Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
63 commits
Select commit Hold shift + click to select a range
909566b
Refresh macOS app polish and release readiness
s1korrrr Jun 29, 2026
f5d5a67
Fix constrained preview layout after audit
s1korrrr Jun 29, 2026
a594a71
Ignore local worktree directory
s1korrrr Jul 13, 2026
7062319
Ignore subagent progress artifacts
s1korrrr Jul 13, 2026
7f63fac
Add validated preferences and layout policy
s1korrrr Jul 13, 2026
61fdbe8
Report skipped files during workspace scans
s1korrrr Jul 13, 2026
526db65
Move scan and selection state into a workspace store
s1korrrr Jul 13, 2026
62b6f0c
Keep workspace state coherent across root changes
s1korrrr Jul 13, 2026
c8ae5e9
Add privacy-conscious output recovery state
s1korrrr Jul 13, 2026
2da5740
Order output persistence across async operations
s1korrrr Jul 13, 2026
2c1ef29
Separate output build and recovery generations
s1korrrr Jul 13, 2026
b7e1bc5
Unify app actions commands and settings
s1korrrr Jul 13, 2026
67d612b
Harden app command readiness and refresh state
s1korrrr Jul 13, 2026
74fb62b
Centralize recovered copy and filter refresh
s1korrrr Jul 13, 2026
84be30d
Rebuild the macOS workspace with adaptive native panes
s1korrrr Jul 13, 2026
f484cf3
Fix adaptive inspector and recovery interactions
s1korrrr Jul 13, 2026
9cf66dc
Stop tracking local Task 6 evidence
s1korrrr Jul 14, 2026
701cf4f
Add isolated end-to-end verification for the Mac app
s1korrrr Jul 14, 2026
18bb4b2
Harden sandboxed end-to-end verification
s1korrrr Jul 14, 2026
04c3862
Document bounded sandbox performance audit
s1korrrr Jul 14, 2026
3052370
Clean scoped E2E export artifacts
s1korrrr Jul 14, 2026
8cc665f
Document adaptive Mac app readiness
s1korrrr Jul 14, 2026
7e33e6f
Close holistic macOS review findings
s1korrrr Jul 14, 2026
d9788e2
Invalidate stale scans before validation
s1korrrr Jul 14, 2026
ffc73e7
Pin SwiftFormat and reconcile CI formatting
s1korrrr Jul 14, 2026
df677dc
Merge pull request #3 from s1korrrr/feat/andrzej_agent_sota_lab
s1korrrr Jul 14, 2026
f03861b
Harden dependencies and release CI
s1korrrr Jul 15, 2026
47c4ce7
Harden App Store packaging validation
s1korrrr Jul 15, 2026
885caea
Bound local processing and add privacy surfaces
s1korrrr Jul 15, 2026
90f0562
Document blocked 0.1.0 release candidate
s1korrrr Jul 15, 2026
722712a
Close traversal and recovery review gaps
s1korrrr Jul 15, 2026
206e4f8
Remove ripgrep dependency from package contract
s1korrrr Jul 15, 2026
43ccbea
Make shell contracts runner-portable
s1korrrr Jul 15, 2026
ae152e6
Record final PR and CI release gates
s1korrrr Jul 15, 2026
8c317f5
feat(release): add Developer ID notarized distribution lane
s1korrrr Jul 15, 2026
d8253db
docs(release): record signing-key authorization gate
s1korrrr Jul 15, 2026
3c92569
docs(release): record GitHub protection gates
s1korrrr Jul 15, 2026
42a3e1f
docs(release): prohibit Developer ID key export
s1korrrr Jul 16, 2026
f359855
fix(extension): harden workspace combination
s1korrrr Jul 16, 2026
c9f0c1d
fix(macOS): secure file reads and output state
s1korrrr Jul 16, 2026
73bcaa2
fix(release): bind credentials source and artifacts
s1korrrr Jul 16, 2026
787d40a
docs(audit): record end-to-end release evidence
s1korrrr Jul 16, 2026
69884ad
Merge pull request #5 from s1korrrr/feat/andrzej_open_source_release
s1korrrr Jul 16, 2026
bc7b8d5
ci: update actions to Node 24 runtimes
s1korrrr Jul 16, 2026
563b493
Merge pull request #16 from s1korrrr/feat/andrzej_actions_v4
s1korrrr Jul 16, 2026
71cda59
Clean release artifacts and harden packaging
s1korrrr Jul 16, 2026
16b4364
Honor Minimatch globstar syntax
s1korrrr Jul 16, 2026
4218ccf
Merge pull request #18 from s1korrrr/feat/andrzej_release_cleanup
s1korrrr Jul 16, 2026
1eb12e9
fix: harden filesystem collection boundaries
s1korrrr Jul 17, 2026
795b24c
fix: isolate release and e2e evidence
s1korrrr Jul 17, 2026
9f4ecc1
docs: record the verified full audit
s1korrrr Jul 17, 2026
fee36b4
fix: preserve notarization resume identity
s1korrrr Jul 17, 2026
aa73b96
Merge pull request #19 from s1korrrr/feat/andrzej_full_audit_20260717
s1korrrr Jul 17, 2026
c66304d
chore: prepare trusted macOS 0.1.0 release
s1korrrr Jul 18, 2026
7e75deb
Prepare trusted macOS 0.1.0 release (#20)
s1korrrr Jul 18, 2026
9c38678
chore: harden open-source release readiness
s1korrrr Jul 20, 2026
bb6ba7b
chore: align repository links with RSI Tech
s1korrrr Jul 20, 2026
567d520
docs: preserve identity boundaries after transfer
s1korrrr Jul 20, 2026
d1f1c73
docs: record canonical repository homepage
s1korrrr Jul 20, 2026
fdc05fb
Adopt RSI Tech Apache release identity
s1korrrr Jul 20, 2026
b17992a
Close release identity review gaps
s1korrrr Jul 20, 2026
12593e8
Merge pull request #25 from rsitech-ai/feat/andrzej_rsitech_org_release
s1korrrr Jul 20, 2026
4bbbe41
Bump minimatch from 9.0.9 to 10.2.5
dependabot[bot] Jul 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 0 additions & 13 deletions .eslintrc.cjs

