- Confirm copyright ownership and third-party license compatibility.
- Confirm every maintained feature phase has a completed
documents/phases/PHASE-NNN-*.mdrecord. - Run
python scripts/manage_documents.py check,python scripts/test_documents.py, and the feature documentation policy. - Run
python scripts/forensic_audit.py --root . --full. - Run the online dependency audit in CI.
- Test a clean installation on an isolated Ubuntu Server 24.04 LTS VPS.
- Verify external inbound SMTP, login, authorization boundaries, live updates, safe HTML, and attachment downloads.
- Build with
python scripts/build_release.py --root . --version 1.3.4-rc.2and verify the ZIP/checksum withpython scripts/verify_release.py. - Merge the intended release commit to
mainand require a successfulmainpush CI run for the exact SHA. - Create the matching
v<version>tag on the currentmainhead and push that tag. Do not create a release manually first. - The tag workflow validates tag/version/package identity, exact
mainhead, successfulmainCI, and release absence; it then builds/verifies the deterministic archive and creates the GitHub Release with ZIP/SHA assets. - Verify the published release classification and attached checksum. RC versions must be pre-releases; stable versions are normal/latest releases.
workflow_dispatch is intentionally build/validation-only. Release automation never edits or clobbers an existing release. A version-marked source baseline is not a production-ready release until the clean-VPS and remaining operational acceptance gates pass.