[workflow-audit] 3 unexplained change(s) on 2026-09-22
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
Research direction
Start with the workflow-audit run summary and the three linked commit diffs. Review .github/audit/application-security.md, .github/audit/_preamble.md, .github/audit/hosted.md, .github/audit/orchestrator.md, and .github/workflows/security-audit.yaml in the context of their listed refs. Done means each unexplained commit has a documented human account or an explicit audit decision.
Written by the indexing model from the issue text.
Description
3 unexplained commit(s) in the audit window (.github/workflows/ .config/tend.yaml .github/audit/ .vscode/) since 2026-09-21T14:00:40Z.
Routine Renovate pin bumps and reproducible tend regenerations are
classified and omitted — see the run summary for what was skipped.
Everything below needs a human to account for it.
dac9993 — Verify vendored pgstencil provenance and defer its code audit to pgstencil
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-09-21 17:39:09 -0700
- Refs: remotes/origin/hosted-audit-domain,remotes/origin/pgstencil-provenance
- Files:
.github/audit/application-security.md
- View diff
f1888e9 — Keep provisioning obligations out of the FAIL IF list so the audit can decide
- Author: dormouse-bot dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
- Date: 2026-09-22 10:14:25 +0000
- Refs: remotes/origin/audit-external-obligations
- Files:
.github/audit/_preamble.md
- View diff
fc56b46 — Split Hosted accounts into a fourth audit domain
- Author: Ned Twigg ned.twigg@diffplug.com (self-declared; not proof of origin)
- Date: 2026-09-21 17:39:13 -0700
- Refs: remotes/origin/hosted-audit-domain
- Files:
.github/audit/application-security.md.github/audit/hosted.md.github/audit/orchestrator.md.github/workflows/security-audit.yaml
- View diff
- Dominant language
- TypeScript
- Stars
- 5
- Forks
- 1
- Avg merge
- 17h 45m
- Merged PRs (30d)
- 235
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from diffplug/dormouse
-
security-audit-failure
Difficulty 5/5 Over a week Newbie friendliness 25/100
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
-
Difficulty 4/5 3-5 days Newbie friendliness 25/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 45/100
All issues in diffplug/dormouse
Similar issues
-
clawsweeper:linked-pr-open clawsweeper:no-new-fix-pr clawsweeper:source-repro impact:message-loss issue-rating: 🦞 diamond lobster maturity:stable P2
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Eynzof/Hermes-CN-Desktop#616 ·
-
ZCode 3.14.3 に対応する Open
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
supermomonga/zcode-acp#24 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
growthbook/growthbook#7100 ·
-
triage
Difficulty 1/5 1-3 hours Newbie friendliness 88/100