## Parent [Deliver Chrome Debugger Bridge from authorized MVP to public release](https://github.com/dvcol/chrome-debugger-bridge/issues/1) ## What to build Converge all package, browser, integration, recovery, and security checks into the immutable-action CI graph required for release. ## Acceptance criteria - [ ] Pull requests run frozen installation, workspace policy, lint, typecheck, unit, browser, extension end-to-end, build, pack, consumer, example, and Conventional Commit validation. - [ ] Vitest Node, jsdom, Browser Mode, extension orchestration, and package-consumer projects own explicit environments and aligned versions. - [ ] Real-Chrome failures retain useful traces without leaking protected data. - [ ] CodeQL and every GitHub Action are pinned to immutable commit SHAs, and publication permissions are absent from test and build jobs. - [ ] The graph proves the same failures are introduced by the branch before treating any failure as pre-existing. ## Blocked by - [Prove multi-client security and recovery in real Chrome](https://github.com/dvcol/chrome-debugger-bridge/issues/20) - [Verify generic host and client examples from packed packages](https://github.com/dvcol/chrome-debugger-bridge/issues/27) - [Verify the packed Devframe example end-to-end](https://github.com/dvcol/chrome-debugger-bridge/issues/31) - [Verify the packed MCP example against supported SDK versions](https://github.com/dvcol/chrome-debugger-bridge/issues/36)
Parent
Deliver Chrome Debugger Bridge from authorized MVP to public release
What to build
Converge all package, browser, integration, recovery, and security checks into the immutable-action CI graph required for release.
Acceptance criteria
Blocked by