Skip to content

Complete setup with map upload and live rule retrieval - #350

Merged
patchstackdave merged 3 commits into
codex/framework-entry-coveragefrom
codex/one-command-security-setup
Oct 2, 2026
Merged

patchstackdave merged 3 commits into
codex/framework-entry-coveragefrom
codex/one-command-security-setup

Conversation

@patchstackdave

@patchstackdave patchstackdave commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Stack

Part 4; depends on #349. Merge after #347, #348, and #349.

Changes

  • The setup command now installs/verifies protection, uploads the structural attack-surface map, stamps its identity for the next startup/build, and retrieves live rules.
  • Reuse runtime validation, authenticated delivery and the source-scoped cache; never create a running guard or override build-scope confirmation.
  • Wire automatic map uploads before builds, preserving existing scripts: npm lifecycle hooks and explicit Yarn, pnpm, and Bun build chains.
  • Distinguish successful empty policy, failed upload, failed rule retrieval, and remaining integration/restart steps.
  • Update privacy disclosures and all three install-prompt copies. Standalone map remains local without --upload.

Validation

  • Full suite: 4,258 passed, 7 skipped (246 files).
  • Build, typecheck (10 templates), capability and disclosure checks passed.
  • Packaged Express setup passed twice: one site/widget, verified protection, map upload, bound rule retrieval, persistent cache, idempotent hooks, unchanged dev commands.
  • Actual package-manager execution tests cover npm, pnpm, Yarn Classic, Yarn Berry, and Bun, including repeated builds and build failure. Yarn fixture initialization is tested in CI mode with network disabled.
  • Regression cases cover authentication/map failures, empty policy, atomic rejection of invalid policy, cache isolation, changed map identity, client-only apps, symlink preservation, and hook ordering.

Outstanding release validation

The required hostile install-prompt field test ran: 0/3 requested rounds green, 9 void attempts. Each refused before obtaining the published package, so this is a failed prompt-reliability gate and inconclusive about shipped documentation, not a successful install test. This PR is ready for code review. The install-prompt review and required gate remain outstanding; marking it ready does not establish that the gate passed. Run the shipped-guide field gate again after release. Raw transcripts remain out of the repository.

Setup does not restart or deploy the application, claim complete static coverage, or protect independently hosted backends. Public-boundary review completed; all new fixtures are synthetic.

@coderbuds

coderbuds Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Setup now uploads structural maps and retrieves live rules in CI and docs.

🎯 Quality: 76% Good · 📦 Size: Large — consider splitting if possible

🛡️ Standards: Not checked — 451 lines changed, over your team's 400-line limit, and nothing checked before it was opened. Coding agents can call the assess-change-fit tool first, while a change this size is still cheap to split.

🤖 Authorship: Probably agent-written — OpenAI Codex, going by its branch name. Whether a person read it is unknown; coding agents can call the report-ai-usage tool to say.

📈 This month: Your 206th PR — above team average · Averaging Good

See how your team is trending →

@patchstackdave
patchstackdave added this pull request to stack #351 October 1, 2026 19:04
@patchstackdave
patchstackdave force-pushed the codex/one-command-security-setup branch from 58bd662 to 3e21bac Compare October 2, 2026 06:28
@patchstackdave

Copy link
Copy Markdown
Contributor Author

Review fixes pushed in 3e21bac; rebased onto the updated stack.

  • Use explicit scan → map upload → application build → mark-build chains for Yarn, pnpm, and Bun. npm retains its lifecycle hooks.
  • Recognize pre-build map uploads from the current project manifest even when package managers omit or inherit lifecycle metadata.
  • Preserve quoted shell arguments and grouped commands when composing hooks.
  • Test actual package-manager execution, repeated setup/builds, fresh pre-build map context, and failure before mark-build. Added the execution test to the npm, pnpm, Yarn Classic, Yarn Berry, and Bun CI matrix.

Local validation: 4,258 tests passed, 7 skipped; build, 10 template typechecks, and capability checks passed. Actual npm, pnpm 9.15.4, Yarn Classic 1.22.22, Yarn Berry 4.18.0, and Bun execution tests passed.

This remains draft. The existing install-prompt reliability gate is still unresolved; these code fixes do not waive it.

@patchstackdave
patchstackdave marked this pull request as ready for review October 2, 2026 06:38
@patchstackdave

Copy link
Copy Markdown
Contributor Author

/review

@patchstackdave
patchstackdave merged commit fa22467 into main Oct 2, 2026
23 checks passed
@patchstackdave
patchstackdave deleted the codex/one-command-security-setup branch October 2, 2026 07:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants