Skip to content

Audit fixes: test hermeticity, discovery guard, doc accuracy#33

Merged
karanb192 merged 1 commit into
mainfrom
hardening-2
Jul 19, 2026
Merged

Audit fixes: test hermeticity, discovery guard, doc accuracy#33
karanb192 merged 1 commit into
mainfrom
hardening-2

Conversation

@karanb192

Copy link
Copy Markdown
Owner

From the adversarial 6-dimension repo audit (6 confirmed findings):

  • standup-autopilot git test: isolate GIT_CONFIG_GLOBAL/SYSTEM so a
    contributor's commit.gpgsign=true can't fail the suite
  • format-code + auto-stage tests: spawn hooks with a temp HOME so runs
    stop appending noise to the user's real ~/.claude/hooks-logs
  • meta discovery guard: walk the whole repo, not just the two expected
    roots — an orphan *.test.js anywhere now fails the guard (verified
    both directions with a planted orphan)
  • format-code: valid-JSON null payload now falls through to {} exit 0
    like the other 7 hooks
  • README: notify-permission matcher row gains elicitation_dialog (the
    hook handles and recommends it); Testing section states the real
    formatter prerequisites instead of 'no dependencies'
  • (repo setting, no diff) GitHub private vulnerability reporting is now
    enabled, making SECURITY.md's only reporting channel actually work

From the adversarial 6-dimension repo audit (6 confirmed findings):
- standup-autopilot git test: isolate GIT_CONFIG_GLOBAL/SYSTEM so a
  contributor's commit.gpgsign=true can't fail the suite
- format-code + auto-stage tests: spawn hooks with a temp HOME so runs
  stop appending noise to the user's real ~/.claude/hooks-logs
- meta discovery guard: walk the whole repo, not just the two expected
  roots — an orphan *.test.js anywhere now fails the guard (verified
  both directions with a planted orphan)
- format-code: valid-JSON null payload now falls through to {} exit 0
  like the other 7 hooks
- README: notify-permission matcher row gains elicitation_dialog (the
  hook handles and recommends it); Testing section states the real
  formatter prerequisites instead of 'no dependencies'
- (repo setting, no diff) GitHub private vulnerability reporting is now
  enabled, making SECURITY.md's only reporting channel actually work
@karanb192
karanb192 merged commit de0d272 into main Jul 19, 2026
3 checks passed
@karanb192
karanb192 deleted the hardening-2 branch July 19, 2026 15:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant