Skip to content

Milestones

List view

  • Governance and auditability major release: owned expiring exceptions, risk-decision history and exports, and portfolio policy rollout simulation. Gated on the v3.0.0 trust release.

    No due date
  • Precision and trust major release: versioned framework evidence packs, external runtime and coverage imports, and generated-code provenance. Gated on the v2.0.0 adoption release.

    No due date
  • Patch tranche for Rust and Swift workspace and import parsing plus cross-language import-resolution correctness.

    No due date
    0/14 issues closed
  • Patch tranche for JavaScript workspace, import, re-export, license, builtin, and usage analysis.

    No due date
    0/12 issues closed
  • Patch tranche for TUI, CLI, VS Code, codemod, SARIF, and Markdown output correctness.

    No due date
    0/14 issues closed
  • Patch tranche for Go, JVM, and Python adapter targeting, vendored provenance, Gradle and Maven bounds, and legacy parsing.

    No due date
    4/57 issues closed
  • Patch tranche for feature lifecycle, policy gates, suppression integrity, dependency automation, and local-hook governance.

    No due date
    29/29 issues closed
  • Patch tranche for .NET, Dart, and PowerShell parser and drift resilience, plus dashboard and CycloneDX reliability.

    No due date
    40/40 issues closed
  • Patch tranche for bounded language inputs and codemod safety across Go, Python, PHP, C++, and Ruby.

    No due date
    30/30 issues closed
  • Patch tranche for workspace confinement and root detection across MCP, profiles, JVM/Kotlin, Elixir, Python, and scoped copies.

    No due date
    48/48 issues closed
  • Patch tranche for analysis state and runtime trust: cache integrity, trace bounds, symlink-safe reads, and runtime metadata privacy.

    No due date
    46/46 issues closed
  • Patch tranche for CI, PR, release, and queue trust boundaries: token isolation, pinned controls, source validation, and safe reporting.

    No due date
    32/32 issues closed
  • Interoperable dependency identity, advisory and VEX workflows, portfolio SBOM output, and CI/dashboard expansion.

    Due by September 25, 2026
    10/32 issues closed
  • Major-release differentiators: explainable transitive evidence, version-aware reachability, safe change planning, signed evidence, portfolio automation, and an adapter ecosystem.

    Due by November 20, 2026
    16/46 issues closed
  • Overflow queue for issues that miss release freeze or exceed milestone capacity.

    No due date
    95/95 issues closed