Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 23 additions & 4 deletions docs/security-review-2026-09-05.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,10 +48,20 @@ human to complete and review the candidate and to trust both local target worktr

A bounded custom scan inspected 410 text blobs among 465 objects reachable from all origin refs. It
looked for common private-key blocks and GitHub, OpenAI and AWS credential signatures; none matched.
One superseded commit contains a local AlvenX experiment path. Every existing commit exposes the
owner's Outlook author email. This was not a full entropy scanner: gitleaks and trufflehog were not
installed. Old pull-request comments, workflow logs and downloadable artifacts require a final
authenticated GitHub review before visibility changes.
One superseded commit contains a local AlvenX experiment path. Historical commits before this task
expose the owner's Outlook author email; locally authored task commits use the GitHub noreply
identity. GitHub's PR #10 merge commit also retained the account's default Outlook author email.
That immutable merge is included in the same pending disclosure decision. This was not a full
entropy scanner: gitleaks and trufflehog were not installed.

Authenticated GitHub review on 2026-09-05 inspected all 10 PR titles/bodies and the 22 completed
workflow logs then available. There were no standalone issues, issue/PR comments, inline review
comments, submitted reviews or downloadable artifacts. The bounded scan found no private-key
blocks, common GitHub/OpenAI/AWS credentials, the historical owner email or owner Windows paths
in that remote surface. Remaining closeout: check the current PR/main CI logs and record their
results in the final receipt.
This signature scan is not proof that arbitrary private data is absent and does not remove the
known Git-history metadata disclosure.

## Required repository settings

Expand All @@ -61,6 +71,15 @@ deletion and require the two Node matrix CI checks through pull requests. Secret
protection should be enabled wherever the account/repository plan exposes them. Default Actions
token permissions remain read-only.

Before [PR #10](https://github.com/AlbertXXuu/ReproLock/pull/10) merged, Dependabot alerts and
automated security fixes were enabled and read back. Main protection requires up-to-date Node
22.23.2/24.20.0 checks from GitHub Actions, PRs and resolved conversations, also for administrators;
force pushes and deletion are disabled. The single-maintainer policy has zero additional required
GitHub approvals. Default Actions permission is read-only and Actions cannot approve PRs.
Private-vulnerability-reporting GET/PUT returned 404 while private, and `security_and_analysis`
was not exposed. Private reporting, secret scanning and push protection must be rechecked when
public controls are available; this review does not claim those settings are enabled.

## Limits of this review

This was source review plus targeted local tests, dependency audit and bounded history scanning; it
Expand Down
48 changes: 40 additions & 8 deletions harness/context/07-public-alpha-readiness.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,11 +66,43 @@ status/report/cleanup contradictions are now rejected.
- Local engineering and independent-checkout gates are complete. The product decision remains
`SPIKE_CONDITIONAL`; no evidence establishes automatic generation, saved effort, lower
maintenance cost, authenticated provenance or production support.
- Remaining sequence: push `codex/public-readiness`, create a PR, pass both Node CI jobs, record the
immutable PR/CI links, enable available GitHub security/branch controls, merge, and fast-forward
the saved D-drive checkout to remote `main`.
- Repository visibility remains private. Every historical commit before this task exposes the
owner's Outlook author email, and one superseded commit contains a local D-drive experiment path.
No credential signature was found and this task uses the GitHub noreply identity. The final
visibility change requires an explicit decision to accept that historical metadata without
rewriting evidence-bound Git history.
- The owner explicitly authorized the exact private origin. Authenticated checks outside the
restricted environment confirmed `AlbertXXuu` and private repository `AlbertXXuu/ReproLock`;
re-login was unnecessary. Both source and separate Gate commit `328cf13` were pushed unchanged.
- [PR #10](https://github.com/AlbertXXuu/ReproLock/pull/10) passed the required
[Node 22.23.2](https://github.com/AlbertXXuu/ReproLock/actions/runs/33950828745/job/101265142364)
and [Node 24.20.0](https://github.com/AlbertXXuu/ReproLock/actions/runs/33950828745/job/101265142325)
checks. The jobs ran the complete check and package smoke, taking 2m27s and 2m32s respectively.
GitHub reported a clean, mergeable PR at the exact Gate head before the authorized merge.
- `gh pr merge 10 --merge --match-head-commit 328cf137c1198bd774a040d4b486704fececa478`
merged at `2026-09-05T06:52:28Z`, producing `874a58f758a1e50de5c695364db64f0a55d26044`.
`git fetch origin`, `git switch main` and `git merge --ff-only origin/main` synchronized the
saved D-drive checkout with empty tracked/untracked status. Original source and Gate commits
remain separate ancestors. The [main workflow](https://github.com/AlbertXXuu/ReproLock/actions/runs/33951007338)
also passed both Node jobs. Remaining closeout: check the documentation PR/main workflows and
final remote logs, then record their results in the final receipt. Those later documentation-only
commits do not change the accepted runtime source.
- Repository description and topics now identify the experimental local regression verifier.
Dependabot vulnerability alerts and automated security fixes are enabled. Main protection requires
the current-base `Node 22.23.2` and `Node 24.20.0` checks from GitHub Actions (app 15368), PRs and
resolved conversations, including administrators; force pushes and deletion are disabled.
The single-maintainer policy requires zero additional GitHub approving reviews; it does not
substitute for the recorded independent implementation reviews. Default Actions permission is
read-only and Actions cannot approve PRs.
- Authenticated remote-surface review on 2026-09-05 inspected all 10 PR titles/bodies and 22
completed workflow logs. GitHub returned zero standalone issues, issue/PR comments, inline review
comments, reviews and downloadable artifacts. The bounded signature/known-owner scan found no
private-key blocks, GitHub/OpenAI/AWS credential forms, historical owner email or owner Windows
paths in that surface. It does not replace the separate Git-history disclosure below. Raw remote
content is not retained in the minimized local audit receipt.
- GitHub's private-vulnerability-reporting GET/PUT returned 404 while private, and repository
`security_and_analysis` was not exposed. Private reporting, secret scanning and push protection
therefore remain unverified and must be rechecked at publication; no paid feature was enabled.
- Historical `spike/issue-to-repro` worktree and shared recovery stash remain preserved. The
temporary independent-acceptance worktree was removed through Git after its content audit.
- Repository visibility remains private. Historical commits before this task and GitHub's
PR #10 merge commit expose the owner's Outlook author email; GitHub used the account's default
identity for that merge. One superseded commit contains a local D-drive experiment path.
No credential signature was found and locally authored task commits use the GitHub noreply
identity. The final visibility change requires an explicit decision to accept that historical
metadata without rewriting evidence-bound Git history.
10 changes: 8 additions & 2 deletions plans/07-public-alpha-readiness.md
Original file line number Diff line number Diff line change
Expand Up @@ -95,5 +95,11 @@ case and evidence viewer, not the general product surface.
- [x] Public CLI/case-workspace contract implemented and targeted tests pass.
- [x] Public documentation, security review and community surface complete.
- [x] Full local and independent acceptance pass at source commit `24a67ec`.
- [ ] PR and both CI jobs pass; merge and D-main sync complete.
- [ ] Repository metadata/security settings complete; visibility decision recorded.
- [x] [PR #10](https://github.com/AlbertXXuu/ReproLock/pull/10) passed both required Node CI jobs,
merged as `874a58f758a1e50de5c695364db64f0a55d26044`, and the saved D-drive main fast-forwarded
cleanly to that commit. The phase context records immutable remote acceptance links.
- [x] Repository description/topics, Dependabot alerts/security updates and protected-main rules
configured and read back. Authenticated historical PR/log/artifact review completed.
- [ ] Owner accepts historical metadata disclosure before any visibility change. Recheck private
vulnerability reporting, secret scanning and push protection when their public controls become
available; keep the repository private until that decision.