Skip to content

Complete Stable Release Assurance And Maintainer Governance #48

Description

@PSchmiedmayer

Problem

Heartwood 0.3.0 has protected releases, immutable artifacts, attestations, support guidance, and security ownership.
Stable release assurance still lacks complete bills of materials, third-party notices, cryptographic signing, and maintainer continuity controls.

Solution

  • Generate software bills of materials and third-party notices for native, web, Python, and container artifacts.
  • Sign release images and supported native assets and publish verification instructions.
  • Define release, security, Skill review, recovery, and succession authority.
  • Keep the shared OpenHands conformance gate required for runtime upgrades, including the upgrade tracked in Upgrade The OpenHands Runtime And Adopt Stable SDK Capabilities #123.
  • Keep support claims linked to automated checks, live evidence, or explicit institutional decisions.

Acceptance Criteria

  • Distributed artifacts have verifiable provenance, bills of materials, and notices.
  • Signing and verification work from a clean environment.
  • Maintainer and recovery responsibilities have named ownership.
  • OpenHands upgrades cannot bypass the shared conformance gate.
  • Release documentation states evidence and limitations conservatively.

Additional Context

Documentation publication is complete in #36.
Audit append recovery, schema migration, and authoritative audit checkpointing are owned by #45; this issue coordinates with that work but does not block it.
Registry retention is tracked in #47 and upstream GPU advisories in #34.

Code of Conduct

  • I agree to follow this project's Code of Conduct and Contributing Guidelines

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    • Status
      Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions