Metadata-Version: 2.4
Name: factoryline-code-factory
Version: 0.47.0
Summary: Audit AI-built code with six evidence lanes, intent-to-proof traces, agent workflow receipts, and human-owned release gates.
Author: Richard Katz
Author-email: rkatz22@gmail.com
Maintainer: Richard Katz
Maintainer-email: rkatz22@gmail.com
License-Expression: MIT OR Apache-2.0
Project-URL: Homepage, https://github.com/zrk222/code-factory
Project-URL: Documentation, https://github.com/zrk222/code-factory#readme
Project-URL: Source, https://github.com/zrk222/code-factory
Project-URL: Issues, https://github.com/zrk222/code-factory/issues
Project-URL: Changelog, https://github.com/zrk222/code-factory/releases
Keywords: software-factory,ai-agents,mutation-testing,release-evidence,developer-tools,mvp,mcp,model-context-protocol,cursor,opencode,ai-coding-assistant,graph-ops,prd-grill,independent-verification,verifier-plane,github-pull-request,proof-review,proof-debt,ai-governance,design-review,ui-quality,langgraph,agent-replay,resume-parity,gauntlet,e2e-testing,survival-card
Classifier: Development Status :: 4 - Beta
Classifier: Intended Audience :: Developers
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3 :: Only
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Topic :: Software Development :: Build Tools
Classifier: Topic :: Software Development :: Quality Assurance
Requires-Python: >=3.10
Description-Content-Type: text/markdown
License-File: LICENSE
License-File: LICENSE-APACHE
License-File: LICENSE-MIT
License-File: NOTICE
Requires-Dist: cryptography<50,>=42
Requires-Dist: httpx<1,>=0.28
Requires-Dist: psycopg[binary]<4,>=3.2
Requires-Dist: PyYAML<7,>=6
Requires-Dist: reportlab<5,>=4
Requires-Dist: tomli>=2.0; python_version < "3.11"
Provides-Extra: dev
Requires-Dist: hypothesis<7,>=6.135; extra == "dev"
Requires-Dist: pytest>=8.0; extra == "dev"
Requires-Dist: pytest-asyncio<1,>=0.24; extra == "dev"
Requires-Dist: pytest-cov<8,>=7; extra == "dev"
Requires-Dist: pytest-xdist==3.8.0; extra == "dev"
Requires-Dist: ruff<0.15,>=0.14; extra == "dev"
Requires-Dist: tomli>=2.0; python_version < "3.11" and extra == "dev"
Provides-Extra: sigstore
Requires-Dist: sigstore<5,>=4.4; extra == "sigstore"
Provides-Extra: enterprise
Requires-Dist: cryptography<50,>=42; extra == "enterprise"
Provides-Extra: hosted
Requires-Dist: gunicorn<24,>=23; platform_system != "Windows" and extra == "hosted"
Dynamic: license-file

# Code Factory

Code Factory + ForgeLine (CF/FL) is a robust, local-first code-audit factory.
It starts by collecting local software review evidence for the candidate change.
It connects requirements, architecture checks, Python AST security analysis,
behavioral test evidence, workflow integrity, specialty AI review, and
actionable repair. Its receipts support review; the tool does not certify
software, guarantee that defects are absent, or approve a release.

## 0.47.0 audit workflow preview

**Fixed:** editor audit views now expose missing and incomplete checks.
**Changed:** Junie's route connects a diff to bounded evidence and a concrete
repair handoff. **Added:** project-neutral `factory audit workflows` contracts
with hash-bound candidate and execution evidence, plus VS Code/Open VSX 1.1.0
evidence tree, JetBrains 1.1.0 CF + ForgeLine tab, and a native
[OpenCode plugin](plugins/code-factory-opencode/README.md).
**Candidate detection fixes:** the Python scanner flags tests without a local
assertion, constant-true assertions, and reflexive comparisons. Declared tenant
reads can be checked with `factory audit security --tenant-read-call db.get`;
this checks the declared `tenant_id` parameter binding, not tenant authentication.
The unchanged eight-case public regression corpus now gives 6 true positives,
2 true negatives, and no false positives or false negatives locally, with the
same tenant-read contract applied to defective, repaired, and clean inputs.
This is a small development regression result, not independent accuracy,
runtime coverage, or release approval. CI verification is still required.
The [autonomous ops plan](docs/AUTONOMOUS_OPS_EDITOR_PLAN.md) explains the
proposed Observer Agent loop and its gates. These versions remain release
candidates until each channel has a verified provider publication receipt.

## Graph Ops in action

![Full-page Graph Ops dashboard capture: lineage runs, a forensic finding, first semantic divergence, recovery preview, guarded actions, graph lanes, and the next action](docs/assets/marketplace/graph-ops-forensics.png)

This full-page local capture shows Graph Ops tracing a change from sealed
lineage through a forensic finding to a proposed recovery path. The guarded
action remains locked; the dashboard is a read-only inspection surface.

![Graph Ops Counterfactual Arena comparing a rejected patch, an eligible refactor, and a verified repair candidate](docs/assets/marketplace/graph-ops-proofsearch.png)

The Counterfactual Arena compares repair candidates and shows their evidence
and risk. [Winner controls](docs/assets/marketplace/graph-ops-proofsearch-controls.png)
and the [Evidence Frontier](docs/assets/marketplace/graph-ops-evidence-frontier.png)
show how a reviewer can inspect the rationale and choose the next proof.

