Dependency scans and release checks are not required gates, signing and publishing are not separated from untrusted build execution, publishing does not demonstrably consume a verified immutable artifact, and no release checklist revalidates applicable requirements.
Dependency scans and release checks are not required gates, signing and publishing are not separated from untrusted build execution, publishing does not demonstrably consume a verified immutable artifact, and no release checklist revalidates applicable requirements.