diff --git a/DEFENSE_IN_DEPTH.md b/DEFENSE_IN_DEPTH.md index 928a6cd..34878c9 100644 --- a/DEFENSE_IN_DEPTH.md +++ b/DEFENSE_IN_DEPTH.md @@ -44,7 +44,7 @@ Profile: npm library · public ## 6. Security tooling - [x] Aikido runs on every build — verified 2026-09-09 (PR #65: Aikido Security: check code) -- [ ] Aikido release gate: the release workflow's stage-publish job `needs:` a passing `scan-release` (PR #75 pending) +- [x] Aikido release gate: the release workflow's stage-publish job `needs:` a passing `scan-release` — PR #75 - [ ] Socket reviews every PR that changes dependencies ## 7. Repository lockdown diff --git a/SECURITY.md b/SECURITY.md index 20598f4..1d4d1b8 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -33,4 +33,4 @@ hardening checklist; progress is tracked in [DEFENSE_IN_DEPTH.md](./DEFENSE_IN_D - `.github/CODEOWNERS` names `@jaredwray` for `/.github/`, `/.vscode/`, `/.cursor/`, `/.devcontainer/`, and `/scripts/`. - Codespaces and Cursor Cloud Agents install through Aikido Safe Chain; package-manager shims must not be bypassed. - The Codespaces Dev Container image is pinned by digest (`name:@sha256:`), not a floating tag. -- Aikido scans every build. +- Aikido scans every build. Stage-publish is gated on a passing Aikido `scan-release` job.