The GitHub Actions job "link-check" on 
airflow-steward.git/docs-security-post-2026-sync-flow has failed.
Run started by GitHub user potiuk (triggered by potiuk).

Head commit for run:
879446367f9b9af3db9e665384d9e1dd384e604a / Jarek Potiuk <[email protected]>
docs(security): align process/roles/README with post-2026 sync-driven RM 
close-out

Recent sync-skill changes (#202, #222, #225, #255) shifted Vulnogram
REVIEW -> PUBLIC, JSON re-push, board move, and tracker close from RM
hand-clicks to sync automation. The reference docs still described the
pre-2026 flow; this brings them back in sync.

- process.md Step 12: document the two-stage hand-off gate (six
  mandatory body fields populated + CVE record state REVIEW) and the
  Remediation-developer fill-fields comment that fires when either
  gate fails. RM hand-off comment now only fires when both gates clear.
- process.md Step 13: rewrite RM checklist as three single-click
  Vulnogram actions (REVIEW -> READY, send advisory, stop). Drop the
  stale "REVIEW (then READY)" phrasing -- REVIEW is set by sync.
- process.md Step 14: rename to "Capture the public advisory URL and
  close out" and list the eleven actions of sync's combined apply
  (URL capture, short-summary extraction, label flips, JSON re-push,
  READY -> PUBLIC via OAuth API, board move, tracker close, board
  archive, conditional milestone close, wrap-up comment).
- process.md Step 15: collapse to "RM verifies the close-out landed"
  -- the RM has no remaining manual work; just receives a
  purely-informational timeline marker.
- process.md Mermaid diagram + label-lifecycle table + label
  reference table updated to match.
- roles.md "Handoff from the remediation developer": mention the
  fill-fields comment they may receive when six mandatory fields
  are incomplete.
- roles.md "Sending the advisory": replace with the three-step
  Vulnogram clickflow matching process.md Step 13.
- roles.md "Capturing the public archive URL and closing out":
  list the sync-driven combined apply.
- roles.md "Publishing the CVE and closing the issue": now
  "Nothing to do".
- roles.md RM "Tools you use most": drop stale Vulnogram-paste
  language.
- README.md: "Eight skills" -> "Nine skills ... plus one read-only
  supporting skill". Split skills table into "Lifecycle skills" (9)
  and "Supporting tools" (1), adding security-tracker-stats-dashboard.

Generated-by: Claude Code (Opus 4.7)

Report URL: https://github.com/apache/airflow-steward/actions/runs/26396171005

With regards,
GitHub Actions via GitBox

Reply via email to