Bump webfactory/ssh-agent from 0.9.0 to 0.9.1 - #4
Merged
hyperpolymath merged 3 commits intoDec 29, 2025
Merged
Conversation
Bumps [webfactory/ssh-agent](https://github.com/webfactory/ssh-agent) from 0.9.0 to 0.9.1. - [Release notes](https://github.com/webfactory/ssh-agent/releases) - [Changelog](https://github.com/webfactory/ssh-agent/blob/master/CHANGELOG.md) - [Commits](webfactory/ssh-agent@dc588b6...a6f90b1) --- updated-dependencies: - dependency-name: webfactory/ssh-agent dependency-version: 0.9.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
hyperpolymath
deleted the
dependabot/github_actions/webfactory/ssh-agent-0.9.1
branch
December 29, 2025 08:52
hyperpolymath
added a commit
that referenced
this pull request
Jun 16, 2026
#505) ## What Adds a `rustls-webpki` version detector to the existing Cargo.lock rule block in `lib/rules/rules.ex` (same pattern as `ring`, `yamux`, `atty`), plus a fix suggestion in `security_errors.ex`. - Matches `rustls-webpki` `0.101.*`, `0.102.*`, `0.103.0–0.103.12`; severity **HIGH**. - **GHSA-82j2-j2ch-gfr8** == **RUSTSEC-2026-0104** (CVSS 7.5, CWE-125, DoS via panic on malformed CRL BIT STRING). Fixed `0.103.13`. - **Non-auto-fixable** (not added to `@auto_fixable`) → security findings go to manual review. - Auto-wired: `scan_file` already runs the Cargo.lock branch, so no orchestration change is needed for this detector. ## Why Closes the **detection gap** for the transitive/lockfile-only class of advisories that Dependabot frequently will **not** auto-PR — the exact class that left `hyperpolymath/007` Dependabot alert #4 (issue #16) open. Part of the **P0 estate dependency-security control-plane** completion (baseline: `dev-notes/2026-06-16-estate-dependency-security-control-plane.md`). ## Validation - Elixir parse-check passes on both files. Full `mix compile`/CI will confirm. - Commit ssh-signed; branch cut from fresh `origin/main`. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
hyperpolymath
added a commit
that referenced
this pull request
Sep 27, 2026
… toolchain policy (21 issues fixed, 3 filed) (#867) Addresses the open issue set of `hyperpolymath/hypatia` in line with `rsr-template-repo` and `standards`, plus items needing immediate attention. One commit (`30e6d14`, five logical waves), 21 issues fixed/resolved, 3 new issues filed from findings, everything else triaged below. > **Note on issue comments:** the GitHub integration used here can create issues but is refused `issue comment` / `issue close` (HTTP 403 "Resource not accessible by integration"). Per-issue dispositions live in this body instead; `Closes #…` keywords below will close the resolved set on merge. ## Wave 1 — CI truth - **#841** — `--locked` now passed on every test/check job (`cargo` invocations across tests.yml, ci.yml, verify-proofs.yml, abi-codegen-drift.yml, batch-security-scan). - **#814** — real cause of red `cargo test --workspace` is the unsatisfiable `testcontainers ^0.28` vs `testcontainers-modules ^0.15` pair (not "network egress"); versions made satisfiable and DEBT-REGISTER CI-1's cause attribution corrected. - **#847–#851** — `security-policy.yml` consolidated to one scan tier with a `security-status` aggregator gating `Fail on critical security findings`; TruffleHog Gates A/B (verified-only off + historical scan); audit jobs keep and report their findings; container-scan joins the aggregator; scanner image pinned by explicit tag (`latest` removed). Decision record + per-step manifest at the top of the workflow. ## Wave 2 — runtime safety - **#857** — `RateLimiterTest` "tracks active bots" flake: tests now own named instances via `start_supervised!` (no sleeps); the drain crasher (`finding.type` KeyError on string-keyed maps) cannot take the limiter down (try/rescue/catch on dispatch; `check_internal/2` mirrors the full check incl. burst); crash-isolation regression test proves owned stats survive `GenServer.whereis(RateLimiter)` being killed. - **#853** — CI-dead `integration/` compose tier deleted. ## Wave 3 — proofs - **#820** — `verify-proofs.yml` + `abi-codegen-drift.yml`: single-prefix Idris2 bootstrap (`make install PREFIX="$HOME/.idris2"`, no sudo), cache key `-3`, PATH export, measurement step printing `idris2 --prefix/--libdir` + support-lib layout. The abi repair step is retained with a sequencing comment: delete it only after a green `-3` run prints "support installation already complete". - **#816** — `scripts/check-proof-status.sh` (new): PROOF-STATUS rows named in docs must exist; Property identifiers must match. Green on tree ("files named 27, identifiers checked 7, mismatches 0"); mutants killed both directions (renamed identifier → red; doc pointing at nonexistent file → red); `proof-status` job in verify-proofs.yml. - **#831** — `scripts/check-trusted-base.sh` (new): zero escape hatches outside `test/soundness/fixtures/`. Tree measured 2026-09-26 (marker files = `RuleEngine.idr` comments + 6 fixtures; 0 assert_total/postulate/%hint/native_decide/admit in code). Run: "fixture=19 allowed=1 comment=1 debt=0"; mutant killed (`believe_me` planted in `verify/src/PipelineState.idr` → DEBT red). `docs/proof-debt.adoc` counts re-derived (6, obj_magic was missing); `AFFIRMATION.adoc` claim scoped "outside test/soundness/fixtures/". `check-trusted-base` job in verify-proofs.yml (5 jobs now: type-check, lake-build, tlc, proof-status, check-trusted-base). ## Wave 4 — toolchain & policy - **#832** — `mise.toml` no longer provisions python/denojs or the Python-only toolchain (pip/black/isort/ruff/pytest, `PYTHON*` env); `language-blockers.yml` now enforces LANGUAGE-POLICY (Deno manifests banned; TS/ReScript sources banned — whole-tree, measured 0; banned runtimes cannot silently return to `mise.toml`) instead of its inverse ("Use Deno instead"). The old TS gate was structurally broken (depth-1 checkout vs `git diff HEAD~1`) and inverted (it blocked `bun.lockb` telling you to use Deno). Checks green; mutant (planted `python = "latest"`) caught. - **#825** — pinning decision recorded in `docs/governance/ACTIONS-PINNING.adoc` (linked from README): `actions.lock` is the pinning mechanism for symbolic refs (option (b)) — no partial SHA sweep. Evidence the lock catches a moved ref is in DEBT-REGISTER CI-1's own runner log ("Lockfile pin … does not match ref"). Residual: one deliberate retag-mutant drill. - **#845** — `mirror.yml` pins standards' `mirror-reusable.yml` at `2479cf76`, past the Gitea empty-host fault (host/fingerprint vars now asserted non-empty and named, SSH host keys fingerprint-verified, per-forge skip notices). New `Mirror coverage` job reports the denominator (N of 7 configured). Disroot/Bitbucket deploy-key registration remains owner action (legible via skip notices). Residual: verify-a-mirror-landed-by-remote-SHA (AC5) needs per-forge remote read. - Also: two broken README links fixed (`DEBT-REGISTER.md` → `.adoc`; `PALIMPSEST.adoc` now points at `hyperpolymath/standards` where the file lives). ## Wave 5 — scanner precision & docs - **#834** — the comment-matching and line-1 defects, mechanism-level: Zig comment stripping (`//` incl `///`/`//!`); `scan_content` reports real line numbers (sarif `region.startLine` no longer defaults to 1); inline `hypatia:ignore <rule>` / `hypatia: allow code_safety/<rule>` directives honoured per line; `ffi/zig/src/main.zig`'s opaque-handle casts carry reviewed pragmas (cast code unchanged); RE005 strips YAML comments before matching and honours `hypatia:ignore RE005 -- <reason>`. Both directions fixtured everywhere. - **#676** — deterministic language resolution: one shared `CrossRepoLearning.primary_language_from_scan_data/1` (declared field → count desc → fixed priority → lexical; total order), used by all three readers. Discriminating test fails on the old `Enum.max_by` tie-break, passes now. Producer-side array ordering is outside this repo → **#866**. - **#746/#748** — secret findings dispositioned: placeholder-shaped values (`xxx`-runs, ellipses, `your-*`, `changeme`, `<…>`) and whole-line comments demote to `medium`/`report` with an explicit reason; an uncommented real-looking value stays `critical`/`revoke_rotate_and_purge`. The 45 measured blocking false positives all fall in the demoted class; nothing is silenced. Harvested-corpus carve-out → **#865**. - **#636** — category-A purge only: Logtalk-as-current claims removed/annotated from ci.yml header, ROADMAP (3), poc-scanner.sh (2), developer-guide (install + toolchain + diagram + data-flow), admin-guide (6), cicd-guidebook (2), NEURAL-ARCHITECTURE present tense; PROOF-STATUS Logtalk claims annotated with reason (status unchanged). B/C/D untouched: `hooks/lib/common.sh`, `lib/rules` migration comments, 6a2 purge records, `MUST.contractile` (owner-gated → **#864**), `.audittraining`, arcvix paper, system-integration's own residual note. - **#695** — PMPL drift fixed in governance/hypatia-scan/scorecard headers (dogfooding `fix-pmpl-drift.sh`'s own fix); SPDX added to `test_helper.exs`, `test_integration.exs`, both `check-*.sh`, `docs/proof-debt.adoc`; `integration/fixtures/test-repo/src/main.rs` stays deliberately headerless (recorded in new `.reuse/dep5`, which also covers the docs/training corpus); unused `LICENSES/AGPL-3.0-or-later.txt` removed; `CITATION.cff` added; `.github/TEST_CI_CODEQL_HYPATIA.md` deleted per its own "DELETE AFTER VERIFICATION" instruction; `mix hypatia.rsr_score` resolves its SSOT from real source-tree candidates — the bare command works without `--ssot` (the old `:code.priv_dir/..` path landed inside `_build`). Stale sub-items confirmed done elsewhere: mise.toml (#832), descriptiles/ migration (6a2/ gone), guix.scm (deleted), #417 (already closed). ## New issues filed (found during this work, not merge blockers) - **#864** — owner-gated: `MUST.contractile:79` "Logtalk rule engine … must be preserved" contradicts the retired engine (#636 category C, doctrine #4: supervised decision). - **#865** — `harvested-registry/` reference material trips `secret_detected`; path-based carve-out proposal (#746 tail note). - **#866** — the verisimdb `scans/` writer lives outside hypatia; edges/rows/attacks must be sorted at *its* emit boundary (the #676 producer-side half). ## Triage of the remaining open set | # | disposition | |---|---| | 358, 359 | panic-attack fact-source / higher-order rules — design work, unchanged; no blocker found this pass | | 361, 363, 366 | #333 cohort detector ideas — additive rules; valid backlog | | 367 | M20 SNIF parser port — blocked on its upstream unlock (hypatia#294), untouched | | 369 | code-scanning→dispatch loop RFC — the `security-status` aggregator pattern from #847 is a building block | | 421 | `reusable_workflow_sha_bump_needs_propagation` wiring — real; registry+dispatch wiring still missing | | 447–449 | taxonomy/self-model/planner RFCs — out of scope for this pass | | 463–466 | estate ops queues (billing wall, red CI, licence PRs, PR stewardship) — owner-facing, unchanged | | 470, 471, 473 | ruleset audits — `ABI-Codegen-Drift` is the only active hypatia ruleset (verified); estate-wide Base ruleset audit still open | | 483 | doc + contractile currency — #636/#695/#864 are slices of it | | 485 | rsr-template↔standards divergence audit — needs owner/consistency-plugin access | | 486 | neural-convergence proofs — needs network+Mathlib; out of pass | | 519 | `Hypatia` check must report on every PR — related to the #847 aggregator design; still open | | 520 | stale `standards` reusable pins estate-wide — hypatia's own `mirror.yml` pin bumped to `2479cf76` in this PR; the estate sweep remains (and `check-lockfile-drift.sh` mode 4 is the detector) | | 523, 554, 556 | scanner deployment/verification ops — unchanged | | 567 | cicd-squabbler feedback channel — design, unchanged | | 582 | ScorecardReconciler scheduling — unchanged | | 585 | ruleset gate-deadlock (structurally-unsatisfiable required checks) — owner/ruleset-admin action; the accept-or-delete ruling applies | | 605 | B-SHAPIN + `actions_policy.ex` — valid detection backlog | | 638 | allowlist heal-then-wipe oscillation — ops, unchanged | | 683 | CI-health estate failure-class report — ops cadence, unchanged | | 676 | **kept open** — hypatia side fixed (see above); the producer-side half is #866 | | 845 | **kept open** — Gitea empty-host fault fixed via pin bump; Disroot/Bitbucket key registration (owner) + remote-SHA verification (AC5) remain | ## Evidence & limits - All new scripts were run green on the tree and mutant-proven both directions (detailed in each commit message). Scanner rule changes ship with both-directions fixtures. - No Elixir/Rust toolchain exists in the fix sandbox: `mix test` / `cargo test` assertions are written to run in CI on this branch and constitute the test-level acceptance evidence. - `actions.lock` kept set-equal to workflow refs (both third-party action tags are `v7.0.1`/`v4.32.0`, matching the lock's recorded resolutions). Closes #814, closes #816, closes #820, closes #825, closes #831, closes #832, closes #834, closes #841, closes #847, closes #848, closes #849, closes #850, closes #851, closes #853, closes #857, closes #636, closes #695, closes #746, closes #748 Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps webfactory/ssh-agent from 0.9.0 to 0.9.1.
Release notes
Sourced from webfactory/ssh-agent's releases.
Changelog
Sourced from webfactory/ssh-agent's changelog.
... (truncated)
Commits
a6f90b1Release v0.9.172c0bfdImprove documentation on why we use os.userInfo()e3f1a8eAcknowledge custom command inputs in cleanup.js (#235)b504c19Update CHANGELOG.mdDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)