Skip to content

N20: Pin checker, policy and offline verifier for containment smoke - #8

Merged
avoroncov971-maker merged 3 commits into
mainfrom
work/n20-pinned-workflow
Sep 8, 2026
Merged

N20: Pin checker, policy and offline verifier for containment smoke#8
avoroncov971-maker merged 3 commits into
mainfrom
work/n20-pinned-workflow

Conversation

@avoroncov971-maker

@avoroncov971-maker avoroncov971-maker commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Allowlist

  • .github/workflows/proof-check-pinned.yml

Merged at head 7a22493b7b66116990d4bbbd2dda0800a7e3acac as commit 363aad91142a01df6e5d72a87495d2f09be28823.

This version pins checker, policy, and offline verifier to accepted commit ea1536eda18fc59a36c3b08edaa93b2ecee111dd and was proven through remote consumption. It still uses the pull_request trigger and checks out the subject. The later trusted-base change was pushed after this PR had merged and is therefore not part of this merge.

Follow-up PR required: change the trigger to pull_request_target and remove the subject checkout before using this status as an enforcement gate.

@avoroncov971-maker
avoroncov971-maker marked this pull request as ready for review September 8, 2026 03:02
@avoroncov971-maker
avoroncov971-maker merged commit 363aad9 into main Sep 8, 2026
3 checks passed

Copy link
Copy Markdown
Contributor Author

@claude Please perform a READ_ONLY_ANALYSIS review of PR #8 at exact head ec64142 against accepted main ea1536e.

Review the single allowlisted workflow. Verify that pull_request_target takes the workflow from the trusted base, no PR-controlled bytes are executed or installed, all permissions are read-only, checker/policy/verifier are pinned to accepted full SHA, FAIL and INDETERMINATE remain failing conclusions, and artifacts remain available. Consider fork PR behavior and status-check enforcement.

Do not edit, push, approve, mark Ready, merge, release, or change settings. Return PASS, BLOCKED, or INDETERMINATE bound to this head with any blocking finding tied to a concrete failure mechanism.

Copy link
Copy Markdown
Contributor Author

CORRECTION: PR #8 merged before commit ec64142 was pushed. The @claude request above is not bound to this merged PR and must not be treated as its review. A separate follow-up PR will carry the trusted-base trigger change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant