Skip to content

Verify final v1.2.1 Candidate and publish #131

Description

@BrettKinny

This was generated by AI during triage.

Type: HITL

Parent

What to build

Verify the protected v1.2.1 Candidate and complete the automated publication decision. Physical amd64/arm64 and desktop-platform qualification are not release gates for v1.2.1.

Acceptance criteria

  • Record the final version, source SHA, multi-architecture digest, and links to the completed automated Evidence.
  • Confirm release.json, version file, MOTD, checked-out source ref/SHA, repository, and digest agree.
  • Verify every asset against SHA256SUMS, the checksum Sigstore bundle against the exact workflow/tag identity, and the image identity signature.
  • Confirm stable installers cannot discover the draft before approval and required assertion Evidence is complete.
  • Confirm the active release-tag ruleset rejects update/deletion and the peeled tag SHA equals the Candidate source SHA.
  • Approve the protected stable environment only after all automated gates pass, publishing without rebuilding.
  • Verify the immutable GitHub Release attestation plus GitHub and GHCR latest identities.
  • Rerun an older stable workflow or equivalent dry-run and confirm neither latest pointer can rewind.
  • Record an explicit promote/no-promote decision and follow-up defects here.

Blocked by

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestready-for-humanRequires human implementation or judgment

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions