Skip to content

fix: close deep-audit safety gaps - #299

Merged
Wibias merged 49 commits into
mainfrom
agent/fix-deep-audit-findings
Aug 19, 2026
Merged

fix: close deep-audit safety gaps#299
Wibias merged 49 commits into
mainfrom
agent/fix-deep-audit-findings

Conversation

@Wibias

@Wibias Wibias commented Aug 19, 2026

Copy link
Copy Markdown
Owner

Summary

  • make Windows Authority CI and C# CodeQL unconditional on pull requests, while running the remaining Node 22 scope selector from the pull request base version
  • redeem trusted authority before autonomous coordination writes
  • make local branch review NUL-safe across rename/copy path generations, including logic, docs-only, and dependency classification
  • enforce canonical structured required-probe evidence in the pre-open gate
  • enforce open stack-parent ordering at the mutation execution boundary
  • pin orphan workflow cleanup to the default-branch generation and globally bound review-brief diff excerpts
  • update README, gate-helper documentation, and CHANGELOG

Audit findings closed

Finding Fix
GD-AUDIT-001 Security-critical Windows/C# lanes are unconditional; the remaining Node selector is base-controlled
GD-AUDIT-002 Grant redemption precedes the first mutating gh command, including autonomous idempotency coordination
GD-AUDIT-003 NUL-safe rename/copy parsing; both path generations drive review classification
GD-AUDIT-004 Pre-open validates the existing canonical structured probe evidence against deterministic trigger files
GD-AUDIT-005 The destructive mutation boundary rejects stack_parent_unlanded
GD-AUDIT-006 Orphan cleanup aborts before deletion if the default-branch generation moved
GD-AUDIT-007 Review briefs have a global hunk-line budget while deterministic scope remains complete

Validation

  • TDD RED: test-only commit 1ff722a5fe12bbc0a0efd4402ce22929ae0a6203 failed CI as expected
  • final head: 5aa393727b323b65b010c6f8f2685abc3d63ca37
  • npm run check: pass on Node 24 / ubuntu-latest
  • Node 26 compatibility: pass
  • Node 22 compatibility: pass
  • Windows Authority restore/build/self-test/XAML/publish/install smoke: pass
  • Dependency Review: pass
  • CodeQL JS/TS: pass
  • CodeQL C#: pass

Notes

  • README, gate-helper documentation, and CHANGELOG are updated for the new safety guarantees.
  • This PR does not merge itself.

@coderabbitai

coderabbitai Bot commented Aug 19, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 912cffb1-c71e-4592-8771-8563329a7bbd


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Wibias
Wibias marked this pull request as ready for review August 19, 2026 05:16
@Wibias
Wibias merged commit 645a60b into main Aug 19, 2026
9 checks passed
@Wibias
Wibias deleted the agent/fix-deep-audit-findings branch August 19, 2026 08:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant