-
Notifications
You must be signed in to change notification settings - Fork 5.1k
ci: add security-aware Dependabot updates for Python and GitHub Actions #3641
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
HAYDEN-OAI
wants to merge
52
commits into
main
Choose a base branch
from
codex/openai-python-dependabot-security-20260817
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
52 commits
Select commit
Hold shift + click to select a range
20c1c08
ci: add security-aware Dependabot updates for Python and GitHub Actions
HAYDEN-OAI 4688d3b
fix: track Python lockfiles and pinned Actions securely
HAYDEN-OAI 42e7f73
fix: preserve release marker in uv dependency lock
HAYDEN-OAI 9eacb6d
fix: use Python 3.11 for dependency lock policy checks
HAYDEN-OAI 05d03fc
Merge main and reconcile security dependency locks
HAYDEN-OAI 253692a
Merge main and preserve uv-native dependency security
HAYDEN-OAI 86b9b62
fix: reject untrusted uv lockfile dependency sources
HAYDEN-OAI 6af5be9
fix: gate dependency installs on lock provenance
HAYDEN-OAI 69acefe
fix: validate dependency artifacts and security update floors
HAYDEN-OAI 70d1ffa
Merge main into dependency security policy updates
HAYDEN-OAI 3e188b8
fix:enforce-strict-dependabot-security-dependency-floors
HAYDEN-OAI 0b3f84b
fix: validate dependency floors against patched lock releases
HAYDEN-OAI d5e8f30
fix: reject weakened security floors with unchanged locks
HAYDEN-OAI 05d1c29
fix: preserve contextual security floors and reject lock downgrades
HAYDEN-OAI 2a4d89e
fix: validate root build provenance and preserve security constraints
HAYDEN-OAI dd2e769
fix: block dependency source builds and preserve marker-specific secu…
HAYDEN-OAI 3860753
fix(ci): permit reviewed editable roots without building dependencies
HAYDEN-OAI 27b0b83
fix(ci): reject direct dependency removals in security updates
HAYDEN-OAI 2b16120
fix(ci): anchor fork build backends to the trusted base
HAYDEN-OAI 4d25ed8
fix(ci): require protected floors to reach patched releases
HAYDEN-OAI f1f729e
fix(ci): preserve marker-specific security floors and trusted source …
HAYDEN-OAI eb134b8
fix(ci): defer source builds and support dependency marker membership
HAYDEN-OAI 9071f2b
fix: preserve supported dependency security branches
HAYDEN-OAI 05c414f
fix(security): require safe published dependency branches
HAYDEN-OAI f012570
fix(security): preserve bounds when dependency locks are unchanged
HAYDEN-OAI 1ef8c69
fix(security): preserve all reviewed dependency bounds
HAYDEN-OAI a0049ec
fix(security): anchor dependency checks to immutable trusted bases
HAYDEN-OAI 7a3b31a
fix(security): preserve reviewed exact dependency pins
HAYDEN-OAI 95769f4
fix(security): require boundaries for transitive dependency patches
HAYDEN-OAI d650c88
fix(security): preserve reviewed dependency boundaries and extras
HAYDEN-OAI 1e1b908
fix(security): guard fork hooks and published dependency exposure
HAYDEN-OAI 24c14ae
fix: validate dependency security across marker domains
HAYDEN-OAI ace8805
test: annotate dependency edge security fixture
HAYDEN-OAI e5a9d7f
fix: validate marker provenance and all supported security branches
HAYDEN-OAI 2ad0073
fix: reconcile resolution domains and scoped extra reviews
HAYDEN-OAI a4091b1
fix: remove unused dependency reachability state
HAYDEN-OAI 8ca4367
Preserve semantic marker and wildcard security bounds
HAYDEN-OAI 03dc92e
Validate the complete relinked Agents dependency lock
HAYDEN-OAI 439a5dd
Preserve exact Python marker security semantics
HAYDEN-OAI 8ff2861
Constrain Agents relinking to reviewed dependency versions
HAYDEN-OAI 51f3e20
fix(ci): preserve reviewed no-build Agents dependencies
HAYDEN-OAI 1c6dc30
fix(ci): type reviewed Agents dependency artifacts
HAYDEN-OAI b34e719
fix: address dependency security review feedback
HAYDEN-OAI 232794d
fix: align dependency bounds and marker evaluation
HAYDEN-OAI 21e42f0
fix: preserve shared extra and platform marker semantics
HAYDEN-OAI e883403
fix: preserve post-release floors and marker orientation
HAYDEN-OAI 8be8386
Merge branch 'main' into codex/openai-python-dependabot-security-2026…
HAYDEN-OAI 923053f
fix: preserve dependency audiences and PEP 440 marker versions
HAYDEN-OAI e2c40e5
fix: preserve complete PEP 440 security marker domains
HAYDEN-OAI 2e94eda
fix: harden security dependency markers and source builds
HAYDEN-OAI 210bf74
fix: preserve security marker release and membership domains
HAYDEN-OAI eedfd70
fix: preserve complete dependency security marker boundaries
HAYDEN-OAI File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.