Skip to content

[PY-01] Regenerate from tagged contracts with reproducible CI provenance #4

Description

@jaavid

Resolution

Completed for the current 1.0.0-draft public contract baseline.

Evidence

  • SDK generation provenance now pins immutable CoreLinkPlatform/api-contracts tag v1.0.0-draft.
  • Tag resolves to contract commit 5bdc07b80c8acbd0617b75e2d7ae3edd17f6324b; the generated OpenAPI blob is 11cd7034f2b6dc736e23a4cf36242a34f0d637e5.
  • The original development generation input resolves to the same OpenAPI blob, so the checked-in generated package is semantically based on the immutable tagged contract.
  • .corelink-contract.json and CODEGEN.md record immutable contract and generator provenance.
  • Blacksmith Generated SDK Conformance regenerates with OpenAPI Generator 7.12.0, verifies checked-in generated source against the pinned contract (normalizing generator-only trailing whitespace), then compiles the package.
  • Blacksmith run 33277017639 completed successfully on commit 2e5a09b0f2e243e51edd47eb5d2cae85c2402d0e.

Acceptance criteria

  • Generation is reproducible from documented immutable/tagged inputs.
  • Generated source drift is checked in CI.
  • Authentication/tenant/error/idempotency semantics remain generated from the normative public contract rather than a hand-written SDK schema.
  • Prerelease maturity is documented accurately; this completion does not claim a Stable PyPI release.
  • Examples/documentation identify current contract/package maturity.
  • Immutable contract/generator provenance is retained.

PY-02 and PY-03 remain the active ergonomics, license-policy, sandbox-conformance and supported-publication gates.

Metadata

Metadata

Assignees

No one assigned

    Labels

    type:technical-taskImplementation or engineering enablement work

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions