Skip to content

Latest commit

 

History

History
1017 lines (973 loc) · 76.3 KB

File metadata and controls

1017 lines (973 loc) · 76.3 KB

Release Readiness

This dashboard is the Gate G release-readiness entry point for 6529Stream. It is a pre-audit local baseline, not production-ready, and not a security claim. Local evidence does not replace fork/testnet/live evidence for public beta or production release.

The canonical requirement inventory is release-artifacts/genesis-deployment-profile.json. Its default checker keeps the 37 numbered [LCM-GENESIS] roles structurally synchronized and rejects every probe row or binding under ADR 0017; production release mode additionally requires the current candidate to satisfy every entry exactly once. The committed implementation catalog remains incomplete and does not yet constitute a concrete deployment-instance manifest, so this gate is red without changing the public-beta decision.

Use this file to answer one question before any release claim: what is already proved by committed local evidence, and what still blocks a public beta or production release? Use docs/production-readiness-execution.md for the current remote-main release-candidate execution packet: frozen commit, locally executed gates, environment-blocked gates, and the public-beta and production evidence rows that still prevent release claims. Use docs/non-local-release-evidence.md as the intake runbook for any fork, testnet, live, audit, gas, invariant, verification, or signing evidence that updates the public-beta evidence status. Use docs/incident-response.md for no-secret triage, containment, recovery, evidence retention, and reopening procedures when an operational incident affects release readiness. Use docs/audit-finding-workflow.md for public-safe external audit finding intake, severity/status triage, remediation PR requirements, retest, accepted-risk decisions, closure gates, and post-audit evidence handoff. Use docs/drop-authorization-signing.md for the local no-secret drop authorization signing fixtures, unsigned payload generator templates, drop authorization signing evidence template, and the EIP-712 / ERC-1271 evidence they cover. Use docs/signer-custody-readiness.md for the no-secret production signer custody readiness evidence model that must accompany reviewed non-local signing evidence. Use docs/release-signatures.md for release signature evidence, signed release tag gate boundaries, and the production release-signing checker and retained artifact that future reviewed production_signatures and signed_git_tag evidence must satisfy. Use the public-beta verified-addresses checker and public-beta verified-addresses retained artifact under release-artifacts/evidence/public-beta-verified-addresses/public-beta-verified-addresses-retained-artifact-template.md for future reviewed verified_deployed_addresses and explorer_verification_status evidence before those public-beta rows can move out of missing or blocked status. Use docs/provenance-manifests.md for the checked 1/1 provenance manifest model, generated provenance artifact catalog, and frontend/indexer display boundaries for artist/story/authenticity context. Use docs/permanence-packages.md for the checked ONE-004 collector-verifiable permanence package model, generated one-of-one permanence manifest, replay commands, browser proof, output hashes, and fully on-chain versus decentralized storage boundaries. Use docs/royalty-policy.md for the checked ONE-003 royalty policy, current ERC-2981 disclosure, governance boundary, marketplace display guidance, and royalty disclosure, not payment enforcement caveat. Use docs/warning-dispositions.md for the checked ONE-007 warning disposition baseline covering fixed NatSpec warning noise and accepted solc, documentation, linter, vendored, test-only, ABI-compatibility, and StreamCore size-tradeoff warning decisions, including the plain-language StreamCore size-tradeoff warning decisions phrase used by the checker. Use docs/protocol-surface.md for the generated function, selector, event, topic0, custom-error, ABI hash, bytecode hash, and runtime-size report over release-tracked contracts. Use docs/natspec-coverage.md for the checked CON-006 NatSpec coverage baseline over release-surface functions, public variable getters, events, and custom errors. The baseline is a burn-down queue, not proof that current API documentation is complete. Use docs/deployment.md for the no-secret admin ceremony evidence model that must accompany reviewed ownership, role, signer, pause, emergency, and post-state proof for non-local deployments. Use docs/integrations/README.md as the integration entrypoint for frontend, mobile, Electron, indexer, operator UI, and backend signing service teams that need to find canonical ABIs, address books, deployment manifests, event catalogs, metadata docs, signing docs, and release artifacts without treating local evidence as public beta or production proof. Use docs/integrations/contract-flows.md as the fixed-price mint and drop authorization flow spec for current INT-002 frontend/backend-signing integration work. Use docs/integrations/auction-flows.md as the auction frontend and indexer flow spec for current INT-003 integration work. Use docs/integrations/wallets-and-signatures.md as the wallet, EIP-712, ERC-1271, and Safe signing guide for current INT-004 integration work. Use docs/integrations/events-and-indexing.md as the event and indexer reconstruction spec for current INT-005 integration work. Use docs/integrations/metadata-rendering.md as the metadata rendering, cache, animation sandbox, and marketplace integration guide for current INT-006 integration work. Use docs/integrations/marketplace-indexer-evidence.md as the ONE-005 retained marketplace/indexer evidence guide for OpenSea, Reservoir, Blur, Manifold, equivalent collector/indexer tooling, contract metadata, token metadata refresh, animation rendering, royalty display, transfer/listing/sale paths, event replay, and cache invalidation. Use docs/integrations/frontend-reference-architecture.md as the React/Next frontend reference architecture for current INT-007 integration work, including artifact import, client layering, query/cache, transaction, wallet, metadata, indexer, environment, and testing boundaries without adding a maintained frontend package or generated SDK. Use docs/integrations/mobile-walletconnect.md as the mobile and WalletConnect integration guide for current INT-008 integration work, including mobile browser, native shell, WalletConnect session lifecycle, foreground wallet handoff, deep links, reconnect, offline/background, telemetry, and no-secret boundaries without adding a maintained mobile SDK, React Native app, or WalletConnect dependency recommendation. Use docs/integrations/electron-security-wallets.md as the Electron security and wallet integration guide for current INT-009 integration work, including Electron main/renderer/preload boundaries, BrowserWindow hardening, context isolation, IPC allowlists, wallet-provider boundaries, metadata animation sandboxing, local cache/secrets policy, signed updates, code signing, autoUpdater caveats, telemetry, and no-secret boundaries without adding a maintained Electron app, native desktop app, desktop SDK, code-signing implementation, or signed-update implementation. Use docs/integrations/operator-admin-ui.md as the operator admin UI specification for current INT-010 integration work, including operator personas, Safe/multisig ceremony, role grants, signer lifecycle, pause domains, metadata freeze, dependency updates, randomizer operations, emergency-withdrawable surplus, monitoring, incident links, and no-secret evidence boundaries without adding a maintained operator dashboard, Safe app, multisig transaction builder, monitoring service, or production signer custody implementation. Use docs/monitoring.md as the GOV-009 protocol monitoring specification covering admin, signer, auction, randomness, credits, metadata, dependency, release evidence, alert severity, dashboard queries, and incident handoff without adding a maintained monitoring service, hosted dashboard, alert provider integration, or production indexer. Use docs/operator-dashboard-query-model.md as the GOV-010 operator dashboard query model, mapping environment/release, admin, signer, fixed-price, auction, randomizer, payment, metadata/dependency, release blocker, and incident drill panels to query inputs, source artifacts, freshness, severity, and no-secret telemetry boundaries without adding a maintained dashboard, hosted monitoring service, alert provider, RPC provider, or production indexer. Use release-artifacts/latest/public-beta-blockers.md and release-artifacts/latest/production-release-blockers.md as the generated blocker reports for the current evidence manifest, and use release-artifacts/latest/release-evidence-packet-index.md as the release evidence packet index that maps blocker rows to templates, retained-artifact expectations, validation commands, and current readiness posture. Use release-artifacts/latest/release-evidence-issue-backlog.md as the generated issue-preparation backlog for the same incomplete evidence rows without creating issues automatically or changing readiness claims. Use release-artifacts/latest/release-evidence-issue-links.json as the committed tracker map from those generated backlog entries to GitHub issues. Use release-artifacts/latest/release-evidence-issue-body-sync.md as the generated no-secret review view for exact GitHub issue body payloads derived from that backlog and tracker map. Use release-artifacts/latest/risk-register.json as the generated risk register for launch blockers, accepted local-baseline risks, planned mitigations, source-document hashes, and evidence links. Run python scripts/check_release_evidence_issue_closure.py before closing any linked tracker issue; that release evidence issue closure readiness check loads the tracker map, release-evidence-issue-backlog.json backlog artifact, body-sync artifact, packet index, and evidence manifest, then keeps issues open until committed evidence is complete or accepted_risk. For live GitHub state, run make release-evidence-live-issue-sync-check with authenticated gh access; it fetches each linked tracker issue, then validates live issue bodies and closure state against the committed release evidence artifacts.

