diff --git a/docs/validation/1.0.0-readiness.md b/docs/validation/1.0.0-readiness.md index 904e512..14c45b5 100644 --- a/docs/validation/1.0.0-readiness.md +++ b/docs/validation/1.0.0-readiness.md @@ -1,6 +1,6 @@ # 1.0.0 Readiness Evidence -Status: Ready for release +Status: Partial release — GitHub channel released; npm channel blocked on registry credentials ## Candidate - Commit: `docs/v1-release-readiness` head at authoring; the release candidate is finalized at the C6 version-bump commit — re-verify before release @@ -52,5 +52,12 @@ Finding-count changes vs 0.8.1 stem from the corrected semantics (implicit block - Temporary worktrees (`/private/tmp/vi-smoke-before`, `/private/tmp/vi-bench-081`) and their tarballs were removed after use. - No plugin `data.json`, vault files, or Obsidian settings were touched (no live environment available in this session). +## Release record (2026-09-18, UTC+8) + +- Release commit: `2ea1cd4` (merge of PR #183); lightweight tag `1.0.0` pushed from that commit. +- Release workflow run 35307337997: success — tag/main ancestry verified, full gates re-run, installed-package smoke on Node 24 and Node 18, GitHub release created with attestation. +- GitHub release `1.0.0` verified: `main.js` (sha256 `0ed332cf…f7a13`), `manifest.json` (`382a750c…4f1b6e`, version 1.0.0), `styles.css` (`98c3fd82…72443`) — identical to the locally verified candidate hashes. +- npm channel: Blocked — no registry credentials in the release session (`npm whoami` → 401). Publish-ready tarball built from the release commit and smoke-verified: `/tmp/vi-npm-staging/vault-inspector-1.0.0.tgz` (sha256 `f7ad58c2…f1faa`). Publish with `npm publish /tmp/vi-npm-staging/vault-inspector-1.0.0.tgz --access public`, then verify with `npm view vault-inspector@1.0.0 version` and a registry-install smoke run. + ## Release decision All required gates have evidence: automated gates (S0, A, B) pass, native acceptance was completed and confirmed by the repository owner on 2026-09-18, and the owner explicitly authorized the 1.0.0 release. Follow-up fix for Unicode URL boundaries (#184) is included in the release candidate; release gates were re-run on the rebased candidate.