26 unexplained commit(s) in the audit window (.github/workflows/ .config/tend.yaml .github/audit/ .vscode/) since 2026-08-26T07:55:07Z.
Routine Renovate pin bumps and reproducible tend regenerations are
classified and omitted — see the run summary for what was skipped.
Everything below needs a human to account for it.
0039b15 — ci: guard the last retry sleep so the stated worst case is the real one
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-27 01:22:10 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
- View diff
0dfa1e3 — security(audit): fold in what #449, #450 and #451 found
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-26 18:29:53 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
.github/audit/supply-chain.md
- View diff
19122fd — ci(standalone): correct the apt worst case to 945s (three sleeps, not two)
1e3c952 — security(audit): own the repository by subtraction, not by a list
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-26 11:52:49 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
.github/audit/application-security.md
.github/audit/ci-and-secrets.md
.github/audit/supply-chain.md
.github/workflows/workflow-audit.yaml
- View diff
1f2f69f — docs(security): qualify website/package.json in the supply-chain build-config list
4046247 — fix(workflow-audit): name .github/audit/ in the report and empty-window text
4353ec7 — security(audit): separate recording a condition from deciding the verdict
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-26 22:11:58 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
.github/workflows/security-audit.yaml
- View diff
47b1779 — security: derive the classifier window, and record that tend shipped the fix
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-26 14:05:49 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
.github/workflows/workflow-audit.yaml
- View diff
47d01c9 — security(audit): let a dissent outrank a missing fragment
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-26 21:44:54 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
.github/workflows/security-audit.yaml
.github/workflows/workflow-audit.yaml
- View diff
527f988 — ci(standalone): give the smoketest's apt step a budget that outlasts its retries (#454)
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-27 07:39:55 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
- View diff
54b9293 — ci: install zsh so the shell-integration tests actually cover it
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-27 00:41:13 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
- View diff
5ab8cce — ci(standalone): give the smoketest's apt step a budget that outlasts its retries
5b7ea04 — docs(security): name every dotfile directory in the audit scopes, and dormouse-lib as a root
60ebf67 — security(audit): report conditions, not combinations
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-26 22:00:53 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
.github/workflows/security-audit.yaml
- View diff
62848c7 — security(audit): give the unreadable-verdict case its own issue prose
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-26 19:53:41 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
.github/workflows/security-audit.yaml
- View diff
6a208e3 — security(standalone): make session snapshots owner-only
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-26 19:13:43 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
.github/audit/application-security.md
- View diff
6c9aec7 — fix(security): address the four review notes on #453
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-27 00:48:01 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
- View diff
905b7b5 — security(audit): run application-security on Opus, and make a domain's verdict binding
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-26 18:27:21 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
.github/audit/_preamble.md
.github/audit/orchestrator.md
.github/workflows/security-audit.yaml
.github/workflows/workflow-audit.yaml
- View diff
a1bd66a — ci: give the zsh install a budget that outlasts its own retries
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-27 01:15:56 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
- View diff
a3d98e1 — docs(security): give supply-chain all of website/ except public/
ae3f015 — ci: stop the apt warning promising a retry that does not happen
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-27 01:27:44 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
- View diff
c0af617 — security(remote): evict the pairing record, not just its payload
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-26 19:35:43 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
.github/workflows/security-audit.yaml
- View diff
e66feee — security: fix three claims the audit proved wrong
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-26 13:16:55 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
.github/audit/application-security.md
- View diff
e7dc783 — security(workflow-audit): make the widened window reach every consumer
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-26 13:48:38 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
.github/workflows/workflow-audit.yaml
- View diff
f254bc4 — fix(workflow-audit): report commits that only touch .github/audit/
fcca569 — security(host): stop the iframe proxy vouching for strangers, and name the rule
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-08-27 00:31:26 -0700
- Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
- Files:
.github/audit/application-security.md
- View diff
26 unexplained commit(s) in the audit window (
.github/workflows/ .config/tend.yaml .github/audit/ .vscode/) since2026-08-26T07:55:07Z.Routine Renovate pin bumps and reproducible tend regenerations are
classified and omitted — see the run summary for what was skipped.
Everything below needs a human to account for it.
0039b15— ci: guard the last retry sleep so the stated worst case is the real one.github/workflows/ci.yml0dfa1e3— security(audit): fold in what #449, #450 and #451 found.github/audit/supply-chain.md19122fd— ci(standalone): correct the apt worst case to 945s (three sleeps, not two).github/workflows/ci.yml1e3c952— security(audit): own the repository by subtraction, not by a list.github/audit/application-security.md.github/audit/ci-and-secrets.md.github/audit/supply-chain.md.github/workflows/workflow-audit.yaml1f2f69f— docs(security): qualify website/package.json in the supply-chain build-config list.github/audit/supply-chain.md4046247— fix(workflow-audit): name .github/audit/ in the report and empty-window text.github/workflows/workflow-audit.yaml4353ec7— security(audit): separate recording a condition from deciding the verdict.github/workflows/security-audit.yaml47b1779— security: derive the classifier window, and record that tend shipped the fix.github/workflows/workflow-audit.yaml47d01c9— security(audit): let a dissent outrank a missing fragment.github/workflows/security-audit.yaml.github/workflows/workflow-audit.yaml527f988— ci(standalone): give the smoketest's apt step a budget that outlasts its retries (#454).github/workflows/ci.yml54b9293— ci: install zsh so the shell-integration tests actually cover it.github/workflows/ci.yml5ab8cce— ci(standalone): give the smoketest's apt step a budget that outlasts its retries.github/workflows/ci.yml5b7ea04— docs(security): name every dotfile directory in the audit scopes, and dormouse-lib as a root.github/audit/application-security.md.github/audit/ci-and-secrets.md60ebf67— security(audit): report conditions, not combinations.github/workflows/security-audit.yaml62848c7— security(audit): give the unreadable-verdict case its own issue prose.github/workflows/security-audit.yaml6a208e3— security(standalone): make session snapshots owner-only.github/audit/application-security.md6c9aec7— fix(security): address the four review notes on #453.github/workflows/ci.yml905b7b5— security(audit): run application-security on Opus, and make a domain's verdict binding.github/audit/_preamble.md.github/audit/orchestrator.md.github/workflows/security-audit.yaml.github/workflows/workflow-audit.yamla1bd66a— ci: give the zsh install a budget that outlasts its own retries.github/workflows/ci.ymla3d98e1— docs(security): give supply-chain all of website/ except public/.github/audit/supply-chain.mdae3f015— ci: stop the apt warning promising a retry that does not happen.github/workflows/ci.ymlc0af617— security(remote): evict the pairing record, not just its payload.github/workflows/security-audit.yamle66feee— security: fix three claims the audit proved wrong.github/audit/application-security.mde7dc783— security(workflow-audit): make the widened window reach every consumer.github/workflows/workflow-audit.yamlf254bc4— fix(workflow-audit): report commits that only touch .github/audit/.github/workflows/workflow-audit.yamlfcca569— security(host): stop the iframe proxy vouching for strangers, and name the rule.github/audit/application-security.md