v1.4.2 — hardened QA runtime
Juror v1.4.2 hardens the isolated post-merge browser QA runtime.
Highlights:
- keep Codex Responses on auth-appropriate HTTPS endpoints through the controller-owned allowlisted proxy, with inherited
NO_PROXYbypasses removed - restore sandboxed Chromium startup for arbitrary non-root runner identities by providing a private writable home
- verify namespace and seccomp-BPF protection on native amd64 before release, including a passwd-less numeric UID/GID
- preserve npm, Action-source, SBOM, image, and provenance verification through the existing trusted release workflows