Skip to content

Document the R09 release security gate - #30

Merged
trsdn merged 1 commit into
mainfrom
standard/1.21.0
Sep 22, 2026
Merged

trsdn merged 1 commit into
mainfrom
standard/1.21.0

Conversation

@trsdn

@trsdn trsdn commented Sep 22, 2026

Copy link
Copy Markdown
Owner

Adds the release security gate R09 needs (new in standard 1.16.0/1.18.0,
not present when this repository was last assessed at 1.15.0): a documented
step in RELEASE_CHECKLIST.md that checks, before tagging, that the release
commit has no open secret-scanning alert and no open critical/high Dependabot
alert. Both are already enabled and running continuously on this repository
(S05, P12); this step reads their state rather than adding a new scanner.

Also adds a "Release security gate log" table, matching the existing smoke-test
log convention, and retroactively records the check for the latest release,
v1.3.2 (commit 649471a): 0 open secret-scanning alerts, 0 open
critical/high Dependabot alerts, checked via the GitHub API on 2026-09-22.

Part of bringing this repository to
Repository Quality Standard 1.21.0,
following the fleet rollout procedure.
This is the "pipeline" PR of at most three; the record PR (.github/conformance.yml,
badge, docs/self-assessment.md) follows separately.

No code changes. Nothing here touches release signing, Apple credentials, or
the notarization broker.

🤖 Generated with Claude Code

https://claude.ai/code/session_01CdiwBVuH6DCEtFPPwxbXKc

Add a step and a recorded log to RELEASE_CHECKLIST.md: before tagging,
confirm the release commit has no open secret-scanning alert and no open
critical or high Dependabot alert, using the checks the repository already
runs continuously (S05, P12). Retroactively records the check for v1.3.2,
the latest release: both empty.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CdiwBVuH6DCEtFPPwxbXKc
@trsdn
trsdn merged commit 8effb7f into main Sep 22, 2026
10 checks passed
@trsdn
trsdn deleted the standard/1.21.0 branch September 22, 2026 08:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant