Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,15 @@

All notable distribution changes are documented here. This project follows semantic versioning for skill and plugin artifacts.

## Unreleased

### Changed

- Aligned the repository publisher mirror with the live founder-operated Openly Useful authority while Openly Useful LLC remains formation-pending.
- Made npm package readiness depend on direct founder-owner authorization, exact package/MCP namespaces, public-policy files, and deterministic release validation instead of LLC formation or provider marketplace review.
- Normalized both npm CLI `bin` maps and made the combined MCP build mark its bundled commands executable so npm preserves every published command without manifest correction.
- Kept npm account authentication at the actual registry boundary and retained marketplace, MCP Registry, deployment, and future LLC operation as separate workflows.

## 1.2.0 - 2026-08-16

### Added
Expand Down
59 changes: 30 additions & 29 deletions COMPLIANCE-PACKET.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,10 @@
# Local compliance packet

Status: local identity, licensing, policy, and runtime-notice inputs are
implemented for release `1.2.0`. Public marketplace submission, package
publication, hosted operation, and business verification remain external
actions. This packet is not legal advice or publication authorization.
Status: identity, licensing, policy, runtime-notice, package, namespace, and
founder-authorization inputs are implemented for release `1.2.0`. npm package
publication is authorized but has not been performed. Marketplace submission,
MCP Registry submission, hosted operation, and provider review remain separate
external actions. This packet is not legal advice.

## Publisher and ownership record

Expand All @@ -13,18 +14,22 @@ The repository mirrors the canonical Openly Useful publisher manifest in
- Public publisher/developer brand: **Openly Useful**.
- Planned legal entity: **Openly Useful LLC**.
- Entity status: **formation-pending**.
- Current operator: **individual founder**, operating as Openly Useful.
- Planned entity roles: publisher, operator, and licensee.
- RunGlance authorship: **sole-author-confirmed**.
- RunGlance copyright: personally owned by the individual founder.
- Ownership transfer: **not required and not planned**.
- Current open-source publication: founder-authorized.
- Current npm package publication: directly founder-owner authorized while
formation remains pending.
- Future LLC publication: authorization documentation pending until after
formation.

Openly Useful LLC must not be described as already formed or as the RunGlance
copyright owner. Its eventual publisher/operator/licensee role does not depend
on an assignment of ownership. Sole authorship and personal ownership are
owner-confirmed and are not public-activation gates.
Openly Useful LLC must not be described as already formed, as the current
operator, or as the RunGlance copyright owner. Its eventual
publisher/operator/licensee role does not depend on an assignment of ownership.
Sole authorship, personal ownership, and direct founder publication
authorization are owner-confirmed and do not depend on LLC formation.

## License and notices

Expand Down Expand Up @@ -60,30 +65,26 @@ website, privacy, terms, and support values. Claude manifests carry the common
publisher, homepage, repository, and license values; their physical skill copy
also contains the canonical component metadata.

## External gates
## npm publication gate

The release may be locally distribution-ready while public publication remains
blocked by external state:
The fail-closed npm gate requires:

1. Complete and verify Openly Useful LLC formation before identifying it as the
active legal operator.
2. After formation, document the founder's authorization for LLC publication,
and verify the public repository and every policy/support URL anonymously.
3. Complete provider business/developer verification and domain-namespace
authentication.
4. Review the generated archives and checksums from the exact release commit.
5. Authorize each package publication, MCP Registry entry, marketplace
submission, and deployment separately.
1. Direct founder-owner authorization effective during formation.
2. Exact `@openly-useful` package and `org.openlyuseful` MCP contracts.
3. Canonical public policy files and authority metadata.
4. Current license, notices, generated wrappers, tests, and deterministic plans.

No IP assignment, ownership transfer, or ownership verification appears in
this gate list. The founder's personal ownership and sole authorship are already
confirmed, and transfer is neither required nor planned.
npm account authentication is not part of the static readiness claim. The
registry enforces it separately at the actual publish request.

Provider review does not block npm. Marketplace, MCP Registry, deployment, and
future LLC operation each remain separately controlled. No IP assignment,
ownership transfer, or ownership verification appears in the npm gate.

