23 unexplained commit(s) in the audit window (.github/workflows/ .config/tend.yaml .github/audit/ .vscode/) since 2026-09-03T12:03:48Z.
Renovate pin bumps, reproducible tend regenerations, clean merges, and
commits first pushed by an admin are classified and omitted — see the
run summary for what was skipped.
Everything below needs a human to account for it.
1c6b7b0 — fix(security-audit): lift the deciding lines above the truncation point
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (branch_creation)
- Date: 2026-09-23 13:17:37 +0000
- Refs: remotes/origin/fix/audit-lift-deciding-lines
- Files:
.github/workflows/security-audit.yaml
- View diff
1ec1323 — docs(security-local): exclude the Relay on what it admits, not on where it binds
- Author: dormouse-bot dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (push)
- Date: 2026-09-15 17:58:47 +0000
- Refs: main,remotes/origin/alert-defer-default-on remotes/origin/alert-dismiss-simplify,remotes/origin/alert-drop-ringseq remotes/origin/alert-retire-bell,remotes/origin/alert-ring-flash remotes/origin/alert-spec-compress,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers
- Files:
.github/audit/application-security.md
- View diff
2128c0d — fix(security-audit): end each orchestrator wait call before the Bash cap
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (branch_creation)
- Date: 2026-09-11 10:04:14 +0000
- Refs: main,remotes/origin/alert-defer-default-on remotes/origin/alert-dismiss-simplify,remotes/origin/alert-drop-ringseq remotes/origin/alert-retire-bell,remotes/origin/alert-ring-flash remotes/origin/alert-spec-compress,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers
- Files:
.github/audit/orchestrator.md
- View diff
2b16536 — chore(deps): update github-actions (#636)
- Author: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> (self-declared; not proof of origin)
- First pushed by: nedtwigg (pr_merge)
- Date: 2026-09-14 15:01:16 -0700
- Refs: main,remotes/origin/alert-defer-default-on remotes/origin/alert-dismiss-simplify,remotes/origin/alert-drop-ringseq remotes/origin/alert-retire-bell,remotes/origin/alert-ring-flash remotes/origin/alert-spec-compress,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers
- Files:
.github/workflows/chromatic.yml
.github/workflows/security-audit.yaml
.github/workflows/tend-mention.yaml
.github/workflows/tend-notifications.yaml
.github/workflows/workflow-audit.yaml
- View diff
340b980 — Keep provisioning obligations out of the FAIL IF list so the audit can decide (#748)
- Author: dormouse-bot ned.twigg+dormouse-bot@diffplug.com (self-declared; not proof of origin)
- First pushed by: nedtwigg (pr_merge)
- Date: 2026-09-23 09:58:07 -0700
- Refs: main,remotes/origin/browser-lifecycle remotes/origin/browser-providers,remotes/origin/browser-quick-wins remotes/origin/fix/audit-lift-deciding-lines,remotes/origin/fix/hosted-production-spawn remotes/origin/fix/noise-header-import-sites,remotes/origin/fix/tool-host-test-user-config remotes/origin/keyboard-input-guards,remotes/origin/main
- Files:
.github/audit/_preamble.md
.github/audit/hosted.md
- View diff
3ad55ff — Address review: anchor the delegate deadline to the caller's own
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (push)
- Date: 2026-09-18 13:57:49 +0000
- Refs: main,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers remotes/origin/browser-quick-wins,remotes/origin/daily/review-runs-35729571305 remotes/origin/fix/audit-lift-deciding-lines,remotes/origin/fix/hosted-production-spawn remotes/origin/fix/noise-header-import-sites,remotes/origin/fix/tool-host-test-user-config
- Files:
.github/audit/_preamble.md
- View diff
3d96a13 — Have audit domains append findings as they determine them
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (branch_creation)
- Date: 2026-09-17 10:32:25 +0000
- Refs: main,remotes/origin/alert-defer-default-on remotes/origin/alert-dismiss-simplify,remotes/origin/alert-drop-ringseq remotes/origin/alert-retire-bell,remotes/origin/alert-ring-flash remotes/origin/alert-spec-compress,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers
- Files:
.github/audit/_preamble.md
.github/audit/orchestrator.md
.github/workflows/security-audit.yaml
- View diff
4b8b565 — chore: update tend workflows (0.3.1 → 0.3.2)
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (branch_creation)
- Date: 2026-09-24 11:49:22 +0000
- Refs: main,remotes/origin/browser-lifecycle remotes/origin/browser-providers,remotes/origin/browser-quick-wins remotes/origin/fix/hosted-production-spawn,remotes/origin/fix/noise-header-import-sites remotes/origin/fix/tool-host-test-user-config,remotes/origin/keyboard-input-guards remotes/origin/main,remotes/origin/playwright-browser
- Files:
.config/tend.yaml
.github/workflows/tend-ci-fix.yaml
.github/workflows/tend-mention-relay.yaml
.github/workflows/tend-mention.yaml
.github/workflows/tend-nightly.yaml
.github/workflows/tend-notifications.yaml
.github/workflows/tend-review-runs.yaml
.github/workflows/tend-review.yaml
.github/workflows/tend-triage.yaml
.github/workflows/tend-weekly.yaml
- View diff
573ea8b — Keep the lift from silencing the step, and cap only the findings
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (push)
- Date: 2026-09-23 13:33:37 +0000
- Refs: remotes/origin/fix/audit-lift-deciding-lines
- Files:
.github/workflows/security-audit.yaml
- View diff
5b5fad7 — Action the draft review: teach §4 the sentinel, tolerate trailing blanks
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (push)
- Date: 2026-09-17 10:42:12 +0000
- Refs: main,remotes/origin/alert-defer-default-on remotes/origin/alert-dismiss-simplify,remotes/origin/alert-drop-ringseq remotes/origin/alert-retire-bell,remotes/origin/alert-ring-flash remotes/origin/alert-spec-compress,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers
- Files:
.github/audit/orchestrator.md
.github/workflows/security-audit.yaml
- View diff
6fa9f90 — docs(security-local): widen the loopback derivation scope to match the set it names
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (push)
- Date: 2026-09-13 17:58:41 +0000
- Refs: main,remotes/origin/alert-defer-default-on remotes/origin/alert-dismiss-simplify,remotes/origin/alert-drop-ringseq remotes/origin/alert-retire-bell,remotes/origin/alert-ring-flash remotes/origin/alert-spec-compress,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers
- Files:
.github/audit/application-security.md
- View diff
811ddb6 — ci(security-audit): raise the orchestrator's wait deadline to 32 minutes
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (branch_creation)
- Date: 2026-09-11 10:04:22 +0000
- Refs: main,remotes/origin/alert-defer-default-on remotes/origin/alert-dismiss-simplify,remotes/origin/alert-drop-ringseq remotes/origin/alert-retire-bell,remotes/origin/alert-ring-flash remotes/origin/alert-spec-compress,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers
- Files:
.github/audit/orchestrator.md
.github/workflows/security-audit.yaml
- View diff
852dd31 — Name the third report marker, and keep a cut-off FAIL a FAIL locally
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (push)
- Date: 2026-09-17 16:32:26 +0000
- Refs: main,remotes/origin/alert-defer-default-on remotes/origin/alert-dismiss-simplify,remotes/origin/alert-drop-ringseq remotes/origin/alert-retire-bell,remotes/origin/alert-ring-flash remotes/origin/alert-spec-compress,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers
- Files:
.github/workflows/security-audit.yaml
- View diff
8efd0e9 — fix(security-audit): mark a cut-off fragment in the no-report fallback
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (push)
- Date: 2026-09-17 17:14:32 +0000
- Refs: main,remotes/origin/alert-defer-default-on remotes/origin/alert-dismiss-simplify,remotes/origin/alert-drop-ringseq remotes/origin/alert-retire-bell,remotes/origin/alert-ring-flash remotes/origin/alert-spec-compress,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers
- Files:
.github/workflows/security-audit.yaml
- View diff
962d86a — Make the ci-and-secrets audit enumerate environments from the API
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (branch_creation)
- Date: 2026-09-15 12:34:36 +0000
- Refs: main,remotes/origin/alert-defer-default-on remotes/origin/alert-dismiss-simplify,remotes/origin/alert-drop-ringseq remotes/origin/alert-retire-bell,remotes/origin/alert-ring-flash remotes/origin/alert-spec-compress,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers
- Files:
.github/audit/ci-and-secrets.md
- View diff
b34037c — fix(security-audit): lift the deciding lines above the truncation point (#764)
- Author: dormouse-bot ned.twigg+dormouse-bot@diffplug.com (self-declared; not proof of origin)
- First pushed by: nedtwigg (pr_merge)
- Date: 2026-09-23 10:03:45 -0700
- Refs: main,remotes/origin/browser-lifecycle remotes/origin/browser-providers,remotes/origin/browser-quick-wins remotes/origin/fix/hosted-production-spawn,remotes/origin/fix/noise-header-import-sites remotes/origin/fix/tool-host-test-user-config,remotes/origin/keyboard-input-guards remotes/origin/main,remotes/origin/playwright-browser
- Files:
.github/workflows/security-audit.yaml
- View diff
c63b312 — Tell a delegating audit domain to block, not end its turn
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (branch_creation)
- Date: 2026-09-18 12:37:30 +0000
- Refs: main,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers remotes/origin/browser-quick-wins,remotes/origin/daily/review-runs-35729571305 remotes/origin/fix/audit-lift-deciding-lines,remotes/origin/fix/hosted-production-spawn remotes/origin/fix/noise-header-import-sites,remotes/origin/fix/tool-host-test-user-config
- Files:
.github/audit/_preamble.md
.github/audit/orchestrator.md
- View diff
ca3a4ab — fix(security-audit): keep every wait call's tail unambiguous
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (push)
- Date: 2026-09-11 10:16:49 +0000
- Refs: main,remotes/origin/alert-defer-default-on remotes/origin/alert-dismiss-simplify,remotes/origin/alert-drop-ringseq remotes/origin/alert-retire-bell,remotes/origin/alert-ring-flash remotes/origin/alert-spec-compress,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers
- Files:
.github/audit/orchestrator.md
.github/workflows/security-audit.yaml
- View diff
cb251fa — fix(security-audit): publish the fragments when the merge never ran
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (push)
- Date: 2026-09-17 16:58:41 +0000
- Refs: main,remotes/origin/alert-defer-default-on remotes/origin/alert-dismiss-simplify,remotes/origin/alert-drop-ringseq remotes/origin/alert-retire-bell,remotes/origin/alert-ring-flash remotes/origin/alert-spec-compress,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers
- Files:
.github/workflows/security-audit.yaml
- View diff
d4ca2c0 — Return the CLI's exit code from dor.cmd on Windows
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (branch_creation)
- Date: 2026-09-24 11:57:36 +0000
- Refs: main,remotes/origin/fix/hosted-production-spawn remotes/origin/fix/noise-header-import-sites,remotes/origin/fix/tool-host-test-user-config remotes/origin/keyboard-input-guards,remotes/origin/main remotes/origin/renovate/cargo,remotes/origin/renovate/kysely-0.x-lockfile remotes/origin/renovate/playwright-core-1.x,remotes/origin/renovate/tauri-apps-plugin-updater-2.x-lockfile
- Files:
- View diff
e0a9399 — fix(security-audit): name the wait call's output as the decision input
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (push)
- Date: 2026-09-11 10:35:27 +0000
- Refs: main,remotes/origin/alert-defer-default-on remotes/origin/alert-dismiss-simplify,remotes/origin/alert-drop-ringseq remotes/origin/alert-retire-bell,remotes/origin/alert-ring-flash remotes/origin/alert-spec-compress,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers
- Files:
.github/audit/orchestrator.md
.github/workflows/security-audit.yaml
- View diff
e5a1582 — Address review: bound the delegate wait, and align the third placeholder
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (push)
- Date: 2026-09-18 12:48:58 +0000
- Refs: main,remotes/origin/audit-external-obligations remotes/origin/browser-lifecycle,remotes/origin/browser-providers remotes/origin/browser-quick-wins,remotes/origin/daily/review-runs-35729571305 remotes/origin/fix/audit-lift-deciding-lines,remotes/origin/fix/hosted-production-spawn remotes/origin/fix/noise-header-import-sites,remotes/origin/fix/tool-host-test-user-config
- Files:
.github/audit/_preamble.md
.github/workflows/security-audit.yaml
- View diff
f1888e9 — Keep provisioning obligations out of the FAIL IF list so the audit can decide
- Author: dormouse-bot dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- First pushed by: dormouse-bot (branch_creation)
- Date: 2026-09-22 10:14:25 +0000
- Refs: remotes/origin/audit-external-obligations
- Files:
.github/audit/_preamble.md
- View diff
23 unexplained commit(s) in the audit window (
.github/workflows/ .config/tend.yaml .github/audit/ .vscode/) since2026-09-03T12:03:48Z.Renovate pin bumps, reproducible tend regenerations, clean merges, and
commits first pushed by an admin are classified and omitted — see the
run summary for what was skipped.
Everything below needs a human to account for it.
1c6b7b0— fix(security-audit): lift the deciding lines above the truncation point.github/workflows/security-audit.yaml1ec1323— docs(security-local): exclude the Relay on what it admits, not on where it binds.github/audit/application-security.md2128c0d— fix(security-audit): end each orchestrator wait call before the Bash cap.github/audit/orchestrator.md2b16536— chore(deps): update github-actions (#636).github/workflows/chromatic.yml.github/workflows/security-audit.yaml.github/workflows/tend-mention.yaml.github/workflows/tend-notifications.yaml.github/workflows/workflow-audit.yaml340b980— Keep provisioning obligations out of the FAIL IF list so the audit can decide (#748).github/audit/_preamble.md.github/audit/hosted.md3ad55ff— Address review: anchor the delegate deadline to the caller's own.github/audit/_preamble.md3d96a13— Have audit domains append findings as they determine them.github/audit/_preamble.md.github/audit/orchestrator.md.github/workflows/security-audit.yaml4b8b565— chore: update tend workflows (0.3.1 → 0.3.2).config/tend.yaml.github/workflows/tend-ci-fix.yaml.github/workflows/tend-mention-relay.yaml.github/workflows/tend-mention.yaml.github/workflows/tend-nightly.yaml.github/workflows/tend-notifications.yaml.github/workflows/tend-review-runs.yaml.github/workflows/tend-review.yaml.github/workflows/tend-triage.yaml.github/workflows/tend-weekly.yaml573ea8b— Keep the lift from silencing the step, and cap only the findings.github/workflows/security-audit.yaml5b5fad7— Action the draft review: teach §4 the sentinel, tolerate trailing blanks.github/audit/orchestrator.md.github/workflows/security-audit.yaml6fa9f90— docs(security-local): widen the loopback derivation scope to match the set it names.github/audit/application-security.md811ddb6— ci(security-audit): raise the orchestrator's wait deadline to 32 minutes.github/audit/orchestrator.md.github/workflows/security-audit.yaml852dd31— Name the third report marker, and keep a cut-off FAIL a FAIL locally.github/workflows/security-audit.yaml8efd0e9— fix(security-audit): mark a cut-off fragment in the no-report fallback.github/workflows/security-audit.yaml962d86a— Make the ci-and-secrets audit enumerate environments from the API.github/audit/ci-and-secrets.mdb34037c— fix(security-audit): lift the deciding lines above the truncation point (#764).github/workflows/security-audit.yamlc63b312— Tell a delegating audit domain to block, not end its turn.github/audit/_preamble.md.github/audit/orchestrator.mdca3a4ab— fix(security-audit): keep every wait call's tail unambiguous.github/audit/orchestrator.md.github/workflows/security-audit.yamlcb251fa— fix(security-audit): publish the fragments when the merge never ran.github/workflows/security-audit.yamld4ca2c0— Return the CLI's exit code from dor.cmd on Windows.github/workflows/ci.ymle0a9399— fix(security-audit): name the wait call's output as the decision input.github/audit/orchestrator.md.github/workflows/security-audit.yamle5a1582— Address review: bound the delegate wait, and align the third placeholder.github/audit/_preamble.md.github/workflows/security-audit.yamlf1888e9— Keep provisioning obligations out of the FAIL IF list so the audit can decide.github/audit/_preamble.md