[workflow-audit] 3 unexplained change(s) on 2026-09-21

Open
#731 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Active
Tech stack
github-actions

Research direction

Start by reading .github/workflows/security-audit.yaml and the run summary, then inspect the diffs for commits 4d5cbb4, a20f69a, and b1ddc4f. Compare the workflow and audit files with the expected audit scope, and finish by accounting for each change or documenting the unresolved concern.

Written by the indexing model from the issue text.

Description

3 unexplained commit(s) in the audit window (.github/workflows/ .config/tend.yaml .github/audit/ .vscode/) since 2026-09-20T12:16:02Z.

Routine Renovate pin bumps and reproducible tend regenerations are
classified and omitted — see the run summary for what was skipped.
Everything below needs a human to account for it.

4d5cbb4 — fix(self-host): close two manage verify gaps, and stop duplicating two values
  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-09-20 23:15:37 -0700
  • Refs: main,remotes/origin/fix/drop-dead-pending-drag-button remotes/origin/fix/walkthrough-per-stream-decoder,remotes/origin/main remotes/origin/renovate/github-actions,remotes/origin/renovate/node-24.x remotes/origin/renovate/node-24.x-lockfile,remotes/origin/renovate/tauri-apps-cli-2.x-lockfile remotes/origin/specs-security-audit,remotes/origin/tend/update-workflows
  • Files:
    • .github/workflows/security-audit.yaml
  • View diff
a20f69a — Merge branch 'main' into daily/review-runs-35344301870
  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-09-20 23:44:18 -0700
  • Refs: main,remotes/origin/fix/drop-dead-pending-drag-button remotes/origin/fix/walkthrough-per-stream-decoder,remotes/origin/main remotes/origin/renovate/github-actions,remotes/origin/renovate/node-24.x remotes/origin/renovate/node-24.x-lockfile,remotes/origin/renovate/tauri-apps-cli-2.x-lockfile remotes/origin/tend/update-workflows
  • Files:
    • .github/workflows/security-audit.yaml
  • View diff
b1ddc4f — docs(security): correct the audited specs and give SELF_HOST.md a rationale
  • Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
  • Date: 2026-09-20 23:15:36 -0700
  • Refs: main,remotes/origin/fix/drop-dead-pending-drag-button remotes/origin/fix/walkthrough-per-stream-decoder,remotes/origin/main remotes/origin/renovate/github-actions,remotes/origin/renovate/node-24.x remotes/origin/renovate/node-24.x-lockfile,remotes/origin/renovate/tauri-apps-cli-2.x-lockfile remotes/origin/specs-security-audit,remotes/origin/tend/update-workflows
  • Files:
    • .github/audit/application-security.md
    • .github/audit/supply-chain.md
  • View diff
Dominant language
TypeScript
Stars
5
Forks
1
Avg merge
18h 26m
Merged PRs (30d)
229

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from diffplug/dormouse

All issues in diffplug/dormouse

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.