Skip to content

feat: add read-only operational state checker for 0.10.0 - #22

Draft
tashaamanda wants to merge 1 commit into
mainfrom
codex/npm-0.10.0-dependency-reduction
Draft

tashaamanda wants to merge 1 commit into
mainfrom
codex/npm-0.10.0-dependency-reduction

Conversation

@tashaamanda

Copy link
Copy Markdown
Contributor

CI-only: This draft pull request exists to run the complete public checks. Do not merge without separate explicit approval.

Summary

  • Add a bounded, read-only operational state checker and reconcile --check command.
  • Keep the checker non-mutating and separate observed evidence from suggested follow-up.
  • Reduce the default installation footprint by making embedding providers optional.
  • Harden public-action risk detection for natural-language branch push requests.
  • Update public documentation, security notes, and release metadata for 0.10.0.

Validation

  • 62 tests pass locally, including read-only, path-boundary, and public-action guard regressions.
  • Public tracked-tree and packed-artifact privacy gates pass with the repository denylist.
  • The packed package contains only the documented npm allowlist.
  • Dependency audit: 0 Critical, 0 High, 2 Moderate, 1 Low. The public audit workflow will verify the high-severity release threshold.

Scope

This PR is for CI evaluation only. Merge, tag, GitHub release, deployment, and npm publication each require separate approval.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant