Summary
Audit doc cites script; no workflow invokes it.
Impact: Production user/operator failure on Osmantic/ODS main
Files:
.github/workflows/*
ods/tests/test-secret-security.sh
SECURITY_AUDIT.md
Repro
On a production-like Osmantic/ODS main checkout:
- Hit the failure mode described in Summary (severity: High).
- Observe the broken behavior / incorrect exit / missing guard from the root cause above.
- Confirm no overlapping open PR (dedup: No open issue. No open PR.).
Fix
Implement a minimal, distro-/path-correct fix in the listed files (no scope creep).
- Address the root cause directly (do not paper over with
|| true / broad catches).
- Prefer resolving runtime values from the environment/repo (like
apt-cache madison) over hardcoding distro-specific version strings when the same bug class applies.
- Add a regression test under
ods/tests/ (or matching suite) that fails without the fix and passes with it.
Context
Filed from Desktop issues.md entry #37 via one-click scout pipeline.
Rationale: Unfiled Desktop issues.md #37 (no GitHub issue yet)
Summary
Audit doc cites script; no workflow invokes it.
Impact: Production user/operator failure on Osmantic/ODS main
Files:
.github/workflows/*ods/tests/test-secret-security.shSECURITY_AUDIT.mdRepro
On a production-like Osmantic/ODS main checkout:
Fix
Implement a minimal, distro-/path-correct fix in the listed files (no scope creep).
|| true/ broad catches).apt-cache madison) over hardcoding distro-specific version strings when the same bug class applies.ods/tests/(or matching suite) that fails without the fix and passes with it.Context
Filed from Desktop
issues.mdentry #37 via one-click scout pipeline.Rationale: Unfiled Desktop issues.md #37 (no GitHub issue yet)