Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
19 commits
Select commit Hold shift + click to select a range
96c258b
Add audited SDK settings ownership and read-only package freshness
unbraind Oct 4, 2026
ae4b064
Preserve local package sources and authenticate mandatory Codecov upl…
unbraind Oct 5, 2026
c3484cc
Record mandatory coverage TLS blocker and actual timer origin
unbraind Oct 5, 2026
6c81d8f
Route verified coverage uploads through the authenticated Codecov Clo…
unbraind Oct 5, 2026
3b6029a
Honor SDK offline manage controls and close the reviewed settings del…
unbraind Oct 5, 2026
3b8b761
Adopt eligible immutable CodeQL and TruffleHog scanner updates
unbraind Oct 5, 2026
2455869
Record exact-head scanner acceptance and generated delivery changelog
unbraind Oct 5, 2026
99408a3
Make managed npm reinstall identity precedence independent of record …
unbraind Oct 5, 2026
2346f0d
Reconcile delivered SDK records and route merge and guidance reports
unbraind Oct 5, 2026
c679815
Require complete protected checks before certifying PR readiness
unbraind Oct 5, 2026
4db3d83
Record final SDK delivery evidence and explicit-selector cost intake
unbraind Oct 5, 2026
56494d2
Preserve imported blocker identities and keep coverage upload logs pr…
unbraind Oct 5, 2026
15191eb
Fix portable blocker identity and complete SDK delivery verification
unbraind Oct 5, 2026
a5a5632
fix(cli): preserve help discovery for every declared option
unbraind Oct 5, 2026
a0447d0
Preserve blocker IO recovery and deterministic physical identity reads
unbraind Oct 5, 2026
ecbf3be
Validate managed npm reinstall registry identity
unbraind Oct 5, 2026
dd27df4
Record SDK delivery admission during GitHub runner outage
unbraind Oct 5, 2026
68bfe57
Preserve literal body assignments after attached CLI options
unbraind Oct 5, 2026
b31135d
Verify physical blocker filenames even when embedded IDs match
unbraind Oct 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
64 changes: 64 additions & 0 deletions .agents/pm/chores/pm-gh1404.toon
Original file line number Diff line number Diff line change
@@ -0,0 +1,64 @@
id: pm-gh1404
title: Adopt CodeQL 4.38.2 and TruffleHog 3.97.9 immutable scanner updates
description: Integrate newly arrived Dependabot PR 1404 into the existing SDK settings and freshness delivery PR 1402. Update three CodeQL subaction references in lockstep and the TruffleHog scanner pin after independently verifying official tags and more than seven full days of release age. Preserve mandatory scanner behavior and workflow contracts.
type: Chore
status: closed
priority: 2
tags[3]: "area:ci",dependencies,security
created_at: "2026-10-05T04:50:59.751Z"
updated_at: "2026-10-05T18:30:40.729Z"
closed_at: "2026-10-05T05:25:45.077Z"
completed_at: "2026-10-05T05:25:45.077Z"
author: "harness:codex"
estimated_minutes: 60
acceptance_criteria: Official tag SHAs and publication times are verified; three CodeQL subactions remain in lockstep; unchanged workflow contracts and static quality pass; new-head hosted security and exact full coverage pass; PR 1404 is linked to this canonical owner and closed as superseded only after the replacement lands
parent: pm-u9d0
risk: low
confidence: high
resolution: Adopted official immutable CodeQL 4.38.2 init/analyze/upload-sarif pins in lockstep and TruffleHog 3.97.9 after seven-day release-age and tag-object verification while retaining scan inputs and least-privilege permissions.
expected_result: All three CodeQL subactions use the same authenticated immutable upstream commit and TruffleHog uses its independently resolved commit; unchanged workflow tests and mandatory hosted scanners and exact source coverage pass.
actual_result: Exact combined head 3b8b76121534ab936bf185b4bd2d0e07fd5e12e0 completed all required hosted checks including updated CodeQL and TruffleHog. Full source suite passed 9766 cases in 775 files at 100/100/100/100. Actual Codecov LCOV 1174303 bytes and JUnit 474581 bytes each returned HTTP 200 with no errors or warnings. Fresh PR-ref CodeQL open-alert count is zero. Unchanged 16-case workflow contract and real linked execution passed; full local static quality passed. Greptile sixth review found no actionable issues; CodeRabbit sixth request and Sourcery are quota-unavailable rather than approvals. The watch transport TLS timeout is retained separately from the independently observed successful hosted checks. PR 1404 has its canonical link and acknowledged bot artifacts; it will close as superseded after replacement PR 1402 merges.
dependencies[3]{id,kind,created_at,author,source_kind,author_source}:
pm-2x67z9,discovered_from,"2026-10-05T04:50:59.751Z","harness:codex","cli:create:dep",detected
pm-mwdout,verifies,"2026-10-05T04:50:59.751Z","harness:codex","cli:create:dep",detected
pm-u9d0,implements,"2026-10-05T04:50:59.751Z","harness:codex","cli:create:dep",detected
comments[9]{created_at,author,text}:
"2026-10-05T04:50:59.751Z","harness:codex","Duplicate-check receipt: all-status live corpus read returned 2885 of 2885 items with zero omissions and no unreadable records; exact 4.38.2 and 3.97.9 and pull/1404 searches found no existing owner; open and in-progress lists checked before create. Closed historical action-refresh lineage was fully read and remains completed. Official CodeQL v4.38.2 published 2026-09-24T10:27:53Z and TruffleHog v3.97.9 published 2026-09-24T09:11:59Z; both exceed the unchanged seven-day adoption window. GitHub report: https://github.com/unbraind/pm-cli/pull/1404."
"2026-10-05T04:53:57.932Z","harness:codex",Official annotated CodeQL tag v4.38.2 dereferences to commit 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2; the TruffleHog v3.97.9 lightweight tag resolves to 4dd8831c5f12599465d4d45c3c447b4018a34c85. Fully read all three affected workflows before changing exactly four uses lines. All existing action inputs and least-privilege permissions are preserved. The unchanged workflow regression suite and complete static gate verify admission; no artificial pin-specific test or threshold change is added. PR 1404 will be superseded only after replacement PR 1402 lands.
"2026-10-05T05:25:42.454Z","harness:codex",Exact combined head 3b8b76121534ab936bf185b4bd2d0e07fd5e12e0 completed all required hosted checks including updated CodeQL and TruffleHog. Full source suite passed 9766 cases in 775 files at 100/100/100/100. Actual Codecov LCOV 1174303 bytes and JUnit 474581 bytes each returned HTTP 200 with no errors or warnings. Fresh PR-ref CodeQL open-alert count is zero. Unchanged 16-case workflow contract and real linked execution passed; full local static quality passed. Greptile sixth review found no actionable issues; CodeRabbit sixth request and Sourcery are quota-unavailable rather than approvals. The watch transport TLS timeout is retained separately from the independently observed successful hosted checks. PR 1404 has its canonical link and acknowledged bot artifacts; it will close as superseded after replacement PR 1402 merges.
"2026-10-05T07:56:52.765Z","harness:codex","Correction (2026-10-05): native gh pr checks --watch certifies emitted-check completion, not required-context completeness. Fresh protection/rollup comparison for 99408a3 and 2346f0d found required codecov/patch absent; 2346f0d is BLOCKED. Twenty-five of 26 protected contexts are present and passing. Actual hosted source coverage is 100/100/100/100 (9766 cases, 775 files) and both genuine LCOV/JUnit uploads succeed, but those uploads are distinct from the missing downstream patch status. The implementation remains verified; merge is prohibited until the real mandatory patch status appears and passes. Canonical pm-0fxa is actively correcting the watcher. No protection, threshold, TLS verification, paid usage or status spoofing is changed."
