Skip to content

docs: cleanup docs guidance, additional workflow hardening#60

Open
lelia wants to merge 4 commits intomainfrom
lelia/cleanup-docs-refs
Open

docs: cleanup docs guidance, additional workflow hardening#60
lelia wants to merge 4 commits intomainfrom
lelia/cleanup-docs-refs

Conversation

@lelia
Copy link
Copy Markdown
Contributor

@lelia lelia commented Mar 31, 2026

Summary

This PR cleans up customer-facing guidance after the recent release and dependency-process changes, simplifies version management, and hardens review automation for toolchain updates. It also clarifies that Trivy-backed container scanning is temporarily disabled in the prebuilt GitHub Action and Docker image distributions while that dependency path remains under additional review.

Changes

  • Refreshes docs to consistently reflect the current published versions and supported usage paths
  • Tightens pinning guidance across GitHub Action, Docker, native install, and parameter examples
  • Clarifies that Trivy-backed container scanning is temporarily disabled in the prebuilt GitHub Action and Docker distributions while security review is underway
  • Makes pyproject.toml the canonical release version source for the new release process, and reintroduces a sync script for derived version files
  • Hardens Dependabot handling with allowlists, modest PR queue caps, grouped minor/patch GitHub Actions updates, and a safer PR-based review workflow

Testing

  • python3 scripts/sync_release_version.py --check
  • YAML parse validation for Dependabot and workflow files

lelia added 4 commits March 31, 2026 16:31
…ng status

Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
@lelia lelia requested a review from a team as a code owner March 31, 2026 20:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants