Skip to content

[PY-03] Resolve public license policy and publish signed packages with sandbox conformance #3

Description

@jaavid

Background

CoreLink is one product across multiple implementation repositories. This work is owned by sdk-python under EPIC-05.

Goal

Resolve the public license gate and publish reproducible, signed Python packages with retained sandbox/conformance evidence and immutable contract provenance.

Parent

  • Primary Product Epic: EPIC-05
  • Backlog ID: PY-03

Scope

  • Package/version the accepted PY-02 SDK surface.
  • Resolve applicable public license/support policy before supported publication.
  • Sign/publish through the organization release/provenance path.
  • Validate against MOCK-03 or an equivalent accepted sandbox.
  • Retain package, dependency, contract and conformance evidence.

Out of Scope

  • Stable claims before license/support policy, SDK behavior and conformance are accepted.
  • Treating successful package publication as runtime Product Acceptance.
  • Bypassing organization release/provenance policy.

Acceptance Criteria

Dependencies and acceptance state

  • Execution prerequisite: PY-02 accepted SDK ergonomics/behavior.
  • Conformance prerequisite: MOCK-03 or equivalent accepted sandbox/package revision.
  • Policy prerequisite: GH-03 accepted license/support policy for public publication.
  • Release-governance prerequisite: GH-04 accepted reusable CI/release/provenance path.
  • Blocks: DOCS-04 Python release guidance, WEB-03 supported-tool claims, and EPIC-05 Python release acceptance.
  • Current dependency state: See the CoreLink Product organization Project.

Planning Metadata

  • Type: Technical Task
  • Priority snapshot: P0
  • Product milestone snapshot: Beta
  • Domain snapshots: sdk, deployment
  • Area snapshot: package
  • Complexity: M
  • Created in status: Triage
  • Current status and DRI: See the CoreLink Product organization Project.
  • Intended repository labels: type:technical-task

Definition of Done

  • Acceptance criteria demonstrated.
  • License/support decision is recorded where required.
  • Artifact provenance/signing and reproducibility are verified.
  • Required conformance checks pass on version-identifiable dependencies.
  • Contract/security/tenant implications are reconciled.
  • Documentation/release notes are updated.
  • Pull request(s), package revision and retained evidence are linked.

Metadata

Metadata

Assignees

No one assigned

    Labels

    type:technical-taskImplementation or engineering enablement work

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions