Skip to content

chore: prepare self-hosted v0.2.0 certification - #20

Merged
Lucenx9 merged 3 commits into
mainfrom
004-self-hosted-onboarding-v0.2.0-prep
Aug 15, 2026
Merged

chore: prepare self-hosted v0.2.0 certification#20
Lucenx9 merged 3 commits into
mainfrom
004-self-hosted-onboarding-v0.2.0-prep

Conversation

@Lucenx9

@Lucenx9 Lucenx9 commented Aug 15, 2026

Copy link
Copy Markdown
Owner

Summary

Prepares the normative, testable inputs needed for the external SkillWire Self-Hosted v0.2.0 certification ceremony without creating a tag, release, signature, or production asset.

This changeset intentionally leaves Feature 004 task T161 unchecked. T161 remains the external release gate that must be completed only after the required infrastructure, participants, signed assets, and immutable release identity exist.

Certification preparation

  • Aligns package version 0.2.0 with the canonical annotated tag identity self-hosted-v0.2.0.
  • Requires an annotated tag object, recursively peels it to the workflow commit, and requires that commit to be reachable from origin/main.
  • Runs the dependency-free tag gate before package installation or repository-code execution in certified release jobs.
  • Requires the Sigstore TrustedRoot media type application/vnd.dev.sigstore.trustedroot+json;version=0.1, matching the pinned Cosign 3.1.3 / sigstore-go 1.2.2 verifier.
  • Keeps Cosign bundles outside the signed release payload inventory, preventing circular manifest or bundle identities.
  • Requires exactly one normal bundle per architecture, constrains signer-overlap exceptions, and rejects duplicate, swapped, or cross-architecture bundles.
  • Adds a strict ten-participant moderated-usability evidence protocol: fixed cohort, no replacements/reruns/exclusions, bounded setup timing, and at least nine unassisted successes.
  • Defines the exact 12-cell support matrix across Ubuntu 24.04, Debian 12, and Debian 13; amd64 and arm64; rootful and rootless Docker.
  • Keeps matrix observations tied to one seven-asset release identity and does not pre-claim certification outcomes.

Safety and scope

  • No self-hosted-v0.2.0 tag or GitHub release is created by this PR.
  • No production asset is generated or signed.
  • The release workflow has no pull_request trigger and therefore cannot publish from the PR event.
  • Features 001–003 and the Feature 003 package identity are unchanged.
  • Feature 004 task T161 remains pending and unchecked.

Validation

  • Repository-certified Node.js 24.18.0 and pnpm 11.21.0.
  • Full bounded offline suite: 898 passed, 9 expected environment-gated skips.
  • Feature 004 aggregate: 400 passed, 8 expected environment-gated skips.
  • Release contracts: 35 passed.
  • Tag/workflow contracts: 12 passed.
  • Feature 003 activation suite: 98 passed; activation adapter: 65 passed.
  • Release reproducibility/security suite: 9 passed.
  • PostgreSQL migrations applied and rerun idempotently through migration 010.
  • Catalog, advisory, package-integrity, Compose, formatting, ESLint, strict typecheck, build, actionlint, secret scan, and git diff --check passed.

Remaining release gate

T161 is deliberately not completed here. It requires the real annotated release tag, immutable signed production assets, the complete 12-cell external matrix, the fixed ten-participant usability evidence, and the final recorded validation ceremony.

@Lucenx9
Lucenx9 marked this pull request as ready for review August 15, 2026 01:40
@Lucenx9
Lucenx9 merged commit ad5fced into main Aug 15, 2026
13 of 14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant