[workflow-audit] 2 unexplained change(s) on 2026-09-20

Open
#720 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
github-actions

Research direction

Review commits 215fc59 and eaad659 and their linked diffs first. Inspect .github/workflows/security-audit.yaml, .github/audit/application-security.md, and .github/audit/supply-chain.md, then compare them with the audit run summary; done means each change in the audit window is accounted for.

Written by the indexing model from the issue text.

Description

2 unexplained commit(s) in the audit window (.github/workflows/ .config/tend.yaml .github/audit/ .vscode/) since 2026-09-19T11:54:05Z.

Routine Renovate pin bumps and reproducible tend regenerations are
classified and omitted — see the run summary for what was skipped.
Everything below needs a human to account for it.

215fc59 — fix(self-host): close two manage verify gaps, and stop duplicating two values
  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-09-20 01:12:56 -0700
  • Refs: remotes/origin/specs-security-audit
  • Files:
    • .github/workflows/security-audit.yaml
  • View diff
eaad659 — docs(security): correct the audited specs and give SELF_HOST.md a rationale
  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-09-20 01:05:13 -0700
  • Refs: remotes/origin/specs-security-audit
  • Files:
    • .github/audit/application-security.md
    • .github/audit/supply-chain.md
  • View diff
Dominant language
TypeScript
Stars
5
Forks
1
Avg merge
18h 26m
Merged PRs (30d)
229

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from diffplug/dormouse

All issues in diffplug/dormouse

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.