Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 13 additions & 15 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,8 @@ Reference Base-managed project and representative demo environment.
Each path states prerequisites, a completion check, and one safe recovery.
This demo is a **curated representative subset**, not every Base contract.
Current-source paths use the [supported inputs](.release/supported-dependencies.json);
the historical-release Quick Start below installs older versions until v0.2.0
publication. Neither path implies native Windows or a full Linux demo.
the release Quick Start below installs the verified v0.2.0 assets. Neither path
implies native Windows or a full Linux demo.

This repository is the public reference project for Base-managed repositories.
It demonstrates Base on a compact but credible project shape: small enough to
Expand Down Expand Up @@ -90,35 +90,33 @@ in the Base repository.

## Quick Start

Until v0.2.0 publishes verified installer assets, use this interim, immutable
bootstrap script from reviewed source commit `96f8e6d0c016aaf73e1a8c448ac92c9222a5aced`.
It installs **Base v1.8.0 and base-demo v0.1.0**, not current `main`.
Run this macOS quick start in a temporary directory; inspect the script before
execution if required by your environment:
Use the verified v0.2.0 release asset. It installs **Base v1.9.0 and
base-demo v0.2.0** at the exact commits recorded in the release BOM. Run this
macOS quick start in a temporary directory; inspect the script before execution
if required by your environment:

```bash
bootstrap_dir="$(mktemp -d)"
(
cd "$bootstrap_dir" || exit 1
curl -fsSL https://raw.githubusercontent.com/basefoundry/base-demo/96f8e6d0c016aaf73e1a8c448ac92c9222a5aced/install.sh -o install.sh &&
printf '%s install.sh\n' dc8728510651c8b59fcc4a99dbf12e7e7c152858a99b745de90cdb7210e85d82 | shasum -a 256 -c - &&
curl -fsSL https://github.com/basefoundry/base-demo/releases/download/v0.2.0/install.sh -o install.sh &&
printf '%s install.sh\n' fab41851d0f7b3f0d533cc7fbc336cde851332e8cb4382a100fe1aeebbde593d | shasum -a 256 -c - &&
RUN_UPDATE_PROFILE=false bash install.sh
)
```

The checksum gates execution. This reviewed script verifies its Base installer
The checksum gates execution. This reviewed release asset verifies its Base installer
and both checkout commits. Fresh installs use `~/work`; clean existing checkouts
at those exact commits are reused, while dirty or divergent checkouts fail
without being pulled, reset, detached, or switched. This command opts out of
shell-profile updates; setup still installs dependencies and project tools.
An existing developer workspace should use the developer route below instead
of deleting or resetting its checkouts to make this release route pass.
An existing developer workspace should use the developer route below instead of
deleting or resetting its checkouts to make this release route pass.

The historical **v0.1.0/install.sh does not provide these guarantees**: it uses
a moving Base installer, permits an absent checksum, and can pull an existing
checkout. Do not substitute that old script for the checksum-verified input
above. [Release preparation #303](https://github.com/basefoundry/base-demo/issues/303)
tracks replacing this interim URL with the verified v0.2.0 release asset.
checkout. Do not substitute that old script for the checksum-verified v0.2.0
asset above.

Contributors with current source peer checkouts under one workspace should opt
into the local developer path explicitly (from the current base-demo checkout):
Expand Down
4 changes: 2 additions & 2 deletions docs/first-success.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,8 @@ Need Base first? Follow the canonical [adopter golden path](https://github.com/b
for install and consent decisions, then select the stable inputs above. That
document is pinned for reference, not an instruction to substitute its candidate
for the stable runtime. The README's checksum-verified [Quick Start](../README.md#quick-start)
is a separate historical Base 1.8/demo 0.1 route until v0.2.0 is published; do not
mix its results with current-source evidence or reset a divergent checkout.
is the published Base 1.9/demo 0.2 release route; do not mix its results with
moving-source development evidence or reset a divergent checkout.

Ubuntu/Debian (including WSL2 on its native filesystem) supports Base setup and
the CI-safe read-only project-health path, not the full demo loop. Native Windows
Expand Down
15 changes: 6 additions & 9 deletions docs/release.md
Original file line number Diff line number Diff line change
Expand Up @@ -73,20 +73,17 @@ access to Actions evidence during verification.

The current source `install.sh` release path is pinned to reviewed immutable
inputs. These guarantees do **not** apply to the historical v0.1.0 installer.
The README temporarily downloads the checksum-verified script from commit
`96f8e6d0c016aaf73e1a8c448ac92c9222a5aced`; it still installs the older release
Base v1.8.0/demo v0.1.0 checkouts, not the current supported input selection
or that source commit as the demo checkout.
Before closing [#303](https://github.com/basefoundry/base-demo/issues/303), replace
the README's interim script URL and digest with the new verified release asset,
update the stated consumed versions, and rerun `bash tests/public_install_test.sh`.
The README downloads the checksum-verified `v0.2.0` release asset. It installs
the supported Base v1.9.0 and base-demo v0.2.0 checkouts recorded below. The
release asset is finalized from the annotated tag target, so its self-commit
pin is the exact immutable v0.2.0 commit.

The consumed inputs are:

- Base installer: the version, full commit and SHA-256 selected by
`.release/supported-dependencies.json`, materialized in current `install.sh`;
- base-demo checkout: release ref `v0.1.0` and commit
`b8ac2ae490e4965b8131195a11377fd0bd787daf`.
- base-demo checkout: release ref `v0.2.0` and commit
`c5709ed8dfa623539e9c326554712490e14f1774`.

When preparing a release, update `PROJECT_RELEASE_REF` in the reviewed
`install.sh` source to the new release tag. Keep `PROJECT_RELEASE_COMMIT` as a
Expand Down
35 changes: 18 additions & 17 deletions docs/v0.2.0-readiness.md
Original file line number Diff line number Diff line change
@@ -1,10 +1,12 @@
# v0.2.0 release-owner handoff

Status: **preparation only; not approved for publication**.
The core implementation train does not create a version tag, publish assets,
waive independent review, or start a bake window on the owner's behalf.
[#303](https://github.com/basefoundry/base-demo/issues/303) remains open until
the publication and downloaded-asset checks below are complete.
Status: **published and independently artifact-verified on 2026-09-28**.
The release uses annotated tag `v0.2.0` at
`c5709ed8dfa623539e9c326554712490e14f1774`. The governed release workflow
exposed a checkout bug that treated the annotated tag as lightweight; the
finalized assets were therefore verified locally from the exact tag target and
published with the same immutable BOM and installer bytes. Follow-up workflow
repair is tracked in [#320](https://github.com/basefoundry/base-demo/issues/320).

## Intended scope and inputs

Expand Down Expand Up @@ -104,17 +106,16 @@ that flag is only a self-identity fixture operation, not compatibility proof.
The strict BOM publication checker is expected to reject the tracked
`not_tested` input. Validate the finalized external BOM instead.

Because the published version is still 0.1.0 during core-train preparation,
any rehearsal at that stage tests mechanics only. It must not be published as
another 0.1.0 release or called the final 0.2.0 candidate.
The earlier 0.1.0 rehearsal tested delivery mechanics only. It was not used as
the v0.2.0 compatibility evidence.

## After separately authorized publication
## Publication verification

Download `release-bom.json`, `release-bom.sha256`, `install.sh` and
`install.sh.sha256` from the new release into a fresh directory. Independently
verify checksums, annotated tag target, finalized self-identity and exact
provider inputs. Re-run the strict BOM gate and inspect the downloaded
installer pins. Update the README public URL/digest and consumed versions to
those actual assets, run `tests/public_install_test.sh`, and rehearse that exact
public command. Record the immutable demo identity for the Base-owned
compatibility BOM. Only then close #303 and mark the release complete.
Downloaded `release-bom.json`, `release-bom.sha256`, `install.sh` and
`install.sh.sha256` were independently checked against the finalized outputs.
The strict BOM gate passed with compatibility run
https://github.com/basefoundry/base-demo/actions/runs/36420902540; the installer
fixtures passed against the downloaded asset. This PR updates the README public
URL/digest and consumed versions, and reruns `tests/public_install_test.sh`.
The immutable demo identity is ready for the Base-owned v1.10 compatibility
BOM.
5 changes: 4 additions & 1 deletion tests/public_install_test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,10 @@ from pathlib import Path

section = Path(sys.argv[1]).read_text().split('## Quick Start\n', 1)[1]
block = section.split('```bash\n', 1)[1].split('```', 1)[0]
urls = re.findall(r'curl -fsSL (https://raw\.githubusercontent\.com/basefoundry/base-demo/[0-9a-f]{40}/install\.sh) -o install\.sh', block)
urls = re.findall(
r'curl -fsSL (https://github\.com/basefoundry/base-demo/releases/download/v[0-9]+\.[0-9]+\.[0-9]+/install\.sh) -o install\.sh',
block,
)
digests = re.findall(r"printf '%s install.sh\\n' ([0-9a-f]{64}) \| shasum -a 256 -c -", block)
if len(urls) != 1 or len(digests) != 1:
sys.exit('public bootstrap must have one exact-commit URL and SHA-256 gate')
Expand Down
Loading