This file was deleted.

8 changes: 4 additions & 4 deletions .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ body:
attributes:
value: |
Thanks for taking the time to report a bug.
Please search existing issues before filing a new one.
Please search existing issues before filing a new one. Redact source code, local paths, credentials, combined output, and other private data from every field and attachment.
- type: textarea
id: summary
attributes:
Expand Down Expand Up @@ -45,7 +45,7 @@ body:
id: logs
attributes:
label: Logs or screenshots
description: Paste relevant logs or attach screenshots.
description: Paste relevant logs or attach screenshots only after redacting source code, local paths, credentials, combined output, and other private data.
render: shell
validations:
required: false
Expand All @@ -54,7 +54,7 @@ body:
attributes:
label: Version
description: App or extension version.
placeholder: 0.0.1
placeholder: Extension 0.0.2 or macOS 0.1.0 candidate
validations:
required: false
- type: dropdown
Expand All @@ -72,6 +72,6 @@ body:
attributes:
label: Environment
description: OS + toolchain versions.
placeholder: macOS 14.x, Node 18.x, Swift 6.x
placeholder: macOS version, Node 20+ or 24.x, Swift 6.x, Xcode version
validations:
required: false
4 changes: 2 additions & 2 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
blank_issues_enabled: false
contact_links:
- name: Security reports
url: https://github.com/s1korrrr/codebase-combiner/security/advisories/new
about: Please report security vulnerabilities via private advisories.
url: https://github.com/rsitech-ai/codebase-combiner/security/policy
about: Read the current private-reporting status; do not disclose vulnerabilities in a public issue.
2 changes: 1 addition & 1 deletion .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
- [ ] `npm run lint`
- [ ] `npm run format:check`
- [ ] `cd SwiftExplorerApp && swift test`
- [ ] `swiftformat --lint .`
- [ ] SwiftFormat 0.61.1: `test "$(swiftformat --version)" = "0.61.1" && swiftformat --lint .`

# Checklist

Expand Down
18 changes: 18 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
version: 2
updates:
- package-ecosystem: npm
directory: /
schedule:
interval: weekly
open-pull-requests-limit: 5
groups:
development-tools:
dependency-type: development
update-types:
- minor
- patch
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
open-pull-requests-limit: 5
64 changes: 59 additions & 5 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,17 +4,28 @@ on:
push:
pull_request:

permissions:
contents: read

concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
build-test:
runs-on: macos-latest
timeout-minutes: 30
env:
SWIFTFORMAT_VERSION: 0.61.1
SWIFTFORMAT_SHA256: b990400779aceb7d7020796eb9ba814d4480543f671d38fc0ff48cb72f04c584
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0

- name: Setup Node
uses: actions/setup-node@v4
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 18
node-version: 24
cache: npm

- name: Install JS dependencies
Expand All @@ -29,11 +40,54 @@ jobs:
- name: JS tests
run: npm test

- name: Audit JS dependencies
run: |
npm audit --omit=dev
npm audit
npm audit signatures

- name: Package VS Code extension
run: |
npm run package
script/tests/vsix_inventory_test.sh

- name: Install SwiftFormat
run: brew install swiftformat
run: |
archive="$RUNNER_TEMP/swiftformat.zip"
install_dir="$RUNNER_TEMP/swiftformat"
curl --fail --location --silent --show-error \
--output "$archive" \
"https://github.com/nicklockwood/SwiftFormat/releases/download/$SWIFTFORMAT_VERSION/swiftformat.zip"
echo "$SWIFTFORMAT_SHA256 $archive" | shasum --algorithm 256 --check
unzip -q "$archive" -d "$install_dir"
echo "$install_dir" >> "$GITHUB_PATH"

- name: SwiftFormat lint
run: swiftformat --lint .
run: |
test "$(swiftformat --version)" = "$SWIFTFORMAT_VERSION"
swiftformat --lint .

- name: Swift tests
run: cd SwiftExplorerApp && swift test

- name: Swift Release build with warnings as errors
run: cd SwiftExplorerApp && swift build -c release -Xswiftc -warnings-as-errors

- name: Shell contracts
run: |
bash -n Packaging/AppStore/build_app_store_package.sh
bash -n Packaging/DeveloperID/build_release.sh
bash -n Packaging/DeveloperID/notarize_release.sh
bash Packaging/AppStore/tests/validate_provisioning_profile_test.sh
bash script/tests/build_and_run_contract_test.sh
bash script/tests/open_source_release_contract_test.sh

- name: Developer ID release contracts
run: Packaging/DeveloperID/tests/run_tests.sh

- name: App Store bundle validation
run: |
plutil -lint Packaging/AppStore/AppStore.entitlements
plutil -lint Packaging/AppStore/Info.plist.in
plutil -lint Packaging/AppStore/PrivacyInfo.xcprivacy
Packaging/AppStore/tests/build_app_store_package_contract_test.sh
42 changes: 42 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
name: CodeQL

on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
- cron: '23 4 * * 1'

permissions:
actions: read
contents: read
security-events: write

concurrency:
group: codeql-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
analyze:
name: Analyze ${{ matrix.language }}
runs-on: macos-latest
timeout-minutes: 45
strategy:
fail-fast: false
matrix:
language: [javascript-typescript, swift]
steps:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0

- name: Initialize CodeQL
uses: github/codeql-action/init@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
with:
languages: ${{ matrix.language }}

- name: Autobuild
uses: github/codeql-action/autobuild@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0

- name: Analyze
uses: github/codeql-action/analyze@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
Loading
Loading