Skip to content

[workflow-audit] 26 unexplained change(s) on 2026-08-27 #456

Description

@github-actions

26 unexplained commit(s) in the audit window (.github/workflows/ .config/tend.yaml .github/audit/ .vscode/) since 2026-08-26T07:55:07Z.

Routine Renovate pin bumps and reproducible tend regenerations are
classified and omitted — see the run summary for what was skipped.
Everything below needs a human to account for it.

0039b15 — ci: guard the last retry sleep so the stated worst case is the real one

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-27 01:22:10 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/workflows/ci.yml
  • View diff

0dfa1e3 — security(audit): fold in what #449, #450 and #451 found

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-26 18:29:53 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/audit/supply-chain.md
  • View diff

19122fd — ci(standalone): correct the apt worst case to 945s (three sleeps, not two)

1e3c952 — security(audit): own the repository by subtraction, not by a list

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-26 11:52:49 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/audit/application-security.md
    • .github/audit/ci-and-secrets.md
    • .github/audit/supply-chain.md
    • .github/workflows/workflow-audit.yaml
  • View diff

1f2f69f — docs(security): qualify website/package.json in the supply-chain build-config list

4046247 — fix(workflow-audit): name .github/audit/ in the report and empty-window text

4353ec7 — security(audit): separate recording a condition from deciding the verdict

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-26 22:11:58 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/workflows/security-audit.yaml
  • View diff

47b1779 — security: derive the classifier window, and record that tend shipped the fix

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-26 14:05:49 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/workflows/workflow-audit.yaml
  • View diff

47d01c9 — security(audit): let a dissent outrank a missing fragment

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-26 21:44:54 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/workflows/security-audit.yaml
    • .github/workflows/workflow-audit.yaml
  • View diff

527f988 — ci(standalone): give the smoketest's apt step a budget that outlasts its retries (#454)

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-27 07:39:55 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/workflows/ci.yml
  • View diff

54b9293 — ci: install zsh so the shell-integration tests actually cover it

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-27 00:41:13 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/workflows/ci.yml
  • View diff

5ab8cce — ci(standalone): give the smoketest's apt step a budget that outlasts its retries

5b7ea04 — docs(security): name every dotfile directory in the audit scopes, and dormouse-lib as a root

  • Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
  • Date: 2026-08-26 19:02:39 +0000
  • Refs: remotes/origin/docs/security-scope-enumerations
  • Files:
    • .github/audit/application-security.md
    • .github/audit/ci-and-secrets.md
  • View diff

60ebf67 — security(audit): report conditions, not combinations

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-26 22:00:53 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/workflows/security-audit.yaml
  • View diff

62848c7 — security(audit): give the unreadable-verdict case its own issue prose

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-26 19:53:41 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/workflows/security-audit.yaml
  • View diff

6a208e3 — security(standalone): make session snapshots owner-only

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-26 19:13:43 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/audit/application-security.md
  • View diff

6c9aec7 — fix(security): address the four review notes on #453

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-27 00:48:01 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/workflows/ci.yml
  • View diff

905b7b5 — security(audit): run application-security on Opus, and make a domain's verdict binding

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-26 18:27:21 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/audit/_preamble.md
    • .github/audit/orchestrator.md
    • .github/workflows/security-audit.yaml
    • .github/workflows/workflow-audit.yaml
  • View diff

a1bd66a — ci: give the zsh install a budget that outlasts its own retries

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-27 01:15:56 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/workflows/ci.yml
  • View diff

a3d98e1 — docs(security): give supply-chain all of website/ except public/

ae3f015 — ci: stop the apt warning promising a retry that does not happen

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-27 01:27:44 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/workflows/ci.yml
  • View diff

c0af617 — security(remote): evict the pairing record, not just its payload

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-26 19:35:43 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/workflows/security-audit.yaml
  • View diff

e66feee — security: fix three claims the audit proved wrong

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-26 13:16:55 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/audit/application-security.md
  • View diff

e7dc783 — security(workflow-audit): make the widened window reach every consumer

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-26 13:48:38 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/workflows/workflow-audit.yaml
  • View diff

f254bc4 — fix(workflow-audit): report commits that only touch .github/audit/

fcca569 — security(host): stop the iframe proxy vouching for strangers, and name the rule

  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-08-27 00:31:26 -0700
  • Refs: main,remotes/origin/fix/scrollback-resurrect-after-kill remotes/origin/main
  • Files:
    • .github/audit/application-security.md
  • View diff

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions