Skip to content

feat: prepare Mesh 0.2.0 beta source - #33

Draft
dhawal-ss wants to merge 3 commits into
mainfrom
codex/mesh-0.2.0-beta-source
Draft

feat: prepare Mesh 0.2.0 beta source#33
dhawal-ss wants to merge 3 commits into
mainfrom
codex/mesh-0.2.0-beta-source

Conversation

@dhawal-ss

@dhawal-ss dhawal-ss commented Aug 4, 2026

Copy link
Copy Markdown
Owner

Scope

Integrates the completed Mesh 0.2.0 public-beta source hardening tranche. Current exact head: ec405614448eac9874f4be714efe83abd8fa0522.

Verified

  • All seven branch-protection contexts pass on the exact current SHA
  • Frontend unit/build plus Playwright/WCAG pass
  • Matrix Rust passes on Ubuntu and Windows; legacy LAN Rust passes
  • CodeQL, dependency/license, dependency/secret audit, feature isolation, and SBOM pass
  • Canonical npm Package URLs replace the CodeQL-flagged incomplete encoding
  • GitHub Actions use immutable Node 24-era stable pins with zero Node 20 annotations on completed jobs
  • Nginx 1.30.4-alpine and LiveKit 1.13.5 pass the unchanged fixable-high container policy
  • Two independent disposable federation reset/test cycles passed 2/2; disposable containers and network were removed

Fail-closed release blockers

The protected security evidence manifest remains red because current compatible upstream images for Caddy, Synapse, PostgreSQL, and lk-jwt-service still contain fixable high or critical vulnerabilities. No exception or severity reduction has been added. This PR must remain draft and must not advance main until compatible upstream rebuilds or separately approved patched derivatives clear the existing policy.

Release boundary

This PR does not tag, sign, deploy, publish, or promote a release. The readiness ledger, signed Windows candidate, 54-case R2 campaign, provider/operations/legal evidence, and manual accessibility evidence remain separate required gates. Voice and macOS/Linux remain unavailable pending R3/R4 evidence.

Comment thread mesh/scripts/generate-release-sboms.mjs Fixed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants