You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This successor issue keeps #192 from becoming a false finish line. The v0.1.4 queue is only stable when default-branch-compatible PR state, dependency/security alerts, security-workflow warning output, and required-gate evidence are reconciled from the current codebase.
상위/하위/인접 관계
상위 직무: v0.1.4 release readiness.
본 이슈 업무: default-branch PR queue and dependency/security gate stabilization.
O3: Patch dependency alerts in maintained-fix order where possible: Pygments lock/audit exception removal, then Rust transitive evidence for rand/glib.
O3: Patch CodeQL upload-sarif DEP0169 warnings by moving to a maintained immutable action SHA, or record external-owner follow-up if warning persists.
O4: Run required branch checks, dependency/security gates, and targeted local verification.
O5~O7: Add closure evidence as issue/PR comments; keep PR body concise and avoid dumping logs.
CodeQL upload-sarif DEP0169 warnings no longer appear in trivy and ossf-scorecard runs, or a narrow upstream-owned follow-up exists with exact run evidence.
v0.1.4 milestone has a clear queue status summary.
Required CI/security gates pass on the current default-branch-compatible head.
현재 역할
현재 상태
Closed baseline:
Open stabilization targets:
rand(GHSA-cq8v-f236-94qc) inapps/desktop/src-tauri/Cargo.lock.Pygments(GHSA-5239-wwwm-4pmq) inservices/analysis-engine/uv.lock.glib(GHSA-wrw7-89jp-8q8g) inapps/desktop/src-tauri/Cargo.lock.github/codeql-action/upload-sarifDEP0169 warnings intrivyandossf-scorecarddefault-branch runs.BEHINDthe default branch.현재 코드 기준 유효성
This successor issue keeps #192 from becoming a false finish line. The v0.1.4 queue is only stable when default-branch-compatible PR state, dependency/security alerts, security-workflow warning output, and required-gate evidence are reconciled from the current codebase.
상위/하위/인접 관계
trivyandossf-scorecard.실행 순서
BEHIND: update branch if still relevant, or supersede/close with evidence.완료 조건
trivyandossf-scorecardruns, or a narrow upstream-owned follow-up exists with exact run evidence.