## Completion criteria

`node scripts/release-check.mjs --json` must report valid local inputs and
`distributionReady: true`. While the publisher manifest records
`formation-pending`, it must continue to report `publishReady: false` and an
`entity-and-external-verification` gate. No local check creates or verifies an
external account, entity filing, registry entry, marketplace listing, or
deployment.
`node scripts/release-check.mjs --json` must report `valid: true`,
`distributionReady: true`, and `publishReady: true`; both package
`prepublishOnly` scripts must pass without publishing. No local check creates or
authenticates an npm account, files an entity, submits a registry or marketplace
listing, or deploys a service.
10 changes: 6 additions & 4 deletions PROVENANCE.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,10 +15,12 @@ or ownership transfer to Openly Useful or to the planned Openly Useful LLC is
required or represented by this repository. Current open-source publication is
founder-authorized.

Openly Useful is the publisher and developer brand. Openly Useful LLC remains
formation-pending and must not be described as formed, active, or as the owner
or operator. A future LLC may publish, operate, and license the project only
under separately documented founder authorization after formation.
Openly Useful is the publisher and developer brand and is currently operated by
the individual founder. The founder-owner directly authorizes source and npm
package publication while formation is pending. Openly Useful LLC remains
formation-pending and must not be described as formed, active, as the current
operator, or as the owner. A future LLC may later publish, operate, and license
the project under separately documented founder authorization.

The canonical public repository target for both products in release 1.2.0 is
<https://github.com/Openly-Useful/project-status>. Product packages, MCP Registry
Expand Down
20 changes: 12 additions & 8 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -107,7 +107,7 @@ The `packages/mcp` commands apply only when that optional package is present. `n
- `dist/server/index.js`
- `dist/.openai/hosting.json`

`scripts/release-check.mjs` validates wrapper drift, version agreement, host-specific marketplace and manifest shapes, the MCP bundle boundary, package safety, changelog coverage, and deterministic archive plans. It reports public-publication gates separately from repository distribution readiness. Both publishable MCP packages also run `scripts/assert-publish-ready.mjs` at the `prepublishOnly` boundary, so `npm publish` fails closed until formation, authorization, namespace verification, live policy verification, and blocker clearance are all recorded. The test suite also extracts both plugin archives into isolated temporary directories and performs a pinned MCP handshake plus readiness and activity tool calls without installing dependencies.
`scripts/release-check.mjs` validates wrapper drift, version agreement, host-specific marketplace and manifest shapes, the MCP bundle boundary, package safety, changelog coverage, deterministic archive plans, package identities, namespaces, public-policy files, and founder publication authorization. Both publishable MCP packages run `scripts/assert-publish-ready.mjs` at the `prepublishOnly` boundary. npm publication is founder-authorized while LLC formation remains pending; the registry still enforces account authentication at the actual publish request, and provider marketplace review is a separate workflow that does not block npm. The test suite also extracts both plugin archives into isolated temporary directories and performs a pinned MCP handshake plus readiness and activity tool calls without installing dependencies.

Third-party notices are generated from the pinned runtime dependency graphs rather than the full development toolchain:

Expand Down Expand Up @@ -187,15 +187,19 @@ The distribution version is recorded in `VERSION`, both canonical component meta

`publisher/publisher.json` is the repository mirror/consumer of <https://openlyuseful.org/publisher/manifest.json>. Openly Useful is the publisher/developer brand. Openly Useful LLC is the planned publisher, operator, and licensee, but remains formation-pending and must not be described as already formed. The `.org` identity is the canonical open-source, publisher, policy, security, and support surface; `.com` is the studio/commercial identity. Component metadata points to the canonical public <https://github.com/Openly-Useful/project-status> repository and <https://openlyuseful.org/support>.

RunGlance was solely authored by and remains personally owned by the founder. Current open-source publication is founder-authorized. No IP assignment, ownership transfer, or ownership verification is required for activation; the future LLC can publish, operate, and license RunGlance after formation and after its founder authorization is documented, without becoming the copyright owner.
RunGlance was solely authored by and remains personally owned by the founder. Openly Useful is currently operated by the individual founder, who directly authorizes open-source and npm package publication while LLC formation remains pending. No IP assignment, ownership transfer, or ownership verification is required; a future LLC can later publish, operate, and license RunGlance under documented founder authorization without becoming the copyright owner.

