diff --git a/README.md b/README.md
index 36ea4f52a..f414e44ae 100644
--- a/README.md
+++ b/README.md
@@ -1,7 +1,7 @@
> [!IMPORTANT]
> **Repository moved:** Reactive Resume now lives at **[`reactive-resume/reactive-resume`](https://github.com/reactive-resume/reactive-resume)** on GitHub.
> **Docker Hub stays at `amruthpillai/reactive-resume`.** GHCR builds now publish to `ghcr.io/reactive-resume/reactive-resume`.
-> Release GHCR tags: `latest`, `v5`, `v5.3`, and `v5.3.0` (AMD64 and ARM64). Future GHCR updates use the new namespace; historical images remain at the old address. See [migration details](https://github.com/reactive-resume/reactive-resume/issues/3503).
+> Verified image tags: `latest`, `v5`, `v5.3`, and `v5.3.0` (AMD64 and ARM64). The current version was rebuilt and production redeployed for this rename; no new GitHub release or version bump was made. See [migration details](https://github.com/reactive-resume/reactive-resume/issues/3503).
> GitHub Sponsors and Open Collective funding links remain unchanged.
diff --git a/docs/agents/container-publishing.md b/docs/agents/container-publishing.md
index 115bbe177..ceebeb0f7 100644
--- a/docs/agents/container-publishing.md
+++ b/docs/agents/container-publishing.md
@@ -16,6 +16,10 @@ the architecture-specific cache keys keep the two builders separate.
| Manual dispatch, default `release=false` | `sha-*`, `canary-
-` | No |
| Push of a `v*` tag or explicit `release=true` | `sha-*`, `latest`, version/major/minor | Yes: SSH redeploy and Cloudflare purge |
+Manual `release=true` republishes the version already in `package.json` and redeploys
+production. It does not create a Git tag, GitHub release, or version bump. Use this for
+an approved current-version rebuild; it replaces the existing stable image aliases.
+
Manual canaries first run a cache-only build on each architecture, then publish, merge,
and sign both registry images. Run one with:
@@ -30,6 +34,19 @@ repository linkage, and Actions access before consumers can pull anonymously.
## Verification and historical images
+The September 12, 2026 rename rebuild used commit `f89acb436865cf536fffed2b23d4d72a7ecff0db`
+in [workflow run 34685606073](https://github.com/reactive-resume/reactive-resume/actions/runs/34685606073).
+Both registries' `latest`, `v5`, `v5.3`, and `v5.3.0` aliases were verified at:
+
+```text
+sha256:7c7b7824785d1386fa6e0e6132c1abe43e3c281f90dbf3b1474b60bffb64d89e
+```
+
+The workflow built both architectures, generated SBOMs and provenance, signed the images,
+passed anonymous AMD64/ARM64 pulls from both registries, redeployed production, and purged
+Cloudflare. The live health endpoint reported healthy version `5.3.0`, and the homepage
+served the new repository URL. No new GitHub release or version bump was made.
+
Check the manifest for `linux/amd64` and `linux/arm64`, then pull both using an empty
Docker configuration with explicit empty registry credentials to prove anonymous access
(a completely empty directory can still discover a system credential helper):