fix: follow up unresolved PR76 security findings - #88
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
૮ >ﻌ< ა ci reviewran on 45cc235 — fix: restore canonical vault progress import
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4b1e7aa7b1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
eb7c55c to
9245e8b
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 35e45663c1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
186e392 to
ebb84fa
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ebb84fa781
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
59c8ddd to
787a2d4
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 787a2d4453
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
787a2d4 to
3f0f4c9
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 45cc23595f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Summary
Follow-up to merged PR #76, based on current fork main
9e83df3634985a234e78aefa66e5ca321a08a3ff. This PR fixes the highest-risk coherent security/lifecycle subset and does not merge or modify PR84/PR85.Fixed:
-P; admitted broker args and runtime args are kept consistent.pre_kanban_completeboundary.--data,--json, and short/equals variants)./dev/nullGit config isolation.Validation
scripts/run_tests.shchanged Python slice: 352 tests passed before the final local-env assertion correction; the final targeted changed tests passed, including the new fencing/auth invariants.../../node_modules/.bin/vitest run --project electron electron/desktop-background-shutdown.test.ts: 2 passed.npm run typecheck --workspace apps/desktop -- --pretty false: passed.scripts/run_tests.sh tests/tools/test_approval.pyrun has one pre-existing unrelated failure inTestDetectDangerousRm.test_nonrecursive_verification_artifact_cleanup_is_not_dangerous; the new curl guard cases pass.Remaining PR76 P1 findings
Not included because they are separate clusters or already fixed on current main:
No merge performed.