← Files codex-sdlcARCHIVED FILE

docs/releases/0.2.0-local-beta.md

3.76 KB · Oct 5, 2026 · 18:34 UTC

↓ Download file

# codex-sdlc 0.2.0 local beta evidence

- Candidate date: 2026-09-10
- Status: local package and plugin candidate; no public release claim
- Environment: macOS 26.6.2 arm64, Node.js 24.19.0, npm 11.17.0
- Runtime tarball: `/tmp/codex-sdlc-artifacts/codex-sdlc-0.2.0.tgz`
- Runtime tarball SHA-256: `e003d769713ac14763358e8515d1dec26a6d4108467d1653634acdbe36386a02`

## Passed evidence

| Scope | Result | Evidence |
| --- | --- | --- |
| TypeScript and unit verification | Passed | `npm run verify`; 4 test files, 16 tests |
| Clean source reproduction | Passed | `npm ci --ignore-scripts` and `npm run verify` passed in `/private/tmp/codex-sdlc-source-build.AtuSzF` without parent-workspace modules |
| Package allowlist | Passed | `npm pack`; runtime, schemas, workflows, policies, presets, templates, skills, plugin manifest, README, and frozen compatibility assets only |
| Project initialization | Passed | Web-only Next.js, mobile-only Flutter, combined Go/Next.js/Flutter, generic backend, dry-run, byte-idempotence, instruction preservation, conflict refusal, and root isolation |
| Technology presets | Passed | Go, Next.js, and Flutter generated native test/typecheck/build command records; PostgreSQL and Redis generated the expected data configuration and lock selections |
| Clean tarball install | Passed | Installed the exact final tarball into `/tmp/codex-sdlc-preset-smoke.M1x3kM` without relying on source-tree modules |
| Pinned project restore | Passed | A combined fixture restored the generated `file:/tmp/codex-sdlc-artifacts/codex-sdlc-0.2.0.tgz` runtime and passed `validate-config` |
| Setup diagnostics | Passed | `doctor` reported ready for web-only, mobile-only, and combined preset fixtures |
| Lifecycle smoke test | Passed | Created and validated `WEBPRESET-001`; its web-only plan omits backend implementation and API-contract review tasks |
| Plugin manifest | Passed | Required plugin-creator `validate_plugin.py` validator |
| Local marketplace staging | Passed | `npm run build:marketplace` created the isolated marketplace and its staged plugin passed plugin validation |
| Six bundled skills | Passed | Required skill-creator `quick_validate.py` validator for setup, PM, BA, backend, frontend, and QC |
| Brand isolation | Passed | New runtime/assets/skills reject legacy identity in tests; frozen compatibility assets require it |
| Source preservation | Passed | No tracked diff under the active `.sdlc/`, `scripts/sdlc/`, or `.agents/skills/` source paths |

The packed artifact was rebuilt after the setup-mode, technology-preset, documentation, and validation changes. Recompute and replace the tarball digest above whenever package bytes change.

## Remaining release work

This candidate configures existing application directories; it does not scaffold Go, Next.js, or Flutter source projects or provision PostgreSQL and Redis services. Preset commands use conventional tool and package-script names and may need repository-specific adjustment. Its new documents still use schema family 1; the frozen v1 assets are packaged but format-aware legacy dispatch, upgrade, rollback, and uninstall are not implemented.

Actual plugin installation in a fresh Codex session, independent role dispatch, a complete Product Owner-accepted synthetic feature, Linux and Windows qualification, final-byte skill evaluations, registry ownership, license selection, a public repository, npm publication, and marketplace submission remain unverified. The npm package stays `private` to prevent accidental publication.

The clean production tarball installation reported zero vulnerabilities. The clean development dependency installation reported two moderate vulnerabilities; resolve or formally accept them before a public release.

No public distribution channel or release milestone is claimed from this local evidence.

SHA-256: d15d32812d46dad0327380242c38dcebdb6c06c459a2dad4c6e0c631c16aa96c