tend check: configuration drift on diffplug/dormouse
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 45/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- github, github-actions
- Área
- devops, documentation, security
Línea de trabajo
Start with tend check and the immutable-releases result, then review .github/workflows/release.yml and docs/specs/security-ci.md. An administrator must enable immutable releases; done means the setting is enabled for future releases, the check is expected to clear at the next release, and the security specification mentions the guarantee.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
tend check reports one FAIL on diffplug/dormouse. It needs repository-admin access, which the CI bot does not hold.
immutable-releases(FAIL): the newest release (v1.1.0) can be rewritten — a write-access account or bot can replace its assets.gh api repos/diffplug/dormouse --jq .immutable_releasesreturnsnull, so the setting has never been enabled. Fix istend check --fixrun by an admin (or Settings → General → "Immutable releases"). GitHub applies the setting only to releases published after it is enabled, so enabling it clears this check at the next release rather than retroactively forv1.1.0.
Every other check passes: branch-protection:main, bot-permission, tag-protection, environment, environment-deployments, credential-environments, secrets, claude-auth, repo-secret-allowlist. The credential-environments FAIL tracked in #339 is cleared.
Why this is not already covered by the release pipeline
.github/workflows/release.yml attests build provenance for the standalone and VS Code artifacts, which lets a consumer detect a substituted asset. Immutable releases is the complementary control: it stops the substitution at the API, so the attestation is not the only thing standing between a compromised write-access token and a rewritten v1.1.0 download. Tag rewriting is already blocked by the Tag operations ruleset (creation + update across ~ALL, bot bypass never); release assets are the remaining mutable surface on a published release.
docs/specs/security-ci.md does not currently mention the setting. Worth adding a row there once it is enabled, so the guarantee is stated where the audit reads it.
Last refreshed: 2026-09-22
- Lenguaje dominante
- TypeScript
- Estrellas
- 5
- Forks
- 1
- Merge medio
- 11 h 31 min
- PR fusionados (30 d)
- 362
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de diffplug/dormouse
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
diffplug/dormouse#912 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 3/5 1-2 días Aptitud para principiantes 38/100
diffplug/dormouse#1007 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 3/5 1-2 días Aptitud para principiantes 62/100
diffplug/dormouse#984 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
diffplug/dormouse#968 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 42/100
diffplug/dormouse#910 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de diffplug/dormouse
Issues similares
-
level/task reporter/qa type/bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
wazuh/wazuh-dashboard-plugins#9310 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
cybersemics/treecrdt#267 ·
-
Dificultad 1/5 1-3 horas Aptitud para principiantes 85/100
wiz-sec-public/backstage-plugin-wiz#16 · 1 comentario ·
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
solana-foundation/solana-com#2245 ·
Los mantenedores suelen responder en 1 día