Skip to content

[PY-03] Resolve public license policy and publish signed packages with sandbox conformance #3

Description

@jaavid

Background

CoreLink is one product across multiple implementation repositories. This work is owned by sdk-python under EPIC-05.

Goal

Resolve the public license gate and publish reproducible, signed Python packages with retained sandbox/conformance evidence and immutable contract provenance.

Parent

  • Primary Product Epic: EPIC-05
  • Backlog ID: PY-03

Scope

  • Package/version the accepted PY-02 SDK surface.
  • Resolve applicable public license/support policy before supported publication.
  • Sign/publish through the organization release/provenance path.
  • Validate against MOCK-03 or an equivalent accepted sandbox.
  • Retain package, dependency, contract and conformance evidence.

Out of Scope

  • Stable claims before license/support policy, SDK behavior and conformance are accepted.
  • Treating successful package publication as runtime Product Acceptance.
  • Bypassing organization release/provenance policy.

Acceptance Criteria

Dependencies and acceptance state

  • Execution prerequisite: PY-02 accepted SDK ergonomics/behavior.
  • Conformance prerequisite: MOCK-03 or equivalent accepted sandbox/package revision.
  • Policy prerequisite: GH-03 accepted license/support policy for public publication.
  • Release-governance prerequisite: GH-04 accepted reusable CI/release/provenance path.
  • Blocks: DOCS-04 Python release guidance, WEB-03 supported-tool claims, and EPIC-05 Python release acceptance.
  • Current dependency state: See the CoreLink Product organization Project.

Planning Metadata

  • Type: Technical Task
  • Priority snapshot: P0
  • Product milestone snapshot: Beta
  • Domain snapshots: sdk, deployment
  • Area snapshot: package
  • Complexity: M
  • Created in status: Triage
  • Current status and DRI: See the CoreLink Product organization Project.
  • Intended repository labels: type:technical-task

Definition of Done

  • Acceptance criteria demonstrated.
  • License/support decision is recorded where required.
  • Artifact provenance/signing and reproducibility are verified.
  • Required conformance checks pass on version-identifiable dependencies.
  • Contract/security/tenant implications are reconciled.
  • Documentation/release notes are updated.
  • Pull request(s), package revision and retained evidence are linked.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    type:technical-taskImplementation or engineering enablement work

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions