Skip to content

docs(release): disposition v4 release identity incident - #67

Closed
aatuh wants to merge 1 commit into
masterfrom
delivery/rel-000-v4-identity
Closed

docs(release): disposition v4 release identity incident#67
aatuh wants to merge 1 commit into
masterfrom
delivery/rel-000-v4-identity

Conversation

@aatuh

@aatuh aatuh commented Aug 15, 2026

Copy link
Copy Markdown
Owner

Summary

Records the v4 release-identity incident, corrects the immutable module checksum used by contrib, pauses unsafe v4 publication, and adds the matching documentation contract assertion.

The reference service uses kin-openapi 0.144.0 rather than 0.142.0, which GitHub dependency review reported as critically vulnerable.

Backlog ticket

  • Ticket ID: REL-000
  • One ticket scope: release-identity repair, including the security-safe dependency version required by its tidy update.

Final commit

  • One conventional final commit with Refs: REL-000.
  • No breaking change.

Tests and verification

GOWORK=off GOTOOLCHAIN=local make docs-check — PASS

Documentation

  • README, release incident, runbook, contract coverage, and generated search index updated.

Compatibility and migration impact

  • No API change or code migration.

Security and dependency impact

  • Documents the release-identity safety hold, corrects the module checksum, and updates kin-openapi to 0.144.0.

Generated-file and benchmark impact

  • Regenerated search index included; no performance-sensitive path changed.

@aatuh
aatuh force-pushed the delivery/rel-000-v4-identity branch from 5793433 to f128272 Compare August 15, 2026 15:05
@aatuh

aatuh commented Aug 15, 2026

Copy link
Copy Markdown
Owner Author

Protected-check blocker — 2026-08-15

All protected checks except the minimum-Go job passed. That job correctly failed make vuln on reachable vulnerabilities in google.golang.org/grpc 1.81.1 and golang.org/x/text 0.37.0; it also reports vulnerable github.com/go-chi/chi/v5 5.2.5 and golang.org/x/net 0.55.0.

The corresponding current Dependabot updates are #65, #63, #58, and #52. Each is itself blocked by the same pre-REL-000 checksum baseline, so neither sequence can merge independently while required checks remain enforced.

Disposition: keep this PR draft and blocked. Do not bypass checks or merge vulnerable code. A scoped bootstrap decision is required to combine the release-baseline checksum repair with these required dependency fixes, or to introduce an equivalent prerequisite path.

@aatuh

aatuh commented Aug 15, 2026

Copy link
Copy Markdown
Owner Author

Superseded by #68, which creates the explicit REL-000A bootstrap ticket and includes the required security upgrades so the protected vulnerability gate can pass without a bypass.

@aatuh aatuh closed this Aug 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant