Milestones
List view
No release clock. Feature work, non-blocking bugs, and follow-ups deferred out of the 4.9.0 security release. Re-triaged after 4.9.0 is tagged.
No due date•48/48 issues closedSplit out of the v1 core-gate proposal per #320. The policy/provenance work: auto-update provenance (#307), App-Password/automation-caller policy (#306), plus CLI/cron/generic programmatic callers. Deferred so v1 can ship a tight, provenance-blind browser/cookie-auth package-write gate. Not started until v1 lands.
No due date•2/2 issues closedDraft core recent-auth-gate proposal maturation. "Cut 1" = the first scope of the PROPOSED core patch (no implementation exists) — not a WP Sudo release and not a fix iteration. See spec §0.
No due date•24/24 issues closedRelease-bound. The 4.9.0 security payload plus its tag-time gates. Nothing enters without a release justification; findings that are not regressions from in-flight PRs get filed and land in post-4.9.0.
No due date•21/21 issues closedCurated near-term feature batch — multisite security/governance hardening plus completing the break-glass path. All backward-compatible additions. Briefly renumbered to v5.1.0 while the security release was taking 5.0.0; that bump was reverted to 4.9.0, so this batch keeps v5.0.0.
No due date•7/7 issues closed