Skip to content

docs(security): add Release path & compromise scope appendix (#140) - #242

Merged
Chris-Wolfgang merged 1 commit into
vNextfrom
docs/security-release-path
Jul 25, 2026
Merged

docs(security): add Release path & compromise scope appendix (#140)#242
Chris-Wolfgang merged 1 commit into
vNextfrom
docs/security-release-path

Conversation

@Chris-Wolfgang

Copy link
Copy Markdown
Owner

Now unblocked by #207/#239 (OIDC is the release path) and the Trusted Publishing policies you just created. Appends the canonical "Release path & compromise scope" section to SECURITY.md — the load-bearing per-repo facts a maintainer needs at 2am during an incident:

  • Release path: OIDC / NuGet Trusted Publishing via NuGet/login@v1 — no long-lived key on GitHub or NuGet.
  • Fallback: none — a compromise is at the GitHub-account level (OIDC identity Chris-Wolfgang/ETL-Test-Kit).
  • Owner: @Chris-Wolfgang.
  • Downstream consumers: known Wolfgang.* dependents (ETL-Xml, ETL-FixedWidth, Etl-DbClient, ETL-Json, ETL-Transformers) + possible unknown external consumers.
  • Package coordinates for unlisting: both Wolfgang.Etl.TestKit and Wolfgang.Etl.TestKit.Xunit with nuget.org URLs.

No [fill in] placeholders remain; generic incident-response steps intentionally not duplicated (GitHub/NuGet docs update faster). Docs-only — no version bump, not a protected file. Shape matches Etl-DbClient #240.

Closes #140 when the vNext cycle merges to main.

🤖 Generated with Claude Code

Appends the canonical SECURITY.md appendix now that the release path is OIDC /
NuGet Trusted Publishing (#207/#239). Records the load-bearing per-repo facts a
maintainer needs during an incident: OIDC release path (no long-lived key),
no fallback, owner, known Wolfgang.* downstream consumers, and both packages'
nuget.org coordinates for unlisting. Generic incident-response steps are
intentionally not duplicated. Shape matches Etl-DbClient #240.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings July 24, 2026 23:51

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants