Skip to content

release: v0.2.0 — Apache-2.0, self-hostable App, reviewer@v0.3.0 - #15

Merged
bkd-dotcom merged 1 commit into
mainfrom
release-v0.2.0
Sep 1, 2026
Merged

release: v0.2.0 — Apache-2.0, self-hostable App, reviewer@v0.3.0#15
bkd-dotcom merged 1 commit into
mainfrom
release-v0.2.0

Conversation

@bkd-dotcom

Copy link
Copy Markdown
Member

Cuts signetry-github-app v0.2.0 — the Apache-2.0 relicense and the community-health
files, none of which had shipped since 0.1.0 on 2026-07-26.

This repo carries no policy logic: it is the App manifest, the setup runbook, and the
docs for an App served by the hosted signetry service. So the release is small by
design — what changes is that forking and self-hosting the App is now explicitly
permitted, CONTRIBUTING.md states the two invariants a change here must preserve (the
App is comment-only, and its comment never claims more than the signed receipt
does), and the CLA's fallback licence grant is non-exclusive.

Pins

was now
advisory reviewer workflow reviewer@v0.2.0 reviewer@v0.3.0

The changelog's sibling-version bullet moves from core@v0.6.0 / reviewer@v0.1.2 to
core@v0.8.0 / reviewer@v0.3.0, matching what the rest of the platform shipped today.

@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown

Signetry Reviewer — 🟣 Escalate to a designated reviewer

Escalate to a designated reviewer — this PR touches security-sensitive surface (.github/workflows/reviewer.yml). No blocking issue was found automatically, but a human owner should sign off.

Deterministic gates (the authority)

Gate Status
Required status check — unknown
Secret scan ✅ clean
CI permission / OIDC ✅ no forbidden change
Dependency skew ✅ ok
All green

Findings (1, 0 blocking)

  • 🟡 Change touches a protected path: .github/workflows/reviewer.yml .github/workflows/reviewer.yml (via cross-check)
    • .github/workflows/reviewer.yml matches a protected pattern (.github/workflows/*). Changes here alter shared/foundational surface and warrant a designated reviewer.
    • Fix: Route to a code owner / architecture reviewer.

Sensitive surface

This PR changes security-sensitive paths that warrant a designated reviewer:

  • .github/workflows/reviewer.yml

Merge

A designated reviewer / code owner should sign off before merge (sensitive surface).

This review is advisory. It never merges on its own judgement — the deterministic gates + a human are the authority. Findings can have false negatives; a green bot verdict is not a guarantee.

@bkd-dotcom
bkd-dotcom merged commit eaefc45 into main Sep 1, 2026
2 checks passed
@bkd-dotcom
bkd-dotcom deleted the release-v0.2.0 branch September 1, 2026 16:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant