Skip to content

release: complete final public showcase gates #95

Description

@Nobodyworld

Goal

Track the distinction between public developer-preview visibility, merged product readiness, formal release authorization, and production deployment safety.

Current classification

main: dcb8e283f8445dd76f215a98023197d8ed5acab3
repository visibility: public
classification: PUBLIC DEVELOPER PREVIEW — NOT PRODUCTION READY
public source visibility: complete
exact-SHA evidence workflow: merged through PR #120
public documentation alignment: ready PR #126, unmerged
formal release authorization: blocked
production deployment authorization: not authorized
release-candidate SHA: not selected

Switchboard is intended for localhost or controlled trusted networks. Untrusted multi-tenant and direct internet-facing deployment are unsupported.

Completed public-preview and execution work

Ready documentation change awaiting owner authorization

PR #126 aligns README.md, SECURITY_NOTES.md, docs/TASKLIST.md, and docs/reports/status.md with the merged execution/evidence baseline and removes stale permanent test/coverage/Mypy claims.

base: dcb8e283f8445dd76f215a98023197d8ed5acab3
head: fa9667dd04d95b5e7c899d4e16ce22d1790c7ae8
state: open, ready, mergeable, unmerged
Commitlint: 29991444435 — success
CI: 29991444455 — success

The complete matrix and connector review passed. Closed PRs #123 and #124 are superseded history and must not be merged.

PR #126 requires separate explicit owner authorization before squash merge.

Formal release technical gate — #104

No release candidate is selected yet. The recommended candidate includes PR #126 if the owner approves it.

After PR #126 is resolved:

  1. Record one immutable main SHA as the release candidate.
  2. Execute issue release: execute Linux symlink and final local validation #104 against exactly that SHA in a clean Linux-capable environment.
  3. Require the Linux symlink-containment regression to run without a skip.
  4. Run the complete clean-clone validation and Docker build.
  5. Update PUBLIC_RELEASE_AUDIT.md through one narrow draft PR.
  6. Verify owner-controlled repository protections and public security alerts.
  7. Create a release/tag only after explicit authorization.

The selected candidate must pass:

  • Linux symlink-containment regression without a skip.
  • Clean Python 3.11 dependency installation and pip check.
  • Pinned pre-commit, Ruff, Black, Mypy, and TODO validation.
  • Full pytest and strict browser suite.
  • Aggregate and module coverage thresholds.
  • Bandit and pip-audit.
  • Full-history Gitleaks.
  • Link validation.
  • Docker build or a precise documented blocker.
  • git diff --check and final clean worktree.
  • PUBLIC_RELEASE_AUDIT.md updated with exact executed evidence.

Active product development outside the release gate

Issue #122 / draft PR #125 implements the GitHub exact-PR request/result adapter from the current merged product baseline. Issue #121 follows with opt-in exact evidence reuse.

Neither #122 nor #121 is a formal-release requirement unless the owner explicitly adds it. Do not silently move the release candidate to include Phase 2 work.

Public security and repository settings

Owner-controlled checks still to verify:

  • Require pull requests before merging to main.
  • Require conversation resolution.
  • Block force pushes.
  • Block branch deletion.
  • Repository is squash-merge-only.
  • Add or verify required checks using actual public check names.
  • Enable or verify CodeQL Default Setup when available.
  • Review CodeQL, Dependabot, and secret-scanning alerts.
  • Confirm Dependabot security updates.
  • Confirm repository description, topics, license detection, and social preview.

Formal release authorization

Explicit non-authorization

Until every formal gate is completed and the owner records authorization:

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions