Skip to content

Harden Apply public release surface - #3

Merged
0xprogrammable merged 1 commit into
mainfrom
codex/apply-public-polish-20260808
Aug 8, 2026
Merged

Harden Apply public release surface#3
0xprogrammable merged 1 commit into
mainfrom
codex/apply-public-polish-20260808

Conversation

@0xprogrammable

Copy link
Copy Markdown
Owner

Outcome

Makes the public Apply repository accurate, navigable, and fail-closed without changing review policy, registry records, intake state, or application semantics.

Changes

  • replaces the tiny Mermaid landing flow with a mobile-readable product and authority explanation
  • adds an exact checker boundary, a clone-to-run example, visible prelaunch state, and working finding routes
  • adds bounded bug and documentation issue forms plus canonical Support and Security links
  • documents responsible testing, scoped safe harbor, and the absence of a standing bounty
  • separates pull-request intake from post-merge verification
  • adds pinned CodeQL analysis and regression tests for the public surface and workflow contract
  • publishes a 1280×640 owned social-preview asset
  • updates stale Apply, Hookbuilder, migration, and code-maturity wording

Security controls

The live protected branch now requires Node 20, Node 22, and public-intake. The previously required post-merge-only check was removed from the merge gate. Application content remains untrusted data and is never executed by the privileged intake workflow.

Validation

  • npm test: 234 tests passed, 1 declared Linux-only skip
  • actionlint .github/workflows/*.yml
  • all issue-template YAML parsed successfully
  • git diff --check
  • public checker example returned launch_ready, checkerOnly: true, launchAuthorized: false, independentAudit: false
  • canonical public Support, Discussions, Security, Hookbuilder, and website links returned successfully

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@0xprogrammable
0xprogrammable force-pushed the codex/apply-public-polish-20260808 branch from 5fc0153 to da752e3 Compare August 8, 2026 07:40
@0xprogrammable
0xprogrammable merged commit d0de55b into main Aug 8, 2026
6 checks passed
@0xprogrammable
0xprogrammable deleted the codex/apply-public-polish-20260808 branch August 8, 2026 07:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants