@@ -61,7 +61,7 @@ reason to repeat initialization.
6161
6262The fail-closed content and identity gate was required before the historical
6363first remote push and passed again before Public Preview readiness. Keep running
64- it before Registry Alpha preparation and after public-document changes:
64+ it before later releases and after public-document changes:
6565
6666``` bash
6767uv run python scripts/check_version.py --require-public-preview-docs
@@ -201,38 +201,31 @@ read-only by default; only the publishing job receives `id-token: write`.
201201Publishing uses a protected ` pypi ` environment and concurrency control.
202202Arbitrary-branch and manual publication are forbidden.
203203
204- ## Alpha release checklist
204+ ## Alpha release checklist (completed)
205205
206206For the current canonical repository, private initialization, pre-visibility
207207closeout, public visibility, repository protection, environments, public
208- default-branch CI, and the one-time Public Preview live smoke are completed
209- historical prerequisites. Do not recreate or repeat them. The next external
210- actions prepare Registry Alpha and require separate explicit authorization.
211- This checklist defines dependency order, not standing permission: every remote
212- mutation, live request, release action, and registry action must be explicitly
213- authorized in the current maintainer request; stop otherwise.
214-
215- Before continuing, re-audit the recorded Public Preview invariants: protected
216- ` main ` and version tags, immutable releases, Private Vulnerability Reporting,
217- the ` live-smoke ` and ` pypi ` environment boundaries, ` LIVE_SMOKE_ENABLED=false ` ,
218- absent ` CODEOWNERS ` , and disabled Release Please. Maintainers then execute the
219- remaining authorized steps in order:
220-
221- 1 . Confirm that the company-managed PyPI identity ` dev@cometapi.com ` owns or can
222- create the unscoped PyPI package ` cometapi ` , and configure the
223- Trusted Publisher for the exact repository, workflow, and ` pypi `
224- environment.
225- 2 . Confirm the protected ` COMETAPI_KEY ` , the approved ` COMETAPI_LIVE_MODEL ` ,
226- and explicit authorization for the documented four-request, 16-token, 30-second,
227- concurrency-one, stop-on-failure budget before creating the GitHub
228- prerelease.
229- 3 . Replace the pre-release availability notice and source-installation text in
230- ` README.md ` with the release-neutral, maintainer-confirmed sentence
231- “` 0.1.0a1 ` is approved for PyPI publication.” Date the ` 0.1.0a1 ` heading in
232- ` CHANGELOG.md ` , remove its candidate/unpublished wording, and rerun every
208+ default-branch CI, the one-time Public Preview live smoke, and Registry Alpha
209+ are completed historical steps. Do not recreate or repeat them. This checklist
210+ records the dependency order that was executed; it grants no standing
211+ permission for later remote mutations, live requests, release actions, or
212+ registry actions.
213+
214+ The recorded Public Preview invariants were re-audited before release:
215+ protected ` main ` and version tags, immutable releases, Private Vulnerability
216+ Reporting, the ` live-smoke ` and ` pypi ` environment boundaries,
217+ ` LIVE_SMOKE_ENABLED=false ` , absent ` CODEOWNERS ` , and disabled Release Please.
218+ Maintainers then completed these steps in order:
219+
220+ 1 . Confirmed company-managed PyPI ownership and configured the Trusted
221+ Publisher for the exact repository, workflow, and ` pypi ` environment.
222+ 2 . Confirmed the protected ` COMETAPI_KEY ` , approved live model, and explicit
223+ authorization for the documented four-request, 16-token, 30-second,
224+ concurrency-one, stop-on-failure budget.
225+ 3 . Finalized the dated changelog and prerelease documentation and reran every
233226 candidate verification gate, including
234227 ` uv run python scripts/check_version.py --expected 0.1.0a1 --require-changelog --require-releasable-docs ` .
235- 4 . Review the exact candidate and create the immutable SemVer recovery tag
228+ 4 . Reviewed the exact candidate and created the immutable SemVer recovery tag
236229 ` v0.1.0-alpha.1+recovery.1 ` and corresponding GitHub prerelease. GitHub
237230 permanently reserved ` v0.1.0-alpha.1 ` after its immutable release reached
238231 OIDC publication but failed before PyPI accepted any distribution. The
@@ -241,12 +234,11 @@ remaining authorized steps in order:
241234 for later releases. Keep Release Please disabled until a separate reviewed
242235 and tested ` last-release-sha ` bridge establishes this recovery commit as its
243236 previous-release boundary.
244- 5 . Allow the release workflow to prove ` immutable=true ` , resolve the tag to the
245- checked-out commit, verify that commit is reachable from the protected
246- default branch, and run the bounded protected live suite against that exact
247- commit. Only successful completion makes the protected PyPI approval
248- eligible; approve that job after reviewing its retained artifact digests.
249- 6 . Verify publication, provenance, public artifact identity and digest, clean
237+ 5 . The release workflow proved ` immutable=true ` , resolved the tag to the
238+ checked-out commit, verified that commit was reachable from the protected
239+ default branch, and ran the bounded protected live suite against that exact
240+ commit before the protected PyPI approval was granted.
241+ 6 . Verified publication, provenance, public artifact identity and digest, clean
250242 installation, import, and the public-registry mocked-call smoke.
251243
252244Missing credentials, model/budget approval, environments, publisher
@@ -261,6 +253,28 @@ The version checker must normalize the SemVer tag and PEP 440 package spelling
261253to the same ` 0.1.0a1 ` value across the tag, release manifest, package metadata,
262254changelog, GitHub release, wheel, and source distribution.
263255
256+ ### Completed Registry Alpha evidence
257+
258+ - Metadata [ PR #16 ] ( https://github.com/cometapi-dev/cometapi-python/pull/16 )
259+ merged as ` 6344c2d0e2e975360b42c887275c1950b82918ee ` ; recovery contract
260+ [ PR #17 ] ( https://github.com/cometapi-dev/cometapi-python/pull/17 ) merged as
261+ release commit ` 31b68904141489ca04932edbf305ccf88af09372 ` .
262+ - Annotated tag ` v0.1.0-alpha.1+recovery.1 ` has tag object
263+ ` fdc4a6cce31f4534f83903f3f95e7757a4d4049f ` , peels to the release commit,
264+ and identifies the
265+ [ immutable GitHub prerelease] ( https://github.com/cometapi-dev/cometapi-python/releases/tag/v0.1.0-alpha.1%2Brecovery.1 ) .
266+ - [ Release workflow run 30261746138] ( https://github.com/cometapi-dev/cometapi-python/actions/runs/30261746138 )
267+ passed the exact artifact gates, authorized protected live smoke, protected
268+ environment approval, PyPI OIDC Trusted Publishing, provenance check, public
269+ digest comparison, clean registry installation, imports, and mocked-call
270+ smoke.
271+ - The exact [ PyPI release] ( https://pypi.org/project/cometapi/0.1.0a1/ ) has wheel
272+ SHA256 ` a6820347317943ca22f7632acbe354dd992f31a122a6172dfe45b57960e3a093 `
273+ and source-distribution SHA256
274+ ` 98d86829ef14771e8b7ec180d452c6638289f49c14a39b7207be5c47cb64cde7 ` .
275+ - ` LIVE_SMOKE_ENABLED=false ` . Release Please remains disabled until a separate
276+ reviewed and tested ` last-release-sha ` bridge is merged.
277+
264278## Stable release sequence
265279
266280``` text
0 commit comments