Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

tend check: configuration drift on diffplug/dormouse

Cerrado
#701 1 comentario 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
2/5
Tiempo estimado
1-3 horas
Aptitud para principiantes
45/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
github, github-actions

Línea de trabajo

Start with tend check and the immutable-releases result, then review .github/workflows/release.yml and docs/specs/security-ci.md. An administrator must enable immutable releases; done means the setting is enabled for future releases, the check is expected to clear at the next release, and the security specification mentions the guarantee.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

tend check reports one FAIL on diffplug/dormouse. It needs repository-admin access, which the CI bot does not hold.

  • immutable-releases (FAIL): the newest release (v1.1.0) can be rewritten — a write-access account or bot can replace its assets. gh api repos/diffplug/dormouse --jq .immutable_releases returns null, so the setting has never been enabled. Fix is tend check --fix run by an admin (or Settings → General → "Immutable releases"). GitHub applies the setting only to releases published after it is enabled, so enabling it clears this check at the next release rather than retroactively for v1.1.0.

Every other check passes: branch-protection:main, bot-permission, tag-protection, environment, environment-deployments, credential-environments, secrets, claude-auth, repo-secret-allowlist. The credential-environments FAIL tracked in #339 is cleared.

Why this is not already covered by the release pipeline

.github/workflows/release.yml attests build provenance for the standalone and VS Code artifacts, which lets a consumer detect a substituted asset. Immutable releases is the complementary control: it stops the substitution at the API, so the attestation is not the only thing standing between a compromised write-access token and a rewritten v1.1.0 download. Tag rewriting is already blocked by the Tag operations ruleset (creation + update across ~ALL, bot bypass never); release assets are the remaining mutable surface on a published release.

docs/specs/security-ci.md does not currently mention the setting. Worth adding a row there once it is enabled, so the guarantee is stated where the audit reads it.

Last refreshed: 2026-09-22

Lenguaje dominante
TypeScript
Estrellas
5
Forks
1
Merge medio
11 h 31 min
PR fusionados (30 d)
362

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de diffplug/dormouse

Todos los issues de diffplug/dormouse

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.