ReasonFirst 0.5.0 release notes¶
This document summarizes ReasonFirst v0.5.0. The GitHub release/tag identifies the exact released commit; source checkouts can move ahead, so use the exact commit SHA when reporting reproducibility evidence.
Why 0.5.0¶
0.5.0 is a compatibility, safety, and public-usability release over the 0.3.0 ActualCoder lifecycle. It keeps the same product direction—ChatGPT/strong reasoning first, replaceable coding workers second—while making the complete chat-only path reproducible for external users.
The 0.5.0 version line is intentional: prior development had already used the 0.4 line, so this release avoids reusing that version family.
Main user-visible changes¶
- Full Bridge-managed chat-only loop: pinned TaskSpec → one managed workspace → Codex App Server execution → reviewed diff → snapshot-bound finish preview → explicit human publication approval → GitLab MR → matching-HEAD CI → EvidencePack.
- Current Codex App Server worker-start compatibility fixes, including policy wire values and safe handling when a ReasonFirst MCP entry is absent.
- macOS launchd proxy synchronization for environments where outbound model traffic needs an HTTP(S) proxy, without writing proxy values into source or LaunchAgent plists.
- Health polling after MCP installation/restart to avoid false-negative startup races.
- Durable TaskSpec/attempt records, bounded EvidencePack, worker-policy evidence, explicit approval mediation, project practice tooling, CI failure classification, and safer finish gates accumulated since v0.3.0.
- Public bilingual chat-only rehearsal, onboarding, troubleshooting, architecture, contribution, and release-maintainer documentation.
- Final release documentation/Pages audit: current guides are reconciled with the implemented architecture, historical v0.2/v0.3 notes are labeled, rendered internal links are CI-checked, and the bilingual site exposes the v0.5.0 architecture/validation baseline.
Observed end-to-end acceptance¶
The 2026-09-28 synthetic GitLab rehearsal observed all of the following on one managed task:
- live GitLab source grounding at a pinned revision;
- one managed workspace and feature branch;
- Bridge-managed Codex App Server worker execution;
- a README-only reviewed diff;
- successful configured unit tests;
- a concrete finish-preview snapshot digest;
- explicit human approval of that exact snapshot;
- controlled commit/push and Merge Request creation;
- matching-HEAD GitLab CI with the real unit-test job successful;
- complete EvidencePack review;
- no automatic merge.
This acceptance proves the exercised path, not every deployment topology.
Known boundaries¶
- GitLab is the implemented SCM/CI target adapter; hosting ReasonFirst itself on GitHub does not provide a GitHub-target task adapter.
- Worktrees and worker subprocess controls are not an OS security sandbox.
- Native Git trust/destination policy remains distinct from Python API/MCP TLS handling.
- The Bridge Preview MCP is more privileged than the read-oriented GitLab MCP and should be enabled deliberately. Whether its write-capable tools are available through ChatGPT depends on the connected client/workspace; terminal ActualCoder remains the portable execution fallback.
- macOS launchd does not automatically inherit an interactive shell's proxy environment; use the documented session-scoped sync helper when required.
- Final merge remains a human decision. ReasonFirst does not auto-merge.
- External coding tools use their own authentication, quotas, and billing; ReasonFirst makes no direct model-inference API calls.
Release validation¶
The v0.5.0 release gate requires exact-head success for:
validate(full Python unit/integration suite);- Ubuntu, macOS, and Windows cross-platform jobs;
- Ubuntu and macOS Bridge regression jobs;
package-release-candidate(wheel + sdist build, archive-path inspection, clean-wheel install/version/CLI checks, and source/full-history secret scan);- the documentation-site build/deploy when documentation changes are present.
At the pre-release audit baseline 7d16061061f6337604bd3135c9e4a693ad1fd68a,
all seven CI jobs and the Docs site passed; validate ran 445 tests.
The final GitHub Release records the exact tagged SHA and must be published only
after the same exact-head gate passes on the final documentation commit.
See docs/PUBLIC_RELEASE_CHECKLIST.md for the full maintainer checklist.