Make protected release plans approval-bound - #11
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Product direction
Makes protected-mode safe release coordination the default product path:
patchlog release --dry-runas the universal immutable planner;mutation targets, publication content, and provider target;
preparefromfinalize;release direct;Transaction and security hardening
Distribution and trust loop
fxdv/homebrew-tapchannel;VERSIONworkaround.
Evidence
bash scripts/gate.sh: 8/8 checks green on Go 1.26.5;workaround required by this macOS host;
qualityruns green;https://github.com/fxdv/homebrew-tap/actions/runs/30016485477;
https://github.com/fxdv/patchlog-validation-ouroboros/pull/1, green
post-merge main CI
https://github.com/fxdv/patchlog-validation-ouroboros/actions/runs/30046698904,
and annotated
v6.3.0targeting the exact green commit;chore(release): prepare v0.2.1 with Patchlog patchlog-validation-vllm-metal#1, green
post-merge main CI
https://github.com/fxdv/patchlog-validation-vllm-metal/actions/runs/30046703150,
and annotated
v0.2.1targeting the exact green commit;were confined to public validation mirrors;
fxdv/demiurgevirtual-workspace version detection was rejected withoutmutation and is now an explicit 0.2.x limitation.
Proxy metrics remain diagnostic, never release gates. True coverage comes from
CI artifacts; dependency risk requires language-aware graphs; lead/cycle time
requires PR and deployment timestamps.
Operational rollout
protection.
qualityrun on the exact squash commit.preparefor patchv0.1.4, merge its one-file PR aftergreen CI, and wait for green main again.
finalizeplan for that exact maincommit.
SHA256SUMS,attestations, the GitHub release, and verify archive execution,
@v0.1.4,@latest, and Homebrew installation.