Close T-0148 with the CI run that proved the audit gate fails - #33
Merged
Conversation
Its last criterion asked that a pull request prove the audit fails in CI, and #30 and #31 had only shown the job running and passing — the wiring and the green path. The red path had been run locally, which this repository does not accept as proof of a pull request. So #32 pinned `hono` to 4.12.33 and changed nothing else. The `audit` job failed on the pull request at the `--audit-level=moderate` step, naming GHSA-8j4g-w8fx-2239, its patched range and the full path through `shadcn` → `@modelcontextprotocol/sdk`, and exited 1. Closed unmerged, branch deleted, `main` untouched. The same install exits 0 at `--audit-level=high`, which demonstrates T-0222's floor change on one tree rather than in prose: an advisory the old floor could not see is exactly what sat in the security tab for days. Recorded with `method: ci` and the run URL, so the claim is the run rather than the assertion. Cards: T-0148 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01D3LTdq3mzMAQ98rwBegGjU
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Record-only: T-0148 moves to
donewithmethod: ciand the run URL.Its last criterion asked that a pull request prove the audit fails in CI. #30 and #31 had shown the
auditjob running and passing — the wiring and the green path — and the red path had only been run locally, which this repo does not accept as proof of a pull request.So #32 pinned
honoto 4.12.33 and nothing else. The job failed at the--audit-level=moderatestep naming GHSA-8j4g-w8fx-2239, its patched range and the path throughshadcn→@modelcontextprotocol/sdk, exit 1:https://github.com/illodev/workfile/actions/runs/31208898683/job/92966664406
Closed unmerged, branch deleted,
mainuntouched.The same install exits 0 at
--audit-level=high, which demonstrates #31's floor change on one tree rather than in prose — an advisory the old floor could not see is exactly what sat in the security tab for days.🤖 Generated with Claude Code
https://claude.ai/code/session_01D3LTdq3mzMAQ98rwBegGjU