Skip to content

ci: stabilize required quality gates - #113

Merged
aatuh merged 1 commit into
masterfrom
delivery/ci-003
Aug 22, 2026
Merged

ci: stabilize required quality gates#113
aatuh merged 1 commit into
masterfrom
delivery/ci-003

Conversation

@aatuh

@aatuh aatuh commented Aug 22, 2026

Copy link
Copy Markdown
Owner

Summary

  • add the canonical app-bound required-check manifest with stable explicit workflow job names and owners
  • verify manifest/workflow drift locally and exact strict branch protection through authenticated governance audits
  • retain verifier and mutation outcomes in release evidence
  • harden GitHub API input, response, outage, and payload-redaction behavior with hermetic provider fixtures

Validation

  • GOTOOLCHAIN=local make finalize
  • GOTOOLCHAIN=local make mutation-check
  • GOTOOLCHAIN=local make actions-audit
  • GOTOOLCHAIN=local make required-checks-verify required-checks-verify-contract
  • GITHUB_REPOSITORY=aatuh/api-toolkit GITHUB_DEFAULT_BRANCH=master make github-governance-check

Repository settings

Strict master protection now exactly matches all 18 app-bound PR checks. The pre-existing 17 identities were preserved and the already-running mutation GitHub Actions context was added.

Refs: CI-003

@aatuh
aatuh merged commit 07d8e41 into master Aug 22, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant