Publish the reviewed allowlisted snapshot whose exact binary completed maintenance deployment, rollback, and reactivation exercises for Gamertan and Sandwich Hime. Private-Source-Commit: 4d7094c8b7c61991bfb67b11fc1558724c874eb2 Private-Source-Tree: 54a2f74804f7acddf3755d7d4da5b97f5fc28381 AI-Assistance: OpenAI Codex assisted implementation, testing, security review, and release verification. Signed-off-by: Cole Speelman <crspeelman@gmail.com>
2.1 KiB
Preview release policy
v0.1.0-preview.2 may be published only after one identical candidate Tend
binary has successfully completed maintenance releases for Gamertan and the
Sandwich Hime website, including injected-failure restoration and explicit
rollback proof. The August 14, 2026 campaign met that gate; the scoped,
sanitized record is in docs/DOGFOOD_EVIDENCE.md.
Before a preview tag:
- Run
./scripts/verify.shfrom a clean pushed private-development commit. - Review dependency, license, race, filesystem, archive, and rollback evidence.
- Export the exact allowlisted public tree into a new root commit.
- Verify canonical Gitea and GitHub discovery trees are byte-identical.
- Sign the canonical Gitea tag and attach checksums and an SPDX SBOM.
- Verify a fresh public checkout before advertising installation.
The release tag and attached candidate must be built from the final reviewed source commit. Documentation-only changes after the recorded campaign require one final identical-candidate maintenance pass before tagging.
v0.2.0-preview.1 is a separate, additive release line. It requires schema 2,
the restricted push/receive transport, root-owned environment-file
references, host-wide activation serialization, and HTTPS public-origin smoke.
It may be tagged only after the exact same v0.2 binary successfully deploys,
rolls back, and reactivates both Gamertan and the Sandwich Hime website. EQL is
not part of this generic gate; its SQLite/catalog publication needs a dedicated
adapter rather than arbitrary hooks.
v0.1.0-preview.1 is immutable but withdrawn: its source and module checksums
are valid, while a fresh go install reports the development identity because
the CLI did not yet adopt the tagged module version from Go build information.
Preview 2 adds that identity path and its regression tests; preview 1 is never
retagged or rewritten.
The canonical public origin is ssh://git@gitea.speelman.ca:2222/gamertan/tend.git.
GitHub is a read-only discovery snapshot. Private development history is not
published or merged into either public history.