nisavid/artifact-customs
Clear, adopt, maintain, replace, and retire exact third-party software components under explicit policy.
Use when explicitly authorized to add an exact third-party software component or materially revise its trust policy, including a first package, vendored artifact, Action, image, toolchain, CLI, or agent-plugin pin. Establishes the durable policy and first admitted identity; do not use for read-only comparison, ordinary updates under an existing policy, or generic Git/PR work.
Use for a standalone ungoverned read-only clearance of an exact third-party software component or immutable artifact, including provenance, license, dependencies, and conformance checks before adoption or maintenance. Includes packages, vendored artifacts, Actions, images, toolchains, CLIs, and agent plugins; a governed advisory enters maintenance first, and mutation and generic vendor, release, deployment, Git, PR, or review work are excluded.
Use when updating, investigating an advisory for a third-party software component governed by a named existing policy, replacing, sealing, retiring, or completing its dependency PR. Includes routine Dependabot work and scheduled or foreign-harness wake-ups; do not use to invent a new trust boundary, silently revise policy, or perform generic Git/PR/review work.