Repository navigation
mono - chore: defense - bootstrap Safe Chain for Claude Code - #1735
Conversation
Co-authored-by: Jared Wray <me@jaredwray.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Co-authored-by: Jared Wray <me@jaredwray.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #1735 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 29 29
Lines 3612 3612
Branches 808 810 +2
=========================================
Hits 3612 3612 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fb6e33f336
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| { | ||
| "hooks": { | ||
| "SessionStart": [ | ||
| { |
There was a problem hiding this comment.
Exclude compaction from the bootstrap hook
This group has no matcher, so Claude runs the full bootstrap after each remote-session compaction, not only when the VM starts. Claude lists compact as a SessionStart source and says to keep these hooks fast (SessionStart documentation). The script downloads the installer and runs pnpm install, so long sessions can pause for up to 600 seconds at each automatic compaction. Add a matcher that excludes compact, or make this path return quickly after successful setup.
Useful? React with 👍 / 👎.
Please check if the PR fulfills these requirements
What kind of change does this PR introduce? (Bug fix, feature, docs update, ...)
Supply-chain hardening for the Safe Chain cloud bootstrap.
Summary
Section 2 now runs the Safe Chain bootstrap from Claude Code on the web, and the Dev Container gains the GitHub CLI feature.
Status update
DEFENSE_IN_DEPTH.md: Safe Chain cloud bootstrap → (PR #1735 pending)CODEOWNERS paths are checked off as merged in PR #1734.
Changes
.claude/hooks/session-start.shand.claude/settings.jsonwith a SessionStart hook, timeout 600.claude/settings.jsonand.claude/hooks/tracked in.gitignoregithub-cli:1to the Dev Container. The image pin anddocker-in-dockerfeature stayinstallcommand,AGENTS.md, andCLAUDE.mdalready matchVerification
bash -npasses for.claude/hooks/session-start.shandscripts/setup-cloud-environment.sh.claude/settings.jsonand.devcontainer/devcontainer.jsonparse as JSONdefense-in-depth-nodejs § 2