Skip to content

docs(devlog): drop remote home-path citations the privacy scanner flags - #3197

Merged
lidge-jun merged 3 commits into
devfrom
codex/260902-admin-merge-3190
Sep 1, 2026
Merged

lidge-jun merged 3 commits into
devfrom
codex/260902-admin-merge-3190

Conversation

@lidge-jun

Copy link
Copy Markdown
Owner

Summary

Verification

  • bun run privacy:scan — exit 0 on this head (ea412aa46).
  • Before the edit the same command failed on devlog/_plan/260902_multiplatform_qa_and_gui/091_wp6_merge_outcome.md:13.
  • scripts/privacy-scan.ts is unchanged.
  • No GUI change; no screenshot.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

jun added 3 commits September 2, 2026 03:03
Roadmap unit for landing the adaptive-effort PR after the privacy-scan
citation on origin/dev is anonymized. Docs-only; no production change.
Fold the PLAN-VERIFIER-REAL-01 audit blocker into the roadmap with live
privacy:scan and gh exit evidence. Docs-only.
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner September 1, 2026 18:04
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-01T18:07:03.415135Z ea412aa PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Sep 1, 2026
@lidge-jun
lidge-jun merged commit 4be4326 into dev Sep 1, 2026
16 checks passed
@lidge-jun
lidge-jun deleted the codex/260902-admin-merge-3190 branch September 1, 2026 18:05

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ea412aa46f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

4. Focused checks only: `bun x tsc --noEmit`; `cd gui && bun x tsc --noEmit` if GUI files changed; `bun test tests/codex-catalog.test.ts tests/openai-chat-hardening.test.ts tests/combo-management-api.test.ts tests/combo-workspace-data.test.ts tests/combos.test.ts tests/management-provider-validation.test.ts` if those files still exist after rebase; `bun run privacy:scan`.
5. Push `--no-verify`. Refresh #3190 (or open the carry). Fill the template.
6. Wait for exact-head Cross-platform CI on the new SHA. Record the run id. `gates` Privacy scan must be SUCCESS. Known macOS websocket flake: rerun that job, compare against #3128, do not rewrite unrelated code.
7. Admin squash merge: `gh pr merge <n> --squash --admin --delete-branch` with comment naming the bypass (owner-authored, CI green on exact head, no security-boundary).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Bind the admin merge to the verified head

If another push updates the PR after step 6 checks the head but before this command runs, --admin can merge that new, unverified revision because the merge is not bound to the SHA whose CI was inspected. The installed gh pr merge --help explicitly provides --match-head-commit SHA for ensuring that “the pull request head must match to allow merge”; pass the verified headRefOid through that option so a concurrent update aborts rather than bypassing exact-head CI. This repository also resets readiness whenever the head changes, so the merge step must preserve that invariant.

AGENTS.md reference: AGENTS.md:L296-L299

Useful? React with 👍 / 👎.

tarunravi pushed a commit to tarunravi/opencodex that referenced this pull request Sep 14, 2026
…gs (lidge-jun#3197)

* docs(devlog): plan the admin merge train for 3190

Roadmap unit for landing the adaptive-effort PR after the privacy-scan
citation on origin/dev is anonymized. Docs-only; no production change.

* docs(devlog): record verifier one-liners for the 3190 train

Fold the PLAN-VERIFIER-REAL-01 audit blocker into the roadmap with live
privacy:scan and gh exit evidence. Docs-only.

* docs(devlog): drop remote home-path citations the privacy scanner flags

---------

Co-authored-by: jun <jun@lidge.dev>
agentHits pushed a commit to agentHits/opencodex that referenced this pull request Sep 17, 2026
…gs (lidge-jun#3197)

* docs(devlog): plan the admin merge train for 3190

Roadmap unit for landing the adaptive-effort PR after the privacy-scan
citation on origin/dev is anonymized. Docs-only; no production change.

* docs(devlog): record verifier one-liners for the 3190 train

Fold the PLAN-VERIFIER-REAL-01 audit blocker into the roadmap with live
privacy:scan and gh exit evidence. Docs-only.

* docs(devlog): drop remote home-path citations the privacy scanner flags

---------

Co-authored-by: jun <jun@lidge.dev>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant