Skip to content

Sentinel Shield v2.0.0 — Engine-Only Production Release

Choose a tag to compare

@bogdaniel bogdaniel released this 09 Jul 16:56
· 388 commits to master since this release
13be630

Sentinel Shield v2.0.0 — Engine-Only Production Release

Sentinel Shield v2.0.0 is an engine-only production release.

The Sentinel Shield engine, installer, recovery system, security controls,
release-governance tooling, PHP-library consumer harnesses, Node/React
consumer harnesses, and black-box adopter validation have passed the
published engine-only production gates.

Laravel and Symfony profiles have not been independently validated in
live consumer repositories. Framework-validated release and full-platform
GA are not claimed by this release.

Release source

  • Engine commit (CI-proven): 13be630a64d044e0ffca8850e3424c2f0799aebf
  • Scope: engine-only, stage ga
  • Tag target: engine commit (source == release; the tag targets the CI-proven engine commit)
  • v2.0.0-rc.1 was published 2026-07-08 from the same engine commit; the RC→GA source is
    unchanged (evidence/docs metadata only). See known-limitations for the soak waiver.

Default-branch CI evidence (event=push, branch=master, head=13be630)

All required release workflows completed successfully at the release source:

Workflow Run ID
ci-self-test 28827885695
ci-pipeline 28827885654
ci-security 28827885649
ci-workflow-lint 28827885684
ci-adopter-validation 28827885656
ci-compatibility 28827885655
ci-production-readiness 28827885648

(Also green on the source: ci-php, ci-node, ci-docker, ci-codeql,
security-incident-validation.)

What was validated

  • Static/lint: sh -n, shellcheck -S error, actionlint, zizmor — all clean.
  • Self-test: full all suite exit 0; production-readiness group PASS.
  • Artifacts: 16 CI artifacts downloaded, digest-verified, owned, unexpired (0 failures).
  • Release manifest: reproducible; self-consistency verified (body sha256 b6b3d543…).
  • Security posture: live ci-security acceptance — decision accepted, 0 critical,
    0 high, 0 blocking findings, 0 violations.
  • Compatibility: matrix complete; covered os, arch, shell, git, jq; nothing missing.
  • Adopter usability: scorecard pass, 7 offline sessions, all 8 blocking criteria pass.
  • Lifecycle: upgrade validation pass; rollback validation pass (0 failures each).

Validation terminology (used precisely)

  • engine-tested
  • standalone-consumer-tested
  • black-box-adopter-harness-tested

This release does not claim production-adopted, framework-validated, or
full-platform-ready.

Known limitations

See docs/v2.0.0-known-limitations.md.