docs(security): clarify local trust and reportable boundaries - #352
Conversation
|
@codex review the exact current head 0a349f5. Verify that the same-account process exclusion does not suppress repository-controlled hooks, filters, executables, paths, or symlinks that alter scan results, resume receipts, authorized targets or credentials, documented cost limits, truthful coverage gates, or release integrity. |
|
Codex Review: Didn't find any major issues. More of your lovely PRs please. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
Summary
Review focus
Confirm that the same-account process exclusion does not suppress repository-controlled subprocess, path, or symlink attacks that alter results, resume receipts, or supported coverage gates.
Verification
resolve_security_md.py --listresolver.SECURITY.mdexactly after the resolver's source header.prettier --check SECURITY.mdgit diff --check