-
Notifications
You must be signed in to change notification settings - Fork 0
docs(operations): record runner audit credential and assignment contract #401
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Changes from all commits
Commits
Show all changes
23 commits
Select commit
Hold shift + click to select a range
e7ecfea
test(security): require runner audit token redaction
seonghobae bdb4864
fix(security): redact runner audit credential errors
seonghobae a39f9fd
fix(security): keep token redaction coverage exact
seonghobae f0d4aed
test(security): cover missing gh stderr redaction path
seonghobae fb04907
test(operations): reproduce queued job timestamp false assignment
seonghobae 9f2557d
fix(operations): require runner identity for assignment evidence
seonghobae 2cd4103
test(docs): reject timestamp runner-assignment authority
seonghobae b4e0f99
docs(operations): align runner assignment authority
seonghobae 5752552
test(security): require runner audit token capability
seonghobae fa0cefd
fix(security): broker runner audit token capability
seonghobae 627b0cb
test(docs): require runner token capability contract
seonghobae c58fed9
docs(security): document runner token capability ingress
seonghobae 61c6892
test(security): align default runner audit credential ingress
seonghobae bbbfe8e
fix(operations): normalize runner audit failure boundaries
seonghobae 0634ba5
test(operations): align production runner audit capability boundary
seonghobae fe09e34
merge: integrate protected main after #396
seonghobae 5f861fb
fix(operations): preserve malformed JSON evidence contract
seonghobae b0a7a38
merge: restack runner audit on protected main a634066
seonghobae c866654
fix(coverage): remove unreachable GitHub API default branch
seonghobae f387edf
test(security): prove delegated runner audit token wins
seonghobae c4a0ffb
test(security): reject ambient runner audit credential selection
seonghobae f4a4bc9
test: cover non-error runner audit rejection
seonghobae 64c6213
docs(operations): record runner audit credential and assignment contract
cursoragent File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
text.split(secret).join("[REDACTED]")is correct for a non-empty active token, andcreateGhSubprocessEnvironmentcurrently rejects emptyGH_TOKENbefore this runs.If this helper is reused with an empty secret,
split("")inserts[REDACTED]between every character. Guard withif (typeof secret !== "string" || secret.length === 0) return textso a later caller cannot take that landmine.