The current Graph Ops UI also separates native deep-scan progress, evaluated
deep-audit receipts, six runtime lanes, and individual JUnit test cases. Each
panel labels its evidence state and next repair. Filter or search the recorded
tests, then load more cases as needed; an inventory or a missing report never
appears as a passing run. The JUnit reader accepts up to 10,000 cases and marks
larger or malformed reports incomplete. A JUnit report is local observation
without a current-candidate binding.

![Updated Graph Ops audit results: labeled native deep scan, evaluated audit, six runtime lanes, and searchable individual test results](docs/assets/marketplace/graph-ops-audit-results-0.46.9.png)

This local UI capture shows each reported test case with its status. The audit
cards keep checks without a bound result explicitly marked not run.

<details>
<summary>Supplement: annotated live Assembly telemetry</summary>

![Annotated Graph Ops telemetry capture: callouts identify the human waiting state, live run counts, evidence actions, and read-only boundary](docs/assets/marketplace/graph-ops-live-annotated.png)

The labels explain an [original local Assembly capture](docs/assets/marketplace/factoryline-0.44-live-dashboard.png).
That pictured run is waiting for human input; it does not imply release approval
or that every check passed.

</details>

## Install and start

```powershell
python -m pip install factoryline-code-factory
factory --help
factory guide
```

In an interactive terminal, `factory` checks PyPI and caches the result for up
to 24 hours, then prints a notice when a newer version is available. Two
simultaneous first runs can both check. It never downloads or installs the
update. The check is quiet in CI, JSON output, server/MCP, help, version, and
non-interactive runs; set `FACTORY_DISABLE_UPDATE_CHECK=1` to turn it off. The
plain PyPI request does not include a project path, account identifier, or
usage data.

Run repository commands from the project being reviewed. `factory guide` is a
read-only orientation; it does not run tests or agents.

## Inspect this repository

These commands show the current architecture policy, the bounded static
security scan, and the runtime-audit setup:

```powershell
factory architecture health --root . --json
factory audit security --root . --json
factory runtime-audit status --root . --json
```

`factory audit security` checks a limited set of source patterns. It is not a
penetration test. The runtime audit needs a separately reviewed plan and its
own environment evidence. A status of `NOT_RUN` or a clean static scan is not a
complete project audit.

To display individual tests in Graph Ops, run your suite with a JUnit report at
`.factory/test-reports/pytest.xml` (for example,
`python -m pytest --junitxml=.factory/test-reports/pytest.xml`). The local
Studio reads the report and labels its candidate binding `UNBOUND`; it does
not infer that those results still apply after source changes.

The prior snapshot's [repository self-audit receipt](evidence/self-audit/quality-reassessment-2026-10-04.json)
records **A (97.9/100)** and 1,055/1,085 functions attributed to test intent
(97.24%). That static measurement applies to its recorded source digest;
it is not a grade for later edits, runtime coverage, or certification.

ForgeLine 0.10.8 computes Python complexity for public module functions and
public class methods in its recorded `metrics.scope.code_files`; names starting
with `_` are excluded. Its AST metric counts branches, boolean alternatives,
exception handlers, `with`, and assertions. Ruff C901 uses a different McCabe
metric and also checks private functions. CI therefore runs
`python -m ruff check --select C901 factoryline tests` separately at limit 10.
The ForgeLine maximum must not be read as the maximum of every Python function.
CI also checks action and reusable workflow references for immutable commit
pins; the generic workflow evidence validator alone does not inspect those refs.
<!-- mcp-name: io.github.zrk222/code-factory -->

## Release controls

Candidate preflight requires release-cadence admission and strict architecture
health. Protected main requires CI and a separate specialty AI source review;
the coordinator records that assessment, separately from test evidence. It is
not a second human approval. Provider publication and marketplace approval are
separate outcomes. See [release channels](docs/RELEASE_CHANNELS.md).

Architecture health checks growth budgets. ForgeLine's repository inventory
and feature QA are separate checks. The [current gap review](docs/AUTONOMOUS_OPS_EDITOR_PLAN.md)
records how the published ForgeLine 0.10.7 graded this source F/70.7 while
parser-corrected ForgeLine 0.10.8 grades it A/95.1. CF 0.47.0 requires 0.10.8
and checks real MJS, TS, and TSX feature QA during `factory doctor --strict`.
Static signals are neither executed coverage nor a security certification.

## More detail

- [Engineering review workflow](docs/PROOF_REVIEW_WORKFLOW.md)
- [GitHub Proof Review](docs/GITHUB_PROOF_REVIEW.md)
- [Commercial availability and limits](docs/COMMERCIAL_PACKAGING.md)
- [Audit condition inventory](docs/AUDIT_CONDITION_INVENTORY.md)
- [Runtime assurance limits](docs/RUNTIME_ASSURANCE.md)
- [Release channels and publication evidence](docs/RELEASE_CHANNELS.md)
- [Changelog](CHANGELOG.md)
- [Documentation index](docs/DOCUMENTATION_INDEX.json)
