Skip to content

specs/functions: reels-loop-generate, content-scripts-generate -- secrets leave the event payload - #8023

Merged
gHashTag merged 1 commit into
masterfrom
secrets-out-of-payloads-spec
Oct 9, 2026
Merged

gHashTag merged 1 commit into
masterfrom
secrets-out-of-payloads-spec

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 9, 2026

Copy link
Copy Markdown
Owner

Closes #8022

Plan: 999-multibots-telegraf docs/audit/inngest-improvement-plan-2026-09-13.md section 3 (secrets in events).

  • reels-loop-generate NOTE: delivery bot resolved from bot_name through the registry (token in env); bot_token honoured only as a deprecated fallback with a non-printing warning; neither -> NonRetriableError. Sender of the event is outside the repo (not verified whether it sends bot_name). SERVICE 77 -> 106.
  • content-scripts-generate NOTE: openai_api_key removed from the schema, zod strips it, key from env in the steps. SERVICE 44 -> 49.
  • docs/now/2026-10-09-the-token-stays-in-the-environment.md.
  • Compiler verdict clean on both (typecheckOk, 0 errors, hirOk). ASCII only.

Code: 999-multibots-telegraf branch secrets-out-of-payloads.

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-09 06:11:37 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 47
PRs with All Checks Green 3
READY 1
FAILING 47
PENDING 0
NO CHECKS YET 0

These columns do not partition: 1 + 47 + 0 + 0 = 48, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=3c0ade9e73e4 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

This was referenced Oct 9, 2026
This was referenced Oct 9, 2026
@gHashTag
gHashTag enabled auto-merge (squash) October 9, 2026 16:54
@gHashTag
gHashTag merged commit d2b5fc1 into master Oct 9, 2026
28 of 29 checks passed
gHashTag pushed a commit that referenced this pull request Oct 9, 2026
…loses #8242)

specs/functions/content-scripts-generate.t27 conflicted: master (#8023)
moved SERVICE to line 49 and extended NOTE. Resolved from master's side:
master's card with this branch's appended tests unchanged after it. The
tests still pass (t27c test-report 5/5, 0 vacuous; t27b 5/5, 65 runtime
asserts). The 9 seals are re-saved with master's t27c 0.5.2 (seal --save,
then --verify: all hashes MATCH). The ledger merged cleanly: master's rows
and this branch's 9.

Closes #8242

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
gHashTag added a commit that referenced this pull request Oct 9, 2026
#8283) (#8288)

Each card held no test block and passed vacuously (0 runtime asserts) under
both the reference and t27b. The same tests as #8243 hold each card to the
schema of specs/functions/README.md: ID is <domain>-<object>-<verb>; an
event function's canonical EVENT names the same three parts as ID and it
has no CRON; a cron function has a five-field CRON and no EVENT; the fields
come from their vocabularies; SAFE_PROBE agrees with PROBE_RESULT; SERVICE
is file:line. With #8243, every function card now carries a test.

robokassa-unclaimed-watch and ton-pending-watch have DOMAIN "money",
outside the README's vocabulary (see #7911), and skip the DOMAIN test.
reels-loop-generate's tests run on the card as #8023 left it.

t27c test-report: 4 or 5 tests per card, 0 vacuous. t27b test --check: all
pass, 23 to 67 runtime asserts. Sealed with master's t27c 0.5.2 (seal
--save, then --verify).

docs/reports/t27b_expectations.json: `bless` of scripts/tri_loop/t27b.py
over lab run 6c5ad4b with this branch's t27b verdicts for the 9 specs,
composed onto master's ledger with only these rows: pass_vacuous -> pass.

Closes #8283

Co-authored-by: Claude <claude@anthropic.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Spec reels-loop-generate and content-scripts-generate: secrets leave the event payload

1 participant