Coming soon
Changelog
What changed, and what it means for your checks.
Each release lists what was added, changed, fixed and withdrawn. A defect that can produce an incorrect PASS is announced here, with the fixed release and the affected template.
-
AddedExecution
- Customer-CI execution from a pinned, checksummed release
- Read-only preflight for committed files
AddedRules
- Rule templates refund.amount-cap@1 and http.auth-required@1
- Rules read from the pull request’s base commit; changes to rules, code owners or workflows report policy-review-required
AddedEvidence
- Trust class customer-ci on every result, with release commit and code digest
- Opt-in evidence file as a 7-day workflow artifact
AddedProfile
- Explicit unsupported-profile result outside the supported profile
No telemetry. Validated with Express 4 (JavaScript and TypeScript 5) and NestJS 11 (TypeScript 5) on GitHub-hosted ubuntu-24.04 runners.
How we announce
An incorrect PASS is a security issue.
- 01
Affected teams are notified directly, not only through this page.
- 02
A fixed release ships, listed here with what it fixes.
- 03
The affected template version is withdrawn. A check that still names it reports UNKNOWN with
template-withdrawn. - 04
New sign-ups and promotion pause until the fix ships. Principles