# codex-sdlc 0.3.0 local beta evidence

- Candidate date: 2026-09-10
- Status: local package and plugin candidate; no public release claim
- Environment: macOS 26.6.2 arm64, Node.js 24.19.0, npm 11.17.0
- Runtime tarball: `/tmp/codex-sdlc-artifacts/codex-sdlc-0.3.0.tgz`
- Runtime tarball SHA-256: `852cd1e18ce2acba973f30eb51378fed99edfd665794e318d6b864540adbcde9`

## Passed evidence

| Scope | Result | Evidence |
| --- | --- | --- |
| TypeScript and unit verification | Passed | `npm run verify`; 5 test files, 20 tests |
| Clean source reproduction | Passed | `npm ci --ignore-scripts` and `npm run verify` passed in `/private/tmp/codex-sdlc-source-build.0MtmIy` without parent-workspace modules |
| Package allowlist | Passed | `npm pack`; runtime, schemas, workflows, policies, presets, templates, skills, plugin manifest, README, and frozen compatibility assets only |
| Upgrade dry-run | Passed | Reported the bounded file set and planned backup without modifying the temporary 0.2.0 project |
| 0.2.0 to 0.3.0 upgrade | Passed | Upgraded `/tmp/codex-sdlc-030-final.LpAG2b/project` with the exact final tarball, restored the pinned 0.3.0 runtime, and passed `doctor` and `validate-config` |
| Upgrade rollback | Passed | Selected the latest ready upgrade backup, restored the 0.2.0 runtime selection and managed files, restored dependencies, and passed the 0.2.0 `doctor` |
| Uninstall dry-run | Passed | Reported the bounded removal and planned backup without changing the installation |
| Reversible uninstall | Passed | Removed managed framework files while preserving `.sdlc/project.yaml`, requests, runs, and backups; rollback restored 0.3.0 and passed `doctor` and `validate-config` |
| Repository edit ownership | Passed | New installations record whether `AGENTS.md` and `.gitignore` were created and which ignore entries were added; uninstall preserved pre-existing content |
| Rollback drift protection | Passed | Rollback refused to overwrite a managed runtime file changed after upgrade |
| Backup path validation | Passed | Rollback rejected a tampered backup manifest containing an unexpected path |
| Plugin manifest | Passed | Required plugin-creator `validate_plugin.py` validator for source and staged marketplace copies |
| Setup skill | Passed | Required skill-creator `quick_validate.py` validator after lifecycle guidance was added |

## Lifecycle behavior

Every applied upgrade or uninstall writes a local snapshot under `.sdlc/backups/<backup-id>/`. Its manifest records SHA-256 state before and after the operation. Rollback checks the current state against the recorded post-operation state before restoring files. Runtime dependencies and generated package locks are not copied into backups; `node .sdlc/runtime.cjs restore` recreates them after upgrade or rollback.

Upgrade preserves repository-specific project settings and commands while updating the required framework identity, runtime selection, managed assets, and permissions generated from configured application roots. Uninstall preserves project configuration, requests, runs, evidence, application code, and backups. For installations created before repository-edit ownership metadata existed, uninstall conservatively preserves `.gitignore` entries whose ownership cannot be proven.

## Remaining release work

The lifecycle currently supports the `codex-sdlc` schema-family-1 installation shape. Format-aware migration from the frozen legacy identity and future schema families is not implemented. The local backup is a rollback mechanism inside the repository, not an external disaster-recovery backup.

Application source scaffolding, PostgreSQL/Redis infrastructure generation, a complete Product Owner-accepted synthetic feature, Linux and Windows qualification, final-byte skill evaluations, registry ownership, license selection, a public repository, npm publication, and marketplace submission remain unverified. The npm package stays `private` to prevent accidental publication.

The clean production tarball installation used cached dependencies. The development dependency tree previously reported two moderate findings; resolve or formally accept them before a public release.

No public distribution channel or release milestone is claimed from this local evidence.
