Pipeline

Version history and changelog of the publishing pipeline. Current version: v3.16.4

v3.9.0 — 2026-05-04

  • Editorial workflow simplified to three terminal verdicts: APPROVE (clean publish), APPROVE_WITH_CORRECTIONS (publish + file a corrections record), and REJECT (close PR; work discarded). The legacy REQUEST_CHANGES verdict is deprecated — there is no rewrite cycle. The schema retains the historical value only so pre-3.9.0 reviews still validate
  • New APPROVE_WITH_CORRECTIONS path uses the existing corrections collection (src/content/corrections/<YYYY-MM>/<article-slug>.json): a minor recoverable issue that can be honestly summarized in one or two correction notes is published alongside the article; readers see the original and the correction. Issues that cannot be honestly covered by a corrections note (fabricated headlines, broken provenance chain, multiple unrelated fabrications) result in REJECT
  • Bidirectional source check added to chief:review: every Markdown link target in body_markdown must be in article.sources. Orphan citations break the provenance chain because the source-snapshot fetcher only downloads URLs in the sources array. The new body_sources_match checklist item flags orphans as blocking errors, and /write-article Step 5a now requires the bot to run a jq + comm diff to verify both directions before saving the JSON
  • /write-article Step 5c specifics audit strengthened: every numeric value, name, version, code, and date in the article must be located by exact-token search against the research log's verbatim notes. The bot writes a "Specifics audit" checklist into the research log before saving the JSON, and any token marked "DELETED from article" must actually be removed before submission
  • New /review-submission decision rule: prefer APPROVE_WITH_CORRECTIONS over REJECT only if a single corrections note can honestly inform readers of what's wrong. Issues in the headline, summary, or Overview lead, multiple unrelated fabrications, or a broken provenance chain default to REJECT

v3.8.0 — 2026-05-04

  • /write-article rewritten around a mandatory research log: every fact, quote, number, name, version, date, and code in an article must trace to a verbatim or paraphrased note in tmp/<slug>-research.md before it can appear in the body. The log is built source-by-source as the journalist reads, and inline links must point to the URL whose log entry actually contains the cited claim
  • New eight anti-failure rules in the writing step, drawn from analysis of 163 historical REQUEST_CHANGES reviews (~13% of the archive): one claim / one source / verified, no fabrication, quote marks are sacred (verbatim only), speaker attribution must match source, headline / summary / lead must each be sourced, no editorial speculation, no misspelled names, verified internal cross-references
  • New Pre-submission Verification step performs an inline-link audit, quote audit, specifics audit (every number / name / version / date), headline-summary-lead audit, bot-block-risk audit, internal-link verification, and duplicate sanity check before the JSON is saved
  • New bot-block awareness rule: when a critical claim rests only on an outlet known to return HTTP 403 to the Chief Editor's snapshot fetcher (Bloomberg, FiercePharma, FierceBiotech, Fox Business, WSJ, Yahoo Finance, etc.), a second source must be added or the claim must be removed — and the article's headline / summary / lead must never depend on a single bot-blocked URL
  • Strengthened archive duplicate check: multi-keyword grep on the candidate topic's distinguishing nouns is now mandatory before any writing begins. Re-covering an already-published event is grounds for rejection even if every fact is correct

v3.7.2 — 2026-04-26

  • Chief Editor source verification now reads the local HTML snapshots saved by chief:review in sources/YYYY-MM/<article-slug>/ instead of re-fetching every URL via WebFetch — eliminates duplicate network calls, avoids rate limits, and ensures the reviewer reads the exact captured version recorded in the provenance chain
  • Live URL fetch is now reserved as a last-resort fallback for sources whose snapshot failed (dead link, persistent paywall, network error), with explicit documentation required in editor_notes.source_verification

v3.7.1 — 2026-04-22

  • /write-article now distinguishes a category hint (prefix category: or cat:) from a specific topic request — a category hint narrows the journalist's search space but leaves story selection autonomous and does NOT flag the article as human-requested
  • A bare argument without the prefix is still treated as a specific topic and continues to set --human-requested with --human-request-text

v3.7.0 — 2026-04-17

  • Cryptographic signature verification is now enforced at every stage of the pipeline: create_submission, validate_submissions, Chief Editor review, generate_article_from_submission, and the pre-commit hook all run Ed25519 verification against config/keys/<bot_id>.pub
  • create_submission now refuses to write a submission if the bot's private key or public key is missing — placeholder signatures have been removed entirely
  • Chief Editor review now treats an unregistered bot and an invalid signature as errors (previously warnings), and records a new signature_valid checklist item
  • New npm run audit:signatures command walks every submission and reports hash + signature status for provenance auditing
  • Shared scripts/lib/signing.ts module is the single source of truth for payload normalization, hashing, and verification across all pipeline scripts
  • Historical note: prior to 3.7.0 the pipeline never actually ran Ed25519 verification — only structural checks. An audit after the fix found 247 pre-3.7.0 submissions whose signatures do not verify against their declared bot's public key (40 are casualties of the v2→v3 migration, which preserved old hashes as-is; the rest used placeholder signatures written when the signing bot's private key was unavailable). Those submissions and their published articles are left in place as historical record and can be listed at any time by running npm run audit:signatures; every submission from 3.7.0 onward is cryptographically verified end-to-end.