- Pin all 23 GitHub Actions uses to 40-char commit SHA with tag comments:
actions/checkout@v6 -> d23441a48e516b6c34aea4fa41551a30e30af803 (v6.1.0)
actions/setup-dotnet@v5 -> 26b0ec14cb23fa6904739307f278c14f94c95bf1 (v5.4.0)
actions/upload-artifact@v6 -> b7c566a772e6b6bfb58ed0dc250532a479d7789f (v6.0.0)
actions/download-artifact@v8 -> 3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c (v8.0.1)
softprops/action-gh-release@v2 -> 3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 (v2.6.2)
SHAs verified via gh api repos/<owner>/<action>/git/ref/tags/<tag>
- Move contents:write from workflow level to release steps only
- Add dotnet CycloneDX SBOM generation to linux-release and windows-release
- Add .github/dependabot.yml (github-actions + nuget, weekly, limit 5 PRs)
- Add SECURITY.md with private advisory channel, 72h SLA, threat model
- Add CHANGELOG.md from real git history (Keep a Changelog format)
- Add CONTRIBUTING.md with build/test instructions and Linux test note
- Add CODEOWNERS
- Add .github/ISSUE_TEMPLATE/{bug_report,feature_request}.md
- Add .github/PULL_REQUEST_TEMPLATE.md with mandatory verification checklist
46 lines
1.3 KiB
Markdown
46 lines
1.3 KiB
Markdown
## Description
|
|
|
|
<!-- What does this PR do? Briefly describe the change and its motivation. -->
|
|
|
|
## Related issue(s)
|
|
|
|
<!-- Link any related issues: Closes #N, Relates to #N -->
|
|
|
|
## Type of change
|
|
|
|
- [ ] Bug fix
|
|
- [ ] New feature / enhancement
|
|
- [ ] Documentation
|
|
- [ ] CI / tooling
|
|
- [ ] Security fix
|
|
- [ ] Refactor (no functional change)
|
|
|
|
---
|
|
|
|
## Verification checklist
|
|
|
|
> Fill in **all three sections**. Omitting a section or leaving placeholders
|
|
> will block review. Claiming something was verified when it was not is worse
|
|
> than marking it as not verified — the latter is acceptable, the former is not.
|
|
|
|
### ✅ Verified locally
|
|
|
|
<!-- List what you ran and the result. Example:
|
|
- `dotnet build` — passed
|
|
- `dotnet test` on Linux — all tests green
|
|
- `shellcheck` on changed deploy scripts — no errors
|
|
- Smoke-tested bootstrap install on Ubuntu 24.04 VM
|
|
-->
|
|
|
|
### ✅ Verified in CI
|
|
|
|
<!-- Paste links to workflow runs for this branch, or state "CI not yet run". -->
|
|
|
|
### ❌ Not verified / out of scope
|
|
|
|
<!-- Explicitly list what was NOT verified and why. Examples:
|
|
- Physical three-server acceptance test — SSH and topology parameters not available.
|
|
- Windows MSIX install on clean machine — no Windows test environment.
|
|
- arm64 boot — no arm64 runner locally.
|
|
|
|
This section must not be left empty. If everything is verified, write "None." -->
|