From 0b8627bbc05d0b9919dc3535970feadfb49ec129 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 06:49:05 +0900 Subject: [PATCH 1/3] docs: document issue coverage --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ docs/gpo-creation.md | 3 +++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 5 files changed, 11 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index be3168f6..8b1c765c 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) + - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) diff --git a/CHANGELOG.md b/CHANGELOG.md index effd312c..a8e5e892 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document the explicit GPO export scope and its domain-deployment limitations. (Related #2) + - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) diff --git a/docs/gpo-creation.md b/docs/gpo-creation.md index 70f60588..32e01f13 100644 --- a/docs/gpo-creation.md +++ b/docs/gpo-creation.md @@ -83,3 +83,6 @@ Windows Server 2022/2025 CI exercises real GPMC backup/report/OverallStatus usin - [GPMBackup report generation](https://learn.microsoft.com/en-us/windows/win32/api/gpmgmt/nf-gpmgmt-igpmbackup-generatereport) - [Native GPO import: settings replacement and destination ACL/link preservation](https://learn.microsoft.com/en-us/windows/win32/api/gpmgmt/nf-gpmgmt-igpmgpo-import) - [OverallStatus must be checked as well as the native operation](https://learn.microsoft.com/en-us/windows/win32/api/gpmgmt/nf-gpmgmt-igpmresult-overallstatus) ++### Issue 2 coverage + +GPO creation is an explicit export workflow with role/build/profile provenance and unsupported-control disclosures. Export success does not claim domain linking, delegation, replication, client refresh, or resultant-policy application. diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index c6d60d09..c54f859f 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) + - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 4799aff0..9fe08ce8 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document the explicit GPO export scope and its domain-deployment limitations. (Related #2) + - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) From 9cf5afe62b17f54bd91ac14116c111a448b4d699 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 07:05:57 +0900 Subject: [PATCH 2/3] docs: fix issue coverage heading --- docs/gpo-creation.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/gpo-creation.md b/docs/gpo-creation.md index 32e01f13..f9ef0577 100644 --- a/docs/gpo-creation.md +++ b/docs/gpo-creation.md @@ -83,6 +83,6 @@ Windows Server 2022/2025 CI exercises real GPMC backup/report/OverallStatus usin - [GPMBackup report generation](https://learn.microsoft.com/en-us/windows/win32/api/gpmgmt/nf-gpmgmt-igpmbackup-generatereport) - [Native GPO import: settings replacement and destination ACL/link preservation](https://learn.microsoft.com/en-us/windows/win32/api/gpmgmt/nf-gpmgmt-igpmgpo-import) - [OverallStatus must be checked as well as the native operation](https://learn.microsoft.com/en-us/windows/win32/api/gpmgmt/nf-gpmgmt-igpmresult-overallstatus) -+### Issue 2 coverage +### Issue 2 coverage GPO creation is an explicit export workflow with role/build/profile provenance and unsupported-control disclosures. Export success does not claim domain linking, delegation, replication, client refresh, or resultant-policy application. From 7e93606b7276faeeb2225f2d3b35a151afb90aae Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 07:35:31 +0900 Subject: [PATCH 3/3] docs: restore GPO changelog entry --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 4 files changed, 8 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index de779ff3..0c1ae8f6 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) + - 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10) - バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185) diff --git a/CHANGELOG.md b/CHANGELOG.md index c78e5739..c3677ed0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document the explicit GPO export scope and its domain-deployment limitations. (Related #2) + - Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10) - Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185) diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index 2b3d7a20..2ceac9cc 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) + - 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10) - バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 564b665c..9826859f 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document the explicit GPO export scope and its domain-deployment limitations. (Related #2) + - Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10) - Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185)