-
Notifications
You must be signed in to change notification settings - Fork 0
[G18] Package signed releases and reproducible distribution #18
Copy link
Copy link
Open
Labels
agent:luna-maxCanonical primary route: gpt-luna-max (gpt-5.6-luna, max reasoning)Canonical primary route: gpt-luna-max (gpt-5.6-luna, max reasoning)priority:P1Required delivery workRequired delivery workrelease:distributionApproved delivery sequencing; does not change acceptance or dependency gatesApproved delivery sequencing; does not change acceptance or dependency gatesrisk:mediumBounded contract and validation reviewBounded contract and validation reviewtype:implementationBounded implementation goal with TDD evidenceBounded implementation goal with TDD evidence
Milestone
Description
Activity
Metadata
Metadata
Assignees
Labels
agent:luna-maxCanonical primary route: gpt-luna-max (gpt-5.6-luna, max reasoning)Canonical primary route: gpt-luna-max (gpt-5.6-luna, max reasoning)priority:P1Required delivery workRequired delivery workrelease:distributionApproved delivery sequencing; does not change acceptance or dependency gatesApproved delivery sequencing; does not change acceptance or dependency gatesrisk:mediumBounded contract and validation reviewBounded contract and validation reviewtype:implementationBounded implementation goal with TDD evidenceBounded implementation goal with TDD evidence
Type
Projects
- StatusShow more project fieldsBacklog
Goal
Produce verifiable macOS ARM64 release artifacts with install/upgrade/rollback instructions and accurate preview/stability labeling.
Create one active Codex goal from the statement above when this issue is dispatched. The Project Goal field is a work specification; it does not start an agent. Do not invent a token budget.
Execution contract
Use one issue branch/worktree and one focused PR. Independent Luna max review is required for authentication, protocol, concurrency, resource ownership, cleanup or service identity boundaries; other changes need independent contract review. Model fields are routing instructions, not GitHub user assignments.
Dependencies
Dependencies must be Done before implementation begins. A new issue is not blocked simply because its future evidence has not been collected.
Scope
Build packaging/checksums/provenance/SBOM/license notices/Homebrew formula plan; signing/notarization only with user-owned credentials when available.
TDD and failure evidence
Capture a meaningful failing case before the implementation, then green evidence and relevant refactor checks. Tooling/prose-only work uses appropriate negative checks without artificial application tests. Live/runtime profiles require reviewed commits, a dedicated trusted test environment and explicit authorization for the concrete experiment. Public PR CI uses hosted environments without credentials. Planned or skipped tests never count as passed.
Acceptance criteria
Safety invariants
Preserve existing manual runners; no global Docker prune/context switching, broad process kill, implicit App enrollment, busy-job cancellation during ordinary scale-down or transparent workflow replay. Use only verifiably owned resources. Keep management credentials and raw secret-bearing SDK errors out of worker environments, logs, fixtures and commits; per-worker JIT transport follows G01. Native pools remain trusted-only.
Design references