and no failures. bun run scripts/release-metadata.ts --tag v9.1.0 --artifact <exact tarball> --canary evals/canary/9.1.0.json independently verified the committed bundle and exact canary. This PR does not tag or publish the release.

Record the exact-artifact canary and sealed 38/38 OpenAI qualification bundle. The original campaign report and receipt identify four transcripts whose diagnostic tool outputs needed local home-path redaction. The provider decisions and scored outcomes are unchanged.
Keep the source report as an extensionless snapshot so its receipt hash remains exact. Format the redaction receipt for repository lint.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T06:51:28.821766Z b6a3a03 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@vriesd

vriesd commented Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

Independent read-only evidence review at b6a3a033dd65b81b21d1d4bee90ee47590ee8e53: PASS.

The packed artifact and bundled artifact both match SHA-256 0b7f7a66bf1910b5d0da3a235f891d532b4aa352a2dbd25e398325c18e051b24. All 272 sealed objects match their recorded sizes and hashes. The original report matches the committed snapshot byte for byte. The redacted bundle changes exactly the receipt's 12 diagnostic output fields across four transcripts; all 38 recorded outcomes remain unchanged. Strict bundle regrading returns VERIFIED at 38/38 with the exact canary.

This verifies retained evidence. It does not rerun paid model calls.

@vriesd
vriesd merged commit 727308d into main Sep 27, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants