Commit 1044d3f
committed
ci: dependabot title exemption, dependency floors, secret-backed account id
Phase C of the OSS-ready program:
- static-checks: the 72-character PR-title ceiling no longer applies to
dependabot[bot] (machine-generated titles grow with group size and are not
configurable; the Conventional-Commits pattern still applies to everyone;
commitlint's own ceiling is 100)
- dependency floors: dompurify override advanced to 3.4.12; body-parser
floored to 2.3.0 (resolved 2.2.2 was inside the advisory range via express
and @modelcontextprotocol/sdk paths)
- deploy-cloudflare reads CLOUDFLARE_ACCOUNT_ID from secrets (masked in
public logs; the secret already exists, the variable is removed after the
next validated deploy)
- build-snapshot environment casing normalized to Production
- sandbox Dockerfile documents that alerts #9/#8 are lockfile-metadata
findings mitigated by the runtime-security-overrides overlay1 parent 2daed6d commit 1044d3f
6 files changed
Lines changed: 23 additions & 17 deletions
File tree
- .github/workflows
- infra/containers/sandbox
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | | - | |
| 27 | + | |
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
70 | 70 | | |
71 | 71 | | |
72 | 72 | | |
73 | | - | |
| 73 | + | |
74 | 74 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
38 | 38 | | |
39 | 39 | | |
40 | 40 | | |
| 41 | + | |
41 | 42 | | |
42 | 43 | | |
43 | 44 | | |
44 | 45 | | |
45 | 46 | | |
46 | 47 | | |
| 48 | + | |
47 | 49 | | |
48 | 50 | | |
49 | 51 | | |
50 | 52 | | |
51 | 53 | | |
52 | | - | |
53 | | - | |
54 | | - | |
55 | | - | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
56 | 59 | | |
57 | 60 | | |
58 | 61 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
| 38 | + | |
38 | 39 | | |
39 | 40 | | |
40 | 41 | | |
| |||
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
49 | 49 | | |
50 | 50 | | |
51 | 51 | | |
52 | | - | |
| 52 | + | |
| 53 | + | |
53 | 54 | | |
54 | 55 | | |
55 | 56 | | |
| |||
0 commit comments