Skip to content

docs(release): make first-publication instructions and audit evidence accurate #110

Description

@rmems

Problem

The publish audit of 485f0445a93c1ec06e8142a2d602c33030d753d7 passed compilation, tests, rustdoc, package verification, and cargo publish --dry-run --locked, but two documentation issues remain:

  • The README shipped inside the crate says “v0.3.0 is not yet published.” That text becomes false in the published 0.3.0 artifact.
  • The release checklist presents old measurements as the final artifact and summarizes dependency licenses inaccurately. The audited archive contains 41 files, 105,118 compressed bytes (102.7 KiB), and Cargo VCS metadata for the audited SHA. Current registry metadata includes Zlib for foldhash, Apache-2.0 for safetensors, and an additional Unicode-3.0 requirement for unicode-ident, among other SPDX expressions missing from the summary.

Acceptance criteria

  • Installation instructions remain accurate before and after the first upload, retain usable registry/feature examples, and provide a concrete immutable Git pin for development snapshots.
  • The release checklist separates reusable package policy from dated audit evidence. Counts, sizes, hashes, license expressions, test results, and model-smoke evidence identify their actual source revision and do not claim qualification of an unpublished future commit.
  • Document the exact lockfile dependency license expressions rather than grouping different licenses under MIT/Apache.
  • Verify the changed README in the generated crate, inspect the package allowlist and VCS identity, and run package/publish dry-run checks.
  • Keep publication, registry authority, tag/release creation, and the maintainer's credential verification under the existing release gate.

Relationships

Parent / release gate: #89. This fix blocks the documentation portion of #89; it does not close the publication issue.

Activity

  1. self-assigned this
    on Oct 2, 2026
  2. linear-code commented on Oct 2, 2026

    @linear-code
  3. testdriverai commented on Oct 2, 2026

    @testdriverai

    Considering the Context

    I'm currently focused on evaluating the context provided, specifically the repository and issue details. I'm noting the sender and bot involved as I process the information. The goal is to fully understand the current situation and the relevant data to formulate a helpful response.

  4. testdriverai commented on Oct 2, 2026

    @testdriverai

    Updating Documentation Efforts

    I'm focusing on Issue #110 within the rmems/engram-parser repository. Specifically, I'm working to refine the README documentation, release checklist, dependency licenses, and cargo publish dry-run checks to ensure accuracy. The goal is to provide a comprehensive and trustworthy user experience.

  5. testdriverai commented on Oct 2, 2026

    @testdriverai
    No description provided.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Projects

Relationships

None yet

Development

No branches or pull requests

Issue actions