From dfcb34c7eae8b5e3d31a9e60f3bd92c41de7689a Mon Sep 17 00:00:00 2001 From: AlbertXXuu <204706285+AlbertXXuu@users.noreply.github.com> Date: Sat, 5 Sep 2026 14:56:17 +0800 Subject: [PATCH 1/2] docs: record merged alpha delivery and remote audit --- docs/security-review-2026-09-05.md | 25 ++++++++++--- harness/context/07-public-alpha-readiness.md | 37 ++++++++++++++++++-- plans/07-public-alpha-readiness.md | 10 ++++-- 3 files changed, 63 insertions(+), 9 deletions(-) diff --git a/docs/security-review-2026-09-05.md b/docs/security-review-2026-09-05.md index f06e9b1..83412cf 100644 --- a/docs/security-review-2026-09-05.md +++ b/docs/security-review-2026-09-05.md @@ -48,10 +48,18 @@ human to complete and review the candidate and to trust both local target worktr A bounded custom scan inspected 410 text blobs among 465 objects reachable from all origin refs. It looked for common private-key blocks and GitHub, OpenAI and AWS credential signatures; none matched. -One superseded commit contains a local AlvenX experiment path. Every existing commit exposes the -owner's Outlook author email. This was not a full entropy scanner: gitleaks and trufflehog were not -installed. Old pull-request comments, workflow logs and downloadable artifacts require a final -authenticated GitHub review before visibility changes. +One superseded commit contains a local AlvenX experiment path. Historical commits before this task +expose the owner's Outlook author email; this task uses the GitHub noreply identity. This was not a +full entropy scanner: gitleaks and trufflehog were not installed. + +Authenticated GitHub review on 2026-09-05 inspected all 10 PR titles/bodies and the 22 completed +workflow logs then available. There were no standalone issues, issue/PR comments, inline review +comments, submitted reviews or downloadable artifacts. The bounded scan found no private-key +blocks, common GitHub/OpenAI/AWS credentials, the historical owner email or owner Windows paths +in that remote surface. Remaining closeout: check the current PR/main CI logs and record their +results in the final receipt. +This signature scan is not proof that arbitrary private data is absent and does not remove the +known Git-history metadata disclosure. ## Required repository settings @@ -61,6 +69,15 @@ deletion and require the two Node matrix CI checks through pull requests. Secret protection should be enabled wherever the account/repository plan exposes them. Default Actions token permissions remain read-only. +Before [PR #10](https://github.com/AlbertXXuu/ReproLock/pull/10) merged, Dependabot alerts and +automated security fixes were enabled and read back. Main protection requires up-to-date Node +22.23.2/24.20.0 checks from GitHub Actions, PRs and resolved conversations, also for administrators; +force pushes and deletion are disabled. The single-maintainer policy has zero additional required +GitHub approvals. Default Actions permission is read-only and Actions cannot approve PRs. +Private-vulnerability-reporting GET/PUT returned 404 while private, and `security_and_analysis` +was not exposed. Private reporting, secret scanning and push protection must be rechecked when +public controls are available; this review does not claim those settings are enabled. + ## Limits of this review This was source review plus targeted local tests, dependency audit and bounded history scanning; it diff --git a/harness/context/07-public-alpha-readiness.md b/harness/context/07-public-alpha-readiness.md index b610ffd..a5f47aa 100644 --- a/harness/context/07-public-alpha-readiness.md +++ b/harness/context/07-public-alpha-readiness.md @@ -66,9 +66,40 @@ status/report/cleanup contradictions are now rejected. - Local engineering and independent-checkout gates are complete. The product decision remains `SPIKE_CONDITIONAL`; no evidence establishes automatic generation, saved effort, lower maintenance cost, authenticated provenance or production support. -- Remaining sequence: push `codex/public-readiness`, create a PR, pass both Node CI jobs, record the - immutable PR/CI links, enable available GitHub security/branch controls, merge, and fast-forward - the saved D-drive checkout to remote `main`. +- The owner explicitly authorized the exact private origin. Authenticated checks outside the + restricted environment confirmed `AlbertXXuu` and private repository `AlbertXXuu/ReproLock`; + re-login was unnecessary. Both source and separate Gate commit `328cf13` were pushed unchanged. +- [PR #10](https://github.com/AlbertXXuu/ReproLock/pull/10) passed the required + [Node 22.23.2](https://github.com/AlbertXXuu/ReproLock/actions/runs/33950828745/job/101265142364) + and [Node 24.20.0](https://github.com/AlbertXXuu/ReproLock/actions/runs/33950828745/job/101265142325) + checks. The jobs ran the complete check and package smoke, taking 2m27s and 2m32s respectively. + GitHub reported a clean, mergeable PR at the exact Gate head before the authorized merge. +- `gh pr merge 10 --merge --match-head-commit 328cf137c1198bd774a040d4b486704fececa478` + merged at `2026-09-05T06:52:28Z`, producing `874a58f758a1e50de5c695364db64f0a55d26044`. + `git fetch origin`, `git switch main` and `git merge --ff-only origin/main` synchronized the + saved D-drive checkout with empty tracked/untracked status. Original source and Gate commits + remain separate ancestors. The [main workflow](https://github.com/AlbertXXuu/ReproLock/actions/runs/33951007338) + also passed both Node jobs. Remaining closeout: check the documentation PR/main workflows and + final remote logs, then record their results in the final receipt. Those later documentation-only + commits do not change the accepted runtime source. +- Repository description and topics now identify the experimental local regression verifier. + Dependabot vulnerability alerts and automated security fixes are enabled. Main protection requires + the current-base `Node 22.23.2` and `Node 24.20.0` checks from GitHub Actions (app 15368), PRs and + resolved conversations, including administrators; force pushes and deletion are disabled. + The single-maintainer policy requires zero additional GitHub approving reviews; it does not + substitute for the recorded independent implementation reviews. Default Actions permission is + read-only and Actions cannot approve PRs. +- Authenticated remote-surface review on 2026-09-05 inspected all 10 PR titles/bodies and 22 + completed workflow logs. GitHub returned zero standalone issues, issue/PR comments, inline review + comments, reviews and downloadable artifacts. The bounded signature/known-owner scan found no + private-key blocks, GitHub/OpenAI/AWS credential forms, historical owner email or owner Windows + paths in that surface. It does not replace the separate Git-history disclosure below. Raw remote + content is not retained in the minimized local audit receipt. +- GitHub's private-vulnerability-reporting GET/PUT returned 404 while private, and repository + `security_and_analysis` was not exposed. Private reporting, secret scanning and push protection + therefore remain unverified and must be rechecked at publication; no paid feature was enabled. +- Historical `spike/issue-to-repro` worktree and shared recovery stash remain preserved. The + temporary independent-acceptance worktree was removed through Git after its content audit. - Repository visibility remains private. Every historical commit before this task exposes the owner's Outlook author email, and one superseded commit contains a local D-drive experiment path. No credential signature was found and this task uses the GitHub noreply identity. The final diff --git a/plans/07-public-alpha-readiness.md b/plans/07-public-alpha-readiness.md index 6ea1467..8b2ba34 100644 --- a/plans/07-public-alpha-readiness.md +++ b/plans/07-public-alpha-readiness.md @@ -95,5 +95,11 @@ case and evidence viewer, not the general product surface. - [x] Public CLI/case-workspace contract implemented and targeted tests pass. - [x] Public documentation, security review and community surface complete. - [x] Full local and independent acceptance pass at source commit `24a67ec`. -- [ ] PR and both CI jobs pass; merge and D-main sync complete. -- [ ] Repository metadata/security settings complete; visibility decision recorded. +- [x] [PR #10](https://github.com/AlbertXXuu/ReproLock/pull/10) passed both required Node CI jobs, + merged as `874a58f758a1e50de5c695364db64f0a55d26044`, and the saved D-drive main fast-forwarded + cleanly to that commit. The phase context records immutable remote acceptance links. +- [x] Repository description/topics, Dependabot alerts/security updates and protected-main rules + configured and read back. Authenticated historical PR/log/artifact review completed. +- [ ] Owner accepts historical metadata disclosure before any visibility change. Recheck private + vulnerability reporting, secret scanning and push protection when their public controls become + available; keep the repository private until that decision. From 863c78086f9de53c993a120c2989390f76fa6cca Mon Sep 17 00:00:00 2001 From: AlbertXXuu <204706285+AlbertXXuu@users.noreply.github.com> Date: Sat, 5 Sep 2026 14:58:24 +0800 Subject: [PATCH 2/2] docs: clarify hosted merge author disclosure --- docs/security-review-2026-09-05.md | 6 ++++-- harness/context/07-public-alpha-readiness.md | 11 ++++++----- 2 files changed, 10 insertions(+), 7 deletions(-) diff --git a/docs/security-review-2026-09-05.md b/docs/security-review-2026-09-05.md index 83412cf..9f8d3ae 100644 --- a/docs/security-review-2026-09-05.md +++ b/docs/security-review-2026-09-05.md @@ -49,8 +49,10 @@ human to complete and review the candidate and to trust both local target worktr A bounded custom scan inspected 410 text blobs among 465 objects reachable from all origin refs. It looked for common private-key blocks and GitHub, OpenAI and AWS credential signatures; none matched. One superseded commit contains a local AlvenX experiment path. Historical commits before this task -expose the owner's Outlook author email; this task uses the GitHub noreply identity. This was not a -full entropy scanner: gitleaks and trufflehog were not installed. +expose the owner's Outlook author email; locally authored task commits use the GitHub noreply +identity. GitHub's PR #10 merge commit also retained the account's default Outlook author email. +That immutable merge is included in the same pending disclosure decision. This was not a full +entropy scanner: gitleaks and trufflehog were not installed. Authenticated GitHub review on 2026-09-05 inspected all 10 PR titles/bodies and the 22 completed workflow logs then available. There were no standalone issues, issue/PR comments, inline review diff --git a/harness/context/07-public-alpha-readiness.md b/harness/context/07-public-alpha-readiness.md index a5f47aa..5fee4e1 100644 --- a/harness/context/07-public-alpha-readiness.md +++ b/harness/context/07-public-alpha-readiness.md @@ -100,8 +100,9 @@ status/report/cleanup contradictions are now rejected. therefore remain unverified and must be rechecked at publication; no paid feature was enabled. - Historical `spike/issue-to-repro` worktree and shared recovery stash remain preserved. The temporary independent-acceptance worktree was removed through Git after its content audit. -- Repository visibility remains private. Every historical commit before this task exposes the - owner's Outlook author email, and one superseded commit contains a local D-drive experiment path. - No credential signature was found and this task uses the GitHub noreply identity. The final - visibility change requires an explicit decision to accept that historical metadata without - rewriting evidence-bound Git history. +- Repository visibility remains private. Historical commits before this task and GitHub's + PR #10 merge commit expose the owner's Outlook author email; GitHub used the account's default + identity for that merge. One superseded commit contains a local D-drive experiment path. + No credential signature was found and locally authored task commits use the GitHub noreply + identity. The final visibility change requires an explicit decision to accept that historical + metadata without rewriting evidence-bound Git history.