Skip to content

Dev/milestone c security report hardening#58

Merged
docushell-dev merged 51 commits into
mainfrom
dev/milestone-c-security-report-hardening
Jun 18, 2026
Merged

Dev/milestone c security report hardening#58
docushell-dev merged 51 commits into
mainfrom
dev/milestone-c-security-report-hardening

Conversation

@docushell-dev

Copy link
Copy Markdown
Collaborator

No description provided.

@docushell-dev docushell-dev self-assigned this Jun 17, 2026
docushell-admin added 29 commits June 18, 2026 09:30
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
docushell-admin added 22 commits June 18, 2026 09:30
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
Signed-off-by: docushell-admin <hello@docushell.com>
@docushell-dev
docushell-dev force-pushed the dev/milestone-c-security-report-hardening branch from 82cf990 to a0fe7a2 Compare June 18, 2026 04:01
@docushell-dev
docushell-dev merged commit 4e3adbb into main Jun 18, 2026
10 checks passed
docushell-dev added a commit that referenced this pull request Jun 22, 2026
* Ground security report span previews

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report artifact identity

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report finding ids

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report finding messages

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report exclusion flags

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report span ownership

Signed-off-by: docushell-admin <hello@docushell.com>

* Add source-only security report command

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report page and bbox grounding

Signed-off-by: docushell-admin <hello@docushell.com>

* Fail closed on security report warning lane drift

Signed-off-by: docushell-admin <hello@docushell.com>

* Align security report validator warning lanes

Signed-off-by: docushell-admin <hello@docushell.com>

* Reject stale security report summary drift

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate unsupported annotation report parity

Signed-off-by: docushell-admin <hello@docushell.com>

* Require security report inventory lanes

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate unsupported annotation finding messages

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate image-only page finding messages

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate text exclusion finding messages

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security warning source messages

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report finding codes

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report inventory fields

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report envelope fields

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report finding fields

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report unexpected fields

Signed-off-by: docushell-admin <hello@docushell.com>

* Reject boolean security report bbox coordinates

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report summary counts

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report attachment byte counts

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report boolean fields

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report script locations

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report attachment digests

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report array items

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report inventory strings

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report identity patterns

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report finding strings

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report page locators

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report locator refs

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report finding ids

Signed-off-by: docushell-admin <hello@docushell.com>

* Harden security report script locations

Signed-off-by: docushell-admin <hello@docushell.com>

* Harden security report code diagnostics

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate null security report pages

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report script triggers

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate null security report locators

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security report inventory kinds

Signed-off-by: docushell-admin <hello@docushell.com>

* Split security report code diagnostics

Signed-off-by: docushell-admin <hello@docushell.com>

* Require security warning codes

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate security warning locator shapes

Signed-off-by: docushell-admin <hello@docushell.com>

* Split security warning message diagnostics

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate document warning ids

Signed-off-by: docushell-admin <hello@docushell.com>

* Validate parser warning messages

Signed-off-by: docushell-admin <hello@docushell.com>

* Reject duplicate warning ids

Signed-off-by: docushell-admin <hello@docushell.com>

* Enforce deterministic warning numbering

Signed-off-by: docushell-admin <hello@docushell.com>

* Add Milestone C internal checks

Signed-off-by: docushell-admin <hello@docushell.com>

* Ground security warning locators

Signed-off-by: docushell-admin <hello@docushell.com>

---------

Signed-off-by: docushell-admin <hello@docushell.com>
Co-authored-by: docushell-admin <hello@docushell.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant