Skip to content

release: finalize beta-16 evidence refs#448

Closed
jeremi wants to merge 1 commit into
mainfrom
codex/beta16-finalize
Closed

release: finalize beta-16 evidence refs#448
jeremi wants to merge 1 commit into
mainfrom
codex/beta16-finalize

Conversation

@jeremi

@jeremi jeremi commented Jul 20, 2026

Copy link
Copy Markdown
Member

Summary

  • pin beta-16 release source references to preparation commit 0e76f5e
  • refresh Notary and Relay advisory baselines from digest-bound OCI scans
  • synchronize generated docs data and security assurance evidence for v0.12.2

Evidence

  • two independent release-wrapper binary builds matched byte for byte across all 11 artifacts
  • two no-cache OCI builds per product matched exactly
  • Grype 0.114.0 scan against the frozen 2026-07-20 database found zero fixable High/Critical findings
  • three Debian libc findings are explicitly reviewed through 2026-08-20

Verification

  • full docs check passed, including all archived docsets and 557,479 internal links/assets
  • release manifest validation passed
  • docset validation and import audit passed
  • release finalization preflight returned ready
  • advisory checker unit tests and live digest-bound policy checks passed
  • independent finalization review approved with no findings

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
@jeremi
jeremi enabled auto-merge (squash) July 20, 2026 18:41

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d449846b58

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

version: 0.12.2
source_repo: registrystack/registry-stack
source_ref: 984efe0eff5eb7e73b5983dc03ccdade0ff05661
source_ref: 0e76f5ea61f78bbc15d91fcb6e9dfcaa956c3df8

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Add the required DCO sign-off

The reviewed commit message has no Signed-off-by: trailer, but the root AGENTS.md explicitly requires every commit to carry a DCO sign-off via git commit -s; as submitted, this change will be rejected by the DCO policy even though the file contents are otherwise reviewable.

Useful? React with 👍 / 👎.

@jeremi
jeremi disabled auto-merge July 20, 2026 19:10
@jeremi

jeremi commented Jul 20, 2026

Copy link
Copy Markdown
Member Author

Superseded by #447, which merged the byte-identical 11-file beta-16 finalization tree with full protected CI green. No additional changes remain in this PR.

@jeremi jeremi closed this Jul 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant