Skip to content

Repair repository refresh trust boundaries - #75

Merged
erinepshovel-code merged 21 commits into
mainfrom
repair/repository-refresh-boundaries-20260923
Sep 25, 2026
Merged

erinepshovel-code merged 21 commits into
mainfrom
repair/repository-refresh-boundaries-20260923

Conversation

@erinepshovel-code

@erinepshovel-code erinepshovel-code commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Scope

Replay and complete the repository-refresh trust-boundary repair on current website authority.

  • reject private/inaccessible repository metadata before exact-head reads and forbid cached-document reuse after visibility loss;
  • preserve explicitly missing captured head identity as unavailable;
  • reject mismatched MSDMD repository identity;
  • bound and time-limit GitHub API/raw reads;
  • surface truncated recursive-tree discovery as incomplete evidence;
  • propagate transient document-read failures to same-head fallback rather than publishing partial live data;
  • resolve repository-relative Markdown images to exact-head raw bytes;
  • update live documentation provenance after refresh;
  • make SITREP refresh request MSDMD without unnecessary document projection;
  • append the required By the builder record.

Verification

Exact head 298d1bef62ec20d1c39b1c032f563d8a5ad31877 against base 64c5eb77b66c1eca56e9695518d29af3f1397191:

  • replayed from current main, 21 commits ahead / 0 behind;
  • full build/validate/test and browser/accessibility release gate passed;
  • Python, JavaScript/TypeScript, Actions, and CodeQL checks are terminal successful;
  • all review threads are resolved;
  • PR is mergeable.

CodeQL's remaining medium js/file-access-to-http result was manually audited as an intentional public GitHub projection boundary: the destination origin is hard-pinned/validated and only normalized public repository/head identifiers are sent. The finding thread is resolved with rationale and query-specific source annotation; no arbitrary file contents leave the process.

hmmm

Fresh Codex review could not run because the account code-review quota is exhausted. Exact-head manual diff audit plus the repository's complete hosted release/security gates were used instead.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-23T12:42:18.170156Z 81f4a19 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e515570fe0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/repository-public-projection.mjs

Copy link
Copy Markdown
Contributor Author

@codex review current head a48447a. Recheck the repaired visibility boundary and the new regressions; report any remaining P1/P2 findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a48447a71a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/repository-public-projection.mjs

Copy link
Copy Markdown
Contributor Author

@codex review current head 1df6a0b7f21237a0caa9275ce24c7de58d90af9f. Recheck the privacy-change path end to end: pinned visibility failure must not restore same-head cached documentation, the unavailable projection must expose no document bytes or head, and the page must label it unavailable. Report any remaining P1/P2 findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1df6a0b7f2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/repository-public-projection.mjs Outdated

Copy link
Copy Markdown
Contributor Author

@codex review current head 81f4a1967648b9e3dc12cad2daa9c4869327ed53. Recheck both privacy representations: explicit private metadata and inaccessible/deleted metadata returning 404. Neither may enter same-head document fallback; report any remaining P1/P2 findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep it up!

Reviewed commit: 81f4a19676

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@erinepshovel-code
erinepshovel-code force-pushed the repair/repository-refresh-boundaries-20260923 branch from 81f4a19 to 64c5eb7 Compare September 25, 2026 17:15
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

Copy link
Copy Markdown
Contributor Author

@codex review

Review exact head b5301cdeaf672def61f4ab3c90e8b9f71d9fd20c against base 64c5eb77b66c1eca56e9695518d29af3f1397191. This branch was replayed onto current main. Verify the privacy/cache boundary, explicit missing-head behavior, MSDMD repository identity check, current-main preservation, builder-journal transaction, and report any remaining P1/P2 findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

2 similar comments
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

2 similar comments
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

Comment thread tests/mcp-server.test.mjs Fixed
Comment thread tests/project-docs.test.mjs Fixed
Comment thread tests/project-docs.test.mjs Fixed
Comment thread scripts/repository-public-projection.mjs
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

1 similar comment
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@erinepshovel-code
erinepshovel-code merged commit 4244a86 into main Sep 25, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants