Skip to content

Change log: 3 August 2026 — inherited routing, security policy, and package metadata #22

Description

@kinlane

Provenance for a day's work, in the same spirit as #2 — recorded as it happens rather than reconstructed later.

Applied directly to the repository

#4 — repository security settings. Private vulnerability reporting, secret scanning, push protection and Dependabot security updates all went from disabled to enabled. Two related settings, secret_scanning_non_provider_patterns and secret_scanning_validity_checks, would not take and appear to need entitlements this repository lacks; noted on the issue rather than assumed handled. The last acceptance box — that a report through the private channel actually reaches someone — is deliberately left unticked until somebody sends a test report and watches it arrive.

#10 — branch protection on main. Force pushes disabled, deletions disabled, linear history required, conversation resolution required. Required status checks and required reviews were not applied, for reasons on the issue.

Open pull requests

PR Closes What
#17 #16 Retire inherited Stoplight CI and org references
#18 #12 Point package metadata at this project
#19 #5 SECURITY.md, GOVERNANCE.md, MAINTAINERS.yaml, NOTICE

Issues opened

Corrections to what was previously written down

Three things stated on existing issues turned out to be wrong, and are corrected in comments rather than edited away:

Decisions recorded

  • Maintainership. One maintainer, stated plainly in GOVERNANCE.md and MAINTAINERS.yaml rather than dressed up as a team. Rules escalate by stage as the roster grows.
  • Security acknowledgement window: 5 business days. Set by what one person can actually meet. A missed self-imposed SLA would be worse than a modest one, given the argument this project was founded on.
  • Contact address: info@apicommons.org across security, conduct and package metadata.
  • Package names untouched. Still @stoplight/spectral-*. That is Decide the npm package scope: @apicommons/spectral-* or @apicommons/spotlight-* #8 and it remains open — but the metadata half that did not depend on it has landed, so when the call is made the only change left is the name.

Still open, and honestly so

The build has still never been verified (#3), nothing has been published, and the CONTRIBUTING rewrite (#6) has a stopgap note rather than a rewrite. The order is: merge #17, open a pull request under packages/#20 is the candidate — and let CI answer #3 for the first time.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions