[workflow-audit] 3 unexplained change(s) on 2026-09-12
- Dominant language
- TypeScript
- Stars
- 5
- Forks
- 0
- Avg merge
- 14h 13m
- Merged PRs (30d)
- 199
Description
3 unexplained commit(s) in the audit window (`.github/workflows/ .config/tend.yaml .github/audit/ .vscode/`) since `2026-09-11T12:09:50Z`.
Routine Renovate pin bumps and reproducible tend regenerations are
classified and omitted — see the run summary for what was skipped.
Everything below needs a human to account for it.
### `13ca270` — Add isolated Hosted accounts with pgstencil Better Auth
- **Author:** Ned Twigg (self-declared; not proof of origin)
- **Date:** 2026-09-11 15:56:24 -0700
- **Refs:** remotes/origin/hosted-auth
- **Files:**
- `.github/audit/application-security.md`
- [View diff](https://github.com/diffplug/dormouse/commit/13ca270c34ff68cc162dd0ae48545349a172fe0a)
### `1ba83d7` — Add isolated Hosted PR previews and verified production releases
- **Author:** Ned Twigg (self-declared; not proof of origin)
- **Date:** 2026-09-11 16:23:26 -0700
- **Refs:** remotes/origin/hosted-auth
- **Files:**
- `.github/workflows/hosted-preview.yml`
- `.github/workflows/hosted-production.yml`
- [View diff](https://github.com/diffplug/dormouse/commit/1ba83d7d9a9ba5ce11cb119009b8206d13be9518)
### `fd5181b` — Verify the PR merge revision for Hosted previews
- **Author:** Ned Twigg (self-declared; not proof of origin)
- **Date:** 2026-09-11 16:25:16 -0700
- **Refs:** remotes/origin/hosted-auth
- **Files:**
- `.github/workflows/hosted-preview.yml`
- [View diff](https://github.com/diffplug/dormouse/commit/fd5181b74d187eb4c6d5bb7a2bad4d49030aa3ea)
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the audit entries in .github/audit/application-security.md and the linked diffs for commits 13ca270, 1ba83d7, and fd5181b. Inspect the affected .github/workflows/ files and their hosted-auth ref, then compare the changes with the run summary. Done means each of the three commits has a documented human explanation or is escalated for investigation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100