Skip to content

feat: add dormant Boss protected provider - #6

Merged
dataforxyz merged 1 commit into
mainfrom
feat/boss-protected-provider
Jul 30, 2026
Merged

dataforxyz merged 1 commit into
mainfrom
feat/boss-protected-provider

Conversation

@dataforxyz

Copy link
Copy Markdown
Owner

Summary

  • add a dormant, deterministic OpenCode protected-provider candidate and standalone artifact
  • keep ensure/start fail-closed before hostile input inspection
  • package only the protected-service source and generated artifact without exports, plugin wiring, or ordinary dist changes

Proof

  • hostile Codex review APPROVE for exact patch SHA-256 57691df015a060adb73035b27cefedd8d95261e1935dbea5e3c8a79aa80fbbe1
  • npm run typecheck
  • focused provider/package/Core: 17/17
  • full suite: 141/141
  • npm run build; all three ordinary dist bundle hashes unchanged
  • two deterministic provider builds
  • real pack: 43 entries; provider contains exactly provider/protected-service.ts and provider/provider.mjs
  • packed hostile imports preserve unavailable-before-inspection semantics

Production Boss remains dormant and unavailable.

@dataforxyz
dataforxyz merged commit 9d81100 into main Jul 30, 2026
2 checks passed
@dataforxyz
dataforxyz deleted the feat/boss-protected-provider branch July 30, 2026 20:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant