Files
chimera-gfx-Public/docs/PUBLICATION_READINESS.md
T
Chimera GFX release export a6037502d7
phase0-ci / build-and-audit (push) Successful in 2m14s
Publish Chimera GFX source
2026-09-03 03:27:14 +02:00

2.1 KiB

Publication readiness

The current source tip is prepared for public review. The repository remains private until the history and security-contact decisions below are confirmed.

Completed

  • GPL-3.0-or-later license, contribution guidance, security policy, third-party notices, and a user-oriented README are present.
  • Development branches are consolidated into one reviewed candidate branch.
  • No generated ELF, SDK archive, crash dump, device capture, or other binary release artifact is tracked.
  • Current source paths and manifests contain no private LAN repository URL or operator-specific filesystem path.
  • Host builds, policy tests, JSON validation, large-object review, and current plus all-ref secret scans are part of the publication review.
  • CI actions, container images, SDK downloads, and source revisions are pinned; downloaded SDK bytes are verified before use. Distribution packages follow the security-updated repository attached to the pinned base image rather than stale exact package revisions.
  • SECURITY.md publishes a fixed private reporting address.
  • Pull requests from public forks cannot run on the self-hosted CI runner.
  • tools/export-public-source.sh creates a parentless source candidate, strips machine-local agent instructions, and rejects private deployment markers, forbidden secret files, generated binaries, and oversized files.

Decisions required before changing visibility

  1. Release policy. Recommended: publish reviewed source only. Do not attach runnable PS5 ELF artifacts; if that policy changes later, require reproducible builds, checksums, corresponding source, and a separate safety review.

Historical commits contain an old private LAN URL, operator-specific paths, and author email metadata. Keep that canonical history private and publish only the parentless export from a reviewed commit. Deleting branches is not a substitute for this export.

Generated payloads, crash dumps, SDK archives, local hardware captures, and unredacted operator records are not public source artifacts and must remain outside Git.