Skip to content

feat(release): deliver Phase 11 release engineering - #43

Merged
ZSeanYves merged 4 commits into
mainfrom
codex/phase-11-release-engineering
Aug 13, 2026
Merged

feat(release): deliver Phase 11 release engineering#43
ZSeanYves merged 4 commits into
mainfrom
codex/phase-11-release-engineering

Conversation

@ZSeanYves

Copy link
Copy Markdown
Collaborator

Summary

  • complete PR-110 through PR-114: Mooncakes metadata/API docs, MoonX staging, policy tiers, cross-platform candidates, supply-chain evidence, and upgrade/rollback rehearsal
  • add deterministic Native/wasm1 candidate artifacts with checksums, CycloneDX 1.5 SBOM, SLSA v1 provenance, exact dependency/license audit, OIDC attestations, and seven-class tamper rejection
  • extend CI with Linux/macOS/Windows candidate build and verification, with all Actions pinned to immutable commits

Verification

  • moon info && moon fmt
  • ./tools/check.sh
  • 303/303 Native tests
  • 298/298 wasm1 tests
  • official CycloneDX 1.5 JSON schema validation
  • shellcheck, Python compile, TOML/YAML parse, immutable Action SHA verification

Publication boundary

This PR prepares, validates, temporarily uploads, and attests release candidates only. It contains no moon publish, tag creation/push, GitHub Release creation, publishing credentials, or repository write permission. Formal publication is explicitly reserved for the maintainer.

Exit process

After first remote CI passes, Phase 11 receives the required independent second audit. Any findings will be remediated and CI rerun before merge. The manual candidate workflow will be exercised without publishing after the reviewed implementation reaches main.

@ZSeanYves
ZSeanYves merged commit b4b318c into main Aug 13, 2026
4 checks passed
@ZSeanYves
ZSeanYves deleted the codex/phase-11-release-engineering branch August 13, 2026 05:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant