On this page
Repo record
The repository-backed record for release evidence, changelog entries, audit ledgers, and current-status boundaries.
Historical proof is useful, but current truth still needs checking.
Audit ledgers and changelog entries explain what was closed and why.
A page should still avoid claiming current publication, host-load, marketplace, or provenance status unless live evidence or current source readback supports it.
Release evidence
Release evidence belongs in tracked audit ledgers, changelog entries, source files, and explicitly recorded live readbacks.
Generated portal metadata proves docs freshness only; it is not release, publication, or provenance evidence.
Current milestone
The repository retains v0.3.3.3 as the public identity for runtime 0.3.3.
The first publication at commit 00591cc4257f1aea1aa9d3d4887ca4069731b074, tree 87d12e6920f680fcfa69f65646a1c536240e9528, and the later correction at commit 3b5c300f366bec41fcbfedfceeda5a8b56747c71, tree 90a420245f3a4fefadce97dc8dccb77d98ac85e4, remain historical evidence. The current 257,998-byte final correction candidate is locally qualified; authoritative-main integration, publication, and fresh public readback remain pending.
Evidence to re-check
- GitHub release and tag state
- CI and Pages workflow status
- Release asset names and checksums
- Audit ledger scope and unresolved caveats
- Host-load proof if an install claim is being made
Re-check before claiming release status:
- The release tag exists.
- Assets can be read.
- The release-page SHA-256 digest supports artifact-integrity readback; release provenance still needs a separate authorized gate.
- Pages is current only after deploy success.
- Local installs do not auto-update.
Source-current map
| Surface | Current source-backed status | Boundary |
|---|---|---|
| Source milestone | Final v0.3.3.3 correction candidate | The corrective fourth component is the public project identity within runtime family 0.3.3; the premature bytes remain superseded history. |
| Manifest version | 0.3.3 | Derived from .claude-plugin/plugin.json. |
| Current release object | GitHub release v0.3.3.3 | Release ID 368332810; corrected tag object 6d57060aeab3aeec1d0ad090c2fa7ab66ca9de67 resolves to final commit 3b5c300.... Historical tag object 89bf563... remains in the internal custody record. |
| Package transition | 227,995-byte superseded asset → 227,999-byte historical correction → 257,998-byte final candidate | Historical SHA-256 values bfe323853fcb814530c9f58e078ef09d4e930419d99005af26c9135f936e3536 and 151cb5400d248e3e41a30750ba690d8c46bbe907294ba82a0a5a627536ad563e; candidate SHA-256 0e10a21600062c6f7cd440a6efb0ff3b795ce1a01067efb4005c7a176db02413; zero /dashboard/ members. Public asset identity remains pending publication/readback. |
| Checksum boundary | The historical 96-byte CHECKSUMS.txt had asset ID 510191721 and SHA-256 f6bb2719c3dd378d226688eaa87d2c989b9ae06fc243f5b57da7826a9f617407. | The final checksum and fresh-download identity remain pending; a digest is not a signature, attestation, SBOM, licence, marketplace check, host-load proof, or proof of provenance. |
| Pages / deploy | Historical correction Pages run 31496828886 | That run establishes the earlier source projection only. Final-main Pages qualification and public readback remain pending. |
| Host load | Local installs do not auto-update | A host-load claim needs host evidence from the current run. |
| Marketplace / provenance | Unclaimed | Separate owner-gated proof is required. |
Historical audit context
Older audit lanes explain why rules exist.
They are not current proof by themselves.
For example, G5 continuity writeback was later strengthened by IMPLEMENTAUDIT_CONTINUITY_SAVED, bounded writeback options, optional custody paths, terrain-update requests, and continuity checks.
Where to inspect ledgers
The existing docs/audits/ directory records dogfood runs and post-release repairs.
The Repo record page should point to that history rather than duplicate every ledger line.
Ledger map
| Ledger | What it records | Use as |
|---|---|---|
docs/audits/INDEX.md | Dogfood history and which detailed ledgers exist. | Starting map, not a raw transcript. |
docs/audits/archive/v0.2.8.0-adaptation.md | Governed casual-build intake, continuity writeback, and docs portal generation. | Parity and product-surface history. |
docs/audits/archive/v0.2.8.0-docs-portal-ci-onboarding.md | Docs portal CI, onboarding repair, and live-portal caveats. | Docs-generation precedent. |
docs/audits/archive/v0.2.8.0-docs-portal-coherence-polish.md | Coherence and prose fixes after the v0.2.8 docs portal rewrite. | Terminology and readability precedent. |
docs/audits/archive/v0.2.9.0-andon-escalation-jidoka-repair.md | Andon/Jidoka repair, no arbitrary caps, sidecar recovery, package parity, and docs truthfulness. | Prior release audit ledger. |
docs/audits/archive/v0.3.0.0-local-package-dogfood-audit.md | Installed-package dogfood, release readiness, package self-sufficiency, and v0.3.0.0 release-gate evidence. | Historical release-gate ledger. |
docs/audits/archive/v0.3.2.0-correction-and-republish-report.md | Corrected same-version v0.3.2.0 publication and digest-pair readback. | Historical public-release ledger. |
docs/audits/archive/v0.3.3.0-release-report.md | v0.3.3.0 package identity, package gate, integration, publication, terminal readback, and tracker closure. | Historical published-release ledger. |
docs/audits/archive/v0.3.3.3-release-report.md | Corrective release identity, eight countermeasures, premature publication custody, final package identity, bounded dispositions, qualification, and public readbacks. | Terminal same-identity correction ledger; R29 row 14 is owner-waived without a model PASS. |
Source surfaces
docs/audits/, CHANGELOG.md, README.md release notes, and release tags.
Evidence surfaces
- Audit ledgers explain findings and closure.
- Changelog entries record milestone history.
- Release pages list release asset entries only after live readback.
- Package checks show local build and archive integrity.
Review checklist
| Question | Inspect |
|---|---|
| What changed in the milestone? | CHANGELOG.md plus the matching audit ledger. |
| What evidence closed it? | Tracked files, run ledger, test output, and release readback if a release happened. |
| What is only historical? | Older ledgers and post-release repair notes; useful context, not current-state proof. |
| What must not be claimed? | Publication, provenance, marketplace load, or host install unless checked in the current gate. |
Current-truth boundary
Historical ledgers explain why a rule exists.
Current state still needs live or source-current verification before the docs claim the latest package, host, Pages, or provenance status.
Do not overclaim
- Pages deployment is not proven until the Pages workflow succeeds.
- Checksum manifests or release-page digests can support artifact-integrity readback; release provenance still requires a separate authorized gate.
- Marketplace publication, host-load proof, and any provenance-gate statement require separate evidence.
Source-backed language
Prefer "the audit ledger records" or "the release page shows after live readback" over broad claims like "published," "proven," or "installed."
If the source is a local checksum match or release-page digest readback, call it integrity evidence. If the source is a published checksum manifest, name the separate provenance gate that authorized and validated it.