Skip to content

release: v0.5.0 — Apache-2.0, core@v0.8.0, reviewer@v0.3.0 - #32

Merged
bkd-dotcom merged 1 commit into
mainfrom
release-v0.5.0
Sep 1, 2026
Merged

release: v0.5.0 — Apache-2.0, core@v0.8.0, reviewer@v0.3.0#32
bkd-dotcom merged 1 commit into
mainfrom
release-v0.5.0

Conversation

@bkd-dotcom

Copy link
Copy Markdown
Member

Cuts Signetry Admission v0.5.0: the Apache-2.0 relicense, signetry-core@v0.8.0,
signetry-reviewer@v0.3.0.

A release that was never written down

CHANGELOG.md had two sections under ## [Unreleased], and only one of them was
actually unreleased. ### Changed — Signetry naming shipped in v0.4.0 on
2026-08-12 — its own bullets pin core@v0.6.0 and reviewer@v0.1.2, versions that
predate main. It was sitting under Unreleased telling readers that the rename,
the signetry CLI, the SIGNETRY_* env prefix and the .signetry/admission.yaml
contract path had not shipped yet, while @v1 had been serving all of it for three
weeks.

So this splits them: ## [0.4.0] — 2026-08-12 now holds the naming section (with the
@v1 move that the other release entries all record), and ## [0.5.0] holds the
licensing change plus this release's pin bumps.

One stale claim corrected

MARKETPLACE.md told Marketplace readers to "Pin @v1 (moving) or @v0.2.0
(exact)" — two releases out of date, so anyone who followed it verbatim pinned an
Action from before the Signetry rename. It names @v0.5.0 now.

Pins

was now
action.yml default core install core@v0.7.0 core@v0.8.0
advisory reviewer workflow reviewer@v0.2.0 reviewer@v0.3.0

The changelog is explicit that the pin was @v0.6.0 as of v0.4.0 and that an
intermediate bump to @v0.7.0 (#30) landed on main without a changelog entry —
the gap is recorded rather than papered over.

Floors are deliberately left alone: SECURITY.md's @v0.1.3+ and the
signetry-core >= 0.5.0 capability floors in action.yml / MARKETPLACE.md are
minimums, not pins, and are still correct.

@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown

Signetry Reviewer — 🟣 Escalate to a designated reviewer

Escalate to a designated reviewer — this PR touches security-sensitive surface (.github/workflows/reviewer.yml). No blocking issue was found automatically, but a human owner should sign off.

Deterministic gates (the authority)

Gate Status
Required status check — unknown
Secret scan ✅ clean
CI permission / OIDC ✅ no forbidden change
Dependency skew ✅ ok
All green

Findings (2, 0 blocking)

  • 🟡 Change touches a protected path: .github/workflows/reviewer.yml .github/workflows/reviewer.yml (via cross-check)
    • .github/workflows/reviewer.yml matches a protected pattern (.github/workflows/*). Changes here alter shared/foundational surface and warrant a designated reviewer.
    • Fix: Route to a code owner / architecture reviewer.
  • 🟡 Change touches a protected path: action.yml action.yml (via cross-check)
    • action.yml matches a protected pattern (action.yml). Changes here alter shared/foundational surface and warrant a designated reviewer.
    • Fix: Route to a code owner / architecture reviewer.

Sensitive surface

This PR changes security-sensitive paths that warrant a designated reviewer:

  • .github/workflows/reviewer.yml

Merge

A designated reviewer / code owner should sign off before merge (sensitive surface).

This review is advisory. It never merges on its own judgement — the deterministic gates + a human are the authority. Findings can have false negatives; a green bot verdict is not a guarantee.

@bkd-dotcom
bkd-dotcom merged commit 99a3092 into main Sep 1, 2026
2 checks passed
@bkd-dotcom
bkd-dotcom deleted the release-v0.5.0 branch September 1, 2026 15:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant