You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Heartwood 0.3.0 has protected releases, immutable artifacts, attestations, support guidance, and security ownership.
Stable release assurance still lacks complete bills of materials, third-party notices, cryptographic signing, and maintainer continuity controls.
Solution
Generate software bills of materials and third-party notices for native, web, Python, and container artifacts.
Sign release images and supported native assets and publish verification instructions.
Define release, security, Skill review, recovery, and succession authority.
Keep support claims linked to automated checks, live evidence, or explicit institutional decisions.
Acceptance Criteria
Distributed artifacts have verifiable provenance, bills of materials, and notices.
Signing and verification work from a clean environment.
Maintainer and recovery responsibilities have named ownership.
OpenHands upgrades cannot bypass the shared conformance gate.
Release documentation states evidence and limitations conservatively.
Additional Context
Documentation publication is complete in #36.
Audit append recovery, schema migration, and authoritative audit checkpointing are owned by #45; this issue coordinates with that work but does not block it.
Registry retention is tracked in #47 and upstream GPU advisories in #34.
Code of Conduct
I agree to follow this project's Code of Conduct and Contributing Guidelines
Problem
Heartwood
0.3.0has protected releases, immutable artifacts, attestations, support guidance, and security ownership.Stable release assurance still lacks complete bills of materials, third-party notices, cryptographic signing, and maintainer continuity controls.
Solution
Acceptance Criteria
Additional Context
Documentation publication is complete in #36.
Audit append recovery, schema migration, and authoritative audit checkpointing are owned by #45; this issue coordinates with that work but does not block it.
Registry retention is tracked in #47 and upstream GPU advisories in #34.
Code of Conduct