Skip to content
Open
Show file tree
Hide file tree
Changes from 12 commits
Commits
Show all changes
17 commits
Select commit Hold shift + click to select a range
d653dff
feat: add safe update mode enforcement for secrets
Copilot Apr 6, 2026
97077a4
refactor: use body secrets from generateYAML in safe update enforcement
Copilot Apr 6, 2026
62b451e
fix: improve log/error messages for safe update manifest failures
Copilot Apr 6, 2026
0f5648f
fix: rename to gh-aw-manifest and restrict safe-update to CLI only
Copilot Apr 7, 2026
c68b82c
chore: plan – extend safe-update to enforce action changes
Copilot Apr 7, 2026
9b72aff
feat: extend safe-update enforcement to also check action changes
Copilot Apr 7, 2026
eb89621
feat: enforce safe-update on first compile when no prior lock file ex…
Copilot Apr 7, 2026
ee3ad48
feat: add safe-update feature flag support and exempt actions/* org f…
Copilot Apr 7, 2026
e7c9a1c
feat: read lock file manifest from git HEAD to prevent local tampering
Copilot Apr 7, 2026
cf555d1
fix: use filepath.Join for path construction and fix %q double-quotin…
Copilot Apr 7, 2026
2896b9d
feat: gate ReadFileFromHEAD tamper prevention to dev mode only
Copilot Apr 7, 2026
48e2078
fix: add missing log message when lock file not found in filesystem (…
Copilot Apr 7, 2026
e73e17a
fix: address review comments — doc accuracy, path-traversal guard, lo…
Copilot Apr 7, 2026
f9994c5
test(integration): add safe-update integration tests for secret and a…
Copilot Apr 7, 2026
973a8e4
style: use 0o644 octal prefix for file permissions in integration tests
Copilot Apr 7, 2026
1732fe0
test(integration): add transitive import tests verifying manifest cap…
Copilot Apr 7, 2026
dd0b544
fix(tests): address code review - safe array bounds check in log stat…
Copilot Apr 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/workflows/ace-editor.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/agent-performance-analyzer.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/agent-persona-explorer.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/agentic-observability-kit.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/ai-moderator.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/api-consumption-report.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/archie.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/artifacts-summary.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/audit-workflows.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/auto-triage-issues.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/blog-auditor.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/bot-detection.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/brave.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/breaking-change-checker.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/changeset.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/ci-coach.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/ci-doctor.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/claude-code-user-docs-review.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions .github/workflows/cli-consistency-checker.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading
Loading