Release v0.2.0
The repository maintainer's direction after #266: release governance (semver labeling, evidence-based approval, tiered assurance, when checksums/provenance/SBOM actually matter, canary-before-promotion, recovery disposition) is real, reusable release-engineering knowledge — it was just wrongly built as infrastructure specific to distributing this repo's own markdown. This extracts the genuine methodology into a real, product- and language-independent profile any Cratis repo publishing compiled artifacts (NuGet, npm, containers) can install.
Deliberately additive: the underlying S10 assurance-lane data model (distribution/s10-release-policy.json, assurance-lanes.json, etc.) is investigated in depth but not touched — it turned out to be load-bearing for the basic validation lane every PR goes through and for the still-live release-passive-previews.yml npm publish, not dead code as assumed. A full dependency map is in this PR's implementation notes for whoever takes on retiring the genuinely-dead pieces next.
Added
skills/cratis-governed-release-methodology/SKILL.md: real, actionable release-engineering methodology — picking an assurance tier before picking checks, what each supply-chain receipt (checksums/provenance/SBOM/canary/recovery) actually proves and for which artifact types, the eight-rung evidence ladder, the ten lifecycle phases a real install cycle must cover, semver release-intent labeling, and a non-circular release-path structure where no step can vouch for itselfprofiles/public/public-methodology-governed-releases.json: a standalone leaf profile (composes nothing, is composed by nothing — same deliberate decoupling as the language profiles) so selecting it never implies a specific product or language- A resolver regression spec asserting the profile pulls in exactly its one skill and nothing else
Changed
catalog/v2/repository-inventory.jsonand related generated catalogs regenerated for the new skill and source (46 sources, up from 45)distribution/public-evaluation-eligibility.json: the new skill is explicitly excluded from marketplace eligibility pending effect assessment — the same disposition an existing skill (cratis-chronicle-reactor) already has — not force-approved