diffplug / diffplug/dormouse

[workflow-audit] 5 unexplained change(s) on 2026-09-11

Open
#628 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
5
Forks
0
Avg merge
13h 46m
Merged PRs (30d)
205

Description

5 unexplained commit(s) in the audit window (`.github/workflows/ .config/tend.yaml .github/audit/ .vscode/`) since `2026-09-10T12:11:46Z`.

Routine Renovate pin bumps and reproducible tend regenerations are
classified and omitted — see the run summary for what was skipped.
Everything below needs a human to account for it.

### `2128c0d` — fix(security-audit): end each orchestrator wait call before the Bash cap

- **Author:** dormouse-bot <287024035+dormouse-bot@users.noreply.github.com> (self-declared; not proof of origin)
- **Date:** 2026-09-11 10:04:14 +0000
- **Refs:** remotes/origin/fix/audit-wait-loop-returns
- **Files:**
- `.github/audit/orchestrator.md`
- [View diff](https://github.com/diffplug/dormouse/commit/2128c0df4892fa089f1f96f21687b79e560ce9ae)

### `811ddb6` — ci(security-audit): raise the orchestrator's wait deadline to 32 minutes

- **Author:** dormouse-bot <287024035+dormouse-bot@users.noreply.github.com> (self-declared; not proof of origin)
- **Date:** 2026-09-11 10:04:22 +0000
- **Refs:** remotes/origin/fix/audit-wait-loop-returns
- **Files:**
- `.github/audit/orchestrator.md`
- `.github/workflows/security-audit.yaml`
- [View diff](https://github.com/diffplug/dormouse/commit/811ddb63533877777ed6cba8ab619eeab0df204d)

### `98a7f79` — docs: keep "cutover" meaning one thing in the remote specs

- **Author:** Ned Twigg (self-declared; not proof of origin)
- **Date:** 2026-09-10 13:08:51 -0700
- **Refs:** remotes/origin/pocket-webrtc-2
- **Files:**
- `.github/audit/application-security.md`
- [View diff](https://github.com/diffplug/dormouse/commit/98a7f79c792a294e130b73a306dcf6cd50559bdb)

### `ca3a4ab` — fix(security-audit): keep every wait call's tail unambiguous

- **Author:** dormouse-bot <287024035+dormouse-bot@users.noreply.github.com> (self-declared; not proof of origin)
- **Date:** 2026-09-11 10:16:49 +0000
- **Refs:** remotes/origin/fix/audit-wait-loop-returns
- **Files:**
- `.github/audit/orchestrator.md`
- `.github/workflows/security-audit.yaml`
- [View diff](https://github.com/diffplug/dormouse/commit/ca3a4abd881b8df504e78ad82e91155ed9fc77b9)

### `e0a9399` — fix(security-audit): name the wait call's output as the decision input

- **Author:** dormouse-bot <287024035+dormouse-bot@users.noreply.github.com> (self-declared; not proof of origin)
- **Date:** 2026-09-11 10:35:27 +0000
- **Refs:** remotes/origin/fix/audit-wait-loop-returns
- **Files:**
- `.github/audit/orchestrator.md`
- `.github/workflows/security-audit.yaml`
- [View diff](https://github.com/diffplug/dormouse/commit/e0a9399536aeb96da815512292dd52ef79f6e383)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the five listed commits and their diffs, especially .github/audit/orchestrator.md, .github/audit/application-security.md, and .github/workflows/security-audit.yaml. Compare them with the audit run summary and repository context; the work is done when each change is accounted for as authorized or escalated for investigation.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.