Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
105 commits
Select commit Hold shift + click to select a range
d3dc3ce
feat(github): add bounded keyless service integration candidate
pallakatos Sep 8, 2026
cd020a1
Checkpoint governed credential integration before privacy ancestry
pallakatos Sep 8, 2026
76db8e1
Merge qualified privacy ancestry into credential candidate
pallakatos Sep 8, 2026
b3f6ca8
Checkpoint private credential issuers before GitHub integration
pallakatos Sep 8, 2026
4e2e107
Merge qualified GitHub consumer into private credential candidate
pallakatos Sep 8, 2026
35411cf
Fence GitHub projection reuse by source revision
pallakatos Sep 8, 2026
b3d0446
Merge current qualified privacy closure into credential candidate
pallakatos Sep 8, 2026
93690ba
Gate Task readiness on live credential authority
pallakatos Sep 8, 2026
45939f6
Checkpoint governed credential continuity and core qualification
pallakatos Sep 9, 2026
330113a
Merge current SRE privacy closure and patched runtime dependencies
pallakatos Sep 9, 2026
fdf07f9
Record forward-qualified credential candidate handoff
pallakatos Sep 9, 2026
ec1ecf5
Implement target-bound controller observation privacy RPC
pallakatos Sep 9, 2026
24646e1
Checkpoint reviewed credential authority and lifecycle repairs
pallakatos Sep 9, 2026
71a42f6
Correct credential repair module and import wiring
pallakatos Sep 9, 2026
cdb8ba7
Correct nested credential suspension test path
pallakatos Sep 9, 2026
45ccc89
Make credential rebind test scoping explicit for Clippy
pallakatos Sep 9, 2026
ba491a9
Record guarded credential repair qualification
pallakatos Sep 9, 2026
94dbcb3
fix(credentials): route identity digests through approved providers
pallakatos Sep 9, 2026
80cffb6
fix(credentials): make production config paths immutable and close so…
pallakatos Sep 9, 2026
f8d641f
fix(credentials): align native UID admission and generated schemas
pallakatos Sep 9, 2026
ce6d263
fix(credentials): keep observer body reads independent of stream feat…
pallakatos Sep 9, 2026
4b24d9c
fix(credentials): preserve native admission semantics across CEL types
pallakatos Sep 9, 2026
9caf91e
test(credentials): exercise native store, rebind and exposure predicates
pallakatos Sep 9, 2026
9893783
fix(admission): handle primary requests without a subresource field
pallakatos Sep 9, 2026
f8ec6d0
test: isolate fresh SRE namespace rendering from unrelated chart work
pallakatos Sep 9, 2026
08d2794
fix(credentials): forward proven namespace collection cleanup guards
pallakatos Sep 10, 2026
7269a80
fix(sre): negotiate Kubernetes log streams with supported media
pallakatos Sep 9, 2026
2582ead
fix(sre): retain native SecretList compatibility in credential compos…
pallakatos Sep 10, 2026
9897986
fix(credentials): bound authority refresh and stabilize rebind acknow…
pallakatos Sep 10, 2026
2d5dba1
fix(credentials): evaluate observation policies against actual runtim…
pallakatos Sep 10, 2026
5ba25c4
fix(sre): preserve the native ReplicaSet controller handoff in compos…
pallakatos Sep 10, 2026
8da5115
fix(credentials): grant controller read access for observer ReplicaSe…
pallakatos Sep 10, 2026
a0992ad
fix(observations): identify private readiness failures without sensit…
pallakatos Sep 10, 2026
6211590
test(observations): use the workspace boxed Kubernetes API status
pallakatos Sep 10, 2026
cb38649
merge: qualify observer readiness diagnostics on the current services…
pallakatos Sep 10, 2026
17f53b6
fix(credentials): reject template workload authority in every live wr…
pallakatos Sep 10, 2026
05807e5
fix(credentials): stage and enforce generic private consumption autho…
pallakatos Sep 10, 2026
463a3e4
Merge public ac9f1b96 foundations into private activation candidate
pallakatos Sep 10, 2026
a3cb81c
refactor(credentials): split private activation phases within LOC limits
pallakatos Sep 10, 2026
69e715c
fix(credentials): retain test module declarations on activation facade
pallakatos Sep 10, 2026
cfcc410
fix(credentials): fence namespace subresources and retire old root au…
pallakatos Sep 10, 2026
9e6965e
Merge qualified public fe29941f evaluator compatibility
pallakatos Sep 10, 2026
5fabfca
fix(credentials): retire root authority before TLS rotation
pallakatos Sep 10, 2026
69654ca
fix(credentials): reject previously exposed rotation keys
pallakatos Sep 10, 2026
2af65a7
Remove duplicate TLS dependencies after foundation composition
pallakatos Sep 11, 2026
847dab5
Use declared credential activation module in regression tests
pallakatos Sep 11, 2026
cc6fc3c
fix(credentials): collapse budget TLS verification guard
pallakatos Sep 11, 2026
63ef643
test(bootstrap): attribute private policy errors without raw bodies
pallakatos Sep 11, 2026
c55cc39
Evaluate private namespace activation in the namespace-aware phase
pallakatos Sep 11, 2026
9f5485a
Compose credential activation with current receipt-log foundation
pallakatos Sep 11, 2026
51c2a77
Scope native connection admission transport to absent fixture Pods
pallakatos Sep 11, 2026
2a18945
Model actual Team-owned principal lineage in credential rebind fixtures
pallakatos Sep 11, 2026
ef7b2d8
Attest ownership-only source version transitions without granting wri…
pallakatos Sep 11, 2026
8989299
Keep connection proxy tests importable by native suite discovery
pallakatos Sep 11, 2026
affa124
Use merge-patch media type for native namespace fences
pallakatos Sep 11, 2026
13440b6
Match native projector fixture to shipped capability scope
pallakatos Sep 11, 2026
c73506b
Wait safely for nullable CRD establishment status
pallakatos Sep 11, 2026
6d6d4f8
Preserve strict activation across standard Pod admission defaults
pallakatos Sep 11, 2026
3233921
Preserve qualified shared authority across workspace enrollment
pallakatos Sep 11, 2026
0ce95b1
Revalidate only proven writer-guard retirement changes during grant u…
pallakatos Sep 11, 2026
e79d7c3
Prepare owned core schemas before admission installation
pallakatos Sep 11, 2026
470773c
Preserve schema data, rollback retention and explicit install contexts
pallakatos Sep 12, 2026
28cff35
Preserve secret-safe governed-service failure evidence before cleanup
pallakatos Sep 12, 2026
ac63714
Recover bundle anchors only while holding exclusive empty CREATE iden…
pallakatos Sep 12, 2026
4f45e24
Compose credential qualification with the actual evaluator integratio…
pallakatos Sep 12, 2026
5ee6137
Retire and requalify reviewed late observer runtime scopes
pallakatos Sep 12, 2026
99c792a
Fence Task-owned bundle recovery through verified runtime caller auth…
pallakatos Sep 12, 2026
9f99dd2
Document target-owned credential bundle recovery limits
pallakatos Sep 12, 2026
7dad541
Require explicit optional Task launch before bundle recovery
pallakatos Sep 12, 2026
b2fd939
Qualify exact historical SRE schema migration before mutation
pallakatos Sep 12, 2026
0fce464
Keep migration profile fixtures distinct on evaluator-v2 source trees
pallakatos Sep 12, 2026
bc2ef01
Use supported metadata-only kubectl projection for private credential…
pallakatos Sep 12, 2026
51ab8bb
Require coherent late-observer snapshots without rejecting RV-only re…
pallakatos Sep 12, 2026
016870f
Validate unchanged migration seeds against the early historical API gate
pallakatos Sep 12, 2026
233800d
Retain bounded migration seed reports in schema qualification artifacts
pallakatos Sep 12, 2026
6d76da4
Test historical scalar action data and strict nested migration bounda…
pallakatos Sep 12, 2026
3a8b02c
Preserve and converge Sandbox condition generation evidence
pallakatos Sep 12, 2026
4359a26
Assert condition transition timestamps at their exact Kubernetes wire…
pallakatos Sep 12, 2026
7470357
Keep wire timestamp fixture inside its transition test scope
pallakatos Sep 12, 2026
2af69c9
Settle witnessed Task credential transitions before late private enro…
pallakatos Sep 12, 2026
5c47cb9
Validate unpersisted CRD previews without inventing storage revisions
pallakatos Sep 12, 2026
affcd1b
Align Secret metadata printer views during witnessed writer settling
pallakatos Sep 12, 2026
d78cc6b
Probe the exact production Task schema SSA request before full migration
pallakatos Sep 12, 2026
74d2498
Trace private observer target requests without exposing upstream cont…
pallakatos Sep 12, 2026
4f525aa
Preserve verified Helm Apply ownership across controlled negative fix…
pallakatos Sep 12, 2026
6e98dac
Use a nonpersisting Pending proposal for the post-migration schema probe
pallakatos Sep 12, 2026
a708271
Report bounded private operator command and lifecycle failure facts
pallakatos Sep 12, 2026
edae589
fix(observer): normalize endpoint and expose bounded transport progress
pallakatos Sep 12, 2026
7d20aff
test(router): initialize TLS provider in isolated observer regressions
pallakatos Sep 12, 2026
a490926
fix(cli): recheck concurrent writer retirement snapshots
pallakatos Sep 12, 2026
f831ade
test(cli): harden wire qualification and expose restoration checks
pallakatos Sep 12, 2026
a82eec3
fix(cli): revalidate a conflicted reviewed sandbox pause
pallakatos Sep 14, 2026
27a1444
fix(cli): observe retirement independently of Task status timing
pallakatos Sep 14, 2026
ebb602a
fix(controller): allow enrolled observers to verify Kubernetes metadata
pallakatos Sep 14, 2026
6fad354
test(e2e): retain bounded port-forward failure details
pallakatos Sep 14, 2026
344a371
fix(controller): complete API namespace recheck and split regressions
pallakatos Sep 14, 2026
c19f9b5
fix(ci): verify bounded tool downloads before qualification
pallakatos Sep 14, 2026
3a09cd7
chore(repo): enforce format-safe Microsoft MIT attribution
pallakatos Sep 14, 2026
4ed8636
fix(deps): require patched Rustls for RUSTSEC-2026-0285
pallakatos Sep 14, 2026
03174dc
fix(ci): preserve raw YAML and Helm document boundaries in headers
pallakatos Sep 14, 2026
9ee285b
test: make Cilium API-group equality explicit
pallakatos Sep 14, 2026
fbc24af
docs: record governed GitHub privacy source closure
pallakatos Sep 14, 2026
793f4bc
fix(ci): require new-scope audit records in core qualification
pallakatos Sep 14, 2026
390c60b
docs: attest scoped credential and GitHub integration review
pallakatos Sep 14, 2026
8798a57
test(ci): retain bounded public CRD readiness errors
pallakatos Sep 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 3 additions & 0 deletions .agt-sdk/.gitignore
Original file line number Diff line number Diff line change
@@ -1,2 +1,5 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

*.tgz
*.tar.gz
3 changes: 3 additions & 0 deletions .cargo/audit.toml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

# cargo-audit configuration
# See: https://docs.rs/cargo-audit/latest/cargo_audit/#configuration

Expand Down
3 changes: 3 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

target/
cli/node_modules/
.git/
Expand Down
3 changes: 3 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

# kars Code Owners
# Each line is a file pattern followed by one or more owners.
#
Expand Down
3 changes: 3 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: Bug Report
description: Report a bug in Kars
body:
Expand Down
3 changes: 3 additions & 0 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

blank_issues_enabled: true
contact_links:
- name: Security Vulnerabilities (Critical/High)
Expand Down
3 changes: 3 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: Feature Request
description: Suggest a new feature for Kars
body:
Expand Down
3 changes: 3 additions & 0 deletions .github/ISSUE_TEMPLATE/security_report.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: Security Issue
description: Report a security vulnerability (for critical vulnerabilities, use MSRC per SECURITY.md)
body:
Expand Down
3 changes: 3 additions & 0 deletions .github/codeql-config.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: "Kars CodeQL Config"

# No vendored AgentMesh source is present after the Phase 5.2 AGT-only migration.
Expand Down
3 changes: 3 additions & 0 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
<!-- Copyright (c) Microsoft Corporation.
Licensed under the MIT License. -->

# Kars — Copilot Instructions

## What is Kars?
Expand Down
3 changes: 3 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

version: 2
updates:
# Rust / Cargo
Expand Down
3 changes: 3 additions & 0 deletions .github/pipelines/esrp-publish.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

# ---------------------------------------------------------
# Azure DevOps Pipeline: Unified ESRP Release Publishing — kars
#
Expand Down
3 changes: 3 additions & 0 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
<!-- Copyright (c) Microsoft Corporation.
Licensed under the MIT License. -->

## Summary
<!-- Brief description of changes -->

Expand Down
3 changes: 3 additions & 0 deletions .github/skills/agt-e2e-encryption/SKILL.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,9 @@
---
description: "Kars AGT E2E encryption skill — how the Signal Protocol inter-agent messaging works, how to debug it, and what was patched."
---
<!-- Copyright (c) Microsoft Corporation.
Licensed under the MIT License. -->


# AGT E2E Encrypted Inter-Agent Communication

Expand Down
3 changes: 3 additions & 0 deletions .github/skills/kars-deployment/SKILL.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,9 @@
---
description: "Kars deployment and infrastructure skill — how to deploy, build images, manage AKS, and troubleshoot."
---
<!-- Copyright (c) Microsoft Corporation.
Licensed under the MIT License. -->


# Kars Deployment & Infrastructure

Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/blocklist-refresh.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: Refresh Blocklist Seed

on:
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/check-agt-released.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: Check AGT Released

# Runs daily to detect when Microsoft AGT publishes a release that
Expand Down
12 changes: 11 additions & 1 deletion .github/workflows/ci-gates.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: ci-gates

on:
Expand Down Expand Up @@ -47,6 +50,10 @@ jobs:
- name: Make scripts executable
run: chmod +x ci/*.sh

- name: Verify fresh audit-record boundaries
if: matrix.gate == 'security-audit-required'
run: python3 -m unittest discover -s ci/tests -p security_audit_gate_test.py

- name: Run gate ${{ matrix.gate }}
shell: bash
env:
Expand All @@ -59,5 +66,8 @@ jobs:
no-null-provider-prod) ./ci/no-null-provider-prod.sh ;;
security-audit-required) ./ci/security-audit-required.sh ;;
a2a-module-isolation) ./ci/a2a-module-isolation.sh ;;
copyright-headers) ./ci/check-copyright-headers.sh ;;
copyright-headers)
python3 ci/tests/copyright_headers_test.py
./ci/check-copyright-headers.sh
;;
esac
39 changes: 34 additions & 5 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: CI

on:
Expand Down Expand Up @@ -415,10 +418,20 @@ jobs:
with:
version: v1.30.5
- uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22"
- name: Build same-source CLI for schema request parity
working-directory: cli
run: npm ci && npm run build
- name: Require the compiled production schema request helper
run: node tests/e2e/sre_authority/task_schema_payload.mjs check
- name: Check public-schema diagnostic privacy
run: PYTHONPATH=tests/e2e python3 -m unittest sre_authority.registration_schema_test sre_authority.bootstrap_probe_test sre_authority.binding_probe_test sre_authority.legacy_crds_test eval_pod_admission_test receipt_log_rotation_test
run: PYTHONPATH=tests/e2e python3 -m unittest sre_authority.registration_schema_test sre_authority.bootstrap_probe_test sre_authority.binding_probe_test sre_authority.legacy_crds_test sre_authority.connection_proxy_test credential_schema_test credential_policy_schema_test sandbox_condition_schema_test eval_pod_admission_test private_consumption_test receipt_log_rotation_test governed_services_test
- name: Create the same disposable API server as the real harness
run: kind create cluster --name kars-e2e --config tests/e2e/kind-config.yaml --kubeconfig "$KUBECONFIG"
- name: Prove native Sandbox condition generation pruning, retention and type validation
run: PYTHONPATH=tests/e2e python3 -m sandbox_condition_schema
- name: Prove native historical Helm wait orders CRDs before hooks and permits schema upgrades
run: PYTHONPATH=tests/e2e python3 -m sre_authority.legacy_crd_probe
- name: Reset disposable cluster after historical Helm proof
Expand All @@ -428,7 +441,14 @@ jobs:
- name: Validate the SRE CRD against the actual API server
id: sre_schema
run: python3 tests/e2e/sre_authority/registration_schema.py --exercise
- name: Prove shipped credential CEL with matching and mismatched native namespace UIDs
id: credential_schema
run: PYTHONPATH=tests/e2e python3 -m credential_schema
- name: Prove shipped credential store, rebind and exposure policies against native types
id: credential_policy_schema
run: PYTHONPATH=tests/e2e python3 -m credential_policy_schema
- name: Prove controller Pod admission with all chart policies and no image execution
if: ${{ !cancelled() && steps.sre_schema.outcome == 'success' }}
id: sre_bootstrap
run: PYTHONPATH=tests/e2e python3 -m sre_authority.bootstrap_probe --retirement-bind-proof
- name: Collect nil-schema adapter candidate evidence without weakening production gates
Expand All @@ -445,8 +465,12 @@ jobs:
path: |
e2e-sre-schema-diag/versions.json
e2e-sre-schema-diag/legacy-helm-readiness.json
e2e-sre-schema-diag/migration-seed-*.json
e2e-sre-schema-diag/validation.json
e2e-sre-schema-diag/validation-instances.json
e2e-sre-schema-diag/credential-namespace-uid.json
e2e-sre-schema-diag/credential-policy-typechecking.json
e2e-sre-schema-diag/sandbox-condition-generation.json
e2e-sre-schema-diag/namespace-accessor-candidate.json
e2e-sre-schema-diag/namespace-accessor-candidate-instances.json
e2e-sre-schema-diag/bootstrap-*.json
Expand All @@ -464,6 +488,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
- run: helm lint deploy/helm/kars
- run: python3 tools/private-consumption-bundle.py --check
- name: Preserve task admission defaults with reused legacy values
run: python3 ci/helm-task-floor-compat.py
- name: Render installation profiles
Expand Down Expand Up @@ -514,6 +539,8 @@ jobs:
version: v0.24.0
- name: Restore existing YAML and test dependencies
run: npm ci --prefix cli
- name: Verify public schema diagnostic and credential redaction boundaries
run: node --test tests/e2e/budget-api-kubectl.test.mjs
- name: Create disposable supported apiserver before any Rust image build
run: kind create cluster --name kars-budget-api --image kindest/node:v1.31.0 --config tests/e2e/kind-config.yaml
- name: Validate real CRD/CEL and Pod audience identity
Expand Down Expand Up @@ -687,12 +714,14 @@ jobs:
# save cost.
save-if: false

- name: Test bounded CI dependency acquisition
run: python3 -m unittest discover -s ci/tests -p acquisition_test.py

- name: Install kind
if: steps.paths.outputs.run == 'true'
uses: helm/kind-action@ef37e7f390d99f746eb8b610417061a60e82a6cc # v1.14.0
with:
install_only: true
version: v0.24.0
# Official v0.24.0 checksum; bounded HTTPS acquisition, no tool-cache
# fallback or implicit kubectl install. Cluster lifecycle is unchanged.
run: python3 ci/acquire_test_tools.py kind

- name: Install kubectl
if: steps.paths.outputs.run == 'true'
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: CodeQL

on:
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/dependency-review.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: Dependency Review

on:
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/image-cache-publish.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: Image Cache Publish

# Publishes runtime container images (controller, inference-router,
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/image-sign-sbom.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: Image Build, Sign & SBOM

on:
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/perf-nightly.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: Perf Nightly (k6)

# Phase 2 S16. Wall-clock perf smoke against the inference router.
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/release-internal.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: Internal Release (private, wall-off)

# Cuts a REAL release end-to-end with EVERY artefact stored behind the wall.
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/release-public-interim.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: Public Release (GHCR + GitHub Release)

# ─────────────────────────────────────────────────────────────────────────
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: Release

on:
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: OpenSSF Scorecard

# OpenSSF Scorecard runs weekly + on push to main, but ONLY when the
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/secret-scanning.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: Secret Scanning

on:
Expand Down
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

## Ignore Visual Studio temporary files, build results, and
## files generated by popular Visual Studio add-ons.
##
Expand Down
3 changes: 3 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
<!-- Copyright (c) Microsoft Corporation.
Licensed under the MIT License. -->

# Changelog

All notable changes to kars will be documented in this file.
Expand Down
3 changes: 3 additions & 0 deletions CODE_OF_CONDUCT.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
<!-- Copyright (c) Microsoft Corporation.
Licensed under the MIT License. -->

# Microsoft Open Source Code of Conduct

This project has adopted the [Microsoft Open Source Code of Conduct](https://opensource.microsoft.com/codeofconduct/).
Expand Down
Loading
Loading