gstack/.github
Garry Tan 2fd506a4e0
fix(ci): SHA-pin dependency-review; the secret gate fails closed without a report
dependency-review.yml rode mutable refs (@v4 resolves to a BRANCH on
that repo) inside the one workflow whose job is supply-chain hygiene —
now commit-pinned like its siblings, with dependabot keeping the pins
fresh. gate-secret-scan.mjs crashed with an unhandled EPIPE on
oversize diffs (the designed report.oversize branch was unreachable:
the scanner emits no JSON on refusal) — the pipe write now tolerates
early exit and a missing report is an explicit fail-closed exit 1.
Oversize + broken-scanner legs pinned.
2026-08-14 17:15:48 -07:00
..
docker v1.28.0.0 feat: browse --headed/--proxy/--navigate + gstack/llms.txt + webdriver-only stealth (#1363) 2026-05-07 20:14:59 -07:00
scripts fix(ci): SHA-pin dependency-review; the secret gate fails closed without a report 2026-08-14 17:15:48 -07:00
workflows fix(ci): SHA-pin dependency-review; the secret gate fails closed without a report 2026-08-14 17:15:48 -07:00
PULL_REQUEST_TEMPLATE.md feat(ci): supply-chain hygiene — secret gate on every PR diff, dependency review, OSV, dependabot, evidence-bar PR template 2026-08-14 13:18:37 -07:00
actionlint.yaml feat: Wave 3 — community bug fixes & platform support (v0.11.6.0) (#359) 2026-03-23 22:15:23 -07:00
dependabot.yml feat(ci): supply-chain hygiene — secret gate on every PR diff, dependency review, OSV, dependabot, evidence-bar PR template 2026-08-14 13:18:37 -07:00