First controls of the P3-live-flip Phase-1 CI hardening (workflow stays INERT; this only tightens the trust boundary). Whole Phase-1 surface is gated by /sh-security-review + GPT-4.1 cross-review before any flip. §4.2 — expand the trust-control denylist with direct code-execution / supply-chain vectors, kept byte-identical across all three copies (ci_gate.DENYLIST_GLOBS + the guard + post-build inline DENY_GLOBS), drift-guarded: .gitmodules, .husky/**, .githooks/**, .gitattributes, .npmrc, and generated/build artifacts (__generated__, *.generated.*, dist/**, build/**, *.min.js). Deliberate: lockfiles are NOT wholesale denied — lockfile-postinstall RCE is already contained by the credential-less egress-blocked build sandbox, and the Tier-3 dep-CVE fixer rewrites lockfiles to produce its draft PRs; a blanket deny would make it un-shippable. Flagged in-code for the security gate. Direct code-execution config (hooks/filters/npmrc/submodules) is the actual §4.2 RCE surface. §4.1 — runner-trust: assert no job (esp. the privileged gate-and-pr) can run on a self-hosted/user-provided runner; all must be GitHub-hosted. 998 tests pass, ruff clean. |
||
|---|---|---|
| .. | ||
| sim | ||
| __init__.py | ||
| conftest.py | ||
| test_apply_verify_workflow_hardening.py | ||
| test_billing.py | ||
| test_build_verify_subgraph.py | ||
| test_builders.py | ||
| test_builders_llm.py | ||
| test_checker_intake.py | ||
| test_ci_fetcher.py | ||
| test_ci_gate.py | ||
| test_ci_gate_workflow.py | ||
| test_clarifier.py | ||
| test_clarifier_llm.py | ||
| test_claude_code_adapter.py | ||
| test_claude_code_live.py | ||
| test_coordinator.py | ||
| test_deadline_timer.py | ||
| test_fixer.py | ||
| test_github_adapter.py | ||
| test_github_intake.py | ||
| test_github_live.py | ||
| test_graph.py | ||
| test_invoker.py | ||
| test_ledger.py | ||
| test_operator_cli.py | ||
| test_planner.py | ||
| test_recovery.py | ||
| test_responder.py | ||
| test_resume_worker.py | ||
| test_review_loop.py | ||
| test_review_loop_llm.py | ||
| test_run_team.py | ||
| test_schema.py | ||
| test_slack_adapter.py | ||
| test_slack_listener.py | ||
| test_slack_live.py | ||
| test_state_store.py | ||
| test_task_model.py | ||
| test_transport_base.py | ||
| test_verifier.py | ||
| test_verifier_llm.py | ||