Release: pin imported-source provenance before public status #5
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Goal\nClose the provenance gap required to change the project status from public-ready to public.\n\n## Scope\n- Pin each imported source to a verifiable upstream revision or reproducible archive.\n- Verify distribution rights and required attribution.\n- Resolve provisional source records where evidence exists.\n\n## Acceptance criteria\n- provenance/source records contain reproducible source revision or archive information.\n- Attribution status is verified for every source referenced by a promoted artifact.\n- npm run public:check passes with provenance/project.json set to public.\n- The public release checklist is completed.\n\n## Non-goals\n- Relicensing imported third-party material.