Parent
Canonical Windows epic: https://github.com/akua-dev/cnap/issues/390
Scope
Recover the already-created immutable v0.8.25 release publication without retagging, recreating the GitHub Release, or changing its assets. The tag must remain 6452eb662445d2ad7c108128f93b9c55138729bb; the existing GitHub Release is 352631784 with its 19 assets, including the Windows native asset. Do not use an npm token.
Acceptance criteria
Evidence
- Akua PR #68 merged the configured Git HTTPS CA-bundle preservation fix at the tag SHA.
- Release run 29171807994 built native Windows and release assets but failed only in Docker push; publish run 29172771842 failed before the first npm package and skipped SDK publication.
- 2026-07-20: All ten npm Trusted Publishers verified complete through the human-owned interactive npm bootstrap — every
@akua-dev package resolves to GitHub org akua-dev, repository akua, workflow release-publish.yml, no Environment, npm-publish only; the prior cnap-tech/akua tuple is absent. Credential-free registry reads confirm all ten packages remain absent at 0.8.25 (latest 0.8.24), and GHCR still holds v0.8.24, not v0.8.25.
Current blocker
Trusted Publisher prerequisites, probes, and the tag/CI/assets reconfirmation are complete. This issue is now blocked only on the separately-authorized OIDC publication-recovery dispatch and its post-publish verification (per-package 0.8.25 resolution, intended dist-tags, Windows optional package, and any authorized GHCR provenance). No token, no retag, no release recreation.
Boundaries
No retag, no release recreation, no source change, and no cnap version update in this issue. The canonical epic remains blocked until this is verified.
Parent
Canonical Windows epic: https://github.com/akua-dev/cnap/issues/390
Scope
Recover the already-created immutable
v0.8.25release publication without retagging, recreating the GitHub Release, or changing its assets. The tag must remain6452eb662445d2ad7c108128f93b9c55138729bb; the existing GitHub Release is352631784with its 19 assets, including the Windows native asset. Do not use an npm token.Acceptance criteria
0.8.25and theirlatesttags. Treat an already-published package as success only after verifying its exact version and provenance; do not overwrite or republish it.akua-dev, repositoryakua, workflowrelease-publish.yml, and no GitHub Environment:@akua-dev/native-engines@akua-dev/native-darwin-arm64@akua-dev/native-darwin-x64@akua-dev/native-linux-arm64-gnu@akua-dev/native-linux-arm64-musl@akua-dev/native-linux-x64-gnu@akua-dev/native-linux-x64-musl@akua-dev/native-win32-x64-msvc@akua-dev/native@akua-dev/sdk29168109111, and the existing release/assets before a separately authorized recovery dispatch.id-token: write) and the existing release-publish path; preserve probe-before-publish/idempotency for every package.0.8.25,@akua-dev/nativeand@akua-dev/sdkresolve at the intended dist-tag, and the Windows optional package is present.86596485362failed while targeting staleghcr.io/cnap-tech/akua; do not claim GHCR provenance forv0.8.25until a safely authorized recovery proves immutable image digest/provenance.Evidence
@akua-devpackage resolves to GitHub orgakua-dev, repositoryakua, workflowrelease-publish.yml, no Environment, npm-publish only; the priorcnap-tech/akuatuple is absent. Credential-free registry reads confirm all ten packages remain absent at0.8.25(latest0.8.24), and GHCR still holdsv0.8.24, notv0.8.25.Current blocker
Trusted Publisher prerequisites, probes, and the tag/CI/assets reconfirmation are complete. This issue is now blocked only on the separately-authorized OIDC publication-recovery dispatch and its post-publish verification (per-package
0.8.25resolution, intended dist-tags, Windows optional package, and any authorized GHCR provenance). No token, no retag, no release recreation.Boundaries
No retag, no release recreation, no source change, and no cnap version update in this issue. The canonical epic remains blocked until this is verified.