Summary
Publish the audited OSS repository and GHCR runtime image after policy, history, workflow, and GitHub hardening prerequisites pass.
Proposed Approach
- Confirm history/identity approval and clean security audit.
- Confirm branch and Actions hardening.
- Change repository visibility to public.
- Change the GHCR runtime package to public through GitHub's supported administrative surface.
- Verify anonymous source access and digest-pinned image pulls.
Acceptance Criteria
Related
Summary
Publish the audited OSS repository and GHCR runtime image after policy, history, workflow, and GitHub hardening prerequisites pass.
Proposed Approach
Acceptance Criteria
Related