docs(security): add github target owner status ledger

This commit is contained in:
Your Name
2026-05-18 14:33:36 +08:00
parent 7be8868e5a
commit 91edf18552
31 changed files with 336 additions and 59 deletions

View File

@@ -34,7 +34,7 @@
| Redacted finding ingestion | MEDIUM | 只準備 ingestion adapter 的 redaction / audit 前置條件 |
| Safe web crawl scope | MEDIUM | 只準備 TLS/header/basic crawl 的低噪音 scope |
| Gitea owner attestation + read-only inventory | MEDIUM | 先依 S4.9 驗收 S4.7 owner response再準備 read-only token 或 redacted export inventory |
| GitHub target decision | HIGH | 只準備 S4.10 owner response request packet / response、S4.12 workflow / secret 名稱 response 驗收、owner / visibility / canonical / workflow parity 決策 |
| GitHub target decision | HIGH | 只準備 S4.10 owner response request packet / template status ledger / response、S4.12 workflow / secret 名稱 response 驗收、owner / visibility / canonical / workflow parity 決策 |
| Ref truth review | HIGH | 只準備 S4.11 owner response 驗收、refs truth / deprecated / release tag 人工判定 |
| Credentialed scan exception | HIGH | 只準備人工 exception、credential lifecycle 與停用方式 |
| Kali full-upgrade / reboot | HIGH | 只準備維護窗口、snapshot、rollback 與 post-health |