You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Both current-main validation suites pass. The template is internally consistent at its older reviewed schema-v3 contract and its immutable example engine pin is reachable from core main. The confirmed gaps are about truthful deployment capabilities/role isolation and the absent release/freshness lifecycle, not a reason to replace an immutable pin with a moving ref.
Without #11, GitHub Free/private adopters can be promised an unavailable approval mechanism and privileged roles remain descriptive rather than machine-isolated. Without #12, no adopter can execute the documented tagged-release baseline and no exact signal says which core/template pair was reviewed together.
Bounded scope
This issue only coordinates #11 and #12 and records their dependency order. Implementation and acceptance remain in those distinct issues.
Non-goals
No source changes are requested in this tracker itself.
No live GitHub Environment, runner group, credential, host, deployment, status receiver, or consumer-repository change.
No project-specific delivery policy in the public template.
No rename decision; core #25 remains owner-controlled.
No mandatory telemetry.
Cross-repository compatibility
The template must remain schema-v3 compatible with explicitly reviewed core commits, preserve ordinary-CI/tester/deployer/ref-writer boundaries, and retain immutable exact pins. Core #24 owns the public operator index; this tracker owns only the template side.
Core #24 links the final template release/update path.
All fictional examples and validation remain Linux/Bash-only, secret-free, and free of private infrastructure inventory.
Final current-main validation passes in both repositories.
Validation
Use the repository checks required by #11 and #12, plus an exact-commit comparison against the core compatibility record. No live deployment or infrastructure proof is part of this tracker.
Audit baseline
This tracks the confirmed public-template follow-up from the 2026-08-08 core/template compatibility audit.
Reviewed heads:
e483998b34595e51426c3b14589a74ca09ae78a9b76aefe668f07904e1a782fa5b779b606d6a44c9Both current-main validation suites pass. The template is internally consistent at its older reviewed schema-v3 contract and its immutable example engine pin is reachable from core main. The confirmed gaps are about truthful deployment capabilities/role isolation and the absent release/freshness lifecycle, not a reason to replace an immutable pin with a moving ref.
Confirmed gap issues
Dependency order:
Core dependencies and cross-links:
User/operator impact
Without #11, GitHub Free/private adopters can be promised an unavailable approval mechanism and privileged roles remain descriptive rather than machine-isolated. Without #12, no adopter can execute the documented tagged-release baseline and no exact signal says which core/template pair was reviewed together.
Bounded scope
This issue only coordinates #11 and #12 and records their dependency order. Implementation and acceptance remain in those distinct issues.
Non-goals
Cross-repository compatibility
The template must remain schema-v3 compatible with explicitly reviewed core commits, preserve ordinary-CI/tester/deployer/ref-writer boundaries, and retain immutable exact pins. Core #24 owns the public operator index; this tracker owns only the template side.
Acceptance criteria
Validation
Use the repository checks required by #11 and #12, plus an exact-commit comparison against the core compatibility record. No live deployment or infrastructure proof is part of this tracker.
Parallel-safe work