Software Build Assurance Kit v1.0.2 — GA
The GA release of the Software Build Assurance Kit.
The 1.0 bar is an integrity bar, not a feature bar: five decision-record properties, each demonstrated absent-of-defect by execution — three-site symlink confinement, parsed-wiredness adoption, a zero-silent-skip release verification lane, POSIX hook liveness in authoritative CI, and byte-safe settings merge with proven restore. Independently verified twice; CI green on the pinned Node 24.
Install: download sbak-v1.0.2-starter.zip, verify (sha256sum -c against the sidecar, or gh attestation verify), unzip into your project, run the adopt step — full steps in sbak/QUICKSTART.md §1.
sha256: bc8745186abcc95417315dd4e421142b8b761e3ffd9003df58133286fcda6826
(v1.0.1 was published without its attestation and stands superseded; v1.0.0 was tagged but never published — its manifest lacked one file, caught by this repository's own CI. Read RELEASE-NOTES.md for what this kit claims, what it does not, and the honest costs — including the trial where our own framework lost on price for small solo builds.)