Conversation
wborn
left a comment
There was a problem hiding this comment.
This is an initial AI-assisted review.
Two workflow inconsistencies should be resolved before merging. The handbook broadens the CVE splitting rule beyond independently fixable vulnerabilities, and its publication rule conflicts with the related advisory tracker by requiring a fixed release even though valid vulnerabilities with no planned fix are explicitly considered publishable. There is also one smaller documentation cleanup around obsolete branch-protection guidance. Details are in the inline comments.
e83b16f to
acea2d5
Compare
|
|
||
| ### Merging | ||
|
|
||
| Branch protection does not need to be touched for this merge. GitHub does not run status checks on pull requests in a temporary private fork, and does not enforce the protection rules set on the branch being merged into. |
There was a problem hiding this comment.
Has this been tested ? In all advisories I merged, I had to make changes to branch protection otherwise merge would be refused / fail.
There was a problem hiding this comment.
Not tested, but also I need to be more accurate here you'll have to use "Merge and bypass branch protections" and therefore you shouldn't need to touch the rules.
It also says this as a note:
This repository is protected by branch protections. These changes can only be merged by bypassing these protections.
There was a problem hiding this comment.
I updated it, but will need to test it before I resolve this thread.
Documents the parts of 6.4 that were only in people's heads, and corrects two things that have gone stale.
openremote/security-managersrather than "Product Owners".Publishable.