docs: publish the v1 beta evidence
Publish the exact-candidate Windows and Linux results, signed-tag and clean-install status, provisional macOS boundary, and reliable runtime-first Beta 1 installation order. The post-publication verifier now cleans read-only module caches safely. This commit is an exact sanitized export from the private development record. Material drafting and review were assisted by OpenAI Codex; Cole Speelman reviewed the changes and accepts human responsibility. Signed-off-by: Cole Speelman <crspeelman@gmail.com>
This commit is contained in:
+2
-2
@@ -17,7 +17,7 @@ advisories, and release decisions.
|
||||
|
||||
| Version | Security status |
|
||||
| --- | --- |
|
||||
| `v1.0.0-beta.1` and `sando/v1.0.0-beta.1` | Current evaluation/classroom prerelease once published; best-effort security assessment and fixes; interfaces may change |
|
||||
| `v1.0.0-beta.1` and `sando/v1.0.0-beta.1` | Current published evaluation/classroom prerelease; best-effort security assessment and fixes; interfaces may change |
|
||||
| Public `main` | Development source; reports welcome, but no compatibility or production-support promise |
|
||||
| Older prereleases | Superseded when a newer prerelease or final version is published; reports are still triaged to determine affected versions |
|
||||
|
||||
@@ -133,7 +133,7 @@ an independent security audit, certification, or formal verification. Coverage
|
||||
percentages, passing scanners, and a clean vulnerability database result are
|
||||
evidence of specific checks—not proof that no vulnerability exists.
|
||||
|
||||
Beta 1 publication requires signed annotated source tags, but may precede the
|
||||
Beta 1 uses signed annotated source tags, but precedes the
|
||||
complete prebuilt-artifact and key-recovery system. Signed binaries, checksums,
|
||||
an SBOM, reproducible archives, and complete source/build provenance are
|
||||
release-candidate and final-v1 gates. Their absence from a source-only beta must
|
||||
|
||||
Reference in New Issue
Block a user