repo sync — fast-forward-only update of an imported repo from its upstream
fix: resume a stranded merge-door release
release.yml + lib/preflight.sh — the merge door resumes the tag it stranded, instead of refusing every re-run with a diagnosis it cannot support
release: prepare stoke 1.4.0
fix: preserve apt signature verification
apt install path — signature-verified end to end (signed-by=), no [trusted=yes]
feat: upload release assets
release create --asset / release upload — attach assets to a release, and print the release id
fix: publish Forgejo releases atomically
lib/forge-forgejo.sh — publish the release atomically, so a failed asset upload cannot strand a published, incomplete release
Harden publish/build/install scripts and fix audit findings
docs: correct upstream sync campaign record
docs/UPSTREAM-SYNC.md — the deferral record names a ceiling that expired before it was written, and an if the operator has now answered
release-init after 0.6.3 — the survey, and the one ruling that decides the next window's identity
Ruling: C — no window yet.
A is the right destination, but not now. Measured: upstream 0.7.0–0.7.6 is
448 commits / 87 files / +24,161 lines — roughly 25× the 0.6.2 port — and…