diff --git a/Repo-docs-PACKAGE-REGISTRY-RELEASES.-.md b/Repo-docs-PACKAGE-REGISTRY-RELEASES.-.md index 4144352..23fcded 100644 --- a/Repo-docs-PACKAGE-REGISTRY-RELEASES.-.md +++ b/Repo-docs-PACKAGE-REGISTRY-RELEASES.-.md @@ -1,4 +1,4 @@ - + > Mirrored from `/mnt/DATA/git/govoplan/docs/PACKAGE_REGISTRY_RELEASES.md`. > Origin: `repository`. @@ -224,6 +224,11 @@ requirements. Missing dependency/interface providers and unsupported update windows are surfaced before an operator adds the entry to a plan; installer preflight remains authoritative. +Catalog entries also carry the permission definitions declared by the tagged +module manifest. Admin groups and exposes their scopes before an install or +update is planned. This is disclosure only: installing a module does not grant +its permissions to an account, role, group, tenant, or service account. + Package lifecycle and availability are intentionally separate: - install, update, and uninstall change the instance-wide package composition;