You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Track the distinction between public developer-preview visibility, merged product readiness, formal release authorization, and production deployment safety.
Current classification
main: dcb8e283f8445dd76f215a98023197d8ed5acab3
repository visibility: public
classification: PUBLIC DEVELOPER PREVIEW — NOT PRODUCTION READY
public source visibility: complete
exact-SHA evidence workflow: merged through PR #120
public documentation alignment: ready PR #126, unmerged
formal release authorization: blocked
production deployment authorization: not authorized
release-candidate SHA: not selected
Switchboard is intended for localhost or controlled trusted networks. Untrusted multi-tenant and direct internet-facing deployment are unsupported.
Completed public-preview and execution work
SHA-pinned, read-only GitHub Actions hardening.
Normal public workflow jobs and logs confirmed.
Dependabot and repository security controls added.
PR #126 aligns README.md, SECURITY_NOTES.md, docs/TASKLIST.md, and docs/reports/status.md with the merged execution/evidence baseline and removes stale permanent test/coverage/Mypy claims.
Require the Linux symlink-containment regression to run without a skip.
Run the complete clean-clone validation and Docker build.
Update PUBLIC_RELEASE_AUDIT.md through one narrow draft PR.
Verify owner-controlled repository protections and public security alerts.
Create a release/tag only after explicit authorization.
The selected candidate must pass:
Linux symlink-containment regression without a skip.
Clean Python 3.11 dependency installation and pip check.
Pinned pre-commit, Ruff, Black, Mypy, and TODO validation.
Full pytest and strict browser suite.
Aggregate and module coverage thresholds.
Bandit and pip-audit.
Full-history Gitleaks.
Link validation.
Docker build or a precise documented blocker.
git diff --check and final clean worktree.
PUBLIC_RELEASE_AUDIT.md updated with exact executed evidence.
Active product development outside the release gate
Issue #122 / draft PR #125 implements the GitHub exact-PR request/result adapter from the current merged product baseline. Issue #121 follows with opt-in exact evidence reuse.
Neither #122 nor #121 is a formal-release requirement unless the owner explicitly adds it. Do not silently move the release candidate to include Phase 2 work.
Public security and repository settings
Owner-controlled checks still to verify:
Require pull requests before merging to main.
Require conversation resolution.
Block force pushes.
Block branch deletion.
Repository is squash-merge-only.
Add or verify required checks using actual public check names.
Enable or verify CodeQL Default Setup when available.
Review CodeQL, Dependabot, and secret-scanning alerts.
Confirm Dependabot security updates.
Confirm repository description, topics, license detection, and social preview.
Goal
Track the distinction between public developer-preview visibility, merged product readiness, formal release authorization, and production deployment safety.
Current classification
Switchboard is intended for localhost or controlled trusted networks. Untrusted multi-tenant and direct internet-facing deployment are unsupported.
Completed public-preview and execution work
dcb8e283f8445dd76f215a98023197d8ed5acab3.Ready documentation change awaiting owner authorization
PR #126 aligns
README.md,SECURITY_NOTES.md,docs/TASKLIST.md, anddocs/reports/status.mdwith the merged execution/evidence baseline and removes stale permanent test/coverage/Mypy claims.The complete matrix and connector review passed. Closed PRs #123 and #124 are superseded history and must not be merged.
PR #126 requires separate explicit owner authorization before squash merge.
Formal release technical gate — #104
No release candidate is selected yet. The recommended candidate includes PR #126 if the owner approves it.
After PR #126 is resolved:
mainSHA as the release candidate.PUBLIC_RELEASE_AUDIT.mdthrough one narrow draft PR.The selected candidate must pass:
pip check.pip-audit.git diff --checkand final clean worktree.PUBLIC_RELEASE_AUDIT.mdupdated with exact executed evidence.Active product development outside the release gate
Issue #122 / draft PR #125 implements the GitHub exact-PR request/result adapter from the current merged product baseline. Issue #121 follows with opt-in exact evidence reuse.
Neither #122 nor #121 is a formal-release requirement unless the owner explicitly adds it. Do not silently move the release candidate to include Phase 2 work.
Public security and repository settings
Owner-controlled checks still to verify:
main.Formal release authorization
Explicit non-authorization
Until every formal gate is completed and the owner records authorization: