Skip to content

Retire the WSL retrieval lock as package-lock.json.frozen (Dependabot alert 17) - #688

Merged
seathatflowsinourveins merged 6 commits into
mainfrom
foundation/retire-wsl-lock-frozen-20261004
Oct 4, 2026
Merged

seathatflowsinourveins merged 6 commits into
mainfrom
foundation/retire-wsl-lock-frozen-20261004

Conversation

@seathatflowsinourveins

Copy link
Copy Markdown
Owner

Scope

  • What this PR changes, in one or two sentences: stores the retired WSL retrieval lock byte-identical as blueprints/convergence-practice/wsl-retrieval/package-lock.json.frozen, so GitHub's dependency graph, Scorecard and OSV-Scanner no longer discover it, and deletes its dedicated OSV-Scanner grant (ignoreUntil 2026-10-17) together with its scan group. This should clear Dependabot alert 17 and code-scanning alert 19 by removing the lock from discovery. Nothing is dismissed and nothing is patched: braces 3.0.3 stays in the archived bytes.
  • Base commit: f77a35eb2bf30bc4bf6f3b4ee51bc9ce5397b4c5. Main at 6af8e55bd9e8f51aaafbf0304e510c11aaa71a6a (CI least privilege: permissions {} by default, cache-mode none on pull requests, workflow policy tripwire #681, CI least privilege, and Preserve PR561 lifecycle fixes and retire source-host evidence #679) is merged in at dd62b1169; every CI least privilege: permissions {} by default, cache-mode none on pull requests, workflow policy tripwire #681 change is kept, and the branch removes only the WSL scan group from security-scan.yml.
  • Lane: lane:foundation
  • Owned paths touched:
    • blueprints/convergence-practice/wsl-retrieval/: the git mv of the lock, audit.py, README.md and experiment.json.
    • .github/osv-scanner-lockfiles.json, .github/osv-scanner-frozen-wsl-retrieval.toml (deleted), .github/workflows/security-scan.yml and the .github/dependabot.yml comment.
    • tests/test_wsl_retrieval.py, tests/test_osv_lockfile_coverage.py, tests/test_workflow_hardening.py and tests/test_frozen_macos_variant_no_use.py (re-pins only).
    • Dated append-only notes in docs/decisions/2026-09-25-longmemeval-frozen-npm-lock.md and docs/decisions/2026-09-22-github-automation-closure.md.
    • evidence/receipts/wsl-lock-frozen-rename-20261004.json and evidence/artifacts/wsl-lock-frozen-rename-20261004/.
    • manifests/evidence.json, in the last commit under the hot-file protocol.

SOTA sources

  • GitHub Docs, Dependency graph supported package ecosystems, fetched 2026-10-04T08:03:25Z. Manifests are recognized by fixed names: npm package-lock.json (recommended) and package.json; pnpm pnpm-lock.yaml; Yarn yarn.lock; Deno deno.lock, deno.json and deno.jsonc. No .frozen form is listed.
  • OSV-Scanner v2.6.0 (commit e840a6e8adb14b7777c78e26cfbf6e2abc1d1fc6), docs/supported_languages_and_lockfiles.md, fetched 2026-10-04T08:03:34Z (sha256 9af241420144883305f3a1cbf3cf62bbf188fac5ff1dac9462ac97160c8e45bc). scan source reads JavaScript lockfiles named bun.lock, package-lock.json, pnpm-lock.yaml and yarn.lock. The controls used the release asset osv-scanner_linux_amd64, verified against the workflow's pinned sha256 ca69b3d3cd08f889a49dc0a383122f71cc528b83803671df5fd874d97485b108.
  • OpenSSF Scorecard v5.5.0, the version that ossf/scorecard-action v2.4.4 (2d1146689b8cda280b9bc96326124645441f03bc, pinned in scorecard.yml) builds on: clients/osv.go L78-L93 (sha256 2e494f81…). The Vulnerabilities check runs osvscanner.DoScan with DirectoryPaths and Recursive: true, so it finds lockfiles by name, as above.
  • GitHub REST API docs, Dependabot alerts, fetched 2026-10-04T08:11:52Z. fixed_at is "The time that the alert was no longer detected and was considered fixed".
  • Repository precedent: docs/decisions/2026-09-25-longmemeval-frozen-npm-lock.md, the .frozen convention with the same discriminating OSV control. The closure record's 2026-10-03 removal list for this archive defines what is deleted here.

Evidence-class table

Claim Evidence class Command / receipt
The lock's bytes are unchanged native_proven (Git) git show -M --summary a71a7dc85 prints rename …/{package-lock.json => package-lock.json.frozen} (100%); blob d37ec744 before and after; sha256 5c51ee65…, 82,463 bytes
OSV-Scanner finds the lock under its npm name and not as .frozen native_proven (pinned binary on scratch copies, sanitized output retained) evidence/artifacts/wsl-lock-frozen-rename-20261004/osv-controls.json: the npm name exits 1 with GHSA-vfj7-8cjw-p6xm (braces 3.0.3, no fix); .frozen exits 128 with "No package sources found"; the whole partition exits 1 before the rename and 128 after it (0 extract calls)
GitHub's dependency graph and Scorecard do not read .frozen names source_review the docs and source above; not observed on a live pull request
Alert 17 was open before this change native_proven (one read-only API GET) receipt alert_readback_before_merge, 2026-10-04T08:12:31Z
Alerts 17 and 19 read fixed after merge not yet observed the coordinator's post-merge read-back, below
The guard rejects a restored lock name, a changed digest, an untracked archive and a missing Git index, and catches 8 code mutants local_integration and synthetic (fault injection) tests/test_wsl_retrieval.py::LockDiscoveryGuardTests; guard-mutants.json (M0 passes 11 scenarios; M1-M8 each fail their scenario; the N1 negative control survives)
The workflow routes two groups and keeps every status synthetic (recording doubles) SyntheticWorkflowInvocationTests and its step mutants
The registry and convergence records are consistent local_integration scripts/validate.py, scripts/validate_convergence.py

Local commands run

Run with TMPDIR set to a task scratch directory and nice -n 19, on the merged head:

$ python3 blueprints/convergence-practice/wsl-retrieval/audit.py
exit 0; current_retirement_assessment.retained_lock = {archive: package-lock.json.frozen, scanner_discovered: false, dependency_patched: false}
$ python3 -m unittest tests.test_osv_lockfile_coverage tests.test_workflow_hardening tests.test_wsl_retrieval tests.test_frozen_macos_variant_no_use tests.test_pre_push_gate tests.test_workflow_policy tests.test_workflow_security_coverage
Ran 274 tests, OK (skipped=3: two need PyYAML, one has no hash-frozen workflow); the two PyYAML tests pass under `uv run --no-project --with pyyaml`
$ python3 -m unittest   (on a3841cc6; the final head adds only a two-line wording fix and its re-registration)
exit 1: Ran 10301 tests in 2292 s, failures=1, skipped=873. The one failure is not caused by this PR:
tests.test_windows_terminal_defaults.OverlayTests.test_the_installed_client_knows_no_notification_type_without_a_decision
scans this host's installed Claude Code binary, which knows the notification type auth_storage_failure that the test's
DECISIONS table lacks. The test skips where no client is installed (as on CI runners), and this PR touches none of its inputs.
$ python3 scripts/validate_convergence.py blueprints/convergence-practice/wsl-retrieval/experiment.json --root . --json
exit 0, valid (and --all-recorded: 30 records valid)
$ python3 scripts/validate.py
exit 0, passed (9881 hashed files, 195 receipts)
$ python3 scripts/evidence_manifest.py --check
exit 0
$ osv-scanner 2.6.0 scan source --config .github/osv-scanner.toml --no-resolve -r <copy with package-lock.json>
exit 1, GHSA-vfj7-8cjw-p6xm on braces 3.0.3
$ osv-scanner 2.6.0 scan source --config .github/osv-scanner.toml --no-resolve -r <copy with package-lock.json.frozen>
exit 128, "No package sources found"
$ zizmor 1.30.1 --offline --no-config --no-ignores --persona regular .github/workflows/security-scan.yml
exit 0, no findings (4 suppressed, the same as at the base)
$ git diff --check origin/main...HEAD
exit 0
$ merge-tree landing check <main> <head>
exit 0, LANDABLE (clean merge; no path outside this PR; main drift 0; registry rows foreign to this PR equal main's)

Decision record

Choices the reviewer should check:

  • experiment.json changes the lock's cited path, with the same sha256 because the bytes are identical. It also moves the evaluation digests of audit.py and tests/test_wsl_retrieval.py: validate_convergence.py binds them and this PR edits both, as Retire historical WSL retrieval replay and isolate its archive scan #622 did. No narrative field changes, and no receipt or the 2026-10-03 retirement-assessment.json is rewritten; audit.py resolves their historical name package-lock.json to the archive.
  • The guard's lockfile names are the four the task requires (package-lock.json, npm-shrinkwrap.json, yarn.lock, pnpm-lock.yaml) plus bun.lock and deno.lock. Those two are a cited extension: OSV-Scanner v2.6.0 and GitHub's dependency graph read them by name.
  • The partition's package.json declares no dependency, so it moves to a new dependency_free inventory class. The coverage tests require such an entry to be a package.json with no dependency, workspace, override or resolution field, with no lockfile beside it, and with a reason and an evidence path. DependencyFreeMutationTests runs that check on mutated copies.
  • The security-scan.yml preflight still runs tests.test_wsl_retrieval.RetiredRunnerTests, which now also runs the discovery guard.
  • The macOS variant (alert 16's artifact) is untouched. With the WSL clause gone its jq -e line lost a trailing and, so tests/test_frozen_macos_variant_no_use.py re-pins that line, its copy in the coverage test and the edited dependabot.yml comment; the retained three-group copies under evidence/ keep the old digest.
  • Intermediate commits do not pass validate.py on their own (the registry is the last commit, under the hot-file protocol); the squash merge lands only the final tree.

Post-merge read-back (coordinator)

gh api repos/{owner}/{repo}/dependabot/alerts/17 --jq '{state, fixed_at, dismissed_reason}'
gh api repos/{owner}/{repo}/code-scanning/alerts/19 --jq '{state, fixed_at}'
  • Expected: alert 17 reads fixed once main's dependency graph no longer lists the lock, and alert 19 reads fixed after the next Scorecard analysis of main.
  • "Fixed" here means removed from discovery, not patched.
  • If alert 17 is still open after the merge, stop and bring option (a) to the user: a not_used dismissal, which needs the user's explicit authorization naming alert 17.
  • Alert 19 is never dismissed.

Host evidence

Not applicable: this PR adds or changes nothing under evidence/hosts/.

Checklist

  • New/changed GitHub Actions are pinned to a full commit SHA with a
    version comment (no floating tags). No action is added; one upload step is removed.
  • New/changed workflows declare top-level permissions: contents: read
    (or a narrower, explicitly justified addition). security-scan.yml keeps CI least privilege: permissions {} by default, cache-mode none on pull requests, workflow policy tripwire #681's narrower permissions: {} and its job-scoped grants.
  • No secrets are printed, logged or committed; no new required secret was
    added without a documented owner.
  • No new paid hosting, subscription or billing surface was introduced.
  • Peer-owned untracked files and worktrees were preserved (not deleted,
    moved or overwritten).

🤖 Generated with Claude Code

Scout and others added 6 commits October 4, 2026 04:18
Rename blueprints/convergence-practice/wsl-retrieval/package-lock.json to
package-lock.json.frozen with git mv; the bytes are unchanged (82,463 bytes,
sha256 5c51ee65cc477f2c1488a38ff5cad1c0a737f81a5b61bbd70d5edc4d15bfc3bb).
GitHub's dependency graph, Scorecard's OSV run and OSV-Scanner find lockfiles
by name, so the lock leaves their discovery. This removes it from discovery;
it does not patch braces 3.0.3 (GHSA-vfj7-8cjw-p6xm).

audit.py resolves the receipts' historical name package-lock.json to the
archive, as it already resolves package.json to package-original.json.txt,
so no receipt is rewritten. audit_retirement now requires the lock to exist
only as package-lock.json.frozen at its digest and tracked in Git, and no
npm, Yarn, pnpm, Bun or Deno lockfile name anywhere in the partition, in any
letter case, on disk or in the Git index; it fails closed without Git.
LockDiscoveryGuardTests runs each requirement as a scenario on a scratch Git
repository and proves eight code mutants of the guard are caught.

experiment.json changes only the lock's path (same sha256) and the
evaluation digests of audit.py and tests/test_wsl_retrieval.py, which the
convergence validator binds.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ventory entries

With the lock stored as package-lock.json.frozen, no scanner reads it, so
the dedicated OSV-Scanner grant (.github/osv-scanner-frozen-wsl-retrieval.toml,
expiring 2026-10-17) is deleted together with everything the closure record's
removal list names: the inventory key, the FROZEN_LOCKS row, the scan
invocation, the SARIF report, the upload step, the jq -e assignment and both
non-empty guards. The ordinary and frozen macOS groups stay exhaustive and
disjoint; the preflight still runs the partition's retirement tests.

The partition's package.json declares no dependency, so it moves from
covered_by_lockfile to a new dependency_free inventory class, which the
coverage tests require to hold a package.json with no dependency, workspace,
override or resolution field and no lockfile beside it, with a reason and an
evidence path; DependencyFreeMutationTests runs that check on mutated copies.

The macOS assignment line lost its trailing "and", so the macOS tripwire
re-pins it, its copy in the coverage test and the edited dependabot.yml
comment; the retained three-group copies keep the old digest. The macOS
archive, its config and the tripwire's scope are otherwise unchanged.

The receipt retains the OSV-Scanner 2.6.0 discovery controls (npm name exits
1 with GHSA-vfj7-8cjw-p6xm; .frozen name exits 128, no package sources), the
guard's mutant results and the cited discovery sources. Fixed means removed
from discovery, not patched.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Append a dated 2026-10-04 addendum to the 2026-09-25 decision that keeps
frozen npm locks under non-manifest names, extending it to the retired WSL
retrieval lock, and a dated note to the closure record after its retired WSL
partition entry. Both state the evidence (OSV-Scanner 2.6.0 controls, the
cited discovery sources, the 100% Git rename), why experiment.json moves the
evaluation digests of audit.py and its test module beside the lock's path,
that fixed means removed from discovery and not patched, and the stop
condition if Dependabot alert 17 stays open. No existing line changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ename

Keeps every #681 change (permissions: {} and cache-mode: none at the top of
security-scan.yml, the job-scoped grants and the workflow policy tests); this
branch removes only the retired WSL scan group from that workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The README's 2026-10-04 section and the receipt's purpose described the
dedicated OSV-Scanner grant as already expired; on 2026-10-04 it was still
in force until 2026-10-17, as the closure note, the addendum and the
inventory reason say. Wording only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Hot-file protocol, last commit, on main's copy after merging main: remove
the entries of the deleted .github/osv-scanner-frozen-wsl-retrieval.toml and
of the lock's old path; register the lock's new path (same sha256 and byte
count), the receipt and its three artifacts, and the new hashes of the twelve
changed files with host_receipts.register_file. component_matrix.py --write
and new_host_grand_list.py --write left their reports unchanged.
receipts[] and convergence_records are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Oct 4, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-04T10:53:42.930341Z ca450f8 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@socket-security

Copy link
Copy Markdown

Dependency limit exceeded — report not shown.

This pull request scan exceeded the 10,000-dependency limit applied to this scan, so the results are incomplete and may be inaccurate. To avoid reporting false positives, Socket has not posted a report.

Upgrade your plan to raise the dependency limit and get complete reports, or view the partial scan in the dashboard.

Socket is always free for open source. If this is a non-commercial open source project, contact us to request a free Team account.

@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Claude session native-agent-stack-5f: landing at head ca450f8bc65277707970c85280373caba1244b61. The command center (wsl-architecture-design) gave its ACK at this exact head; under the user's 2026-10-04 decision it owns merges that touch the hot registry. The read-only cross-family review (GPT-6.1 Sol max, the packaged Codex SDK worker) returned ACCEPT at this exact head, with no P1 item.

Observed main 6af8e55bd9e8f51aaafbf0304e510c11aaa71a6a. coordination/merge_tree_landing_check.py (sha256 a11649fcf2e5844c…) exit 0:

main 6af8e55bd9e8f51aaafbf0304e510c11aaa71a6a head ca450f8bc65277707970c85280373caba1244b61 base 6af8e55bd9e8f51aaafbf0304e510c11aaa71a6a merged-tree 03f1cd80dc8b112e2972b32b0f1bd6832d0db80c merge-tree-exit 0
ok   1: clean three-way merge
ok   2: merged-vs-main paths 20, outside PR-owned 0 []
ok   3: main drift 0 paths, overlap with PR-owned inputs (registry excluded) []
ok   4: registry foreign rows equal True, order preserved True, PR-owned rows 19, unowned top-level keys differing []
ok   5: merged files[] sorted by path with no duplicates: True (9881 rows)
LANDABLE
condition 5: merged files[] sorted and unique (tree 03f1cd80dc8b112e2972b32b0f1bd6832d0db80c)

Required checks at this head: 8 pass . Unresolved review threads: 0.

@seathatflowsinourveins
seathatflowsinourveins merged commit 15cb148 into main Oct 4, 2026
25 checks passed
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Claude session native-agent-stack-5f: post-merge observation. Landed as 15cb14841938493906509e4cd66cf23eb0a9808e (parent 6af8e55bd9e8f51aaafbf0304e510c11aaa71a6a), tree 03f1cd80dc8b112e2972b32b0f1bd6832d0db80c. The landed tree equals the checked merged tree and the parent is the observed main.

@seathatflowsinourveins
seathatflowsinourveins deleted the foundation/retire-wsl-lock-frozen-20261004 branch October 4, 2026 14:15
seathatflowsinourveins pushed a commit that referenced this pull request Oct 4, 2026
… three files

Hot-file protocol, merge path (docs/lanes.md): main moved during the review round and its #688 edits
docs/decisions/2026-09-22-github-automation-closure.md (30 lines at 465; this branch's sentence, now at 1653, merged
cleanly) and .github/workflows/security-scan.yml. manifests/evidence.json is main's copy with
tests/test_workflow_policy.py and the two decision records re-registered through host_receipts.register_file;
component_matrix.py --write and new_host_grand_list.py --write changed nothing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Oct 4, 2026
…1004

manifests/evidence.json conflicted (hot file): resolved by the docs/lanes.md merge path, taking
main's copy and re-registering this branch's five files with host_receipts.register_file:
.github/workflows/{adoption-bootstrap,catalog-freshness,validate}.yml and
tests/test_{shell_parser_ci,workflow_hardening}.py. tests/test_workflow_hardening.py merged
cleanly (#688's retired WSL OSV group, lines ~289-350, beside this branch's suite checks).
component_matrix.py and new_host_grand_list.py --write changed nothing; validate.py passes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Oct 4, 2026
…ot-file protocol)

#683 (New-WSL Codex 0.160.0 profile pins, main-checkout trust grant, Opus 5.5)
lands before this PR and edits the B1 record. manifests/evidence.json is
main's copy (it auto-merged; main's copy was taken by checkout); the
branch's rows are re-registered in the last commit.

Conflict resolved in docs/decisions/2026-10-02-new-wsl-client-configuration.md
(Decision 2's counts): main's wording (the trust grant as an authorization
piece) with the counts measured on this merged tree by
new_wsl_client_config.py --check --json:
- measured on the merged tree: (386, 294, 200, 94, 79, 41, 38, 13)
- main b629b5b alone:        (385, 293, 200, 93, 79, 41, 38, 13)
- approved on 2026-10-04:      (386, 294, 200, 94, 80, 41, 39, 12)
The one new row is still codex/stack-worker/mcp_servers.serena.required
(slot:serena, wired); #683 moved one piece from not wired to authorization.
The dated 2026-10-04 sentence (385, 293 and 93 before #674) still holds, and
Decision 14's phrase (authorization 13, 79 not wired) does not move.
tests/test_new_wsl_client_config.py merged cleanly; the module exits 0.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant