Skip to content

Sanitize public bundle provenance - #2

Merged
sftimeless merged 3 commits into
mainfrom
codex/public-bundle-forward-remediation
Sep 2, 2026
Merged

Sanitize public bundle provenance#2
sftimeless merged 3 commits into
mainfrom
codex/public-bundle-forward-remediation

Conversation

@sftimeless

Copy link
Copy Markdown
Member

Summary

  • replace private repository and SHA provenance with a public release version plus an immutable product-file digest
  • reduce public_surface.json to a strict positive allowlist
  • remove the private source path from fields.md while retaining all customer-facing limitations
  • update the release checker and checksums to enforce the sanitized boundary

Validation

  • release bundle checker: PASS (37 allowlisted files)
  • execute contract checker: PASS
  • keel-policy tests: 10 passed
  • keel-setup tests: 58 passed
  • shared tests: 15 passed
  • private/public product-file comparison: PASS
  • targeted private-vocabulary scan: zero hits
  • git diff --check: PASS

History and release boundary

This is a forward-only remediation. It does not rewrite public history, merge, deploy, certify, touch production, or publish a separate release.

@sftimeless
sftimeless merged commit b052696 into main Sep 2, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant