From b1670bc02de895e0a7368f634718d76cb648eaaa Mon Sep 17 00:00:00 2001 From: Zhi Pei Date: Sun, 27 Sep 2026 10:57:27 +0800 Subject: [PATCH 1/3] ci: harden workflow permissions and action refs --- .github/workflows/ci.yml | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 6ecbcfa..5605922 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,11 +1,13 @@ name: CI on: [push, pull_request] +permissions: + contents: read jobs: verify: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 with: { node-version: '24', cache: 'npm' } - run: npm ci --no-fund - run: npm run typecheck From a5b0b47b5ed97f1b1a38749331a0e24d5667f0e9 Mon Sep 17 00:00:00 2001 From: Zhi Pei Date: Sun, 27 Sep 2026 10:57:29 +0800 Subject: [PATCH 2/3] ci: opt into workflow security readiness checks --- .delivery-readiness.yml | 9 +++++++++ 1 file changed, 9 insertions(+) create mode 100644 .delivery-readiness.yml diff --git a/.delivery-readiness.yml b/.delivery-readiness.yml new file mode 100644 index 0000000..25b55f7 --- /dev/null +++ b/.delivery-readiness.yml @@ -0,0 +1,9 @@ +version: 1 +recommended_checks: + - dependency_lock + - security_guidance + - support_guidance + - architecture_guidance + - limitations_guidance + - workflow_permissions + - action_pinning From 9b577b2c40cb8d5ae80328ba43d39ed7921507b8 Mon Sep 17 00:00:00 2001 From: Zhi Pei Date: Sun, 27 Sep 2026 10:59:28 +0800 Subject: [PATCH 3/3] docs: make setup run and test guidance explicit --- README.md | 25 +++++++++++++++++++++---- 1 file changed, 21 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index 8629647..bf61627 100644 --- a/README.md +++ b/README.md @@ -16,21 +16,38 @@ The rescue moves validation to the HTTP boundary, durably claims one order opera See [the root-cause analysis](docs/ROOT_CAUSE_ANALYSIS.md), [before/after evidence](docs/BEFORE_AFTER.md), and [architecture](docs/ARCHITECTURE.md). -## Reproduce and validate +## Setup Requires Node 24. ```sh npm ci --no-fund +``` + +On Windows where `npm.ps1` is blocked, `npm.cmd` is equivalent. No private cache path is required. + +## Run + +Start the local synthetic API with: + +```sh +npm run dev +``` + +The fixed route is `POST /webhooks/orders` with `eventId`, `orderId`, and positive integer `amountCents`; `GET /health` returns service status. + +## Test and validation + +Run the deterministic verification set with: + +```sh npm run typecheck npm test npm run build npm audit ``` -On Windows where `npm.ps1` is blocked, `npm.cmd` is equivalent. No private cache path is required. - -The tests named `SYNTHETIC INTENTIONALLY FLAWED BASELINE` pass by asserting known-bad behavior. They are evidence, not approval of the baseline. The fixed route is `POST /webhooks/orders` with `eventId`, `orderId`, and positive integer `amountCents`; `GET /health` returns service status. +The tests named `SYNTHETIC INTENTIONALLY FLAWED BASELINE` pass by asserting known-bad behavior. They are evidence, not approval of the baseline. ## Limitations