← Files codex-sdlcARCHIVED FILE

docs/releases/0.3.0.md

2.61 KB · Oct 5, 2026 · 18:34 UTC

↓ Download file

# codex-sdlc 0.3.0 release evidence

- Candidate date: 2026-09-10
- Environment qualified: macOS 26.6.2 arm64, Node.js 24.19.0, npm 11.17.0
- Final runtime tarball: `/tmp/codex-sdlc-release-final/codex-sdlc-0.3.0.tgz`
- Final runtime tarball SHA-256: `47c3fddfa995cadc6708dcd7010e4711c36ca8a015bc0f15330a5ae8d04c8c33`
- Linux and Windows qualification: deferred by release decision

## Package verification

| Check | Result |
| --- | --- |
| TypeScript, tests, and build | Passed: 6 files, 24 tests |
| Production dependency audit | Passed: 0 vulnerabilities |
| Complete dependency audit | Passed: 0 vulnerabilities |
| npm publication dry run | Passed for `codex-sdlc@0.3.0`, public access |
| Package allowlist | Passed: 157 files, 116.2 kB compressed |
| Portable Agent Plugins manifest | Passed against the public 1.0.0 schema |
| Codex plugin manifests | Passed for source and staged marketplace copies |
| Skills | Passed for all six packaged skills |

## Independent-agent delivery

Run `AGENTTEST-001` installed and upgraded from the exact release tarball in an unrelated web-only repository. Separate PM, BA, frontend, and QC agents performed the delivery through the repository runtime.

| Stage | Result |
| --- | --- |
| Intake and requirements | Passed; 14 facts/claims, 5 requirements, 10 acceptance criteria |
| Frontend implementation | Passed; authorized source, test, documentation, and summary files only |
| Frontend evidence | Passed: `sdlc_test` and `sdlc_typecheck` |
| PM review and integration | Passed; fresh test, typecheck, and configuration evidence |
| Independent QC | Passed: 12/12 cases, all requirements and acceptance criteria, zero defects |
| Product Owner review | Accepted |
| Final run validation | Passed with no diagnostics at authority version 49 |

The run exercised typed assignment publication, authority upgrades and repair, runtime-owned evidence, exact changed-file authority, strict delivery-report reconciliation, role-separated review, integration, QC, finalization, and Product Owner disposition.

## Lifecycle verification

Upgrade, rollback, and uninstall were exercised against temporary installations. Backups preserve repository configuration and delivery history, rollback rejects drift and unsafe backup paths, and uninstall preserves repository-owned content. The final independent run also upgraded the same-version runtime repeatedly as defects were corrected, preserving its authority history throughout.

## Deferred qualification

Linux and Windows verification remain outside this release evidence. The GitHub verification workflow intentionally runs on macOS until those environments are qualified.

SHA-256: a971353c4fe0c373ddc8da5e24bf06880afaf7689137b44d22de675af819d736