Skip to content

[Release] Publish the first verified Renderflow integration-candidate release and reconcile distribution truth #419

Description

@szmyty

Depends on: #415, #416, #417, and #418
Suite roadmap: egohygiene/flow#11
Flow adapter owner: egohygiene/flow#3

Observed release truth

At main 170c3d5985af073d3da8f6ac2e0c4b639cfd2b3e, Cargo declares 0.2.1; the only tag is historical unsigned v0.2.1 at 96d1e55231c30449b12f4849d7cdda63853abc68; GitHub has no release; and public documentation advertises release/package channels that are not all observed live.

Outcome

Publish the first verified Renderflow integration-candidate release that Flow and clean-room consumers can install and lock by immutable version and digest, while making every public distribution claim match observed reality.

Scope

  • Select a new SemVer candidate; never move or reuse v0.2.1.
  • Reconcile Cargo/package versions, generated version surfaces, changelog, roadmap, README, docs, manifests, and capability metadata.
  • Publish an immutable GitHub prerelease/release from one exact green commit.
  • Produce supported binaries/packages, SHA-256 checksums, SBOM, dependency/license notices, provenance/attestation, and an explicit signing decision.
  • Record exact CLI, schema, plugin SDK, provider contract, capability, supported-platform, and external-tool compatibility versions.
  • Clean-install and smoke-test downloaded release artifacts, not worktrees.
  • Test every advertised distribution channel that is actually published; mark unavailable channels planned/unsupported.
  • Publish a machine-readable release manifest suitable for Flow's provider lock and compatibility matrix.

Acceptance criteria

  • A new immutable GitHub release resolves to the exact reviewed commit.
  • Historical v0.2.1 is documented and not reused or moved.
  • Every required artifact and checksum is independently verified.
  • SBOM, notices, provenance/attestation, and signing status are attached or linked.
  • Clean hosts install and run supported artifacts without repository source.
  • --version, help, doctor, planning, dry-run, deterministic fixture execution, and failure exits are smoke-tested.
  • README, docs, package metadata, changelog, release metadata, and observed binary version agree.
  • Unsupported or unpublished package-manager channels are labeled honestly.
  • Flow can pin the release by version and digest without importing Renderflow source.
  • Main CI, docs, conformance, scheduled evidence, and release verification are green.
  • Rollback and compromised-release response are documented.

Non-goals

  • Declaring final stable v1 before Flow integration and the final audit.
  • Adding unrelated product capabilities.
  • Pretending an unavailable package-manager account or channel published successfully.
  • Mutating or replacing an existing tag.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions