Skip to content

specs: audit release, supply-chain, and published security contracts - #907

Merged
nedtwigg merged 6 commits into
spec-cleanup-public-docsfrom
spec-cleanup-delivery-security
Oct 2, 2026
Merged

nedtwigg merged 6 commits into
spec-cleanup-public-docsfrom
spec-cleanup-delivery-security

Conversation

@nedtwigg

@nedtwigg nedtwigg commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Correct release and audit claims against the shipped scripts, shorten the security overview, and move dependency inventories to their canonical registry. This preserves every public guarantee, accepted risk, and known gap, including the Windows storage gaps from the trimmed earlier PRs.

The specs now distinguish OS signing from updater signing, trusted workflow steps from the bot's environment, and attempted audit reporting from guaranteed reporting. Unfixed audit-reporter and ambient-runtime problems are recorded as current gaps. Executable code is unchanged; the dependency generator receives source comments only.

Validation: root build; 277 website tests and typecheck; spec/public-doc/e2e/loopback/deploy/xterm gates and mutation tests; release/audit tests also run locally (83 pass, 30 existing Windows failures reproduced on unchanged main: Unix modes, symlinks, and missing jq); Linux CI provides their full platform validation.

Stacked on #906. Argos failures are excluded per the requested review policy.

Trimmed in review. Reverted SECURITY.md, which GitHub shows to vulnerability reporters; it keeps only the added "Hosted" deployment. On /security, restored the Domains table that .github/audit/_preamble.md cites, the lint paragraph, and the specific guarantees the condensation had blurred. Restored the "STATUS is assigned in exactly two places" rule, the AGENTS.md lint section, and security-ci.md's "none escalates" summary.

🤖 Generated with Claude Code

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Deploying mouseterm with  Cloudflare Pages  Cloudflare Pages

Latest commit: 50cf59f
Status: ✅  Deploy successful!
Preview URL: https://36c0bb8b.mouseterm.pages.dev
Branch Preview URL: https://spec-cleanup-delivery-securi.mouseterm.pages.dev

View logs

@nedtwigg
nedtwigg added this pull request to stack #896 October 2, 2026 13:23
nedtwigg and others added 2 commits October 2, 2026 06:40
The condense pass cut text whose readers cannot follow a pointer:

- SECURITY.md, which GitHub shows to vulnerability reporters, became a
  link to security.md and lost the no-public-issue / no-email rule, what
  to include, and the description of the nightly audit and its failure
  issues.
- security.md (published at /security) lost the Domains table, so
  `.github/audit/_preamble.md`'s claim that it "names the spec each
  domain audits" was false; lost the `pnpm test` lint paragraph; and
  blurred concrete guarantees into vague ones: the two-digit pairing and
  one-time confirmation, the per-boot browser-pane token, the socket
  directory, the 256-bit setup credential, the end-to-end channel the
  Relay holds no keys for, and "two evasions in the window" (which became
  "can miss malicious changes").
- security-audit.md dropped the rule that STATUS is assigned in exactly
  two places, which security-audit.yaml still honors (the parse and the
  single escalation block).
- AGENTS.md lost which lints carry self-tests, the spec-lint-selftest and
  ps1-cmdlet-lint-selftest pointers, and the e2e-lint inventory.
- security-ci.md lost its summary that no tend secret escalates to main
  or a deployment secret.

Restore each from the base, keeping the PR's genuine corrections: the
Hosted intro and Hosted as a reporting deployment (now in SECURITY.md
too), the OSC 367 file-access caveat, the single Pocket device-
verification gap, the cargo-outside-pnpm-test note, the build and hosted
lines in AGENTS.md, and the deploy, supply-chain, and generate-deps.js
changes. The security-ci summary says "the four secrets below" rather
than base's "three", matching its table. Budgets ratcheted for the
restored text.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@nedtwigg
nedtwigg merged commit 5ce9132 into main Oct 2, 2026
22 checks passed
@nedtwigg
nedtwigg deleted the spec-cleanup-delivery-security branch October 2, 2026 15:45

This branch is waiting to be deployed

1 waiting deployment
hosted-preview — 50cf59f9 Waiting Oct 2, 2026 by nedtwigg via cleanup #766
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants