Skip to content

Harden v0.2.0 source candidate readiness - #86

Merged
jacklv-coder merged 1 commit into
mainfrom
codex/v0.2.0-source-candidate-readiness
Aug 4, 2026
Merged

Harden v0.2.0 source candidate readiness#86
jacklv-coder merged 1 commit into
mainfrom
codex/v0.2.0-source-candidate-readiness

Conversation

@jacklv-coder

Copy link
Copy Markdown
Owner

Summary

  • fail closed unless the only unsatisfied source gate is source-release-authorized
  • emit atomic JSON verification reports with commit, archive digest, file counts, blockers, and authorization status
  • retain JSON reports in candidate and trusted tag workflows without uploading source tar, RootFS, App, or binary artifacts
  • document the source candidate boundary in Chinese and English

Validation

  • ruby Tests/Scripts/SourceReleaseVerificationTests.rb — 19 runs, 80 assertions
  • ruby Tests/Scripts/ReleaseComplianceTests.rb — 71 runs, 635 assertions
  • ruby Scripts/generate-release-compliance.rb --check
  • ./Scripts/check-docs.sh
  • workflow YAML parse, Ruby syntax, and git diff --check
  • Codex CR: no findings, patch correct, confidence 0.9
  • committed-HEAD candidate report: candidate ready, exact blocker source-release-authorized, no RootFS/runtime artifact, no retained archive path

Release boundary

This PR does not create a tag or GitHub Release. It does not authorize or publish a RootFS, App, IPA, XCFramework, source tar, or binary SDK.

@jacklv-coder
jacklv-coder marked this pull request as ready for review August 4, 2026 01:26
@jacklv-coder
jacklv-coder merged commit 8d7a4ce into main Aug 4, 2026
7 checks passed
@jacklv-coder
jacklv-coder deleted the codex/v0.2.0-source-candidate-readiness branch August 4, 2026 01:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant