Audit release licenses and provenance (#104)
Some checks failed
API and SemVer surface / api-surface (push) Failing after 13m11s
Native code generation / deterministic (push) Failing after 2m9s
Documentation / documentation (push) Failing after 1m39s
Imaging and meshing gate / native (push) Failing after 2m58s
Release platform and feature matrix / audit (push) Successful in 44s
Native Rust workspace compile / compile (push) Failing after 55s
Dependency and supply-chain audit / audit (push) Failing after 9m14s
Release platform and feature matrix / matrix (false, linux-stable-minimal, x86_64-unknown-linux-gnu, stable) (push) Failing after 9m22s
Release platform and feature matrix / matrix (false, windows-stable-portable, x86_64-pc-windows-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-msrv-portable, x86_64-unknown-linux-gnu, 1.96.0) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-stable-default, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-stable-features, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-stable-release-surface, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (false, macos-stable-portable, x86_64-apple-darwin, stable) (push) Has been cancelled

This commit is contained in:
2026-08-12 02:12:49 +00:00
parent d08b59c9a9
commit b71386dc31
25 changed files with 26749 additions and 62 deletions

View File

@@ -529,3 +529,16 @@ filtering, output, cancellation, and safety paths without connecting to a
privileged live grid. Command ownership, resource limits, explicit
live-operation gates, and the focused verification command are documented in the
[`TestClient` guide](docs/test-client.md).
### Milestone 12
The release surface now has deterministic native Rust gates for toolchain and
feature coverage, dependency policy, documentation completeness, API/SemVer
stability, concurrency/resource lifecycle, and license/source provenance. The
license audit corrects the separate CC-BY-SA-3.0 status of the seven required
Linden data inputs, rejects unknown fixtures and opaque bundled assets,
consolidates license texts for every locked Rust package, records all native
linkage and redistribution obligations, and hashes the complete source and
notice distribution. See the
[`release provenance guide`](docs/release-provenance.md) for reproduction and
the exact source/binary notice contract.