Skip to content

Add trusted exact-deletion gate approvals - #101

Merged
Pigbibi merged 2 commits into
mainfrom
codex/aiauditbridge-deletion-gate-bootstrap-20260729
Jul 29, 2026
Merged

Add trusted exact-deletion gate approvals#101
Pigbibi merged 2 commits into
mainfrom
codex/aiauditbridge-deletion-gate-bootstrap-20260729

Conversation

@Pigbibi

@Pigbibi Pigbibi commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Summary

  • allow the deterministic gate to accept only exact deletion paths pre-approved in the trusted base policy
  • reject glob, absolute, traversal, backslash, and non-normalized approvals
  • stage a one-shot four-path approval and 3000-line cap for the already-disabled duplicate PR reviewer cleanup

The follow-up cleanup PR removes the temporary approval list and restores the 2000-line limit. This does not bypass the gate: approval must exist on protected main before a deletion PR is evaluated.

Tests-first evidence

  • focused gate suite failed on the exact base because an approved deletion was still blocked
  • focused gate suite now passes: 7 passed, 4 subtests passed

Verification

  • Ruff
  • full pytest: 640 passed, 1 skipped, 54 subtests passed
  • actionlint
  • proxy Node tests: 13 passed
  • dashboard Node tests: 15 passed
  • JSON validation and diff-check

Boundaries

  • no required-check, ruleset, protection, permission, secret, OIDC, VPS, or deploy mutation
  • no provider/data/trading/live action

Co-Authored-By: Codex <noreply@openai.com>
@Pigbibi

Pigbibi commented Jul 29, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a4ab14f497

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/codex_auto_merge_policy.json Outdated
Comment thread .github/codex_auto_merge_policy.json Outdated
Comment thread .github/codex_auto_merge_policy.json Outdated
Co-Authored-By: Codex <noreply@openai.com>
@Pigbibi

Pigbibi commented Jul 29, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🎉

Reviewed commit: 994c296d0a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@Pigbibi
Pigbibi merged commit 068a034 into main Jul 29, 2026
7 checks passed
@Pigbibi
Pigbibi deleted the codex/aiauditbridge-deletion-gate-bootstrap-20260729 branch July 29, 2026 03:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant