Skip to content

chore: Track 2026-08-08 core/template audit gaps: capability-aware policy (#11) and template release (#12) #13

Description

@Nickfost

Audit baseline

This tracks the confirmed public-template follow-up from the 2026-08-08 core/template compatibility audit.

Reviewed heads:

  • template: e483998b34595e51426c3b14589a74ca09ae78a9
  • core: b76aefe668f07904e1a782fa5b779b606d6a44c9

Both current-main validation suites pass. The template is internally consistent at its older reviewed schema-v3 contract and its immutable example engine pin is reachable from core main. The confirmed gaps are about truthful deployment capabilities/role isolation and the absent release/freshness lifecycle, not a reason to replace an immutable pin with a moving ref.

Confirmed gap issues

Dependency order:

  1. feat: Model GitHub plan capability and isolate privileged deployment roles in fleet.json policy #11 — make deployment policy capability-aware and isolate privileged roles. Design input comes from core deployer/tester issues #22/#23; the minimum truthful documentation/schema boundary can land before those installers.
  2. feat: Publish tagged template release and machine-readable core compatibility/freshness signal #12 — publish a real template release and exact core compatibility signal. It must include or explicitly defer feat: Model GitHub plan capability and isolate privileged deployment roles in fleet.json policy #11 before advertising the template as a complete delivery contract.

Core dependencies and cross-links:

User/operator impact

Without #11, GitHub Free/private adopters can be promised an unavailable approval mechanism and privileged roles remain descriptive rather than machine-isolated. Without #12, no adopter can execute the documented tagged-release baseline and no exact signal says which core/template pair was reviewed together.

Bounded scope

This issue only coordinates #11 and #12 and records their dependency order. Implementation and acceptance remain in those distinct issues.

Non-goals

  • No source changes are requested in this tracker itself.
  • No live GitHub Environment, runner group, credential, host, deployment, status receiver, or consumer-repository change.
  • No project-specific delivery policy in the public template.
  • No rename decision; core #25 remains owner-controlled.
  • No mandatory telemetry.

Cross-repository compatibility

The template must remain schema-v3 compatible with explicitly reviewed core commits, preserve ordinary-CI/tester/deployer/ref-writer boundaries, and retain immutable exact pins. Core #24 owns the public operator index; this tracker owns only the template side.

Acceptance criteria

Validation

Use the repository checks required by #11 and #12, plus an exact-commit comparison against the core compatibility record. No live deployment or infrastructure proof is part of this tracker.

Parallel-safe work

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions