openclaw/docs/ci
Peter Steinberger 56f616e437
fix(release): dependency advisories no longer fail or delay a release (#161463)
* fix(release): record dependency advisories without blocking releases

Release dependency evidence now blocks only on known malware. Vulnerability
advisories of every severity are recorded in the evidence summary and surfaced
as GitHub warning annotations, and CI dispatched by Full Release Validation or
release publication reports a failing production audit as a warning. The
per-release risk-acceptance table existed only to accept advisory blockers and
is removed.

The release skills also record that main CI health never gates a release and
that every failed test gets an explicit real-blocker-or-flake decision.

* fix(ci): keep release audit relaxation within the workflow size budget

ci.yml sits at the 480000-byte guard, so the release-dispatch check moves
into a trusted harness script that security-fast already checks out.
2026-09-30 01:11:12 +00:00
..
release-validation fix(e2e): size update lane budgets from hosted 4-vCPU measurements 2026-09-28 20:03:19 -07:00
scope-and-routing
capacity.md fix(ci): retry Gateway-first packing only when the hybrid plan exceeds its cap 2026-09-29 02:50:04 -07:00
checkout.md
local-proof.md fix(ci): prepare channels workers before test collection 2026-09-29 07:41:16 -07:00
pipeline.md fix(release): dependency advisories no longer fail or delay a release (#161463) 2026-09-30 01:11:12 +00:00
release-validation.md
routing-costs.md
runners.md fix(ios): pause the hidden sidebar mascot (#160607) 2026-09-28 19:22:15 +00:00
scheduled-workflows.md fix(release): dependency advisories no longer fail or delay a release (#161463) 2026-09-30 01:11:12 +00:00
scope-and-routing.md
watching-runs.md