ranade-oss puts upstream sync on a safety catch
ROSS chose a clean pause over importing a batch of upstream changes it could not safely validate.
An automated update found that ten proposed changes from Mike did not fit ROSS cleanly. The batch touched authentication, multi-factor login, data structure changes, document storage, access controls, interface work, testing and deployment.
Nothing was partially imported. Instead, ranade-oss recorded each item for later review, including one data change already present in ROSS. That keeps the update queue moving while leaving potentially consequential changes for a bounded decision when the fork's own structure and governance can be considered.
For a legal AI product carrying its own operating rules, that restraint is a feature: upstream improvements still stay visible, without quietly changing security or workflow behaviour.
Spotted something wrong? Or know the PR text has fresher detail than the writeup above?