Repository navigation
Conversation
|
GhostDeps independent review - APPROVE the inert code at head I reviewed the full diff and merged the current The README correctly lists missing production gates: authenticated file-hash binding, actual independent GitHub revalidation, replay persistence, a separate trusted credential path, and ambiguous-write readback. The dependency-injected Merged-tree Action tests passed 24/24; workspace build, ESLint, Prettier, and diff check passed. All six hosted checks for this head were green when checked. I did not merge. |
Scope
Gated slice-4 preparation only. Two granular commits add an Ed25519 signed-envelope parser and a dependency-injected commit-only CAS boundary with refusal-path tests. Neither module is exported or wired to dispatch, a workflow, or the GitHub App. Nothing can apply a fix from this PR.
Checks
pnpm --filter @ghostdeps/action test(24 pass)pnpm exec eslint packages/action/src/apply/*.tspnpm exec prettier --check packages/action/src/apply/*.tsGates before any user-facing delivery
M3 stability, slice-2 evidence gates, and ADR-0004 execution/security boundary review. The README names further gaps: no runner workflow, live PR/comment/eligibility revalidation, replay tracking, signed file-hash binding, dedicated consumer App token path, or live proof of new-head CI. Keep this draft and do not merge as production apply.