Skip to content

release: v0.4.0 — Apache-2.0, core@v0.8.0, first tag in this repo - #18

Merged
bkd-dotcom merged 1 commit into
mainfrom
release-v0.4.0
Sep 1, 2026
Merged

release: v0.4.0 — Apache-2.0, core@v0.8.0, first tag in this repo#18
bkd-dotcom merged 1 commit into
mainfrom
release-v0.4.0

Conversation

@bkd-dotcom

Copy link
Copy Markdown
Member

Cuts signetry-cursor v0.4.0 — the first release tagged in this repository.

CHANGELOG.md carries a ## [0.3.0] — 2026-07-26 entry, but git tag here is empty:
that release was cut in the pre-move repo and its tag did not survive the org move. So
the repo has been at "0.3.0 plus six weeks of unreleased work" with nothing installable
to point at. v0.4.0 is the first tag that exists here, and the changelog says so
rather than leaving a reader to work it out.

Everything in the promoted block is real and unreleased: the Apache-2.0 relicense under
the open-core split, the Signetry naming, and the non-exclusive CLA fallback grant.

Pins

was now
signetry-core (README.md, CONTRIBUTING.md) core@v0.7.0 core@v0.8.0
advisory reviewer workflow reviewer@v0.2.0 reviewer@v0.3.0

The unreleased bullet claimed the pins were core@v0.6.0 / reviewer@v0.1.2. Since
none of that block ever shipped, the delta an adopter actually gets is
core@v0.8.0 / reviewer@v0.3.0, and the bullet now states that.

@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Signetry Reviewer — 🟣 Escalate to a designated reviewer

Escalate to a designated reviewer — this PR touches security-sensitive surface (.github/workflows/reviewer.yml). No blocking issue was found automatically, but a human owner should sign off.

Deterministic gates (the authority)

Gate Status
Required status check — unknown
Secret scan ✅ clean
CI permission / OIDC ✅ no forbidden change
Dependency skew ✅ ok
All green

Findings (1, 0 blocking)

  • 🟡 Change touches a protected path: .github/workflows/reviewer.yml .github/workflows/reviewer.yml (via cross-check)
    • .github/workflows/reviewer.yml matches a protected pattern (.github/workflows/*). Changes here alter shared/foundational surface and warrant a designated reviewer.
    • Fix: Route to a code owner / architecture reviewer.

Sensitive surface

This PR changes security-sensitive paths that warrant a designated reviewer:

  • .github/workflows/reviewer.yml

Merge

A designated reviewer / code owner should sign off before merge (sensitive surface).

This review is advisory. It never merges on its own judgement — the deterministic gates + a human are the authority. Findings can have false negatives; a green bot verdict is not a guarantee.

@bkd-dotcom
bkd-dotcom merged commit 50b9f79 into main Sep 1, 2026
2 checks passed
@bkd-dotcom
bkd-dotcom deleted the release-v0.4.0 branch September 1, 2026 16:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant