Commit Graph
10 Commits
Author SHA1 Message Date
dependabot[bot] 4e2ead98a6 ci(deps): bump github/codeql-action from 4.36.0 to 4.36.2
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.0 to 4.36.2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/7211b7c8077ea37d8641b6271f6a365a22a5fbfa...8aad20d150bbac5944a9f9d289da16a4b0d87c1e)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.36.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 16:09:17 +00:00
dependabot[bot] 285a8a5b5f ci(deps): bump actions/checkout from 6.0.2 to 6.0.3
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...df4cb1c069e1874edd31b4311f1884172cec0e10)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 07:20:25 +00:00
AIOSAIandClaude Opus 4.8 1ee51f3295 ci(security): upgrade pip in dependency-scan, drop stale ignores
dependency-scan (pip-audit) was red: it scans the whole env, and the runner's
bundled pip 26.1.1 carries PYSEC-2026-196 (fixed in 26.1.2). The job was the
only CI job not upgrading pip. Now runs 'python -m pip install --upgrade pip'
before auditing — removes the vulnerable version outright instead of
suppressing it.

pip 26.1.2 also fixes CVE-2026-3219 and CVE-2026-6357 (both were pip vulns, per
pip-audit attributing them to the pip package), so the two now-stale
--ignore-vuln entries are removed — stale security ignores mask the exact CVEs
they name if those reappear elsewhere.

Verified in a clean reproduction of the job env (fresh venv, upgrade pip, pip
install -e ., pip-audit --skip-editable with NO ignores): 'No known
vulnerabilities found', exit 0.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-06 04:54:11 -07:00
dependabot[bot] 62e639794f ci(deps): bump github/codeql-action from 4.35.3 to 4.36.0
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.35.3 to 4.36.0.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/e46ed2cbd01164d986452f91f178727624ae40d7...7211b7c8077ea37d8641b6271f6a365a22a5fbfa)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-30 08:02:55 +00:00
AIOSAI efa5aced74 ci: harden workflows — least-privilege permissions + SHA-pinned actions 2026-05-29 23:47:27 -07:00
AIOSAI 453c847359 fix(ci): auto-format on commit, decouple lint from tests, add codecov threshold 2026-05-12 22:41:03 -07:00
AIOSAIand@devpulse 3b8fa1fa5a feat(system): test
Co-Authored-By: @devpulse <devpulse@aipass>
2026-05-12 17:33:34 -07:00
AIOSAIand@devpulse 3d1d820e26 feat(system): fix(system): ruff format 13 hook/init files + pip-audit CVE-2026-6357 ignore — unblock CI lint and security
Co-Authored-By: @devpulse <devpulse@aipass>
2026-05-07 00:39:58 -07:00
AIOSAIand@devpulse ad53c78386 feat(system): fix: ignore CVE-2026-3219 pip vulnerability in security scan — upstream pip issue, no fix available yet
Co-Authored-By: @devpulse <devpulse@aipass>
2026-04-25 22:01:37 -07:00
AIOSAIandClaude Opus 4.6 f30443504c chore: add hooks, CI/CD infrastructure, ignore runtime JSON
- Transfer Claude Code hooks from internal: identity injector, email
  notification, auto-fix diagnostics, pre-compact recovery
- Add notification sounds for tool use, stop, and alerts
- Wire all hooks in .claude/settings.json
- Add global system prompt (.aipass/aipass_global_prompt.md)
- Add branch-local prompt placeholders for all modules
- Set up CI pipeline: lint (ruff) → test matrix (3.10-3.13) → coverage
- Add workflows: PyPI publish, security scanning, stale issues
- Add GitHub issue templates, dependabot, editorconfig
- Configure pytest norecursedirs and coverage fail-under=70
- Add *.json to gitignore — runtime JSON files constantly change
- Untrack runtime JSON (registry, plans, seed bypass, module data)
- Keep source JSON tracked via negation rules (json_templates, pack,
  spawn templates, settings, pyrightconfig)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 20:33:40 -08:00