Board: yes
Security and quality alerts are worked before any phase, one issue per class of alert (the rule of 2026-09-05 on steinbruch, fleet-wide since 2026-09-06). This is the class PinnedDependenciesID from code-scanning, 2 open alerts, the highest severity medium.
What the class says
Determines if the project has declared and pinned the dependencies of its build process.
The alerts
Done when
- This class stands at zero open alerts on the Security tab: every alert repaired by a change that lands here, or dismissed with a reason written on this issue that names the predicate, pasted from the API rather than clicked.
- The planning issue for this class on the operations tracker, which asks how the class is kept from arriving again, is named here; nothing here waits on it.
Board: yes
Security and quality alerts are worked before any phase, one issue per class of alert (the rule of 2026-09-05 on steinbruch, fleet-wide since 2026-09-06). This is the class
PinnedDependenciesIDfrom code-scanning, 2 open alerts, the highest severity medium.What the class says
Determines if the project has declared and pinned the dependencies of its build process.
The alerts
.github/workflows/release.yml:76: https://github.com/Flowfin/site/security/code-scanning/36.github/workflows/package-caller.yml:32: https://github.com/Flowfin/site/security/code-scanning/35Done when