CI / Rust checks (push) Waiting to run
CI / Docs and registry checks (push) Waiting to run
CI / Smoke checks (push) Waiting to run
Coverage / Coverage baseline (push) Waiting to run
Security / Cargo audit (push) Waiting to run
Security / Cargo deny (push) Waiting to run
Security / Secret pattern check (push) Waiting to run
Security / Dependency review (push) Waiting to run
85 lines
3.0 KiB
Markdown
85 lines
3.0 KiB
Markdown
# AWatch-rus: PR review evidence
|
|
|
|
Дата: 2026-06-24
|
|
|
|
pr_review_status: "pending_review_required"
|
|
|
|
GitHub issue: https://github.com/igor04091968/AWatch-rus/issues/48
|
|
|
|
Этот документ фиксирует evidence первого protected PR-based workflow после
|
|
включения GitHub ruleset на `main`. Он не утверждает, что review requirement
|
|
уже выполнен или что external peer review завершен.
|
|
|
|
## Evidence Criteria
|
|
|
|
Первый evidence-backed reviewed PR должен содержать:
|
|
|
|
- PR URL;
|
|
- linked issue URL;
|
|
- completed pull request template;
|
|
- passed checks;
|
|
- reviewer approval;
|
|
- merge commit;
|
|
- no bypass, or documented bypass with reason and follow-up checks.
|
|
|
|
## Evidence Record
|
|
|
|
- PR URL: `https://github.com/igor04091968/AWatch-rus/pull/50`
|
|
- Linked issue URL: `https://github.com/igor04091968/AWatch-rus/issues/48`
|
|
- Evidence issue URL: `https://github.com/igor04091968/AWatch-rus/issues/49`
|
|
- Required checks status: `passed`
|
|
- Required checks: `Coverage baseline`, `security`, `rust-checks`,
|
|
`docs-registry-checks`, `smoke-checks`
|
|
- Review requirement status: `pending_review_required`
|
|
- Merge status: `open`
|
|
- Admin bypass used: `false`
|
|
- Reviewer: `pending`
|
|
- Reviewer type: `pending`
|
|
- Approval URL or screenshot filename: `pending`
|
|
- Merge commit: `pending`
|
|
- Date: `2026-06-24`
|
|
- Maintainer note: PR #50 demonstrates protected branch workflow and required
|
|
checks execution, but first reviewed PR evidence remains pending until review
|
|
requirement is satisfied and the PR is merged without bypass.
|
|
|
|
## Reviewer Interpretation
|
|
|
|
Review by the same maintainer improves change discipline but does not prove
|
|
external peer review. External peer review must not be marked completed unless a
|
|
reviewed public PR includes a reviewer who is not the submitting maintainer and
|
|
the review is visible.
|
|
|
|
## Current Status
|
|
|
|
- PR workflow documentation: ready.
|
|
- PR template: ready.
|
|
- CODEOWNERS routing: ready.
|
|
- First protected PR validation reference: PR #50.
|
|
- Required checks for PR #50: passed.
|
|
- First reviewed PR evidence: pending.
|
|
- External peer review completed: not claimed.
|
|
|
|
## Not Registry Release Evidence
|
|
|
|
PR review evidence is governance/process evidence for public development
|
|
visibility. It is not registry release evidence and does not replace artifacts,
|
|
checksums, logs or release evidence from the Russian build-runner.
|
|
|
|
## Russian Contour Note
|
|
|
|
Primary registry-readiness contour remains Russian Gitea plus the planned
|
|
Russian build-runner. GitHub remains public mirror validation only.
|
|
|
|
## Guardrails
|
|
|
|
- Do not publish secrets, private URLs, private account data or customer
|
|
identifiers.
|
|
- Do not claim completed external peer review until the evidence record is
|
|
filled from a real reviewed PR.
|
|
- Do not claim branch protection verification from PR evidence alone.
|
|
- Do not claim completed registry submission.
|
|
- Do not claim certification.
|
|
- Do not claim SIEM/DLP replacement.
|
|
- Do not claim ML/LLM-based detection.
|
|
- Do not claim automatic remediation.
|