Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions REUSE.toml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@ path = [
".vscode/**/",
".gitignore",
".gitmodules",
"audit/**/",
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Avoid blanket exclusion of audit files without compliance rationale.

Excluding audit/**/ from REUSE annotations can omit SPDX metadata for audit artifacts, which are often compliance‑sensitive (especially if third‑party reports are redistributed). Please confirm the legal intent and consider narrowing the pattern or adding explicit licensing/annotation for audit outputs instead.

🤖 Prompt for AI Agents
In `@REUSE.toml` at line 10, The REUSE.toml currently excludes "audit/**/" which
blanket-omits SPDX annotations for audit artifacts; review the legal intent and
either remove or narrow this pattern so audit files are included in REUSE
processing, or alternatively add explicit license/metadata entries for audit
outputs. Update the REUSE.toml rule for the "audit/**/" pattern (or replace it
with a narrower path like "audit/reports/**" or explicit filenames) or add
corresponding SPDX/License entries for those audit artifacts so they are not
silently excluded.

"README.md",
"flake.lock",
"flake.nix",
Expand Down
Binary file added audit/protofire.rain.factory.feb-2026.pdf
Binary file not shown.