Skip to content

Community GA: isolate clone install and publish clean-clone proof - #53

Draft
seanheiney wants to merge 16 commits into
mainfrom
codex/community-ga-clean-clone-proof
Draft

seanheiney wants to merge 16 commits into
mainfrom
codex/community-ga-clean-clone-proof

Conversation

@seanheiney

@seanheiney seanheiney commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Isolate a second Community checkout from another checkout's periscan-deps containers and volumes, while preserving the existing project's name and honoring explicit overrides.
  • Repair public release-gate drift in BAS wording, TypeScript tests, license notices, browser selection, and acceptance assertions. The internal analyst scorecard gate now reports an explicit skip in the public export; it still fails if that scorecard disappears from the private tree.
  • Publish a bounded clean-clone technical proof receipt for verified scope → policy → Gitleaks finding → remediation → measured retest. The README continues to say this Periscan repository itself is not measured.
  • Replace internal Plane and ops-token guidance in the public tree with GitHub issue guidance, remove the internal sync note, and add a tracked-source hygiene gate. The gate fails on a synthetic private-operator marker and passes on this branch.

Verification

  • pnpm verify passed locally on Node 24.21.0 against disposable PostgreSQL 16 and Redis 7: 80 browser tests, 37 security tests, 263 acceptance passes and two skips, with zero high-severity dependency advisories.
  • A fresh public clone completed the actual Community API proof loop against a disposable owned repository. An unverified second tenant had zero missions and could not read the first tenant's mission.
  • The second checkout selected a separate Compose project. Its install and down left the original checkout's Postgres running.
  • gitleaks git --log-opts='HEAD~2..HEAD' . found zero leaks.

Limits

This receipt does not qualify uncoached first-hour usability, Linux or bundled Docker Gitleaks execution, production capacity, broad BAS/AEV coverage, external customer value, or analyst standing. Hosted CI remains a separate gate. Removing private operational references from current source does not remove copies in earlier public Git history; historical review remains open.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants