Public documentation v0.1.0

Changelog

Public changelog for Software Factory profile distributions.

0.1.0 — Initial public publication

Software Factory v0.1.0 publishes the initial public source monorepo and generated Hermes profile repositories.

Added

Public source repository, generated installable PM/builder/orchestrator/reviewer/publisher/docs profile repositories, MPL-2.0 licensing, public install and upgrade documentation, docs deployment target contract documentation, profile matrix and role-boundary documentation, and public/private boundary and security notes.

Conditional disposable profile validation

Added public guidance that keeps static reviewer checks as the default for low-risk docs/comment-only/typo changes and requires disposable test-profile validation for behavior-risk triggers or explicit human request. The documented chain uses random-suffix disposable profiles, focused acceptance, a maximum of two remediation iterations, reviewer/evidence gating, cleanup or explicit retention, and public-safe precedent lessons.

Builder source-update workflow

Added public guidance for Builder source-update work: PM Source Map as scope authority, canonical repository clone or fetch into the workspace, topic branches, source-controlled edits only, installed profile directories treated as deployment output, scoped mutation only when authorized, and complete evidence for reviewer and publisher gates.

PM Source Map requirements

Added public guidance requiring PM-created profile/source-update handoffs to include canonical monorepo and affected source paths, generated or installable role repositories, runtime verification targets only, topic-branch expectations, publisher/submodule follow-through, reviewer verification expectations, and disposable test-profile validation decision and rationale.

Profile-managed project-specific skills

Added public guidance distinguishing reusable published/shared skills from local profile-managed skills for project-specific instructions, examples, checklists, routing notes, customer or tenant conventions, and other scoped guidance. Promotion to shared skills requires generalized content plus the normal source-update, review, and publication gates.

Docs deployment target contract

Documented that distribution.yaml env_requires declares expected environment variables, .env is user-owned and not overwritten by distribution updates, install guidance may show non-secret examples, PM hands off deployed-docs work only when a target exists, and docs profiles publish only to the explicit or SOFTWARE_FACTORY_DOCS_SPRITE_NAME target.

Verification

Remote public repositories, default branches, tags, releases, licenses, and README install contracts were independently verified. Final public-safety review found no blocking exposure of credentials, private workspace paths, private sprite URLs, local state, or internal task identifiers in the approved public outputs.

Known limitations

Branch protection and mandatory PR-review settings are deferred for this initial publication. Repository descriptions and topics may be unset until a later repository-settings pass. Generated profile repositories are artifacts; future changes should flow from the source monorepo.