Skip to content

mono - chore: defense - record the lockdown audit - #1737

Merged
jaredwray merged 4 commits into
mainfrom
chore/defense-lockdown-audit
Oct 6, 2026
Merged

jaredwray merged 4 commits into
mainfrom
chore/defense-lockdown-audit

Conversation

@jaredwray

@jaredwray jaredwray commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Please check if the PR fulfills these requirements

  • Followed the Contributing guidelines and Code of Conduct
  • Tests for the changes have been added (for bug fixes/features) with 100% code coverage. Not a bug fix or feature. Lockdown audit record only.

What kind of change does this PR introduce? (Bug fix, feature, docs update, ...)

Checklist and security summary update after the admin lockdown audit.

Summary

Section 7 records the admin --check from 2026-10-06. The audit passed for every applicable setting.

Status update

DEFENSE_IN_DEPTH.md: lockdown --check → passed 2026-10-06 (PR #1737 is pending)

Changes

  • Record the clean admin audit on the lockdown item
  • Update SECURITY.md for the live pnpm pin, Safe Chain hook, Dev Container digest, and CODEOWNERS paths
  • Codex cloud and the Claude Code network allowlist stay unchecked

Verification

  • The admin --check on 2026-10-06 reported Audit: all applicable settings are in the desired state.
  • The branch-ruleset pass line matches the current lockdown-repo.sh
  • A repeat --check from this session. This token is not a repo admin, so admin settings return 403.

defense-in-depth-nodejs § 7

Open in Web Open in Cursor 

cursoragent and others added 2 commits October 6, 2026 09:08
Co-authored-by: Jared Wray <me@jaredwray.com>
Co-authored-by: Jared Wray <me@jaredwray.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T09:11:32.245644Z e5fb71d PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@codecov

codecov Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (23d7333) to head (7068800).

Additional details and impacted files
@@            Coverage Diff            @@
##              main     #1737   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files           29        29           
  Lines         3612      3612           
  Branches       823       822    -1     
=========================================
  Hits          3612      3612           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e5fb71d672

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread SECURITY.md Outdated
Comment thread DEFENSE_IN_DEPTH.md Outdated
Co-authored-by: Jared Wray <me@jaredwray.com>
@cursor

cursor Bot commented Oct 6, 2026

Copy link
Copy Markdown

test-26 failed a known cache-manager flake at packages/cache-manager/test/mdel.test.ts:98. The run received [undefined, undefined, undefined] and expected the third faker value. The same assertion failed on main (db17eb5) and on tinybench (051a8d5). An empty commit retriggers CI.

Co-authored-by: Jared Wray <me@jaredwray.com>
@jaredwray
jaredwray merged commit 3616da2 into main Oct 6, 2026
15 checks passed
@jaredwray
jaredwray deleted the chore/defense-lockdown-audit branch October 6, 2026 09:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants