Repository navigation
Make native session defaults persistent and verify upstream token tools in CI - #19
Merged
Merged
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
seathatflowsinourveins
pushed a commit
that referenced
this pull request
Sep 25, 2026
Independent review confirmed the code change is correct (syft finds urllib3 1.26.4 in the temp-copied requirements.txt, 0 packages in the renamed in-repo fixture); this round only corrects doc/test-docstring statements found imprecise or wrong: - docs/github-automation.md: the osv-scanner `excluded` list is not empty; it still names three gap-wave-2 DVC-lock evidence fixtures. Describe it accurately instead. - docs/decisions/2026-09-22-github-automation-closure.md: replace the wrong "reads the dependency graph directly" reasoning with the actual mechanism (Scorecard v5.5.0's vulnerabilities check runs OSV-Scanner/osv-scalibr directly over repository files, matching any *requirements*.txt name, which is why this repo's own exclusion lists were never honored). Say alert #19 is "expected to close" (not "closing"), credit the rename rather than the Dependabot removal, add the verification command, and add alternatives-considered and an overturn condition to both superseded notes. - tests/test_grype_known_cve_fixture.py: fix the docstring's backwards claim ("grype scans by directory content, not filename convention" -> syft's Python cataloger matches by filename convention, any *requirements*.txt, which is exactly why the temp copy is needed); split the fixture-content checks (declares urllib3==1.26.4, matches its registered sha256) into an unconditional test class so CI checks the fixture even where grype is absent (including the validate job); assert the temp scan directory resolves outside the repository root before copying into it. - catalogs/foundation/automation.json: update the stale osv-scanner job description to match the corrected exclusion-list and fixture-naming state. - manifests/evidence.json: refreshed hashes for the four changed files. Six validators and the targeted test modules re-run clean. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
seathatflowsinourveins
added a commit
that referenced
this pull request
Sep 25, 2026
… dependency scan (#224) Renames the deliberately vulnerable grype positive-control fixture (urllib3==1.26.4) to requirements.txt.fixture, so Scorecard's embedded OSV-Scanner, which reads *requirements*.txt, stops counting its 9 urllib3 advisories (alert #19, expected to close after the next main Scorecard run). The test copies the fixture into a temp dir outside the repo before running grype. Stale osv and Dependabot exclusions are removed. Docs and the decision record are corrected, and the fixture-content test now runs unconditionally in CI. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
New sessions previously depended on project PATH setup and a copied startup prompt. The handbook now records persistent Linux/WSL defaults for both Codex homes, native Claude and shell startup, with actual child-process evidence and explicit project adoption boundaries.
The new GitHub workflow installs pinned RTK, QMD, Repomix and TOON through upstream release/package commands. It checks source fidelity, recovery, expected errors and cleanup, then uploads sanitized command receipts. The offline HTML guide embeds the updated setup handbook.
Validation: 79 focused tests; publication, catalog, convergence and generated-HTML checks passed. Clean local installation passed 41 command expectations and 14 acceptance checks. Both Codex homes returned 13 trusted/enabled hooks and native child environments; Claude returned four successful startup completions. No model turn was started in these launch checks. Independent review found no remaining issues.
Hosted GitHub execution also passed all 41 command expectations and 14 checks: https://github.com/seathatflowsinourveins/native-agent-stack/actions/runs/35527455997. The downloaded receipt and five byte-exact fixture outputs are retained permanently in Git, with seven verified input hashes. Independent review also confirmed the hosted results.
Codex hook execution and SessionEnd completion are not established by the initialization-only path. Fixture savings remain separate from retained host statistics and provider usage.