You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
v1.4.0 is released. Its five-task hosted-Devin campaign is complete: Devin delivered 3/5; Codex independently completed #865 through #971 and #935 through #973. The final #935 recovery was user-cancelled before delivery, not a completed failed repair. Devin is qualified for bounded, well-scoped hosted builder work; orchestration and merge-authority review require separate evidence. Qualification scorecard · Operational closeout.
Release order remains v1.4.0 complete → v1.4.1 Graphify → v1.4.2 Board → v1.5.0 supervised Slack. An explicit evidence-backed Graphify deferral recorded in #915/#902 may satisfy that dependency; elapsed time, implementation difficulty, or a draft PR never changes release order automatically. Already merged post-v1.4.0 fixes, including #935/#973, are recorded as on main until a subsequent published package is verified to contain them.
Workstream
Epic
Verified position
Remaining delivery / release gate
Released Devin transport and bounded builder qualification
A replacement writer starts only after verified source quiescence; ordered contributors, current writer, labels, and review exclusion agree at the exact head.
A real qualified Codex/Claude supervisor controls bounded hosted Devin work. Missing supervisor readiness blocks dispatch; selecting a provider never promotes its role.
Parallel work follows independent source ownership, one current writer and Code Mower sessions/audits. Release, tag and deployment actions are serial. Board and Slack work do not compete with ready stabilization/Graphify work under the owner's current priority.
completed foundation PRs #929/#933 retained as evidence
After merging #980/#981/#984/#985 and adding #983, there are 22 remaining mapped implementation PR slots: four existing drafts (#956/#957/#982/#987) and 18 planned PRs, including the three release PRs. #983 is one additional OSS campaign-authentication PR required before #923, scheduled after #915. Future PR numbers are assigned only when a real branch/change exists. There is no umbrella implementation PR. #918/#919/#920/#978 are hosted repository PRs; #977/#921/#922 and all other listed implementation units are OSS PRs. Keep the exact private hosted repository/PR binding in the authorized record and publish only approved metadata. #921 owns the frozen cross-repository telemetry contract; #978 owns its hosted implementation, with separate reviews and deployment evidence.
Delivery and operational contract
One named Code Mower builder and one writer per branch. Use qualified Codex/Claude for cross-cutting contracts, supervision, recovery, and release work. Bounded Devin observation canaries may implement a small approved task.
Every implementation PR has a qualified independent reviewer excluded from all verified contributors to the current diff, the exact current head, focused/relevant tests, privacy checks, normal CI, and authoritative code-mower/gate (or the hosted repository's equivalent required gate). Fix all P0/P1/P2 findings. A changed head invalidates the prior audit; a successful gate publisher is not the gate verdict. If no eligible reviewer remains, stop for one explicit owner action.
A final writer must be demonstrably quiescent before takeover/final-head acceptance where the workflow requires it. Completion, cancellation acknowledgement, provider exit, review readiness, and merge are distinct observations. Unknown exit fails closed for takeover.
Future paid campaigns require an explicit initial and aggregate ACU cap, stable private binding, and no automatic uncertain retry. At most one or two explicitly budgeted recovery creates precede splitting or changing builders. This plan creates no additional provider allowance. Track creates, interventions, elapsed time, coverage, observed/settled spend, and outcome; unknown billing is not zero and need not cause an indefinite release wait.
Each epic carries live PR/head, contributor lineage, review/test/gate, package/deployment, Board, and cloud evidence. Historical results stay historical. A merged feature is marked shipped only after the package/deployment containing it is verified.
Privacy and scope boundaries
Graphify remains optional, deterministic, local, immutable-revision-bound, explicit-refresh, and code-only. Board remains a local observation/read model: refresh never dispatches, retries, cancels, restarts, renews a lease, or merges. Board v1.4.2 adds no cloud fields. Slack remains authorized ingress/conversation transport; a separately qualified supervisor owns orchestration. New Slack telemetry belongs to #921/#978 only. Existing #906 lifecycle and #935 discovery are reused.
Source, diffs, task/answer prose, prompts, transcripts, Slack/private identities, credentials, raw provider records, provider references, graph/context contents, and personal paths stay out of public planning evidence and cloud uploads. Private runtime content follows the existing authorized storage/retention contract.
Broad unattended rollout, Devin orchestrator/reviewer promotion, Cursor cold-install investigation #860, new optional integrations, and general productivity claims are follow-on scope rather than v1.5.0 promises.
Final Code Mower Board and CodeMower.com views show the accepted outcomes with source freshness; stored event receipts and freshly observed aggregate visibility pass separately. Cloud: verify aggregate freshness after accepted release metadata #974 and any confirmed-defect child are closed.
The owner has prioritized fully completing v1.4.0 stabilization and Graphify v1.4.1 first, then Board v1.4.2. This overrides the earlier overlap schedule where it would start Board or Slack work ahead of ready stabilization work.
No new hosted-Devin session allowance is inferred. Local Code Mower Codex/Claude builders and independent audits drive the current work.
Incorporated v1.4.0 hosted adoption report
The reported upgrade, CLI/wrapper version alignment, loopback Board lifecycle, lanes status, preview/drift and quiet opt-in behavior are positive historical adoption evidence. The report does not establish Devin orchestrator qualification, remote reachability of a loopback Board, or readiness of an isolated campaign from an ordinary CLI login.
Repo secrets, auto-merge promotion and generated-file drift
Selected-repository operator actions, not installation failures; preview changes and preserve informational policy until explicitly promoted
Release rehearsal retains successful default/no-optional-provider behavior and distinguishes warn/exit 0, full activation and package shipment. Do not freeze the report's warning count, silently apply its generated setup, or provision credentials from this report.
Current acceptance count for v1.4.1 plus required stabilization: 7 of 12 units accepted (two Graphify foundation units and five #979 units). This is a deliverable count, not an effort-weighted percentage or a claim that the remaining work takes equal time. Active drafts and published-package verification remain outstanding. Other independently owned repository PRs are outside the mapped-slot count and must be reconciled into the final candidate if merged.
Completion roadmap through v1.5.0
Current position and release order
v1.4.0 is released. Its five-task hosted-Devin campaign is complete: Devin delivered 3/5; Codex independently completed #865 through #971 and #935 through #973. The final #935 recovery was user-cancelled before delivery, not a completed failed repair. Devin is qualified for bounded, well-scoped hosted builder work; orchestration and merge-authority review require separate evidence. Qualification scorecard · Operational closeout.
Release order remains v1.4.0 complete → v1.4.1 Graphify → v1.4.2 Board → v1.5.0 supervised Slack. An explicit evidence-backed Graphify deferral recorded in #915/#902 may satisfy that dependency; elapsed time, implementation difficulty, or a draft PR never changes release order automatically. Already merged post-v1.4.0 fixes, including #935/#973, are recorded as on main until a subsequent published package is verified to contain them.
The maintained first-run default remains Claude + Codex. Devin, Coworker, Graphify, Slack, and optional reviewers remain explicit selections grouped by role.
Five approved revisions and their PR mapping
Execution waves and dependencies
Parallel work follows independent source ownership, one current writer and Code Mower sessions/audits. Release, tag and deployment actions are serial. Board and Slack work do not compete with ready stabilization/Graphify work under the owner's current priority.
Epic-to-PR inventory
After merging #980/#981/#984/#985 and adding #983, there are 22 remaining mapped implementation PR slots: four existing drafts (#956/#957/#982/#987) and 18 planned PRs, including the three release PRs. #983 is one additional OSS campaign-authentication PR required before #923, scheduled after #915. Future PR numbers are assigned only when a real branch/change exists. There is no umbrella implementation PR. #918/#919/#920/#978 are hosted repository PRs; #977/#921/#922 and all other listed implementation units are OSS PRs. Keep the exact private hosted repository/PR binding in the authorized record and publish only approved metadata. #921 owns the frozen cross-repository telemetry contract; #978 owns its hosted implementation, with separate reviews and deployment evidence.
Delivery and operational contract
code-mower/gate(or the hosted repository's equivalent required gate). Fix all P0/P1/P2 findings. A changed head invalidates the prior audit; a successful gate publisher is not the gate verdict. If no eligible reviewer remains, stop for one explicit owner action.Privacy and scope boundaries
Graphify remains optional, deterministic, local, immutable-revision-bound, explicit-refresh, and code-only. Board remains a local observation/read model: refresh never dispatches, retries, cancels, restarts, renews a lease, or merges. Board v1.4.2 adds no cloud fields. Slack remains authorized ingress/conversation transport; a separately qualified supervisor owns orchestration. New Slack telemetry belongs to #921/#978 only. Existing #906 lifecycle and #935 discovery are reused.
Source, diffs, task/answer prose, prompts, transcripts, Slack/private identities, credentials, raw provider records, provider references, graph/context contents, and personal paths stay out of public planning evidence and cloud uploads. Private runtime content follows the existing authorized storage/retention contract.
Broad unattended rollout, Devin orchestrator/reviewer promotion, Cursor cold-install investigation #860, new optional integrations, and general productivity claims are follow-on scope rather than v1.5.0 promises.
Completion gates
Active execution priority
The owner has prioritized fully completing v1.4.0 stabilization and Graphify v1.4.1 first, then Board v1.4.2. This overrides the earlier overlap schedule where it would start Board or Slack work ahead of ready stabilization work.
Incorporated v1.4.0 hosted adoption report
The reported upgrade, CLI/wrapper version alignment, loopback Board lifecycle, lanes status, preview/drift and quiet opt-in behavior are positive historical adoption evidence. The report does not establish Devin orchestrator qualification, remote reachability of a loopback Board, or readiness of an isolated campaign from an ordinary CLI login.
Release rehearsal retains successful default/no-optional-provider behavior and distinguishes warn/exit 0, full activation and package shipment. Do not freeze the report's warning count, silently apply its generated setup, or provision credentials from this report.
Current acceptance count for v1.4.1 plus required stabilization: 7 of 12 units accepted (two Graphify foundation units and five #979 units). This is a deliverable count, not an effort-weighted percentage or a claim that the remaining work takes equal time. Active drafts and published-package verification remain outstanding. Other independently owned repository PRs are outside the mapped-slot count and must be reconciled into the final candidate if merged.