Maturity And Scope

Current maturity:

  • Repository status: pre-audit and not production-ready.
  • Evidence status: local baseline plus reviewed fork metadata and marketplace evidence; current CON-015 fork deployment, fork ceremony, and fork randomizer artifacts are pending re-review after deployment/release artifacts changed.
  • Public beta status: blocked by 32 Open first-party production Slither High/Medium findings, open record-family authorization risk RISK-GOV-002, High open Governance risk RISK-GOV-003, missing external audit, pending fork deployment review, missing testnet deployment evidence, pending fork ceremony review, pending fork randomizer review, verified deployed addresses, and explorer verification.
  • Production release status: blocked by the same 32 Open Slither findings and RISK-GOV-002 / RISK-GOV-003, incomplete #670 pointer integration and candidate remeasurement, incomplete instance-aware genesis evidence, an honestly incomplete checked governed-parameter inventory whose concrete host/value/floor/evidence bindings remain unavailable under #684 and RISK-GOV-004, missing production signatures, signed Git tags, verified deployed addresses, explorer verification, non-local retained evidence, and post-audit remediation evidence.

This dashboard covers release-readiness evidence only. It does not perform a real release, does not create production signatures, and does not assert that local tests prove protocol correctness.

The release-mode CI profile is the opt-in hard gate for public-beta or production-release claims. It is exposed as a manual workflow_dispatch workflow and local make release-mode-public-beta-check / make release-mode-production-release-check targets. The local targets run the aggregate check gate plus the pinned live exact Slither comparison first; the manual workflow fails unless it runs from the protected default branch, then runs both before evaluating release evidence. The gate is expected to fail until retained evidence is complete; an active accepted-risk record may satisfy only a waivable public-beta row. External-audit evidence and every production requirement are non-waivable. Release mode requires public-beta readiness before production-release readiness, so a production run validates both phases. It also validates the checksum-covered current StreamCore size against the normative 2,000-byte EIP-170 deployment headroom rule from the Genesis Deployment Profile and Core Hook Budget. Missing, malformed, inconsistent, or sub-threshold size fields fail closed. The permanent target measurement in release-artifacts/latest/bytecode-release-proof.json passes the non-waivable 2,000-byte production margin and the approved 22,184-byte objective. This resolves the Core-size row only; concrete #670 pointer contracts, candidate-instance reconciliation, governed-parameter evidence, audit, and live release evidence remain independently blocking.

Both release phases validate the canonical normalized ops/SLITHER_BASELINE.json and its checked Markdown mirror. Any Open first-party production High/Medium row blocks the release decision even when the live analyzer exactly matches the baseline. The current 32 Open rows therefore keep public beta and production red under issue #658.

The bounded assembly call in StreamGovernanceExecutor prevents returndata bombs but makes proposal-selected native-value authority invisible to Slither's arbitrary-send-eth detector. The Executor now binds and revalidates a checksum-covered closed-world action/target/selector/value catalog at scheduling and execution, with zero value as the default and explicit typed semantics for any nonzero row. RISK-GOV-003 remains a separate High open blocker until issue #656 provides exact candidate addresses and code hashes and the deployment, system-manifest, non-local rehearsal, monitoring, and independent-review evidence is complete. The Governance V2 foundation is pre-audit and not production-ready.

Both release phases also run the record-family authorization checker and consume its code-owned hard completion blocker. The current metadata and preservation writer model is as_built_fail_open: its five mutation selectors accept selector/global-admin grants without enforcing the exact record-family authority required by [CMC-AUTHZ]. The planning inventory, its schema, the retained-evidence and grant-map schemas, and the template make the missing implementation and evidence explicit, but no JSON edit, environment variable, accepted risk, template, or admin ceremony can waive the stop. Issue #690 and RISK-GOV-002 therefore block both public beta and production.

Strict release mode now proves whether the implementation catalog satisfies the canonical Genesis Deployment Profile as a closed world. The committed catalog fails that check, and the current manifest model still cannot prove every required distinct deployment instance for the 37-entry, no-probe target. That reconciliation remains an independent production blocker tracked by issue #656; the structural profile gate is not concrete deployment evidence.

Production mode also runs the governed-parameter inventory checker with --require-complete. The ordinary aggregate gate validates the schema-validated 22-GGP/3-GTP planning artifact and permits explicitly not_available candidate bindings so development can continue without fabricated values. Production mode permits no such placeholder: every logical row and every required host profile must bind an exact candidate instance, genesis value, immutable floor, exhaustive guarded-consumer inventory, reviewed measurement or cadence evidence, and fixed-stipend compatibility. Until issue #656 adds a structured production-candidate model and reconciliation checker, the inventory checker also rejects any self-reported complete candidate rather than trusting an opaque artifact. The committed artifact intentionally fails that stricter decision, so #684 and RISK-GOV-004 remain open.

Readiness Summary

Area Current state Blocks public beta Blocks production release
CI and local gates Passing local/CI baseline exists for build, tests, size, local deployment rehearsals, incident response, release artifacts, architecture/threat model, audit package, release manifest, checksums, and changelog No No, but release commit CI must be green
StreamCore deployment headroom The canonical bytecode proof passes the 2,000-byte production margin and approved 22,184-byte objective without an exception; this does not clear candidate, audit, or live evidence rows No No
Genesis inventory completeness The canonical 37-entry no-probe launch profile and fail-closed production checker exist, but the current implementation catalog is incomplete and the manifest model cannot yet prove every required distinct deployment instance; issue #656 tracks reconciliation No Yes
Governed parameter completeness The schema-validated 22-GGP/3-GTP inventory pins exact 50-binding host-profile policy, failure/cadence rules, evidence obligations, and the shared Core completion buffer. Issue #671 binds the as-built permanent Core, actual royalty/metadata boundaries, independent raise-chain tests, six via-IR measurements, and inventory-bound 1,460,000 floor / 2,910,000 genesis planning values without adding a 23rd GGP. Candidate bindings remain honestly not_available; concrete #670 artist/revenue rows, exhaustive consumer review, candidate-bound sizing/cadence evidence, fixed-stipend compatibility, and instance-aware addresses are incomplete. #656/#684 and RISK-GOV-004 keep this non-waivable production gate red No Yes
Record-family authorization The checked planning inventory pins five selector/global-admin mutation surfaces, eight authorization classes, fourteen family groups, and eight fail-open behaviors. The retained-evidence and strict grant-map schemas plus the template require candidate, classifier, grant-map, snapshot-intersection, lifecycle, phase, runtime, and independent-review bindings, but current contracts enforce none of that family-scoped policy; issue #690 and RISK-GOV-002 remain open Yes Yes
Protocol maturity Pre-audit, not production-ready, local baseline only Yes Yes
External audit Audit package and external audit retained-artifact template/checker exist; completed external audit report and post-audit remediation do not exist Yes Yes
Deployment evidence Local Anvil deployment, auction, metadata-browser, and emergency redeployment rehearsals exist; fork deployment rehearsal evidence is retained but pending re-review for the CON-015 artifact set; fork ceremony evidence is retained but pending re-review for the CON-015 artifact set; testnet rehearsal retained-artifact template/checker and admin ceremony evidence template/checker exist Pending CON-015 fork deployment review, reviewed testnet/live evidence, reviewed admin ceremony evidence, pending CON-015 fork ceremony review, verified deployed addresses, explorer verification, and pending fork/testnet randomizer evidence Production broadcast retention, production admin ceremony evidence, verified deployed addresses, and explorer verification missing
Release artifacts Release manifest, checksum bundle, bytecode-to-release proof, release-candidate lockfile, risk register, ABI baseline, gas snapshot, gas envelope baseline, protocol surface report, source verification inputs, address books, ceremony evidence, admin ceremony evidence schema/template/checker, randomizer operations evidence, release-signature evidence, production release-signing checker and retained artifact, drop authorization signing fixtures, unsigned payload-generator examples, drop authorization signing evidence schema/template/checker, signer custody readiness schema/template/checker, 1/1 provenance manifest schema/template/checker/generated catalog, collector-verifiable permanence package schema/template/checker/generated one-of-one permanence manifest, public-beta evidence status, generated public-beta and production-release blocker reports, release evidence packet index, release evidence issue backlog, release evidence issue links, release evidence issue body sync, release evidence issue closure readiness, non-local release evidence runbook/schema/generic template, external audit retained-artifact template/checker, testnet deployment retained-artifact template/checker, public-beta verified-addresses checker and retained artifact, reviewed fork retained artifact/evidence envelope, per-requirement public-beta and production-release templates, and checker exist for the local baseline Live release artifacts, live bytecode proof, production signing evidence, reviewed 1/1 provenance evidence where used for collector-facing claims, reviewed permanence packages with browser proof and output hashes where used for collector-facing claims, reviewed signer custody readiness, reviewed admin ceremony evidence, reviewed testnet/live retained evidence, verified deployed addresses, explorer verification, and completed external audit evidence missing Production signatures, signed Git tags, reviewed 1/1 provenance evidence and reviewed collector permanence evidence where used for production collector-facing claims, and reviewed live bytecode proof missing
Static analysis and tests The normalized first-party production Slither baseline contains 2 High and 30 Medium open findings; RISK-GOV-003 separately preserves the Governance Executor native-value authority hidden from Slither by bounded assembly; an exact metadata/drift gate, warning disposition baseline, NatSpec coverage baseline, test matrix, invariants, local gas snapshot, and local gas envelope ceilings are tracked Yes: all 32 Slither rows and RISK-GOV-003 remain Open, and testnet/live invariant and gas evidence is missing Yes: open Slither findings, RISK-GOV-003, external audit, and production evidence are missing

Local Evidence Already Passing

The current local baseline includes:

These items are release evidence, not launch approval.

Public Beta Blockers

Public beta remains blocked until maintainers add or explicitly accept evidence for:

  • completed external audit report and issue-linked remediation status;
  • testnet/live deployment rehearsal evidence plus fork/testnet/live metadata browser execution, ceremony evidence, randomizer operations evidence, emergency redeployment evidence, and invariant/gas checks following docs/non-local-release-evidence.md;
  • production address books generated from retained broadcast artifacts;
  • verified deployed addresses and explorer verification status;
  • production signer and admin ceremony evidence with secrets redacted;
  • reviewed incident drill evidence for mint pause, bid pause, settlement pause, withdrawal policy, failed randomness, stuck auction, bad metadata or dependency configuration, bad Merkle root, and signer compromise drills;
  • reviewed signer compromise drill evidence for drop-execution pause, signer rotation or revocation, signer epoch invalidation, per-drop cancellation, stale payload rejection, recovered payload execution, monitoring confirmation, reviewer approval, and redaction;
  • reviewed stuck auction drill evidence for auction identity, stuck condition, custody, pause/unpause, settlement or cancellation outcome, bidder and proceeds credits, withdrawal availability, emergency-surplus boundary, monitoring handoff, reviewer approval, and redaction;
  • reviewed bad metadata/dependency drill evidence for metadata schema/state, token URI snapshots, URI/UTF-8/raw-attributes or browser-sandbox failure, dependency key/version/content hash, freeze and repin boundary, ERC-4906/cache invalidation, marketplace/indexer handoff, reviewer approval, and redaction;
  • reviewed signer custody readiness evidence with custody owner, signer manager, signer epoch source, signer-service integration, ERC-1271 status, rotation/revocation drills, monitoring, and incident-response references;
  • production drop authorization signing evidence and approved signer integration beyond the no-secret local fixtures and unsigned payload generator;
  • a final review that known blockers in docs/known-blockers.md and ops/ROADMAP.md have either been resolved or explicitly deferred outside public beta.

Production Release Blockers

Production release remains blocked until maintainers add or explicitly accept:

  • production signatures over the checksum bundle;
  • signed Git tags for the release commit;
  • production release-signature evidence following docs/release-signatures.md;
  • retained production broadcast outputs and generated live deployment manifests;
  • production broadcast retention retained artifact review following the production broadcast retention checker;
  • verified deployed addresses and explorer verification output following the production verified-addresses checker;
  • post-audit remediation evidence for every accepted audit finding;
  • dependency source retention and migration evidence following docs/dependency-operations.md;
  • randomizer provider configuration, funding, lifecycle, and request-health evidence following docs/randomizer-operations.md.
  • no-secret non-local release evidence intake records following docs/non-local-release-evidence.md.

Required Evidence Links

Core project and governance:

Audit and protocol evidence:

Release artifacts:

Release Commands

Run the dashboard checker directly:

python scripts/test_release_readiness.py
python scripts/check_release_readiness.py
python scripts/test_release_mode.py
python scripts/check_release_mode.py --phase public-beta
python scripts/check_release_mode.py --phase production-release
python scripts/test_production_broadcast_retention.py
python scripts/check_production_broadcast_retention.py
python scripts/test_public_beta_verified_addresses.py
python scripts/check_public_beta_verified_addresses.py
python scripts/test_sepolia_evidence_preflight.py
python scripts/check_sepolia_evidence_preflight.py
python scripts/test_production_verified_addresses.py
python scripts/check_production_verified_addresses.py
python scripts/test_signed_release_tag.py
python scripts/check_signed_release_tag.py
python scripts/test_production_release_signing_evidence.py
python scripts/check_production_release_signing_evidence.py
python scripts/test_incident_response.py
python scripts/check_incident_response.py
python scripts/test_stuck_auction_drill_evidence.py
python scripts/check_stuck_auction_drill_evidence.py
python scripts/test_failed_randomness_drill_evidence.py
python scripts/check_failed_randomness_drill_evidence.py
python scripts/test_bad_metadata_dependency_drill_evidence.py
python scripts/check_bad_metadata_dependency_drill_evidence.py
python scripts/test_contract_flows.py
python scripts/check_contract_flows.py
python scripts/test_auction_flows.py
python scripts/check_auction_flows.py
python scripts/test_wallet_signature_flows.py
python scripts/check_wallet_signature_flows.py
python scripts/test_events_and_indexing.py
python scripts/check_events_and_indexing.py
python scripts/test_metadata_rendering.py
python scripts/check_metadata_rendering.py
python scripts/test_marketplace_indexer_evidence.py
python scripts/check_marketplace_indexer_evidence.py
python scripts/test_react_next_reference.py
python scripts/check_react_next_reference.py
python scripts/test_mobile_walletconnect.py
python scripts/check_mobile_walletconnect.py
python scripts/test_electron_security_wallets.py
python scripts/check_electron_security_wallets.py
python scripts/test_operator_admin_ui.py
python scripts/check_operator_admin_ui.py
python scripts/test_operator_dashboard_query_model.py
python scripts/check_operator_dashboard_query_model.py
python scripts/test_monitoring_spec.py
python scripts/check_monitoring_spec.py
python scripts/test_drop_authorization_payload_generator.py
python scripts/generate_drop_authorization_payload.py --input test/fixtures/drop-authorization/payload-generator/fixed-price-input.json --output test/fixtures/drop-authorization/payload-generator/fixed-price-output.json --check
python scripts/generate_drop_authorization_payload.py --input test/fixtures/drop-authorization/payload-generator/auction-input.json --output test/fixtures/drop-authorization/payload-generator/auction-output.json --check
python scripts/test_drop_authorization_fixtures.py
python scripts/check_drop_authorization_fixtures.py
python scripts/test_drop_authorization_signing_evidence.py
python scripts/check_drop_authorization_signing_evidence.py
python scripts/test_signer_custody_readiness.py
python scripts/check_signer_custody_readiness.py
python scripts/test_one_of_one_provenance_manifest.py
python scripts/check_one_of_one_provenance_manifest.py
python scripts/generate_one_of_one_provenance_manifest.py --check
python scripts/test_one_of_one_permanence_package.py
python scripts/check_one_of_one_permanence_package.py
python scripts/generate_one_of_one_permanence_manifest.py --check
python scripts/test_royalty_policy.py
python scripts/check_royalty_policy.py
python scripts/test_warning_dispositions.py
python scripts/run_forge_size_log.py --log cache/forge-size.log
python scripts/check_warning_dispositions.py --solc-warnings-log cache/forge-size.log
python scripts/test_natspec_coverage.py
python scripts/check_natspec_coverage.py
python scripts/test_gas_envelopes.py
python scripts/check_gas_envelopes.py
python scripts/test_public_beta_evidence.py
python scripts/check_public_beta_evidence.py
python scripts/test_risk_register.py
python scripts/check_risk_register.py
python scripts/generate_risk_register.py --check
python scripts/test_production_release_blocker_report.py
python scripts/generate_production_release_blocker_report.py --check
python scripts/test_release_evidence_packet_index.py
python scripts/generate_release_evidence_packet_index.py --check
python scripts/test_release_evidence_issue_backlog.py
python scripts/generate_release_evidence_issue_backlog.py --check
python scripts/test_release_evidence_issue_links.py
python scripts/check_release_evidence_issue_links.py
python scripts/test_release_evidence_issue_snapshot.py
python scripts/test_release_evidence_issue_snapshot_audit.py
python scripts/test_release_evidence_live_audit_report.py
python scripts/check_release_evidence_live_audit_report.py
python scripts/test_release_evidence_live_audit_markdown.py
python scripts/check_release_evidence_live_audit_markdown.py
python scripts/test_release_evidence_live_audit_archive.py
python scripts/generate_release_evidence_live_audit_archive.py --check
python scripts/test_release_evidence_issue_labels.py
python scripts/check_release_evidence_issue_labels.py
python scripts/test_release_evidence_issue_body_sync.py
python scripts/generate_release_evidence_issue_body_sync.py --check
python scripts/test_release_evidence_issue_bodies.py
python scripts/check_release_evidence_issue_bodies.py
python scripts/test_release_evidence_issue_closure.py
python scripts/check_release_evidence_issue_closure.py
python scripts/test_non_local_release_evidence.py
python scripts/check_non_local_release_evidence.py

Run the release evidence drift checks:

The release-tool call policy and schema are manually reviewed upstream inputs, not generated outputs. Review any required policy update before running the canonical generated tail in dependency order: risk register, release notes, release manifest, bytecode proof, candidate lockfile, then checksum bundle.

python scripts/audit_release_evidence_issue_snapshots.py --report-json tmp/release-evidence-live-audit-report.json --report-md tmp/release-evidence-live-audit-report.md
python scripts/audit_release_evidence_issue_snapshots.py --generated-at YYYYMMDDTHHMMSSZ --report-json release-artifacts/evidence/live-audit-reports/YYYYMMDDTHHMMSSZ-release-evidence-live-audit-report.json --report-md release-artifacts/evidence/live-audit-reports/YYYYMMDDTHHMMSSZ-release-evidence-live-audit-report.md
python scripts/check_release_evidence_live_audit_report.py --report-json tmp/release-evidence-live-audit-report.json
python scripts/check_release_evidence_live_audit_report.py --report-json release-artifacts/evidence/live-audit-reports/YYYYMMDDTHHMMSSZ-release-evidence-live-audit-report.json
python scripts/check_release_evidence_live_audit_markdown.py --report-json tmp/release-evidence-live-audit-report.json --report-md tmp/release-evidence-live-audit-report.md
python scripts/check_release_evidence_live_audit_markdown.py --report-json release-artifacts/evidence/live-audit-reports/YYYYMMDDTHHMMSSZ-release-evidence-live-audit-report.json --report-md release-artifacts/evidence/live-audit-reports/YYYYMMDDTHHMMSSZ-release-evidence-live-audit-report.md
python scripts/generate_release_evidence_live_audit_archive.py --archive-dir release-artifacts/evidence/live-audit-reports
python scripts/generate_release_evidence_live_audit_archive.py --archive-dir release-artifacts/evidence/live-audit-reports --check
python scripts/generate_release_evidence_live_audit_archive.py --check
python scripts/check_signed_release_tag.py --mode release --tag vX.Y.Z --evidence path/to/post-bundle-release-signature-evidence.json
python scripts/generate_release_manifest.py --check
python scripts/generate_release_candidate_lockfile.py --check
python scripts/generate_release_checksums.py --check

Run the full local release gate:

make check
powershell -ExecutionPolicy Bypass -File scripts\check.ps1

Maintenance

Update this dashboard whenever a release gate, launch gate, evidence artifact, production blocker, or accepted risk changes.

Required maintenance rules:

  • New release evidence must be linked here before it can be treated as part of the public release baseline.
  • New blockers must be added here, docs/known-blockers.md, or ops/ROADMAP.md before a PR claims readiness.
  • Any public beta or production-ready claim must point to the CI run, release manifest, checksum bundle, signatures, signed tag, deployment evidence, explorer verification, audit report, and post-audit remediation evidence that justify it.
  • Any fork/testnet/live evidence that changes public-beta or production status must follow the non-local release evidence intake runbook and include a reviewer before the related requirement is marked complete.
  • Regenerate the release manifest and checksum bundle after changing this file, because it is a governance document in the release evidence package.