Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
30 commits
Select commit Hold shift + click to select a range
2c321a9
feat: v0.3.0 managed advisory Jev runtime, multi-harness integration,…
Coding-Dev-Tools Sep 28, 2026
5943d75
feat: complete portable Jev integration and qualified evidence selection
Coding-Dev-Tools Sep 28, 2026
a100ae7
test: preserve evidence bytes on Python 3.9
Coding-Dev-Tools Sep 28, 2026
d6c4530
test: make deadline and contention checks portable across Windows run…
Coding-Dev-Tools Sep 28, 2026
9e4275b
fix: bind evidence qualification and add explicit Command Code workflow
Coding-Dev-Tools Sep 28, 2026
6ece687
test: retain case-insensitive Windows environment for capture subproc…
Coding-Dev-Tools Sep 28, 2026
2b957e9
fix: preserve existing keyring credentials during guided reconfiguration
Coding-Dev-Tools Sep 28, 2026
95048e5
test: isolate response contract fixtures from disk accounting timing
Coding-Dev-Tools Sep 28, 2026
27da47d
fix: redact wire question IDs and preserve caller mappings
Coding-Dev-Tools Sep 28, 2026
adc337c
fix: close release review gaps and ship portable evidence capture
Coding-Dev-Tools Sep 29, 2026
09cbde8
fix: preserve caller score legends and default evidence calls off
Coding-Dev-Tools Sep 29, 2026
d60f21f
test: verify bounded ledger waits without a spurious wall deadline
Coding-Dev-Tools Sep 29, 2026
05dfb54
fix: reject unusable credentials before protected storage
Coding-Dev-Tools Sep 29, 2026
f9ed66c
fix: reject anomalous usage with conservative accounting
Coding-Dev-Tools Sep 29, 2026
6249fe0
fix(harness): keep the environment interpreter in generated entries
Coding-Dev-Tools Sep 30, 2026
85b4f50
fix(credentials): treat unexpanded harness references as absent keys
Coding-Dev-Tools Sep 30, 2026
d7d0a70
fix(evidence): screen private names only below the approved root
Coding-Dev-Tools Sep 30, 2026
8d4af48
fix(client): honor an explicit library key before setup
Coding-Dev-Tools Sep 30, 2026
fab5643
build: single-source the package version
Coding-Dev-Tools Sep 30, 2026
685524c
feat(hooks): escalate-only pre-execution shell guard for harness hooks
Coding-Dev-Tools Sep 30, 2026
873b32b
perf(mcp): advertise a compact jev_decide input schema
Coding-Dev-Tools Sep 30, 2026
660a79f
ci: test Python 3.14 and Node 24; neutral credential dialog wording
Coding-Dev-Tools Sep 30, 2026
a6af974
fix(cli): explain why a configured runtime is disabled
Coding-Dev-Tools Sep 30, 2026
2344832
feat(client): accept plain question objects in Python
Coding-Dev-Tools Sep 30, 2026
b640bef
docs: task-first quickstart, hook guide and review migration notes
Coding-Dev-Tools Sep 30, 2026
eb87ad5
fix(hooks): guard Claude Code's PowerShell tool on Windows
Coding-Dev-Tools Sep 30, 2026
1373297
fix(hooks): check reads outside the working directory
Coding-Dev-Tools Sep 30, 2026
22e46de
docs(validation): record the 2026-09-30 merge-readiness review
Coding-Dev-Tools Oct 1, 2026
c0e9165
feat: add structured memory advice and harden Command Code integrations
Coding-Dev-Tools Oct 1, 2026
837d909
Merge local harness updates and preserve explicit Jev consent and evi…
Coding-Dev-Tools Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
* text=auto eol=lf
*.py text eol=lf
*.md text eol=lf
*.json text eol=lf
*.toml text eol=lf
*.yml text eol=lf
*.sh text eol=lf
*.ps1 text eol=lf
*.ts text eol=lf
*.cjs text eol=lf
55 changes: 52 additions & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ jobs:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
python-version: ["3.9", "3.10", "3.11", "3.12", "3.13"]
python-version: ["3.9", "3.10", "3.11", "3.12", "3.13", "3.14"]

steps:
- uses: actions/checkout@v4
Expand All @@ -26,13 +26,62 @@ jobs:
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -e ".[test]"
pip install -e ".[test,mcp,setup]"

- name: Run Pytest
run: |
python -m pytest tests/ -v

- name: Check configured Python lint rules
if: matrix.os == 'ubuntu-latest' && matrix.python-version == '3.12'
run: |
python -m pip install ruff==0.16.9
python -m ruff check .

- name: Test CLI
run: |
jev --help
jev guard "git status"
jev doctor --json

- name: Clean wheel and source installation
if: matrix.python-version == '3.12'
run: |
python -m pip install build
python scripts/check_packages.py --output "${{ runner.temp }}/jev-artifacts"

- name: Retain Python release candidates
if: matrix.python-version == '3.12'
uses: actions/upload-artifact@v4
with:
name: python-release-${{ matrix.os }}
path: |
${{ runner.temp }}/jev-artifacts/dist/*
${{ runner.temp }}/jev-artifacts/verification.json

typescript:
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
node-version: ["22", "24"]
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: ${{ matrix.node-version }}
- run: npm ci
working-directory: ts
- run: npm test
working-directory: ts
- run: npm run check:package
working-directory: ts
- uses: actions/upload-artifact@v4
with:
name: npm-release-${{ matrix.os }}-node${{ matrix.node-version }}
path: ts/*.tgz
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- run: python -m pip install -e ".[test]"
- run: python -m pytest tests/test_parity.py tests/test_question_ids.py -q
6 changes: 6 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -8,3 +8,9 @@ __pycache__/
.venv/
venv/
.env
build/
dist/
ts/node_modules/
ts/dist/
ts/*.tgz
.coverage
14 changes: 14 additions & 0 deletions Claude outputs/PR_DESCRIPTION.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
Jev v0.3 gives Python, TypeScript, CLI and MCP users a portable advisory runtime with explicit setup, protected credentials and bounded requests. Command Code users can capture approved evidence before model ingestion, and memory systems can consume structured advice without handing Jev permission or memory authority.

- Enforce pinned provider contracts, redacted wire identifiers, per-caller label restoration, one request deadline and conservative shared Python budget accounting. Missing or anomalous usage remains unknown and reserved. Fresh clients, CLI/MCP processes and hooks stay offline; an explicit library key can opt in before setup, while saved disabled settings always win.
- Preserve unrelated settings through owned installation/restoration. Command Code ships an explicitly invoked skill, shared-project ownership checks, core capture and Windows-safe argv handling. Generated POSIX launchers retain their environment interpreter; unexpanded credential references count as absent keys.
- Add bounded `assess_memory_relation` and `assess_memory_relevance` helpers plus a dependency-free Engraphis question bridge. Unknown judgments and confidence remain null. Host consent, scoped routing, deterministic verifiers and memory governance remain authoritative.
- Read saved evidence through pinned roots and validated opened handles, preserving original bytes, hashes and complete source spans. Credential files and Windows stream aliases are denied globally; redirected roots cannot grant new access. Off/shadow/select policy and workload qualification govern omission; no automatic omission profile ships.
- Offer optional pre-tool shell hooks for five harnesses. They request a native prompt or deny flagged commands and fail open on unavailable advice. Command Code covers shell and Windows PowerShell. Path-qualified executables, unknown flags and effectful options are assessed; hooks never approve commands.
- Advertise compact MCP questions while retaining complete backend/native-map compatibility and meaningful-content validation. Keep a single Python version source, task-oriented migration/setup guides, shared memory examples and clean package verification receipts. CI covers Python 3.9–3.14 and Node 22/24 on Windows, macOS and Linux.

Validation on Windows / Python 3.12.10 with the official MCP SDK 2.2.0: **781 passed, 2 platform-related skips**; TypeScript build and **87 tests passed**; Ruff and Git whitespace checks passed. Clean wheel, source and npm installations run outside the checkout, including packaged memory/bridge/hook/capture/skill checks and legacy/current MCP handshakes, with zero provider requests. Four bounded internal reviewers returned; the parent integrated their actionable findings.

This PR includes the current checkout's changes, all 14 commits from `review/merge-ready`, and the applicable safeguards from the preserved older worktree. Its remaining edits are superseded by the current contracts and remain untouched in that worktree. The [combined review record](https://github.com/Coding-Dev-Tools/jev-decision/blob/codex/jev-harness-integration/docs/validation/command-code-memory-20261001.md) explains the reconciliation and evidence boundaries.

These local/package checks do not establish authenticated provider operation, named-client live usability, improved recall or token/time/billing savings. Live evaluation remains separate and budget-authorized. No merge or package publication is included. GitHub CI and review status must be read for this PR's latest head.
21 changes: 21 additions & 0 deletions LICENSE
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
MIT License

Copyright (c) 2026 Coding-Dev-Tools and contributors

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
9 changes: 9 additions & 0 deletions MANIFEST.in
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
include LICENSE README.md
recursive-include docs *.md *.json
recursive-include examples *.py *.ps1 *.sh *.json *.log
recursive-include scripts *.py *.ps1
recursive-include tests *.py
include ts/package.json ts/package-lock.json ts/tsconfig.json ts/README.md ts/LICENSE
recursive-include ts/src *.ts
recursive-include ts/test *.cjs *.json
recursive-include ts/scripts *.cjs
Loading
Loading