Engineering · Release evidence
A release is a chain of evidence, not one status light.
Different checks answer different questions. RuleOak keeps those evidence classes separate and binds them to the exact candidate they describe.
Evidence layers
| Layer | What it can establish |
|---|---|
| Source/static | Identity, manifests, policy, dependency and source-contract properties. |
| Deterministic runtime | Behavior exercised in a controlled test environment. |
| Native build | Compilation/link/package behavior on the target toolchain. |
| Device/platform | Installed behavior on representative target environments. |
| Store/provider | External acceptance, purchase, distribution or provider integration truth. |
| Deployment | What is actually reachable by users now. |
Invalidation matters
Evidence should be reused only when decision-critical inputs remain unchanged. Source, policy, configuration, adapters, signing/distribution inputs and qualification logic can all invalidate earlier evidence.
No false green
If a native toolchain, device, network, store or provider is unavailable, the honest result is pending—not PASS.