ranade-oss keeps ROSS's guardrails ahead of upstream
A merged sync review deliberately brought in no product changes, preserving ROSS's own security and operating controls.
Eight upstream changes were assessed, then held back or declined. That is the point of this update: ROSS is not accepting changes merely because they arrived from the parent project.
- Security and external-access changes need separate scrutiny.
- Data-integrity, database, public-interface, and workflow changes remain protected.
- Testing, deployment, and dependency changes also require review.
- Two proposals were declined because ROSS already has stricter access controls and its own security and governance approach.
The only update was the record of what has been reviewed, while existing checks on review status and safe merging remain in place.
So what Legal teams assessing ROSS should care because its maintainers are treating inherited security and workflow changes as decisions, not automatic upgrades.
Spotted something wrong? Or know the PR text has fresher detail than the writeup above?