Repository navigation
Retire the WSL retrieval lock as package-lock.json.frozen (Dependabot alert 17) - #688
Conversation
Rename blueprints/convergence-practice/wsl-retrieval/package-lock.json to package-lock.json.frozen with git mv; the bytes are unchanged (82,463 bytes, sha256 5c51ee65cc477f2c1488a38ff5cad1c0a737f81a5b61bbd70d5edc4d15bfc3bb). GitHub's dependency graph, Scorecard's OSV run and OSV-Scanner find lockfiles by name, so the lock leaves their discovery. This removes it from discovery; it does not patch braces 3.0.3 (GHSA-vfj7-8cjw-p6xm). audit.py resolves the receipts' historical name package-lock.json to the archive, as it already resolves package.json to package-original.json.txt, so no receipt is rewritten. audit_retirement now requires the lock to exist only as package-lock.json.frozen at its digest and tracked in Git, and no npm, Yarn, pnpm, Bun or Deno lockfile name anywhere in the partition, in any letter case, on disk or in the Git index; it fails closed without Git. LockDiscoveryGuardTests runs each requirement as a scenario on a scratch Git repository and proves eight code mutants of the guard are caught. experiment.json changes only the lock's path (same sha256) and the evaluation digests of audit.py and tests/test_wsl_retrieval.py, which the convergence validator binds. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ventory entries With the lock stored as package-lock.json.frozen, no scanner reads it, so the dedicated OSV-Scanner grant (.github/osv-scanner-frozen-wsl-retrieval.toml, expiring 2026-10-17) is deleted together with everything the closure record's removal list names: the inventory key, the FROZEN_LOCKS row, the scan invocation, the SARIF report, the upload step, the jq -e assignment and both non-empty guards. The ordinary and frozen macOS groups stay exhaustive and disjoint; the preflight still runs the partition's retirement tests. The partition's package.json declares no dependency, so it moves from covered_by_lockfile to a new dependency_free inventory class, which the coverage tests require to hold a package.json with no dependency, workspace, override or resolution field and no lockfile beside it, with a reason and an evidence path; DependencyFreeMutationTests runs that check on mutated copies. The macOS assignment line lost its trailing "and", so the macOS tripwire re-pins it, its copy in the coverage test and the edited dependabot.yml comment; the retained three-group copies keep the old digest. The macOS archive, its config and the tripwire's scope are otherwise unchanged. The receipt retains the OSV-Scanner 2.6.0 discovery controls (npm name exits 1 with GHSA-vfj7-8cjw-p6xm; .frozen name exits 128, no package sources), the guard's mutant results and the cited discovery sources. Fixed means removed from discovery, not patched. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Append a dated 2026-10-04 addendum to the 2026-09-25 decision that keeps frozen npm locks under non-manifest names, extending it to the retired WSL retrieval lock, and a dated note to the closure record after its retired WSL partition entry. Both state the evidence (OSV-Scanner 2.6.0 controls, the cited discovery sources, the 100% Git rename), why experiment.json moves the evaluation digests of audit.py and its test module beside the lock's path, that fixed means removed from discovery and not patched, and the stop condition if Dependabot alert 17 stays open. No existing line changes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ename Keeps every #681 change (permissions: {} and cache-mode: none at the top of security-scan.yml, the job-scoped grants and the workflow policy tests); this branch removes only the retired WSL scan group from that workflow. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The README's 2026-10-04 section and the receipt's purpose described the dedicated OSV-Scanner grant as already expired; on 2026-10-04 it was still in force until 2026-10-17, as the closure note, the addendum and the inventory reason say. Wording only. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Hot-file protocol, last commit, on main's copy after merging main: remove the entries of the deleted .github/osv-scanner-frozen-wsl-retrieval.toml and of the lock's old path; register the lock's new path (same sha256 and byte count), the receipt and its three artifacts, and the new hashes of the twelve changed files with host_receipts.register_file. component_matrix.py --write and new_host_grand_list.py --write left their reports unchanged. receipts[] and convergence_records are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Dependency limit exceeded — report not shown. This pull request scan exceeded the 10,000-dependency limit applied to this scan, so the results are incomplete and may be inaccurate. To avoid reporting false positives, Socket has not posted a report. Upgrade your plan to raise the dependency limit and get complete reports, or view the partial scan in the dashboard. Socket is always free for open source. If this is a non-commercial open source project, contact us to request a free Team account. |
|
Claude session native-agent-stack-5f: landing at head Observed main Required checks at this head: 8 pass . Unresolved review threads: 0. |
|
Claude session native-agent-stack-5f: post-merge observation. Landed as |
… three files Hot-file protocol, merge path (docs/lanes.md): main moved during the review round and its #688 edits docs/decisions/2026-09-22-github-automation-closure.md (30 lines at 465; this branch's sentence, now at 1653, merged cleanly) and .github/workflows/security-scan.yml. manifests/evidence.json is main's copy with tests/test_workflow_policy.py and the two decision records re-registered through host_receipts.register_file; component_matrix.py --write and new_host_grand_list.py --write changed nothing. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…1004
manifests/evidence.json conflicted (hot file): resolved by the docs/lanes.md merge path, taking
main's copy and re-registering this branch's five files with host_receipts.register_file:
.github/workflows/{adoption-bootstrap,catalog-freshness,validate}.yml and
tests/test_{shell_parser_ci,workflow_hardening}.py. tests/test_workflow_hardening.py merged
cleanly (#688's retired WSL OSV group, lines ~289-350, beside this branch's suite checks).
