Every immutable release remains available for consumers pinned to its tag or commit. If a release is defective, stop recommending its moving major alias, restore that alias to the last accepted immutable release, and publish any fix under a new semantic version.
For every release:
- Record the accepted OpenAPI digest, reviewed source commit, lockfile hash, bundled entrypoint hash, tarball hash, immutable release tag, and major alias target.
- Prove in a disposable repository that the major alias can be returned to the prior verified immutable tag without moving or overwriting that tag.
- Prove a consumer workflow pinned to the previous immutable SHA still fails
closed on
deny,requires_approval, errors, and cardinality mismatch. - Keep the prior immutable artifact and workflow example available throughout rollback; never replace an existing release asset silently.
- Disable new recommendations and Marketplace promotion immediately on secret leakage, false allow, decision reordering, unexpected network use, report-path escape, or contract drift.
- Publish a repair only as a newly reviewed immutable version. Notify consumers through an approved changelog/security channel with affected version hashes and no customer request data.
Marketplace delisting and repository removal are last-resort actions because they can break existing consumers. Prefer an advisory, major-alias rollback, and a new immutable repair release.