REQUEST CHANGES from the cross-family plan-review (2026-06-22), dispositioned: - expanded denylist (§4.2): submodules/.gitmodules, git hooks, .gitattributes filters, lockfile postinstall, generated artifacts - runner-trust assertion (privileged jobs GitHub-hosted only) - concrete diff-transport spec + threat model (signed artifact / branch-only token, nonce anti-replay) - gate-weakening detection (noqa/skip/excludes/--no-verify) - PR-metadata secret sanitization; ledger diff-hash anti-tamper - Phase 1b: recovery for an accidentally-merged/applied privileged change + draft-PR rate monitoring + stale-PR cleanup - required-check-name discovery; deploy-before-merge enforcement; no-write-token audit Notes which BLOCK items are already implemented in PR #17's CI (Phase 1 verifies, not rebuilds). |
||
|---|---|---|
| .. | ||
| DEPLOY-AUDIT.md | ||
| OPERATOR-RUNBOOK.md | ||
| P1-DEMO-SCRIPT.md | ||
| P3-LIVE-FLIP-PLAN.md | ||
| PROVISIONING-RUNBOOK.md | ||