ochenstarik-ui
|
4cc873883c
|
chore: repo hygiene — pin actions, dependabot, SBOM, docs
- Pin all 23 GitHub Actions uses to 40-char commit SHA with tag comments:
actions/checkout@v6 -> d23441a48e516b6c34aea4fa41551a30e30af803 (v6.1.0)
actions/setup-dotnet@v5 -> 26b0ec14cb23fa6904739307f278c14f94c95bf1 (v5.4.0)
actions/upload-artifact@v6 -> b7c566a772e6b6bfb58ed0dc250532a479d7789f (v6.0.0)
actions/download-artifact@v8 -> 3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c (v8.0.1)
softprops/action-gh-release@v2 -> 3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 (v2.6.2)
SHAs verified via gh api repos/<owner>/<action>/git/ref/tags/<tag>
- Move contents:write from workflow level to release steps only
- Add dotnet CycloneDX SBOM generation to linux-release and windows-release
- Add .github/dependabot.yml (github-actions + nuget, weekly, limit 5 PRs)
- Add SECURITY.md with private advisory channel, 72h SLA, threat model
- Add CHANGELOG.md from real git history (Keep a Changelog format)
- Add CONTRIBUTING.md with build/test instructions and Linux test note
- Add CODEOWNERS
- Add .github/ISSUE_TEMPLATE/{bug_report,feature_request}.md
- Add .github/PULL_REQUEST_TEMPLATE.md with mandatory verification checklist
|
2026-08-07 11:40:34 +07:00 |
|
ochenstarik-ui
|
c13501e529
|
fix(security): pin SSH trust and protect session keys (#8)
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
|
2026-07-31 02:36:52 +07:00 |
|
ochenstarik-ui
|
93e0f8ddbd
|
fix(security): harden enrollment and provisioning helper (#7)
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
|
2026-07-31 02:32:47 +07:00 |
|
ochenstarik-ui
|
3851d87534
|
Add standalone Linux bootstrap foundation (#5)
* Add standalone Linux bootstrap foundation
* Record bootstrap foundation progress
* Add single-code Node enrollment
* Validate bootstrap release payloads
* Add managed WireGuard mesh bootstrap
* Exercise repeated systemd installation in CI
* Expose systemd smoke failure diagnostics
* Fix bootstrap os-release variable collision
* Create policy helper directory during install
* Capture systemd smoke healthcheck errors
* Report Control listener diagnostics in CI
* Capture stalled Control process diagnostics
* Set service working directories
* Run protected CA healthcheck as root
* Add local Mesh emergency recovery
* Add multi-architecture Linux system matrix
* Add provisioning job control plane
* Stabilize Debian systemd smoke files
* Add node-scoped provisioning job channel
* Add provisioning progress state machine
* Reconcile expired provisioning jobs
* Add provisioning rollback workflow
* Add redacted provisioning event history
* Add restricted provisioning preflight helper
* Persist typed provisioning preflight facts
* Add preflight desired state drift detection
* Define strict base install schema catalog
* Add safe base install plan generation
* Add pre-confirmation base install plans
* Test base install plan API flow
* Authorize confirmed provisioning execution
---------
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
|
2026-07-30 21:18:39 +07:00 |
|
ochenstarik-ui
|
266900115c
|
Harden Link lifecycle and Control operations
* Harden link lifecycle and control operations
* Complete three-server acceptance lifecycle
---------
Co-authored-by: Ochenstarik <ochenstarik@inbox.ru>
|
2026-07-19 12:25:10 +07:00 |
|
Ochenstarik
|
497f197069
|
Normalize Windows workflow script indentation
|
2026-07-17 09:49:50 +07:00 |
|
Ochenstarik
|
2c31a10216
|
Fix clean runner MSIX publishing
|
2026-07-17 09:49:10 +07:00 |
|
Ochenstarik
|
5c383ec9e2
|
Add signed Windows MSIX release pipeline
|
2026-07-17 09:19:09 +07:00 |
|
Ochenstarik
|
3b28ff4462
|
Mark alpha artifacts as prerelease
|
2026-07-16 20:46:57 +07:00 |
|
Ochenstarik
|
46a1c393c7
|
Add persistent mTLS control layer
|
2026-07-16 20:35:05 +07:00 |
|
Ochenstarik
|
0f6dd31646
|
Restore ReadyToRun pack in CI
|
2026-07-16 18:52:48 +07:00 |
|
Ochenstarik
|
4fc5263c8d
|
Restore explicit Windows runtime in CI
|
2026-07-16 18:48:00 +07:00 |
|
Ochenstarik
|
4015e3e777
|
Add Windows build verification
|
2026-07-16 18:18:03 +07:00 |
|