You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/V0.5.4_ENGINEERING_PLAN.md
+17-2Lines changed: 17 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -41,8 +41,8 @@ opens a lower-friction support channel and submits the one currently eligible cu
41
41
| G2 | Real-world regression corpus | One deterministic command executes structured cases for report rendering, pnpm workspace inheritance, nested templates, moved-condition retest and benign numeric SVG review; generated JSON/Markdown records provenance and limits | completed |
42
42
| G3 | First-trial and v0.5.4 candidate surfaces | Main-branch first trial is unpinned; CI/release/trusted install examples stay pinned; candidate version surfaces agree on 0.5.4 while published release state remains 0.5.3 | completed |
43
43
| G4 | Focused and final verification | New focused tests pass, generated artifacts are byte-current, one bounded complete-suite pass and Skill Creator validation pass | completed |
44
-
| G5 | Authorized external actions | Discussions is enabled and verified; awesome-devsecops rules are rechecked and a factual v0.5.3 PR is submitted if still eligible |in progress|
45
-
| G6 | Release approval checkpoint | Candidate commits and external evidence are pushed; exact release operations and residual risks are presented to the author |pending|
44
+
| G5 | Authorized external actions | Discussions is enabled and verified; awesome-devsecops rules are rechecked and a factual v0.5.3 PR is submitted if still eligible |completed|
45
+
| G6 | Release approval checkpoint | Candidate commits and external evidence are pushed; exact release operations and residual risks are presented to the author |in progress|
46
46
| G7 | Public v0.5.4 release | Signed tag/assets, GitHub Release, npm provenance, `v1` consumer verification and release-state update | blocked on explicit approval |
47
47
48
48
## G0 - Scope and baseline
@@ -229,6 +229,21 @@ awesome-devsecops:
229
229
- Record PR URL, head commit, review state and any maintainer requirement. A submitted PR is not an
230
230
accepted listing.
231
231
232
+
Completion record (2026-08-16):
233
+
234
+
- Enabled GitHub Discussions and read back `has_discussions: true`; recorded the verified
235
+
repository timestamp and Discussions URL without creating synthetic questions or testimonials.
236
+
- Rechecked awesome-devsecops at current default-branch commit
237
+
`1704e442a30ca21caeb05e8721eb26855129c86b`: the repository is not archived, its free/open-source
238
+
scope and empty `CONTRIBUTING.md` are unchanged, and recent accepted additions use one README
239
+
line under the relevant category.
240
+
- Forked the repository, added one alphabetical `Tools > Testing` link and opened
"notes": "The published scope accepts free or open-source capabilities that support DevSecOps, which the CLI and Action can satisfy. CONTRIBUTING.md is empty and gives no current submission format, so recheck repository practice before any owner-authorized pull request."
44
+
"notes": "The policy commit remains current and accepts free or open-source DevSecOps capabilities. CONTRIBUTING.md is empty; recent merged additions change one README list item. PR 172 adds one Testing entry and makes no accuracy, adoption or endorsement claim.",
0 commit comments