Active Evaluation FINOS Labs This material is provisional and has not been published as a formal FINOS standard.
REL-006

Patch Request Authorization

Patch releases should trace to an approved backlog item, request, sponsor record, or equivalent authorization record.

Status
Pre-Draft
Version
0.0.1
Pack
OSERA-SP-0.2.0 observe
Ratified
Not ratified
Fitness
Observe-only check
Category
Release Process
Applies to
OSERA maintainers, Patch providers, Repository operators
Machine-readable
YAML / JSON

Structured Requirements

REL-006.REQ-001 SHOULD manual

Patch releases should identify the backlog item, public request, sponsor record, or equivalent authorization record for the patched coordinate and line.

Check Severity Evidence
REL-006.CHECK-001
Patch request authorization evidence is present
observe backlog_item, sponsor_record, coordinate_line

Requirement

Patch releases SHOULD identify the backlog item, public request, sponsor record, or equivalent authorization record for the patched coordinate and line.

Rationale

The publication gate may need to know that a producer was authorized to release a patch for a specific coordinate and maintenance line.

This is deferred to observe mode because the working group has not yet decided whether the backlog is always public, whether privately sponsored requests are allowed, or what evidence should be visible to recipients.

Observe-mode evidence

Observe-mode evidence SHOULD identify:

  • patched coordinate;
  • upstream version line;
  • public backlog item, if available;
  • sponsor or request record, if the backlog item is not public;
  • approval or exception record.