"2026-10-05T08:39:36.132Z","harness:codex","Provider recovery (2026-10-05T08:25:22Z): GitHub now has a genuine completed/success codecov/patch CheckRun at 2346f0d144a3651db4271b3de548d8b148127d08 from required app ID 254/codecov. A later real corrected-helper watch reports all 26 required contexts present, no omissions, passed and CLEAN. This supersedes the earlier missing-provider boundary for that old hosted head only. The new local watcher changes still require their own exact-head hosted coverage, mandatory gates and requested reviews before merge. No provider root cause or new-source approval is inferred."
"2026-10-05T09:55:12.941Z","harness:codex","2026-10-05 ownership correction: the distinct absent-required-check certification and direct-exit fix is now owned by pm-zpwfzy. The original review-helper foundation pm-0fxa retains its shipped July release and resolution, and all dated investigation receipts remain preserved. The new issue verifies this delivery through explicit typed linkage; all source, closure, generated changelog and exact new-head checks/review remain in PR 1402. Genuine Codecov recovery at ninth head 2346f0d is unchanged and cannot pre-certify the new head."
"2026-10-05T10:29:11.009Z","harness:codex","Exact source-head delivery evidence: c67981502631bfd6653ec23b8f49d397f393474d passed all 26 protected requirements with none missing and authoritative GitHub CLEAN through the corrected native-watch helper. CI 37294201471 passed the complete Gates (static) command and the full 9766-test/775-file suite with exact 100/100/100/100 and unchanged existing Windows-only skips; real LCOV/JUnit uploads each returned storage HTTP 200 with no upload-result errors/warnings. CodeRabbit completed the full 83-file source review with no actionable findings. Its split-PR suggestion conflicts with the explicit single-BIG-PR delivery requirement and is declined; this cohort includes its canonical scanner/upload/readiness owners. Greptile current review is unavailable after exhausting 100 free OSS credits; its prior source review is not substituted for fresh approval. DeepScan exact-head and CodeFactor PR reports show zero new issues. Fresh paginated Dependabot-security, secret-scanning and CodeQL inventories are empty. Required 14-day production Sentry/telemetry gate passes with zero critical/high, a real flush drains 1 to 0, and 20 recent actual command start/finish rows were inspected separately. This is source-head evidence; the final PM-only intake/evidence successor must pass its own hosted admission and review requests before merge. No gate or paid provider policy is changed."
"2026-10-05T16:38:50.523Z","harness:codex","Final local source after fresh Greptile P1 help review: all 9772 tests across775 passed files pass; exact 100/100/100/100 with zero uncovered: statements 66826/66826, branches 51156/51156, functions 13807/13807, lines 63687/63687. All1968 authored tracked digests stayed frozen over four fresh independently isolated coverage shards; no earlier shard blob is reused. Complete static quality, all four TypeScript configurations, canonical help and watcher linked suites, real newly packed npm/Node and Bun consumers outside checkout ancestors, and fresh nine-package npx/bunx smoke pass at unchanged limits. The real packed consumers additionally verify root --json --help and create/update -b and linked file/test/doc/alias/estimate help with unchanged item/history bytes and no new items. The isolated prior15191 source fails eight intended SDK/real CLI assertions; current118-case primary suite passes. The first new full-source attempt correctly failed the existing root JSON-help regression; the isolated pre-correction source fails five intended assertions. Preserving authoritative global boolean presentation flags fixes that regression, and the unchanged source-runPmCli case passes. Both failed attempts remain recorded separately from this fresh successful source verdict. Earlier15191 hosted26/CLEAN, native platform, real quiet upload and zero-new-analyzer receipts remain separate prior-head evidence. Its fresh GreptileCLI P1 was reproduced/fixed; a new pushed head must obtain fresh required checks and both requested provider replies. Current production required Sentry/telemetry gate also passes: critical/high/total0, measured finish error rate2.52% within unchanged6%, zero missing error-code rows; existing-consent flush drains1 to0 and20 actual recent start/finish rows are separately inspected. A separate fresh1h Sentry trace query returned0 rows; error health and telemetry reliability do not establish recent tracing. This is production telemetry evidence, not complete capture of all user actions or hosted approval. No paid quota, bypass, TLS change, exclusion, retry or gate relaxation."
