Objective
Close v0.4 W31 technical readiness, owner release decision and governed publication.
Status
COMPLETED — v0.4 RELEASED
Final candidate
Exact-head evidence passed: quality-gate, dependency-review, CodeQL C#/JavaScript, kafka-smoke, release-supply-chain, v0.3 regression benchmark, v0.4 benchmark, release-quality, Kafka 4.3.1/4.2.1/4.1.2/3.9.2, SPDX SBOM, High/Critical scan, all substantive review threads resolved and fresh CODEOWNER approval.
Final corrected bounded benchmark evidence:
- consumer lag / 64 partitions: 20,000 ops / 99.904 ms / 200,192.99 ops/s
- schema diff / 128 lines: 20,000 ops / 368.719 ms / 54,241.77 ops/s
- fail-closed Connect projection / 67 fields: 20,000 ops / 379.693 ms / 52,674.06 ops/s
These are bounded in-process implementation measurements, not Kafka/provider end-to-end throughput or a public SLA.
Release decision
The v0.4 Release Decision was explicitly owner-approved on 2026-09-21 after live verification confirmed no pre-existing v0.4 tag or GitHub Release.
Governed publication
Publication evidence:
- protected-main quality-gate
35607746838 — SUCCESS
- protected-main kafka-smoke
35607746884 — SUCCESS
- publish-release
35607746950, attempt 2 — SUCCESS
- release-quality — SUCCESS
- Kafka 4.3.1 / 4.2.1 / 4.1.2 / 3.9.2 — SUCCESS
- release-evidence — SUCCESS
- SPDX SBOM and High/Critical vulnerability scan — SUCCESS
- keyless cosign signing — SUCCESS
- final OCI tag promotion — SUCCESS
- publish-github-release — SUCCESS
The first protected-main Kafka 4.1.2 attempt had one transient Kafka is temporarily unavailable integration-test failure. The same exact source passed on rerun without weakening code, tests or governance.
Published artifacts
- tag
v0.4 → e22426026d4f03f675df703773ca072ed7ea0f03
- GitHub Release: v0.4
- OCI:
ghcr.io/araditc/kafdeck@sha256:8183ced585bd6eb73bf280f4ded5751e2ffc9370b1e170e0b9074a3acc9e2ed1
Invariants preserved
No Kafka mutation/produce/replay; no consumer-offset mutation/commit; no Schema Registry or Connect mutation; no ksqlDB statement/query execution; no payload persistence by default; no unbounded scan/polling; no generic upstream proxy; no arbitrary server-side JavaScript/general SQL engine; no masking bypass; metadata/ecosystem permissions never imply record.read; record.export remains separate; v0.3 masking remains server-side/fail-closed.
Central tracker: #100
Scope authority: #99 / RFC-0004.
Objective
Close v0.4 W31 technical readiness, owner release decision and governed publication.
Status
COMPLETED — v0.4 RELEASED
Final candidate
a94b3baa415f32b7b8420c4bc398f405fa674709dd8acdeac726756788c7bb679aa1feb25856e337b05b61f1835effcee78a7aef4d6eb481faba8915Exact-head evidence passed: quality-gate, dependency-review, CodeQL C#/JavaScript, kafka-smoke, release-supply-chain, v0.3 regression benchmark, v0.4 benchmark, release-quality, Kafka 4.3.1/4.2.1/4.1.2/3.9.2, SPDX SBOM, High/Critical scan, all substantive review threads resolved and fresh CODEOWNER approval.
Final corrected bounded benchmark evidence:
These are bounded in-process implementation measurements, not Kafka/provider end-to-end throughput or a public SLA.
Release decision
The v0.4 Release Decision was explicitly owner-approved on 2026-09-21 after live verification confirmed no pre-existing v0.4 tag or GitHub Release.
Governed publication
fcfafe1a6658b4473ea9a963da2675463a709425e22426026d4f03f675df703773ca072ed7ea0f03Publication evidence:
35607746838— SUCCESS35607746884— SUCCESS35607746950, attempt 2 — SUCCESSThe first protected-main Kafka 4.1.2 attempt had one transient
Kafka is temporarily unavailableintegration-test failure. The same exact source passed on rerun without weakening code, tests or governance.Published artifacts
v0.4→e22426026d4f03f675df703773ca072ed7ea0f03ghcr.io/araditc/kafdeck@sha256:8183ced585bd6eb73bf280f4ded5751e2ffc9370b1e170e0b9074a3acc9e2ed1Invariants preserved
No Kafka mutation/produce/replay; no consumer-offset mutation/commit; no Schema Registry or Connect mutation; no ksqlDB statement/query execution; no payload persistence by default; no unbounded scan/polling; no generic upstream proxy; no arbitrary server-side JavaScript/general SQL engine; no masking bypass; metadata/ecosystem permissions never imply
record.read;record.exportremains separate; v0.3 masking remains server-side/fail-closed.Central tracker: #100
Scope authority: #99 / RFC-0004.