Skip to content

Public launch: final repository settings verification #11

Description

@vladimirperovic

The repository is public and the code-side/publication-side launch checks have materially advanced. This issue now tracks only the remaining owner/UI verification items instead of the obsolete pre-publication state.

Verified on 2026-08-09

  • vladimirperovic/minimalrouter is Public.
  • main is the default branch.
  • Squash merge is enabled; merge commits and rebase merge are disabled.
  • Required branch checks are enforced: a release-hardening PR merge was rejected until its branch was updated onto the current main and the required checks reran.
  • Repository CI defaults to read-only contents: read; CodeQL uses only the additional security-events: write permission it needs.
  • CodeQL runs for Go and JavaScript/TypeScript and is green on the current release-hardening candidate.
  • Secret scanning workflow is green on the current release-hardening candidate.
  • Dependabot configuration exists for Go modules, npm, and GitHub Actions on a weekly schedule.
  • GitHub Actions used by the reviewed CI/CodeQL workflows are pinned by commit SHA.

Owner/UI settings still to verify

  • Set/confirm description: Minimal Alpine Linux router appliance with a Go control plane and React dashboard.
  • Set/confirm topics: router, firewall, alpine-linux, golang, react, nftables, wireguard, pppoe, homelab, networking.
  • Add/confirm a synthetic social-preview image with no real network data.
  • Keep the website field empty until an official project site exists.
  • Confirm branch/push rules explicitly block force pushes and branch deletion, in addition to the required checks already observed.
  • Confirm dependency graph, Dependabot alerts, and Dependabot security updates are enabled in repository settings.
  • Confirm GitHub secret-scanning push protection is enabled in repository settings (separate from the repository's own secret-scan workflow).
  • Confirm private vulnerability reporting is enabled and the reporting path works.
  • Confirm the Security tab contains no unresolved high/critical findings.
  • Confirm the original development repository, if retained separately, remains private and does not expose private branches/tags/artifacts.
  • Verify the public repository from a signed-out browser: README logo, screenshot, badges, Mermaid diagram, internal documentation links, and issue templates.

Detailed procedure: docs/RELEASE_PROCESS.md.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions