-
Notifications
You must be signed in to change notification settings - Fork 0
fix: autorelease unattended hardening #56
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
48 commits
Select commit
Hold shift + click to select a range
8427c3c
docs: add autorelease unattended hardening plan
loadinglucian fba2b25
fix: accept any maintained branch in stage-4 module comparison
loadinglucian 145211a
fix: validate version shape only in build and package gates
loadinglucian a1375a1
fix: protect gate harness scripts and tests from admitted patches
loadinglucian 12fa3f4
fix: protect toolchain pins and the shared shell library from admitte…
loadinglucian 368dbee
refactor: unify merge admission check assertions in one script
loadinglucian 9a899ea
fix: correct admission assert rationale and cover check-name path
loadinglucian eb91008
refactor: assert workflow structure instead of source text in verifier
loadinglucian b907f5d
fix: assert the whole release workflow is free of the OpenAI credential
loadinglucian 7c9c0c0
feat: decide to recover a published release with no event record
loadinglucian d174ea8
feat: recover missing event records from the watcher
loadinglucian 0f641aa
fix: stop a blocked record recovery from starving the watcher
loadinglucian e78e2f9
fix: bind a recovered record to an attested release on main
loadinglucian 8b0c869
fix: keep record recovery out of the shared checkout and branch name
loadinglucian 243329f
fix: keep the recovery merge from deleting a branch in use
loadinglucian 78cbe67
refactor: route watch actions through deterministic control table
loadinglucian 9c632b8
fix: route the recovery action and assert the hard operator gates
loadinglucian 9e82fd1
chore: delete unreferenced schemas
loadinglucian ae0454a
refactor: align the completion assessment schema with admission
loadinglucian 952ed15
refactor: dedupe digest and sha validation helpers
loadinglucian 47f1123
chore: enforce bash defaults and least privilege in workflows
loadinglucian 4075fbf
fix: bind trusted automation exemptions to single-file records
loadinglucian b104cf6
test: fold line continuations before checking gh calls name the repo
loadinglucian d3df414
docs: record why the recovery withdraw path traps only EXIT
loadinglucian 3cf020c
chore: scope the public-language check to tracked files
loadinglucian bec6c5e
chore: keep the packaging test artifacts out of the working tree
loadinglucian 8dc474b
refactor: reuse canonical digest helpers in the admin snapshot
loadinglucian abd64cc
fix: shut the release fixture server down cleanly
loadinglucian 723dc81
chore: narrow the shellcheck suppression and cover every bash script
loadinglucian ea543de
test: assert both repositories name event records identically
loadinglucian 8f5baf6
fix: shield the recovery withdraw from cancellation escalation
loadinglucian 9ef9071
fix: fail the public-language check when it lists no files
loadinglucian 49092ac
refactor: split control module behind stable facade
loadinglucian 192074a
refactor: split plan admission into its three gates
loadinglucian 6f7b221
docs: state the watcher routing invariant the workflow depends on
loadinglucian 06cb37d
test: scan the whole control package for classifier markers
loadinglucian 2958457
docs: correct autorelease references and document unattended lifecycle
loadinglucian 0964951
fix: set the validate output only after its artifact uploads
loadinglucian c8589aa
test: scan nested control modules for classifier markers
loadinglucian 09a03af
docs: make the automation the subject of the rebuild revision
loadinglucian e34872c
fix(autorelease): defer the no-change evidence record after a recover…
loadinglucian 2b7d9be
refactor(autorelease): read the missing record after the health guards
loadinglucian b32afa0
fix(autorelease): protect the shared dependabot configuration in php-bin
loadinglucian bb27c0d
docs: drop the committed hardening plan from the release repository
loadinglucian 6f59ab3
docs(autorelease): bind an in-flight action key across watcher runs
loadinglucian ca9cd9b
test(autorelease): validate the jq-built recovery record as a complet…
loadinglucian 5e5d99f
fix: group the grep tolerance so the listing failure stays fatal
loadinglucian 2b22061
test: anchor codeowners pairing on the repo root and tolerate tabs
loadinglucian File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.