You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
doc: correct SO.UserUpdateNotification — dfetch does check for new versions
dfetch check and dfetch environment both call newer_version_available()
in dfetch/util/github_version_check.py, which polls the GitHub releases
API and notifies the user if a newer release exists (suppressed in CI).
- Restore SO.UserUpdateNotification as ✓ Implemented with direct
reference to github_version_check.py; note CI suppression in Gaps
- Move C-040 (test result attestation) to ECR-A where it belongs:
attesting that CI tests passed before release is a vulnerability
management control, not an update notification mechanism
- Correct the note below the table: replace the wrong "N/A — passive
CLI tool" explanation with an accurate description of the check
https://claude.ai/code/session_01MoaUFm7mhFxEFuk14NKPh2
* - **ECR-B** — Be made available on the market with a secure by default configuration, including the possibility to reset the product to its original state.
@@ -205,9 +205,9 @@ The table below summarises dfetch's implementation of each prEN 40000-1-4 Securi
205
205
- — N/A
206
206
* -
207
207
- SO.UserUpdateNotification
208
-
- —
209
-
- dfetch is a passive CLI tool with no persistent process or network channel; proactive in-product update notification is not technically feasible without architectural change. Users discover updates via PyPI and GitHub Releases.
0 commit comments