Skip to content

docs(security): add Release path & compromise scope appendix (#188) - #264

Merged
Chris-Wolfgang merged 1 commit into
vNextfrom
tier2/188-security-release-path
Jul 17, 2026
Merged

docs(security): add Release path & compromise scope appendix (#188)#264
Chris-Wolfgang merged 1 commit into
vNextfrom
tier2/188-security-release-path

Conversation

@Chris-Wolfgang

Copy link
Copy Markdown
Owner

Closes #188.

Summary

Appends the canonical Release path & compromise scope section to SECURITY.md, per the Etl-DbClient #240 template. Fills all 5 bullets with Try-Pattern specifics — OIDC release path, no fallback, owner, downstream consumer (D20-Dice), package coordinates.

Original acceptance criteria (full docs/DISASTER-RECOVERY.md runbook) is superseded by the OIDC decision (PR #254); the appendix pattern is what stays. Generic incident-response steps (unlisting, advisories, credential rotation) deliberately excluded — GitHub / NuGet own that documentation and update faster than a checked-in runbook.

Stacked-PR base

Base branch is vNext. First of a new 11-PR batch on vNext.

Test plan

  • SECURITY.md renders on GitHub with the appendix
  • No [fill in] placeholders left

Closes #188.

Appends the canonical "Release path & compromise scope" section per
the Etl-DbClient #240 template. Fills the 5 bullets with Try-Pattern
specifics:

- Release path via `NuGet/login@v1` OIDC Trusted Publishing (wired
  in PR #254; no long-lived API key on the NuGet account).
- Fallback: none — OIDC compromise = GitHub-account compromise.
- Owner: @Chris-Wolfgang.
- Known Wolfgang.* downstream: Wolfgang.D20.Dice.
- Package coordinates: Wolfgang.TryPattern on nuget.org.

Original scope ("full DISASTER-RECOVERY.md runbook") is superseded by
the OIDC decision — the appendix pattern is what stays. Generic
incident-response steps (unlisting, advisories, credential rotation)
deliberately excluded — GitHub / NuGet own that documentation.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings July 16, 2026 00:07

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants