Skip to content

PHCT v1.9.0-rc.1

Pre-release
Pre-release

Choose a tag to compare

@crypticpy crypticpy released this 22 Aug 19:23
4b02b7b

PHCT v1.9.0-rc.1

Warning

Superseded by the v1.9.0-rc.2 remediation. The first real BCHC run resolved this tag, preserved
all 116 protected files, regenerated the deployment, passed npm run verify, and retained its
preview/checksum artifact. GitHub then refused the update-branch push because the built-in
Actions token cannot update .github/workflows. Do not use this candidate for a downstream
merge; the immutable tag remains as release evidence.

PHCT v1.9.0-rc.1 is the audited release candidate for wider-demo validation. It is not the stable release or a BCHC organizational handoff.

  • Full commit: 4b02b7b19a2dc793d313d37da49acff66811e691
  • Rollback point: v1.8.1

Change summary

  • Adds the protected, ownership-aware PHCT-to-deployment updater and immutable version lock.
  • Adds reproducible doctor/verify commands, complete preset and module builds, coverage, CodeQL, supply-chain, license, SBOM, accessibility, Lighthouse, link, and scale gates.
  • Adds the real-Chrome supported-scale interaction budget and final search/filter performance fixes.
  • Adds maintainer, support, incident, rollback, backup, and downstream-update documentation.

Security and compatibility

  • Exact npm and Bundler advisory audits, CodeQL, secret scanning, license policy, expiring security exceptions, and CycloneDX evidence pass on this tree.
  • The tested support ceiling is 100 entries. The 500- and 1,000-entry fixtures are characterization evidence, not a support claim.
  • No BCHC identity, governance, schema, content, media, naming, or demo configuration should be copied from PHCT. The updater snapshots and verifies these protected paths byte-for-byte.

Migration actions

  • Do not hand-copy this release into a deployment.
  • In BCHC, run Actions → Update from PHCT with release v1.9.0-rc.1.
  • Review generated-file changes, protected-path checksum evidence, the preview artifact, and every dispatched check before merging any downstream update.

Generated files

The downstream workflow regenerates declared generated outputs using the candidate generator after reconciling template-owned files. Those generated changes remain reviewable in the downstream pull request.

Rollback

Before a downstream merge, close the candidate update PR and retain the existing v1.7.0 lock. If an update is later merged, revert its merge commit through a normal reviewed PR; never rewrite main or move this tag.

Evidence