Skip to content

mono - chore: defense - bootstrap Safe Chain for Claude Code - #1735

Merged
jaredwray merged 2 commits into
mainfrom
chore/defense-safe-chain-cloud
Oct 6, 2026
Merged

jaredwray merged 2 commits into
mainfrom
chore/defense-safe-chain-cloud

Conversation

@jaredwray

@jaredwray jaredwray commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Please check if the PR fulfills these requirements

  • Followed the Contributing guidelines and Code of Conduct
  • Tests for the changes have been added (for bug fixes/features) with 100% code coverage. Not a bug fix or feature. Cloud bootstrap only.

What kind of change does this PR introduce? (Bug fix, feature, docs update, ...)

Supply-chain hardening for the Safe Chain cloud bootstrap.

Summary

Section 2 now runs the Safe Chain bootstrap from Claude Code on the web, and the Dev Container gains the GitHub CLI feature.

Status update

DEFENSE_IN_DEPTH.md: Safe Chain cloud bootstrap → (PR #1735 pending)

CODEOWNERS paths are checked off as merged in PR #1734.

Changes

  • Add .claude/hooks/session-start.sh and .claude/settings.json with a SessionStart hook, timeout 600
  • Keep .claude/settings.json and .claude/hooks/ tracked in .gitignore
  • Add github-cli:1 to the Dev Container. The image pin and docker-in-docker feature stay
  • The bootstrap script, Cursor install command, AGENTS.md, and CLAUDE.md already match

Verification

  • bash -n passes for .claude/hooks/session-start.sh and scripts/setup-cloud-environment.sh
  • .claude/settings.json and .devcontainer/devcontainer.json parse as JSON
  • The hook matches the skill template

defense-in-depth-nodejs § 2

Open in Web Open in Cursor 

Co-authored-by: Jared Wray <me@jaredwray.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T08:37:22.029218Z fb6e33f PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Co-authored-by: Jared Wray <me@jaredwray.com>
@codecov

codecov Bot commented Oct 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (082fe88) to head (ebf8959).

Additional details and impacted files
@@            Coverage Diff            @@
##              main     #1735   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files           29        29           
  Lines         3612      3612           
  Branches       808       810    +2     
=========================================
  Hits          3612      3612           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@jaredwray
jaredwray merged commit 339b298 into main Oct 6, 2026
15 checks passed
@jaredwray
jaredwray deleted the chore/defense-safe-chain-cloud branch October 6, 2026 08:35

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: fb6e33f336

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .claude/settings.json
{
"hooks": {
"SessionStart": [
{

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Exclude compaction from the bootstrap hook

This group has no matcher, so Claude runs the full bootstrap after each remote-session compaction, not only when the VM starts. Claude lists compact as a SessionStart source and says to keep these hooks fast (SessionStart documentation). The script downloads the installer and runs pnpm install, so long sessions can pause for up to 600 seconds at each automatic compaction. Add a matcher that excludes compact, or make this path return quickly after successful setup.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants