Skip to content

Release metadata qualification drift: no publication-time artifact validation gate or assertion mapping records #43

Description

@roninjin10

Summary

The repository currently has no visible release-automation implementation for the PRD section-3.4 publication-time metadata validation gate, and no checked-in qualification assertion mapping records required by section 3.5.

Why this matters

This is a high-impact reproducibility and release-governance gap: canonical publication claims can be made without machine-enforced validation of release-tuple.json / light-default-checkpoints.json invariants and without auditable shipped-surface assertion mapping.

Normative contract

  • docs/specs/prd.md:119-121 requires a mandatory publication-time CI/release validation gate for required release artifacts.
  • docs/specs/prd.md:161-168 requires assertion mapping records and explicit release-asset/provenance/supersession-note mapping rows for metadata-backed qualification.

Evidence

  • No GitHub workflow files are present under .github/ (repository search returned no .github/workflows/* files).
  • Search for release-asset validation/provenance assertion implementation in code/workflow surfaces shows no executable validation path; references are documentation-only.
  • Search for required assertion mapping record fields (surfaceId, assertionType, release-asset-validation, release-provenance-validation, supersession-note-validation) returns PRD text only:
    • docs/specs/prd.md:161

Suggested scope

  • Add release automation that validates, at publication time, both required release assets (release-tuple.json, light-default-checkpoints.json) against PRD 3.4 invariants.
  • Add auditable qualification artifact(s) containing assertion mapping rows required by PRD 3.5 (including release-asset, release-provenance, and supersession-note categories when applicable).
  • Make the gate blocking for canonical publication claims.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions