add CodeQL note to governance docs

This commit is contained in:
2026-06-11 16:55:31 +02:00
parent 00dccdcd7b
commit 405b4c3f0a
+3
View File
@@ -81,6 +81,9 @@ not published. The maintainer tests the draft binaries before publishing.
> tagged release. The `.intoto.jsonl` file is included with the
> binaries. No configuration needed.
> CodeQL static analysis is enabled on every push and pull request.
> Alerts are reviewed before release. Currently zero open alerts.
Before signing a release tag, the maintainer verifies:
- [ ] Impact analysis completed — all call sites for new/changed functions identified and updated