"2026-10-05T18:30:40.729Z","harness:codex","Final local source includes accepted physical-blocker IO recovery from the a5a5632 CodeRabbit review: all 9772 tests across 775 passed files pass at exact 100/100/100/100 with zero uncovered counts: statements 66827/66827, branches 51158/51158, functions 13808/13808, lines 63688/63688. All 1968 authored tracked digests remain unchanged across four fresh independent coverage shards, with no prior blob reused after the source change. Complete static quality, all four TypeScript configurations, canonical blocker/control and watcher linked suites, newly packed separate npm/Node and Bun consumers outside checkout ancestors including real OS directory-listing denial through both public SDK and CLI, and fresh nine-package npx/bunx smoke pass at unchanged limits. The same primary SDK corruption fixture in an isolated external a5a5632 archive fails only the intended typed-directory-failure assertion (1 failure, 18 passes); current focused SDK/Beads/control suites pass51 tests, including all15 safe source controls and15 genuine negative mutants. The Node filesystem EACCES boundary does not implement SDK behavior; real temporary persistence proves original cause retention and unchanged item/history bytes. Exact physical leaves retain precedence, equal-priority candidates sort deterministically, and embedded-identity refusal remains unchanged. Native aliases intentionally share a destination while Linux retains colliding leaves. Previous a5 native and all emitted checks passed, but CodeFactor required context was absent and its service page was unavailable, so no merge occurred. The service later recovered and its real successful prior-head context was published; this does not certify the new IO source. Greptile CLI returned free_reviews_limit_reached, which is not new-head approval; paid usage and protections remain unchanged. Fresh immutable pushed-head native checks, required publisher-aware GitHub readiness and both requested review responses remain mandatory before merge. Production health/telemetry and recent tracing are separate evidence; the previous fresh1h trace query was empty and is not asserted as current tracing success."
files[3]{path,scope}:
.github/workflows/codeql.yml,project
.github/workflows/scorecard.yml,project
.github/workflows/security.yml,project
tests[1]{command,scope,provenance{author,created_at,source_kind,source_ref}}:
node scripts/run-tests.mjs test -- tests/integration/ci-workflow-contract.spec.ts,project,"harness:codex","2026-10-05T04:53:56.477Z",local_mutation,sdk/owned-settings-schema-history-extension-freshness
test_runs[1]:
- run_id: test-local-muuseg3l-citksz
kind: test
status: passed
started_at: "2026-10-05T05:05:57.708Z"
finished_at: "2026-10-05T05:06:08.769Z"
recorded_at: "2026-10-05T05:06:08.769Z"
passed: 1
failed: 0
skipped: 0
executions[1]{command,requested_pm_context_mode,pm_context_mode,workspace_context_mode,trust_reason}:
node scripts/run-tests.mjs test -- tests/integration/ci-workflow-contract.spec.ts,schema,schema,source,local_source_ref
docs[1]{path,scope}:
CHANGELOG.md,project
close_reason: Immutable scanner updates are implemented and verified at the exact combined hosted source head
escape_class: review_caught_late
gate_evidence:
disposition: gate_strengthened
gate_id: ci-immutable-security-scanners
negative_control: "node scripts/run-tests.mjs test -- tests/integration/ci-workflow-contract.spec.ts -t \"rejects mutable and incomplete Codecov references in either upload\""
local_checks[2]: node scripts/run-tests.mjs test -- tests/integration/ci-workflow-contract.spec.ts,"pnpm quality:static"
hosted_checks[4]: Analyze (javascript-typescript),Trivy,Gates (coverage),Gates (static)
owner: maintainer
body: ""
Loading
Loading