Public documentation v0.1.0
Publishing workflow
Software Factory publication is intentionally gated and separate from drafting or validating artifacts.
Roles
PM defines release intent and gates; builder prepares authorized source changes; reviewer verifies readiness and public-safety boundaries; publisher performs approved generation, tagging, releases, and repository updates with scoped credentials; docs updates public docs and release notes after reviewer verification.
v0.1.0 publication outputs
The initial publication produced the source repository jack-michaud/software-factory on main with tag profiles/v0.1.0, generated profile repositories on main with tag and release v0.1.0, MPL-2.0 license across public repositories, public README install contracts, and reviewer-verified public-safety checks.
Release sequence
Prepare source/profile changes, run local validation and public-safety scans, obtain explicit approval for repository owner/names/license/visibility/credentials/branch-protection scope, publish only with scoped credentials, verify remote heads/tags/releases/licenses/install instructions, update public docs, and create follow-up tasks for residual risks.
Credential and settings boundaries
Publisher credentials should be least-privilege and scoped to the approved repositories. Public docs must never include tokens, credential file paths, private workspaces, runtime state, private logs, local profile state, or private deployment URLs.
Generated repository policy
Generated profile repositories are public artifacts. Routine changes should be made in the source monorepo and republished. Direct edits to generated repositories risk drifting from the source of truth.