Skip to content

release: make the OSS repository and runtime image public #80

Description

@bradtaylorsf

Summary

Publish the audited OSS repository and GHCR runtime image after policy, history, workflow, and GitHub hardening prerequisites pass.

Proposed Approach

  • Confirm history/identity approval and clean security audit.
  • Confirm branch and Actions hardening.
  • Change repository visibility to public.
  • Change the GHCR runtime package to public through GitHub's supported administrative surface.
  • Verify anonymous source access and digest-pinned image pulls.

Acceptance Criteria

  • Policy, history, workflow, and settings prerequisites are complete.
  • Repository is publicly browsable and anonymously cloneable.
  • Runtime package is anonymously pullable by immutable digest.
  • No private dependency blocks a fresh user.
  • Publication state is re-read anonymously and recorded.
  • Incident and disclosure instructions are visible.

Related

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestneeds-human-inputRequires human review or decisionpriority:highImportant for the complete OSS product

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions