Skip to content

Milestones

List view

  • No release clock. Feature work, non-blocking bugs, and follow-ups deferred out of the 4.9.0 security release. Re-triaged after 4.9.0 is tagged.

    No due date
    48/48 issues closed
  • Split out of the v1 core-gate proposal per #320. The policy/provenance work: auto-update provenance (#307), App-Password/automation-caller policy (#306), plus CLI/cron/generic programmatic callers. Deferred so v1 can ship a tight, provenance-blind browser/cookie-auth package-write gate. Not started until v1 lands.

    No due date
    2/2 issues closed
  • Draft core recent-auth-gate proposal maturation. "Cut 1" = the first scope of the PROPOSED core patch (no implementation exists) — not a WP Sudo release and not a fix iteration. See spec §0.

    No due date
    24/24 issues closed
  • Release-bound. The 4.9.0 security payload plus its tag-time gates. Nothing enters without a release justification; findings that are not regressions from in-flight PRs get filed and land in post-4.9.0.

    No due date
    21/21 issues closed
  • Curated near-term feature batch — multisite security/governance hardening plus completing the break-glass path. All backward-compatible additions. Briefly renumbered to v5.1.0 while the security release was taking 5.0.0; that bump was reverted to 4.9.0, so this batch keeps v5.0.0.

    No due date
    7/7 issues closed