Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions docs/compliance-audit-2026-04-10.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,14 @@ see its "`Discrepancy 1`" section)
* `+docs/branch-protection-remediation-2026-04-10.adoc+` — estate-wide
ruleset remediation that followed the scaffolder work

*Erratum (2026-09-30), added without altering the frozen rows below:*
the aerie row calls `+/tmp/aerie.pid+` "`standard-compliant`". That was
true of the 2026-04-10 standard only. Under the current
`+standards/launcher-standard_praxis.deed+`, a PID file in `+/tmp+` (or
`+$TMPDIR+`) is *non-compliant* — a predictable name in a world-writable
directory lets another user choose which PID `+stop+` kills (CWE-377).
Do not cite this row as precedent.

Of the 11 launchers audited here, 6 have since been migrated to
scaffolder management (aerie, burble, game-server-admin, nqc, panll,
project-wharf — plus stapeln, which the audit did not cover because
Expand Down
Loading