Skip to content

fix(security): promote boundary policy refinements to prod - #200

Merged
allenwoods merged 2 commits into
prodfrom
v0.1-dev/hackforger
Jul 10, 2026
Merged

fix(security): promote boundary policy refinements to prod#200
allenwoods merged 2 commits into
prodfrom
v0.1-dev/hackforger

Conversation

@allenwoods

@allenwoods allenwoods commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

Summary

Promote the reviewed public-boundary policy refinements from the default branch to prod before the large current-tip cleanup.

Includes only:

Verification

  • Independent static review found no P0/P1/P2 after refinement
  • 53 public-boundary tests passed on the source branch
  • latest default tip: b87b90fe0f2cfefd6a143eee2f033a3da71f54ed

Expected policy behavior

This is a policy-bootstrap PR. It changes the protected guard itself, and its candidate tip is intentionally still the pre-cleanup public tree. The trusted scan therefore reports both the guard change and the existing private-content findings. Any merge is an explicit, audited administrator exception limited to installing the reviewed policy before the separate cleanup PR.

The following cleanup PR must pass the trusted policy normally; this exception must not be reused for content changes.

Deployment

No deployment. Do not run redeploy.sh. Do not run rsync --delete.

allenwoods and others added 2 commits July 10, 2026 16:07
Co-authored-by: ci-smoke <ci@example.com>
Co-authored-by: ci-smoke <ci@example.com>
@allenwoods
allenwoods requested a review from a team as a code owner July 10, 2026 08:23
@allenwoods
allenwoods merged commit 219c98f into prod Jul 10, 2026
5 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant