Public, GitHub-native automation for publishing coordinated findmydoc platform releases and preparing verified release history for registered applications.
This repository contains only the deterministic release engine, reusable deployment workflows, configuration derived from public repository metadata, and automated tests. It contains no credentials, private operational context, or internal runbooks.
Internal operating documentation is maintained in the Operations repository.
Platform release plans freeze the Ops source and complete opted-in Supabase scope. Approved applies reconcile Preview, then Production, before deploying applications. The Runner verifies each exact workflow run's audited convergence and reuses those runs on resume. See the reconciliation contract for approval, evidence, recovery, and GitHub App installation prerequisites.
The Website reusable deployment workflow requires the caller secret GH_PACKAGES_READ_TOKEN with private package read access.
It exposes that credential as NODE_AUTH_TOKEN only while the runner installs and builds the frozen Website checkout through
vercel build --prod. The upload uses the prebuilt output; upload, alias, and runtime configuration do not receive the package token.
Callers keep the token in GitHub Actions secrets and must not add it to a Vercel project environment variable.
The Website workflow disables package-manager caching and uses no Actions cache for its install or build output.
Fork pull requests can read default-branch Actions caches, so private package files must never enter those caches.
- Manifest v2 remains readable for existing joint releases.
- Manifest v3 models either one registered application (
releaseMode: application) or a platform release with at least two registered applications (releaseMode: platform). - Components must match the versioned catalog in
config/platform-release.json. - Deployment evidence is optional in v3 and is never fabricated.
- Imported GitHub releases use
notificationMode: silent; native releases usestandard.
The import path is intentionally separate from publication. It cannot create tags, GitHub Releases, deployments, or chat messages.
pnpm platform-release import-releases plan --help
pnpm platform-release import-releases build --help
pnpm platform-release import-releases ingest --helpplan reads published GitHub Releases and exact linear tag ranges. Repeating it against unchanged GitHub state reuses the existing immutable plan and its original timestamp. Any release-note discrepancy must be acknowledged byte-for-byte in release-content.json; the acknowledgement is therefore covered by the content and manifest digests. build accepts reviewed German content and writes immutable Manifest v3 files plus a batch index of no more than eight releases. ingest requires both --apply and the exact batch digest, then sends only the stored manifests to the configured FounderOps endpoint.
The generic announcement command accepts only native platform manifests with standard notifications. The immutable manifest-gap recovery path supports both legacy Manifest v2 archives and current native Manifest v3 archives with their exact stable publication timestamp.