Release
Release candidates
Every release candidate published to Deploy's release graph, with the human version claims bound to it. A candidate is immutable metadata: its claims are recorded, not proved.
Publication records claims; it does not prove them. Deploy.ReleaseDecision, ReleasePromote and ReleaseRollback all answer release_provenance_authority_required: durable authority, signed nonce and expiry, ABI, migration and security-epoch proofs are not verified, no channel epoch is written, and resolution never grants install authorization. A named compiler build is checked only as evidence beside that refusal.
No release candidate has been published on this host. Deploy.ReleasePublish records one from a composed cre8.system.release.v1 candidate.