security: freeze legacy install and release before DEN-3944 migration - #2
Draft
ORESoftware wants to merge 6 commits into
Draft
security: freeze legacy install and release before DEN-3944 migration#2ORESoftware wants to merge 6 commits into
ORESoftware wants to merge 6 commits into
Conversation
Owner
Author
Validation status — 2026-09-03No pull-request workflow run is observable for head The reviewed source change removes the npm |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Issue #1 correctly identified that the current package can still publish and invokes
assets/postinstall.sh, which writes into$HOME/.oresoftwareduring installation. The legacy shell dispatcher also has no repository-local governance or machine-readable command contract.Change
privateand add a fail-closedprepublishOnlyblocker;postinstallpackage hook so npm installation no longer invokes the home-directory write;AGENTS.mdtied to the ORESoftware/my-ai policy;.cli-flags.tomlwith unknown options rejected and dry-run as the future default;Validation state
The JSON and TOML changes were reviewed structurally against current repository content and the active flags-2-env command-manifest format. No package installation, legacy command, remote Git operation, publication, or hosted CI run was executed through this connector. Keep this pull request draft until exact-head checks and consumer-impact review are attached.
Remaining before #1 can close
This PR intentionally does not replace the shell dispatcher, wire flags-2-env into runtime parsing, add
.zpkg.toml, publish a release, archive the repository, or claim consumer compatibility. Those require the issue's inventory, implementation, packaging, and release/retirement gates.Rollback
Reverting this branch restores the prior package metadata, but release/install side effects should not be re-enabled without the explicit owner review described in the migration decision.
Refs #1 and Linear
DEN-3944. No chat-supplied credential was used or copied, and no token was revoked or modified.