mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-07 16:19:09 +00:00
Switches the workflow push guard from diffing against a sandbox-writable remote-tracking ref to hashing the actual workflow tree at the pushed head via . This closes the confused-deputy base-poisoning vector and the replay vector: approval is bound to the exact files and blob SHAs at head, so a different workflow tree requires re-approval. Also: - Fails the git push parser CLOSED: unrecognized or unsafe push forms are now blocked instead of running unguarded. - Checks the exact fingerprint's rejected status before the stale-approval path. - Updates prompt and Slack copy to reflect the new head-tree behavior. - Adds tests for base-poisoning, replay, deletion, unparsed push blocking, and rejection-before-stale ordering. Refs: 98 |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| check_message_queue.py | ||
| ensure_no_empty_msg.py | ||
| exclude_tools.py | ||
| model_fallback.py | ||
| notify_step_limit.py | ||
| plan_mode.py | ||
| refresh_github_proxy.py | ||
| refresh_slack_status.py | ||
| repair_orphaned_tool_calls.py | ||
| sandbox_circuit_breaker.py | ||
| sanitize_thinking_blocks.py | ||
| sanitize_tool_inputs.py | ||
| settle_review_check.py | ||
| tool_artifact.py | ||
| tool_error_handler.py | ||
| workflow_push_guard.py | ||