Skip to content

[JAVA-03] Publish signed prerelease and stable artifacts with sandbox conformance #4

Description

@jaavid

Background

CoreLink is one product across multiple implementation repositories. This work is owned by sdk-java under EPIC-05.

Goal

Publish reproducible, signed Java prerelease/stable artifacts with retained sandbox/conformance evidence and immutable contract provenance.

Parent

  • Primary Product Epic: EPIC-05
  • Backlog ID: JAVA-03

Scope

  • Package/version the accepted JAVA-02 SDK surface.
  • Sign/publish artifacts through the organization release/provenance path.
  • Verify compatibility against MOCK-03 or an equivalent accepted sandbox.
  • Distinguish prerelease, RC and stable support claims.
  • Retain package, dependency, contract and conformance evidence.

Out of Scope

  • Treating artifact publication as product-runtime acceptance.
  • Stable claims for Java behavior not accepted by JAVA-02/conformance gates.
  • Bypassing organization release/provenance policy.

Acceptance Criteria

  • Artifact is reproducible from immutable source and contract revisions.
  • Signing/provenance satisfies the accepted [JAVA-03] Publish signed prerelease and stable artifacts with sandbox conformance #4 release path.
  • Positive, denied, malformed, retry and recovery behavior passes against MOCK-03 or equivalent accepted sandbox.
  • Published metadata identifies SDK, contract and sandbox revisions and maturity.
  • Prerelease versus stable maturity is explicit.
  • Documentation/release notes are reconciled.
  • Retained evidence advances EPIC-05 Java release/conformance criteria.

Dependencies and acceptance state

  • Execution prerequisite: JAVA-02 accepted SDK behavior/integration guidance.
  • Conformance prerequisite: MOCK-03 or equivalent accepted sandbox/package revision.
  • Release-governance prerequisite: GH-04 accepted reusable CI/release/provenance path before supported publication claims.
  • Blocks: DOCS-04 Java release guidance, WEB-03 supported-tool claims, and EPIC-05 Java release acceptance.
  • Current dependency state: See the CoreLink Product organization Project.

Planning Metadata

  • Type: Technical Task
  • Priority snapshot: P1
  • Product milestone snapshot: Release Candidate
  • Domain snapshots: sdk, deployment
  • Area snapshot: package
  • Complexity: M
  • Created in status: Triage
  • Current status and DRI: See the CoreLink Product organization Project.
  • Intended repository labels: type:technical-task

Definition of Done

  • Acceptance criteria demonstrated.
  • Artifact provenance/signing and reproducibility are verified.
  • Required conformance checks pass on version-identifiable dependencies.
  • Contract/security/tenant implications are reconciled.
  • Documentation/release notes are updated.
  • Pull request(s), package revision and retained evidence are linked.

Metadata

Metadata

Assignees

No one assigned

    Labels

    type:technical-taskImplementation or engineering enablement work

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions