Security and privacy
Software supply chain
Building and signing releases and checking dependencies. A process plan in the repo, not a result.
Designed in a document, no code yet
What to plan for
- Dependency vulnerabilities
- Reproducible builds
- Signing keys
What the catalog lists
Planned items that match this topic (keyword match; read each as a pointer):
- Dependency vulnerability scanning SEC-0040
- Release channels (stable/beta) LIC-0015
Honesty note
Everything listed is a plan or a design principle. No app is released and nothing is audited or certified.