chore(restack): adopt protected auth baseline into SIGINT lifecycle repair - #304
Conversation
* fix(auth): fail closed without write-capable admin on public bind * fix(auth): reject unusable bootstrap credentials * fix(auth): reject header-ambiguous admin secrets * docs(security): record research redistribution assessment * test(auth): strengthen strict admin-token properties * test(auth): mirror strict admin-token rejection in fuzz target * test(auth): keep fuzz role semantics in sync * test(auth): property-check credential and RBAC boundary * test(auth): exercise fuzz invariants for arbitrary bytes * fix(auth): align health and write denial auth semantics * test(auth): reject fixed smoke administrator credential * fix(auth): mint ephemeral smoke administrator credential * docs(security): preserve fail-closed auth traceability * test(auth): bind smoke token generation to forwarding * docs(auth): retain redistributable NIST SSDF evidence * docs(auth): preserve external-secret deployment lifecycle after restack * docs(security): reconcile NIST artifact provenance --------- Co-authored-by: OpenAI Codex <codex@openai.com>
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Non-force adoption of protected
main@f8260f1e03836039ff9463dd99fa982e4e270c4b(#155) into Draft #245 after protected main advanced froma52ccd0a24a727d9349bb32def7713882d8cad1e. Preserve the SIGINT lifecycle/research delta and treat all predecessor workflow/review evidence as historical after integration. Merge only if GitHub reports the reverse-direction restack mechanically conflict-free.