PASS — satisfies the done-criterion of sneak/webhooker#115; single commit 855439c on next, clean fast-forward, no attribution trailers, no scope creep.
Gate, in an…
Added to the 1.0.0 milestone.
Reason: sneak/webhooker#135's definition of done did permit filing this rather than fixing it inline, and https://git.eeqj.de/sneak/webho…
Plan:
Dockerfile.lintat repo root, two stages off the pinned digestgolangci/golangci-lint:v2.12.2@sha256:5cceeef0...: adepsstage (go.mod/go.sum+go mod download, cacheable)…
Moved INTO the 1.0.0 milestone, reversing the "does NOT block the tag" line in the body. sneak/webhooker#149 made the exposure visible; it did not remove it. Shipping…
Moved INTO the 1.0.0 milestone, reversing the "not milestoned" line in the body above.
Reason: the test for 1.0 is not only what an attacker can reach but whether the shipped artifact is…
Moved INTO the 1.0.0 milestone and taken off sneak as a decision — I am ruling option 1 and dispatching it.
Reason it is a blocker: the receiver rate limit is a security control the README…