Skip to content

Release v0.2.0

Choose a tag to compare

@github-actions github-actions released this 06 Sep 20:54
c32f407

The repository maintainer's direction after #266: release governance (semver labeling, evidence-based approval, tiered assurance, when checksums/provenance/SBOM actually matter, canary-before-promotion, recovery disposition) is real, reusable release-engineering knowledge — it was just wrongly built as infrastructure specific to distributing this repo's own markdown. This extracts the genuine methodology into a real, product- and language-independent profile any Cratis repo publishing compiled artifacts (NuGet, npm, containers) can install.

Deliberately additive: the underlying S10 assurance-lane data model (distribution/s10-release-policy.json, assurance-lanes.json, etc.) is investigated in depth but not touched — it turned out to be load-bearing for the basic validation lane every PR goes through and for the still-live release-passive-previews.yml npm publish, not dead code as assumed. A full dependency map is in this PR's implementation notes for whoever takes on retiring the genuinely-dead pieces next.

Added

  • skills/cratis-governed-release-methodology/SKILL.md: real, actionable release-engineering methodology — picking an assurance tier before picking checks, what each supply-chain receipt (checksums/provenance/SBOM/canary/recovery) actually proves and for which artifact types, the eight-rung evidence ladder, the ten lifecycle phases a real install cycle must cover, semver release-intent labeling, and a non-circular release-path structure where no step can vouch for itself
  • profiles/public/public-methodology-governed-releases.json: a standalone leaf profile (composes nothing, is composed by nothing — same deliberate decoupling as the language profiles) so selecting it never implies a specific product or language
  • A resolver regression spec asserting the profile pulls in exactly its one skill and nothing else

Changed

  • catalog/v2/repository-inventory.json and related generated catalogs regenerated for the new skill and source (46 sources, up from 45)
  • distribution/public-evaluation-eligibility.json: the new skill is explicitly excluded from marketplace eligibility pending effect assessment — the same disposition an existing skill (cratis-chronicle-reactor) already has — not force-approved