Skip to content

Close T-0148 with the CI run that proved the audit gate fails - #33

Merged
illodev merged 1 commit into
mainfrom
chore/close-t-0148
Aug 7, 2026
Merged

Close T-0148 with the CI run that proved the audit gate fails#33
illodev merged 1 commit into
mainfrom
chore/close-t-0148

Conversation

@illodev

@illodev illodev commented Aug 7, 2026

Copy link
Copy Markdown
Owner

Record-only: T-0148 moves to done with method: ci and the run URL.

Its last criterion asked that a pull request prove the audit fails in CI. #30 and #31 had shown the audit job running and passing — the wiring and the green path — and the red path had only been run locally, which this repo does not accept as proof of a pull request.

So #32 pinned hono to 4.12.33 and nothing else. The job failed at the --audit-level=moderate step naming GHSA-8j4g-w8fx-2239, its patched range and the path through shadcn@modelcontextprotocol/sdk, exit 1:

https://github.com/illodev/workfile/actions/runs/31208898683/job/92966664406

Closed unmerged, branch deleted, main untouched.

The same install exits 0 at --audit-level=high, which demonstrates #31's floor change on one tree rather than in prose — an advisory the old floor could not see is exactly what sat in the security tab for days.

🤖 Generated with Claude Code

https://claude.ai/code/session_01D3LTdq3mzMAQ98rwBegGjU

Its last criterion asked that a pull request prove the audit fails in CI, and
#30 and #31 had only shown the job running and passing — the wiring and the
green path. The red path had been run locally, which this repository does not
accept as proof of a pull request.

So #32 pinned `hono` to 4.12.33 and changed nothing else. The `audit` job
failed on the pull request at the `--audit-level=moderate` step, naming
GHSA-8j4g-w8fx-2239, its patched range and the full path through
`shadcn` → `@modelcontextprotocol/sdk`, and exited 1. Closed unmerged,
branch deleted, `main` untouched.

The same install exits 0 at `--audit-level=high`, which demonstrates T-0222's
floor change on one tree rather than in prose: an advisory the old floor could
not see is exactly what sat in the security tab for days.

Recorded with `method: ci` and the run URL, so the claim is the run rather
than the assertion.

Cards: T-0148

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D3LTdq3mzMAQ98rwBegGjU
@vercel

vercel Bot commented Aug 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
workfile Ready Ready Preview Aug 7, 2026 6:56pm
workfile-site Ready Ready Preview Aug 7, 2026 6:56pm

@illodev
illodev merged commit 94c9db1 into main Aug 7, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant