PHCT v1.9.0-rc.1
Pre-releasePHCT v1.9.0-rc.1
Warning
Superseded by the v1.9.0-rc.2 remediation. The first real BCHC run resolved this tag, preserved
all 116 protected files, regenerated the deployment, passed npm run verify, and retained its
preview/checksum artifact. GitHub then refused the update-branch push because the built-in
Actions token cannot update .github/workflows. Do not use this candidate for a downstream
merge; the immutable tag remains as release evidence.
PHCT v1.9.0-rc.1 is the audited release candidate for wider-demo validation. It is not the stable release or a BCHC organizational handoff.
- Full commit:
4b02b7b19a2dc793d313d37da49acff66811e691 - Rollback point:
v1.8.1
Change summary
- Adds the protected, ownership-aware PHCT-to-deployment updater and immutable version lock.
- Adds reproducible doctor/verify commands, complete preset and module builds, coverage, CodeQL, supply-chain, license, SBOM, accessibility, Lighthouse, link, and scale gates.
- Adds the real-Chrome supported-scale interaction budget and final search/filter performance fixes.
- Adds maintainer, support, incident, rollback, backup, and downstream-update documentation.
Security and compatibility
- Exact npm and Bundler advisory audits, CodeQL, secret scanning, license policy, expiring security exceptions, and CycloneDX evidence pass on this tree.
- The tested support ceiling is 100 entries. The 500- and 1,000-entry fixtures are characterization evidence, not a support claim.
- No BCHC identity, governance, schema, content, media, naming, or demo configuration should be copied from PHCT. The updater snapshots and verifies these protected paths byte-for-byte.
Migration actions
- Do not hand-copy this release into a deployment.
- In BCHC, run Actions → Update from PHCT with release
v1.9.0-rc.1. - Review generated-file changes, protected-path checksum evidence, the preview artifact, and every dispatched check before merging any downstream update.
Generated files
The downstream workflow regenerates declared generated outputs using the candidate generator after reconciling template-owned files. Those generated changes remain reviewable in the downstream pull request.
Rollback
Before a downstream merge, close the candidate update PR and retain the existing v1.7.0 lock. If an update is later merged, revert its merge commit through a normal reviewed PR; never rewrite main or move this tag.
Evidence
- Audit implementation
- Release-record correction
- Final merge supply chain
- Final merge performance
- Final merge browser quality
- Attached CycloneDX 1.5 SBOM SHA-256:
fa47d85d41d6cf199393cdf799578c13fcdfc74aac10b98b51cd262268f32bf3