Skip to content

fix(security): make credential rotation gate incident-driven - #22

Merged
AllenXiao95 merged 1 commit into
masterfrom
fix/docs-site-ci
Aug 24, 2026
Merged

AllenXiao95 merged 1 commit into
masterfrom
fix/docs-site-ci

Conversation

@AllenXiao95

@AllenXiao95 AllenXiao95 commented Aug 24, 2026 •

Copy link
Copy Markdown
Owner

Stop treating an absent rotation record as evidence of leaked credentials. Add credential_rotation_required with a safe, explicit default of false, while preserving fail-closed behavior whenever an incident or mandatory rotation is declared.

Expose the effective remote-publish policy in the dashboard before execution and retain each target's actionable error message after a failed publish instead of collapsing it to target:failed.

Update Chinese and English configuration guidance, the example project, and the local WoT policy semantics. Add regression coverage for normal, blocked, completed, provider-validation, API, and dashboard states.

Verification: WoT configs validated; mkdocs build --strict; 697 unittest cases passed.

Summary

Describe the problem and the change in a few sentences.

Scope

  • Area(s) affected:
  • User-visible behavior changed: yes / no
  • Compatibility or migration impact:

Validation

List the tests, commands, or manual checks you ran.

python -X utf8 -m unittest discover -s tests

For documentation changes, also consider:

mkdocs build --strict

Safety and release checks

  • No secrets, credentials, private localization data, or non-redistributable game assets are included.
  • New behavior has regression coverage where practical.
  • Configuration or user-facing workflow changes include documentation updates.
  • Changes touching TM writes, QualityGate, release, publishing, filesystem scope, or agent tools preserve deterministic validation and explicit authorization boundaries.
  • The pull request is focused and does not mix unrelated refactors.

Stop treating an absent rotation record as evidence of leaked credentials. Add credential_rotation_required with a safe, explicit default of false, while preserving fail-closed behavior whenever an incident or mandatory rotation is declared.

Expose the effective remote-publish policy in the dashboard before execution and retain each target's actionable error message after a failed publish instead of collapsing it to target:failed.

Update Chinese and English configuration guidance, the example project, and the local WoT policy semantics. Add regression coverage for normal, blocked, completed, provider-validation, API, and dashboard states.

Verification: WoT configs validated; mkdocs build --strict; 697 unittest cases passed.
@AllenXiao95
AllenXiao95 merged commit fb2b03c into master Aug 24, 2026
12 checks passed
@AllenXiao95
AllenXiao95 deleted the fix/docs-site-ci branch August 24, 2026 13:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant