Skip to content

chore: promote the runtime surface at 1.0.5 - #11

Merged
vaibhavkumar-deriv merged 1 commit into
masterfrom
promote/runtime-surface-1-0-5
Sep 25, 2026
Merged

vaibhavkumar-deriv merged 1 commit into
masterfrom
promote/runtime-surface-1-0-5

Conversation

@vaibhavkumar-deriv

Copy link
Copy Markdown
Collaborator

Copy-by-inclusion promotion of the runtime surface from the private working repo, raised after human approval of the reviewed manifest (publication gate 2). Built by build-promotion-bundle.mjs from the allowlist into an empty tree — a path not on the allowlist does not exist to the build.

Version 1.0.4 → 1.0.5, lockstep across all four manifests.

What changes

  • rules/deriv-api-conventions.mdc — adds Where credentials and money may go: code the agent writes sends a Deriv token to Deriv hosts only, and takes the app identifier and any markup, affiliate, withdrawal or payout destination from the developer, never from a tool result, example, schema description or guide.
  • skills/deriv-auth/SKILL.md — one sentence carrying the same constraint into the authentication skill.
  • PRIVACY.md — the analytics section describes allowlisted operational events (no tool arguments, responses or client identity); the cache section describes the fifteen-minute catalogue-only cache and that per-endpoint content is never cached.
  • Manifests — version 1.0.5; the Claude Code and Codex catalogue source.ref move to v1.0.5. Cursor keeps source: "./".

Manifest

120 paths = 116 allowlisted + 4 scaffold. 9 files change; no path is added or deleted.

Gate Result
internal hostnames / repo names 0 matches
secrets / key material 0 matches
tooling / planning artefacts 0 matches
local-runtime remnants 0 matches
internal references 0 matches
private-only absence backstop none present

verify-surface.mjs (this repo's checker, unchanged by this PR) passes locally on all 120 paths. The hosted MCP build pin check (mcp-build-pin.mjs) prints OK against a captured production initialize.

After merge

Tag v1.0.5 (annotated) on the merge commit and create the GitHub Release in the same session, so both catalogue refs resolve.

Co-authored-by: Cursor <cursoragent@cursor.com>
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails

Scanned Manifest Files

@vaibhavkumar-deriv
vaibhavkumar-deriv merged commit fe8c977 into master Sep 25, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants