Outcome
Create a trustworthy delivery pipeline in which non-mutating lint, frontend tests/build, Functions lint/tests, Firestore Rules tests, dependency/secret checks, and exact-commit staging evidence gate any deployment. Remove service-account material from frontend builds and move toward least-privilege OIDC/WIF with protected approval.
Why this is a tracker
This is cross-boundary delivery and external IAM work. Assign only atomic children.
Children
System acceptance
- The exact commit cannot deploy until every required check passes.
- Lint never rewrites files or hides failures.
- Frontend builds receive no server credential.
- Missing deployment authority/config fails visibly.
- Backend/rules/index changes precede dependent frontend code.
- Production requires named approval and staging evidence.
Dependencies
SAFETY-001 (#99) is the local-safety foundation. External IAM/environment work requires an authorized owner.
Claim rule
Do not claim this tracker. Claim exactly one dependency-ready child, assign it, and post the repository-standard timestamped CLAIMED marker before editing.
Outcome
Create a trustworthy delivery pipeline in which non-mutating lint, frontend tests/build, Functions lint/tests, Firestore Rules tests, dependency/secret checks, and exact-commit staging evidence gate any deployment. Remove service-account material from frontend builds and move toward least-privilege OIDC/WIF with protected approval.
Why this is a tracker
This is cross-boundary delivery and external IAM work. Assign only atomic children.
Children
mainand closed)mainand closed)mainand closed)9eafab1217aff7058c42240aaba72d7b93f8ed24; safe negative probes published nothingSystem acceptance
Dependencies
SAFETY-001 (#99) is the local-safety foundation. External IAM/environment work requires an authorized owner.
Claim rule
Do not claim this tracker. Claim exactly one dependency-ready child, assign it, and post the repository-standard timestamped CLAIMED marker before editing.