Skip to content
This repository was archived by the owner on Oct 1, 2026. It is now read-only.

[CTX-0080] feat: reconcile DevTools identity, platform, version, quality contracts - #144

Merged
Xuepoo merged 2 commits into
mainfrom
carryctx/ctx-0080
Sep 26, 2026
Merged

Xuepoo merged 2 commits into
mainfrom
carryctx/ctx-0080

Conversation

@Xuepoo

@Xuepoo Xuepoo commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Priority: P1 | Area: contracts | Labels: feat, P1 | Milestone: v0.1.0 | Task: CTX-0080

Reconciles DevTools identity, platform, version, and quality contracts to ensure fail-closed validation and comprehensive testing.

Changes

  • Add platform contract validation (Node.js, Bun, Deno runtime detection)
  • Add protocol boundary enforcement (strict DevTools Protocol version, method allowlists)
  • Add comprehensive validation layer (socket path, process existence, auth token format)
  • Extend workflow import with offline/pinned modes, budget tracking
  • Add required CI status checks tracking
  • Update quality gates to enforce contract validation
  • Add comprehensive test coverage for all new contracts

Testing

  • All existing tests pass (634 tests)
  • Added new test suites: platform-contract, protocol-boundary, validation, workflow-import-budget
  • Quality gates pass: format, lint, type-check, test, cargo-check

Closes #141

…ity contracts

- Add platform contract validation (Node.js, Bun, Deno runtime detection)
- Add protocol boundary enforcement (strict DevTools Protocol version, method allowlists)
- Add comprehensive validation layer (socket path, process existence, auth token format)
- Extend workflow import with offline/pinned modes, budget tracking
- Add required CI status checks tracking
- Update quality gates to enforce contract validation
- Add comprehensive test coverage for all new contracts

Closes #141
@Xuepoo Xuepoo added this to the v0.1.0 milestone Sep 26, 2026
@Xuepoo Xuepoo added feat feature P1 Priority P1 labels Sep 26, 2026
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Rust does not support the autobuild build mode in CodeQL.
Updated the workflow to use build-mode: none for Rust analysis,
and updated the platform contract test to expect two build-mode: none
occurrences (one for JavaScript/TypeScript+actions, one for Rust).
@Xuepoo
Xuepoo merged commit d16e244 into main Sep 26, 2026
9 checks passed
@Xuepoo
Xuepoo deleted the carryctx/ctx-0080 branch September 26, 2026 01:36
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

feat feature P1 Priority P1

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[P1/P2] Reconcile DevTools identity, platform, version, and quality contracts

2 participants