Skip to content
ReleaseOrigin
January guideSampleTemplatesAsk about a pilot

T Terms

One release lane. Clear control boundaries.

Effective September 4, 2026

Inquiry and acceptance

Submitting the form is an inquiry, not a purchase, automatic booking, or promise that a package is suitable. Work begins only after ReleaseOrigin confirms fit and scope in writing and agreed payment is received. Unsuitable paths are declined or rescoped before charging.

Founding pilot price and scope

The $149 founding rate is limited to the first three accepted, paid pilots. Each pilot covers one npm package, one package-declared public repository, one visible release workflow, one supported hosted CI path, and one consolidated revision. It does not include monorepo-wide migration, multiple packages or workflows, private repository review, ongoing release operations, or account administration.

Deliverables

The accepted handoff includes a dated public registry and repository evidence card; an explicit direct-OIDC, staged-publishing, verification-only, or no-fit decision; a PR-ready workflow patch when compatible; customer-only npm configuration steps; static, non-executing validation; an owner-run rehearsal, retry, and post-release verification checklist; and rollback notes.

Delivery target

The 24-hour target begins after written fit and scope confirmation, receipt of the required public inputs, and agreed payment. Platform outages, unavailable public metadata, newly discovered compatibility constraints, or delayed client feedback may require a revised delivery time. Any material change will be communicated.

Public sources and access

Initial fit review uses the npm public registry and a package-declared public GitHub or GitLab repository. ReleaseOrigin does not require an npm token, production credential, private repository, package archive, customer data, or source upload for the founding pilot. Do not send such material through the inquiry form.

No code execution or publication by the site

The checker does not download package tarballs, install dependencies, run lifecycle scripts, execute package code, change registry or repository settings, or publish a package. Any dry run or release rehearsal is an owner-run checklist for the customer’s controlled environment after review. The authorized customer publisher controls account configuration, merge, trigger, and publication.

Evidence and outcome limits

Registry attestation metadata and public workflow paths are point-in-time evidence. Their presence is not proof of security, authenticity, compliance, or non-malicious code. Their absence is not proof of insecurity, a vulnerability, negligence, noncompliance, or an incorrect release. ReleaseOrigin is not a security audit, code audit, penetration test, compliance assessment, certification, or legal opinion and does not guarantee registry approval, availability, adoption, revenue, or any other commercial result.

Client responsibilities

The client must have authority to request the work, identify the correct package and release owner, verify public links, review the proposed change, safeguard all accounts and credentials, confirm current provider requirements, and perform or authorize every state-changing action.

Third-party platforms

npm, GitHub, GitLab, hosted CI providers, package managers, and repositories are controlled by their respective operators and remain subject to their own terms and availability. ReleaseOrigin cannot control later platform or policy changes.

Ownership and reuse

After agreed payment, the client may use and adapt the custom workflow patch and handoff materials for the accepted package. Pre-existing tools, general methods, public-source material, and third-party components remain subject to their existing ownership and licenses.

Independent service

ReleaseOrigin is an independent service and is not affiliated with or endorsed by npm, Inc., GitHub, Inc., GitLab B.V., or the publishers of packages mentioned by the public checker.

Written scope controls

If an accepted written scope conflicts with these general terms, the accepted written scope controls for that pilot.

© 2026 ReleaseOrigin.

PrivacyTerms