Skip to content

ci: harden automation and refresh verification evidence - #65

Merged
KIM3310 merged 1 commit into
mainfrom
agent/automation-hardening-20260810
Aug 10, 2026
Merged

ci: harden automation and refresh verification evidence#65
KIM3310 merged 1 commit into
mainfrom
agent/automation-hardening-20260810

Conversation

@KIM3310

@KIM3310 KIM3310 commented Aug 10, 2026

Copy link
Copy Markdown
Owner

Summary

  • replace mutable same-release checksum retrieval with the independently verified Gitleaks 8.30.1 archive SHA-256
  • stagger this repository's weekly secret scan and each Dependabot ecosystem into account-wide unique slots
  • refresh the generated verification evidence from the sorted Git-tracked source inventory

Why

This removes a release-asset substitution gap, prevents 36 repositories and 108 Dependabot update jobs from starting together, and reduces transient runner/API failures without weakening any test or security gate.

Validation

  • actionlint 1.7.12
  • Dependabot YAML parsed; all 108 account schedules are unique and remain weekly in Asia/Seoul
  • hard-coded release digest independently matched the downloaded artifact
  • Gitleaks 8.30.1 local scan: no findings
  • repository-surface validator (where present)
  • git diff --check
  • account publication generator and all central commercial validators; generator drift is zero

@KIM3310
KIM3310 merged commit fe5a78f into main Aug 10, 2026
16 checks passed
@KIM3310
KIM3310 deleted the agent/automation-hardening-20260810 branch August 10, 2026 15:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant