Public documentation v0.1.0

Security and safety notes

Software Factory public profiles are not credential bundles or private runtime snapshots.

Credential handling

Do not commit .env files, tokens, private keys, OAuth credentials, API keys, or local credential stores. Configure credentials separately for the local profile that needs them, use least-privilege credentials, and keep credential handoff details out of public docs and release notes.

Role authority

PM and orchestrator profiles plan and route work. Builder profiles perform implementation and explicitly approved infrastructure changes. Reviewer profiles verify independently. Publisher profiles publish only after approval and with scoped credentials. Docs profiles maintain public docs and release notes; production mutation requires explicit task scope.

Public-safety validation

Before public release, run repository validation and public-safety scans for forbidden private paths, secrets, local state, and unsafe URLs. Independent reviewer verification should confirm public repository heads, tags, releases, licenses, and install instructions.

v0.1.0 security posture

The v0.1.0 publication was reviewed as public-safe for the approved repositories. Remaining v0 limitations are operational rather than hidden security claims: branch protection and repository metadata settings are deferred, and generated repositories remain artifacts of the source monorepo.

Reporting issues

Report public issues in the source repository. Do not include secrets, private local paths, or private operational logs in public issue reports.