- Run host artifact and ASan contracts on supported platforms with a Sandbox fallback.
- Clear image-seeded workspace files before extracting the dirty worktree.
- Pin current Linux artifact size classes and regression coverage.
- Retain representative Darwin kqueue coverage in the default gate.
- Schedule native runtime tests by host and make Linux clang invocations portable.
- Resolve canonical OCI manifest digests for direct and indexed images.
- Shard portable coverage across 16 sandboxes while retaining focused Darwin contracts.
- Run invariant suites once and keep differential and sanitizer-sensitive coverage in both lanes.
- Harden sandbox transport, exit-status parsing, and Linux runtime test portability.
- Add a custom Node 24 test image with tenant-neutral VCR configuration.
- Shard differential suites across disposable Sandboxes while preserving host-specific coverage.
- Load local agent credentials safely and document the validation workflow.
- packages/compiler/surface-manifest.json is generated (pnpm manifest), committed, and shipped in @scriptc/compiler; entries project mechanically from the diagnostics registry, the unsupported-syntax dispatch tables, the stdlib/builtin lowering tables, and the supported-builtin-module list
- every non-static entry carries the SC code the compiler raises for it, and the version spine is the exact published release version
- FENCE_CODES joins the diagnostics registry so factory-minted construct fences are enumerable
- the sampling harness compiles listed-static probes and asserts each sampled non-static entry refuses with exactly its listed code, beside a byte-identical staleness guard
- the release workflow regenerates the manifest, fails on drift, and attaches it to the GitHub release
- RELEASING.md documents the lockstep three-package prepare flow and the marked-changelog convention
- CHANGELOG.md starts with an Unreleased section and the marked 0.0.1 entry that becomes the GitHub release body
- AGENTS.md states repo-wide build/test conventions and defers docs-site specifics to docs/AGENTS.md
- scripts/sync-versions.mjs stamps runtime and compiler from the CLI version; the workflow's sync check now hints at it
- release.yml gains a github-release job that tags v<version> after a successful publish, never gating npm