Release GuardDocs

Release review

Publisher Mode

Audit the exact package root intended for customer distribution without fabricating marketplace portal state.

Release Guard 26.9.0Exact-root audit

Local package audit

Publisher Mode can evaluate package identity and version, Unity compatibility, author/dependencies/keywords/samples, deterministic inventory and digest, metadata and GUID integrity, assembly topology, editor/runtime boundaries, namespaces, customer-readable C#, current-year headers, documentation, sample/listing parity, credits/notices, AI disclosure, dead/internal/evidence files, path and size limits, binaries, Unity internal API use, and locally representable Unity/Fab requirements.

Decision levels

  • Package-root pass: every applicable local rule passed for the exact scanned root.
  • External evidence missing: local content may pass while portal, platform, validator, media, licensing, pricing, reviewer, or policy evidence is absent or stale.
  • Marketplace-ready pass: the exact candidate, current official-requirements audit, external evidence, final bytes, and portal handoff all pass under release authority.

A package-root pass can never be labeled marketplace-ready by itself.

Exact root and negative controls

Scan the staged customer root, not a broad repository root containing internal evidence. Symlinks, redirected paths, untracked files, or changes during hashing fail closed. Critical rule families retain known failing fixtures; a validator that cannot detect its controlled failure cannot grant a passing candidate.

Reports

Publisher Mode exports JSON, HTML, and SARIF with exact inventory, source binding, rules, external gates, warning dispositions, and candidate state. Requirements that cannot be inferred locally remain explicitly external.