From 2b3f8b45cb7054d8ddd769939326b53dc3061692 Mon Sep 17 00:00:00 2001 From: Ramesh Padmanabhaiah <22363102+codeforester@users.noreply.github.com> Date: Mon, 28 Sep 2026 18:01:50 +0530 Subject: [PATCH] docs(release): finalize v0.2.0 public bootstrap --- README.md | 28 +++++++++++++--------------- docs/first-success.md | 4 ++-- docs/release.md | 15 ++++++--------- docs/v0.2.0-readiness.md | 35 ++++++++++++++++++----------------- tests/public_install_test.sh | 5 ++++- 5 files changed, 43 insertions(+), 44 deletions(-) diff --git a/README.md b/README.md index 94a0b67..d7149bb 100644 --- a/README.md +++ b/README.md @@ -17,8 +17,8 @@ Reference Base-managed project and representative demo environment. Each path states prerequisites, a completion check, and one safe recovery. This demo is a **curated representative subset**, not every Base contract. Current-source paths use the [supported inputs](.release/supported-dependencies.json); -the historical-release Quick Start below installs older versions until v0.2.0 -publication. Neither path implies native Windows or a full Linux demo. +the release Quick Start below installs the verified v0.2.0 assets. Neither path +implies native Windows or a full Linux demo. This repository is the public reference project for Base-managed repositories. It demonstrates Base on a compact but credible project shape: small enough to @@ -90,35 +90,33 @@ in the Base repository. ## Quick Start -Until v0.2.0 publishes verified installer assets, use this interim, immutable -bootstrap script from reviewed source commit `96f8e6d0c016aaf73e1a8c448ac92c9222a5aced`. -It installs **Base v1.8.0 and base-demo v0.1.0**, not current `main`. -Run this macOS quick start in a temporary directory; inspect the script before -execution if required by your environment: +Use the verified v0.2.0 release asset. It installs **Base v1.9.0 and +base-demo v0.2.0** at the exact commits recorded in the release BOM. Run this +macOS quick start in a temporary directory; inspect the script before execution +if required by your environment: ```bash bootstrap_dir="$(mktemp -d)" ( cd "$bootstrap_dir" || exit 1 - curl -fsSL https://raw.githubusercontent.com/basefoundry/base-demo/96f8e6d0c016aaf73e1a8c448ac92c9222a5aced/install.sh -o install.sh && - printf '%s install.sh\n' dc8728510651c8b59fcc4a99dbf12e7e7c152858a99b745de90cdb7210e85d82 | shasum -a 256 -c - && + curl -fsSL https://github.com/basefoundry/base-demo/releases/download/v0.2.0/install.sh -o install.sh && + printf '%s install.sh\n' fab41851d0f7b3f0d533cc7fbc336cde851332e8cb4382a100fe1aeebbde593d | shasum -a 256 -c - && RUN_UPDATE_PROFILE=false bash install.sh ) ``` -The checksum gates execution. This reviewed script verifies its Base installer +The checksum gates execution. This reviewed release asset verifies its Base installer and both checkout commits. Fresh installs use `~/work`; clean existing checkouts at those exact commits are reused, while dirty or divergent checkouts fail without being pulled, reset, detached, or switched. This command opts out of shell-profile updates; setup still installs dependencies and project tools. -An existing developer workspace should use the developer route below instead -of deleting or resetting its checkouts to make this release route pass. +An existing developer workspace should use the developer route below instead of +deleting or resetting its checkouts to make this release route pass. The historical **v0.1.0/install.sh does not provide these guarantees**: it uses a moving Base installer, permits an absent checksum, and can pull an existing -checkout. Do not substitute that old script for the checksum-verified input -above. [Release preparation #303](https://github.com/basefoundry/base-demo/issues/303) -tracks replacing this interim URL with the verified v0.2.0 release asset. +checkout. Do not substitute that old script for the checksum-verified v0.2.0 +asset above. Contributors with current source peer checkouts under one workspace should opt into the local developer path explicitly (from the current base-demo checkout): diff --git a/docs/first-success.md b/docs/first-success.md index 8786c7b..06c2103 100644 --- a/docs/first-success.md +++ b/docs/first-success.md @@ -16,8 +16,8 @@ Need Base first? Follow the canonical [adopter golden path](https://github.com/b for install and consent decisions, then select the stable inputs above. That document is pinned for reference, not an instruction to substitute its candidate for the stable runtime. The README's checksum-verified [Quick Start](../README.md#quick-start) -is a separate historical Base 1.8/demo 0.1 route until v0.2.0 is published; do not -mix its results with current-source evidence or reset a divergent checkout. +is the published Base 1.9/demo 0.2 release route; do not mix its results with +moving-source development evidence or reset a divergent checkout. Ubuntu/Debian (including WSL2 on its native filesystem) supports Base setup and the CI-safe read-only project-health path, not the full demo loop. Native Windows diff --git a/docs/release.md b/docs/release.md index 2cd99c1..2fdb482 100644 --- a/docs/release.md +++ b/docs/release.md @@ -73,20 +73,17 @@ access to Actions evidence during