component_matrix.py and new_host_grand_list.py --write changed nothing; validate.py passes.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ot-file protocol) #683 (New-WSL Codex 0.160.0 profile pins, main-checkout trust grant, Opus 5.5) lands before this PR and edits the B1 record. manifests/evidence.json is main's copy (it auto-merged; main's copy was taken by checkout); the branch's rows are re-registered in the last commit. Conflict resolved in docs/decisions/2026-10-02-new-wsl-client-configuration.md (Decision 2's counts): main's wording (the trust grant as an authorization piece) with the counts measured on this merged tree by new_wsl_client_config.py --check --json: - measured on the merged tree: (386, 294, 200, 94, 79, 41, 38, 13) - main b629b5b alone: (385, 293, 200, 93, 79, 41, 38, 13) - approved on 2026-10-04: (386, 294, 200, 94, 80, 41, 39, 12) The one new row is still codex/stack-worker/mcp_servers.serena.required (slot:serena, wired); #683 moved one piece from not wired to authorization. The dated 2026-10-04 sentence (385, 293 and 93 before #674) still holds, and Decision 14's phrase (authorization 13, 79 not wired) does not move. tests/test_new_wsl_client_config.py merged cleanly; the module exits 0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Scope
blueprints/convergence-practice/wsl-retrieval/package-lock.json.frozen, so GitHub's dependency graph, Scorecard and OSV-Scanner no longer discover it, and deletes its dedicated OSV-Scanner grant (ignoreUntil2026-10-17) together with its scan group. This should clear Dependabot alert 17 and code-scanning alert 19 by removing the lock from discovery. Nothing is dismissed and nothing is patched: braces 3.0.3 stays in the archived bytes.f77a35eb2bf30bc4bf6f3b4ee51bc9ce5397b4c5. Main at6af8e55bd9e8f51aaafbf0304e510c11aaa71a6a(CI least privilege: permissions {} by default, cache-mode none on pull requests, workflow policy tripwire #681, CI least privilege, and Preserve PR561 lifecycle fixes and retire source-host evidence #679) is merged in atdd62b1169; every CI least privilege: permissions {} by default, cache-mode none on pull requests, workflow policy tripwire #681 change is kept, and the branch removes only the WSL scan group fromsecurity-scan.yml.lane:foundationblueprints/convergence-practice/wsl-retrieval/: thegit mvof the lock,audit.py,README.mdandexperiment.json..github/osv-scanner-lockfiles.json,.github/osv-scanner-frozen-wsl-retrieval.toml(deleted),.github/workflows/security-scan.ymland the.github/dependabot.ymlcomment.tests/test_wsl_retrieval.py,tests/test_osv_lockfile_coverage.py,tests/test_workflow_hardening.pyandtests/test_frozen_macos_variant_no_use.py(re-pins only).docs/decisions/2026-09-25-longmemeval-frozen-npm-lock.mdanddocs/decisions/2026-09-22-github-automation-closure.md.evidence/receipts/wsl-lock-frozen-rename-20261004.jsonandevidence/artifacts/wsl-lock-frozen-rename-20261004/.manifests/evidence.json, in the last commit under the hot-file protocol.SOTA sources
package-lock.json(recommended) andpackage.json; pnpmpnpm-lock.yaml; Yarnyarn.lock; Denodeno.lock,deno.jsonanddeno.jsonc. No.frozenform is listed.e840a6e8adb14b7777c78e26cfbf6e2abc1d1fc6),docs/supported_languages_and_lockfiles.md, fetched 2026-10-04T08:03:34Z (sha2569af241420144883305f3a1cbf3cf62bbf188fac5ff1dac9462ac97160c8e45bc).scan sourcereads JavaScript lockfiles namedbun.lock,package-lock.json,pnpm-lock.yamlandyarn.lock. The controls used the release assetosv-scanner_linux_amd64, verified against the workflow's pinned sha256ca69b3d3cd08f889a49dc0a383122f71cc528b83803671df5fd874d97485b108.ossf/scorecard-actionv2.4.4 (2d1146689b8cda280b9bc96326124645441f03bc, pinned inscorecard.yml) builds on:clients/osv.goL78-L93 (sha2562e494f81…). The Vulnerabilities check runsosvscanner.DoScanwithDirectoryPathsandRecursive: true, so it finds lockfiles by name, as above.fixed_atis "The time that the alert was no longer detected and was considered fixed".docs/decisions/2026-09-25-longmemeval-frozen-npm-lock.md, the.frozenconvention with the same discriminating OSV control. The closure record's 2026-10-03 removal list for this archive defines what is deleted here.Evidence-class table
