Skip to content

[workflow-audit] 6 unexplained change(s) on 2026-09-24 #781

Description

@github-actions

6 unexplained commit(s) in the audit window (.github/workflows/ .config/tend.yaml .github/audit/ .vscode/) since 2026-09-23T12:43:01Z.

Renovate pin bumps, reproducible tend regenerations, clean merges, and
commits first pushed by an admin are classified and omitted — see the
run summary for what was skipped.
Everything below needs a human to account for it.

1c6b7b0 — fix(security-audit): lift the deciding lines above the truncation point

  • Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
  • First pushed by: dormouse-bot (branch_creation)
  • Date: 2026-09-23 13:17:37 +0000
  • Refs: remotes/origin/fix/audit-lift-deciding-lines
  • Files:
    • .github/workflows/security-audit.yaml
  • View diff

340b980 — Keep provisioning obligations out of the FAIL IF list so the audit can decide (#748)

  • Author: dormouse-bot ned.twigg+dormouse-bot@diffplug.com (self-declared; not proof of origin)
  • First pushed by: nedtwigg (pr_merge)
  • Date: 2026-09-23 09:58:07 -0700
  • Refs: main,remotes/origin/alert-improve remotes/origin/browser-lifecycle,remotes/origin/browser-providers remotes/origin/browser-quick-wins,remotes/origin/browser-viewer-socket remotes/origin/fix/audit-lift-deciding-lines,remotes/origin/fix/dor-cmd-exit-code remotes/origin/main,remotes/origin/playwright-browser
  • Files:
    • .github/audit/_preamble.md
    • .github/audit/hosted.md
  • View diff

4b8b565 — chore: update tend workflows (0.3.1 → 0.3.2)

  • Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
  • First pushed by: dormouse-bot (branch_creation)
  • Date: 2026-09-24 11:49:22 +0000
  • Refs: remotes/origin/tend/update-workflows
  • Files:
    • .config/tend.yaml
    • .github/workflows/tend-ci-fix.yaml
    • .github/workflows/tend-mention-relay.yaml
    • .github/workflows/tend-mention.yaml
    • .github/workflows/tend-nightly.yaml
    • .github/workflows/tend-notifications.yaml
    • .github/workflows/tend-review-runs.yaml
    • .github/workflows/tend-review.yaml
    • .github/workflows/tend-triage.yaml
    • .github/workflows/tend-weekly.yaml
  • View diff

573ea8b — Keep the lift from silencing the step, and cap only the findings

  • Author: dormouse-bot 287024035+dormouse-bot@users.noreply.github.com (self-declared; not proof of origin)
  • First pushed by: dormouse-bot (push)
  • Date: 2026-09-23 13:33:37 +0000
  • Refs: remotes/origin/fix/audit-lift-deciding-lines
  • Files:
    • .github/workflows/security-audit.yaml
  • View diff

b34037c — fix(security-audit): lift the deciding lines above the truncation point (#764)

  • Author: dormouse-bot ned.twigg+dormouse-bot@diffplug.com (self-declared; not proof of origin)
  • First pushed by: nedtwigg (pr_merge)
  • Date: 2026-09-23 10:03:45 -0700
  • Refs: main,remotes/origin/alert-improve remotes/origin/browser-lifecycle,remotes/origin/browser-providers remotes/origin/browser-quick-wins,remotes/origin/browser-viewer-socket remotes/origin/fix/dor-cmd-exit-code,remotes/origin/main remotes/origin/playwright-browser,remotes/origin/tend/update-workflows
  • Files:
    • .github/workflows/security-audit.yaml
  • View diff

d4ca2c0 — Return the CLI's exit code from dor.cmd on Windows

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions