Skip to content

Adopt the shared Foundation Dagger guard - #34

Merged
hseshadr merged 1 commit into
mainfrom
codex/privacy-core-central-dagger-20260829
Aug 29, 2026
Merged

Adopt the shared Foundation Dagger guard#34
hseshadr merged 1 commit into
mainfrom
codex/privacy-core-central-dagger-20260829

Conversation

@hseshadr

Copy link
Copy Markdown
Owner

TL;DR: Pin the central Foundation Lego at 068c3c08 and bind the caller snapshot to the exact public commit before any product or security work.

What changed:

  • require ci(commit_sha) and run Foundation source binding plus guard first
  • consolidate push, pull request, manual, and Monday security ingress into the protected Dagger workflow
  • keep the source-free npm OIDC release candidate and publisher byte-identical
  • document the current central npm-publisher gap and ownership boundary

Verification:

  • Python quality: Ruff, format, strict mypy, Xenon A, 15 tests
  • Product gate: 139 tests, 100% core coverage, 2 Playwright tests, build
  • Dagger: develop/schema, quality, dependency audit, actionlint workflow audit, 57-commit secret scan
  • Independent review: Ready Yes, no findings

@hseshadr
hseshadr merged commit 27f1322 into main Aug 29, 2026
2 checks passed
@hseshadr
hseshadr deleted the codex/privacy-core-central-dagger-20260829 branch August 29, 2026 22:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant