Skip to content

ci: drop adoption grace — run the osv lane at hard-fail - #49

Merged
bdelanghe merged 2 commits into
mainfrom
claude/deps-hard-fail
Jul 30, 2026
Merged

ci: drop adoption grace — run the osv lane at hard-fail#49
bdelanghe merged 2 commits into
mainfrom
claude/deps-hard-fail

Conversation

@bdelanghe

Copy link
Copy Markdown
Collaborator

Fleet-wide grace sweep — ci-workflows#8.

report-only: true was adoption grace so a pre-existing advisory couldn't block instrumentation. Temporary by design, but with no expiry or owner a repo left holding it shows a green check that gates nothing.

Self-verifying: if this repo still has a finding, this PR's own osv check goes red and it isn't merged. Green means genuinely clean at hard-fail.


Generated by Claude Code

The report-only flag was adoption grace so a pre-existing advisory could not
block instrumentation. It was always meant to be temporary, and it has no expiry
or owner, so a repo left holding it shows a green check that gates nothing.

This repo's scan is clean, so grace comes off: a known vulnerability now reds the
lane, which is the template's intended steady state.

Self-verifying by construction — if this repo did still carry a finding, this
PR's own osv check goes red and it does not get merged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Removing report-only grace turned this lane red on the first non-npm finding of
the fleet sweep — a Rust advisory from Cargo.lock rather than a JS one.

Patch-level bump inside the existing range; cargo update touched one package and
nothing else. No manifest change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@bdelanghe
bdelanghe merged commit d5b569c into main Jul 30, 2026
7 checks passed
@bounded-systems-front-desk bounded-systems-front-desk Bot moved this from Todo to Done in Front Desk Jul 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant