Skip to content

ci: make full validation fail closed on security checks - #322

Merged
codeforester merged 2 commits into
mainfrom
security/310-20260902-fail-closed-validation
Sep 2, 2026
Merged

ci: make full validation fail closed on security checks#322
codeforester merged 2 commits into
mainfrom
security/310-20260902-fail-closed-validation

Conversation

@codeforester

Copy link
Copy Markdown
Contributor

Fixes #310

  • require Bandit and pip-audit in the authoritative full validation gate
  • exclude only the unpublished editable checkout from the dependency audit
  • write a machine-readable full/partial result and reject missing Node.js as non-authoritative
  • install Node.js in distribution/WSL validation lanes

Focused checks and shell validation pass locally.

@codeforester
codeforester force-pushed the security/310-20260902-fail-closed-validation branch from 8458186 to 0fc12f3 Compare September 2, 2026 09:55
@codeforester
codeforester force-pushed the security/310-20260902-fail-closed-validation branch from 911eb1f to f959e92 Compare September 2, 2026 10:21
@codeforester
codeforester merged commit 1ad8992 into main Sep 2, 2026
55 of 106 checks passed
@codeforester
codeforester deleted the security/310-20260902-fail-closed-validation branch September 2, 2026 10:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[v1.0] Make the authoritative validation gate fail closed on security tools

1 participant