AIOSAI
9048666c65
ci: OSSF scorecard hardening (DPLAN-0243) — hash-pin all standalone workflow pip installs via .github/requirements/ locks (pip/lint/build/e2e/audit, pip-compile --generate-hashes, 11/11 target-env closure verified incl. Windows colorama marker fix) + provenance attestation on publish (attest-build-provenance v4.1.1 SHA-pinned, id-token+attestations perms) + dependabot pip ecosystem for the new locks. Editable -e . installs untouched byte-identical. 5/5 fresh-venv --require-hashes installs green, 5/5 YAML parse, pinned ruff matches repo lint. First SSH-signed commit (repo config wired this session).
2026-07-15 12:21:22 -07:00
dependabot[bot]
aea90da5c6
ci(deps): bump actions/setup-python from 6.2.0 to 6.3.0
...
Bumps [actions/setup-python](https://github.com/actions/setup-python ) from 6.2.0 to 6.3.0.
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](https://github.com/actions/setup-python/compare/a309ff8b426b58ec0e2a45f0f869d46889d02405...ece7cb06caefa5fff74198d8649806c4678c61a1 )
---
updated-dependencies:
- dependency-name: actions/setup-python
dependency-version: 6.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-27 08:02:22 +00:00
dependabot[bot]
ef5ae933d0
ci(deps): bump actions/checkout from 6.0.3 to 7.0.0
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6.0.3 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b4311f1884172cec0e10...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-20 08:02:50 +00:00
AIPass
1deb786c8a
Merge pull request #637 from AIOSAI/dev
...
security(ci): least-privilege token on e2e-wheel workflow + W24 changelog (also carries playbook commit 6b89fcd)
2026-06-08 10:36:14 -07:00
AIOSAI and Claude Opus 4.8
dab8d29645
security(ci): add least-privilege permissions block to e2e-wheel workflow
...
e2e-wheel.yml was the only workflow missing a top-level permissions: block
(added during cross-OS work after PR #624 hardened the rest), so it ran with
default broad GITHUB_TOKEN scopes -> OpenSSF Scorecard Token-Permissions = 0.
Add 'permissions: contents: read' to match the other 7 workflows. CHANGELOG
W24 entry.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-08 10:09:00 -07:00
dependabot[bot]
285a8a5b5f
ci(deps): bump actions/checkout from 6.0.2 to 6.0.3
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...df4cb1c069e1874edd31b4311f1884172cec0e10 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 6.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-08 07:20:25 +00:00
AIOSAI and Claude Opus 4.8
cd1af34be8
test(e2e): cross-OS wiring harness + 3-OS CI, red-first (FPLAN-0239)
...
Build-wheel -> install-clean -> assert 4-tier wiring ladder (install/init/
hooks-fire/drone-route). Validated green on Linux; Windows red-first by design
(symlink/venv-path/tmp gaps = DPLAN-0194 P3 fix-list).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-04 00:03:37 -07:00