b0158c96e9
Toolchain: - go.mod: go 1.25.0 -> 1.25.12 (closes 24 stdlib vulns: archive/tar, crypto/tls, crypto/x509, net/http, net/url, encoding/pem, os) - go mod tidy clean; make build + test + lint pass Pre-existing test bugs fixed (surfaced by toolchain bump): - acl_test.go: KindToken always denies (R-021); tests updated to KindOidc - acl.go: parseIdentity defaults to KindOidc (was KindToken, making acl grant/check CLI path non-functional for non-spiffe identities) - init_test.go: migration version updated to 0008 (was 0007, stale since v0.12) - doctor.go: CertCA now checks CA cert exists (was only checking file modes, passing when no CA present) - scenarios_test.go: ACL integration test uses KindOidc + acl.json 0600 ---ci--- project: orca phase: 1 milestone: v0.13 status: complete requirements: covered: [149] ---/ci---
22 lines
586 B
JSON
22 lines
586 B
JSON
{
|
|
"phase": 1,
|
|
"stage": "complete",
|
|
"milestone": "v0.13",
|
|
"milestone_slug": "production-hardening-2",
|
|
"phase_role": "execution",
|
|
"attempts": 0,
|
|
"updated_at": "2026-08-07T19:05:00Z",
|
|
"milestone_complete": false,
|
|
"previous_milestone": "v0.12",
|
|
"phase_count": 14,
|
|
"phases_shipped": ["P0", "P1"],
|
|
"tags_shipped": ["v0.12.0", "v0.12.1"],
|
|
"requirements": {
|
|
"covered": [149],
|
|
"partial": []
|
|
},
|
|
"binding_conditions": ["C-39","C-40","C-41","C-42","C-43","C-44","C-45","C-46","C-47","C-48","C-49"],
|
|
"load_bearing_rule": "R-022",
|
|
"next_milestone": "v1.0"
|
|
}
|