[workflow-audit] 5 unexplained change(s) on 2026-09-18
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 25/100
- Issue type
- Bug
- Clarity
- Needs clarification
- Activity status
- Active
- Tech stack
- github-actions
- Domain
- ci-cd
Research direction
Start with .github/workflows/security-audit.yaml and .github/audit/orchestrator.md, then review the linked commit diffs and the audit run summary. Determine how each of the five commits should be accounted for; completion requires the unexplained changes to have an explicit explanation or follow-up.
Written by the indexing model from the issue text.
Description
5 unexplained commit(s) in the audit window (.github/workflows/ .config/tend.yaml .github/audit/ .vscode/) since 2026-09-17T12:33:38Z.
Routine Renovate pin bumps and reproducible tend regenerations are
classified and omitted — see the run summary for what was skipped.
Everything below needs a human to account for it.
852dd31 — Name the third report marker, and keep a cut-off FAIL a FAIL locally
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- Date: 2026-09-17 16:32:26 +0000
- Refs: main,remotes/origin/fix/audit-fragment-incremental-35205193090 remotes/origin/main,remotes/origin/preserve-dir
- Files:
.github/workflows/security-audit.yaml
- View diff
8c03ebf — Merge remote-tracking branch 'origin/main' into fix/audit-wait-loop-returns
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-09-17 09:20:38 -0700
- Refs: main,remotes/origin/main remotes/origin/preserve-dir
- Files:
.github/workflows/security-audit.yaml
- View diff
8efd0e9 — fix(security-audit): mark a cut-off fragment in the no-report fallback
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- Date: 2026-09-17 17:14:32 +0000
- Refs: main,remotes/origin/main remotes/origin/preserve-dir
- Files:
.github/workflows/security-audit.yaml
- View diff
c21beb6 — Merge origin/main (#682) into fix/audit-wait-loop-returns
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-09-17 09:47:07 -0700
- Refs: main,remotes/origin/main remotes/origin/preserve-dir
- Files:
.github/audit/orchestrator.md.github/workflows/security-audit.yaml
- View diff
cb251fa — fix(security-audit): publish the fragments when the merge never ran
- Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- Date: 2026-09-17 16:58:41 +0000
- Refs: main,remotes/origin/main remotes/origin/preserve-dir
- Files:
.github/workflows/security-audit.yaml
- View diff
- Dominant language
- TypeScript
- Stars
- 5
- Forks
- 1
- Avg merge
- 17h 45m
- Merged PRs (30d)
- 235
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from diffplug/dormouse
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
-
security-audit-failure
Difficulty 5/5 Over a week Newbie friendliness 25/100
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
-
Difficulty 4/5 3-5 days Newbie friendliness 25/100
All issues in diffplug/dormouse
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
bug v2
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
modelcontextprotocol/inspector#2458 · 1 comment ·
-
Difficulty 1/5 Under an hour Newbie friendliness 75/100
railmapgen/rmp-gallery#4068 ·
-
Mend: dependency security vulnerability status: needs triage 🕵️♀️
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
carbon-design-system/ibm-products#9907 ·