ranade-oss puts the brakes on automatic upstream syncs
ROSS declined two upstream updates rather than letting an automated process carry changes it could not safely assess.
One proposed update altered operational guidance around secrets, provider credentials, cloud storage and deployment setup. Because ROSS handles environment configuration differently, it was held for closer review.
The other touched citation checking, data boundaries and the user interface - a broad, security-sensitive package. Instead of treating it as routine maintenance, the sync process left the existing product unchanged and sent it for architectural review.
That restraint matters: an empty update can be the right outcome when a change crosses security or configuration boundaries.
Spotted something wrong? Or know the PR text has fresher detail than the writeup above?