Local distribution readiness and public activation are separate. `distributionReady` may be true when source, generated wrappers, license/notices, policies, metadata, and deterministic packages validate. While the publisher record remains `formation-pending`, `publishReady` must remain false. Public activation still requires:
Local distribution readiness and npm package readiness remain separate signals. `distributionReady` covers source, generated wrappers, license/notices, policies, metadata, and deterministic packages. `publishReady` additionally requires:

1. Openly Useful LLC formation and documentation of the founder's authorization for its publishing role;
2. anonymous reachability checks for the public repository and policy/support URLs;
3. provider business/developer verification and domain/namespace authentication;
4. review of generated archives and checksums from the exact release commit; and
5. separate authorization for each package publication, registry entry, marketplace submission, or deployment.
1. direct founder-owner authorization effective while LLC formation is pending;
2. exact npm package and MCP namespace contracts;
3. the canonical privacy, terms, security, and support policy files;
4. current license, notices, generated wrappers, tests, and deterministic package plans.

Account authentication is not fabricated by the static readiness result. npm
enforces it separately when an actual registry request is made.

OpenAI/Claude provider review, marketplace submission, MCP Registry submission, deployment, and future LLC operation remain separate workflows. None is inferred from npm readiness, and provider review does not block npm publication.

The repository contains the unmodified Apache License 2.0 text and a deterministic third-party notice bundle. Apache-2.0 does not require a project-specific copyright-holder/year placeholder in the license text.

Expand Down
30 changes: 17 additions & 13 deletions RELEASE-POLICY-DECISIONS.md
Original file line number Diff line number Diff line change
@@ -1,27 +1,30 @@
# Local release and monitoring policy record

Status: approved local preparation decisions recorded. External monitoring,
publication, marketplace, and business-verification actions remain inactive.
This record does not authorize deployment, installation, scheduling,
notification, or publication.
Status: founder-authorized open-source and npm package publication is recorded.
External monitoring, marketplace submission, MCP Registry submission,
deployment, and provider-review actions remain separate. This record does not
authorize installation, scheduling, notification, deployment, or provider
submission.

## Publisher, authorship, and entity boundary

- **Openly Useful** is the public publisher and developer brand used in local
component and provider metadata.
- **Openly Useful LLC** is the planned publisher/operator/licensee and remains
`formation-pending`.
- Openly Useful is currently operated by the individual founder.
- RunGlance was solely authored by, and remains personally owned by, the
founder.
- No copyright assignment or ownership transfer is required or planned.
- The future entity may publish, operate, and license RunGlance under founder
authorization without becoming its copyright owner.
- The founder-owner directly authorizes current source and npm package
publication while formation is pending. The future entity may later publish,
operate, and license RunGlance under founder authorization without becoming
its copyright owner.
- Sole authorship and personal ownership are owner-confirmed facts, not
public-activation gates.
- Public marketplace, registry, package, and commercial activation remains
pending entity formation, documentation of founder authorization for future
LLC publication, provider business verification, public URL reachability,
and separate authorization.
- Provider marketplace review does not block npm package publication.
Marketplace submission, MCP Registry submission, deployment, and commercial
activation retain separate authorization and validation paths.

## Approved monitoring preparation parameters

Expand Down Expand Up @@ -81,6 +84,7 @@ escalation procedure.
The public-safe publisher mirror contains brand, policy, namespace, planned
entity-role, and non-identifying ownership-status facts. Private legal filings,
personal identifiers, account credentials, and restricted contact records must
not enter archives. No entry here authorizes a commit, push, merge, deployment,
installation, schedule, publication, filing, purchase, outreach, or account
change.
not enter archives. This record documents the founder's current source and npm
package publication authorization; it does not itself initiate a commit, push,
merge, deployment, installation, schedule, registry request, filing, purchase,
outreach, or account change.
2 changes: 1 addition & 1 deletion packages/mcp/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ Optional local, read-only companions for Project Status readiness and standalone

The publishable Project Status package identity is `@openly-useful/project-status-mcp`, with official MCP Registry name `org.openlyuseful/project-status`. This source package deliberately retains both the `project-status-mcp` and `runglance-mcp` local bins so existing plugin builds and tests keep working. Public RunGlance packaging is owned by the sibling `packages/runglance-mcp` bundle and uses its independent package and registry identity.

Neither package nor either MCP Registry record is published by this repository. External publication remains gated on formation of the planned publisher, explicit authorization, namespace verification, and public policy verification.
The founder-owner directly authorizes npm package publication while Openly Useful LLC formation remains pending. The package's `prepublishOnly` gate validates the founder authorization, package/MCP namespaces, public-policy files, licensing, generated wrappers, tests, and deterministic release inputs. npm account authentication is enforced by the registry at the actual publish request; provider marketplace review is separate and does not block npm.

This subpackage targets Node.js 20+, the stable MCP TypeScript SDK v2 split packages,
the 2026-07-28 protocol, and Zod v4 Standard Schemas. It serves stdio only and never
Expand Down
6 changes: 3 additions & 3 deletions packages/mcp/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,8 @@
"license": "Apache-2.0",
"type": "module",
"bin": {
"project-status-mcp": "./dist/index.js",
"runglance-mcp": "./dist/runglance-index.js"
"project-status-mcp": "dist/index.js",
"runglance-mcp": "dist/runglance-index.js"
},
"files": [
"dist/index.js",
Expand All @@ -17,7 +17,7 @@
"LICENSE"
],
"scripts": {
"build": "node scripts/sync-license.mjs && tsc -p tsconfig.json && esbuild src/index.ts --bundle --platform=node --format=esm --target=node20 --outfile=dist/index.js --charset=utf8 --legal-comments=eof && esbuild src/runglance-index.ts --bundle --platform=node --format=esm --target=node20 --outfile=dist/runglance-index.js --charset=utf8 --legal-comments=eof",
"build": "node scripts/sync-license.mjs && tsc -p tsconfig.json && esbuild src/index.ts --bundle --platform=node --format=esm --target=node20 --outfile=dist/index.js --charset=utf8 --legal-comments=eof && esbuild src/runglance-index.ts --bundle --platform=node --format=esm --target=node20 --outfile=dist/runglance-index.js --charset=utf8 --legal-comments=eof && node scripts/finalize-build.mjs",
"typecheck": "tsc -p tsconfig.json --noEmit",
"test": "node --test tests/*.test.mjs",
"prepack": "npm run build && npm test",
Expand Down
12 changes: 12 additions & 0 deletions packages/mcp/scripts/finalize-build.mjs
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
#!/usr/bin/env node

import { chmodSync, existsSync } from "node:fs";
import { resolve } from "node:path";
import { fileURLToPath } from "node:url";

const packageRoot = resolve(fileURLToPath(new URL("..", import.meta.url)));
for (const relativePath of ["dist/index.js", "dist/runglance-index.js"]) {
const output = resolve(packageRoot, relativePath);
if (!existsSync(output)) throw new Error(`Missing MCP executable: ${relativePath}`);
chmodSync(output, 0o755);
}
11 changes: 8 additions & 3 deletions packages/mcp/tests/identity.test.mjs
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
import assert from "node:assert/strict";
import { readFileSync } from "node:fs";
import { readFileSync, statSync } from "node:fs";
import { join, resolve } from "node:path";
import test from "node:test";
import { fileURLToPath } from "node:url";
Expand Down Expand Up @@ -28,9 +28,14 @@ test("Project Status npm and MCP Registry identities agree", () => {
test("combined source package preserves both existing local bins", () => {
const packageJson = json(join(packageRoot, "package.json"));
assert.deepEqual(packageJson.bin, {
"project-status-mcp": "./dist/index.js",
"runglance-mcp": "./dist/runglance-index.js",
"project-status-mcp": "dist/index.js",
"runglance-mcp": "dist/runglance-index.js",
});
for (const path of Object.values(packageJson.bin)) {
const output = join(packageRoot, path);
assert.ok(readFileSync(output, "utf8").startsWith("#!/usr/bin/env node\n"));
assert.notEqual(statSync(output).mode & 0o111, 0);
}
});

test("published package carries the owner-approved root license", () => {
Expand Down
2 changes: 1 addition & 1 deletion packages/runglance-mcp/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,4 +17,4 @@ node dist/index.js --help

The shared pinned TypeScript/esbuild toolchain under `../mcp` must be present in a source checkout. The published bundle has no runtime dependency installation step.

Nothing in this package authorizes npm publication or MCP Registry submission. External publication remains gated on formation of the planned publisher, explicit publisher authorization, namespace verification, and public policy verification.
The founder-owner directly authorizes npm package publication while Openly Useful LLC formation remains pending. The package's `prepublishOnly` gate validates the founder authorization, package/MCP namespaces, public-policy files, licensing, generated wrappers, tests, and deterministic release inputs. npm account authentication is enforced by the registry at the actual publish request; provider marketplace review and MCP Registry submission remain separate workflows.
2 changes: 1 addition & 1 deletion packages/runglance-mcp/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
"license": "Apache-2.0",
"type": "module",
"bin": {
"runglance-mcp": "./dist/index.js"
"runglance-mcp": "dist/index.js"
},
"files": [
"dist/index.js",
Expand Down
Loading