Skip to content

v0.1.0-beta.1 release evidence and follow-up ledger #32

Description

@jremick

v0.1.0-beta.1 release evidence and follow-up ledger

Moodarr v0.1.0-beta.1 was published as an early public beta on 2026-07-20. This issue records the released identity, evidence used for the beta decision, and the broader validation work that remains for later beta hardening. Unchecked follow-ups below are not represented as passing release evidence.

Released identity

  • Source commit: 08447e87df2e1705aa9a79193a52a65fb00724c3
  • Protected Git tag: v0.1.0-beta.1 at the exact source commit
  • Candidate image: ghcr.io/jremick/moodarr:sha-08447e87df2e1705aa9a79193a52a65fb00724c3
  • Released image: ghcr.io/jremick/moodarr:v0.1.0-beta.1
  • Immutable OCI digest: sha256:c1558d33b1e38c01d7d77171354464dd2b507fd6b84b353f2b0e11372ed73157
  • GitHub prerelease: https://github.com/jremick/moodarr/releases/tag/v0.1.0-beta.1
  • Protected main at publication: 633a060080f02225761520cb8084e9eb2a2fa78a; the release source remains reachable from main

Never use any candidate recorded in .github/release-revocations.json, including the superseded c7b6deff54a78ede279d607e38bfe8df2bec3582 candidate.

Passed release evidence

  • Exact candidate source CI: https://github.com/jremick/moodarr/actions/runs/29565465519
  • Exact candidate CodeQL analysis: https://github.com/jremick/moodarr/actions/runs/29565465417
  • Exact-source candidate publication, attestation, runtime scan, and registry read-back: https://github.com/jremick/moodarr/actions/runs/29565540479
  • Independent exact-digest supply-chain, clean-install, Compose-install, alpha.21 upgrade, and rollback validation: https://github.com/jremick/moodarr/actions/runs/29565760158
  • Protected exact-digest promotion, repeated release verification, vulnerability scan, revocation checks, and byte-identical GHCR read-back: https://github.com/jremick/moodarr/actions/runs/29727611811
  • The frozen source contains the Finder/Admin redesign, catalog identity repair, SQLite failure hardening, configured Plex-home fallback, and direct-Unraid origin correction.
  • GHCR package-writer ACL was maintainer-confirmed before candidate publication.
  • The exact candidate ran healthy with the expected version, revision, policies, worker readiness, and protected access behavior.
  • EXP ran the exact released digest and passed live Plex and Seerr connection checks plus a non-writing 90,000-item search smoke test.
  • Desktop and 390-pixel mobile protected-shell rendering, keyboard focus visibility, and zero application console errors passed in the release smoke session.
  • The pinned catalog asset was uploaded to the draft prerelease, downloaded again, and matched dd25ba6602e1bdb8e6999b0442bc40165e6d4faadd02e91e74e1a24e2b55e85a at 14,160,185 bytes before publication.
  • Final Git tag, GitHub prerelease, GHCR semantic tag, catalog asset, and EXP exact-digest read-backs passed after publication.

Broader beta-hardening follow-ups

The original matrix below exceeds the intentionally narrower gate used for this early public beta. It remains useful hardening work for later beta prereleases and stable-release planning, but none of these unchecked rows should be inferred as completed:

  • Complete fresh-Unraid Docker Manager and prior-alpha update coverage across additional real installations.
  • Retain a full stopped, networkless catalog-import evidence package covering isolation, ambiguous-identity rejection, and request-attempt disclosure.
  • Complete the dedicated-identity Plex and Seerr/Jellyseerr write matrix, including Watchlist cleanup, exactly-once confirmed request, idempotent retry, uncertain-outcome reconciliation, and upstream cleanup.
  • Retain a production-sized native Linux amd64 two-CPU/two-GiB responsiveness report.
  • Complete current-stable Chrome, Edge, Firefox, and macOS Safari coverage for Plex sign-in, request confirmation, Admin lock/unlock, keyboard-only navigation, focus, mobile layout, reduced motion, and console errors.
  • Produce the comprehensive privacy-reviewed moodarr-beta-manual-evidence-v1 artifact for a later release gate.

Release boundary

This is an early beta, not v1.0. The published release notes define its supported platform, trusted-LAN/VPN deployment boundary, AI-off official-image policy, experimental iOS exclusion, and known limitations. Continue using the exact digest above for reproducible deployment and rollback.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions