- Update
CHANGELOG.md, migration notes, compatibility status, and the package version. - Run
npm ciandnpm run checkfrom a clean checkout. - Verify the public synthetic GitHub Pages demo. When the release changes the maintained Cloudflare recipe, also verify an Access-protected synthetic deployment.
- For every hosted provider path claimed as maintained, record a synthetic run through prompt generation, permission review, pull-request publication, independent validation, and dashboard refresh. Provider-neutral foundation releases do not imply hosted-provider certification.
- Confirm GitHub Actions remain pinned to reviewed full commit SHAs.
- Merge through the protected
Quality gateand CodeQL checks. - Create and push a signed tag matching
vX.Y.Z; the protectedv*tag ruleset prevents later updates or deletion. Do not publish the GitHub release manually. The tag workflow reruns all checks before creating it. - Verify the release notes, signed and protected tag, immutable-release status, assets, demo, and fork-upgrade instructions.
Do not create a release when the complete-source, privacy, or independent-publication gates are failing. A shiny tag is not a security control, although it does look fetching.