Skip to content

chore: prepare repository for public maintenance - #16

Merged
fly1d merged 1 commit into
mainfrom
codex/public-repository-readiness
Aug 11, 2026
Merged

chore: prepare repository for public maintenance#16
fly1d merged 1 commit into
mainfrom
codex/public-repository-readiness

Conversation

@fly1d

@fly1d fly1d commented Aug 11, 2026

Copy link
Copy Markdown
Owner

Summary

  • upload CodeQL results now that the repository is public while retaining the warning/error gate
  • run the required desktop status on every pull request so branch protection cannot wait forever
  • add a private security-report contact link and public status badges
  • document the enforced branch process and current unlicensed status

Local verification

  • npm run check
  • npm run test:smoke (5 passed, 1 environment-specific test skipped)
  • npm run desktop:check (2 Rust tests passed)
  • YAML parse and git diff --check

License

This PR does not grant an open-source license; the project remains UNLICENSED.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@fly1d fly1d left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the complete diff against the public-repository settings. CodeQL upload is scoped to security-events, the existing warning/error SARIF gate remains intact, every PR now emits the required desktop status, and the security reporting link targets the enabled private advisory flow. Local and GitHub checks pass, native CodeQL upload is visible, and there are zero open code-scanning alerts. No blocking findings.

@fly1d
fly1d merged commit d8912d3 into main Aug 11, 2026
5 checks passed
@fly1d
fly1d deleted the codex/public-repository-readiness branch August 11, 2026 10:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants