diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index af4fb139..be3168f6 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) + - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) - `SeAuditPrivilege`、`SeSecurityPrivilege`、`CrashOnAuditFail` の独立したプロファイル対応と、省略時の保持およびレビュー範囲を文書化しました。 (#384) diff --git a/CHANGELOG.md b/CHANGELOG.md index 3cbce61b..effd312c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) + - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) - Document independent audit-right and CrashOnAuditFail profile coverage, including omission-preserves semantics and service-account review boundaries. (Related #384) diff --git a/docs/native-provider-packs.md b/docs/native-provider-packs.md index e9b02158..6be571e3 100644 --- a/docs/native-provider-packs.md +++ b/docs/native-provider-packs.md @@ -54,3 +54,6 @@ Primary references: [Microsoft WEF Appendix C/F](https://learn.microsoft.com/en- For an explicitly reviewed DNS Server analytical transition with stopped-trace archival, use the separate [DNS analytical lifecycle](dns-analytical.md). The ordinary provider-pack setter continues to refuse Analytical/Debug configuration. The separate [`dns-client-probe`](dns-client-probe.md) can collect a fixed native DNS Client lookup completion and exact Operational3008 XML. The six pinned rule channel strings remain mismatched; the probe grants no Sigma readiness credit. +# Issue 386 coverage + +Provider packs are explicit and opt-in. Each pack pins its provider, channel, event IDs, required string fields, source rule hashes, supported role/build families, and minimum buffer size. Schema or service uncertainty produces a manual-review result; analytical/debug channels stay inventory-only. A configured channel receives no Sigma or detection credit until emitted XML, field mapping, forwarding, and matching are validated separately. diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index 3237a671..c6d60d09 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) + - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) - `SeAuditPrivilege`、`SeSecurityPrivilege`、`CrashOnAuditFail` の独立したプロファイル対応と、省略時の保持およびレビュー範囲を文書化しました。 (#384) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 178415ed..4799aff0 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) + - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) - Document independent audit-right and CrashOnAuditFail profile coverage, including omission-preserves semantics and service-account review boundaries. (Related #384)