Problem/Motivation
1.0.0-alpha2 resolves the original issue queue and has passing automated coverage. A stable 1.0.0 needs explicit evidence for the supported platform matrix, published-package upgrades, and actual provider delivery. This plan tracks release acceptance; it does not imply a newly discovered critical defect.
Remaining tasks
- Run CI against the currently supported Drupal branches and applicable PHP and mailer combinations.
- Verify MySQL, MariaDB and SQLite alongside PostgreSQL for installation, updates and concurrent intake.
- Record a reproducible staging upgrade and real Postmark webhook verification using the published package.
- Correct and consolidate installation, privacy and upgrade documentation.
- Document the 1.x public API and backward-compatibility commitments.
Release acceptance
Each child issue must have reviewable evidence and pass its acceptance checks before 1.0.0 is tagged. Re-run the required checks on the final release commit and verify the Drupal.org archive and Composer metadata. A beta or release candidate may be used to gather evidence; no arbitrary soak duration is required.
Security advisory coverage will be pursued separately by the maintainer and is not a dependency of this plan. Optional feature requests are follow-up work and do not expand the 1.0.0 acceptance criteria.
Stable acceptance issues
- #3621225: Verify all supported Drupal branches and PHP combinations in CI
- #3621226: Verify installation, upgrades and concurrent intake across Drupal database drivers
- #3621227: Record published-package upgrade and real Postmark webhook acceptance evidence
- #3621228: Consolidate stable installation and upgrade guidance and correct privacy documentation
- #3621229: Document and verify the public API compatibility contract for 1.x
Optional roadmap, not release blockers
Recommended sequence: operational health and reconciliation visibility first, then the integration event contract. Multi-source credentials, message history and higher-volume retention can follow demonstrated adoption needs. Accessibility verification can proceed independently.
- #3621230: Add proactive webhook health checks and actionable operational alerts
- #3621231: Support independently rotated webhook credentials bound to source profiles
- #3621232: Expose durable integration events for accepted webhooks and suppression changes
- #3621233: Add scheduled read-only reconciliation previews and suppression drift reports
- #3621234: Add a protected message delivery timeline and searchable event history
- #3621235: Add configurable bounded retention draining and backlog visibility for busy sites
- #3621236: Complete screen-reader and admin-theme accessibility verification of operator workflows
Comments
Comment #2
jmcerdaLinked five stable acceptance tasks and seven optional follow-ups. All are Active and unassigned. The original alpha2 issues remain Fixed. Security advisory coverage remains a separate maintainer activity.
Comment #3
jmcerdaProgress: stable children #3621225, #3621226, #3621228 and #3621229 are Fixed. Optional follow-ups #3621230 through #3621236 are Fixed. #3621227 still lacks a dedicated Postmark test token; the published 1.0.0-alpha2 Composer archive is verified, live webhook acceptance is not. Production and shared staging are not used. This plan stays Active until that evidence exists. Security advisory coverage remains a separate maintainer activity. No 1.0.0 tag.
Comment #4
jmcerdaProgress: #3621227 live sandbox Postmark evidence is recorded and that issue is Fixed (comment #12). All five stable children are now Fixed. Optional follow-ups #3621230 through #3621236 remain Fixed.
Remaining for this plan: 1.0.0 tag and Drupal.org publish. Re-run the required checks on the final release commit when that is authorized.
This plan stays Active until 1.0.0 exists. No tag in this update.
Comment #14
jmcerda1.0.0 is published.
1.0.0on commite073bf785e0cb2a32634d90f32ef3ffa16578abaat git.drupalcode.org.composer require 'drupal/postmark_webhooks:^1.0'.1f260a3c5f59e6e3b46cc57e5295586840bc5b5bmatches packages.drupal.orgdist.shasum.Sites on 1.0.0-alpha2 run update 10007 after upgrading. Optional health, source profiles, outbox, scheduled reconciliation, MessageID timeline and retention-drain features stay off until configured. Security advisory coverage remains operator-deferred and is not a stable-release gate.