Skip to content

Current qualification status

The public version is 0.0.0-qualification.

Foundations through T77 have public validation reports. They cover the CLI, workspace placement, policy, drivers, probes, evidence, memory, distribution, recovery, human-review contracts, the persistent signing-key lifecycle, enforced cost and duration ceilings, a declared gate repair loop with bounded attempts and human escalation, a hardened policy boundary with declarative tests and signed bundles, an isolated Self-Test trust domain with all four packaged profiles, doctor --deep with a closed read-only check catalog, stable diagnostic exits, sentinel invariance, purpose-bound signed reports, a frozen public regression-campaign corpus with distribution-and-confidence reporting rather than single-run scores, a sealed-holdout evaluator with evaluator-owned evidence and a zero-authority candidate boundary, platform, security, and fault qualification across all five supported platforms with a signed evidence index, and a signed TUF release publication whose sealed launchers were verified by live activation on Windows and Linux.

The T69 Self-Test trust domain, T70 smoke and workspace profiles, T71 full, fault, and approved-driver profiles, T72 deep diagnostics, T73 public regression campaigns, T74 sealed-holdout promotion, T75 platform, security, and fault qualification, T76 verified release publication, and T77 final acceptance evidence and release-decision machinery are complete. Every task the roadmap declares now has a validation report, so the declared qualification chain is fully verified. The public CLI exposes init, all four Self-Test profiles, and doctor --deep. Seven source-mode doctor checks still report fixture presence rather than live subsystem health; their provisioned-machine upgrades remain tracked beyond T76.

The signed promote-or-reject decision that RELEASE-DECISION-CONTRACT.md defines — requiring an operational reviewer, a security reviewer, and an accountable human, all distinct — has been made. It is a signed reject: a recorded hold (release-decision-1.0.0.md). The candidate keeps operating as 0.0.0-qualification and is not promoted to 1.0.0; a promote round would decide on a fresh candidate with its own decision file, after the tracked promote-readiness work lands.

Read the canonical roadmap or inspect the qualification evidence.