docs(security): add github target owner status ledger
This commit is contained in:
@@ -39,7 +39,7 @@ S3.4 開始,等待 runtime gate 時要看哪些前置條件,由 `security_fo
|
||||
| 1 | Redacted finding ingestion | `design_or_draft_review` | 只審是否可設計或建立 draft PR |
|
||||
| 2 | Safe web crawl | `low_noise_scan_scope_review` | 只審低噪音 scope 定義 |
|
||||
| 3 | Gitea owner attestation + read-only inventory | `read_only_inventory_review` | 先依 S4.9 審 S4.7 owner response,再審只讀 token 或 redacted export |
|
||||
| 4 | GitHub target decisions | `design_or_draft_review` | 先審 S4.10 owner response request packet / response 與 S4.12 workflow / secret 名稱 response,再審 owner / visibility / canonical 草案 |
|
||||
| 4 | GitHub target decisions | `design_or_draft_review` | 先審 S4.10 owner response request packet / template status ledger / response 與 S4.12 workflow / secret 名稱 response,再審 owner / visibility / canonical 草案 |
|
||||
| 5 | Ref truth review | `design_or_draft_review` | 先審 S4.11 owner response 驗收,再審人工分類與 reconcile 草案 |
|
||||
| 6 | Credentialed scan | `manual_exception_review` | 只審 exception 設計 |
|
||||
| 7 | Kali full-upgrade / reboot | `manual_exception_review` | 只審維護窗口與 rollback 計畫 |
|
||||
|
||||
Reference in New Issue
Block a user