diff --git a/docs/TODO.md b/docs/TODO.md index 0bcfaec..d2c33ef 100644 --- a/docs/TODO.md +++ b/docs/TODO.md @@ -128,6 +128,7 @@ 6. Supply-chain hygiene: enforce tiered image pinning (stateful `tag@digest`; stateless rolling tags — ADR-011) + official/verified images via the service checklist; revisit active scanning (Trivy/Grype) once a triage stack exists (R1). + 7. Is our network setup as it should be? I am not sure if all traffic between ubongo and notes goes via askari? what if askari breaks - will the rest work? 16. **ADR-011 (update management) — resolve open questions + accept.** Committed as **Proposed**; resolve before marking Accepted: