Skip to content

Make native session defaults persistent and verify upstream token tools in CI - #19

Merged
seathatflowsinourveins merged 5 commits into
mainfrom
codex/native-defaults-20260920
Sep 20, 2026
Merged

seathatflowsinourveins merged 5 commits into
mainfrom
codex/native-defaults-20260920

Conversation

@seathatflowsinourveins

@seathatflowsinourveins seathatflowsinourveins commented Sep 20, 2026 •

Copy link
Copy Markdown
Owner

New sessions previously depended on project PATH setup and a copied startup prompt. The handbook now records persistent Linux/WSL defaults for both Codex homes, native Claude and shell startup, with actual child-process evidence and explicit project adoption boundaries.

The new GitHub workflow installs pinned RTK, QMD, Repomix and TOON through upstream release/package commands. It checks source fidelity, recovery, expected errors and cleanup, then uploads sanitized command receipts. The offline HTML guide embeds the updated setup handbook.

Validation: 79 focused tests; publication, catalog, convergence and generated-HTML checks passed. Clean local installation passed 41 command expectations and 14 acceptance checks. Both Codex homes returned 13 trusted/enabled hooks and native child environments; Claude returned four successful startup completions. No model turn was started in these launch checks. Independent review found no remaining issues.

Hosted GitHub execution also passed all 41 command expectations and 14 checks: https://github.com/seathatflowsinourveins/native-agent-stack/actions/runs/35527455997. The downloaded receipt and five byte-exact fixture outputs are retained permanently in Git, with seven verified input hashes. Independent review also confirmed the hosted results.

Codex hook execution and SessionEnd completion are not established by the initialization-only path. Fixture savings remain separate from retained host statistics and provider usage.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@seathatflowsinourveins
seathatflowsinourveins merged commit a86b8df into main Sep 20, 2026
7 checks passed
seathatflowsinourveins pushed a commit that referenced this pull request Sep 25, 2026
Independent review confirmed the code change is correct (syft finds
urllib3 1.26.4 in the temp-copied requirements.txt, 0 packages in the
renamed in-repo fixture); this round only corrects doc/test-docstring
statements found imprecise or wrong:

- docs/github-automation.md: the osv-scanner `excluded` list is not empty;
  it still names three gap-wave-2 DVC-lock evidence fixtures. Describe it
  accurately instead.
- docs/decisions/2026-09-22-github-automation-closure.md: replace the wrong
  "reads the dependency graph directly" reasoning with the actual mechanism
  (Scorecard v5.5.0's vulnerabilities check runs OSV-Scanner/osv-scalibr
  directly over repository files, matching any *requirements*.txt name,
  which is why this repo's own exclusion lists were never honored). Say
  alert #19 is "expected to close" (not "closing"), credit the rename
  rather than the Dependabot removal, add the verification command, and add
  alternatives-considered and an overturn condition to both superseded notes.
- tests/test_grype_known_cve_fixture.py: fix the docstring's backwards claim
  ("grype scans by directory content, not filename convention" -> syft's
  Python cataloger matches by filename convention, any *requirements*.txt,
  which is exactly why the temp copy is needed); split the fixture-content
  checks (declares urllib3==1.26.4, matches its registered sha256) into an
  unconditional test class so CI checks the fixture even where grype is
  absent (including the validate job); assert the temp scan directory
  resolves outside the repository root before copying into it.
- catalogs/foundation/automation.json: update the stale osv-scanner job
  description to match the corrected exclusion-list and fixture-naming state.
- manifests/evidence.json: refreshed hashes for the four changed files.

Six validators and the targeted test modules re-run clean.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
seathatflowsinourveins added a commit that referenced this pull request Sep 25, 2026
… dependency scan (#224)

Renames the deliberately vulnerable grype positive-control fixture (urllib3==1.26.4) to requirements.txt.fixture, so Scorecard's embedded OSV-Scanner, which reads *requirements*.txt, stops counting its 9 urllib3 advisories (alert #19, expected to close after the next main Scorecard run). The test copies the fixture into a temp dir outside the repo before running grype. Stale osv and Dependabot exclusions are removed. Docs and the decision record are corrected, and the fixture-content test now runs unconditionally in CI.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@seathatflowsinourveins
seathatflowsinourveins deleted the codex/native-defaults-20260920 branch September 25, 2026 18:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant