Cull Release Recover
Principle
Derive truth from external evidence, then resume the first incomplete safe phase. Never erase immutable release history to make local state look consistent.
Diagnose
- Resolve the Cull checkout.
- Run
npm run release:cull -- resume --version "$VERSION" --jsonand parse exactly one JSON envelope. Treat local release state as a cache. - Authenticate and compare the prepared commit, remote annotated tag and peeled commit, Actions run, exact asset inventory, public release, updater metadata, provenance, and Homebrew cask/evidence.
- Classify the next action exactly as
rerun-check,prepare-new-version,watch-build,verify-artifact,publish-verified-artifacts,promote-homebrew, orprepare-patch-plan. - Execute only the safe resumable phase the user already authorized. Do not repeat a completed signed build or replace verified artifacts.
A post-publish verification failure creates or updates the stable P0 bd incident,
blocks later release checks, and returns prepare-patch-plan. Prepare the patch
plan but never publish that patch implicitly.
Never delete or move a tag or release. Never force-push, clobber assets, reset
unrelated work, bypass a gate, clean cull.db, or treat missing evidence as
success.