v0.20.0 — Opt-in issue-backlog hygiene (flag, never auto-close)
Opt-in issue-backlog hygiene — decided by a 5-expert sub-agent panel (unanimous PARTIAL) after a downstream adopter (Council) accreted 700+ open sentinel:* issues, ~half no longer applicable.
Principle: the accretion is structural (Sentinel files issues and never revisits them), but Sentinel must never auto-close — "stale ≠ resolved." Sentinel emits self-verifying signals; the human keeps closure authority.
Added
docs/sentinel/BACKLOG-HYGIENE.md(opt-in): the validity anchor (file:line+ snippet + reviewed SHA + dim, plussentinel:securitytag), a label vocabulary, and an opt-in re-validation sweep that flags but never closes — asymmetric closure authority (security never auto-closeable; non-security only on positive resolution evidence), migration-aware, default-on-doubt = keep open, auditable trail, + an optional SHA-pinned flag-only example Action.- Validity anchor + inflow discipline at filing (AGENTS.md §After Sentinel): 🟢 minors file as one digest issue per review.
Changed
- De-dup hardened to compare exploitability (SENTINEL.md Phase 3 + SEVERITY-RUBRIC.md): a new finding more severe or newly reachable than a matched open issue is no longer "Known" — it escalates.
Metrics
- SENTINEL.md 176/178 (unchanged) · AGENTS.md 134/135 post-setup (+1) · new companion doc · no gate weakening.
Full changelog: see CHANGELOG.md · PR #17