This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
# Publication readiness
|
||||
|
||||
The current source tip is prepared for public review. The repository remains
|
||||
private until the history and security-contact decisions below are confirmed.
|
||||
|
||||
## Completed
|
||||
|
||||
- GPL-3.0-or-later license, contribution guidance, security policy, third-party
|
||||
notices, and a user-oriented README are present.
|
||||
- Development branches are consolidated into one reviewed candidate branch.
|
||||
- No generated ELF, SDK archive, crash dump, device capture, or other binary
|
||||
release artifact is tracked.
|
||||
- Current source paths and manifests contain no private LAN repository URL or
|
||||
operator-specific filesystem path.
|
||||
- Host builds, policy tests, JSON validation, large-object review, and current
|
||||
plus all-ref secret scans are part of the publication review.
|
||||
- CI actions, container images, SDK downloads, and source revisions are pinned;
|
||||
downloaded SDK bytes are verified before use. Distribution packages follow
|
||||
the security-updated repository attached to the pinned base image rather than
|
||||
stale exact package revisions.
|
||||
- `SECURITY.md` publishes a fixed private reporting address.
|
||||
- Pull requests from public forks cannot run on the self-hosted CI runner.
|
||||
- `tools/export-public-source.sh` creates a parentless source candidate, strips
|
||||
machine-local agent instructions, and rejects private deployment markers,
|
||||
forbidden secret files, generated binaries, and oversized files.
|
||||
|
||||
## Decisions required before changing visibility
|
||||
|
||||
1. **Release policy.** Recommended: publish reviewed source only. Do not attach
|
||||
runnable PS5 ELF artifacts; if that policy changes later, require reproducible
|
||||
builds, checksums, corresponding source, and a separate safety review.
|
||||
|
||||
Historical commits contain an old private LAN URL, operator-specific paths, and
|
||||
author email metadata. Keep that canonical history private and publish only the
|
||||
parentless export from a reviewed commit. Deleting branches is not a substitute
|
||||
for this export.
|
||||
|
||||
Generated payloads, crash dumps, SDK archives, local hardware captures, and
|
||||
unredacted operator records are not public source artifacts and must remain
|
||||
outside Git.
|
||||
Reference in New Issue
Block a user