diff --git a/PUBLIC-SNAPSHOT.json b/PUBLIC-SNAPSHOT.json index 6347912..f6af1e1 100644 --- a/PUBLIC-SNAPSHOT.json +++ b/PUBLIC-SNAPSHOT.json @@ -1 +1 @@ -{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":128,"allowlist_sha256":"4f067a37de73082f3534ebfeb5a73b53b37ace9e4c6b21956405e2fefacbeb38","manifest_sha256":"90192f06c4ae7182834e5c1bc6890568698635b71530cb9593fb946ea2e6b3f4"} +{"schema_version":2,"project":"sandwich-hime","export_policy":"exact-allowlist-v1","export_mode":"release","file_count":128,"allowlist_sha256":"4f067a37de73082f3534ebfeb5a73b53b37ace9e4c6b21956405e2fefacbeb38","manifest_sha256":"ca9cc15ace466e3086e24f8d8aa225fdaf12ce5d77348f7daff71611be02e787"} diff --git a/PUBLIC-SNAPSHOT.sha256 b/PUBLIC-SNAPSHOT.sha256 index 5933c14..1d7799f 100644 --- a/PUBLIC-SNAPSHOT.sha256 +++ b/PUBLIC-SNAPSHOT.sha256 @@ -15,7 +15,7 @@ b6aa08e5ccaec3c5dccdc19d7cd7f54a70adae4d57966263c7aa353c7ba70e08 ./MAINTAINERS. 6638db2f1fba831c79de835ce95c847a5b36c5b5c693b99a28655b2d096cc440 ./OUTPUT_EXCEPTION.md 007ffcafd32b50ed6ba4241ced90ef2e22a79cc7ad10f768e9e1f9560453b41f ./README.md fd2f45bb683d804afc127414e88e6b8ab75754af0596efe58fcb4ca3f4a55b9f ./RELEASE.md -953e226cb5179c17b1b2ce091653cbdaf83e92dd4913cc3b34a3cc893843496f ./ROADMAP.md +75bb0f85372cc298bfc316a2a5b53e03d17c7a0f7cbbfcd8daecc8ad98b6972a ./ROADMAP.md 44a895f8a738d21121379a5a417445ecc953f2ebfb64a7e575543769f642d1b6 ./SECURITY.md d566b8b27777cb33209602df81d654a94072ad875440c089ac41764a349b6c17 ./SPEC.md 8906258cc7aaadf03bd7e84b69efc3be6a01d1c392b0711fbcee9abf4863b25b ./TRADEMARKS.md diff --git a/ROADMAP.md b/ROADMAP.md index 6a68824..8678443 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -66,13 +66,17 @@ it is not a production-stability promise. ## Final public launch -Final-release preparation is active. Preserve the existing reviewed public -history and append allowlisted updates; keep operator and archival records -outside the public snapshot. Completed native and signing evidence remains -bound to its exact candidate, not automatically to a later documentation or -export-tool update. Final tags and artifacts have not been published. +Version 1.0.0 was published on September 9, 2026 from public commit +`d978994b274db223370ad15c8291230e1b60d9ca`. The signed runtime tag preceded the +signed compiler tag; both are immutable. The +[canonical release](https://gitea.speelman.ca/gamertan/sandwich-hime/releases/tag/v1.0.0) +provides the notarized Apple Silicon DMG and Linux/amd64 archive with checksums. +All four maintained native/toolchain lanes and final preflight passed. Fresh +runtime-first direct and public-proxy/checksum-database installs passed on +macOS/arm64 and Linux/amd64. Evidence remains bound to that source, not to later +documentation commits. Private development and archival history stays private. -Use [RELEASE.md](RELEASE.md) for the remaining final-publication requirements. +Use [RELEASE.md](RELEASE.md) for subsequent immutable releases. Passing CI is evidence for that review, not an automatic publication decision. - [x] Finalize the maintainer-approved individual [contribution agreement](CLA.md) @@ -88,19 +92,20 @@ Passing CI is evidence for that review, not an automatic publication decision. primary project identity and Hime-san as its tool name. This is acceptance of the documented name-review limitations, not formal trademark clearance, completed similarity analysis or a registration requirement. -- [ ] Complete final security/signing readiness review. Distinguish successful +- [x] Complete final security/signing readiness review. Distinguish successful signing from the explicitly deferred recovery drills below. - [x] Verify `gamertan.com` vanity metadata and documented RC installs using clean - direct-fetch and public-proxy caches. Final-version installs remain post-tag - checks; an independent Mac installation is an accepted follow-up below. -- [ ] Confirm the sanitized public Gitea source contains no private paths, + direct-fetch and public-proxy caches. Final-version installs also passed after + publication on both maintained platforms; an independent Mac installation + remains an accepted follow-up below. +- [x] Confirm the sanitized public Gitea source contains no private paths, identifiers, history, or unsupported claims. - [x] Publish signed RC.1 artifacts on Linux/amd64 and Darwin/arm64. - [x] Record the maintainer's v1 acceptance of existing live dogfooding despite missing timed checkpoint notes. This is an explicit assurance-gap acceptance, not reconstructed reviews or a claim of measured error-free operation. Missing notes alone do not restart the observation period or block release. -- [ ] Publish `sando/v1.0.0`, then `v1.0.0`, without moving either tag. +- [x] Publish `sando/v1.0.0`, then `v1.0.0`, without moving either tag. ## Accepted assurance follow-ups