native_proven(Git)git show -M --summary a71a7dc85printsrename …/{package-lock.json => package-lock.json.frozen} (100%); blobd37ec744before and after; sha2565c51ee65…, 82,463 bytes.frozennative_proven(pinned binary on scratch copies, sanitized output retained)evidence/artifacts/wsl-lock-frozen-rename-20261004/osv-controls.json: the npm name exits 1 with GHSA-vfj7-8cjw-p6xm (braces 3.0.3, no fix);.frozenexits 128 with "No package sources found"; the whole partition exits 1 before the rename and 128 after it (0 extract calls).frozennamessource_reviewnative_proven(one read-only API GET)alert_readback_before_merge, 2026-10-04T08:12:31Zlocal_integrationandsynthetic(fault injection)tests/test_wsl_retrieval.py::LockDiscoveryGuardTests;guard-mutants.json(M0 passes 11 scenarios; M1-M8 each fail their scenario; the N1 negative control survives)synthetic(recording doubles)SyntheticWorkflowInvocationTestsand its step mutantslocal_integrationscripts/validate.py,scripts/validate_convergence.pyLocal commands run
Run with
TMPDIRset to a task scratch directory andnice -n 19, on the merged head:Decision record
docs/decisions/2026-09-25-longmemeval-frozen-npm-lock.md, "Addendum (2026-10-04): the retired WSL retrieval lock": the evidence, the decision, what the rename does not do, and the overturn.docs/decisions/2026-09-22-github-automation-closure.md: a dated note after "Retired historical WSL retrieval partition".evidence/receipts/wsl-lock-frozen-rename-20261004.json.Choices the reviewer should check:
experiment.jsonchanges the lock's cited path, with the same sha256 because the bytes are identical. It also moves the evaluation digests ofaudit.pyandtests/test_wsl_retrieval.py:validate_convergence.pybinds them and this PR edits both, as Retire historical WSL retrieval replay and isolate its archive scan #622 did. No narrative field changes, and no receipt or the 2026-10-03retirement-assessment.jsonis rewritten;audit.pyresolves their historical namepackage-lock.jsonto the archive.package-lock.json,npm-shrinkwrap.json,yarn.lock,pnpm-lock.yaml) plusbun.lockanddeno.lock. Those two are a cited extension: OSV-Scanner v2.6.0 and GitHub's dependency graph read them by name.package.jsondeclares no dependency, so it moves to a newdependency_freeinventory class. The coverage tests require such an entry to be apackage.jsonwith no dependency, workspace, override or resolution field, with no lockfile beside it, and with a reason and an evidence path.DependencyFreeMutationTestsruns that check on mutated copies.security-scan.ymlpreflight still runstests.test_wsl_retrieval.RetiredRunnerTests, which now also runs the discovery guard.jq -eline lost a trailingand, sotests/test_frozen_macos_variant_no_use.pyre-pins that line, its copy in the coverage test and the editeddependabot.ymlcomment; the retained three-group copies underevidence/keep the old digest.validate.pyon their own (the registry is the last commit, under the hot-file protocol); the squash merge lands only the final tree.Post-merge read-back (coordinator)
fixedonce main's dependency graph no longer lists the lock, and alert 19 readsfixedafter the next Scorecard analysis of main.not_useddismissal, which needs the user's explicit authorization naming alert 17.Host evidence
Not applicable: this PR adds or changes nothing under
evidence/hosts/.Checklist
version comment (no floating tags). No action is added; one upload step is removed.
permissions: contents: read(or a narrower, explicitly justified addition).
security-scan.ymlkeeps CI least privilege: permissions {} by default, cache-mode none on pull requests, workflow policy tripwire #681's narrowerpermissions: {}and its job-scoped grants.added without a documented owner.
moved or overwritten).
🤖 Generated with Claude Code