Skip to content

docs: define the UrbanPy 0.3 production-readiness program - #61

Open
Claudio9701 wants to merge 2 commits into
masterfrom
roadmap/urbanpy-0.3
Open

docs: define the UrbanPy 0.3 production-readiness program#61
Claudio9701 wants to merge 2 commits into
masterfrom
roadmap/urbanpy-0.3

Conversation

@Claudio9701

Copy link
Copy Markdown
Collaborator

Summary

  • documents the audited current state of UrbanPy
  • defines the W0-W10 production-readiness roadmap and release gates
  • provides dedicated OSRM/Geofabrik and Pydantic plans
  • reconciles existing issues and PRs with the 0.3 program
  • records SonarQube as a mandatory EL-BID requirement

Review focus

Please review scope, ownership assumptions, release gates, and compatibility policy. Implementation will proceed in dependent stacked PRs.

Validation

  • git diff --check
  • local Markdown cross-links verified
  • current GitHub checks, ruleset, Dependabot alerts, issues, and official upstream documentation audited

This PR contains planning documentation only.

@Claudio9701

Copy link
Copy Markdown
Collaborator Author

Autonomous implementation handoff (2026-08-10)\n\nThe complete reviewable stack is now: #61#74#76#78#80#82#84#85#87#89#91#94#96#98#103. Review and merge in that dependency order; each PR names its immediate base.\n\nImplemented across the stack: uv/PEP 621 and locked Python 3.11–3.14 development; hermetic CI and Trunk; mandatory SonarQube; agent governance/CODEOWNERS; strict Pydantic boundaries; canonical official Geofabrik catalog resolution; cross-platform Python OSRM lifecycle and client; H3/OSMnx/HDX/CRS regressions; community/security/governance/release docs; OIDC trusted publishing and immutable artifacts/SBOM/provenance; machine-enforced dependency license evidence; scheduled provider/Docker contracts; explicit public exports; Overpass BoundingBox validation; OSRM lifecycle/error-path coverage; MapLibre plotting; and versioned advisory CodeRabbit policy.\n\nCurrent top-branch evidence: 88 hermetic tests pass (4 scheduled/manual tests deselected); branch-aware total coverage 72%; Sonar new-code coverage 86.9% against 80% and duplication 0%; Ruff, mypy boundary scope, Trunk, docs, package, dependency audit, license evidence, and Python 3.11–3.14 jobs pass. No release/tag was created.\n\nExternal/admin blockers are explicit and must not be bypassed: #101 authorized Sonar review/remediation (13 findings + security hotspots); #99 FOSSA 95-finding legal reconciliation and legacy PyPI token revocation/audit confirmation; #102 protected TestPyPI/PyPI environments, trusted publishers, and tag protection; #100 optional CodeRabbit GitHub App permission/data-governance approval; #104 first provider/Docker workflow dispatch after contracts.yml reaches the default branch. GitHub Project creation remains unavailable to the current token, so native sub-issue hierarchy under #62#72 is the authoritative project structure.

@Claudio9701

Copy link
Copy Markdown
Collaborator Author

Final stack update: append #106 after #103. PR #106 contains the dated release-readiness matrix, complete 0.3 changelog/README summary, and explicit py.typed alpha deferral. The merge order now ends #98 → #103 → #106.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant