diffplug / diffplug/dormouse

[workflow-audit] 2 unexplained change(s) on 2026-09-14

Aperta
#641 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
TypeScript
Stelle
5
Fork
0
Merge medio
13h 46m
PR unite (30g)
205

Descrizione

2 unexplained commit(s) in the audit window (`.github/workflows/ .config/tend.yaml .github/audit/ .vscode/`) since `2026-09-13T12:41:26Z`.

Routine Renovate pin bumps and reproducible tend regenerations are
classified and omitted — see the run summary for what was skipped.
Everything below needs a human to account for it.

### `6fa9f90` — docs(security-local): widen the loopback derivation scope to match the set it names

- **Author:** dormouse-bot <287024035+dormouse-bot@users.noreply.github.com> (self-declared; not proof of origin)
- **Date:** 2026-09-13 17:58:41 +0000
- **Refs:** remotes/origin/fix/loopback-inventory-fourth
- **Files:**
- `.github/audit/application-security.md`
- [View diff](https://github.com/diffplug/dormouse/commit/6fa9f90ec26359be412699800e798a53a148f7e8)

### `a71dec4` — chore(deps): update github-actions

- **Author:** renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> (self-declared; not proof of origin)
- **Date:** 2026-09-14 10:23:18 +0000
- **Refs:** remotes/origin/renovate/github-actions
- **Files:**
- `.github/workflows/chromatic.yml`
- `.github/workflows/security-audit.yaml`
- `.github/workflows/tend-mention.yaml`
- `.github/workflows/tend-notifications.yaml`
- `.github/workflows/workflow-audit.yaml`
- [View diff](https://github.com/diffplug/dormouse/commit/a71dec482e9d01678c986043d6d51dfa2b75f771)

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Direzione di ricerca

Start by reviewing the workflow-audit run summary and the diffs for commits 6fa9f90 and a71dec4, especially .github/audit/application-security.md and the listed .github/workflows files. Done means each change has a documented human explanation or is escalated as an unauthorized change.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
git, github-actions
Ambito
ci-cd, security
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Attiva
Chiarezza
Da chiarire
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.