feat: harden reviewed registry releases
All checks were successful
Standalone registry checks / check (push) Successful in 3m43s
All checks were successful
Standalone registry checks / check (push) Successful in 3m43s
This commit is contained in:
parent
0bcd4a2fc9
commit
e83f43d00f
37 changed files with 2856 additions and 286 deletions
|
|
@ -15,8 +15,8 @@ a consumer's accepted destinations or signing keys.
|
|||
Policy, license, normalization, source-allowlist and signature changes receive
|
||||
explicit maintainer review and complete acceptance checks. Additional independent
|
||||
review is appropriate for trust-boundary changes when another qualified reviewer
|
||||
is available. This is a governance expectation; the current software does not
|
||||
enforce a multi-reviewer quorum or authenticate a free-text reviewer name.
|
||||
is available. The software authenticates each decision to an allowed SSH reviewer
|
||||
identity, but does not enforce a multi-reviewer quorum.
|
||||
|
||||
Corrections and appeals must identify the exact assertion or review fingerprint
|
||||
and supply contrary evidence. Retain the original claim and decision, append the
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue