Skip to content

ci: harden release and document security process - #4

Merged
joey-huckabee merged 1 commit into
mainfrom
ci-release-endor-hardening
Sep 7, 2026
Merged

joey-huckabee merged 1 commit into
mainfrom
ci-release-endor-hardening

Conversation

@joey-huckabee

Copy link
Copy Markdown
Contributor

Summary

  • document container and repository-only release/version behavior in docs/VERSION.md
  • document CI layers, result review, enforced GitHub settings, and minimal Endor Labs adoption in docs/CI.md and docs/ENDOR.md
  • validate release tags, image inputs, dated changelog sections, and annotated tags before publication
  • add workflow concurrency/timeouts plus focused release-validator tests
  • add security-aware bug and pull-request templates

Live repository controls

  • require pull requests, resolved threads, and up-to-date lint/image checks on main
  • prevent deletion and non-fast-forward updates with no bypass actors
  • require full commit SHAs for GitHub Actions
  • add accurate discovery/security topics

Required approvals remain at zero per the documented pre-release decision.

Validation

  • release-tag positive and negative tests pass
  • pre-commit run --all-files --show-diff-on-failure passes
  • git diff --check passes

This is repository-only work and does not publish or increment a container version.

@joey-huckabee
joey-huckabee merged commit 2b22f24 into main Sep 7, 2026
4 checks passed
@joey-huckabee
joey-huckabee deleted the ci-release-endor-hardening branch September 7, 2026 03:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant