AsiBackbone 5.1.0 Release Readiness Record
Release candidate date: 2026-09-11
Release intent
5.1.0 is a backward-compatible stabilization release for the stable 5.x
package family. It packages the public API baseline, repository security,
security-advisory distribution, branch-retention, documentation-governance, and
project-stewardship work completed after 5.0.0 while preserving the runtime
contract.
This record is a pre-tag checklist. Do not create v5.1.0 or publish packages
until every required validation is complete on the final release-candidate
commit.
Included scope
- Add committed
v5.0.0public API baselines and release-blocking baseline and package-boundary validation for every managed stable package. - Add auditable repository security-control definitions and dry-run-first management tooling.
- Add security-advisory distribution and CVE-request audit/apply tooling with fail-closed response handling and non-mutating preview behavior.
- Add branch-retention policy, maintenance tooling, fixtures, and tests.
- Add
SUPPORT.mdandMAINTAINERS.mdand align repository ownership and contribution routing. - Reorganize documentation navigation and strengthen cross-repository link and current-release-claim validation.
- Carry forward workflow, stable-smoke, citation, and documentation annotation
corrections merged after
5.0.0.
Compatibility boundary
- Package IDs remain unchanged.
- Public namespaces remain unchanged.
- The target framework remains
net10.0. AssemblyVersionremains5.0.0.0for the compatible5.xbinary line.FileVersion, package version, informational version, citation metadata, and release metadata advance to5.1.0.- No stable public API additions, removals, or signature changes are included.
- No runtime behavior or durable artifact shape changes are included.
- NuGet package signing remains deferred while the project is independently maintained.
Version and metadata checklist
- [ ]
Directory.Build.propsresolves package version5.1.0. - [ ]
AssemblyVersionremains5.0.0.0. - [ ]
FileVersionis5.1.0.0. - [ ]
CITATION.cffreports version5.1.0and release date2026-09-11. - [ ]
.zenodo.jsonreports version5.1.0and stabilization-release scope. - [ ] Template fallback package references use
5.1.0. - [ ] Source Link post-publication validation resolves the central version.
- [ ] Lock files are regenerated after the version bump and locked restore succeeds.
- [ ]
CHANGELOG.mdand release notes describe the same change set and compatibility boundary. - [ ] Evergreen documentation identifies
5.1.0as the current release without rewriting historical release records.
Required validation before tag
- [ ] Version consistency passes for
5.1.0and tagv5.1.0. - [ ] Debug solution-build coverage validation passes.
- [ ] Locked restore succeeds using the repository SDK and package configuration.
- [ ] Debug and Release solution builds succeed.
- [ ]
dotnet format --verify-no-changessucceeds. - [ ] All test projects pass.
- [ ] Public API baseline and package-boundary validation pass.
- [ ] Documentation continuity and cross-repository link validation pass.
- [ ] DocFX site generation succeeds.
- [ ] Package creation succeeds for the complete publishable package set.
- [ ] Generated package IDs, versions, dependencies, repository metadata, symbols, and README content are correct.
- [ ] Package SBOM generation succeeds.
- [ ] Template, external-consumer, and stable-package smoke tests succeed.
- [ ] CodeQL and dependency review report no blocking findings.
- [ ] OpenSSF Scorecard, workflow-security, actionlint/Zizmor, and OWASP Dependency-Check results have no unexplained blocking findings.
- [ ] No package-signing claim is made for unsigned packages.
Local release-candidate evidence
The release-preparation change should record the following checks before it is merged:
| Check | Expected result |
|---|---|
Version consistency for 5.1.0 and v5.1.0 |
Passed |
| Locked restore | Passed |
| Debug solution build | Passed |
| Release solution build | Passed |
| Formatting verification | Passed |
| Test suite | Passed |
| Public API and package-boundary validation | Passed |
| DocFX and documentation validation | Passed |
| Package metadata and SBOM generation | Passed |
| Template and consumer smoke tests | Passed |
GitHub-hosted security, dependency, provenance, and repository-control evidence remains authoritative for checks that cannot be completed solely from a local checkout.
Release sequence
- Confirm the
5.1.0changelog entry and release notes are consistent. - Regenerate and commit NuGet lock files after the central version change.
- Merge the release-preparation pull request after required checks pass.
- Confirm
maincontains the final5.1.0metadata and release documentation. - Create the annotated release tag
v5.1.0from the validated commit. - Run the stable release workflow against that tag.
- Confirm all expected NuGet and symbol packages are published from the official source.
- Confirm all package SBOMs,
sbom-manifest.json,release-evidence-manifest.json, and retained release notes are attached to the public GitHub release, and verify package/SBOM attestations by subject digest. - Confirm documentation deployment succeeds.
- Run post-publication Source Link validation:
./scripts/Validate-Source-Link-commit-metadata.ps1 -Version 5.1.0
- Verify package repository commit metadata resolves to the tagged source commit.
- Create the version-specific Zenodo record, then update citation metadata in a follow-up change if a new version DOI is intentionally recorded.
- Record any release exception explicitly rather than silently weakening the release claim.
Final scope statement
AsiBackbone remains Accountable Systems Infrastructure for governed .NET decision flow. This release improves evidence and operational stewardship around the package family; it does not make AsiBackbone an authentication system, authorization system, host executor, compliance certification, complete tamper-evidence platform, production key-management system, or production replay-protection system by default.