Changed
-
Aligned current source with the supported Base 1.9.0, base-cli 0.4.3 and
base-bash-libs 2.1.0 input contract, with exact macOS/Ubuntu CI revisions and
live final-candidate evidence binding outside the tracked tree. -
Added disposable workspace selection, failure/skip, fail-fast and targeted
recovery scenarios, with separate stable and exact-candidate boundaries. -
Added isolated stable/candidate trust scenarios for denial, invalidation,
revocation, runtime verification and independent IDE consent, with explicit
Base v1.9 historical-revocation limitations. -
Made release BOM publication fail closed on incomplete participants, stale
pins, inconsistent platforms, and missing exact-commit hosted evidence. -
Corrected the public bootstrap to a checksum-verified, immutable source
installer, with explicit historical-release limitations and contract tests
against the actual downloaded script. -
Align the locked project dependency and source-compatibility CI checkout
with the releasedbase-cli0.4.3provider. -
Pinned the release installer to reviewed Base and base-demo revisions, made
checksum and existing-checkout validation fail closed, and added explicit
--dev/BASE_DEMO_DEV_MODEsupport for contributor workspaces. -
Added a pinned Vitest/React Testing Library demo-console suite covering
catalog loading, rendering, failure states, accessibility discovery, and
summary semantics, and made it part of local and hosted validation. -
Moved the current release identity into a top-of-page README version strip
with the matching release and release-policy links. -
Aligned the README badge strip with Base's tests, platform, and version
ordering.