Skip to content

[JAVA-03] Publish signed prerelease and stable artifacts with sandbox conformance #4

Description

@jaavid

Background

CoreLink is one product across multiple implementation repositories. This work is owned by sdk-java under EPIC-05.

Goal

Publish reproducible, signed Java prerelease/stable artifacts with retained sandbox/conformance evidence and immutable contract provenance.

Parent

  • Primary Product Epic:EPIC-05
  • Backlog ID:JAVA-03

Scope

  • Package/version the accepted JAVA-02 SDK surface.
  • Sign/publish artifacts through the organization release/provenance path.
  • Verify compatibility against MOCK-03 or an equivalent accepted sandbox.
  • Distinguish prerelease, RC and stable support claims.
  • Retain package, dependency, contract and conformance evidence.

Out of Scope

  • Treating artifact publication as product-runtime acceptance.
  • Stable claims for Java behavior not accepted by JAVA-02/conformance gates.
  • Bypassing organization release/provenance policy.

Acceptance Criteria

  • Artifact is reproducible from immutable source and contract revisions.
  • Signing/provenance satisfies the accepted [JAVA-03] Publish signed prerelease and stable artifacts with sandbox conformance #4 release path.
  • Positive, denied, malformed, retry and recovery behavior passes against MOCK-03 or equivalent accepted sandbox.
  • Published metadata identifies SDK, contract and sandbox revisions and maturity.
  • Prerelease versus stable maturity is explicit.
  • Documentation/release notes are reconciled.
  • Retained evidence advances EPIC-05 Java release/conformance criteria.

Dependencies and acceptance state

  • Execution prerequisite:JAVA-02 accepted SDK behavior/integration guidance.
  • Conformance prerequisite:MOCK-03 or equivalent accepted sandbox/package revision.
  • Release-governance prerequisite:GH-04 accepted reusable CI/release/provenance path before supported publication claims.
  • Blocks: DOCS-04 Java release guidance, WEB-03 supported-tool claims, and EPIC-05 Java release acceptance.
  • Current dependency state: See the CoreLink Product organization Project.

Planning Metadata

  • Type: Technical Task
  • Priority snapshot: P1
  • Product milestone snapshot: Release Candidate
  • Domain snapshots: sdk, deployment
  • Area snapshot: package
  • Complexity: M
  • Created in status: Triage
  • Current status and DRI: See the CoreLink Product organization Project.
  • Intended repository labels:type:technical-task

Definition of Done

  • Acceptance criteria demonstrated.
  • Artifact provenance/signing and reproducibility are verified.
  • Required conformance checks pass on version-identifiable dependencies.
  • Contract/security/tenant implications are reconciled.
  • Documentation/release notes are updated.
  • Pull request(s), package revision and retained evidence are linked.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    type:technical-taskImplementation or engineering enablement work

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions