Repository navigation
Record and guard the Dependabot alert 16 dismissal (frozen macOS variant) - #635
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6cd585e962
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
6cd585e to
406a7e9
Compare
…guard the frozen variant Round 2 of PR #635, answering the three P2 findings of the Codex review of 6cd585e: - R1: evidence/receipts/dependabot-alert-16-dismissal-20261003.json retains a read-only GET readback of Dependabot alert 16 at 2026-10-03T06:58:43Z (dismissed, not_used, dismissed_at 04:51:57Z; GHSA-vcvr-r3jv-pc5j, critical; npm next on the variant's package.json, range >= 16.2.0, < 16.3.6, first patched 16.3.6), the PATCH as recorded (not re-run), the reasoning chain, the overturn and the limits. The closure record's alert-16 note cites it. - R2: docs/decisions/2026-10-02-github-automation-practice.md and docs/github-automation.md return to main's bytes; open #595 rewrites the same lines against the merged definitive manifest (#602). - R3: tests/test_frozen_macos_variant_no_use.py fails when the frozen variant stops being inert: a file beside package.json and the lock (on disk or tracked); a reference to the directory from a tracked workflow, script, build file, TOML file or package.json other than the records that only check or bind it (workflow and script references pinned to their present lines); or a lock that no longer pins next 16.3.5 at the sha256 FROZEN_LOCKS binds (read with ast). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…-16 cause, authority and review date Round 3 of PR #635, answering the reviews of round 2: - tests/test_frozen_macos_variant_no_use.py is now a tripwire for direct references. It matches the artifact directory's name (the parent of variant/) in every file git ls-files lists except the record classes (*.md, evidence/**, manifests/evidence.json, catalogs/**, blueprints/**/*.json), and scans configuration and scripts inside those classes too (package.json and other workspace manifests, .devcontainer/**, *.toml, *.yml, *.yaml, script suffixes, build files, shebangs, executable modes, symbolic links). Whole-file allowances are replaced by 31 pinned lines in 15 files (sha256 of each stripped line, the module's own constant included); a new referencing line fails anywhere, and a pinned line that is no longer found fails too, so a broken scope rule cannot drop a pinned file. git ls-files failing is a failure, not a skip. OS metadata files are ignored in the variant directory, and an absent variant passes. Its docstring states the limit: a route that never spells the name (inventory loop, glob, fragments, Markdown recipe) is not caught. - Mutation checks in a scratch clone: the reconstructed round-2 mutants, the five round-3 mutants and eight added checks fail; the four stated limits and the two allowed cases pass; the unmutated tree passes. The results are retained in the receipt's guard_mutation_checks. - evidence/receipts/dependabot-alert-16-dismissal-20261003.json and the closure record's alert-16 note: Dependabot alerts come from the dependency graph (manifests, lock files and submissions; GitHub Docs read 2026-10-03), so the alert is independent of the OSV exception's scope; the dismissal was made at the user's request of 2026-10-03 under section 8's not_used practice (alerts 7-15); it has no expiry and is rechecked when the frozen OSV exception (ignoreUntil 2026-12-24) is renewed, changed or removed, or when the tripwire fails; the live recipe lock pins next 16.3.8 (the frozen config's 16.3.6 clause predates #587 and is left unedited). The branch is rebased onto main 652c15a (#620, after #639), and the receipt's checked_commit moves to it; the files the receipt cites are identical at e88d59e and 652c15a. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
406a7e9 to
7ce51c0
Compare
…recheck to the OSV exception's date and quote the authority Round 4 of PR #635, answering the security review of round 3: - tests/test_frozen_macos_variant_no_use.py: blueprints/**/*.json is no longer an excluded class, so a launch configuration there (an mcpServers entry such as socraticode-mcp.json) is scanned. The excluded classes are *.md, evidence/**, manifests/evidence.json and catalogs/**, and inside them only the configuration and scripts the module recognises are read. The 25 referencing lines this exposes are pinned (23 in experiment-macos-20260924.json, one in each retained OSV-Scanner JSON output of the 2026-09-30 relocks): 56 lines in 18 files. The name is matched in any ASCII letter case; pins stay exact. A new test reads .github/osv-scanner-frozen-macos.toml with tomllib and fails with the recheck message when the exception for GHSA-vcvr-r3jv-pc5j is absent or duplicated or its ignoreUntil is not 2026-12-24. The docstring describes the scope as the code applies it and names the limits: a launch configuration under evidence/** or catalogs/** with a name the module does not recognise is not scanned, and PINNED_LINES can be extended in the change that adds a use (the main ruleset requires no code-owner review). - Mutation checks in a scratch clone: round 3's 25 mutants keep their outcomes; N1 (blueprints/x/launch.json running pnpm in the variant), N2 (an upper-cased path) and N3 (ignoreUntil changed) fail now and pass against the round-3 module; X9-X12 (scope and case regressions, exception removed, reason edited) fail; L5 (the N1 configuration under evidence/**) passes, as the stated limit says. - evidence/receipts/dependabot-alert-16-dismissal-20261003.json: authorization quotes the user's message of 2026-10-03 verbatim with its limits; the alerts 7-15 precedent is analogous, not identical; the dismissal lasts until reopened, with its recheck tied to the exception's date test and to the tripwire. guard, review_date, overturn, limitations and guard_mutation_checks match the module; checked_commit moves to main d2777ee (#619 changed none of the cited files). - The closure record's alert-16 note gives the authority in one sentence that points to the receipt, quotes the dismissal comment's "Live recipe lock pins next 16.3.6+" and states the 16.3.8 fact separately, says exactly when the module fails on the lock, and describes the scan scope as applied. The branch is rebased onto main d2777ee (#619); round 3's registry commit was dropped first. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…d state the module-review limit Round 5 of PR #635, closing the three minor findings of the security recheck of round 4 and its nits: - tests/test_frozen_macos_variant_no_use.py: every file under a .claude, .codex or .agents directory, at any depth, is configuration (CONFIG_DIRECTORIES, beside .devcontainer), so agent, command and skill definitions, whose YAML frontmatter can declare hooks or tools the client runs, are read although they are Markdown; Markdown stays excluded only outside those directories. The 12 tracked Markdown files this brings into the scan name no artifact path, so no pin was added (56 lines in 18 files, as before). - The directory tests watch the whole artifact directory, not only variant/: nothing beyond run-summary.json, variant/package.json and variant/pnpm-lock.yaml (ARTIFACT_FILES) may be there, on disk or in Git, OS metadata excepted, a missing file or absent directory allowed (the exit path). Tracked paths are compared in any ASCII letter case, with a unit test that pins it. - The review-date test also fails when the exception entry has a key besides id, ignoreUntil and reason. - The docstring states that the guard is only as strong as review of the module itself (PINNED_LINES, REVIEW_DATE, ARTIFACT_FILES, the recognisers, the excluded classes or the module), that a symbolic link's path is read rather than its target, and that unreadable files (a submodule, a file missing from the work tree) are skipped. - Mutation checks in a scratch clone at 4af88b1: round 4's 33 rows keep their outcomes (M2, M3 and X8 name the renamed directory tests); N4-N6 (rebuild.sh beside variant/, tracked, on disk, and under an upper-cased directory name), N7 (a .claude/agents/x.md frontmatter hooks: entry running pnpm in the variant), N8 (an extra exception key) and X13 (.agents skill) fail now and pass against the round-4 module; X14 and X15 (scope regressions) fail; P3 (OS metadata beside variant/) and P4 (artifact removed) pass. - evidence/receipts/dependabot-alert-16-dismissal-20261003.json: guard lists exactly what CONFIG_NAMES, CONFIG_DIRECTORIES and the other recognisers cover; limitations state the module-review limit; evidence_class marks as relayed the quotation, the open-items context, the session's reading and the review history; review_date names the key check; guard_mutation_checks holds the 43 rows and the new module_sha256. - The closure record's alert-16 note: the module fails when the artifact directory gains a file, OS metadata excepted, or the exception gains a key; client definitions are read as configuration; and the guard is only as strong as review of the module itself. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
native-agent-stack-f9: the Codex reviewer's three P2 findings on
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7ce51c0a67
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
7ce51c0 to
06c90df
Compare
|
native-agent-stack-f9: the Codex reviewer's four findings on
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 06c90dfc19
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
06c90df to
9faa5c4
Compare
|
native-agent-stack-f9: the Codex reviewer's two P2 findings on Retain the source used by the historical control runs: fixed.
