Skip to content

[B1] Freeze exact-SHA and immutable-evidence release contract #1187

Description

@SisyphusZheng

Part of #1155 and #1192. Target: v0.44.0-beta.3.

Objective

Complete publication authorization and release hardening after framework, UI, and website architecture stabilizes and before RC.

Deliverables

  • Require machine-readable unanimous implementer, fresh release-verifier, and thinker GO evidence bound to version, repository, workflow, authoritative PR CI run, and exact candidate SHA
  • Reject absent, malformed, stale, mismatched, weakened, non-unanimous, or unsupported closure evidence
  • Configure npm Trusted Publishing/OIDC and remove long-lived token/.npmrc publication paths
  • Finalize dev/main/release rulesets, required checks, bypass policy, and publication provenance
  • Read back effective rules and perform safe negative validation

Current work

PR #1191 is a green, unmerged implementation of the first closure-evidence slice. Preserve it for Beta.3 review; it does not block Alpha and must not be merged merely because its earlier Alpha.0 CI passed.

Boundary

The separate minimal Alpha.0 branch-safety issue #1193 owns only concurrent-development protection. Alpha work does not perform publication closure.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P0governanceRepository governance and policy ownershipreleasev0.44v0.44 compiled OpenElement architecture train

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions