Skip to content

chore(helios-cli): pin CI action SHAs and update deny.toml - #592

Closed
KooshaPari wants to merge 9 commits into
mainfrom
ci/pin-trufflehog
Closed

chore(helios-cli): pin CI action SHAs and update deny.toml#592
KooshaPari wants to merge 9 commits into
mainfrom
ci/pin-trufflehog

Conversation

@KooshaPari

Copy link
Copy Markdown
Owner

Draft PR opened during branch cleanup inventory.

Branch compare against main: ahead 9, behind 21, status diverged.

This PR needs normal review/CI before merge.

codex and others added 9 commits May 3, 2026 08:36
Remove harness_zig, harness-native, and transport symlinks - these
were scaffolding links that were never populated.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
- Add docs/ARCHITECTURE.md with system diagrams, component responsibilities,
  data flow, security model, and deployment topology
- Add ADR-008: NDJSON streaming output protocol with versioning strategy
- Add ADR-009: Session bundle format with HMAC-SHA256 signing and zstd
- Add ADR-010: Plugin architecture with WASM sandboxing
- Add ADR-011: Codex-RS API versioning and backwards compatibility
- Add docs/PLANS/technical-roadmap.md: 6-month phased roadmap with milestones

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
…, uv locks

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
…clean TODOs

- src/lib.rs: replace 2-line stub with workspace doc comments and re-export
  of helios_cli crate; documents workspace structure and build patterns
- docs/cli.md: add 366-line comprehensive CLI reference covering all 18
  subcommands (exec, review, login, logout, mcp, app-server, completion,
  sandbox, apply, resume, fork, cloud, features, debug, execpolicy,
  mcp-server, responses-api-proxy, stdio-to-uds), global flags, exit
  codes, config TOML sections, and environment variables
- docs/checklists/03_DAG_WBS.md: mark absorb-allowlist.txt and
  absorb-blocklist.txt checklist items as completed (allowlist had 6032
  lines of canonical roots already; blocklist had 8 entries)
- codex-rs/deny.toml: replace 3 bare TODO comments with dated NOTE
  annotations describing exact removal conditions (ratatui/lru 0.13+,
  aws-lc patch availability, syntect yaml-rust/bincode resolution)

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
…p-go

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Restore the workspace members array by listing all crate directories
present on disk, removing invalid glob patterns.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@gemini-code-assist

Copy link
Copy Markdown

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@sonarqubecloud

sonarqubecloud Bot commented Jun 3, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
1 Security Hotspot
E Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

@KooshaPari

Copy link
Copy Markdown
Owner Author

Closing during cleanup: stale conflicting workflow/security-pinning/trufflehog churn. This branch is DIRTY against current default and overlaps the broader hygiene/pinning cleanup already processed; regenerate as a focused PR if still needed.

@KooshaPari KooshaPari closed this Jun 4, 2026
@KooshaPari
KooshaPari deleted the ci/pin-trufflehog branch June 4, 2026 07:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants