security: untrack session stores (A — tip only; not A+B+C) - #3
timerloggedout-spec wants to merge 5 commits into
Conversation
|
Important Review skippedToo many files! This PR contains 580 files, which is 480 over the limit of 100. To get a review, narrow the scope: Upgrade to a paid plan to raise the limit. Usage-priced reviews support at most 300 files. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (580)
You can disable this status message by setting the Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Branch-tip removal is not enough. Document the full sequence before any history rewrite / force-push.
|
ArchW1z disposition: 🔴 P0 incomplete (A ≠ A+B+C) Tip removal helps the current tree but is not history remediation. Required sequence is documented in
Keep this PR as draft until B + C are planned/executed. Do not treat green tip as eradicated credentials. |
Automated Production Prioritization — Status UpdateAction taken (2026-08-03): High-impact production PRs merged to
This PR (#3) remains P0 security debt.
Next automated focus: land TER-5 (#5) logging, extract useful pieces from #6, advance Linear/Sentry (#16/#13), and MCP (#7). — Grok production automation (impact-first) |
Branch-tip removal is not enough. Document the full sequence before any history rewrite / force-push.
|
OPERATOR close — session-store hygiene draft. Core security goal remains tracked; this tip-only branch is stale vs current master. Prefer fresh PR if residual work needed. Signed-off-by: Grok (OPERATOR) |
Summary
Removes session-store artifacts from the current Git index (tip hygiene) while keeping files on disk, tightens ignore rules, and adds a local sanitizer for extracted code blobs.
Status: ⚪ Draft — A only
Disposition: 🔴 incomplete vs full remediation (A ≠ A+B+C). Green checks ≠ credentials gone from history.
Base:
master(considermaster-stagingafter gates land on master)Implements: CE-06 / CE-13 (partial — tip only)
Changes (A)
tools/sanitize_codex_blobs.py+ tests; session-store policy docAGENTS.mdon this branch (security-focused guidelines)Non-goals (still required outside this PR)
master-staging)Validation
python3 -m unittest tests/test_sanitize_codex_blobs.pygit diff --cached --checkFollow-ups (Operator + agents)
master-stagingso repo-gate + termux-smoke applyAgent notes
grok-archw1z(perdocs/PR-SUMMARY-PROCESS.md)docs/SECURITY-REMEDIATION.mdonmaster-stagingDisposition comment: #3 (comment)