verification. The current source `install.sh` release path is pinned to reviewed immutable inputs. These guarantees do **not** apply to the historical v0.1.0 installer. -The README temporarily downloads the checksum-verified script from commit -`96f8e6d0c016aaf73e1a8c448ac92c9222a5aced`; it still installs the older release -Base v1.8.0/demo v0.1.0 checkouts, not the current supported input selection -or that source commit as the demo checkout. -Before closing [#303](https://github.com/basefoundry/base-demo/issues/303), replace -the README's interim script URL and digest with the new verified release asset, -update the stated consumed versions, and rerun `bash tests/public_install_test.sh`. +The README downloads the checksum-verified `v0.2.0` release asset. It installs +the supported Base v1.9.0 and base-demo v0.2.0 checkouts recorded below. The +release asset is finalized from the annotated tag target, so its self-commit +pin is the exact immutable v0.2.0 commit. The consumed inputs are: - Base installer: the version, full commit and SHA-256 selected by `.release/supported-dependencies.json`, materialized in current `install.sh`; -- base-demo checkout: release ref `v0.1.0` and commit - `b8ac2ae490e4965b8131195a11377fd0bd787daf`. +- base-demo checkout: release ref `v0.2.0` and commit + `c5709ed8dfa623539e9c326554712490e14f1774`. When preparing a release, update `PROJECT_RELEASE_REF` in the reviewed `install.sh` source to the new release tag. Keep `PROJECT_RELEASE_COMMIT` as a diff --git a/docs/v0.2.0-readiness.md b/docs/v0.2.0-readiness.md index c4da946..5a32bb7 100644 --- a/docs/v0.2.0-readiness.md +++ b/docs/v0.2.0-readiness.md @@ -1,10 +1,12 @@ # v0.2.0 release-owner handoff -Status: **preparation only; not approved for publication**. -The core implementation train does not create a version tag, publish assets, -waive independent review, or start a bake window on the owner's behalf. -[#303](https://github.com/basefoundry/base-demo/issues/303) remains open until -the publication and downloaded-asset checks below are complete. +Status: **published and independently artifact-verified on 2026-09-28**. +The release uses annotated tag `v0.2.0` at +`c5709ed8dfa623539e9c326554712490e14f1774`. The governed release workflow +exposed a checkout bug that treated the annotated tag as lightweight; the +finalized assets were therefore verified locally from the exact tag target and +published with the same immutable BOM and installer bytes. Follow-up workflow +repair is tracked in [#320](https://github.com/basefoundry/base-demo/issues/320). ## Intended scope and inputs @@ -104,17 +106,16 @@ that flag is only a self-identity fixture operation, not compatibility proof. The strict BOM publication checker is expected to reject the tracked `not_tested` input. Validate the finalized external BOM instead. -Because the published version is still 0.1.0 during core-train preparation, -any rehearsal at that stage tests mechanics only. It must not be published as -another 0.1.0 release or called the final 0.2.0 candidate. +The earlier 0.1.0 rehearsal tested delivery mechanics only. It was not used as +the v0.2.0 compatibility evidence. -## After separately authorized publication +## Publication verification -Download `release-bom.json`, `release-bom.sha256`, `install.sh` and -`install.sh.sha256` from the new release into a fresh directory. Independently -verify checksums, annotated tag target, finalized self-identity and exact -provider inputs. Re-run the strict BOM gate and inspect the downloaded -installer pins. Update the README public URL/digest and consumed versions to -those actual assets, run `tests/public_install_test.sh`, and rehearse that exact -public command. Record the immutable demo identity for the Base-owned -compatibility BOM. Only then close #303 and mark the release complete. +Downloaded `release-bom.json`, `release-bom.sha256`, `install.sh` and +`install.sh.sha256` were independently checked against the finalized outputs. +The strict BOM gate passed with compatibility run +https://github.com/basefoundry/base-demo/actions/runs/36420902540; the installer +fixtures passed against the downloaded asset. This PR updates the README public +URL/digest and consumed versions, and reruns `tests/public_install_test.sh`. +The immutable demo identity is ready for the Base-owned v1.10 compatibility +BOM. diff --git a/tests/public_install_test.sh b/tests/public_install_test.sh index 02fdf22..72a005e 100644 --- a/tests/public_install_test.sh +++ b/tests/public_install_test.sh @@ -13,7 +13,10 @@ from pathlib import Path section = Path(sys.argv[1]).read_text().split('## Quick Start\n', 1)[1] block = section.split('```bash\n', 1)[1].split('```', 1)[0] -urls = re.findall(r'curl -fsSL (https://raw\.githubusercontent\.com/basefoundry/base-demo/[0-9a-f]{40}/install\.sh) -o install\.sh', block) +urls = re.findall( + r'curl -fsSL (https://github\.com/basefoundry/base-demo/releases/download/v[0-9]+\.[0-9]+\.[0-9]+/install\.sh) -o install\.sh', + block, +) digests = re.findall(r"printf '%s install.sh\\n' ([0-9a-f]{64}) \| shasum -a 256 -c -", block) if len(urls) != 1 or len(digests) != 1: sys.exit('public bootstrap must have one exact-commit URL and SHA-256 gate')