Skip to content

Commit 65b3380

Browse files
committed
doc: correct SO.UserUpdateNotification — dfetch does check for new versions
dfetch check and dfetch environment both call newer_version_available() in dfetch/util/github_version_check.py, which polls the GitHub releases API and notifies the user if a newer release exists (suppressed in CI). - Restore SO.UserUpdateNotification as ✓ Implemented with direct reference to github_version_check.py; note CI suppression in Gaps - Move C-040 (test result attestation) to ECR-A where it belongs: attesting that CI tests passed before release is a vulnerability management control, not an update notification mechanism - Correct the note below the table: replace the wrong "N/A — passive CLI tool" explanation with an accurate description of the check https://claude.ai/code/session_01MoaUFm7mhFxEFuk14NKPh2
1 parent fefeb31 commit 65b3380

1 file changed

Lines changed: 10 additions & 11 deletions

File tree

‎doc/explanation/compliance_track.rst‎

Lines changed: 10 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -175,7 +175,7 @@ The table below summarises dfetch's implementation of each prEN 40000-1-4 Securi
175175
- Status
176176
* - **ECR-A** — Be made available on the market without known exploitable vulnerabilities.
177177
- SO.VulnerabilityManagementProcess
178-
- :ref:`C-015 <c-015>`, :ref:`C-016 <c-016>`, :ref:`C-017 <c-017>`, :ref:`C-022 <c-022>`, :ref:`C-043 <c-043>`
178+
- :ref:`C-015 <c-015>`, :ref:`C-016 <c-016>`, :ref:`C-017 <c-017>`, :ref:`C-022 <c-022>`, :ref:`C-040 <c-040>`, :ref:`C-043 <c-043>`
179179
- —
180180
- ✓ Implemented
181181
* - **ECR-B** — Be made available on the market with a secure by default configuration, including the possibility to reset the product to its original state.
@@ -205,9 +205,9 @@ The table below summarises dfetch's implementation of each prEN 40000-1-4 Securi
205205
- — N/A
206206
* -
207207
- SO.UserUpdateNotification
208-
- —
209-
- dfetch is a passive CLI tool with no persistent process or network channel; proactive in-product update notification is not technically feasible without architectural change. Users discover updates via PyPI and GitHub Releases.
210-
- — N/A
208+
- `dfetch/util/github_version_check.py <https://github.com/dfetch-org/dfetch/blob/main/dfetch/util/github_version_check.py>`_
209+
- Check is suppressed when the ``CI`` environment variable is set (intentional: avoids spurious output in automated pipelines)
210+
- ✓ Implemented
211211
* -
212212
- SO.PostponeUpdates
213213
- —
@@ -359,13 +359,12 @@ blocks release if known vulnerabilities are present in runtime dependencies. Pr
359359
the update *mechanism* is the manufacturer's obligation under SUM-1/SUM-2; delivery
360360
to the end user is the responsibility of the user's package manager.
361361

362-
**ECR-C SO.UserUpdateNotification** — N/A. dfetch is a passive CLI tool that runs
363-
to completion and exits; it has no persistent process, no background service, and
364-
no maintained network channel between invocations. Proactive in-product update
365-
notification (LNM-1) is not technically feasible without a fundamental architectural
366-
change. Users discover new releases via PyPI (``pip index versions dfetch``),
367-
GitHub Release subscriptions, or Dependabot/Renovate rules on their own
368-
``requirements.txt``.
362+
**ECR-C SO.UserUpdateNotification** — ``dfetch check`` and ``dfetch environment``
363+
both call ``newer_version_available()`` (``dfetch/util/github_version_check.py``),
364+
which polls the GitHub releases API and prints a notice if a newer dfetch release
365+
exists. The check is skipped when the ``CI`` environment variable is set to avoid
366+
noise in automated pipelines; developers running dfetch interactively always receive
367+
the notification.
369368

370369
**ECR-M SO.SecureDataDeletion** — No dfetch-specific control is needed. DLM-1 is
371370
satisfied by design: dfetch stores no personal data, credentials, or cryptographic

0 commit comments

Comments
 (0)