diffplug / diffplug/dormouse

[workflow-audit] 2 unexplained change(s) on 2026-09-14

Ouverte
#641 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
Langage dominant
TypeScript
Étoiles
5
Forks
0
Merge moyen
13 h 46 min
PR mergées (30 j)
205

Description

2 unexplained commit(s) in the audit window (`.github/workflows/ .config/tend.yaml .github/audit/ .vscode/`) since `2026-09-13T12:41:26Z`.

Routine Renovate pin bumps and reproducible tend regenerations are
classified and omitted — see the run summary for what was skipped.
Everything below needs a human to account for it.

### `6fa9f90` — docs(security-local): widen the loopback derivation scope to match the set it names

- **Author:** dormouse-bot <287024035+dormouse-bot@users.noreply.github.com> (self-declared; not proof of origin)
- **Date:** 2026-09-13 17:58:41 +0000
- **Refs:** remotes/origin/fix/loopback-inventory-fourth
- **Files:**
- `.github/audit/application-security.md`
- [View diff](https://github.com/diffplug/dormouse/commit/6fa9f90ec26359be412699800e798a53a148f7e8)

### `a71dec4` — chore(deps): update github-actions

- **Author:** renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> (self-declared; not proof of origin)
- **Date:** 2026-09-14 10:23:18 +0000
- **Refs:** remotes/origin/renovate/github-actions
- **Files:**
- `.github/workflows/chromatic.yml`
- `.github/workflows/security-audit.yaml`
- `.github/workflows/tend-mention.yaml`
- `.github/workflows/tend-notifications.yaml`
- `.github/workflows/workflow-audit.yaml`
- [View diff](https://github.com/diffplug/dormouse/commit/a71dec482e9d01678c986043d6d51dfa2b75f771)

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Piste de recherche

Start by reviewing the workflow-audit run summary and the diffs for commits 6fa9f90 and a71dec4, especially .github/audit/application-security.md and the listed .github/workflows files. Done means each change has a documented human explanation or is escalated as an unauthorized change.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
git, github-actions
Domaine
ci-cd, security
Type d'issue
Bug
Difficulté
4/5
Temps estimé
3-5 jours
Activité
Active
Clarté
À clarifier
Accessibilité débutants
35/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.