Reject indirect installs before keeping the alert dismissed: kept as a recorded decision, not a code change. The receipt's new The alternatives, with counts from
No workspace configuration is tracked at "Neither channel reports" holds only until the OSV exception lapses, and that date is fixed:
The decision is overturned if a tracked workspace configuration appears, or if a workflow or script that iterates the inventory or the package manifests runs a package manager. @codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9faa5c4e13
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
9faa5c4 to
47da9f8
Compare
|
native-agent-stack-f9: round 10 at
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 47da9f8da1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
47da9f8 to
d53cd63
Compare
|
native-agent-stack-f9: round 11 at @codex review |
|
Codex Review: Didn't find any major issues. Nice work! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
849f957 to
4917601
Compare
4917601 to
62394f4
Compare
62394f4 to
5339442
Compare
…S variant The closure record notes the dismissal of Dependabot alert 16 (GHSA-vcvr-r3jv-pc5j) as not_used on the frozen macOS variant's package.json, with its API readback receipt, evidence/receipts/dependabot-alert-16-dismissal-20261003.json. tests/test_frozen_macos_variant_no_use.py, a tripwire in the required validate job, fails when: - a scanned file names the frozen artifact directory beyond its pinned lines; - the directory gains a file; - the lock or its next pin changes; - the frozen OSV exception's date or keys change. The guard's mutation driver is kept under evidence/artifacts/frozen-variant-guard-mutations-20261003/. The anti-pattern log gains two 2026-10-03 rows. This commit replaces the branch's earlier content commits (review rounds 1-7), rebuilt on main 4ced292, so that no commit on the branch quotes a user message. Its tree equals round 7's first content commit 8f547913, apart from main's changes since 9b0b8d6. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ssembled name The mutation driver's returned results are kept under evidence/artifacts/frozen-variant-guard-mutations-20261003/: - round 8's final run: all 45 rows against the content commit a447a51, every row as expected; - round 7's three runs of the new rows against the round-3, round-4 and round-5 modules. Each gap row passes there, so each of these runs exits 1 by design. runs.json gives the argument vectors, times, exit codes, clone heads and hashes. Clone roots, the output directory and the Python prefix are replaced with placeholders. The receipt's table equals the retained output (45 rows, 0 mismatches) and binds the driver and runs.json by sha256. Its limitations now say: - the retained driver assembles the artifact name from fragments, a stated blind spot of the guard, and installs, builds or serves nothing; - configuration names inside an excluded class that differ only in letter case are not read. The closure note says "ASCII letter case", since the module folds ASCII letters only. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rd the indirect-route decision This commit answers the Codex review at 06c90df. Control runs: - The three earlier modules the control runs used are kept byte for byte, as .txt files, under evidence/artifacts/frozen-variant-guard-mutations-20261003/controls/. The guard does not read .txt files under evidence/**, and the receipt says so. - The control runs were re-run on main's d2777ee with each kept module committed in a scratch clone, so anyone can rebuild them from the repository. Their outcomes, failing tests and messages equal round 7's runs, which they replace. runs.json records each control's base commit and module file. Indirect routes: the receipt gains indirect_routes, a dated decision. The dismissal stands, and the indirect routes stay stated limits. The record names: - the alternatives declined: pinning the 43 lines that read the inventory, pinning the 297 package-manager lines, resolving each command's target, reopening the alert, and keeping the frozen manifest under names that tools don't parse; - the precedent; - the dated backstop of the OSV exception: it lapses on 2026-12-24, can be renewed at most 90 days ahead, and each renewal fails the review-date test. The closure note points to the decision. Round 8 review fixes: - runs.json defines <repo> without tying it to the final run's clone head. - runs.json describes the commits after the content commit accurately. - The receipt states X15's correction as a deduction from the module. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ecision and log the tripwire scope miss This commit answers the round-9 review and the Codex review at 9faa5c4. Backstop: once the frozen exception lapses, the required osv-scanner job fails in its unittest preflight (FrozenScanTests) before OSV-Scanner runs, and validate's full suite fails IgnorePolicyTests, both through ignore_entry_problems. A renewal that also edits REVIEW_DATE passes, and the receipt now says so. Precedent: the dismissal of alerts 7-15 that this record cites was superseded on 2026-09-25 by renaming the fixture (#224). The authorization, reasoning.precedent and indirect_routes now say so. Convergence decision: indirect_routes records the same day's convergence round. It ran Claude and GPT-6 research, two GPT-6 Astra and two Claude Opus votes, and took the GitHub/CI lane session's input. It chose to rename both frozen variant files to .frozen and stop scanning them in a follow-up pull request. The dismissal and the tripwire stand until then. The overturn and the closure note carry the new conditions. Other fixes: - The two counts now record their exact git grep commands. - The statement that the guard does not read the .txt control modules names the recogniser's conditions. - docs/harness-defaults.md gains a row for scoping a tripwire by expected file kinds, proven by controls N1, N4-N6, N7 and X13. - The branch is rebased onto main 59f8a1e (#653). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The Codex review at 47da9f8 found that the new row's rule said the guard reads JSON launch configurations inside the record classes. The guard deliberately leaves `evidence/**/launch.json` unread: it is stated limit L5, and its control passes. The rule now scans every file outside the record classes, reads each recognised runnable or configuring kind inside them, and names every kind left unread as a stated limit with a passing control. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…utation runs in manifests/evidence.json Hot-file protocol (docs/lanes.md): this is the branch's last commit, on main e0c329a (#677), and takes main's manifests/evidence.json. It re-registers the closure record, the receipt and docs/harness-defaults.md, and the 71 files under evidence/artifacts/frozen-variant-guard-mutations-20261003/. component_matrix --write and new_host_grand_list --write changed nothing else. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
5339442 to
69303cd
Compare
|
native-agent-stack-f9: merged at
Next: the follow-up PR from the 2026-10-03 convergence decision supersedes this dismissal. It renames the frozen variant files to |
Scope
package.json, with a retained API readback receipt.tests/test_frozen_macos_variant_no_use.py, which fails when anything in the repository starts to install, build or serve that frozen artifact, or when the matching OSV exception's review date changes.evidence/artifacts/frozen-variant-guard-mutations-20261003/..frozenand stop scanning them in a follow-up PR. That PR supersedes this dismissal; this PR keeps it as history.59f8a1e3(main after Track GPT runtime workers, SDKs, the gateway and pi in the daily catalog-freshness report #634, AGENTS.md: drop "(lands with unit F3)" now that the skill lifecycle guide is on main #636 and Raise the Linux validate job timeout from 40 to 60 minutes while the suite stays serial #653)lane:foundationdocs/decisions/2026-09-22-github-automation-closure.md(the alert-16 note)evidence/receipts/dependabot-alert-16-dismissal-20261003.json(new)tests/test_frozen_macos_variant_no_use.py(new)evidence/artifacts/frozen-variant-guard-mutations-20261003/(new: the driver, the runs and the control modules)docs/harness-defaults.md(two anti-pattern rows)manifests/evidence.json(registrations, in the last commit)SOTA sources
next>= 16.2.0, < 16.3.6, fixed in 16.3.6..github/osv-scanner-frozen-macos.toml(ignoreUntil = 2026-12-24) andevidence/receipts/osv-urllib3-next-20260930.json, plus the closure record's practice for files nothing installs.docs/acceptance-evidence-policy.md("Preserve the returned result", "Discriminating controls"), for keeping the mutation runs.Evidence-class table
not_usedat 2026-10-03T04:51:57Zreadback(GET at 06:58:43Z)next16.3.8source_reviewplus the tripwiretests/test_frozen_macos_variant_no_use.py(10 tests) at this head; the existing OSV reviewguard_mutation_checks, equal to the retained output (runs.json,final/). The discriminating controls run the round-3, round-4 and round-5 modules, kept byte for byte incontrols/, on main'sd2777ee7, so anyone can rebuild them (round*-module/).indirect_routes: the alternatives declined, the precedent, and the OSV exception's dated backstop (it lapses on 2026-12-24, renews at most 90 days ahead, and each renewal fails the review-date test)authorization; precedent: closure record alerts 7-15 (analogous, not identical)Local commands run
At
47da9f8d:The final mutation run: all 45 rows as expected against a clone of
a447a511, this branch's content commit. The control runs ond2777ee7reproduced round 7's outcomes exactly. The receipt-to-output row comparison found 0 mismatches.The full
python3 -m unittestran at round 7's head on this host: 25 failures in 20 methods. All of them also fail onorigin/mainhere, from the host's environment (unzip,dirname, systemd, a cross-device link, client auth storage). CI is the authority for that suite.Review history
6cd585e9: three P2 findings, each addressed.7ce51c0a: two P1 and two P2 findings, addressed in rounds 7 and 8.06c90dfc: two P2 findings. Round 9 keeps the controls' modules and makes the controls reproducible from main, and records the indirect-route decision in the receipt (see the reply on the PR).9faa5c4e: one P1 (log the proven scope miss), fixed in round 10.7ce51c0a, did; the squash merge keeps them off main.Decision record
The closure record's frozen macOS lock section: the alert-16 note, with the overturn and the recheck tied to the OSV exception's review date.
Host evidence
Not applicable.
Checklist
🤖 Generated with Claude Code