diff --git a/docs/maintainers/experimental-0.4.3-announcement.md b/docs/maintainers/experimental-0.4.3-announcement.md index 32ba6b9..d996e5e 100644 --- a/docs/maintainers/experimental-0.4.3-announcement.md +++ b/docs/maintainers/experimental-0.4.3-announcement.md @@ -21,6 +21,9 @@ Review the [0.4.3 changelog](https://github.com/codeacme17/launchrally/blob/v0.4 and [external verification record](https://github.com/codeacme17/launchrally/blob/v0.4.3/docs/maintainers/experimental-0.4.3-p1-evidence.md) before adoption. +The [prepublication checks](https://github.com/codeacme17/launchrally/blob/v0.4.3/docs/maintainers/experimental-0.4.3-prepublication.md) +record the assessed candidate and publisher controls separately from public verification. + ## Resolved issues - [#187 — Style the complete Architect Human Mode decision flow](https://github.com/codeacme17/launchrally/issues/187) @@ -36,7 +39,9 @@ before adoption. - [#209 — Complete remaining Phase 1 Human Mode flows](https://github.com/codeacme17/launchrally/pull/209) - [#211 — Prepare Phase 1 Experimental 0.4.3](https://github.com/codeacme17/launchrally/pull/211) - [#212 — Promote Phase 1 Experimental 0.4.3](https://github.com/codeacme17/launchrally/pull/212) +- [#213 — Refresh P1 release assessment for 0.4.3](https://github.com/codeacme17/launchrally/pull/213) +- [#214 — Complete 0.4.3 release inventory and prepublication evidence](https://github.com/codeacme17/launchrally/pull/214) ## Contributors -- [@codeacme17](https://github.com/codeacme17) — [#206](https://github.com/codeacme17/launchrally/pull/206), [#207](https://github.com/codeacme17/launchrally/pull/207), [#208](https://github.com/codeacme17/launchrally/pull/208), [#209](https://github.com/codeacme17/launchrally/pull/209), [#211](https://github.com/codeacme17/launchrally/pull/211), [#212](https://github.com/codeacme17/launchrally/pull/212) +- [@codeacme17](https://github.com/codeacme17) — [#206](https://github.com/codeacme17/launchrally/pull/206), [#207](https://github.com/codeacme17/launchrally/pull/207), [#208](https://github.com/codeacme17/launchrally/pull/208), [#209](https://github.com/codeacme17/launchrally/pull/209), [#211](https://github.com/codeacme17/launchrally/pull/211), [#212](https://github.com/codeacme17/launchrally/pull/212), [#213](https://github.com/codeacme17/launchrally/pull/213), [#214](https://github.com/codeacme17/launchrally/pull/214) diff --git a/docs/maintainers/experimental-0.4.3-prepublication.md b/docs/maintainers/experimental-0.4.3-prepublication.md new file mode 100644 index 0000000..08699e9 --- /dev/null +++ b/docs/maintainers/experimental-0.4.3-prepublication.md @@ -0,0 +1,75 @@ +# Phase 1 Experimental 0.4.3 prepublication checks + +Assessment date: 2026-09-07 UTC. + +This record covers checks performed before publishing the 0.4.3 candidate. +It does not establish public availability, independent external verification, +P1 Validated status, or Stable-promotion approval. + +## Candidate identity + +- Version: `0.4.3` across all five packages. +- Candidate manifest: `release/p1-release-candidate.json`. +- Assessed correction commit: `08907b8c21d0f21a5f022b4740271dd153943583`. +- Dev integration commit: `4f5b5a033899e3ee9323e1c087df08e8d31955d6`. +- Correction: refresh the supply-chain assessment from August 23 to September 7. +- The correction changes no candidate package digest. +- Release channel: `experimental`; preserved Stable channel: `latest` at `0.3.2`. + +The final release tag must identify the approved main promotion commit. +Neither commit above is a substitute for that final main identity. + +## npm identity and publisher controls + +Authenticated package-access checks confirmed write access to every package. +All five `npm trust list` checks returned the following exact configuration: + +| Package | Provider | Repository | Workflow | Environment | +| --- | --- | --- | --- | --- | +| `@launchrally/contracts` | GitHub | `codeacme17/launchrally` | `release.yml` | `npm` | +| `@launchrally/core` | GitHub | `codeacme17/launchrally` | `release.yml` | `npm` | +| `@launchrally/cli` | GitHub | `codeacme17/launchrally` | `release.yml` | `npm` | +| `@launchrally/codex-plugin` | GitHub | `codeacme17/launchrally` | `release.yml` | `npm` | +| `@launchrally/claude-plugin` | GitHub | `codeacme17/launchrally` | `release.yml` | `npm` | + +Each publisher allows `publish` and `stage publish`. The release workflow uses +the approved direct publication path; no publisher configuration was changed. +The GitHub `npm` environment requires deployment review and permits `v*.*.*` +tags. An active tag ruleset protects `refs/tags/v*.*.*`. + +At assessment time all five public `experimental` tags resolved to `0.4.2`, +and all five `latest` tags resolved to `0.3.2`. + +## Verification results + +| Check | Result | +| --- | --- | +| Locked dependency installation with scripts disabled | Passed | +| Build and generated Skill synchronization | Passed; no generated diff | +| Supply-chain test suite | 68 passed, 0 failed | +| Full test suite after the assessment correction | 849 passed, 0 failed, 3 existing TODOs | +| Exact packed-artifact journeys within the full suite | Passed | +| Acceptance traceability | 25 P0 requirements, 39 P1 requirements, 17 release gates validated | +| P0 governance | Passed | +| P1 publication readiness | 39 requirements and 5 mandatory gates validated | +| Tagged release validation for `v0.4.3` | Passed on the assessment date | +| Candidate digest verification | All five npm pack digests match the committed manifest | +| Independent standards and specification review of the correction | No findings on either axis | +| Correction PR CI | All nine executed jobs passed; branch-policy job skipped | + +The separate optional preflight fan-out was declined by the maintainer. +Same-day tagged-release validation must be repeated if publication moves to +another UTC date; this record does not extend the assessment's validity. + +## Public references and remaining gates + +- [Assessment correction PR #213](https://github.com/codeacme17/launchrally/pull/213). +- [Correction CI](https://github.com/codeacme17/launchrally/actions/runs/34081920547). +- [Main promotion PR #212](https://github.com/codeacme17/launchrally/pull/212). +- [Release tracker #210](https://github.com/codeacme17/launchrally/issues/210). + +Main promotion, protected annotated-tag publication, public digest/provenance +smoke, and the published-artifact Human Mode checks required by #187 remain +separate gates. Independent CLI, Codex, and Claude external verification must +be recorded through the existing signed-result procedure after publication. +No public-release or external-verification gate is marked complete here.