Skip to content

Add a roller-security developer skill for report triage and coordination - #187

Merged
snoopdave merged 1 commit into
add-roller-release-skillfrom
add-roller-security-skill
Sep 11, 2026
Merged

snoopdave merged 1 commit into
add-roller-release-skillfrom
add-roller-security-skill

Conversation

@snoopdave

Copy link
Copy Markdown
Contributor

Adds an optional Roller security-response skill with generic guidance, blank private-case templates, and helpers for tracking, migration, and disclosure linting. Obsidian integration is optional; the PMC retains case, release, and disclosure decisions. Project-specific coordination and reporter-review guidance are included for PMC review.

The disclosure linter requires explicit commit-range endpoints, rejects malformed or unknown revisions, and reports Git failures instead of treating them as a clean scan.

Stacked on #186: this PR adds only roller-security and its README table entry. Merge #186 first, then retarget this PR to master.

Validation: shell/Python syntax, local Markdown links, ASF headers, and publication-content scans passed. Twelve isolated behavioral cases passed for range handling, including exclusion of historical flagged commits. Earlier preparation covered tracking/migration helpers; the latest bundled metadata-validator attempt was blocked by missing PyYAML. No application build was run because the skill is outside the build and distribution allowlist.

@snoopdave
snoopdave merged commit 2d90afd into add-roller-release-skill Sep 11, 2026
snoopdave added a commit that referenced this pull request Sep 11, 2026
#186)

* Add a roller-release developer skill documenting the release procedure

Adds an optional skills/ directory holding written-down project procedures
for Roller developers, starting with the release workflow: preparing and
versioning a candidate, building, signing, verifying, staging, voting,
promoting the approved bytes, updating the website and announcing.

The skill is plain Markdown plus two helper scripts. It is not part of the
build, the runtime, or the source and binary distributions; the source
assembly's include list does not cover this directory. Developers who use an
agent tool can symlink it under .claude/skills/, and everyone else can read
it as documentation. See skills/README.md.

The helpers preview by default and never commit, tag, push, sign or send
mail. The skill records procedure only; the PMC owns release decisions and
ASF policy governs what a release requires.

Claude-Session: https://claude.ai/code/session_015X69HHQ5XnjRkJP8ymzwFf

* Add a roller-security developer skill for report triage and coordination (#187)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant